โŒ

Normal view

There are new articles available, click to refresh the page.
Before yesterdayMain stream

California hospitals can escape fines if workers expose patient info

By: Dissent
7 October 2025 at 12:18
Scott Holland reports that a California state appeals court agreed with a hospital that it should not be held liable for employee misbehavior if they had a clear policy in place but the employee knowingly violated it: A state appeals panel has agreed hospitals canโ€™t be sued if one of their employees posts confidential patient...

Source

Harris Health discloses insider-wrongdoing breach that went on for a decade

By: Dissent
7 October 2025 at 07:56
Here is todayโ€™s reminder of the insider threat and why it may be challenging, but itโ€™s still necessary, to monitor and audit employee access to patient records to spot any inappropriate access. Harris Health is notifying more than 5,000 patients that an employee โ€” who was fired and referred to law enforcement when their wrongdoing...

Source

Latvian health authority official and IT company head fined for data breach

By: Dissent
17 September 2025 at 07:35
From Latvian Public Media: The Kurzeme Regional Court has decided to overturn the acquittal of the District Court and to find guilty an official of a state institution for disclosing confidential information and a board member of a company for inciting a public official to disclose this information, Latvian Television reports on 17 September. Latvian...

Source

Former Defense Contractor Sentenced to Over 10 Years in Prison for Attempted Espionage

By: Dissent
15 September 2025 at 20:38
From the U.S. Department of Justice: John Murray Rowe Jr., 67, of Lead, South Dakota, was sentenced today to 126 months in prison followed by three years of supervised release and a $25,000 fine for attempted espionage. The defendant was charged by indictment in December 2021 andย pleaded guiltyย in April of last year to one count...

Source

Department of State employee sentenced for transmitting national defense information to suspected Chinese government agents

By: Dissent
4 September 2025 at 20:06
Todayโ€™s reminder of the insider threat, from the U.S. Attorneyโ€™s Office for the Eastern District of Virginia: ALEXANDRIA, Va. โ€“ A U.S. Department of State (DOS) employee was sentenced today to four years in prison for conspiring to collect and transmit national defense information to individuals he knew to be working for the government of...

Source

Bail for 2 Hong Kong doctors accused of leaking data to implicate surgeon

By: Dissent
2 September 2025 at 07:05
Oscar Liu reports: Two public hospital doctors have been granted bail after being arrested in Hong Kong on suspicion of leaking a cancer patientโ€™s medical data to highlight alleged professional shortcomings by her operating surgeon. Observers, meanwhile, said that although the incident did not align with the principles of โ€œwhistle-blowingโ€, it underscored the need for...

Source

3rd Circuit Clarifies Scope of Computer Fraud Abuse Act With Employerโ€™s Policies

By: Dissent
29 August 2025 at 07:12
Riley Brennan reports: The U.S. Court of Appeals for the Third Circuit clarified this week that an employeeโ€™s purported violations of workplace computer use policies cannot be criminalized under federal law as long as there is no evidence of hacking or violations of trade secrets. Onย Tuesday, the federal appellate court affirmed the U.S. District Court...

Source

Developer jailed for taking down employerโ€™s network with kill switch malware

By: Dissent
22 August 2025 at 07:38
Iain Thomson reports an update to a case previously reported on this site: A US court sentenced a former developer at power management biz Eaton to four years in prison after he installed malware on the companyโ€™s servers. Davis Lu, 55, spent a dozen years at Eaton and rose to become a senior developer of...

Source

18 Arrested as Gurugram Call Centre Data Leak Fuels Massive SBI Credit Card Scam

By: Dissent
17 August 2025 at 06:56
The420.in reports: The Delhi Police have arrested 18 individuals for duping State Bank of India (SBI) credit card holders of nearly โ‚น2.6 crore [USD $296,630.45] in a nationwide fraud. The operation, which ran for six months, relied on insider leaks at a Gurugram-based call centre and a sophisticated money-laundering network that spanned cash deals and...

Source

Government papers found in an Alaskan hotel reveal new details of Trump-Putin summit

By: Dissent
16 August 2025 at 16:01
For the โ€œNo need to hack when itโ€™s leakingโ€ and the โ€œour government is our insider threatโ€ files, Chiara Eisner of NPR reports: Papers with U.S. State Department markings, found Friday morning in the business center of an Alaskan hotel, revealed previously undisclosed and potentially sensitive details about the Aug. 15 meetings between President Donald...

Source

UK: HMRC sacks dozens of staff for snooping on taxpayers

By: Dissent
16 August 2025 at 06:19
Neil Shaw reports: HM Revenue and Customs (HMRC) has revealed that hundreds of staff have accessed the records of taxpayers without permission or breached security in other ways. HMRC dismissed 50 members of staff last year for accessing or risking the exposure of taxpayersโ€™ records, according toย The Telegraph. 354 tax employees have been disciplined for...

