Tag: data-breach
-
Worm Targets More Than 2,000 npm Package Versions
Attackers Compromised Keyv and Cacheable Source or Release Credentials. A self-replicating npm worm linked by tradecraft to Shai-Hulud has compromised more than 2,000 versions of 444 packages, stealing cloud and CI credentials and using exposed publisher tokens to spread through trusted dependencies. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/worm-targets-more-than-2000-npm-package-versions-a-32412
-
Securing Agentic AI Workflows in n8n: From Leaked API Keys to Encryption Key Compromise
A leaked n8n API key is only the start. GitGuardian’s research traces the full chain, from exposed tokens and weak keys to CVE-2026-25053 and the N8N_ENCRYPTION_KEY that protects every stored credential, then lays out a hardened configuration to break it. First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/08/securing-agentic-ai-workflows-in-n8n-from-leaked-api-keys-to-encryption-key-compromise/
-
DarkSword Server Combines iPhone Exploits With Fake Apple ID Login Page
Tags: apple, credentials, cyber, data-breach, exploit, google, group, intelligence, iphone, login, risk, threatDarkSword’s leaked iOS exploit chain is now powering a fast”‘moving server cluster that marries one”‘click Safari exploitation with a convincing fake Apple ID login page, putting millions of iPhone users at risk of seamless device compromise and credential theft. Originally disclosed by Google Threat Intelligence Group, iVerify, and Lookout, the kit was later leaked to…
-
Russian Access Broker Sells Network Access to Ransomware Gangs While Spying on Ukraine
Tags: access, cyber, data-breach, defense, exploit, intelligence, network, ransomware, russia, ukraineAn exposed server linked to a Russian”‘speaking initial access broker (IAB) has revealed a sprawling operation that simultaneously fuels ransomware intrusions worldwide and supports Russian state-aligned intelligence collection against Ukrainian defense and aerospace targets. The artefacts show a mature, high”‘volume access brokerage pipeline that industrialises exploitation of internet”‘facing appliances, pivots to full Active Directory compromise,…
-
18 Malicious npm Packages Deploy Cross-Platform RAT Against Alibaba Developers
18 malicious npm packages have been used in a tightly coordinated software supply chain attack to deliver a cross”‘platform RAT that specifically targets developers working with Alibaba’s internal Aone tooling and @ali-scoped packages. The operation came to light after researchers analyzed a seemingly simple malicious npm package, lib-mtop, which acted as a downloader and exposed…
-
PNLD Data Breach Exposes Police and Government Contact Details on Dark Web
The PNLD data breach has exposed contact information belonging to police officers, government partners, criminal justice professionals and customers after data from the Police National Legal Database (PNLD) was published on the dark web. The data breach at PNLD, identified on July 26, 2026, also affected some users of Ask the Police, raising concerns about targeted phishing attacks. First seen on thecyberexpress.com Jump to…
-
31,000 Records Compromised in Breach of Liechtenstein Companies and Foundations Register
Cyberattack exposed data of 31,000 people in Liechtenstein’s beneficial ownership register for companies and foundations. A cyberattack compromised data belonging to about 31,000 people in Liechtenstein’s register of beneficial owners linked to companies, foundations, and trusts. Liechtenstein’s Register of People Behind Companies and Foundations is a government-maintained register of beneficial ownership. Its purpose is to…
-
UK’s Police National Legal Database Reveals Data Breach
The UK’s Police National Legal Database and Ask the Police service have been breached First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/uks-police-national-legal-database/
-
Amgen Tells SEC Hack Exposed Patient Data, Trade Secrets
Drug Maker Says PHI, Research, Confidential Business Data Potentially Stolen. Pharmaceutical maker Amgen has notified the U.S. Securities and Exchange Commission that cybercriminals have potentially stolen a cache of sensitive company data, including patient information, intellectual property, research and development, and other confidential business files. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/amgen-tells-sec-hack-exposed-patient-data-trade-secrets-a-32401
-
Coldcard RNG Flaw Linked to Suspected $88.6M Bitcoin Theft
