Tag: data-breach
-
RustDuck: The Botnet That’s Still Small but Engineering Like It Plans to Grow
RustDuck is a small, evolving DDoS botnet migrating to Rust. It uses advanced encryption, anti-analysis evasion, and exploits known IoT flaws. Since February 2026, researchers at QiAnXin’s XLab have been tracking a new malware family, called RustDuck, that hijacks routers, cameras, Android set-top boxes, and exposed servers, then uses them to flood targets with junk…
-
RedLine Infostealer Thread Reveals Hidden Maritime Phishing and BEC Infrastructure
A routine threat-feed alert for a RedLine Stealer command-and-control (C2) IP morphed into a full-scale pivot investigation that exposed a tailored maritime spear”‘phishing and business email compromise (BEC) ecosystem. The starting signal a UniqueSignal entry from VMRay identified 194[.]156.79.122:55615 as a RedLine-associated host. That solitary indicator, combined with targeted forensic pivots across VirusTotal, FOFA, Censys…
-
Insurance Giant Aflac Discloses Data Breach Impacting Millions
Aflac Japan has notified regulators that policy details and personal and banking information have been compromised First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/insurance-giant-aflac-data-breach/
-
Nissan confirms employee data exposed in Oracle PeopleSoft cyberattack
First seen on scworld.com Jump to article: www.scworld.com/brief/nissan-confirms-employee-data-exposed-in-oracle-peoplesoft-cyberattack
-
KDDI discloses data breach affecting up to 14.2 million customers
First seen on scworld.com Jump to article: www.scworld.com/brief/kddi-discloses-data-breach-affecting-up-to-14-2-million-customers
-
Attackers Hijack Exposed AI Endpoints to Power Offensive Ops
Attackers don’t need any special authentication to reach a target endpoint, they just need to know where it is. First seen on darkreading.com Jump to article: www.darkreading.com/cloud-security/attackers-hijack-exposed-ai-endpoints-power-offensive-ops
-
Nissan Traces Data Breach to PeopleSoft Zero-Day Exploit
Extortionists Add National Association of Insurance Commissioners to Breach List. Japanese automotive giant Nissan and the U.S. National Association of Insurance Commissioners are the latest organizations to confirm they fell victim to cyber extortionists who recently wielded a zero-day exploit against Oracle PeopleSoft, leading to the theft of data. First seen on govinfosecurity.com Jump to…
-
Langflow RCE Exploited to Deploy Monero Miner on Exposed AI App Endpoints
Tags: ai, attack, crypto, cve, data-breach, endpoint, exploit, intelligence, rce, remote-code-execution, threat, vulnerabilityThreat actors are continuing to exploit a critical Langflow vulnerability as part of fresh attacks designed to deliver a Monero cryptocurrency miner.The activity has been found to weaponize CVE-2026-33017 (CVSS score: 9.3), an unauthenticated remote code execution (RCE) vulnerability in Langflow, indicating threat actors are scanning and targeting exposed artificial intelligence (AI) First seen on…
-
Nissan Discloses Employee Data Breach Linked to Oracle Zero-Day
Nissan says employees’ data was stolen via the Oracle PeopleSoft zero-day campaign First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/nissan-oracle-peoplesoft-zero-day/
-
Aflac Japan Data Breach Exposes Sensitive Customer Information
Aflac disclosed a data breach at its Japan subsidiary that exposed sensitive customer and bank account information. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/threats/aflac-japan-data-breach-exposes-sensitive-customer-information/
-
iPhone 18 Leak: Apple’s Next Pro Design May Have Appeared Online
Leaked Tata files reportedly show possible iPhone 18 Pro design details, factory images, and supplier records ahead of Apple’s expected September launch. The post iPhone 18 Leak: Apple’s Next Pro Design May Have Appeared Online appeared first on TechRepublic. First seen on techrepublic.com Jump to article: www.techrepublic.com/article/news-iphone-18-pro-design-leak-tata-breach/
-
Japanese Telecom Giant Says Breach May Expose 14.2 Million Email Accounts
KDDI says a breach may have exposed email addresses and passwords for up to 14.2 million ISP accounts across six providers. The post Japanese Telecom Giant Says Breach May Expose 14.2 Million Email Accounts appeared first on TechRepublic. First seen on techrepublic.com Jump to article: www.techrepublic.com/article/news-kddi-breach-isp-email-accounts-apac-japan/
-
282 iOS AI Apps Leak API Keys and Open AI Proxy Access in Network Traffic Study
Researchers tested 444 AI chatbot apps for iPhone and found that 282 of them, nearly two-thirds, exposed paid AI access through their network traffic.In many cases, the path in was visible just by watching what the app sent: a plaintext API key, a reusable token, or a backend server that accepted requests with no key…
-
Insurance giant Aflac discloses data breach after subsidiary hack
American insurance giant Aflac has disclosed a new data breach after attackers breached its Japan subsidiary’s systems and stole personal and bank account information. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/insurance-giant-aflac-discloses-data-breach-after-subsidiary-hack/
-
Multiple AirDrop and Quick Share Vulnerabilities Allow Attackers to Crash Devices
Tags: access, android, apple, attack, authentication, cyber, data-breach, flaw, google, vulnerability, windowsA new technical analysis has exposed six proximity-transfer flaws across Apple AirDrop, Samsung Quick Share on Android, and Google Quick Share for Windows, showing that device-sharing stacks still contain fragile pre-authentication attack surfaces that can be abused from wireless range. The findings include three AirDrop access crashes, two Quick Share protocol bypasses, and one Windows…
