Data & Analytics
Data and analytics explores pipelines, governance, privacy, databases and breaches. Articles connect technical aspects, protection requirements and the operational impact of data management.

Dark Web: 153 Million Driver's Licenses for Sale, FBI Investigates IDScan.net
The Nexus dark web platform claims 153 million U.S. and Canadian driver's licenses. KrebsOnSecurity empirically verified records and t…

CareCloud Breach Exposes 3.75 Million Patient Records: The B2B Model Hides the Victims
CareCloud confirmed in March that an unauthorized actor accessed an AWS environment for six days, compromising 3,756,469 individuals.…

LLM Safety Rests on 50 Neurons: How Unit 42 Shatters the Myth of Distributed Alignment
Unit 42 research shows that safety mechanisms in large language models reside in less than 0.02% of neurons. The perturbation probing…

NVIDIA Transformers4Rec: RCE with CVSS 4.3 — The Risk Scoring Gap
A deserialization flaw in NVIDIA Transformers4Rec enables remote code execution, yet the official CVE record rates it 4.3 MEDIUM with…

DecryptAds Exposes the Invisible: The Ad Supply Chain Under the Microscope
DecryptAds parses ads.txt and sellers.json files, revealing hidden links between mainstream sites, data brokers, and geopolitical acto…

NVIDIA Transformers4Rec Exposed to RCE: ML Checkpoint Turns Weapon
A deserialization flaw in NVIDIA's ML library enables remote code execution via malicious checkpoints. A documented discrepancy betwee…

Metabase Under Zero-Day Attack: Critical SQL Injection with CVSS 10.0 Exposes Entire Data Layers
The Metabase BI platform is under active zero-day exploitation via a critical SQL injection. The risk extends beyond Metabase itself t…

aeon: RCE via eval() in Python Dataset Loading, Patch Released
ZDI-26-469 discloses a code injection vulnerability in the Python aeon library. The use of eval() during dataset loading allows arbitr…

Aeon RCE via Pickle Dataset: ML Pipeline Risk
CVE-2026-18285: The Python library Aeon executed arbitrary code through pickle deserialization of seemingly legitimate datasets. The b…

Aeon RCE Flaw in Benchmark Loading: The Risk Lies in the Datasets
Trend Micro's Zero Day Initiative published advisory ZDI-26-470 assigning CVE-2026-18287 to a code injection vulnerability in the Pyth…

NVIDIA NVTabular: RCE via Pickle, CVE-2026-24237 Rated CVSS 7.8
A deserialization flaw in NVIDIA NVTabular enables remote code execution through malicious pickle files. User interaction is required;…

EncForge: JadePuffer Hits Irrecoverable AI Models With Agentic Ransomware
The agentic threat actor JadePuffer has deployed EncForge, ransomware purpose-built for AI/ML assets. Encrypted models cannot be recov…