The misconfiguration on Klaviyo's sign-up page allowed any third-party trackers present on the site to potentially access and share sensitive customer data.
A vulnerability in HP ThinPro 8 and 9 operating systems allows attackers with physical access to bypass TPM-backed full-disk encryption and recover the key securing the device's root partition.
A vendor, identified as "Gordon Freeman," advertised a 7.5 GB database allegedly containing national ID numbers, addresses, phone numbers, birth and death dates, and family links for nearly all Israeli citizens.
The attack exploits a time-of-neutralization to time-of-use (TONTOU) window in Spectre v2 defenses, where a gap exists between when the branch predictor is isolated and when it is used.
As organizations rush to adopt agentic AI, agents are often given broad access to critical business systems and sensitive data. Legacy insider risk management tools weren't built for this, and organizations have spent years on insider risk posturing and investments that leave security teams inundated with false positives while the real risk slips t...
Fast Five
Selected by the SC Media Editorial team every Tuesday.
Sign up now for the top five issues cybersecurity pros need to know this week.