-
Facebook-Datenlecks: EuGH soll über Zulässigkeit von Sammelklage entscheiden
Tags: data-breachVerbraucherschützer wollen über eine Sammelklage eine Entschädigung für Facebook-Nutzer nach einem Datenleck durchsetzen. Das könnte unzulässig sein. First seen on golem.de Jump to article: www.golem.de/news/facebook-datenlecks-eugh-soll-ueber-zulaessigkeit-von-sammelklage-entscheiden-2606-210343.html
-
Datenleck bei Tata enthüllt Details zum iPhone 18 Pro
Ein Datenleck beim Apple-Zulieferer Tata Electronics legt vertrauliche Dokumente, Lieferantenlisten und Testbilder des kommenden iPhone 18 Pro offen. First seen on it-daily.net Jump to article: www.it-daily.net/it-sicherheit/cybercrime/iphone-18-pro-datenleck-tata
-
Datenleck bei Tata enthüllt Details zum iPhone 18 Pro
Ein Datenleck beim Apple-Zulieferer Tata Electronics legt vertrauliche Dokumente, Lieferantenlisten und Testbilder des kommenden iPhone 18 Pro offen. First seen on it-daily.net Jump to article: www.it-daily.net/it-sicherheit/cybercrime/iphone-18-pro-datenleck-tata
-
KDDI Data Breach May Expose 14.2 Million Email Accounts
KDDI disclosed a breach that may have exposed up to 14.2 million email accounts after attackers exploited a third-party software vulnerability. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/threats/kddi-data-breach-may-expose-14-2-million-email-accounts/
-
Nissan discloses employee data breach linked to Oracle zero-day attacks
Nissan is warning that it suffered a data breach affecting current and former employees after threat actors exploited an Oracle PeopleSoft vulnerability in data theft attacks previously linked to the ShinyHunters extortion group. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/nissan-discloses-employee-data-breach-linked-to-oracle-zero-day-attacks/
-
Iran, Russia, China Target Water Systems for Sabotage
Nation-state attackers breach water systems through weak passwords, exposed PLCs, and poor segmentation, not sophisticated malware. First seen on darkreading.com Jump to article: www.darkreading.com/ics-ot-security/iran-russia-china-target-water-systems-sabotage
-
HIBP-Meilenstein zeigt wachsende Meldeverzögerung bei Datendiebstählen – Datenleck-Opfer warten bis zu 45 Tage auf Benachrichtigung
Tags: data-breachFirst seen on security-insider.de Jump to article: www.security-insider.de/datenleck-opfer-benachrichtigung-verzoegerung-dsgvo-hibp-a-02b98fca6e4eeee4e65435e293e352aa/
-
US Federal Insurance Regulator Confirms Data Breach Via Oracle Flaw
An attacker has exploited a zero day in Oracle Peoplesoft to gain access to the IT systems of the NAIC, the standard-setting association for the US federal insurance system First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/us-insurance-regulator-confirms/
-
SSU and FBI Uncover Russian Cyber Espionage Operation Against Officials and Military Personnel
Tags: cyber, data-breach, espionage, government, hacking, intelligence, military, russia, service, ukraineUkraine’s SSU and the FBI Just Confirmed Russian Intelligence Has Been Systematically Hacking Messenger Accounts for Years. The Security Service of Ukraine (SSU), working jointly with the FBI, has formally exposed a sustained Russian intelligence campaign targeting the messaging accounts of government officials, military personnel, politicians, and activists across Ukraine, Europe, and the United States.…
-
Langflow RCE Vulnerability Exploited to Deploy Monero Cryptominer on Exposed AI Servers
Tags: ai, cve, cyber, data-breach, exploit, Internet, rce, remote-code-execution, tactics, threat, vulnerabilityThreat actors are actively exploiting CVE-2026-33017, a critical unauthenticated remote code execution (RCE) vulnerability in Langflow, to compromise internet-exposed AI application servers and silently deploy a customized Monero (XMR) cryptominer. Tracked and documented by Trend Micro researchers Simon Dulude and John Zhang, the campaign marks a significant pivot in commodity cryptominer delivery tactics, from traditional…
-
Root-Zugriff möglich: Exploits für gefährliche Lücke im Linux-Kernel geleakt
Admins sollten zügig ihre Linux-Systeme absichern. Auf Github sind Exploits für eine Root-Lücke in Debian, Ubuntu und RHEL aufgetaucht. First seen on golem.de Jump to article: www.golem.de/news/root-zugriff-moeglich-exploits-fuer-gefaehrliche-luecke-im-linux-kernel-geleakt-2606-210283.html
-
KDDI Data Breach Impacts up to 14.2 Million Email Accounts at Six ISPs
KDDI Corporation disclosed a breach affecting up to 14.2 million email accounts after attackers exploited a vulnerability in third-party software. KDDI Corporation disclosed a data breach that exposed up to 14.2 million email accounts across six Japanese internet service providers. KDDI Corporation is one of Japan’s largest telecommunications companies. It employs more than 60,000 people…
-
Data breach exposes up to 14.2 million email logins at six ISPs
Japanese telecommunications operator KDDI Corporation disclosed a data breach where threat actors gained access to one of its email systems used by five other internet service providers (ISPs) in the country. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/data-breach-exposes-up-to-142-million-email-logins-at-six-isps/
-
Amazon Q Developer extension vulnerability could have exposed cloud credentials
First seen on scworld.com Jump to article: www.scworld.com/brief/amazon-q-developer-extension-vulnerability-could-expose-cloud-credentials
-
Weak Access Controls Leave Enterprise Networks at Risk
Barracuda researchers found that weak credentials and exposed remote services continue to fuel malware, botnet, and credential attacks. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/threats/weak-access-controls-leave-enterprise-networks-at-risk/

