Search This Blog

Powered by Blogger.

Blog Archive

Labels

Footer About

Footer About

Labels

Showing posts with label Cyber Security. Show all posts

AI Adoption Shifts Focus Toward Data Governance and Enterprise Trust

 

The rise of artificial intelligence (AI) is uncovering vulnerabilities in enterprise data governance, as organizations grapple with managing information rather than applications and users. As companies rely on AI to analyze, create, research, and make decisions using enterprise data, experts say data governance is becoming a priority. 

According to industry research, over 50% of employees are already using AI outside of corporate systems, raising concerns about shadow AI. However, experts say the bigger issue is understanding how enterprise information is being used, accessed, and processed by employees and systems. AI is fundamentally changing the value of enterprise data as it empowers organizations to analyze, summarize, and act on information instantly. Documents that previously required human analysis can now be processed by AI to extract business intelligence in seconds. 

This makes enterprise information more valuable than ever before as it becomes embedded in decision-making processes and systems. As the value of enterprise data increases, so does the need to ensure its context is appropriately maintained. Experts say that business documents, customer data, intellectual property, and presentations have value and meaning based on their intended use. 

As this information is shared internally and externally and processed by AI, policies, accountability, and governance must be attached to the data to ensure it is used as intended. Security professionals say information governance should be connected to the data itself rather than where that information is stored. They recommend that policies, procedures, and enforcement be attached to the information to ensure its proper use in an increasingly distributed and AI-driven enterprise. 

Trust is quickly becoming a critical success factor for organizations that want to maximize the value of AI while minimizing risk. Business leaders, regulators, and customers are demanding more excellent transparency, which puts pressure on enterprises to ensure sensitive information is handled responsibly. Experts say organizations that get governance right will be best positioned to adopt AI while maintaining the trust of their stakeholders. 

The next wave of AI innovation will include autonomous agents that can access and retrieve information, coordinate tasks, make recommendations, and take action across enterprise systems. These AI agents will require access to data, which means organizations must have robust information governance practices to ensure the data being processed is accurate and secure. 

As the capabilities of AI continue to evolve, enterprises are focusing on ensuring the information that fuels these systems is governed appropriately. Experts recommend organizations prioritize information governance, maintain the context of enterprise data, and leverage trusted AI to maximize the value of their data assets.

Coldcard Wallet Security Incident Linked to Multi-Million Dollar Bitcoin Theft


 

There has been a connection between a critical firmware flaw in the Coldcard hardware wallet and one of the largest cryptocurrency thefts of the year, after hackers allegedly drained nearly $70.2 million in Bitcoins (BTC) from 1,196 wallets on July 30 by exploiting a critical firmware flaw, according to Galaxy Research. 

A firmware integration error introduced in March 2021 is responsible for the vulnerability, which affects Coldcard, a Bitcoin-only hardware wallet developed by Canadian company Coinkite. According to security researchers, affected firmware versions generated wallet recovery seeds using deterministic software-based pseudorandom number generators (PRNGs) rather than the hardware random number generators (RNGs) of the devices. In this way, the amount of randomness necessary to create cryptographic seeds has been significantly reduced. 

Block researchers explained that, under certain circumstances, an attacker could reproduce seed values offline under sufficient knowledge of the device's unique identification number and internal state. Attackers can then identify and steal funds from vulnerable wallets by matching those candidate seeds against publicly available blockchain addresses. 

It was found that the flaw occurred as a result of a production configuration error resulting in affected Coldcard devices relying on MicroPython's Yasmarang pseudorandom number generator instead of the hardware random number generator intended for them. 

During initialization of the fallback algorithm, unique identifiers and timer values of the device were used without the collection of fresh entropy, leading to significantly more predictable recovery seeds. Contrary to conventional cryptocurrency attacks directed towards exchanges, smart contracts, and online wallets, this incident involved hardware wallets designed to remain offline. 

According to security experts, the compromise did not require the device to be connected directly to the internet. As an alternative, attackers are alleged to have generated a large number of possible recovery seeds offline, derived the addresses of the corresponding wallets, and compared them with blockchain records available on the Internet until they found matching wallets containing Bitcoins. 

As determined by investigators, the attacker generated candidate recovery seeds using hardware configured under similar conditions, then deduced the Bitcoin address corresponding to each seed. The address of a blockchain is publicly visible, and matching the address of a recreated seed to the address of an active wallet would allow the attacker to retrieve the private keys and transfer funds without physically accessing the victim's device. 

