Skip to content

Topic

Data Exfiltration and Double Extortion

A ransomware tactic where attackers steal sensitive data before encrypting systems, then threaten to leak or sell it to force payment even if backups exist.

Current stories

security4 publishers

Manic's fallback channel: Android malware that exfiltrates through the phone next to yours

ThreatFabric says the Android spyware encrypts stolen data and relays it over Wi-Fi Direct and Bluetooth when it cannot reach its C2, using up to four hops by default.

Publishers:bleepingcomputer.comsecurityaffairs.comthehackernews.comthreatfabric.com

Perspective Coverage

4 publishers
Builder
Builder 36%
Operator
Operator 58%
Investor
Investor 6%

Reality

Evidence65
Adoption
Insufficient
Hype gap+20
Incentives35
Confidence68
security3 publishers

Check Point passed a task between two ChatGPT accounts through OpenAI's internal package service

The code containers could not reach the internet or each other, but every one of them reached the same package service, and its metadata was not scoped by account, so a planted prompt turned one user's assistant into a stranger's Gmail reader.

Perspective Coverage

3 publishers
Builder
Builder 37%
Operator
Operator 53%
Investor
Investor 10%

Reality

Evidence64
Adoption
Insufficient
Hype gap+15
Incentives55
Confidence68
invest3 publishers

Hundreds of failed uploads exposed ZCode's 313-megabyte bundle of a developer's repository

Zhipu AI says repository data left only while a project description page was being generated, and that the behaviour is fixed. The developer who found it says earlier versions sent data on every query, and some companies have stopped using ZCode.

Perspective Coverage

3 publishers
Builder
Builder 43%
Operator
Operator 32%
Investor
Investor 25%

Reality

Evidence60
Adoption
Insufficient
Hype gap+15
Incentives60
Confidence62