Data & Analytics
Data and analytics explores pipelines, governance, privacy, databases and breaches. Articles connect technical aspects, protection requirements and the operational impact of data management.

Aeon RCE via Pickle Dataset: ML Pipeline Risk
CVE-2026-18285: The Python library Aeon executed arbitrary code through pickle deserialization of seemingly legitimate datasets. The b…

Aeon RCE Flaw in Benchmark Loading: The Risk Lies in the Datasets
Trend Micro's Zero Day Initiative published advisory ZDI-26-470 assigning CVE-2026-18287 to a code injection vulnerability in the Pyth…

NVIDIA NVTabular: RCE via Pickle, CVE-2026-24237 Rated CVSS 7.8
A deserialization flaw in NVIDIA NVTabular enables remote code execution through malicious pickle files. User interaction is required;…

EncForge: JadePuffer Hits Irrecoverable AI Models With Agentic Ransomware
The agentic threat actor JadePuffer has deployed EncForge, ransomware purpose-built for AI/ML assets. Encrypted models cannot be recov…

AssuranceAmerica: 7 Million Driver's Licenses Exposed, No Credit Monitoring Offered
A single compromised employee account opened access to nearly 7 million driver's license numbers. AssuranceAmerica is not offering cre…

Beyond IOCs: Talos Unveils Vision for LLMs in Threat Intelligence
Cisco Talos explores how large language models transcend traditional indicators of compromise by indexing strategic reports in natural…

'Snoopy' Sentenced: 18 Months for the Massive DraftKings Hack
Nathan Austad, known as 'Snoopy,' received an 18-month federal prison sentence for orchestrating the November 2022 credential-stuffing…

Infinite Campus: 137,123 Staff Emails Exposed in Salesforce Breach
ShinyHunters compromised an Infinite Campus employee's Salesforce account on March 18, 2026. After a failed extortion attempt, 137,123…

NVIDIA Transformers4Rec Flaw Enables RCE via Malicious ML Models
NVIDIA has patched a high-severity deserialization vulnerability (CVE-2026-24162, CVSS 7.8) in its Transformers4Rec library that allow…

BadBone: Dormant AI Backdoor Evades Six Major Security Defenses
BadBone research demonstrates that backdoors in pre-trained AI models remain invisible until customized, maintaining a 0.10% attack su…

Trojan Detection: 33 Behavioral Signals May Challenge Complex Machine Learning Models
A new framework utilizing 33 refined behavioral features aims to detect Windows Trojans with competitive performance on standard enter…

Vishing and AiTM Bypass MFA: Invisible Extortion in SaaS
Criminal groups like Cordial Spider use vishing and AiTM to bypass MFA and target SaaS environments. Protect your corporate data from…