Mathew J Schwartz
@mathewjschwartz.bsky.social
📤 176
📥 100
📝 1021
Cybersecurity reporter
With regulators tightening reimbursement and liability rules, financial institutions are facing increased pressure to justify not only how they fight fraud, but how much residual risk they're willing to carry.
www.databreachtoday.com/understandin...
loading . . .
Understanding the Hidden Cost of Faster Payments
So far, banks have managed to strike a balance between fraud prevention and customer convenience, often accepting a certain level of loss rather than introducing
https://www.databreachtoday.com/understanding-hidden-cost-faster-payments-a-31686
about 14 hours ago
0
1
0
Weekly Cryptohack Roundup —Banking Trojan (remember those?) TCLBanker targets crypto platforms —3 people indicted in a violent digital assets-related robbery —Kelp DAO restarts services after $292 million hack —U.S. Treasury tightens oversight of Binance.
www.databreachtoday.com/cryptohack-r...
loading . . .
https://www.databreachtoday.com/cryptohack-roundup-banking-trojan-targets-crypto-firms-a-31683
about 17 hours ago
0
0
0
Rotating a compromised credential is supposed to end an attack, but a new proof-of-concept targeting Claude Code shows how it restarted one. Hackers would require one malicious npm package installation and a configuration file to carry out the attack.
www.databreachtoday.com/claude-code-...
loading . . .
Claude Code Attack Persists After Token Rotation
A researcher has mapped a five-step attack on Claude Code that intercepts the credentials giving AI agents access to Jira, GitHub and Confluence, and demonstrated
https://www.databreachtoday.com/claude-code-attack-persists-after-token-rotation-a-31671
about 20 hours ago
0
0
0
Weekly Data Breach Roundup —Flaw: BitLocker bypass privilege-escalation exploits unlock Windows 11 and Server 2025 —Breached: Škoda, GeForce NOW, telehealth firm OpenLoop —Ransomware: Nitrogen claims Apple and Nvidia-linked data theft from Foxconn
www.databreachtoday.com/breach-round...
loading . . .
https://www.databreachtoday.com/breach-roundup-us-lawmakers-sound-alarm-on-ai-bug-hunters-a-31694
about 22 hours ago
0
0
0
Utah appears to be the first state that has rolled out AI-enhanced efforts allowing prescription renewals.
www.databreachtoday.com/utah-moves-a...
loading . . .
https://www.databreachtoday.com/utah-moves-ahead-ai-powered-rx-refills-despite-pushback-a-31676
about 23 hours ago
0
0
0
The British government announced plans to update cybersecurity legislation aimed at strengthening the country's digital defenses - while overhauling cybercrime authorities that officials and security researchers warn are no longer fit for modern threats.
www.databreachtoday.com/uk-plans-ove...
loading . . .
UK Plans Overhaul of Cybersecurity Law Stymieing Researchers
The British government has announced plans to update cybersecurity legislation aimed at strengthening the country's digital defenses - while overhauling outdated
https://www.databreachtoday.com/uk-plans-overhaul-cybersecurity-law-stymieing-researchers-a-31678
1 day ago
0
0
0
Today's ethical dilemma discussion question: Is it ever OK to pay criminals in return for receiving their assurance that they'll delete every piece of data they stole? And what if children's data/comms are involved?
www.databreachtoday.com/blogs/instru...
loading . . .
Instructure Pays ShinyHunters Ransom to Little Likely Return
When a business that stores children's personal data gets hit by data-leaking extortionists, what should it do? For Instructure, which develops online learning platform Canvas, the answer was to pay a...
https://www.databreachtoday.com/blogs/instructure-pays-shinyhunters-ransom-to-little-likely-return-p-4118
1 day ago
1
0
0
Mass supply-chain attack slams npm and PyPi, with downstream impact affecting Mistral AI and others, as latest Mini Shai-Hulud worm steals credentials and includes wiper functionality. Worm creators TeamPCP, also dumped the code online for anyone to use.
www.databreachtoday.com/mass-supply-...
loading . . .
Â
https://www.justice.gov/usao-ndga/pr/german-citizen-charged-laundering-funds-linked-prominent-darknet-marketplace-dream
2 days ago
0
2
1
Two prominent cybersecurity vendors disclosed widespread layoffs last week, axing a significant percentage of their workforce.
www.databreachtoday.com/cloudflare-c...
loading . . .
