Tag: data-breach
-
Researchers Expose Flying Eagle Criminal Ecosystem Behind Fake Chinese Police App
Researchers linked the Flying Eagle Android RAT to fake police apps, uncovering 170 servers in a growing cybercrime ecosystem. Hunt.io researchers and independent journalist NetAskari started with a fraudulent Android app impersonating a Chinese Provincial Public Security Bureau service and ended up mapping a sprawling criminal ecosystem built around a leaked Android RAT framework called…
-
South Korea fines telco giant KT $39 million for customer data breach
South Korea’s Personal Information Protection Commission (PIPC) has fined telecommunications giant KT Corporation KRW 53.979 billion ($39 million) over data protection violations. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/south-korea-fines-telco-giant-kt-39-million-for-customer-data-breach/
-
A Leaked Memo Ties Cyberattacks on Minnesota Water Utilities to Iran
A memo obtained by WIRED, issued by the water utilities information sharing group WaterISAC, links dozens of cyberattacks against Minnesota water utilities to Tehran. First seen on wired.com Jump to article: www.wired.com/story/a-leaked-memo-ties-cyberattacks-on-minnesota-water-utilities-to-iran/
-
Semiconductor chip titan Analog Devices reports data breach
In a filing for federal regulators, Massachusetts-based Analog Devices said intruders had exfiltrated data from its networks earlier this summer, but the scope of the incident is still under investigation. First seen on therecord.media Jump to article: therecord.media/analog-devices-semiconductor-company-data-breach
-
Thousands of Data Center Controllers Open to Takeover
A host of Internet-exposed remote hardware management processors are subject to offline password-cracking attacks, and adversaries have taken note. First seen on darkreading.com Jump to article: www.darkreading.com/cyber-risk/flaw-exposes-data-centers-server-takeover
-
Here’s what Anthropic found when it turned Mythos loose on encryption algorithms
Claude Mythos exposed mathematical weaknesses in a post-quantum candidate and a simplified version of AES, marking a major breakthrough for AI-driven cryptanalysis. First seen on cyberscoop.com Jump to article: cyberscoop.com/anthropic-claude-mythos-encryption-flaws-hawk-aes-pqc/
-
Here’s what Anthropic found when it turned Mythos loose on encryption algorithms
Claude Mythos exposed mathematical weaknesses in a post-quantum candidate and a simplified version of AES, marking a major breakthrough for AI-driven cryptanalysis. First seen on cyberscoop.com Jump to article: cyberscoop.com/anthropic-claude-mythos-encryption-flaws-hawk-aes-pqc/
-
Flaw From 2002 Exposes Data Centers to Server Takeover
Lots of Internet-exposed server management controllers are subject to offline password-cracking attacks, and adversaries have taken note. First seen on darkreading.com Jump to article: www.darkreading.com/cyber-risk/flaw-exposes-data-centers-server-takeover
-
Your Money Was Never the Target. Your Identity Was
Identity Theft, Not Transaction Systems, Now Drives the Biggest Banking Fraud Risks Bank of Baroda’s recent breach shows why core systems unaffected is no longer enough. While transactions remained secure, leaked KYC data can fuel mule accounts, synthetic identity fraud and account takeovers, making customer identity – not banking infrastructure – the real target. First…
-
ShinyHunters Claims Ernst Young (EY) Data Breach, Threatens July 31 Leak
EY confirmed the theft of client tax documents from its third-party support platform. ShinyHunters claims responsibility and is threatening to publish the data. First seen on hackread.com Jump to article: hackread.com/shinyhunters-ernst-young-ey-data-breach-threat-leak/
-
24,650 Internet-Exposed BMCs Disclose IPMI Password Hashes Before Login
Cybersecurity researchers have sounded an alert after finding more than 36,000 Baseboard Management Controller (BMC) management interfaces exposing Intelligent Platform Management Interface (IPMI) protocol to the public internet.Of the 36,872 internet-exposed server-management interfaces running IPMI, 24,650 have been found to disclose password-derived authentication hashes before login due to First seen on thehackernews.com Jump to article:…
-
Exposed BMCs hand out password hashes before login
An attacker who reaches UDP port 623 on a server’s baseboard management controller can ask it for a password hash and receive one before logging in. The exchange is part … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/07/28/exposed-bmc-ipmi-vulnerability-research/
-
Over 24,000 exposed server BMCs leak password hash via decades-old flaw
More than 24,000 internet-exposed servers are leaking authentication password hashes due to a 20-year-old vulnerability in their Baseboard Management Controller (BMC) interface. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/over-24-000-exposed-server-bmcs-leak-password-hash-via-decades-old-flaw/
-
Dismantled Kratos Phishing Kit Becomes Blueprint for Attacks on Microsoft 365 Users
The takedown of the Kratos phishing-as-a-service (PhaaS) platform in July 2026 has done little to slow the broader threat landscape. As security researchers warn that its leaked techniques and infrastructure patterns are already being repurposed in ongoing campaigns targeting Microsoft 365 environments. Despite being disrupted under Operation Olympus Blade, which led to the seizure of…
-
Coca-Cola Reveals Subsidiary Fairlife Suffered Data Breach
Coca Cola claims data was stolen from its Fairlife business after a recent ransomware attack First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/coca-cola-subsidiary-fairlife-data/
-
Origin Energy Data Breach Affects 900,000 Current and Former Customers
