Tag: breach
-
AI ‘Machine Speed’ Cuts 2-Week Attack Down to 10 Hours
The incident demonstrates how frontier AI agents can dramatically compress an attack timeline and coordinate a large-scale breach, according to researchers. First seen on darkreading.com Jump to article: www.darkreading.com/cyberattacks-data-breaches/ai-machine-speed-2-week-attack-10-hours
-
AI ‘Machine Speed’ Cuts 2-Week Attack Down to 10 Hours
The incident demonstrates how frontier AI agents can dramatically compress an attack timeline and coordinate a large-scale breach, according to researchers. First seen on darkreading.com Jump to article: www.darkreading.com/cyberattacks-data-breaches/ai-machine-speed-2-week-attack-10-hours
-
Your Employee’s Password Appeared in an Infostealer Log. Now What?
Infostealers can expose far more than passwords, including authenticated sessions that may let attackers bypass MFA. Flare explains how defenders can prioritize compromised identities, determine whether stolen access is still usable, and respond before it leads to account takeover. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/your-employees-password-appeared-in-an-infostealer-log-now-what/
-
Your Employee’s Password Appeared in an Infostealer Log. Now What?
Infostealers can expose far more than passwords, including authenticated sessions that may let attackers bypass MFA. Flare explains how defenders can prioritize compromised identities, determine whether stolen access is still usable, and respond before it leads to account takeover. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/your-employees-password-appeared-in-an-infostealer-log-now-what/
-
Your Employee’s Password Appeared in an Infostealer Log. Now What?
Infostealers can expose far more than passwords, including authenticated sessions that may let attackers bypass MFA. Flare explains how defenders can prioritize compromised identities, determine whether stolen access is still usable, and respond before it leads to account takeover. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/your-employees-password-appeared-in-an-infostealer-log-now-what/
-
Thomson Reuters reveals breach that exposed U.S. and Canadian court records
Thomson Reuters has disclosed a data breach affecting C-Track, a court case management platform operated by its subsidiaries, exposing court records and sensitive personal … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/09/03/thomson-reuters-reveals-breach-that-exposed-u-s-and-canadian-court-records/
-
US and Canadian court data exposed in Thomson Reuters breach
Sealed court information and sensitive personal data were exposed in a breach of a Thomson Reuters records platform affecting courts in at least 12 U.S. states, the U.S. Virgin Islands and Canada. First seen on therecord.media Jump to article: therecord.media/thomson-reuters-cyberattack-data
-
FBI Probes Possible Breach of 153 Million Driver’s Licenses
The FBI is investigating how scans of over 153 million driver’s licenses are being sold on the dark web First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/fbi-probes-breach-153-million/
-
FBI Probes Possible Breach of 153 Million Driver’s Licenses
The FBI is investigating how scans of over 153 million driver’s licenses are being sold on the dark web First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/fbi-probes-breach-153-million/
-
Ransomware Hackers Can Go From Network Access to Encryption in Less Than 24 Hours
Tags: access, breach, business, credentials, cyber, data-breach, encryption, hacker, infrastructure, network, ransomware, service, threatThe Gentlemen ransomware-as-a-service operation can move from confirmed access inside a victim network to encryption in under 24 hours. Demonstrating how rapidly modern affiliates can turn stolen credentials or exposed infrastructure into a full-scale business disruption. Counter Threat Unit researchers tracking the operation as GOLD SHERWOOD found that the Gentlemen affiliates follow a repeatable post-compromise…
-
UK airport hackers leak stolen customer data
The cyber gang that attacked Manchester Airports Group has leaked data on 8.7 million travellers after its victim refused to pay a ransom. First seen on computerweekly.com Jump to article: www.computerweekly.com/news/366649824/UK-airport-hackers-leak-stolen-customer-data
-
I rented a car, and within hours, my driver’s license was for sale
The FBI is reportedly investigating a massive data breach that is unfolding in real time. First seen on arstechnica.com Jump to article: arstechnica.com/security/2026/09/my-drivers-license-is-one-of-153-million-for-sale-on-a-new-dark-website/
-
It sure looks like hackers breached a major ID card verification service
An identity theft search site claimed to have more than 150 million driver’s license photos stolen from an ID verification service. The crime site has now shut down. First seen on techcrunch.com Jump to article: techcrunch.com/2026/09/02/it-sure-looks-like-hackers-breached-a-major-id-card-verification-service/
-
Irish Privacy Watchdog Details Psychiatric Data Breaches
