Tag: breach
-
Mini Shai-Hulud npm Attack: More Than 2,200 Components Impacted
Tags: access, ai, attack, breach, cloud, container, control, credentials, data, data-breach, github, guide, infection, intelligence, kubernetes, malicious, malware, microsoft, open-source, risk, sbom, service, software, threat, update<div cla TL;DR A new wave of the Shai-Hulud malicious package campaign emerged on npm, with 2,225 software component versions impacted. The malware executes through a malicious preinstall hook, steals npm, GitHub, cloud, Kubernetes, Vault, CI/CD, and other credentials, then uses stolen publishing access to compromise additional packages. Organizations that installed an affected version should…
-
Beacon CRM, Widely Used by Charities, Suffers Data Breach
English National Ballet is Among the Confirmed Victims Notifying Supporters. Cloud-based customer relationship management software provider Beacon CRM said it’s suffered a security breach that likely led to the theft of customer data. Over 1,000 charities use the software, and English National Ballet and the Centre for Sustainable Energy report they’ve been affected. First seen…
-
Brown Health Medical Group-MA Data Breach Exposes Information of 311,000 Individuals
Brown Health Medical Group-MA breach exposed personal, medical, and financial data of over 311,000 individuals after hackers accessed its servers. Brown Health Medical Group-MA data breach exposed personal, medical, and financial data of over 311,000 individuals after hackers accessed its servers. The healthcare group identified a data security breach involving a legacy file server on…
-
Arctic Wolf gibt CyberReadiness-Accelerator für Partner bekannt
Arctic Wolf gibt die Verfügbarkeit des <> bekannt. Das neue, partnergeführte Programm unterstützt Unternehmen dabei, Cyberrisiken besser zu verstehen und ihre Widerstandsfähigkeit in einer zunehmend von KI beschleunigten Bedrohungslandschaft zu stärken. Trotz Vulnerability- und Patch-Management bleiben Unternehmen unbekannten Risiken durch blinde Flecken innerhalb ihrer Angriffsfläche ausgesetzt, Tendenz steigend. Laut dem weltweiten Verizon-2026-Data-Breach- […] First seen…
-
Stolen Greatness Tokens Provide Microsoft 365 Access More Than Two Weeks After Phishing
Stolen Greatness authentication tokens are providing sustained, MFA”‘approved access to victim Microsoft 365 tenants for more than two weeks after the initial phish, underscoring that token replay not password theft is driving the persistence in this AiTM PhaaS ecosystem. Originally documented by Cisco Talos in May 2023 and further covered by Hornet Security, […] The…
-
Why Cloud Misconfigurations Continue to Cause Data Breaches in 2026
Just like a physical lock, a mistake when setting up a cloud service is usually hidden. You will typically only become aware of the mistake after a security incident. The provider is not responsible for the customer’s mistakes. This is called the ‘shared responsibility model.’ AWS, Azure, and Google Cloud all provide a secure operation,……
-
TP-Link patches Omada ZTP flaws allowing hackers to breach networks
TP-Link has patched 15 vulnerabilities in the zero-touch provisioning (ZTP) mechanism of its Omada network devices that could be chained with previously disclosed flaws to achieve remote code execution (RCE). First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/tp-link-patches-omada-ztp-flaws-allowing-hackers-to-breach-networks/
-
GitHub Account Breach Fuels Shai-Hulud npm Supply Chain Attack
A compromised GitHub account fueled a supply chain attack, spreading credential-stealing malware across hundreds of packages. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/threats/github-account-breach-fuels-shai-hulud-npm-supply-chain-attack/
-
Lawmakers spring to save ID theft services for OPM breach victims, with expiration looming
Sen. Mark Warner, D-Va., and Del. Eleanor Holmes Norton, D-D.C., hope to make the services permanent before they end next month. First seen on cyberscoop.com Jump to article: cyberscoop.com/opm-breach-lifetime-identity-protection-bill/
-
PNLD Data Breach Exposes Police and Government Contact Details on Dark Web
The PNLD data breach has exposed contact information belonging to police officers, government partners, criminal justice professionals and customers after data from the Police National Legal Database (PNLD) was published on the dark web. The data breach at PNLD, identified on July 26, 2026, also affected some users of Ask the Police, raising concerns about targeted phishing attacks. First seen on thecyberexpress.com Jump to…
-
Liechtenstein Cyberattack Exposes Data From Beneficial Ownership Register
The Liechtenstein cyberattack has prompted authorities to investigate a major security breach after copies of sensitive data linked to around 31,000 legal entities were unlawfully accessed from the country’s Register of Beneficial Owners (VwbP). First seen on thecyberexpress.com Jump to article: thecyberexpress.com/liechtenstein-cyberattack-vwbp/
-
31,000 Records Compromised in Breach of Liechtenstein Companies and Foundations Register
Cyberattack exposed data of 31,000 people in Liechtenstein’s beneficial ownership register for companies and foundations. A cyberattack compromised data belonging to about 31,000 people in Liechtenstein’s register of beneficial owners linked to companies, foundations, and trusts. Liechtenstein’s Register of People Behind Companies and Foundations is a government-maintained register of beneficial ownership. Its purpose is to…
-
UK’s Police National Legal Database Reveals Data Breach
The UK’s Police National Legal Database and Ask the Police service have been breached First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/uks-police-national-legal-database/
-
Hotel Wi-Fi attacks use custom malware to breach Microsoft 365 accounts
