Tag: data-breach
-
Beacon CRM confirms cyberattack exposed UK charity data
First seen on scworld.com Jump to article: www.scworld.com/brief/beacon-crm-confirms-cyberattack-exposed-uk-charity-data
-
Brazil’s health system data exposed online
First seen on scworld.com Jump to article: www.scworld.com/brief/brazils-health-system-data-exposed-online
-
Top 10 Best External Attack Surface Management (EASM) Platforms 2026
In the sprawling digital ecosystem of 2026, organizations grapple with an increasingly complex and often poorly understood external attack surface. This attack surface encompasses all internet-facing assets that are discoverable and potentially exploitable by malicious actors. These assets extend far beyond traditional network perimeters to include cloud resources, web applications, APIs, orphaned infrastructure, exposed databases,…
-
Despite federal warnings, thousands of U.S. industrial controllers used in water systems remain exposed online
A scan of internet-connected industrial equipment found 4,400 exposed PLCs, including 22 in cities recently targeted by water system attacks. First seen on cyberscoop.com Jump to article: cyberscoop.com/exposed-rockwell-controllers-water-system-attacks/
-
Exposed SISVISA Database Leaks 102,000 Brazilian Health Surveillance Records
An exposed SISVISA database leaked 102,215 Brazilian health records, exposing IDs, tax data, and regulatory documents without authentication. Researcher Jeremiah Fowler found a publicly accessible database that turned out to belong to SISVISA, Brazil’s Health Surveillance Information System, and alerted ExpressVPN, which later shared the findings with Hackread. The exposed instance held exactly 102,215 files,…
-
New Zapscape KVM Flaw Could Let Privileged L1 Guest Code Escape to Linux Hosts
Zapscape, a new Linux kernel vulnerability, could allow an attacker with kernel privileges inside an L1 guest virtual machine (VM) to escape KVM isolation and execute code on the host. The risk applies when nested virtualization is exposed to untrusted guests.The flaw is tracked as CVE-2026-64561 and affects KVM/x86’s shadow memory management unit (MMU), which…
-
ThreatsDay: Odysseus RCE, Samsung One-Click Takeover, iCloud Backdoor Fight + 27 More Stories
Apparently, opening the thing is now enough. A repo can run before the first prompt, a package can hide among hundreds, and a harmless-looking PDF can finish the job.This week runs on cheap leverage: exposed servers, recycled bugs, poisoned agent instructions, remote-access tools dressed as support software, and trusted defaults doing attackers a favor.Nothing here…
-
How AI Exposed a Browser Security Gap that Enterprises Cannot Ignore
AI did not create a new browser security problem. It exposed one that enterprises have long been able to ignore. Skyhigh Security explains why browsers have become a critical control point for governing data movement, AI interactions, and modern work. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/how-ai-exposed-a-browser-security-gap-that-enterprises-cannot-ignore/
-
Critical Paperclip AI Agent Flaws Allow Unauthenticated Remote Code Execution
Critical vulnerabilities in the open-source Paperclip AI-agent orchestration platform could allow attackers to execute commands remotely on exposed servers or on a developer’s local machine. These flaws arise from broken authorization boundaries across agent imports and API routes, as well as trust assumptions for localhost. Paperclip is designed to coordinate autonomous agents across >>companies,<< with…
-
Over 4,400 Rockwell PLCs Exposed Online, 22 Found in Water Attack Cities
Forescout found 22 internet-facing Rockwell Automation programmable logic controllers (PLCs) in cities hit by recent cyberattacks on US water utilities. Nineteen used the same mobile carrier network.Its August 3 scan counted 4,407 exposed Rockwell controllers worldwide, including 2,844 in the United States, but Forescout could not confirm any were compromised. That figure counts exposed First…
-
CISA Alerts Issues on Actively Exploited TeamCity Remote Code Execution Vulnerability
Tags: cisa, cve, cyber, cybersecurity, data-breach, exploit, flaw, infrastructure, kev, rce, remote-code-execution, vulnerabilityThe U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical vulnerability in JetBrains TeamCity, tracked as CVE-2026-63077, to its Known Exploited Vulnerabilities (KEV) catalog due to evidence of active exploitation. This flaw allows unauthenticated remote code execution (RCE) on vulnerable TeamCity On-Premises servers exposed via HTTP or HTTPS. CISA Issues on TeamCity RCE…