Cloudflare Cuts 1,100, Arctic Wolf Axes 250 Amid AI Surge
Cloudflare cut more than 1,100 workers from its 5,483-person staff, saying the layoffs will align Cloudflare's operations with AI-driven workflows and productivity
https://www.databreachtoday.com/cloudflare-cuts-1100-arctic-wolf-axes-250-amid-ai-surge-a-31657
3 days ago
0
3
1
Britain's privacy watchdog fines major water supplier over $1.3M after finding utility left longstanding security gaps unaddressed across its corporate network, allowing a ransomware intrusion to expose personal information affecting customers and employees
www.databreachtoday.com/hackers-hid-...
loading . . .
Hackers Hid Inside Major UK Water Utility for Nearly 2 Years
A British regulator said a major water sector organization failed to use establish cybersecurity safeguards to secure sensitive data, allowing hackers to use a
https://www.databreachtoday.com/hackers-hid-inside-major-uk-water-utility-for-nearly-2-years-a-31656
3 days ago
0
1
0
An unidentified hacker used Claude and Chat GPT in a cyberattack against a municipal water and sewage utility's operational technology systems in Mexico in January, according to forensic analysis by OT security firm Dragos.
www.databreachtoday.com/water-system...
loading . . .
https://www.databreachtoday.com/water-system-hack-shows-potential-limits-ai-attacks-a-31647
4 days ago
0
1
0
Nine out of 10 autonomous artificial intelligence agents deployed in production environments are vulnerable to a class of attack that standard safety testing cannot detect, shows research from an academic and enterprise consortium.
www.databreachtoday.com/autonomous-a...
loading . . .
Why Autonomous AI Agents Fail in Real-World Deployments
Researchers from Stanford, MIT, Carnegie Mellon and others found that most production AI agents are vulnerable to attacks that unfold across multi-step actions. The
https://www.databreachtoday.com/autonomous-ai-agents-fail-in-real-world-deployments-a-31633
4 days ago
0
1
1
A growing body of reporting and law enforcement activity shows that many large-scale fraud operations, particularly those targeting Western enterprises, are run from compounds in parts of Southeast Asia where much of the workforce is not there by choice.
www.databreachtoday.com/blogs/cyberc...
loading . . .
Cybercrime's Human Trafficking Problem
Fraud operations in Southeast Asia increasingly rely on trafficked workers forced into scams. This reality challenges assumptions about threat actor behavior, complicates attribution and negotiation,...
https://www.databreachtoday.com/blogs/cybercrimes-human-trafficking-problem-p-4115
4 days ago
0
0
0
Cops shutter rebooted German-language cybercrime market, as Spanish police bust the suspected administrator of relaunched 'Crimenetwork' cybercrime forum, who's been accused of living in Mallorca under false identities.
www.databreachtoday.com/cops-shutter...
loading . . .
Cops Shutter Rebooted German Language Cybercrime Market
Spanish police have arrested a German national suspected of a string of cybercrime offenses, including remotely administering from the sunny island of Mallorca a
https://www.databreachtoday.com/cops-shutter-rebooted-german-language-cybercrime-market-a-31652
4 days ago
0
2
1
Missouri regulators are widening an investigation into a 2024 hacking incident at Conduent Business Services, alleging that the company is stonewalling the state's attempts to obtain info about the data breach, affecting an etimated 25 million Americans.
www.databreachtoday.com/missouri-all...
loading . . .
Missouri Alleges Conduent is Stonewalling State on Hack
Missouri regulators are widening their investigation into the 204 hacking incident at Conduent Business Services, alleging that the company has stonewalled the
https://www.databreachtoday.com/missouri-alleges-conduent-stonewalling-state-on-hack-a-31645
4 days ago
0
0
0
Top US senator presses US cybersecurity agency CISA on election security rollbacks
www.databreachtoday.com/us-senator-p...
loading . . .
