Tag: data-breach
-
Origin Energy confirms data breach impacting millions of customers
First seen on scworld.com Jump to article: www.scworld.com/brief/origin-energy-confirms-data-breach-impacting-millions-of-customers
-
Iran-Linked Actors Breach Are Targeting US Water and Energy Control Systems
US agencies warn Iran-linked actors are targeting internet-exposed water and energy control systems, risking disruption. Federal agencies updated their cybersecurity advisory this week: Iran-linked actors are inside American water and energy control systems, and they’re not just looking around. They’re changing things. The updated advisory from CISA, the FBI, NSA, and the Department of Energy…
-
Australian energy provider Origin Energy disclosed a data breach impacting customer data
Origin Energy confirmed a data breach after a hacker claimed to have stolen data from 2 million customers and threatened to leak it. Origin Energy disclosed a cyberattack that exposed customer data after a hacker claimed to have stolen records belonging to 2 million customers and threatened to publish them. An alleged hacker calling themselves…
-
ShinyHunters data leaks fuel $2,000 sextortion email scam
Threat actors are using email addresses exposed in data breaches leaked by the ShinyHunters extortion group to send sextortion emails demanding $2,000 in Bitcoin. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/shinyhunters-data-leaks-fuel-2-000-sextortion-email-scam/
-
Cl0p Affiliates Target Internet-Exposed PTC Windchill and FlexPLM with Unauthenticated RCE
Tags: authentication, data, data-breach, endpoint, exploit, extortion, flaw, Internet, login, ransomware, rce, remote-code-execution, threatThreat actors linked to the Cl0p (aka Chubby Scorpius, FIN11, Graceful Spider, and Lace Tempest) ransomware campaign are exploiting flaws in internet-exposed PTC Windmill and FlexPLM deployments as part of a new data extortion campaign.”Attackers chain a pre-authentication information disclosure in the FlexPLM WSDL endpoint with a server-side flaw in the Windchill login servlet, enabling…
-
Hackers Exploit Industrial PLCs and Manipulate HMI Displays to Hide Attacks
Six federal agencies have updated a joint advisory warning that Iranian-affiliated advanced persistent threat (APT) actors are actively exploiting internet-exposed programmable logic controllers (PLCs) across U.S. critical infrastructure, manipulating human-machine interface (HMI) displays so operators cannot visually detect the intrusion. The advisory, first issued in April 2026 and revised on July 22, 2026, is cosigned…
-
OnTrac notifies customers of data breach after network hack
OnTrac parcel delivery company is informing that hackers breached its corporate network and may have accessed personal details belonging to its customers. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/ontrac-notifies-customers-of-data-breach-after-network-hack/
-
OnTrac notifies customers of data breach after network hack
OnTrac parcel delivery company is informing that hackers breached its corporate network and may have accessed personal details belonging to its customers. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/ontrac-notifies-customers-of-data-breach-after-network-hack/
-
Chick-fil-A data breach affects more than 13,000 customers
Chick-fil-A has confirmed that over 13,000 customers had their accounts breached in a wave of credential stuffing attacks targeting its website and mobile app between June 17 and June 19. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/chick-fil-a-data-breach-affects-more-than-13-000-customers/
-
The most vulnerable AI products are also some of the most commonly exposed online
It is becoming increasingly easy for hackers to target vulnerable AI tools on companies’ networks, even as those companies come to depend on them for more tasks. First seen on cybersecuritydive.com Jump to article: www.cybersecuritydive.com/news/industrial-control-systems-ai-internet-exposure-censys-report-preview/826133/
-
Cl0p Targets Internet-Exposed Windchill Servers in Global Engineering Data-Theft Campaign
Cl0p ransomware affiliates are actively exploiting internet-exposed PTC Windchill and FlexPLM deployments in a global data-theft campaign targeting high-value engineering environments. Observed post-exploitation activity includes filesystem enumeration via files such as “flst.txt,” followed by staging and exfiltration of sensitive engineering and product design data. This chaining enables unauthenticated remote code execution, allowing attackers to deploy…
-
Thailand’s Ministry of Finance Targeted With Hermes AI Agent Running Unattended, Hades Implant Staged
Hunt.io uncovered a cyber-espionage attack on Thailand’s Finance Ministry using Hermes AI agent and Hades malware for reconnaissance and persistence. Researchers at Hunt.io have uncovered an intrusion targeting Thailand’s Ministry of Finance that offers a rare look inside a live cyber-espionage operation. Instead of recovering malware after the fact, the team found exposed staging servers…
-
2.2 Million Vehicles Exposed to KARR Bluetooth Security Flaw
Millions of drivers with a dealer-installed KARR Security System are being urged to update their KARR alarm using an iPhone or Android device after researchers uncovered a Bluetooth vulnerability that could allow nearby attackers to unlock or immobilize affected vehicles. First seen on thecyberexpress.com Jump to article: thecyberexpress.com/karr-security-system-flaw/
-
2.2 Million Vehicles Exposed to KARR Bluetooth Security Flaw
