Tag: breach
-
80,000+ Organizations Had AI Logins Stolen: From Shadow AI to LLMjacking
Infostealer logs exposed AI account credentials and sessions tied to more than 80,000 corporate domains, creating risks ranging from stolen conversations to LLMjacking. SOCRadar examines the growing market for stolen AI logins and how organizations can identify their exposure. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/80-000-plus-organizations-had-ai-logins-stolen-from-shadow-ai-to-llmjacking/
-
Researchers Discover Cybercrime Server Containing AI Tools, Phishing Kits and Stolen Data
Tags: ai, breach, control, credentials, cyber, cybercrime, data, data-breach, infrastructure, Internet, phishing, toolAn internet-exposed cybercrime server linked to the BlackHatSect0r and DXQRTXX personas, revealing an operational environment that allegedly combined AI-assisted automation. Custom command-and-control tooling, phishing resources, stolen credentials, target lists, and internal operator communications. The exposure is notable not only for the scale of the material recovered, but also for its irony. Weeks later, infrastructure attributed…
-
Storm-3168, Linked to JADEPUFFER, Abused Stolen Azure Identities
Microsoft details Storm-3168, the JADEPUFFER-linked actor that used stolen service principals to delete Azure storage in minutes and harvest keys. Microsoft just published the first detailed look at what JADEPUFFER does inside Azure. Sysdig first spotted the group’s activity in July 2026 and called it the first documented agentic ransomware operation. Microsoft tracks the same…
-
OpenAI Pauses Training Its Most Powerful Models After Rogue Agents Target Government
Sam Altman says the company “have not been as fast as we would have liked” at dealing with security breaches, after news of further incidents over the summer forces another temporary halt. First seen on wired.com Jump to article: www.wired.com/story/openai-pauses-training-most-powerful-models-after-rogue-agents-target-government/
-
Rydox Admin Faces 20 Years After Selling Stolen Data and Fraud Tools
Kosovo national Ardit Kutleshi pleaded guilty to running Rydox, a cybercrime marketplace that sold stolen identities and credentials for years. Ardit Kutleshi, 28 years old and a citizen of Kosovo, pleaded guilty last week to building and running the cybercrime marketplace Rydox. The Rydox marketplace has been active since February 2016; it facilitated over 7,600…
-
Week in review: Gyazo breach exposes 23.6M user data, TASK#STOMP steals documents
Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: Know what was tested before your SAP ECC migration goes live In this Help Net … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/09/27/week-in-review-gyazo-breach-exposes-23-6m-user-data-taskstomp-steals-documents/
-
Investigative journalist seeks damages from police over unlawful phone surveillance
Northern Ireland journalist subject to unlawful communications surveillance seeks damages from police in Northern Ireland in high court claim for data protection breaches and harassment First seen on computerweekly.com Jump to article: www.computerweekly.com/news/366651203/Investigative-journalist-seeks-damages-from-police-over-unlawful-phone-surveillance
-
The Cyber Express Weekly Roundup: ShinyHunters’ FBI Breach Claim, North Korea’s WaterPlum Campaign, and the EU KIDS Act
Tags: access, advisory, ai, application-security, breach, crypto, cyber, korea, malware, north-koreaThis weekly roundup covers a brazen breach claim against the FBI’s recruitment portal, a multinational advisory exposing North Korea’s fake-recruiter malware operation, a sweeping EU proposal to reshape children’s access to social media, a conversation on application security in the age of AI agents, a short-lived Discord ban in the Philippines, and a multimillion-dollar hot-wallet…
-
Rydox marketplace admin pleads guilty, faces 22 years in prison
A Kosovar national has pleaded guilty to operating Rydox, a large illegal online marketplace that sold stolen personal information, login credentials, credit card details, and cybercrime tools. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/rydox-marketplace-admin-pleads-guilty-faces-22-years-in-prison/
-
Rydox marketplace admin pleads guilty, faces 22 years in prison
A Kosovar national has pleaded guilty to operating Rydox, a large illegal online marketplace that sold stolen personal information, login credentials, credit card details, and cybercrime tools. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/rydox-marketplace-admin-pleads-guilty-faces-22-years-in-prison/
-
Rydox marketplace admin pleads guilty, faces 22 years in prison
A Kosovar national has pleaded guilty to operating Rydox, a large illegal online marketplace that sold stolen personal information, login credentials, credit card details, and cybercrime tools. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/rydox-marketplace-admin-pleads-guilty-faces-22-years-in-prison/
-
Duelbits Hit by $7 Million Hack as Crypto Stolen Across Four Blockchains
Crypto casino Duelbits has shut down its platform after attackers took roughly $7 million from several of its wallets. In the Duelbits crypto hack, the stolen assets were moved across four blockchains, and most of them were then converted into Ether. First seen on thecyberexpress.com Jump to article: thecyberexpress.com/duelbits-crypto-hack-7m-stolen-casino-offline/
-
Hackers steal $351.6 million in Bitget crypto exchange hack
Cryptocurrency exchange Bitget disclosed today that suspected North Korean hackers have stolen $351.6 million from its hot and warm wallets. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/hackers-steal-3516-million-in-bitget-crypto-exchange-hack/
-
Duelbits Hot Wallet Hack Drains $7 Million, Forces Platform Offline
