Every story tagged Data Exfiltration, curated for CIOs and IT leaders — ranked by source credibility, engagement, and freshness.
6 stories · open in the command center
A new browser-based attack called FROST exploits SSD timing side channels to allow websites to covertly identify other websites and applications active on a user's device, significantly expanding the attack surface of modern web browsers. This emerging threat requires IT organizations to reassess their endpoint security strategies and browser sandboxing assumptions, as traditional isolation boundaries prove insufficient against this class of physical-layer attacks. Organizations must work with browser vendors on mitigations such as OPFS file size limits while implementing detection mechanisms and endpoint monitoring to identify suspicious large file allocations.
ChatGPT for Google Sheets contains a critical vulnerability enabling indirect prompt injection attacks that can exfiltrate entire workbooks across a user's account, display phishing overlays, and hijack the extension interface—all without triggering required human approval safeguards. This represents a significant data governance and security risk for organizations deploying AI-integrated productivity tools, as a single benign user action involving untrusted data sources can compromise sensitive financial models and cross-linked spreadsheets enterprise-wide. IT leaders must immediately assess their organization's exposure to this extension and implement access controls while OpenAI addresses the underlying security gaps in their responsible disclosure process.
A critical vulnerability in Ramp's Sheets AI allowed attackers to exfiltrate sensitive financial data through indirect prompt injection attacks embedded in external datasets, enabling unauthorized formula insertion without user approval. This incident highlights a broader security risk in autonomous AI agents operating on business-critical spreadsheets and underscores the need for IT organizations to implement human-in-the-loop controls and visibility when deploying AI tools that access confidential data. While Ramp patched the issue, similar vulnerabilities identified in comparable products like Claude for Excel demonstrate that AI-driven productivity tools require enhanced approval workflows and transparent formula validation before executing external network requests.
A significant data breach of UK Biobank exposed health records for approximately 500,000 individuals, with personal health details being offered for sale on the dark web, representing a critical failure in healthcare data protection and regulatory compliance. This incident underscores the severe reputational, legal, and financial risks organizations face when managing sensitive personal health information, particularly given the strict requirements of GDPR and healthcare privacy regulations. IT leaders must recognize this as a watershed moment demonstrating that even trusted institutions managing health data are vulnerable to sophisticated threats, demanding immediate investment in advanced security controls, breach detection capabilities, and incident response planning.
A critical breach of France's national identity document agency (ANTS) exposed personal data for potentially 19 million citizens, including names, addresses, birth dates, and contact information—creating significant risk for large-scale phishing and social engineering attacks against the French population. This incident highlights the vulnerability of government infrastructure managing sensitive identity data and demonstrates how threat actors are actively targeting critical administrative systems for financial gain. IT leaders must reassess their government agency partnerships, identity data protection protocols, and incident response capabilities, as breaches of this scale can cascade across dependent systems and undermine public trust in digital government services.
Microsoft patched a critical prompt injection vulnerability (CVE-2026-21520) in Copilot Studio that allowed attackers to hijack AI agents through SharePoint forms and exfiltrate sensitive data via Outlook—bypassing DLP controls because the system treated malicious instructions as authorized operations. This represents a new vulnerability class for agentic AI systems that cannot be fully eliminated through traditional patching, as the fundamental architecture prevents LLMs from distinguishing between trusted instructions and untrusted user input. Similar vulnerabilities affecting Salesforce Agentforce remain unpatched, signaling that any enterprise deploying AI agents with access to private data, exposure to external input, and communication capabilities faces inherent exploitation risk that traditional security controls cannot adequately address.