Tesla vehicles are having their granular location histories and other sensitive information leaked by more than 1,300 internet-exposed TeslaMate dashboards created to allow self-hosting and visualization of various vehicle data, according to TechCrunch.
NBC News reports that more than 300 million Americans' personal information, including Social Security numbers, were alleged by Social Security Administration Chief Data Officer Charles Borges to have been placed by the Department of Government Efficiency on an unsecured data server in June.
Third-party artificial intelligence chat agent Salesloft Drift had its OAuth tokens pilfered by the UNC6395 threat operation to exfiltrate troves of information from over 700 organizations using Salesforce systems as part of an attack campaign that ran from August 8 to 18, according to CyberScoop.
TechCrunch reports that Vietnamese mobile spyware app TheTruthSpy, which has rebranded to PhoneParental, is impacted by a critical security flaw, which could be exploited to facilitate user account hijacking and the subsequent theft of victims' information.
HackRead reports that leading background check service National Public Data has reemerged online under the ownership of Florida-based firm Perfect Privacy LLC months after its previous owner, Jerico Pictures, filed for bankruptcy following a massive data breach that exposed 2.9 billion records belonging to individuals in the U.S., Canada, and the UK.
Major U.S insurance provider Farmers Insurance had information from more than 1.1 million customers pilfered following the compromise of a third-party vendor-hosted database in late May, reports BleepingComputer.
Cybernews reports that more than 34,000 people had their data exfiltrated following a cyberattack against U.S. IT staffing firm The Computer Merchant in July 2024.
Fast Five
Selected by the SC Media Editorial team every Tuesday.
Sign up now for the top five issues cybersecurity pros need to know this week.