Medical Records ‘Contaminated by Animal Droppings’ Recovered From Disused Sites. Rotting old mental health records stored on paper contaminated by animal droppings and left in abandoned psychiatric hospitals in Ireland have led to the country’s privacy watchdog reprimanding and fining the national health service for GDPR violations and demanding security improvements. First seen on govinfosecurity.com…
-
The Gentlemen Ransomware Hackers Use TukTuk C2 to Steal Credentials and Disable EDR Security
Tags: breach, control, credentials, cyber, edr, framework, group, hacker, healthcare, ransomware, technologyThe Gentlemen ransomware operation has been linked to a previously undocumented, cross-platform command-and-control framework named TukTuk, alongside EDR-disabling tooling, DLL sideloading research, and datasets apparently stolen from technology and healthcare organizations. Analysis of a Finland-hosted server identified what researchers assess as the complete TukTuk development project, providing an unusually detailed view into the group’s post-compromise capabilities.…
-
Nutex Health Says Patient Data Stolen, Hackers Threaten Leak
The US healthcare provider confirmed that sensitive patient and employee data, alongside financial and business information, were exfiltrated by a third party First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/nutex-patient-data-stolen/
-
Hackers Breach Brazilian Financial Firms and Execute Hundreds of Fraudulent Transactions
A financially motivated threat actor tracked as BREEZE COMET has breached Brazilian financial, retail, and eCommerce organizations, using privileged access to payment platforms to execute hundreds of fraudulent transactions in tightly timed waves. The activity overlaps with clusters publicly identified as Plump Spider and SHADOW-AETHER-064, although GTIG’s reporting frames this as operational overlap rather than…
-
FulcrumSec Claims Responsibility for Manchester Airport Group Breach
Threat group FulcrumSec claims MAG breach and leaks 550GB of data online First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/fulcrumsec-manchester-airport/
-
FulcrumSec Claims Responsibility for Manchester Airport Group Breach
Threat group FulcrumSec claims MAG breach and leaks 550GB of data online First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/fulcrumsec-manchester-airport/
-
McKesson discloses data breach after ShinyHunters claims theft of 284 million records
First seen on scworld.com Jump to article: www.scworld.com/brief/mckesson-discloses-data-breach-after-shinyhunters-claims-theft-of-284-million-records
-
Old, Unpatched Flaws Give Attackers Access to Philippines Nuclear Agency
Threat actors exploited commodity in ownCloud to gain initial access, resulting in stolen reactor databases, personnel records, and credential stores. First seen on darkreading.com Jump to article: www.darkreading.com/cyberattacks-data-breaches/old-unpatched-flaws-attackers-philippines-nuclear-agency
-
Australia introduces new digital identity strategy amid rising data breach and surveillance risks
First seen on scworld.com Jump to article: www.scworld.com/brief/australia-introduces-new-digital-identity-strategy-amid-rising-data-breach-and-surveillance-risks
-
Aesto Health says data breach affects over 9.5 million patients
Aesto LLC, operating as Aesto Health, disclosed that a data breach discovered recently affects more than 9.5 million individuals. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/aesto-health-says-data-breach-affects-over-95-million-patients/
-
Healthcare facilities operator Nutex says patient, employee data stolen in August incident
Cybercriminals breached company data and made an extortion attempt with it, Houston-based Nutex Health said in a filing with federal regulators. First seen on therecord.media Jump to article: therecord.media/nutex-health-data-breach
-
Attackers Access Aesto Health AWS Infrastructure, Exposing 9.5 Million Records
Aesto Health suffered a breach exposing personal and health data of more than 9.5 million people after attackers accessed its AWS infrastructure. Aesto Health, a U.S. healthcare technology company, disclosed a data breach that exposed personal and health information belonging to more than 9.5 million people. The company discovered the incident on December 18, 2025,…
-
Novocure data breach affects more than 1,400 cancer patients
Healthtech company Novocure says the data of an undisclosed number of employees and more than 1,400 U.S. cancer patients has been exposed in a mid-August cyberattack. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/novocure-data-breach-affects-more-than-1-400-cancer-patients/
-
Attackers Steal METR API Key and Burn $600,000 in AI Credits
Attackers used a stolen METR API key for three weeks, consuming model credits worth $600,000 First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/attackers-steal-metr-api-key/
-
Berlin refuses to be blackmailed after network breach
Berlin’s state government has confirmed an extortion attempt following a data theft from its administrative network in August. Governing Mayor Kai Wegner and Interior … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/09/01/berlin-data-breach-rhysida-ransomware/
-
Healthcare Giant McKesson Investigates Data Breach Incident
ShinyHunters claims to have stolen 284 million records from McKesson First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/healthcare-mckesson-investigates/