A Coldcard RNG flaw may have exposed predictable wallet seeds linked to $88.6 million in suspected Bitcoin thefts across 4,585 addresses. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/threats/news-coldcard-rng-flaw-bitcoin-theft/
-
âš¡ Weekly Recap: Rogue AI Models, $88M Bitcoin Theft, Water-System Attacks and Dangling DNS Hijacks
This week kept coming back to permission. A model crossed a boundary. A wallet trusted bad randomness. Webmail kept an intruder around. Public systems, package feeds, hotel networks, and login flows all gave away more than intended.Some of it was clever. Most of it was just access left lying around: old bugs, exposed gear, poisoned…
-
PNLD Confirms Data Breach Affecting UK Police and Justice Staff
UK police legal database breach exposed officers’ names and work emails, increasing phishing risks. NCA is investigating. The Police National Legal Database (PNLD), the legal reference system used by all 43 Home Office police forces in England and Wales, confirmed that a data breach exposed the contact details of police officers, staff, and criminal justice…
-
30 days with Claude Mythos Preview: How Tenable adapted our security program, and why yours is next
Tags: ai, api, attack, business, control, cybersecurity, data, data-breach, endpoint, exploit, flaw, injection, LLM, remote-code-execution, risk, service, threat, tool, update, vulnerabilityTenable spent 30 days running frontier AI models against our own code. It didn’t just find bugs, it proved they’re real, with reproducible exploits. That fundamentally changes code security from ranking potential code defects to a much higher signal focused on the findings that matter. Read on to learn how it reshaped our security team’s…
-
Chinese Threat Actor Uses Leaked DarkSword Kit to Deploy GHOSTBLADE on iOS
An unknown Chinese-threat actor has been observed running a campaign targeting Apple iOS devices by leveraging a publicly leaked version of the DarkSword exploit kit.Attack surface management platform Censys said it identified the threat actor running more than 100 web properties, most of which are fake Amazon Web Services (AWS) sign-in pages on a domain…
-
PNLD Breach Exposes U.K. Police and Government Contact Details on Dark Web
The Police National Legal Database (PNLD) has confirmed that police, government and customer contact information was compromised and published on the dark web.The data included names, organisations and work email addresses belonging to police officers, police staff, criminal justice professionals, government partners and customers.The incident, identified on July 26, also exposed some names First seen…
-
What the Minnesota Water Attacks Reveal About Securing Remote Access to Critical Infrastructure
Tags: access, ai, attack, authentication, cisa, control, corporate, credentials, cyberattack, data-breach, exploit, Hardware, identity, infrastructure, Internet, law, least-privilege, malware, mfa, monitoring, network, password, risk, router, supply-chain, technology, vpn, zero-day, zero-trustWhen headlines break about cyberattacks targeting critical infrastructure, the conversation often turns immediately to zero-day exploits, advanced malware, and other sophisticated techniques. The recent attacks on municipal water systems across at least seven US states, including more than 30 Minnesota water and wastewater utilities, illustrate why this assumption can be misleading. As a “recovering CISO” who…
-
Product showcase: Guardio Mobile Security turns breach alerts into a recovery plan
Guardio Mobile Security brings several protection features to iPhone and Android, allowing users to monitor exposed personal information, identify phishing attempts, and … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/08/03/product-showcase-guardio-mobile-security/
-
CISA Urges Utilities to Remove Internet-Exposed PLCs After Minnesota Attacks
After attacks hit 30+ Minnesota water systems, CISA urged utilities to remove internet-exposed PLCs and strengthen OT security. Between Sunday and Monday, July 26 and 27, a coordinated cyberattack hit operational technology (OT) systems at more than 30 community water utilities across the state, according to Minnesota IT Services (MNIT). “A coordinated cyberattack targeted operational technology…
-
UK’s state investments agency hit by data breach
Security lapse leaves sensitive information and contact details of 51 government officials exposed for 40 hoursThe public body in charge of the UK’s state investments has been pushed to improve its internal security after a data breach left “high-level management information” publicly accessible for nearly two days.UK Government Investments (UKGI), the agency that manages the…