A firmware update was released by Coinkite on July 31 for all Coldcard models that were affected. However, the company has stressed that installing the update alone will not secure wallets that have been created with vulnerable firmware. 

Users whose recovery seeds were generated on affected versions have been advised to generate new seeds utilizing the patched firmware and transfer their Bitcoin to new wallets as soon as possible. It is important to note that even when an old seed is restored on an updated firmware or another wallet, the underlying weakness remains. 

Galaxy Research has reported that the stolen funds were transferred in batches over a period of six Bitcoin blocks rather than through a single continuous transaction. Observations by researchers indicated that three interconnected blocks did not show any related activity, indicating that the transactions were deliberately grouped before being broadcast. 

Coldcard versions 4.0.1 to 4.1.9, Mk4 and Mk5 versions before 5.6.0, Q versions before 1.5.0Q, and Edge builds released prior to the latest patches are affected by this firmware. The vulnerability has been estimated by Coinkite to reduce the effective entropy of wallet recovery seeds by approximately 40 bits for Mk3 devices and around 72 bits for Mk4, Mk5 and Q devices. This results in significantly lower levels of security than a standard 12-word BIP-39 seed's 128-bit encryption. 

Researchers noted that practical challenges in recovering a seed are still influenced by factors such as device characteristics, boot timing and computational resources. It was noted by Coinkite that wallets generated with at least 50 fair and private dice rolls do not suffer from this vulnerability. Despite the fact that a strong passphrase provided additional security, users should nonetheless replace vulnerable seeds with stronger BIP-39 passphrases. 

Multisignature wallets will not be compromised if all signing devices are not affected by the same issue. There has been no public identification of the attacker. According to Galaxy Research, the observed on-chain transaction patterns indicate a coordinated wallet sweep, but do not conclusively indicate theft. Researchers also observed that blockchain activity followed a distinctive transaction pattern, though they cautioned that on-chain analysis alone cannot conclusively prove theft. 

The pattern instead pointing to coordinated wallet sweeps consistent with a single operator or related group of operators, which has raised concerns over the importance of secure random number generation in cryptocurrency wallets. In order to store cryptocurrency offline securely, hardware devices that remain disconnected from the internet must maintain strong cryptographic entropy during wallet creation, and any weakness in that process can compromise its security. 

After Coinspect released the "Ill Bloom" vulnerability in just weeks past, another weak random number generation vulnerability has led to more than $5 million worth of cryptocurrency theft across Bitcoin, Ethereum, Tron, Rootstock and Polygon, with the "Ill Bloom" vulnerability being linked to more than $5 million in cryptocurrency thefts. Even wallets designed with strong offline security can be compromised by vulnerabilities in cryptographic randomness. 

A subsequent update from Galaxy Research identified two more suspected Coldcard-related wallet sweeps, which increased the estimated losses to 1,367.05 Bitcoins, worth approximately $88.6 million across 4,585 addresses, for a total of 1,367.05 Bitcoins. In addition to sharing details with federal investigators, compliance organizations and cybersecurity teams about nearly 600 suspected attacker-controlled addresses, the firm said the activity is ongoing.

Hackers Compromise Organization to Swap Crypto Wallet Address In A Supply Chain Attack


Threat actors exploited a JavaScript file offered by advertising technology firm Adform, and modified it into a browser-side tool that rewrites crypto wallet addresses.

Malicious script

Adform found the incident and removed the malicious code, informed the impacted clients, and notified the authorities.

For users who visited a website carrying the modified script on July 27 and copied Ethereum, Tron, or Bitcoin may have deployed malicious code by pasting the a different address.

What should the users do?

Adform has advised users to clean their browser cache as the modified file may stay cached after the fix, and to also double-check any wallet address before sending any money.

According to Adform, the code was not built to deploy software or create persistence and worked only when an affected page stayed open. Clipboard copying was not the only method of replacement; the captured sample also rewrites addresses entered straight into form fields. 

According to Adform’s implementation document, the tracking code can run across a website, several sections, or even a single page. Exploiting the shared resource allowed the hackers a path into downstream websites without having to hack each one of them. Supply chain compromise happened due to the shared deployment path. 

Shared path leading to supply chain attack

One modified address at the point of payment could change a transfer, as the impacted page stayed open.

Security expert Beaumont discovered the hack and said, "Even if you notice the address is wrong and recopy the wallet, it keeps replacing it.”

Beaumont also said that “this allows end user devices of downstream websites to be compromised with crypto stealing malware. Meaning if you visit example.com and they use Adform, example.com will compromise your device.” The file and linked domains, IP addresses, and URLs showed no detections on VirusTotal at the time. 