Crypto casino Duelbits has confirmed a cybersecurity breach that drained approximately $7 million from its hot wallets. In response, the company has taken its platform offline while it investigates the incident. Co-founder Joe said they are still determining “exactly what happened and how,” while assuring customers their funds are safe. Multi-Chain Wallet Drain The incident…
-
Australia sets up taskforce after OpenAI agent breaches statistics portal
Prime minister Anthony Albanese says OpenAI did not alert the government until almost three months after one of its AI agents got around blocks on a Medicare statistics portal, and even then only by emailing a public mailbox First seen on computerweekly.com Jump to article: www.computerweekly.com/news/366651163/Australia-sets-up-taskforce-after-OpenAI-agent-breaches-statistics-portal
-
Bitget Confirms $351.6 Million Hack, Suspects North Korea’s Lazarus Group
Bitget confirms a $351.6 million theft, suspends withdrawals and says North Korea’s Lazarus Group may be involved as investigators examine the breach in detail. First seen on hackread.com Jump to article: hackread.com/bitget-hack-suspects-north-korea-lazarus-group/
-
Bitget Confirms $351.6 Million Hack, Suspects North Korea’s Lazarus Group
Bitget confirms a $351.6 million theft, suspends withdrawals and says North Korea’s Lazarus Group may be involved as investigators examine the breach in detail. First seen on hackread.com Jump to article: hackread.com/bitget-hack-suspects-north-korea-lazarus-group/
-
Breach Roundup: Thousands of AI Relays Hide China Users
Tags: ai, breach, china, cisa, cve, cybercrime, data, data-breach, flaw, google, jobs, north-korea, russia, scam, vpnAlso, CISA Ends Weekly CVE Bulletin After 22 Years, Check Point VPN Flaw Exploited. This week: AI relay servers connect to China, CISA ends weekly CVE bulletin, cybercriminal guilty pleas and sentences, drug dealers hijack Google Maps, Russian Burger King customers’ data leaked, North Korean fake job scams, SectopRAT, a Check Point VPN flaw and…
-
Lawmakers introduce bill for voluntary telecom cyber rules after Salt Typhoon hacks
U.S. Sens. Mark Warner (D-VA) and Ted Cruz (R-TX) introduced the Telecommunications Cybersecurity and Resilience Act on Thursday, arguing that the new effort was necessary in light of the Salt Typhoon attacks which saw Chinese hackers breach nearly all of the major telecommunications giants in the U.S. First seen on therecord.media Jump to article: therecord.media/lawmakers-introduce-bill-for-voluntary-telecom-cyber-rules
-
Rydox cybercriminal marketplace operator pleads guilty following co-conspirator brothers’s deportation
Ardit Kutleshi, 28, was extradited from his home country of Kosovo last year after prosecutors accused him and his older brother of running Rydox, an illicit platform used by cybercriminals to sell stolen personal information, illegal access to devices and other tools for carrying out fraud. First seen on therecord.media Jump to article: therecord.media/rydox-criminal-marketplace-operator-pleads-guilty
-
Astrana latest healthcare tech firm to report data breach to SEC
The healthcare firm Astrana warned regulators that hackers accessed confidential information by impersonating company personnel. First seen on therecord.media Jump to article: therecord.media/astrana-cyberattack-sec-ransomware
-
Australia to investigate if OpenAI hack of government health website broke the law
The incident is the first known breach to affect a government agency, and Australia’s prime minister has vowed to hold OpenAI accountable. First seen on techcrunch.com Jump to article: techcrunch.com/2026/09/24/australia-to-investigate-if-openai-hack-of-government-health-website-broke-the-law/
-
OpenAI AI Agent Breaches Australian Government Website, Albanese Demands Answers
Australian Prime Minister Anthony Albanese has demanded answers from OpenAI chief executive Sam Altman after an AI agent broke into an Australian government website. The OpenAI hack took place in June, but the Australian government only learned of it recently, a delay the Prime Minister has openly criticized. First seen on thecyberexpress.com Jump to article:…
-
Shiny Hunters Claim FBI Breach, Offer Sample of Alleged Stolen Data
The FBI is investigating an apparent breach of its networks after the cybercriminal group Shiny Hunters claimed on Tuesday to have stolen personal data belonging to thousands of federal agents. Two sources familiar with the matter confirmed the probe, which centers on the bureau’s FBIjobs recruitment website. First seen on thecyberexpress.com Jump to article: thecyberexpress.com/shiny-hunters-fbi-breach-fbijobs-agent-data/
-
ShinyHunters claims FBI hack, data theft in PeopleSoft zero-day breach
The ShinyHunters extortion gang claims it breached FBI systems using a new Oracle PeopleSoft zero-day vulnerability, gaining access to internal services and stealing sensitive data on employees and job applicants. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/shinyhunters-claims-fbi-hack-data-theft-in-peoplesoft-zero-day-breach/
-
Shai-Hulud Attack Nips Cyber-Firm CrowdSec’s GitHub Data
Threat actors stole 170 private repositories using an OAuth token stolen from a former employee’s computer through the TanStack npm supply chain attack. First seen on darkreading.com Jump to article: www.darkreading.com/cyberattacks-data-breaches/shai-hulud-attack-cyber-firm-crowdsec-github-data
-
ShinyHunters Hacked Cl0p. Now What About Cl0p’s Victims?
ShinyHunters defaced Cl0p’s Dark Web site and claims to have stolen victim data, potentially exposing organizations that paid ransoms to renewed extortion attempts. First seen on darkreading.com Jump to article: www.darkreading.com/cyberattacks-data-breaches/shinyhunters-hacked-clop-what-about-clops-victims
-
Stolen passwords are exposing America’s water providers to hackers
Researchers say another looming threat hangs over some of America’s most important critical infrastructure. First seen on techcrunch.com Jump to article: techcrunch.com/2026/09/22/stolen-passwords-are-exposing-americas-water-providers-to-hackers/