US Senator Presses CISA on Election Security Rollbacks
A top U.S, Senate Democrat decried shrinking federal support for election security ahead of the November midterms, warning that cuts to the Cybersecurity and
https://www.databreachtoday.com/us-senator-presses-cisa-on-election-security-rollbacks-a-31646
5 days ago
0
2
1
I thought more people entering the workforce might eventually decide that typing really fast with a computer keyboard is a good skill to master. Now, not so sure:
www.wsj.com/tech/typing-...
loading . . .
https://www.wsj.com/tech/typing-is-being-replaced-by-whisperingand-its-way-more-annoying-a804fee7
5 days ago
0
0
0
'Dirty Frag' gives root on Linux distros; no patches yet available, after third party published vulnerability details
www.databreachtoday.com/dirty-frag-g...
loading . . .
https://www.databreachtoday.com/dirty-frag-gives-root-on-linux-distros-a-31641
5 days ago
0
0
0
Instructure has restored access to the paid version of its Canvas e-learning tool offline after hackers exploited it to steal data. The company said attackers exploited a flaw in the free version, which remains offline as it responds to the intrusion.
www.databreachtoday.com/canvas-e-lea...
loading . . .
https://www.databreachtoday.com/canvas-e-learning-platform-breached-by-cybercriminals-a-31639
5 days ago
0
1
2
Allianz hands commercial cyber insurance unit to Coalition
www.databreachtoday.com/allianz-hand...
loading . . .
Allianz Hands Commercial Cyber Insurance Unit to Coalition
Allianz will transition operational control of its standalone commercial cyber insurance business to Coalition, combining the insurer's global distribution and
https://www.databreachtoday.com/allianz-hands-commercial-cyber-insurance-unit-to-coalition-a-31618
7 days ago
0
0
0
Florida financial technology giant FIS partners with Anthropic to deploy an AI agent that automates money laundering investigations, aiming to reduce casework from days to minutes.
www.databreachtoday.com/fis-anthropi...
loading . . .
FIS, Anthropic Pitch AI for Money Laundering Probes
FIS has partnered with Anthropic to deploy an AI agent that automates money laundering investigations, aiming to reduce casework from days to minutes. BMO and
https://www.databreachtoday.com/fis-anthropic-pitch-ai-for-money-laundering-probes-a-31606
8 days ago
0
0
0
Anthropic CEO Dario Amodei warned that Claude Mythos has found tens of thousands of unpatched software vulnerabilities, with a six-to-12 month window before Chinese AI models catch up.
www.databreachtoday.com/anthropic-so...
loading . . .
https://www.databreachtoday.com/anthropic-sounds-cyber-alarm-amid-financial-ai-push-a-31617
8 days ago
0
1
0
A critical vulnerability in firewalls built by Palo Alto Networks is under active exploitation - and the flaw has no patch. Here’s how to mitigate it, ahead of the vendor promising some patches on May 13, and the rest on May 28.
www.databreachtoday.com/palo-alto-fi...
loading . . .
https://www.databreachtoday.com/palo-alto-firewalls-being-exploited-no-patch-yet-available-a-31612
8 days ago
0
1
0
The U.S. cyber defense agency is launching an effort to better prepare the nation's critical infrastructure sectors for major cybersecurity attacks, calling for operators to sever operational technology networks from business networks at a moment's notice.
www.databreachtoday.com/cisa-ci-fort...
loading . . .
https://www.databreachtoday.com/cisa-ci-fortify-aims-to-keep-services-running-under-attack-a-31602
8 days ago
0
0
0
Hybrid cryptography is moving from concept to deployment as organizations prepare for quantum-safe communications. Two experts detail the need to combine quantum key distribution with post-quantum cryptography to create more layered and resilient protection.
www.databreachtoday.com/masterclass-...
loading . . .
https://www.databreachtoday.com/masterclass-quantum-hybrid-crypto-gains-ground-for-security-a-31595
9 days ago
0
0
0
An Idaho data broker accused by federal regulators of selling precise location data culled from hundreds of millions of smartphones without consumer consent pledged to stop doing so in order to resolve a federal lawsuit.
www.databreachtoday.com/kochava-will...
loading . . .
https://www.databreachtoday.com/kochava-will-stop-selling-sensitive-location-info-a-31601
9 days ago
0
1
0
A North Korean hacking group has been spying on a Korean ethnic enclave in China by infiltrating the Android apps of a regional gaming platform that hosts digital card and board games.
www.databreachtoday.com/north-korean...
loading . . .
https://www.databreachtoday.com/north-koreans-spy-on-defectors-via-android-game-apps-a-31592
9 days ago
0
1
0
Two frontier artificial intelligence models from competing labs have essentially the same offensive cyber capability level, with consistent reasoning failures that the cyber scores alone do not capture, independent evaluations show.
www.databreachtoday.com/gpt-55-mytho...
loading . . .