Source

Two Defendants Plead Guilty To Fraud Scheme Involving Data Stolen From Hospital Patients

By: Dissent
14 August 2025 at 15:05
The following is part of a press release related to a case previously reported on DataBreaches.net in 2020. On August 7, 2025, WILKINS ESTRELLA and CHARLENE MARTE pled guilty before U.S. District Judge Gregory H. Woods in New York to conspiracy to commit wire fraud and bank fraud in connection with using social security numbers...

Source

North Korean Kimsuky Hackers Suffer Data Breach as Insiders Leak Information Online

By: Dissent
12 August 2025 at 06:50
Sometimes we like insider leaks, right? Divya reports: A member of North Koreaโ€™s notorious Kimsuky espionage group has experienced a significant data breach after insiders leaked hundreds of gigabytes of internal files and tools to the public. The breach, which emerged in early June 2025, exposed the groupโ€™s sophisticated backdoors, phishing frameworks, and reconnaissance operations,...

Source

DOGE Denizen Marko Elez Leaked API Key for xAI

14 July 2025 at 21:23

Marko Elez, a 25-year-old employee at Elon Muskโ€™s Department of Government Efficiency (DOGE), has been granted access to sensitive databases at the U.S. Social Security Administration, the Treasury and Justice departments, and the Department of Homeland Security. So it should fill all Americans with a deep sense of confidence to learn that Mr. Elez over the weekend inadvertently published a private key that allowed anyone to interact directly with more than four dozen large language models (LLMs) developed by Muskโ€™s artificial intelligence company xAI.

Image: Shutterstock, @sdx15.

On July 13, Mr. Elez committed a code script to GitHub called โ€œagent.pyโ€ that included a private application programming interface (API) key for xAI. The inclusion of the private key was first flagged by GitGuardian, a company that specializes in detecting and remediating exposed secrets in public and proprietary environments. GitGuardianโ€™s systems constantly scan GitHub and other code repositories for exposed API keys, and fire off automated alerts to affected users.

Philippe Caturegli, โ€œchief hacking officerโ€ at the security consultancy Seralys,ย said the exposed API key allowed access to at least 52 different LLMs used by xAI. The most recent LLM in the list was called โ€œgrok-4-0709โ€ and was created on July 9, 2025.

Grok, the generative AI chatbot developed by xAI and integrated into Twitter/X, relies on these and other LLMs (a query to Grok before publication shows Grok currently uses Grok-3, which was launched in Feburary 2025). Earlier today, xAI announced that the Department of Defense will begin using Grok as part of a contract worth up to $200 million. The contract award came less than a week after Grok began spewing antisemitic rants and invoking Adolf Hitler.

Mr. Elez did not respond to a request for comment. The code repository containing the private xAI key was removed shortly after Caturegli notified Elez via email. However, Caturegli said the exposed API key still works and has not yet been revoked.

โ€œIf a developer canโ€™t keep an API key private, it raises questions about how theyโ€™re handling far more sensitive government information behind closed doors,โ€ Caturegli told KrebsOnSecurity.

Prior to joining DOGE, Marko Elez worked for a number of Muskโ€™s companies. His DOGE career began at the Department of the Treasury, and a legal battle over DOGEโ€™s access to Treasury databases showed Elez was sending unencrypted personal information in violation of the agencyโ€™s policies.

While still at Treasury, Elez resigned after The Wall Street Journal linked him to social media posts that advocated racism and eugenics. When Vice President J.D. Vance lobbied for Elez to be rehired, President Trump agreed and Musk reinstated him.

Since his re-hiring as a DOGE employee, Elez has been granted access to databases at one federal agency after another. TechCrunch reported in February 2025 that he was working at the Social Security Administration. In March, Business Insider found Elez was part of a DOGE detachment assigned to the Department of Labor.

Marko Elez, in a photo from a social media profile.

In April, The New York Times reported that Elez held positions at the U.S. Customs and Border Protection and the Immigration and Customs Enforcement (ICE) bureaus, as well as the Department of Homeland Security. The Washington Post later reported that Elez, while serving as a DOGE advisor at the Department of Justice, had gained access to the Executive Office for Immigration Reviewโ€™s Courts and Appeals System (EACS).

Elez is not the first DOGE worker to publish internal API keys for xAI: In May, KrebsOnSecurity detailed how another DOGE employee leaked a private xAI key on GitHub for two months, exposing LLMs that were custom made for working with internal data from Muskโ€™s companies, including SpaceX, Tesla and Twitter/X.

Caturegli said itโ€™s difficult to trust someone with access to confidential government systems when they canโ€™t even manage the basics of operational security.

โ€œOne leak is a mistake,โ€ he said. โ€œBut when the same type of sensitive key gets exposed again and again, itโ€™s not just bad luck, itโ€™s a sign of deeper negligence and a broken security culture.โ€

Advanced Msfvenom Payload Generation

By: BHIS
10 May 2016 at 10:07

Joff Thyer // It has been known for some time that an executable payload generated with msfvenom can leverage an alternative template EXE file, and be encoded to better evade [โ€ฆ]

The post Advanced Msfvenom Payload Generation appeared first on Black Hills Information Security, Inc..

โŒ
โŒ