Tag: breach
-
Paidwork Data Breach Exposes 23.3 Million Accounts, Banking Data and bcrypt Password Hashes
Gig-economy platform Paidwork has been linked to a significant data breach that affects 23.3 million accounts. This breach, involving an approximately 11GB dataset, was publicly released in July 2026. The incident was added to the Have I Been Pwned (HIBP) breach database on July 19, with the compromise reportedly occurring in March 2026. Paidwork Data…
-
HOLLOWGRAPH Malware Turns Microsoft 365 Calendar Events Into Covert CommandControl Channels
HOLLOWGRAPH, a Windows malware implant that transforms Microsoft 365 calendar events into a covert command-and-control channel. This malware, which is highly likely linked to the Cavern modular backdoor framework, utilizes the Microsoft Graph API to retrieve tasks from operators and to exfiltrate stolen data via a compromised Microsoft 365 mailbox. This technique enables malicious communications…
-
Estée Lauder discloses data breach via Oracle E-Business flaw
Cosmetics giant Estée Lauder is notifying customers of a data breach after hackers exploited a flaw in Oracle E-Business Suite that the company used for human resources (HR) operations. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/est-e-lauder-discloses-data-breach-via-oracle-e-business-flaw/
-
Cosmetics giant Estée Lauder victim of mass Oracle breach
Employee data at US-based cosmetics firm Estée Lauder was compromised through a vulnerability in Oracle’s software, likely orchestrated by the Cl0p ransomware gang. First seen on computerweekly.com Jump to article: www.computerweekly.com/news/366645849/Cosmetics-giant-Estee-Lauder-victim-of-mass-Oracle-breach
-
HOLLOWGRAPH malware turns Microsoft 365 calendars into an espionage channel
Microsoft 365 calendars have become a hiding place for espionage malware, with commands and stolen files stashed inside appointments dated to the year 2050, researchers from … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/07/20/hollowgraph-malware-microsoft-365-calendar/
-
New HollowGraph malware uses Microsoft Graph for stealthy C2 comms
A malicious component dubbed HollowGraph uses the calendar feature in compromised Microsoft 365 mailboxes as a command-and-control channel to receive attacker commands and exfiltrate stolen data. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/new-hollowgraph-malware-uses-microsoft-graph-for-stealthy-c2-comms/
-
The 12 Best Identity Threat Detection Response (ITDR) Solutions, Compared and Priced (2026)
Identity is where breaches start, and ITDR pricing is where budgets get confused platform modules, IdP SKUs, E5 bundles, and managed services all claim the same acronym. The value verdict up front: Huntress is the best published-price ITDR for SMBs and MSPs, Microsoft Defender for Identity is effectively the bundled default inside E5 estates, Sophos…
-
Hackers steal customer data from major hospital software vendor
The breach is another reminder of how vulnerable the healthcare industry is to supply-chain attacks. First seen on cybersecuritydive.com Jump to article: www.cybersecuritydive.com/news/craneware-health-care-data-breach/825643/
-
Hackers stole ‘significant’ amount of data from tech firm relied on by thousands of US hospitals and pharmacies
Edinburgh-based tech firm Craneware said customer data was stolen during a cyberattack. The company makes software that thousands of U.S. hospitals, pharmacies, and clinics rely on for billing patients, potentially exposing health data. First seen on techcrunch.com Jump to article: techcrunch.com/2026/07/20/hackers-stole-significant-amount-of-data-from-tech-firm-relied-on-by-thousands-of-us-hospitals-and-pharmacies/
-
Paidwork breach exposes sensitive data of 23 million user
Data belonging to more than 23 million users has been exposed following a breach at Paidwork, a platform that pays people for completing online microtasks. Paidwork markets … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/07/20/paidwork-data-breach-23-million-users/
-
HollowGraph Malware Hides C2 and Stolen Files in Microsoft 365 Events Dated 2050
A newly discovered espionage implant has been using a hijacked Microsoft 365 calendar as its command channel, planting operator instructions and smuggling out stolen files as attachments on calendar events dated to the year 2050.Group-IB, which named the malware HollowGraph, says the approach moves tasking and stolen data through legitimate Microsoft Graph API traffic, so…
-
Italy fines WINDTRE Euro1.7 million over security flaws behind two data breaches
Italy’s data protection authority, the Garante per la Protezione dei Dati Personali, fined WINDTRE Euro1.7 million over >>serious data security shortcomings<< … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/07/20/italy-windtre-1-7-million-fine/
-
âš¡ Weekly Recap: WordPress RCE, SonicWall 0-Days, AI Service Attacks, SharePoint 0-Day and More
Tags: ai, attack, breach, data-breach, malware, rce, remote-code-execution, service, wordpress, zero-dayA single request should not be able to do this much. But this week, small inputs led to code execution, memory loss, stolen keys, and disabled security tools.The paths were often simple: exposed systems, weak checks, old drivers, fake prompts, and public code used for malware delivery. Some bugs were new. Others were already being…
-
Hugging Face discloses breach linked to autonomous AI agent
