Publications & Analyses
Argus Flow releases, platform announcements, press updates, and cybersecurity analyses.
AssuranceAmerica Breach Exposes 7 Million Driver's Licenses
U.S. insurer AssuranceAmerica confirmed that a hack of an employee account led to the theft of driver's license data for nearly 7 million customers. Details of the March attack and the company's response are inside.
Estée Lauder Discloses Data Breach From Oracle Flaw
Cosmetics giant Estée Lauder has announced a data breach resulting from the exploitation of a vulnerability in its Oracle E-Business Suite system, used for HR operations. The attack is linked to a method previously used by the Clop ransomware group.
Lidl Data Breach Affects Customers in Three Countries
Lidl has notified its online shop customers in Germany, Belgium, and the Netherlands about a cyberattack on a business partner that exposed their personal data. Financial information is reported to be safe.
JadePuffer The First Fully LLM Driven Ransomware Attack
The cybersecurity world was shaken by the first ransomware attack reportedly conducted by AI agents, dubbed 'JadePuffer'. Attackers exploited a Langflow flaw to steal data from a production database and encrypt other systems.
Ernst & Young Discloses Breach via Third-Party System
Auditing and consulting giant Ernst & Young has announced a data breach resulting from a cyberattack on a third-party support system. The breach reportedly exposed documents containing client tax information.
Hugging Face Reveals Its Network Was Breached by an Autonomous AI Agent
Hugging Face, the giant platform in the AI and machine learning space, has announced a first-of-its-kind security breach: it was hacked by an autonomous AI agent. The attackers used this method to infiltrate the company's production infrastructure, gaining access to internal datasets and credentials.
Nissan Employee Data Breached in Oracle PeopleSoft Hack
Automotive giant Nissan has confirmed that sensitive data of its current and former employees was breached in a cyberattack targeting a zero-day vulnerability in Oracle PeopleSoft software. The ShinyHunters group is believed to be behind the attack.
Aflac Japan Data Breach Impacts 4.38 Million Individuals
The Japanese subsidiary of insurance giant Aflac confirmed that cyberattackers accessed its systems for 10 days, stealing the personal and financial data of 4.38 million customers and agents.
Insurance Giant Aflac Discloses Data Breach via Subsidiary
US insurance giant Aflac has announced a data breach involving personal and bank information after its Japanese subsidiary's systems were compromised. The attack did not affect the company's US operations.
NAIC States Data Breach Involves Public Data, Disputes Hackers' Claims
The U.S. National Association of Insurance Commissioners (NAIC) confirmed a breach by the ShinyHunters group via an Oracle PeopleSoft zero-day. NAIC claims only public data was stolen, while the hackers assert they leaked 3.1 TB of critical data.
US Insurance Regulator Confirms Data Breach
The US National Association of Insurance Commissioners (NAIC), a non-profit regulatory body, has disclosed a data breach resulting from a cyberattack exploiting a zero-day vulnerability in Oracle PeopleSoft. Credit rating data of US citizens was compromised in the attack.
KDDI Data Breach Hits 14 Million Email Accounts Across 6 ISPs
Japanese telecom giant KDDI announced that up to 14.2 million email accounts at six internet service providers have been exposed due to a vulnerability in third-party software. There are concerns that attackers may have obtained email addresses and encrypted passwords.