#exfiltration

2025-12-08

Oof. With my legal background, this one hits close to home! 😬

The ICO fined a law firm after data breach and subsequent leak to dark web. Identities of protected victims and witnesses were exposed. All attackers gained access to an old, supposedly archived case management system. (Why was this online?)

lawsociety.org.uk/topics/ethic

Given the size of the fine (£60k), I would guess this was not a large law firm. Some of the affected individuals may sue, so that's probably not the end of the matter.

#databreach #law #lawfirm #ico #darkweb #exfiltration

Patryk Krawaczyńskiagresor@infosec.exchange
2025-12-07
2025-11-18

You know you're doomed when your operating system vendor is selling their "#AI" fetish to you with a text like this.

»Agentic AI has powerful capabilities today—for example, it can complete many complex tasks in response to user prompts, transforming how users interact with their PCs. As these capabilities are introduced, AI models still face functional limitations in terms of how they behave and occasionally may #hallucinate and produce unexpected outputs. Additionally, agentic AI applications introduce novel #security #risks, such as cross-prompt injection (XPIA), where malicious content embedded in UI elements or documents can override agent instructions, leading to unintended actions like data #exfiltration or #malware installation.«

support.microsoft.com/en-us/wi

Client Info

Server: https://mastodon.social
Version: 2025.07
Repository: https://github.com/cyevgeniy/lmst