Tag: breach
-
Vektorisierung und Abliteration als KI-Risiken
Die Zahl der Kompromittierungsversuche auf öffentlich zugängliche KI-Modelle und eigenentwickelte LLMs nimmt zu. Laut den Ergebnissen des aktuellen Cost of a Data-Breach-Reports von IBM stieg die Zahl der KI-gestützten Angriffe im Vergleich zum Vorjahr um 56 Prozent. Die finanziellen Folgen waren nicht unerheblich. KI-gestützte Angriffe verursachten pro Sicherheitsvorfall durchschnittlich 1 Million US-Dollar an Kosten, da Angreifer…
-
Ledger Fixes Ethereum App Flaw as Disclosure Timeline Is Disputed
Ledger CTO Charles Guillemet said on Aug. 23, 2026, that the company had fixed a clear-signing flaw in its Ethereum app two weeks before security firm TestMachine publicly disclosed the issue. As of Aug. 24, there were no independently verified reports of funds stolen through the specific vulnerability. First seen on thecyberexpress.com Jump to article:…
-
24th August Threat Intelligence Report
Latvia’s Road Traffic Safety Directorate (CSDD) has confirmed a breach affecting payment records of more than 1.2 million people roughly two-thirds of the country’s population as well as 200,000 organizations. The […] First seen on research.checkpoint.com Jump to article: research.checkpoint.com/2026/24th-august-threat-intelligence-report/
-
South Korean startup platform breach exposes key management failures
A breach at South Korea’s government-backed startup platform exposed encrypted personal data after an encryption key was included in an API. Penta Security explains why encryption keys must be securely managed and kept separate from the data they protect. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/south-korean-startup-platform-breach-exposes-key-management-failures/
-
The Rise of Service-Centric Credential Compilations
How Cybercriminals Are Repackaging Infostealer Data Over the last year, the underground economy has undergone a significant transformation. Cybercriminals are no longer focused on distributing massive collections of raw infostealer logs, they are increasingly investing time in organizing and enriching stolen information into service-specific compilations. These datasets are no longer random collections of credentials extracted……
-
Cybersecurity Newsletter Bulletin Top 50 Biggest Cybersecurity Stories of the Week Shell Azure Mega-Breaches, Salt Typhoon Evicted, Entra ID RCE, Chinese vCenter ESXi Ransomware More
Tags: breach, china, cisa, credentials, cyber, cybersecurity, exploit, flaw, mobile, ransomware, rce, remote-code-execution, theft, vcenterWelcome to this week’s edition of the GBHackers cybersecurity newsletter, your weekly cybersecurity bulletin covering the 50 most important stories from August 1721, 2026. Breaches and exploited flaws dominated: Cl0p claimed 89GB from Shell, a mass Azure credential-theft campaign hit McDonald’s and Vodafone, and T-Mobile physically cut a cable to evict Salt Typhoon. CISA […]…
-
Apollo Data Breach Shows the Risk Behind a Simple Phone Call
Apollo Global Management has disclosed a data breach involving sensitive personal information after attackers gained access to parts of its cloud environment. The breach occurred between July 6 and July 10, 2026. Apollo later determined that the affected information may include names, dates of birth, contact details, home addresses, and Social Security numbers. The company……
-
Week in review: Records allegedly stolen from Azure tenants, Medusa ransomware hits 500+ orgs
Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: Windows 11’s strongest security defenses can be bypassed without a … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/08/23/week-in-review-records-allegedly-stolen-from-azure-tenants-medusa-ransomware-hits-500-orgs/
-
Hospital for Sick Children discloses employee data breach due to third-party software flaw
First seen on scworld.com Jump to article: www.scworld.com/brief/hospital-for-sick-children-discloses-employee-data-breach-due-to-third-party-software-flaw
-
US Bank investigates LockBit ransomware claims of data breach
First seen on scworld.com Jump to article: www.scworld.com/brief/us-bank-investigates-lockbit-ransomware-claims-of-data-breach
-
ShinyHunters Leaks 7.1 Million Baxter International Records
Gang Claims It Stole Medical Device Maker’s Salesforce Info Including Personal Data. Extortion gang ShinyHunters has struck the healthcare sector again. The notorious cybercriminal gang claims on its darkweb site of leaking 7.1 million Salesforce records stolen from medical device maker Baxter International, including personally identifiable information. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/shinyhunters-leaks-71-million-baxter-international-records-a-32630
-
Apollo discloses data breach from ongoing wave of attacks hitting financial sector
The private equity firm said attackers broke into some of its cloud platforms during a five-day period in early July, compromising sensitive personal data. First seen on cyberscoop.com Jump to article: cyberscoop.com/apollo-discloses-data-breach-social-engineering-attack/
-
New Manic Android Malware Uses Offline Networks to Drain Bank Accounts
Manic Android malware steals banking credentials and can relay stolen data through nearby infected phones, complicating traditional device isolation. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/threats/news-manic-android-malware-device-relay-data-theft/
-
U.S. Bank says breach claims related to fourth-party incident
