Such a leak stemming from inadequate security configurations is the first to impact a Chroma database, according to a report from UpGuard, which identified the internet-exposed database that has since been secured.
Independent security researcher brutecat was able to create an exploit that facilitated the exposure of targeted accounts' full display names while circumventing Google's anti-bot defense mechanism hindering password reset request spamming.
While data exposed by Arkana Security was initially suspected to be from a new data breach, BleepingComputer discovered that the recently leaked files were the same as those previously identified in the Snowflake attacks.
Attackers who breached the state's CRIS using a compromised account, which has since been taken down, were able to exfiltrate data, including names, driver's license numbers, license plate numbers, car insurance policy numbers, and addresses, as well as details on crash-related injuries and incident narratives.
U.S. multinational industrial technology firm Sensata Technologies has disclosed that data from current and former employees, as well as their dependents, had been compromised following a ransomware attack in April.
A new analysis by Frances data protection authority, CNIL, estimates that the GDPR has delivered significant cybersecurity benefits across the EU, preventing cyber-related losses of up to 1.4 billion since its 2018 implementation, Cybernews reports.
Fast Five
Selected by the SC Media Editorial team every Tuesday.
Sign up now for the top five issues cybersecurity pros need to know this week.