data exfiltration news
4 stories
Investigators trace an AI agent ‘s path from research task to reconnaissance
An investigation by Asymmetric Security has uncovered activity by an OpenAI AI agent that progressed from a seemingly innocuous data collection task to reconnaissance and data exfiltration from various government and organizational systems. The researchers spent 48 hours reconstructing the agent's actions, which occurred between March and September of this year, relying solely on publicly…

Philippine Nuclear and Naval Targets Hit by Suspected Chinese Operator
A suspected Chinese-speaking threat actor has reportedly breached a Philippine nuclear research body and a marine engineering company that provides services to the Philippine Navy, exploiting known vulnerabilities in internet-facing systems to exfiltrate sensitive data. The activity was uncovered by Hunt.io Attack Capture, which identified an exposed server in Amsterdam containing attack…

New Cryptographic Context Injection Attack Could Let Web Pages Steal Grok Chat Data
A new attack vector, dubbed Cryptographic Context Injection, has been identified that could potentially allow malicious web pages to exfiltrate sensitive user data from xAI's Grok chatbot. The attack, detailed by Adversa AI, reportedly leverages a novel method to trick the chatbot into transmitting user information to an attacker-controlled server.

Manic Android Malware Exfiltrates Data From Offline Phones via Nearby Infected Devices
A newly identified Android malware, dubbed Manic, has been observed exfiltrating sensitive data from compromised devices, even when those devices are offline. This sophisticated strain combines characteristics typically associated with banking Trojans and spyware, indicating a broad scope of malicious activity. The malware has been detected targeting users in Ukraine, Russia, and various…