The Origin Energy data breach has affected approximately 900,000 current and former customers after Australia’s largest energy retailer confirmed unauthorized access to customer information. The company also revealed it had received a warning about the potential breach weeks before it publicly disclosed the incident. First seen on thecyberexpress.com Jump to article: thecyberexpress.com/origin-energy-data-breach-900000-customers/
-
Data breach at medical billing firm MCBS affects 1.26 million people
Healthcare billing company Medical Computer Business Services (MCBS) has disclosed that a 2025 network breach exposed the sensitive information of more than 1.2 million people. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/data-breach-at-medical-billing-firm-mcbs-affects-126-million-people/
-
Persönliche Daten geleakt: Unzählige Claude-Chats bei Google aufgetaucht
Claude-Nutzer können Links zu ihren Chats mit anderen Personen teilen. Die Unterhaltungen wurden bis vor kurzem aber auch bei Google gelistet. First seen on golem.de Jump to article: www.golem.de/news/persoenliche-daten-geleakt-unzaehlige-claude-chats-bei-google-aufgetaucht-2607-211338.html
-
ShinyHunters Claims EY Data Breach, Threatens to Leak Stolen Client Tax Data
ShinyHunters has claimed responsibility for the data breach at Ernst & Young (EY) and is threatening to publish allegedly stolen client tax information unless the professional services firm engages in negotiations before July 31, 2026. The extortion group posted about EY on its dark web leak site, describing the deadline as a “final warning” and…
-
OnTrac parcel delivery company reports customer data breach
First seen on scworld.com Jump to article: www.scworld.com/brief/ontrac-parcel-delivery-company-reports-customer-data-breach
-
Private Claude Chats Exposed in Google and Bing Search Results
The screwup shows how tricky it can be to stop web crawlers from making ostensibly private conversations with AI chatbots entirely too public. First seen on wired.com Jump to article: www.wired.com/story/private-claude-chats-exposed-in-google-and-bing-search-results/
-
Bank of Baroda Breach Tests Disclosure Readiness
Email Compromise Exposes Sensitive Data, Raising DPDP Act Compliance Questions. A Bank of Baroda employee email compromise exposed customer and internal data allegedly leaked by the Triple X ransomware group. The incident shows how India’s new DPDP Act breach notification rules test banks’ readiness to disclose cyber incidents quickly and transparently. First seen on govinfosecurity.com…
-
Ernst & Young data breach claimed by ShinyHunters extortion gang
The ShinyHunters extortion gang has claimed responsibility for a recently disclosed Ernst & Young data breach, saying it obtained credentials for some of the company’s systems via a supply-chain attack. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/ernst-and-young-data-breach-claimed-by-shinyhunters-extortion-gang/
-
Origin Energy Data Breach Exposes Customer and Partial Card Details
Origin Energy confirms hackers stole customer and partial payment-card data, but the number affected and the method of access remain unknown. The post Origin Energy Data Breach Exposes Customer and Partial Card Details appeared first on TechRepublic. First seen on techrepublic.com Jump to article: www.techrepublic.com/article/news-origin-energy-customer-data-breach/
-
âš¡ Weekly Recap: Rogue AI Agents, Check Point Exploit, Slopsquatting, ClickFix Lures and More
Monday starts with the usual promise that everything is under control. Then the logs wake up.This week, trusted tools crossed lines, old flaws found new work, exposed systems stayed exposed, and attackers kept hiding inside normal-looking services. Nothing looked strange at first. That helped.That is the mood. Here is the full recap.âš¡ Threat of the…
-
DentaQuest disclosed a data breach that impacted +23 million individuals
DentaQuest disclosed a data breach that may have exposed the personal and dental health information of more than 23 million people. DentaQuest is notifying more than 23 million people of a data breach after hackers accessed its network in May 2026. The incident may have exposed customers’ personal information and dental health data. DentaQuest, part…
-
Anyone With a Browser Could Access 700,000 Vatican Prayer App Accounts
A critical access control vulnerability in the Vatican’s official “Click to Pray” platform has exposed the personal data of more than 700,000 users, highlighting once again how basic web security misconfigurations continue to put large-scale user bases at risk. The service, operated by the Pope’s Worldwide Prayer Network, is widely used across the globe to…
-
BlueNoroff Fake Meeting Kit Captures Webcams, Disables Defender and Steals Cryptocurrency Credentials
BlueNoroff, a financially motivated threat cluster linked to the Lazarus Group, has been observed deploying a highly sophisticated “fake meeting” phishing kit. That goes far beyond traditional lures, enabling webcam capture, Microsoft Defender evasion, and targeted cryptocurrency credential theft. New research from JUMPSEC provides rare source-level visibility into the operation after attackers mistakenly exposed JavaScript…
-
Google Indexed Claude AI Shared Chats Exposing Sensitive User Conversations
Anthropic’s Claude includes a share feature that creates a publicly accessible URL for conversations, allowing users to share AI chats with colleagues, clients, or friends. However, this convenience also brings exposure risks when shared URLs are posted in public forums, on social media platforms, web pages, or other crawlable locations. Claude AI Shared Chats Exposed…
-
Weekly Cybersecurity Newsletter Top 50 Biggest Cybersecurity Stories SonicWall Zero-Day, Cl0p Windchill Attack, AI-Weaponized Threats, Data Breaches More
Welcome to this week’s edition of the GBHackers cybersecurity newsletter, your weekly cybersecurity bulletin covering the 50 most important stories from July 2024, 2026. It was a heavy week: Cl0p turned internet-exposed Windchill servers into a global data-theft campaign, attackers rode SonicWall SMA zero-days to root, a Bluetooth flaw put 2 million cars at […]…