Microsoft has linked a global campaign targeting hospitality Wi-Fi networks to the Russian threat actor Midnight Blizzard, also known as APT29. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/hotel-wi-fi-attacks-use-custom-malware-to-breach-microsoft-365-accounts/
-
Amgen Tells SEC Hack Exposed Patient Data, Trade Secrets
Drug Maker Says PHI, Research, Confidential Business Data Potentially Stolen. Pharmaceutical maker Amgen has notified the U.S. Securities and Exchange Commission that cybercriminals have potentially stolen a cache of sensitive company data, including patient information, intellectual property, research and development, and other confidential business files. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/amgen-tells-sec-hack-exposed-patient-data-trade-secrets-a-32401
-
Bitcoin hardware wallet maker destroys some inventory after more than $88 million stolen
The company behind a popular hardware wallet for bitcoin owners was forced to destroy part of its inventory after thieves siphoned more than $88 million from customers through a firmware vulnerability. First seen on therecord.media Jump to article: therecord.media/bitcoin-theft-coldcard-cyberattack
-
River Bank obtained assurances from the attackers that the stolen data in the June attack was deleted
River Bank says hackers deleted data stolen in its June ransomware attack, though the investigation into the incident is still ongoing. River Financial Corporation, the parent company of River Bank & Trust, says hackers deleted data stolen during a ransomware attack that hit parts of its server environment in June. The breach began on June…
-
PNLD Confirms Data Breach Affecting UK Police and Justice Staff
UK police legal database breach exposed officers’ names and work emails, increasing phishing risks. NCA is investigating. The Police National Legal Database (PNLD), the legal reference system used by all 43 Home Office police forces in England and Wales, confirmed that a data breach exposed the contact details of police officers, staff, and criminal justice…
-
Biotech giant Amgen says patient data stolen from third-party cloud systems
The biotech giant Amgen informed regulators that patient information and proprietary company data were accessed through a breach of third-party cloud systems. First seen on therecord.media Jump to article: therecord.media/amgen-hackers-cyberattack-sec
-
PNLD Breach Exposes U.K. Police and Government Contact Details on Dark Web
The Police National Legal Database (PNLD) has confirmed that police, government and customer contact information was compromised and published on the dark web.The data included names, organisations and work email addresses belonging to police officers, police staff, criminal justice professionals, government partners and customers.The incident, identified on July 26, also exposed some names First seen…
-
Korea’s Largest Telco KT Fined $38m After Femtocell Campaign
Korean telco KT has been fined $39m for a year-long breach linked to femtocell compromise First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/koreas-largest-telco-kt-fine-39m/
-
Alleged Żabka Breach Exposes Jira Data, Source Code, and API Keys
Alleged Å»abka data leak offered for Euro5,000 includes Jira data, GitLab repos, and secrets; researchers verified much of the sample. A brand-new forum account showed up on August 2, posted once, and asked five grand for what it claims is a full data dump from Å»abka Polska. Å»abka Polska is Poland’s largest convenience store operator…
-
Product showcase: Guardio Mobile Security turns breach alerts into a recovery plan
Guardio Mobile Security brings several protection features to iPhone and Android, allowing users to monitor exposed personal information, identify phishing attempts, and … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/08/03/product-showcase-guardio-mobile-security/
-
CareCloud Breach Exposes Medical and Financial Data of 345,000
CareCloud disclosed a breach affecting 345,000 people after hackers stole medical and financial data from its AWS-hosted systems. TechCrunch reports that CareCloud, the New Jersey-based health tech company that stores patient records for more than 45,000 providers across the US, is finally notifying people impacted by a breach the firm first disclosed back in March.…
-
Weekly Cybersecurity Newsletter Top 50 Biggest Cybersecurity Stories of the Week Hugging Face, Iranian ICS Attacks, EY, Hyundai, AI Agent Breaches
Welcome to this week’s edition of the GBHackers cybersecurity newsletter, your weekly cybersecurity bulletin covering the 50 most important stories from July 27August 1, 2026. The week’s throughline was AI on both sides of the fight: an autonomous agent escaped its sandbox and breached Hugging Face, a DeepSeek agent drove autonomous attacks, and Google […]…
-
UK’s state investments agency hit by data breach
Security lapse leaves sensitive information and contact details of 51 government officials exposed for 40 hoursThe public body in charge of the UK’s state investments has been pushed to improve its internal security after a data breach left “high-level management information” publicly accessible for nearly two days.UK Government Investments (UKGI), the agency that manages the…
-
What we learned about zero-trust from the OpenAI breach of HuggingFace
First seen on scworld.com Jump to article: www.scworld.com/perspective/what-we-learned-about-zero-trust-from-the-openai-breach-of-huggingface
-
KT Corporation fined $39 million for 11-month data breach
First seen on scworld.com Jump to article: www.scworld.com/brief/kt-corporation-fined-39-million-for-11-month-data-breach
-
When AI Hackers Meet Machine Identity: The Ignored Attack Surface
The Salesloft Drift breach hit 700+ companies with stolen OAuth tokens and never touched a password. Machine identities now outnumber humans 80 to 1, and AI-powered attackers are harvesting them at machine speed. Here is why human-shaped IAM cannot protect AI agents, and what to fix in 90 days. First seen on securityboulevard.com Jump to…