Millions of drivers with a dealer-installed KARR Security System are being urged to update their KARR alarm using an iPhone or Android device after researchers uncovered a Bluetooth vulnerability that could allow nearby attackers to unlock or immobilize affected vehicles. First seen on thecyberexpress.com Jump to article: thecyberexpress.com/karr-security-system-flaw/
-
Clop ransomware targets Windchill, FlexPLM in data theft attacks
The Clop ransomware gang (also tracked as Cl0p) is targeting Internet-exposed PTC Windchill and FlexPLM instances in a new data theft extortion campaign. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/clop-ransomware-targets-windchill-flexplm-in-data-theft-attacks/
-
CISA Again Sounds Warning Over Exposed PLCs
Internet-Exposed Programmable Logic Controllers ‘An Easy Target’. Thousands of vulnerable industrial devices, accessible from the public internet, are being targeted by Iran-linked hackers, U.S. authorities said this week. The warning was an update to an advisory CISA originally published in April. The revision is because a broader range of device brands are under attack. First…
-
Censys Finds AI/LLM Tool Exposures Up More Than 60%
Censys found Internet-exposed AI/LLM tools increased more than 60% in nine months, expanding organizations’ attack surfaces. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/threats/censys-finds-ai-llm-tool-exposures-up-more-than-60/
-
Breach Roundup: Zelle Must Face NY Lawsuit Over Fraud
Also, Spain Fines 23andMe Over 2023 Data Breach. This week: Zelle can’t transfer out of a New York state lawsuit alleging poor controls over rampant fraud, a hack wiped Romania’s land registry, Spain fined 23andMe, Australia’s Origin Energy data breach and pirate World Cup streaming sites seized. Malware found hiding in Microsoft 365 calendars. First…
-
China-Nexus JadeProx Uses New TriBack Loader in Government and Healthcare Attacks
An exposed Alibaba Cloud server has revealed a China-nexus operation that Group-IB tracks as JadeProx. The cluster has targeted government, healthcare, and education organizations across Asia and Latin America with a previously undocumented Windows loader called TriBack Loader.Group-IB found the server in mid-April 2026 in Alibaba Cloud’s Singapore region; it was offline by the time…
-
AI Agents Now the Enterprises Fastest Growing Exposed Attack Surface
Sophos report warns that the rapid adoption of AI by businesses is leaving them vulnerable to a new source of cyber threats First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/ai-agents-attack-surface/
-
Stadler Rail verweigert Lösegeldzahlung nach Hackerangriff
Der Schweizer Zugbauer Stadler Rail weist eine Lösegeldforderung der Everest-Gruppe über 12,3 Millionen Dollar nach einem Datenleck bei einem Lieferanten zurück. First seen on it-daily.net Jump to article: www.it-daily.net/it-sicherheit/cybercrime/stadler-rail-hacker
-
Hackers Lurked for 10 Months Inside South Korea Diplomatic System
The National Diplomatic Academy data breach has raised significant cybersecurity concerns in South Korea after the Ministry of Foreign Affairs confirmed that hackers maintained access to the academy’s online education system for nearly 10 months. The cyberattack resulted in the exposure of personal information belonging to current and former ministry employees, including diplomats serving overseas. First seen on thecyberexpress.com…
-
Chick-fil-A Confirms Data Breach After Credential Stuffing Attack Exposes Customer Personal and Payment Data
Chick-fil-A has confirmed a data breach affecting an undisclosed number of Chick-fil-A One loyalty accounts. This breach occurred as threat actors executed credential-stuffing attacks on its website and mobile application. The incident underscores the ongoing risk associated with password reuse, where usernames and passwords exposed in unrelated third-party breaches are automatically tested against consumer platforms.…
-
Multi-patch vulnerability fixes can leave open source exposed
Vulnerability management runs on a shorthand. A CVE shows a linked patch, someone applies it, and the ticket moves to closed. That shorthand covers most open source fixes. A … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/07/23/research-multi-patch-vulnerability-fixes/
-
Carla car rental data exposed in unsecured AWS bucket
First seen on scworld.com Jump to article: www.scworld.com/brief/carla-car-rental-data-exposed-in-unsecured-aws-bucket
-
North Korean IT Worker Scams Fueling Ukrainian Invasion
Leaked Payment Server Data Lets Researchers Trace Money Flows. Salaries paid to North Korean IT workers end up converted to ammunition used against Ukraine, warns new research based on a trove of leaked payment server data. North Korea has for years smuggled remote and contract IT workers onto Western payrolls. First seen on govinfosecurity.com Jump…
-
South Korea discloses data breach impacting diplomats worldwide
South Korea disclosed that hackers breached the National Diplomatic Academy’s online education system for ten months and stole personal information belonging to current and former employees of the Ministry of Foreign Affairs (MFA), including overseas diplomats. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/south-korea-discloses-data-breach-impacting-diplomats-worldwide/
-
Chick-fil-A Data Breach Linked to Credential Stuffing Attack
Chick-fil-A is notifying customers after credential stuffing attacks compromised loyalty accounts. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/threats/chick-fil-a-data-breach-linked-to-credential-stuffing-attack/

