Tag: breach
-
Google Mandiant AI Agents Find Over 100 Critical Vulnerabilities in Source Code Within Two Days
Tags: ai, breach, corporate, cyber, google, group, incident response, intelligence, mandiant, penetration-testing, RedTeam, threat, vulnerabilityGoogle’s Threat Intelligence Group has announced that its Agentic Vulnerability Discovery Harness (AVDH) identified over 100 critical true-positive vulnerabilities in stolen corporate source code repositories within just two days. This result highlights how agentic AI can significantly accelerate vulnerability discovery during incident response, red teaming, penetration testing, and proactive secure code reviews, especially when adversaries…
-
StopAndProtect Uses Nearly 2,000 Hacked WordPress Sites to Spread Malware and Steal Data
Cybersecurity researchers have flagged a global cybercrime operation that abuses thousands of hacked WordPress websites as infrastructure to disseminate malware, commandeer infected hosts, store stolen documents, screenshots, and activity logs created to track the status of the activity.”The operation doesn’t rely on a single piece of malware, but on a whole toolkit of criminal software…
-
Ransom Busters Ransomware Affiliate Targets Victims With Fake Data Recovery Extortion
A threat actor calling itself “Ransom Busters” is targeting ransomware victims with a deceptive recovery offer, claiming it can restore encrypted files and delete stolen data from ransomware infrastructure. GuidePoint Security’s Research and Intelligence Team (GRIT) assesses with moderate confidence that the purported recovery service is actually a ransomware affiliate attempting to divert extortion payments…
-
McDonald’s employee records allegedly stolen from Azure
Tags: breachFirst seen on scworld.com Jump to article: www.scworld.com/brief/mcdonalds-employee-records-allegedly-stolen-from-azure
-
Hacker Claims 3.6 Million Azure Records Stolen From McDonald’s, Vodafone and Others
A hacker claims to be selling 3.6 million Azure-linked employee records from McDonald’s, Vodafone, TCS, and others, but no breach is confirmed. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/threats/news-hacker-claims-3-6-million-azure-records-mcdonalds-vodafone/
-
OpenAI institutes new safeguards after Hugging Face breach
The new safeguards include more detailed monitoring of models during the development process, as well as greater emphasis on alignment and security during the post-training process. First seen on techcrunch.com Jump to article: techcrunch.com/2026/08/18/openai-institutes-new-safeguards-after-hugging-face-breach/
-
Hackers Expose Data of 1.2 Million Heights Finance Customers
A Heights Finance breach exposed personal and financial data of over 1.2 million people after hackers compromised a third-party cloud platform. Heights Finance is a U.S. consumer finance company that provides personal loans and related lending services, mainly to customers who may have limited access to traditional bank credit. It is part of Heights Finance…
-
Ransom Busters Claims It Hacked Ransomware Servers, Asks Victims for Up to $60,000
A ransomware affiliate calling itself Ransom Busters has been spotted proactively sending emails to victim organizations and claims to delete stolen data from ransomware groups’ servers in exchange for a fee ranging from $20,000 to $60,000.”In these messages, the third-party offers to help the victim recover from ransomware attack. This immediately stands out as anomalous,”…
-
Hugging Face Breach Raises Big Questions About AI Security Controls
Adam Shostack, president of Shostack & Associates and an affiliate professor at the University of Washington, talks with the Dark Reading News Desk about why he was blown away by OpenAI’s revelations regarding the Hugging Face attack. First seen on darkreading.com Jump to article: www.darkreading.com/vulnerabilities-threats/adam-shostack-talks-hugging-face-phantom-b
-
Berlin cuts two state ministries off government network after security breach
The affected ministries, one responsible for urban development, construction and housing, and the other for mobility, transport, climate protection and the environment, have been isolated from government networks since Friday as a precaution. First seen on therecord.media Jump to article: therecord.media/berlin-cuts-two-state-ministries-off-government-breach
-
Hacker Claims Millions of Records Stolen From Azure Tenants
A threat actor is claiming to have stolen millions of employee records from the Microsoft Azure environments of several major companies, raising concerns that the information could be used to launch targeted phishing, impersonation, and privilege escalation attacks. The threat actor, known as >>TheHatman,<< has reportedly posted internal employee directories belonging to companies including McDonald's,…
-
Adam Shostack Talks Hugging Face Breach & PHANTOM-B
The security expert talks with the Dark Reading News Desk about why he blown away by OpenAI’s revelations regarding the Hugging Face attack, and also discussed his new threat model for LLMs. First seen on darkreading.com Jump to article: www.darkreading.com/vulnerabilities-threats/adam-shostack-talks-hugging-face-phantom-b
-
OpenAI tightens defenses after AI agents breach research environment
Following the OpenAI-Hugging Face incident, in which an agentic collective autonomously penetrated OpenAI’s research infrastructure and another company’s production … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/08/18/openai-strengthening-security-measures/
-
Hacker claims millions of records stolen from corporate Azure tenants
A threat actor known as >>TheHatman<< claims to have obtained millions of employee records from the Azure environments of several Fortune 500 companies, including … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/08/18/azure-data-leak-fortune-500-companies/
-
Pokémon Center Data Breach Exposes Customers’ Personal and Order Data
Pokémon Center has begun notifying customers in the United Kingdom and Germany that personal information from their online orders was exposed following a cyberattack on CEVA Logistics, its third-party fulfillment partner. The retailer clarified that the incident did not originate from Pokémon Center’s own systems or website. Instead, attackers compromised the systems CEVA uses to…
-
SafePal warns of data breach affecting nearly 40,000 customers
First seen on scworld.com Jump to article: www.scworld.com/brief/safepal-warns-of-data-breach-affecting-nearly-40000-customers
-
Clop Claims Data Theft From More Than 40 Companies
Victims Are Assessing Claims of Stolen Databases, CAD Files and Backups. Russia-linked Clop claims it stole databases, engineering files, backups and other sensitive corporate data from more than 40 organizations in a breach wave tied to exploitation of a critical remote code execution flaw in PTC Windchill and FlexPLM. First seen on govinfosecurity.com Jump to…