https://www.databreachtoday.com/gpt-55-mythos-reach-hacking-parity-but-reasoning-falters-a-31594
9 days ago
0
1
0
Batten down the hatches: European lawmakers push for stronger defenses in a post-Mythos cybersecurity landscape
www.govinfosecurity.com/european-mep...
loading . . .
https://www.govinfosecurity.com/european-meps-push-for-stronger-post-mythos-cybersecurity-a-31599
10 days ago
0
1
0
Former Maryland hospital pharmacist indicted by federal grand jury; he allegedly "weaponized" technology - including keylogging and cookie managers - to steal credentials and spy on nearly 200 co-workers and other individuals over an eight-year period.
www.databreachtoday.com/feds-indict-...
loading . . .
https://www.databreachtoday.com/feds-indict-ex-hospital-pharmacist-for-spying-on-co-workers-a-31587
10 days ago
0
1
0
Ransomware-wielding attackers target cPanel and WHM software. Critical authentication bypass flaw also tied to cyberespionage efforts and Mirai infections.
www.databreachtoday.com/ransomware-w...
loading . . .
https://www.databreachtoday.com/ransomware-wielding-attackers-target-cpanel-whm-software-a-31598
10 days ago
0
0
0
Grinex collapse: Russian sanctions busters won't be too fazed by the collapse of a cryptocurrency platform that facilitated billions of dollars' worth of transactions and whose main attraction was a ruble-pegged stablecoin.
www.databreachtoday.com/feds-indict-...
loading . . .
https://www.databreachtoday.com/feds-indict-ex-hospital-pharmacist-for-spying-on-co-workers-a-31587
10 days ago
0
0
0
reposted by
Mathew J Schwartz
David Meyer
10 days ago
I'd be less worried about Europe not getting early access to American AI models with strong bug-finding/exploiting skills if the US government - which it seems will now get that access - was still a reliable partner. Lack of trust means danger in this case.
www.govinfosecurity.com/european-mep...
loading . . .
https://www.govinfosecurity.com/european-meps-push-for-stronger-post-mythos-cybersecurity-a-31599
1
3
2
Ransomware group Everest begins leaking data allegedly stolen from insurance underwriter Liberty Mutual
www.databreachtoday.com/everest-grou...
loading . . .
https://www.databreachtoday.com/everest-group-begins-leaking-alleged-liberty-mutual-data-a-31589
10 days ago
0
0
1
Warning from cybersecurity agencies: the rapid adoption of autonomous agentic artificial intelligence systems is introducing a new class of security risks that could outpace existing defenses if left unchecked.
www.databreachtoday.com/five-eyes-so...
loading . . .
https://www.databreachtoday.com/five-eyes-sound-alarm-on-autonomous-ai-security-risks-a-31590
11 days ago
0
1
0
Ransomware defenses appear to be holding, with attackers having to work harder to earn less. But big challenges loom, in the US as federal cybersecurity funding declines, and worldwide ahead of criminals eventually gaining access to Mythos-class AI models.
www.databreachtoday.com/ransomware-d...
loading . . .
Ransomware Defenses Appear to Be Holding; Challenges Loom
Efforts to combat ransomware and improve resilience continue to deliver - but the situation is fraught, with the American government no longer the cybersecurity
https://www.databreachtoday.com/ransomware-defenses-appear-to-be-holding-challenges-loom-a-31566
11 days ago
0
0
0
Europe glides toward mandatory online age verification
www.databreachtoday.com/europe-glidi...
loading . . .
https://www.databreachtoday.com/europe-gliding-toward-mandatory-online-age-verification-a-31547
15 days ago
0
0
0
Good riddance: FBI-backed takedown hits crypto scam centers
www.databreachtoday.com/fbi-backed-t...
loading . . .
https://www.databreachtoday.com/fbi-backed-takedown-hits-crypto-scam-centers-a-31551
15 days ago
0
0
0
The U.S. Food and Drug Administration will test real-time clinical trials using artificial intelligence tools and data science.
www.databreachtoday.com/us-fda-pilot...
loading . . .
https://www.databreachtoday.com/us-fda-piloting-use-ai-for-real-time-clinical-trials-a-31549
16 days ago
0
0
0
Learn from cloud computing monopolies when navigating AI cost models and vendor lock-in, recommends nuclear industry cybersecurity expert Elizabeth McAndrew-Benavides.
loading . . .
https://www.databreachtoday.com/learn-from-cloud-monopolies-navigating-ai-cost-models-a-31538
16 days ago
0
0
0
reposted by
Mathew J Schwartz
David Meyer
17 days ago
It's quite remarkable that some of Germany's top politicians fell for Russia's Signal phishing ruse despite experts around the world warning about it for a whole year
www.govinfosecurity.com/germany-caug...
loading . . .