The bank said there is no evidence that its own systems, networks or data repositories were compromised. First seen on therecord.media Jump to article: therecord.media/us-bank-says-breach-claims-related-to-fourth-party-incident
-
Canada’s Hospital for Sick Children attacked by cybercriminals again as employee data stolen
The Hospital for Sick Children, which was hit in a ransomware incident in 2022 that disabled some of its systems, released a statement on Thursday warning of a data theft incident they believe is tied to a third-party software application. First seen on therecord.media Jump to article: therecord.media/canada-hospital-for-sick-children-attacked-again-employee-data
-
Copilot Revealed Its Own Vulnerability Through ‘Meta-Hacking’: Varonis
Using a method they call “meta-hacking,” Varonis researchers were able to convince Microsoft’s Copilot AI model to detail its architecture, exposing vulnerabilities given the umbrella name “CoSnitch” that can be exploited to launch attacks that could lead to sensitive information being stolen from victims. First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/08/copilot-revealed-its-own-vulnerability-through-meta-hacking-varonis/
-
Is Online Privacy Possible? How Digital Identities Can Help
Using the same email, phone number, payment method, and other identifiers makes it easier for data brokers and attackers to profile your activity. Anonyome Labs explains how separate digital personas can reduce correlation and limit the impact of breaches, spam, and identity theft. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/is-online-privacy-possible-how-digital-identities-can-help/
-
The Cyber Express Weekly Roundup: Tax Data Breach, AI Security Risks, and Critical GitLab Flaw
Tags: ai, breach, cyber, cybersecurity, data, data-breach, exploit, flaw, gitlab, government, risk, software, threat, vulnerabilityThis weekly roundup highlights a broad range of cybersecurity threats affecting government agencies, businesses, enterprise AI systems, and software platforms. From a major French tax authority breach to a critical GitLab vulnerability, recent incidents demonstrate how attackers continue to exploit sensitive data, digital systems, and emerging technologies. First seen on thecyberexpress.com Jump to article: thecyberexpress.com/weekly-roundup-tax-breach-ai-gitlab-flaw/
-
US Bank Investigates Alleged Data Breach After LockBit Ransomware Extortion Claim
US Bank is currently investigating claims made by the LockBit ransomware group, which alleges that it breached the bank and stole sensitive data. The group has set a deadline of September 3 for the bank to meet an undisclosed extortion demand. As of now, the details of the alleged attack have not been independently verified,…
-
Private equity firm Apollo confirms data breach amid hacking wave targeting financial giants
The private equity giant confirms a breach, weeks after Google researchers said hackers were targeting financial companies. First seen on techcrunch.com Jump to article: techcrunch.com/2026/08/21/private-equity-firm-apollo-confirms-data-breach-amid-hacking-wave-targeting-financial-giants/
-
The Cyber Express Weekly Roundup: Tax Data Breach, AI Security Risks, and Critical GitLab Flaw
Tags: ai, breach, cyber, cybersecurity, data, data-breach, exploit, flaw, gitlab, government, risk, software, threat, vulnerabilityThis weekly roundup highlights a broad range of cybersecurity threats affecting government agencies, businesses, enterprise AI systems, and software platforms. From a major French tax authority breach to a critical GitLab vulnerability, recent incidents demonstrate how attackers continue to exploit sensitive data, digital systems, and emerging technologies. First seen on thecyberexpress.com Jump to article: thecyberexpress.com/weekly-roundup-tax-breach-ai-gitlab-flaw/
-
Medical records, SSNs, and bank details exposed in CareCloud data breach
Healthcare technology provider CareCloud confirmed that 3.75 million people were affected by a March data breach. First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/08/medical-records-ssns-and-bank-details-exposed-in-carecloud-data-breach/
-
SickKids data breach exposes employee and job applicant info
Toronto’s Hospital for Sick Children (SickKids) says a cybersecurity incident exposed the personal information of some current and former employees and job applicants, stemming from a flaw in third-party software. Clinical systems and patient records were not affected. (264) First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/sickkids-data-breach-exposes-employee-and-job-applicant-info/
-
Principle of least privilege explained in plain English
If a staff account, supplier login, or application account has more access than it needs, the business takes on unnecessary risk. A single mistake, stolen password, or poorly managed admin account can then affect more systems, more data, and more customers than it should. That is why the principle of least privilege matters. In plain……
-
Breach Roundup: Grandoreiro Returns
Also, French Tax Agency Breach and Accused Ransomware Developer in Swiss Court. This week: Grandoreiro returns, Swiss prosecutors sought a 12-year sentence for ransomware developer, a Medusa ransomware warning, Ransom Busters demanded up to $60,000 from victims, French tax agency disclosed a breach, a Fuxa vulnerability, Stripe vendors exposed in 33 gigabytes data leak. First…

