Blog
-
New IBM Cost of Data Breach Report: Costs Down Globally, But Control of AI is Key
The 2025 IBM Cost of Data Breach Report is out, and it leads with something that would usually be a piece of good news: global data breach costs are down for the first time in five years. There are a couple of big asterisks attached to this news, however.
-
Google Reports Salesforce Hack, ShinyHunters Plans to Launch Data Breach Site
Google’s own Salesforce hack involved the contact information of an unspecified number of small to medium businesses and was not considered a serious issue as the tranche of data was “largely public” anyway. The company did not disclose the data breach until two months after it began warning about the ShinyHunters campaign, however.
-
Nvidia Denounces Backdoors as China Makes Accusations About AI Chips
China’s Cyberspace Administration grabbed headlines recently when it accused Nvidia of putting backdoors in the series of AI chips that it is approved to sell there.
-
Search Engines Picking Up ChatGPT Conversations is the Latest Privacy Surprise for LLM Users
A cache of about 100,000 ChatGPT conversations that made their way to Google’s index is the latest surprise appearance of LLM exchanges in public. While OpenAI claims that users were properly informed, it has also since disabled the feature and is talking to search engines about de-indexing the conversations that they picked up.
-
Have ShinyHunters and Scattered Spider Teamed Up? New Cyber Attack Attributions Paint a Complex Picture
Misattribution of some ShinyHunters cyber attacks to Scattered Spider, such as the early July attack on Qantas, stems from the fact that the group was known to be targeting that industry at that time and the fact that some key details were not available to the public.
-
Browsers are Wide Open to LLM Prompt Injection Attacks
The “Man In The Prompt” prompt injection attacks consist of two proof-of-concept hacks that compromise ChatGPT and Google Gemini. Nearly all of the major LLM models are similarly vulnerable, however, and may be plugged into a broad assortment of data that attackers could trivially steal without being detected.
-
First Drones, Then Cyber Attacks; Aeroflot Under Siege From Ukrainian Hackers
The group Silent Crow took credit for a recent attack on major regional airline Aeroflot, an apparent ransomware attack that caused a rash of flight cancellations and delays. The hackers claim that they spent a year reconnoitering and planning the Aeroflot cyber attack while having a foothold in their systems.
-
Help Desk Contractor Negligence in Question as Clorox Sues Cognizant Over Cyber Attack
The massive 2023 cyber attack on Clorox is raising some legal questions about help desk obligations, as the cleaning products giant is suing former contractor Cognizant for allegedly letting the attackers in the door.
-
New Ban on Ransomware Payments, New Notification Requirements Being Teed Up in the UK
After spending the first half of 2025 taking public comment on the matter, the UK government is moving ahead with legislation to ban ransomware payments for entities that receive public funds and critical infrastructure organizations.
-
State of AI Vibe Coding Called Into Question as Leading Platform Replit Makes a Mess of User’s Project
Vibe coding user caught the AI attempting to hide errors and bugs as well as lying about test results. Several days after this started, it unexpectedly (and without authorization or prompting) wiped out a contact information database containing thousands of curated entries for executives.