-
KT Corporation fined $39 million for 11-month data breach
First seen on scworld.com Jump to article: www.scworld.com/brief/kt-corporation-fined-39-million-for-11-month-data-breach
-
Amgen says cloud data breach exposed patient health, proprietary info
Pharmaceutical company Amgen says it suffered a data breach after threat actors stole corporate data and patient information stored in multiple cloud systems operated by third-party service providers. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/amgen-says-cloud-data-breach-exposed-patient-health-proprietary-info/
-
CISA warns of spike in attacks on water systems as Minnesota incidents probed
The Cybersecurity and Infrastructure Security Agency said in a public alert on Thursday that facilities should “remove publicly exposed PLCs and other operational technology (OT) from the internet as soon as possible.” First seen on therecord.media Jump to article: therecord.media/cisa-warns-of-spike-in-water-system-attacks
-
Hacker uses DeepSeek AI to autonomously attack vulnerable servers
A Chinese-speaking threat actor is using the DeepSeek AI model and the open-source Hermes Agent to conduct autonomous cyberattacks on exposed servers with limited human involvement. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/hacker-uses-deepseek-ai-to-autonomously-attack-vulnerable-servers/
-
CISA warns of cyberattacks disrupting U.S. water utilities
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) is warning of a significant increase in attacks targeting internet-exposed programmable logic controllers (PLCs) in the water and wastewater systems sector. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/cisa-warns-of-cyberattacks-disrupting-us-water-utilities/
-
Critical JetBrains TeamCity Flaw Enables Unauthenticated Remote Code Execution
Tags: access, authentication, cve, cyber, data-breach, flaw, network, remote-code-execution, risk, vulnerabilityJetBrains has revealed a critical security vulnerability in TeamCity On-Premises that enables unauthenticated remote code execution (RCE) on affected servers. This poses a significant risk to CI/CD environments exposed over HTTP(S). The vulnerability, tracked as CVE-2026-63077, affects all supported versions of TeamCity On-Premises and allows attackers with network access to bypass authentication checks and execute…
-
Healthcare Disruption, Critical Software Flaws, and Exposed PLCs Show How Quickly Cyber Risk Becomes Business Risk
Tags: business, computer, cyber, cyberattack, data-breach, flaw, healthcare, Internet, phone, risk, softwareAnMed temporarily closed 79 of its 106 facilities after a cyberattack disrupted computer systems, phone lines, and internet connectivity. Appointments were postponed, elective procedures faced uncertainty, and the health system had to coordinate care while teams worked to restore access. For a healthcare provider, that kind of disruption reaches far beyond technology. It affects how……
-
ShutterGap Exposes Millions of Misconfigured AWS Resources to Attackers
A cloud-security blind spot known as Cloud ShutterGap, which involves millions of AWS resources being briefly exposed to the public before being removed, often within minutes. These short-lived misconfigurations can include Amazon RDS and DocumentDB snapshots, Amazon Machine Images (AMIs), and AWS Systems Manager (SSM) documents that contain sensitive organizational data. ShutterGap Exposes Millions of…
-
CISA Urges Water Utilities to Remove Publicly Exposed PLCs From the Internet
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued an urgent alert to the Water and Wastewater Systems (WWS) Sector due to a significant rise in cyber threat activity targeting internet-exposed programmable logic controllers (PLCs). Released on July 30, 2026, the advisory urges critical infrastructure owners, operators, and system integrators to immediately identify and…
-
CosmosEscape Vulnerability Enables Full Takeover of Azure Cosmos DB Databases
A critical vulnerability chain in Azure Cosmos DB, named CosmosEscape, allowed attackers to gain full read and write access to every Cosmos DB database, including potentially those managed internally by Microsoft. The issue specifically affected the service’s Gremlin API. It exposed a cross-tenant attack path that could bypass customer network isolation controls. CosmosEscape Vulnerability According…