The discovered sample consists of two malicious blocks attached to the authentic library. Their replacement strings are hidden with a six-byte XOR key. The first looks out for the copy event, attempts to read the clipboard every four seconds, and to replace matching addresses.

The second block rewrites values in textarea, contenteditable elements, and input, and restores the cursor point after a rewrite.

“Based on our investigation to date, we have found no evidence that the malicious code transmitted users’ IP addresses or information about the websites they visited to an external party. Technical analysis indicates that such transmission may have been possible, and this aspect remains under investigation,” says Adform.

Flock Cameras Blanket Southwest Florida, Sparking Privacy and Safety Backlash

 

Flock Safety's automated license plate reader (ALPR) cameras are spreading rapidly across Southwest Florida, with hundreds now installed at intersections, parking lots, and private communities. These solar-powered devices, mounted on poles along roads, capture detailed vehicle data—including license plates, make, model, color, and unique features like bumper stickers or dents—every time a car passes. The information is instantly uploaded to a shared law enforcement database, enabling police to search and track vehicles without warrants, raising serious privacy concerns among residents and civil liberties advocates.

The network's growth in Southwest Florida reflects a national trend, with over 100,000 Flock cameras now mapped across the United States. In Cape Coral and surrounding Lee and Charlotte counties, cameras are so dense that some intersections have readers on every corner. Local agencies, including the Cape Coral Police, Sanibel Police, and county sheriffs, use Flock or access its shared data, while private gated communities and businesses also deploy cameras that feed into the same system. Florida law allows agencies to query Flock records from other jurisdictions nationwide without a warrant, amplifying the reach of this surveillance infrastructure.

Critics argue that Flock's technology enables mass surveillance, as the AI-powered cameras generate "vehicle fingerprints" and log every trip, from grocery runs to medical appointments. Privacy advocates warn that the data can be misused: police officers have been caught using Flock networks to stalk ex-partners, with hundreds of illegal license plate searches documented. Additionally, a 2025 investigation found at least 60 Flock cameras exposed to the open internet, allowing outsiders to view live footage, highlighting security vulnerabilities in the system. 

Backlash against Flock has intensified, with citizens in five states destroying cameras using sledgehammers and vice grips, while city governments in Fort Collins, Eugene, Madison, and others have canceled contracts or deactivated the devices. At the federal level, Representative Thomas Massie plans to introduce legislation blocking federal funding for Flock cameras, citing civil liberties concerns. Road safety advocates have also raised alarms, noting that Flock's 80,000 to 100,000 roadside poles may violate federal clear-zone rules, creating crash hazards beyond privacy issues. 

As Flock cameras expand into retail parking lots—Home Depot and Lowe's have deployed them nationwide—the debate over warrantless surveillance and data sharing is set to intensify. For Southwest Florida residents, the visible proliferation of these devices underscores a broader tension between law enforcement capabilities and the right to privacy in public spaces.

Indian Banks Increase Cybersecurity Investments to Counter AI-Powered Cyber Threats

 

Indian banks are ramping up cybersecurity spending as artificial intelligence-fueled cyber threats grow more sophisticated. As per the Digital Threat Report 2025-26 for the Banking, Financial Services and Insurance (BFSI) sector, six out of seven cyber threats identified by the report in the previous year have become operational, forcing banks to shore up their cyber defenses. 

“The threat landscape is evolving with bad actors using AI, impersonation, and payment process orchestration to mimic legitimate customer behavior. BFSI players are adopting advanced security technologies and countermeasures such as AI-driven fraud detection and prevention, zero-trust architecture, micro segmentation, and enhanced cyber defenses,” said the report. 

With security being increasingly prioritized as an operating imperative over technology spending, banks are also investing more in secure digital lending platforms, Unified Payment Interface (UPI) services, cloud, and AI applications. 

PNB, for instance, has set aside about 20% of its FY27 technology budget or ₹7-8 billion for cybersecurity. This is more than double the spending made in the previous fiscal. “We can always increase our cybersecurity budget if the need arises,” said the bank. The Reserve Bank of India (RBI) has also been focusing on cybersecurity and AI governance. 

In the recent past, the central bank has been interacting with banks on AI, geopolitical issues, and ECL (expected credit loss) implementation. Additionally, RBI has also shared a draft framework on AI governance for regulated entities. “The BFSI cybersecurity market size is estimated to grow at a double-digit CAGR through 2030 as banks and financial institutions continue to focus on operational resilience, address technology-related third-party risks, respond to tightening regulatory compliance needs, and mitigate the talent shortage in specialized cybersecurity roles,” said the report. 