-
Snowflake Hacker Pleads Guilty Over Breaches Affecting at Least 100 Million People
Connor Riley Moucka pleaded guilty in Seattle federal court on Wednesday to computer fraud, wire fraud, aggravated identity theft and a related conspiracy over the 2024 breaches of Snowflake customer accounts.The intrusions reached at least 165 organizations and exposed records belonging to at least 100 million people. Moucka, 26, of Kitchener, Ontario, personally took at…
-
VanishID Previews AI Exploitability Management at Black Hat USA 2026
VanishID has unveiled AI Exploitability Management, a capability designed to measure what frontier AI could build from publicly exposed information about an organization’s people. The company is demonstrating the capability publicly for the first time at Black Hat USA 2026. VanishID said the system evaluates more than 40 AI-powered attack scenarios, including executive impersonation, real-time..…
-
Flooding Dropper Hits npm With 850 Malicious Packages
Tags: attack, automation, cloud, container, control, credentials, cvss, data-breach, detection, dns, endpoint, github, guide, infrastructure, linux, macOS, malicious, malware, monitoring, software, threat, windows<div cla TL;DR Sonatype Research Labs is tracking an active malicious package campaign, dubbed ‘Flooding Dropper,’ spreading on npm, currently impacting 846 software components. The attacker appears to be automating parts of the npm account and package creation process, combining terms such as bigops and bnpl with other words and recurring version patterns, such as releases…
-
Mini Shai-Hulud npm Attack: More Than 2,200 Components Impacted
Tags: access, ai, attack, breach, cloud, container, control, credentials, data, data-breach, github, guide, infection, intelligence, kubernetes, malicious, malware, microsoft, open-source, risk, sbom, service, software, threat, update<div cla TL;DR A new wave of the Shai-Hulud malicious package campaign emerged on npm, with 2,225 software component versions impacted. The malware executes through a malicious preinstall hook, steals npm, GitHub, cloud, Kubernetes, Vault, CI/CD, and other credentials, then uses stolen publishing access to compromise additional packages. Organizations that installed an affected version should…
-
Beacon CRM, Widely Used by Charities, Suffers Data Breach
English National Ballet is Among the Confirmed Victims Notifying Supporters. Cloud-based customer relationship management software provider Beacon CRM said it’s suffered a security breach that likely led to the theft of customer data. Over 1,000 charities use the software, and English National Ballet and the Centre for Sustainable Energy report they’ve been affected. First seen…
-
Brown Health Medical Group-MA Data Breach Exposes Information of 311,000 Individuals
Brown Health Medical Group-MA breach exposed personal, medical, and financial data of over 311,000 individuals after hackers accessed its servers. Brown Health Medical Group-MA data breach exposed personal, medical, and financial data of over 311,000 individuals after hackers accessed its servers. The healthcare group identified a data security breach involving a legacy file server on…
-
Dutch retailer De Bijenkorf warns customer data may be exposed after cyber incident
Amsterdam-based luxury goods chain De Bijenkorf is the latest retailer to announce a cyber incident involving a third-party logistics provider. First seen on therecord.media Jump to article: therecord.media/de-bijenkorf-luxury-retailer-third-party-cyber-incident
-
Arctic Wolf gibt CyberReadiness-Accelerator für Partner bekannt
Arctic Wolf gibt die Verfügbarkeit des <> bekannt. Das neue, partnergeführte Programm unterstützt Unternehmen dabei, Cyberrisiken besser zu verstehen und ihre Widerstandsfähigkeit in einer zunehmend von KI beschleunigten Bedrohungslandschaft zu stärken. Trotz Vulnerability- und Patch-Management bleiben Unternehmen unbekannten Risiken durch blinde Flecken innerhalb ihrer Angriffsfläche ausgesetzt, Tendenz steigend. Laut dem weltweiten Verizon-2026-Data-Breach- […] First seen…
-
Paperclip AI Flaws Let Unauthenticated Attackers Run Commands
3 Paperclip flaws exposed data & allowed unauthenticated command execution in two deployment modes First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/paperclip-ai-vulnerabilities-rce/
-
Leaked n8n API Tokens Exposed Live Instances to Credential Theft