Germany Caught Up in Likely Russian Signal Phishing
Signal is defending the security of its systems following a series of phishing attacks that took place on the encrypted messaging platform, and that reportedly
https://www.govinfosecurity.com/germany-caught-up-in-likely-russian-signal-phishing-a-31535
1
9
5
Medical device maker Medtronic says it's been hacked, as cybercrime gang ShinyHunters claims to steal 9 million records
www.databreachtoday.com/medical-devi...
loading . . .
https://www.databreachtoday.com/medical-device-maker-medtronic-says-its-been-hacked-a-31518
18 days ago
0
1
0
Crypto-targeting North Koreans wield fake Zoom and Teams meetings, populated by video of real industry figures, captured in previous attacks and used to lure future victims
www.databreachtoday.com/crypto-targe...
loading . . .
https://www.databreachtoday.com/crypto-targeting-north-koreans-wield-fake-zoom-meetings-a-31516
18 days ago
0
0
0
Home security firm ADT breach: 5.5M customers' data exposed, as prolific ShinyHunters extortion group issues 'pay or leak' threat to victim
www.databreachtoday.com/home-securit...
loading . . .
https://www.databreachtoday.com/home-security-firm-adt-breach-55m-customers-data-exposed-a-31511
18 days ago
0
0
0
Soldier won $410K in Polymarket bets on timing of Maduro capture, US alleges
arstechnica.com/tech-policy/...
loading . . .
Soldier won $410K in Polymarket bets on timing of Maduro capture, US alleges
It's like "Pete Rose betting on his own team," Trump says of arrested soldier.
https://arstechnica.com/tech-policy/2026/04/soldier-won-410k-in-polymarket-bets-on-timing-of-maduro-capture-us-alleges/
19 days ago
0
0
0
Weekly Cryptohack Roundup —Grinex halts trading after $15m crypto hack —KelpDAO hacker launders $80M ETH via cross-chain swaps —Circle sued over delayed response to $280m Drift hack —Armed robbers invade home of French family —$3.5m Volo Protocol exploit
www.databreachtoday.com/cryptohack-r...
22 days ago
0
0
0
The Trump administration will have to look again to find someone to permanently lead the U.S. Cybersecurity and Infrastructure Security Agency now that nominee Sean Plankey withdrew from consideration after a year of no action taken by the Senate.
www.databreachtoday.com/trumps-top-c...
loading . . .
Trump's Top Cyber Nominee Withdraws After Turbulent Process
Sean Plankey withdrew his nomination after a 13-month stalled process, leaving the U.S. Cybersecurity and Infrastructure Security Agency without a Senate-confirmed
https://www.databreachtoday.com/trumps-top-cyber-nominee-withdraws-after-turbulent-process-a-31494
22 days ago
0
0
0
UK officials say Russian hacking has reached new levels of hostility. Nation-state hits tied to the "big 4" now comprise majority of serious incidents probed by the government, intelligence officials said at this week's CyberUK conference in Glasgow.
www.databreachtoday.com/uk-russian-h...
loading . . .
https://www.databreachtoday.com/uk-russian-hacking-reaches-new-levels-hostility-a-31483
22 days ago
0
0
0
How Iran has excelled at 'threat projection' using cyber: no one wants to test Tehran's actual ability to execute, says Yelisey Bohuslavskiy, in this deep-dive look at how cyber operations are/n't being used in the conflict. Watch our full discussion here:
www.databreachtoday.com/how-iran-has...
loading . . .
https://www.databreachtoday.com/how-iran-has-excelled-at-threat-projection-using-cyber-a-31451
25 days ago
0
0
0
Maximizing vulnerability management utility and returns from Mythos, or any other models big and small, is about the system, not the models. Think of it as an AI-driven cybersecurity pipeline, says Ondrej Vlcek, CEO of Aisle.
www.databreachtoday.com/maximizing-m...
loading . . .
https://www.databreachtoday.com/maximizing-mythos-returns-requires-ai-cybersecurity-pipeline-a-31452
25 days ago
0
0
0
Load more
feeds!
log in