While BFSI players are witnessing a dip in capital expenditures (capex) on physical infrastructure, technology budgets are being allocated to cyber monitoring, identity management, fraud management systems, cloud security, and regular vulnerability assessments. “The Financial Stability Report (FSR) 2025 has identified AI-enabled cyber threats as one of the critical emerging risks to the financial stability of the Indian economy. 

Even as India’s banking system remains resilient with stress tests showing that gross NPAs will remain below 2% through 2028 in the baseline scenario, the focus on cybersecurity, particularly AI-driven financial crime prevention, is gaining momentum,” said the report. “With AI-driven financial crime prevention becoming a strategic imperative, cybersecurity is set to be one of the largest technology expenditures for banks. 

The question now is not whether banks will increase cybersecurity spending but how quickly they can build resilient and AI-ready digital ecosystems to secure their digital banking ecosystems,” added the report.

Fitness Trackers Can Expose Your Health Data, EFF Warns

 

Fitness trackers have become part of everyday life, helping people monitor steps, sleep, heart rate, stress, and workouts with impressive convenience. But a recent investigation highlighted a serious privacy issue: much of the health data collected by popular wearables is not protected under federal health privacy law, which means it can be exposed through legal requests far more easily than many users realize. 

Among the major brands reviewed, Apple stands out because its health data can be protected with end-to-end encryption, giving users a stronger layer of control over sensitive information. The core concern is that most wearable devices rely on cloud storage, where the company that makes the device often holds the keys to the data. That setup may feel secure because the information is encrypted while being transferred and stored, but it is not the same as true end-to-end encryption. If the company can access the data, then law enforcement may also be able to obtain it through a subpoena. 

For users, that means intimate details such as sleep patterns, location history, menstrual cycles, and heart-rate trends may be accessible outside the privacy protections many people assume apply.  This issue matters because wearable health data is highly revealing. A fitness tracker can create a detailed picture of daily routines, physical condition, and even emotional stress patterns. In legal disputes, such records have already been used to challenge alibis, verify movements, and support claims in civil cases. 

As wearable adoption continues to grow, the volume of personal information collected will only increase, making privacy protections more important than ever. Many consumers buy these products for wellness, but they may not realize they are also generating a persistent data trail. Apple’s approach is different because its Health ecosystem supports end-to-end encryption when properly configured. 

That means the company cannot read the protected health data, and a subpoena would not produce the same level of information that cloud-based systems can reveal. Apple also allows users to limit syncing and keep more data local, which adds another privacy advantage. For users who want the strongest protection, this makes Apple Watch and Apple Health a standout option compared with most other wearable brands. 

Before buying a fitness tracker, consumers should look beyond features like battery life, workout tracking, and smartwatch functions. Privacy policies, transparency reports, local storage options, and encryption standards should matter just as much as design and price. In an era where health data is constantly collected, the best wearable is not only the one that tracks well, but the one that protects personal information responsibly.

Location Sharing: Convenience at the Cost of Safety

 

Location sharing has become a routine feature in messaging, navigation, and social apps, yet it carries security and privacy risks that many users underestimate. While convenient for coordinating meetups or ensuring family safety, careless configuration can expose sensitive patterns about your daily life to strangers, advertisers, and even attackers who compromise the platforms you trust. 

The most immediate danger is physical safety. Continuous location sharing reveals where you live, work, study, and spend leisure time, effectively mapping your routine for anyone with access. Stalkers, harassers, or opportunistic criminals can exploit this data to time thefts, orchestrate impersonation scams, or physically follow you. Real-time updates on platforms like Snapchat’s Snap Maps make it trivial to see when you are home or away, turning a social feature into a surveillance tool if permissions are too broad. 

Beyond individual bad actors, the apps themselves and their data ecosystems present another layer of risk. Many services collect and retain location histories, which can be sold to data brokers, advertisers, or accessed by third parties through data breaches. Incidents like the Gravy Analytics hack show how aggregated location data can leak at scale, exposing users who never intended their movements to be public. Even when companies claim strong security, breaches and insider misuse remain persistent threats in today’s threat landscape. 

Location data also fuels more sophisticated cyberattacks through social engineering and targeted fraud. Attackers can correlate your whereabouts with spending habits, social posts, and device usage to craft convincing phishing messages, fake support calls, or credential-reset scams. For example, seeing that you just visited a shopping mall or a specific campus building can help criminals personalize spam about credit-card fraud or IT alerts, increasing the chance you click a malicious link. Geotagged photos and live stories further amplify this risk by publicly broadcasting your precise coordinates. 

