Tag: breach
-
UK’s small power plants face continued cyber risk after Iran-linked hack
Government measures to improve resilience are not due until 2030 and July’s hack has not altered this timeline<br><br> Hundreds of Britain’s smallest power plants could remain at a higher risk to state-sponsored cyber-attacks until the 2030s despite a successful Iran-linked hack last month, it has emerged.Officials this week briefed energy bosses on the breach, which…
-
ATF confirms “major incident” after recent Qilin breach claims
ATF, the regulatory agency that enforces federal laws governing firearms and explosives in the United States, has confirmed that one of its systems was compromised after breach claims made by the Qilin ransomware gang. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/atf-confirms-major-incident-after-recent-qilin-breach-claims/
-
AnonyMousKIT PhaaS Automates Apple ID, Device Passcode, and Live 2FA Harvesting Across Five Channels
AnonyMousKIT, an AI-enabled Phishing-as-a-Service (PhaaS) platform built to turn stolen Apple devices into monetizable assets. The service automates the collection of an owner’s device passcode, Apple ID credentials and live two-factor authentication (2FA) codes information that can enable criminals to remove Activation Lock and resell a stolen device. Rather than relying on a single phishing…
-
Carhartt data breach claims inflated by synthetic data, analysis finds
First seen on scworld.com Jump to article: www.scworld.com/brief/carhartt-data-breach-claims-inflated-by-synthetic-data-analysis-finds
-
LACMA data breach exposes customer and employee information
First seen on scworld.com Jump to article: www.scworld.com/brief/lacma-data-breach-exposes-customer-and-employee-information
-
Alabama attorney general subpoenas OpenAI over AI breach
First seen on scworld.com Jump to article: www.scworld.com/brief/alabama-attorney-general-subpoenas-openai-over-ai-data-breach
-
OpenAI Agents Coordinated Hugging Face Breach at Scale
Probe Finds 1,200 Agents Communicated Outside Sandboxes, With 700 Targeting Hugging Face. OpenAI and its third-party advisors found new information about the OpenAI-Hugging Face incident, in which artificial intelligence agents hacked the model repository to access internal datasets and steal credentials. OpenAI agents had already begun planning similar breaches as early as May. First seen…
-
Agent behavior that led to Hugging Face intrusion formed in May
The company says the breach stemmed from a systemic failure of alignment and security, and has taken measures to prevent agents from independently orchestrating complex cyberattacks. First seen on cyberscoop.com Jump to article: cyberscoop.com/openai-hugging-face-agent-breach-report/
-
ASOS Account Takeover Attack Exposes Data of 138,828 Customers
ASOS says attackers used credentials stolen elsewhere to access customer accounts, exposing personal data belonging to an estimated 138,828 people. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/threats/news-asos-account-takeover-138828-customers/
-
US seizes domains of Chinese botnet used to hack NASA, Justice Department, and the Senate
The FBI has seized domains associated with a botnet that allowed Chinese-backed hackers to breach several U.S. government departments. First seen on techcrunch.com Jump to article: techcrunch.com/2026/08/26/us-seizes-domains-of-chinese-botnet-used-to-hack-nasa-justice-department-and-the-senate/
-
AnonyMousKIT phishing-as-a-service uses AI voice calls to steal iPhone passcodes
A phishing-as-a-service (PhaaS) platform called AnonyMousKIT is automating the theft of Apple ID credentials needed to remove Activation Lock from stolen iPhones, SOCRadar … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/08/26/anonymouskit-phishing-stolen-iphone/
-
Bogus recruiters go after high-value corporate credentials on mobile
Scammers posing as HR staff at well-known companies are running interview scheduling scams that end with a stolen corporate password, according to Zimperium. Attackers are … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/08/26/recruitment-scam-corporate-passwords-mobile/
-
88 ID Verification Breaches Show the Cost of Collecting Identity Data
88 ID-verification breaches exposed billions of records, highlighting the growing risks of collecting sensitive identity and biometric data. A new report from Mysterium VPN compiles 88 documented incidents since 2011 where data collected specifically to verify someone’s identity or age got breached, exposed, or sold. The confirmed and researcher-verified total sits at 2.15 billion records,…