GitGuardian researchers found 321 n8n instances accepting API tokens exposed in public GitHub commits and demonstrated four ways attackers could use them to access sensitive data and downstream credentials without exploiting a software vulnerability.We scanned public GitHub commits for exposed n8n API tokens and identified 4,576 unique credentials associated with 1,255 hostnames. Of the 896…
-
Brazil Health Surveillance Database Exposed 79GB of Sensitive Records
Brazil’s SISVISA health surveillance system left 102,215 files totaling 79GB open online, including tax IDs and identity documents, without password protection. First seen on hackread.com Jump to article: hackread.com/brazil-health-surveillance-database-exposed-records/
-
Worm Targets More Than 2,000 npm Package Versions
Attackers Compromised Keyv and Cacheable Source or Release Credentials. A self-replicating npm worm linked by tradecraft to Shai-Hulud has compromised more than 2,000 versions of 444 packages, stealing cloud and CI credentials and using exposed publisher tokens to spread through trusted dependencies. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/worm-targets-more-than-2000-npm-package-versions-a-32412
-
Securing Agentic AI Workflows in n8n: From Leaked API Keys to Encryption Key Compromise
A leaked n8n API key is only the start. GitGuardian’s research traces the full chain, from exposed tokens and weak keys to CVE-2026-25053 and the N8N_ENCRYPTION_KEY that protects every stored credential, then lays out a hardened configuration to break it. First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/08/securing-agentic-ai-workflows-in-n8n-from-leaked-api-keys-to-encryption-key-compromise/
-
DarkSword Server Combines iPhone Exploits With Fake Apple ID Login Page
Tags: apple, credentials, cyber, data-breach, exploit, google, group, intelligence, iphone, login, risk, threatDarkSword’s leaked iOS exploit chain is now powering a fast”‘moving server cluster that marries one”‘click Safari exploitation with a convincing fake Apple ID login page, putting millions of iPhone users at risk of seamless device compromise and credential theft. Originally disclosed by Google Threat Intelligence Group, iVerify, and Lookout, the kit was later leaked to…
-
Russian Access Broker Sells Network Access to Ransomware Gangs While Spying on Ukraine
Tags: access, cyber, data-breach, defense, exploit, intelligence, network, ransomware, russia, ukraineAn exposed server linked to a Russian”‘speaking initial access broker (IAB) has revealed a sprawling operation that simultaneously fuels ransomware intrusions worldwide and supports Russian state-aligned intelligence collection against Ukrainian defense and aerospace targets. The artefacts show a mature, high”‘volume access brokerage pipeline that industrialises exploitation of internet”‘facing appliances, pivots to full Active Directory compromise,…
-
18 Malicious npm Packages Deploy Cross-Platform RAT Against Alibaba Developers
18 malicious npm packages have been used in a tightly coordinated software supply chain attack to deliver a cross”‘platform RAT that specifically targets developers working with Alibaba’s internal Aone tooling and @ali-scoped packages. The operation came to light after researchers analyzed a seemingly simple malicious npm package, lib-mtop, which acted as a downloader and exposed…
-
PNLD Data Breach Exposes Police and Government Contact Details on Dark Web
The PNLD data breach has exposed contact information belonging to police officers, government partners, criminal justice professionals and customers after data from the Police National Legal Database (PNLD) was published on the dark web. The data breach at PNLD, identified on July 26, 2026, also affected some users of Ask the Police, raising concerns about targeted phishing attacks. First seen on thecyberexpress.com Jump to…
-
31,000 Records Compromised in Breach of Liechtenstein Companies and Foundations Register
Cyberattack exposed data of 31,000 people in Liechtenstein’s beneficial ownership register for companies and foundations. A cyberattack compromised data belonging to about 31,000 people in Liechtenstein’s register of beneficial owners linked to companies, foundations, and trusts. Liechtenstein’s Register of People Behind Companies and Foundations is a government-maintained register of beneficial ownership. Its purpose is to…
-
UK’s Police National Legal Database Reveals Data Breach
The UK’s Police National Legal Database and Ask the Police service have been breached First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/uks-police-national-legal-database/