Mitigating these risks requires deliberate permission management and a mindset Of location sharing has become a routine feature in messaging, navigation, and social apps, yet it carries security and privacy risks that many users underestimate. While convenient for coordinating meetups or ensuring family safety, careless configuration can expose sensitive patterns about your daily life to strangers, advertisers, and even attackers who compromise the platforms you trust.

Vatican ‘Click to Pray’ App Security Flaw Exposed Data of 700,000 Users


Approximately 700,000 personal data of Vatican users were reportedly exposed due to a critical security vulnerability in Click to Pray, causing concerns about data privacy and phishing. An independent security researcher BobDaHacker discovered in January 2026 that the backend API lacked basic authentication and access controls, leading to the discovery of the flaw. 

Researchers indicate that anyone could retrieve user information by simply altering sequential user ID numbers in API requests, thereby making sensitive data publicly accessible without authorization. It has been identified as an Insecure Direct Object Reference (IDOR) flaw, a type of access control weakness that can allow unauthorized users to manipulate object identifiers in order to gain access to restricted data. 

Using the exposed API endpoint, the researcher reported that no authentication was required, thus anybody with knowledge of the endpoint could access user records directly through a web browser, without requiring advanced technical knowledge. The information exposed was reported to include first and last names, email addresses, dates of birth, preferred language, and account information. However, cybersecurity experts caution that, even though financial information was not disclosed, email addresses combined with personal information can significantly increase the risk of targeted phishing scams and social engineering attacks. 

Additionally, the exposed records revealed the country of origin of each user, his account status, and the level of privileges he or she possessed, including whether the account belongs to an administrator or a regular user. Research findings identified that the platform's staff accounts were among the lowest-numbered user IDs, which made internal accounts accessible via the same vulnerable API. Other security flaws were also identified by the researcher. 

By assigning sequential user IDs to newly created accounts, automated requests were able to access the entire user database. Additionally, the API did not contain rate limits, which allowed attackers to collect a large number of user records without restrictions. Additionally, the validation hash used to verify emails was stored in plain text, thus providing another potential attack vector. 

Further, the researchers indicated that the vulnerable endpoint could be exploited without specialized tools, since user IDs were assigned sequentially. This allowed attackers to automate requests to enumerate the database and gather user information at a large scale. Due to the absence of authorization checks, the vulnerability represents a fundamental failure in access control rather than a sophisticated attack. 

In accordance with the disclosure, the researcher attempted to inform multiple contacts related to the application of the vulnerabilities immediately after discovery. However, despite several requests for responses, the issues were not resolved for nearly six months. Security journalist Nate Nelson of Dark Reading also contacted the developers, but did not receive a response. 

The vulnerability was independently tested prior to publication by cybersecurity publication Dark Reading. As stated in the publication, the Pope's Worldwide Prayer Network, which operates the platform, as well as La Machi Communication for Good Causes, the agency responsible for developing the application, were also contacted, but no response was received before the issue became public. 

According to the researcher, the vulnerabilities were addressed only after they were made public through media coverage. Although the researcher followed responsible disclosure practices, no formal acknowledgement was provided for the vulnerabilities. There are reportedly nearly 720,000 registered accounts on Click to Pray by July 2026, making the exposure significant despite the app's niche target audience. 

According to researchers, many faith-based application users might not be aware of cybersecurity threats, thus making them attractive targets for online scams and phishing attacks. As a result of this incident, fundamental API security measures such as authentication, authorization, rate limiting, and safe handling of sensitive information need to be implemented. Furthermore, the incident emphasizes the importance of maintaining effective vulnerability disclosure programs and responding promptly when security researchers uncover security flaws. 

Security experts point out that the incident highlights one of the most common vulnerabilities in application security. There is no doubt that broken access control is one of the most critical risks in OWASP's Top 10. Issues with IDOR vulnerabilities persist across organizations of all sizes when developers implement authentication procedures without properly enforcing authorization procedures. 

Organizations collecting personal information, including commercial businesses, nonprofit organizations, and religious institutions, should implement robust security controls and maintain effective vulnerability disclosure processes as a result of this incident. Keeping user information secure is an integral part of every organization that has been given personal information.

Click to Pray illustrates that no organization is exempt from cybersecurity risks. Using strong access controls, secure API practices, and responding to vulnerabilities promptly remain essential for protecting user data and maintaining public trust in digital platforms.