The Hugging Face artificial intelligence repository disclosed that attackers gained access to internal datasets and credentials after breaching its production infrastructure using an autonomous AI agent system. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/hugging-face-breach-autonomous-ai-agent-system-internal-datasets-credentials/
-
20th July Threat Intelligence Report
Ernst & Young, a global accounting and professional services company, has disclosed a data breach involving a compromised third-party IT support platform. The exposed support tickets may have contained client documents, tax information, […] First seen on research.checkpoint.com Jump to article: research.checkpoint.com/2026/20th-july-threat-intelligence-report/
-
Hugging Face confirms breach affected internal datasets and credentials, urges users to take action
Hugging Face is urging users to rotate any access tokens stored on the platform and review account activity. First seen on techcrunch.com Jump to article: techcrunch.com/2026/07/20/hugging-face-confirms-breach-affected-internal-datasets-and-credentials-urges-users-to-take-action/
-
Hugging Face breached by autonomous AI agent
Hugging Face, the widely used platform for sharing open-source machine learning models and datasets, has disclosed a security breach it says was carried out by an autonomous … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/07/20/hugging-face-breached-by-autonomous-ai-agent/
-
Researchers Uncover HOLLOWGRAPH: Malware That Hides Inside Microsoft 365 Calendar Invites
A previously undocumented strain of Windows malware is using Microsoft 365 calendar invites as a covert communications channel, allowing attackers to issue commands and exfiltrate stolen files from victim networks while hiding in plain sight among ordinary enterprise traffic, according to new research from the threat intelligence firm Group-IB. The malware, dubbed HOLLOWGRAPH, was detailed…
-
Weekly Cybersecurity Newsletter The 50 Biggest Cybersecurity Stories Microsoft Patch, AI Attack, Exploits Releases, Data Breaches More
Welcome to this week’s edition of the GBHackers cybersecurity newsletter, your weekly cybersecurity bulletin covering the 40 most important stories from July 1317, 2026. What a week: Microsoft shattered records with 570 vulnerabilities patched in a single Patch Tuesday, China-linked hackers weaponized Claude Code and DeepSeek against government networks, GPT-5.6 wrote a complete Chrome […]…
-
GoldenEyeDog Threat Group Behind DigiCert Code-Signing Certificate Attack
GoldenEyeDog, a Chinese cybercrime group increasingly tracked as an advanced threat cluster, has been linked to a sophisticated intrusion into DigiCert that enabled the theft and abuse of legitimate code-signing certificates. The group has been active since at least 2015 and, since 2024, has consistently leveraged stolen or abused code-signing certificates to bypass Windows SmartScreen…
-
More alerts are making your team slower, and an outcome-based SOC fixes that
In this Help Net Security video, Thom Langford, EMEA CTO, Rapid7, explains why piling on more security alerts makes a SOC slower to respond. Attackers log in with stolen … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/07/20/outcome-based-soc-video/
-
Your Period Tracker Is (Probably) Spying on You
Plus: Russian cyberspies turn to infrastructure hacking, DHS repeatedly fails to realize it’d been hacked, a breach exposes an AI music generator’s scraping ways, and more. First seen on wired.com Jump to article: www.wired.com/story/security-news-this-week-your-period-tracker-is-probably-spying-on-you/
-
Ernst Young (EY) Investigates Data Breach Involving Third-Party Support Tickets
Ernst & Young (EY) disclosed a data breach after attackers compromised a third-party IT support system containing client documents and tax information. Ernst & Young (EY) is disclosed a data breach linked to a compromised third-party support ticket system used by its IT teams. The platform stored support requests that may have included documents containing…
-
23andMe Agrees to $18M Settlement With 43 States Over 2023 Data Breach
23andMe will pay $18 million to settle claims from 43 states over its 2023 data breach, which exposed genetic information tied to nearly 7 million people. The post 23andMe Agrees to $18M Settlement With 43 States Over 2023 Data Breach appeared first on TechRepublic. First seen on techrepublic.com Jump to article: www.techrepublic.com/article/news-23andme-18-million-settlement-2023-genetic-data-breach/
-
GoldenEyeDog Subgroup Linked to DigiCert Breach and Code-Signing Certificate Theft
Cybersecurity researchers have attributed the April 2026 DigiCert security incident to a threat activity cluster dubbed CylindricalCanine.Expel, which shared technical details of the event, described the threat actor as a sub-group of GoldenEyeDog (aka APT-Q-27, Dragon Breath, and Miuuti Group), a Chinese cybercrime group known for its targeting of the gambling and gaming sectors using…
-
Ransomware attack forces Coca-Cola to suspend US production at dairy unit
The beverage company is still working to determine the full scope of the breach at its Fairlife business. First seen on cybersecuritydive.com Jump to article: www.cybersecuritydive.com/news/ransomware-attack-coca-cola-suspend-production-dairy/825540/
-
23andMe Faces New Security Mandates in $18m Data Breach Settlement
23andMe has agreed to an $18m settlement with 42 US attorneys general over its 2023 data breach, including enhanced data protection requirements First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/23andme-18m-data-breach-settlement/

