⚠️ Malware / Trojaner / VirenLumma Stealer – dllhost.exe Hollowing, C2 Domains & Payload Extraction(01.09.2026 um 17:19 Uhr)
🔧 AI Nachrichten Simcha Kosman AMA: Owning ChatGPT's Secure Sandbox(03.09.2026 um 07:41 Uhr)
⚠️ Malware / Trojaner / VirenThe Gentlemen Ransomware Analysis: Go Obfuscated(04.09.2026 um 12:05 Uhr)
⚠️ Malware / Trojaner / VirenTengu, a Mirai-style Linux and IoT botnet(06.09.2026 um 15:27 Uhr)
🕵️ SicherheitslückenSecurity Vulnerability in a Voting System(04.09.2026 um 13:09 Uhr)
🕵️ SicherheitslückenHow an Integer Overflow Vulnerability Let Me Buy Anything for ₹0(04.09.2026 um 05:04 Uhr)
🕵️ SicherheitslückenHow I Turned Self-XSS into Reflected XSS (and Bypassed the WAF)(04.09.2026 um 05:09 Uhr)
🕵️ SicherheitslückenFile upload to RCE(04.09.2026 um 05:12 Uhr)
⚠️ Malware / Trojaner / VirenBerlin lehnt 30-BTC-Lösegeld von Rhysida ab, Hacker veröffentlichen 5,7 Terabyte(06.09.2026 um 19:22 Uhr)
⚠️ Malware / Trojaner / VirenLumma Stealer – dllhost.exe Hollowing, C2 Domains & Payload Extraction(01.09.2026 um 17:19 Uhr)
🔧 AI Nachrichten Simcha Kosman AMA: Owning ChatGPT's Secure Sandbox(03.09.2026 um 07:41 Uhr)
⚠️ Malware / Trojaner / VirenThe Gentlemen Ransomware Analysis: Go Obfuscated(04.09.2026 um 12:05 Uhr)
⚠️ Malware / Trojaner / VirenTengu, a Mirai-style Linux and IoT botnet(06.09.2026 um 15:27 Uhr)
🕵️ SicherheitslückenSecurity Vulnerability in a Voting System(04.09.2026 um 13:09 Uhr)
🕵️ SicherheitslückenHow an Integer Overflow Vulnerability Let Me Buy Anything for ₹0(04.09.2026 um 05:04 Uhr)
🕵️ SicherheitslückenHow I Turned Self-XSS into Reflected XSS (and Bypassed the WAF)(04.09.2026 um 05:09 Uhr)
🕵️ SicherheitslückenFile upload to RCE(04.09.2026 um 05:12 Uhr)
⚠️ Malware / Trojaner / VirenBerlin lehnt 30-BTC-Lösegeld von Rhysida ab, Hacker veröffentlichen 5,7 Terabyte(06.09.2026 um 19:22 Uhr)

📰 IT Security Nachrichten 🕛 kürzlich 5 Min Lesezeit SECURITY-FEED
0

Meta pauses employee monitoring program after data protections fail

↗ Quelle (csoonline.com)
🗣️ Stimme:








An extensive program at Meta to gather a wide range of data from employees to train its AI model has been frozen after employees reportedly broke through its guardrails and accessed restricted data, and then did so again after Meta claimed to have fixed the vulnerability.





Whether or not , a director with consulting firm Acceligence. “That is what it looks like when the policy decision and the technical execution are happening in two different rooms that are not fully in sync. It is the kind of gap you see often enough at organizations under structural strain.”





, involved a program that Meta rolled out in April called the Model Compatibility Initiative (MCI), which collects computer inputs such as mouse movements, click locations, and keystrokes, as well as screen content, the story said. Meta employees were initially not allowed to opt out. 





The data collected included full prompts and transcriptions, private conversations, people and performance data, Wired said, adding, “Meta executives have repeatedly defended the data-gathering project, saying it was necessary to train AI systems to operate computer software the way humans do, and that employees were the best examples for the artificial intelligence to learn from.”





Wired also quoted Stephane Kasriel, a Meta vice president overseeing AI research, who saying that the company discovered that unauthorized employees were found to have accessed MCI data on June 18, and that the hole was closed “within four hours.” But, he added, “ the initial fix didn’t stick, and access to the data had to be further locked down.”





In an email statement shared with CSO Online, Meta confirmed that the program was being halted for the time being. “We have carefully designed this program with privacy safeguards, and while we have no indication at this time that any data was improperly accessed by Meta employees, we’re pausing it while we investigate,” Meta said. 





A ‘liability surface’





Analysts, consultants, and industry practitioners said they were more concerned about the inadequate protections than the underlying data exposure.





, CEO of Conifers.ai. “But internal prompts, transcripts, chats, data tables, and performance notes can tell you a lot about how a company works, what it’s building and where things are messy or exposed. That’s sensitive, even if it’s not someone’s Social Security number.”





Findling argued that Meta executives “wanted to pretend that they didn’t understand” how sensitive the collected data was, and that was their excuse for why they should not have to protect it sufficiently. “There is no doubt that Meta did not tag this at an appropriate risk level,” he said.





Info-Tech’s Jean-Louis took particular umbrage at the particulars of the collected data. 





“Employee behavioral data, such as keystrokes, screenshots, and usage patterns, is effectively sensitive by default. If you’re using it to train AI, you have to treat it like production secrets, not analytics exhaust,” Jean-Louis said. “When thousands of internal tables are broadly accessible, you have a liability surface rather than a data platform. Trust nowadays is a security control. Once employees believe their data is overcollected or underprotected, you introduce both insider risk and reputational damage at the same time.”





Acceligence’s Michelle echoed Jean-Louis’ concerns.





“The data Meta exposed is not the real risk. Security policy only works if people believe it, and belief is exactly what is now in question,” Michelle said. “That gap is where incidents like this one do their damage: once employees stop trusting what leadership says about their own data, the doubt follows every policy that comes next, producing workarounds, quiet noncompliance, and employees who stop raising flags.”


Vollständiger Original-Bericht
Ausführliche Details, Code-Beispiele & Hersteller-Stellungnahme auf csoonline.com.
↗ Original-Artikel auf csoonline.com lesen
Wie bewertest du diesen Beitrag?
1 Klick Feedback
Teilen mit Netzwerk & Team:
Community Threat-Level Barometer
Live Votum

Wie stufst du das Risiko dieser Schwachstelle / Bedrohung für dein Unternehmen ein?

Noch keine Stimmen — schätze das Risiko als Erster ein.

Community-Analysen & Experten-Meinungen 0

Verfasse deine eigene Analyse, teile Workarounds oder diskutiere diesen Vorfall im Blog.
Noch keine Community-Analyse verfasst. Markiere einen Textabschnitt oder klicke oben auf Eigene Analyse verfassen“!
Community Pulse: Relevanz-Einschätzung
1 Klick Experten-Votum
🔴 Akute Relevanz 50%
🟡 In Evaluierung 23%
🟢 Keine Auswirkung 10%
Spannende Innovation 17%
Verwandte Story-Cluster & Quellen (Vektor-KI)
Port 8095 Engine
1 Quelle
ChatGPT showing blank screen [Fix]
1 Quelle
Excel keeps people on Windows, and a Linux distro creator wants Microsoft to end that
1 Quelle
Sofort deinstallieren: Diese 19 Browser-Erweiterungen sind mit Malware verseucht
Ähnliche Beiträge
🔍 Verwandte News

Auch interessante Nachrichten Meta pauses employee monitoring program after data protections fail

Thematisch verwandte Begriffe: Meta, pauses, employee, monitoring · 6 Treffer

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...