-
Fake Apple Support AI Calls Target Stolen-Device Owners for Passcodes and 2FA Codes
Cybersecurity researchers have disclosed details of a phishing-as-a-service (PhaaS) platform built to strip Apple’s Activation Lock from stolen devices, using rented AI voice agents that call theft victims posing as Apple Support and ask for their device passcode.SOCRadar Threat Research Unit (STRU) said the platform, which it tracks as AnonyMousKIT, is credit-metered and drives lures…
-
How Much Does a Data Breach Cost? IBM’s 2026 Report Puts the US Average at $11.5 Million
IBM’s 2026 Cost of a Data Breach Report puts the global average at a record $4.99M, and $11.5M in the US. Here’s what actually drives the bill. First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/08/how-much-does-a-data-breach-cost-ibms-2026-report-puts-the-us-average-at-11-5-million/
-
LACMA data breach last year exposed social security and medical data
The Los Angeles County Museum of Art (LACMA) has announced that a breach last year exposed customer and employee information. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/lacma-data-breach-last-year-exposed-social-security-and-medical-data/
-
AnonyMousKIT PhaaS uses voice AI agents to phish iPhone passcodes
A newly uncovered phishing-as-a-service (PhaaS) platform called AnonyMousKIT automates the retrieval of codes used to unlock stolen Apple devices and disable the Activation Lock feature. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/anonymouskit-phaas-uses-voice-ai-agents-to-phish-iphone-passcodes/
-
Network Compliance Is Failing 50% of Enterprises. Here’s Why and How to Fix It
According to Hyperproof’s 2026 IT Risk and Compliance Benchmark Report, 50% of organizations managing compliance ad hoc suffered a data breach in 2025. Organizations using an integrated, automated approach cut that number nearly in half. That gap does not happen by accident. The breached organizations were not ignoring compliance. Most had policies, scheduled checks, and..…
-
U.S. Sanctions Iran-Linked Hackers Behind Critical Infrastructure Breaches
The U.S. Department of the Treasury has announced fresh sanctions on Iranian cyber actors as part of what it called an “unprecedented, whole-of-government, economic campaign” against the nation and its enablers.”We are launching an economic onslaught against Iran’s financial connections around the globe. Our objective is to sever every economic lifeline that sustains this tyrannical…
-
Most Organizations Declare Victory Over a Breach Too Early
Why Bringing Systems Back Online Is Not the Same as Breach Recovery Getting systems back online may end the outage, but it doesn’t end the breach. Organizations that equate service restoration with recovery risk leaving attackers’ footholds, persistence mechanisms and governance failures untouched – and vulnerable to compromise again. First seen on govinfosecurity.com Jump to…
-
Is Cyber Facing an Affordability Crisis?
As breach costs reach record highs and defense spending nears $240 billion, small businesses are dangerously exposed, threatening supply chain security. First seen on darkreading.com Jump to article: www.darkreading.com/cybersecurity-operations/is-cyber-facing-an-affordability-crisis-
-
The Rising Cost of Trusted Access
IBM 2026 Cost of a Data Breach Report The cost of a data breach continues to climb. According to the IBM Cost of a Data Breach Report 2026, the global average reached a record $4.99 million, up 12% from the previous year. In the United States, the average cost rose to $11.5 million, more than……
-
Vektorisierung und Abliteration als KI-Risiken
Die Zahl der Kompromittierungsversuche auf öffentlich zugängliche KI-Modelle und eigenentwickelte LLMs nimmt zu. Laut den Ergebnissen des aktuellen Cost of a Data-Breach-Reports von IBM stieg die Zahl der KI-gestützten Angriffe im Vergleich zum Vorjahr um 56 Prozent. Die finanziellen Folgen waren nicht unerheblich. KI-gestützte Angriffe verursachten pro Sicherheitsvorfall durchschnittlich 1 Million US-Dollar an Kosten, da Angreifer…
-
Ledger Fixes Ethereum App Flaw as Disclosure Timeline Is Disputed
Ledger CTO Charles Guillemet said on Aug. 23, 2026, that the company had fixed a clear-signing flaw in its Ethereum app two weeks before security firm TestMachine publicly disclosed the issue. As of Aug. 24, there were no independently verified reports of funds stolen through the specific vulnerability. First seen on thecyberexpress.com Jump to article:…

