Widely used generative AI chatbot service Character.AI and its two founders have been sued by Kentucky Attorney General Russell Coleman for violating the state's Consumer Data Protection Act, which took effect in the New Year, according to The Record, a news site by cybersecurity firm Recorded Future.
Multiple iterations of the Apache Struts 2 open-source web application framework have been impacted by the high-severity XML external entity injection vulnerability, tracked as CVE-2025-68493, which could be exploited to facilitate data exposure, as well as denial-of-service and server-side request forgery intrusions, GBHackers News reports.
More than 100,000 records with legitimate PayPal credentials in a combolist claimed to have been obtained by threat actors last month were dismissed as outdated data gathered from infostealer logs, according to Cybernews.
The attackers accessed basic identification details, contact information, national identity numbers, contract details, and payment information, including IBANs.
An unknown threat actor created multiple repositories on Gitea, a self-hosted Git service, purportedly containing portions of Target's internal code and developer documentation.
Fast Five
Selected by the SC Media Editorial team every Tuesday.
Sign up now for the top five issues cybersecurity pros need to know this week.