Tag: data-breach
-
Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker
Artificial intelligence is rapidly changing the way software is developed, analyzed, and secured. However, the same capabilities that help developers inspect applications can also be misused by cybercriminals to automate reconnaissance, identify exposed secrets, and accelerate data theft.According to Cybersecurity… First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/hackers-abuse-youtube-gaming-channels-and-seo-poisoning-to-deploy-rats-and-chrome-hijacker/
-
CenterPoint Energy confirms customer data stolen in cyberattack
CenterPoint Energy disclosed a breach compromising some customers’ personal information after an attacker leaked data allegedly stolen from the utility company. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/centerpoint-energy-confirms-customer-data-stolen-in-cyberattack/
-
Leaks, data breaches, and ransom notes: The worst hacks of 2026 so far
From the massive DOGE data breach and the compromise of critical infrastructure to the hack of federal surveillance systems, here are the most damaging security incidents and data breaches of 2026 so far. First seen on techcrunch.com Jump to article: techcrunch.com/2026/09/15/the-worst-hacks-and-breaches-of-2026-so-far/
-
Electric and gas utility CenterPoint Energy warns of data breach after dark web post
Houston-based CenterPoint Energy notified federal regulators about an incident that exposed some customer data on the dark web. First seen on therecord.media Jump to article: therecord.media/centerpoint-energy-data-breach
-
eBook: Identity-First Threat Intelligence
Attackers increasingly bypass traditional defenses by logging in with credentials that have already been stolen, exposed, or sold on the Dark Web. As infostealer malware … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/09/15/enzoic-ebook-identity-first-threat-intelligence/
-
Mass-Scanning Campaign Exploits Vite Flaw to Extract Cloud Credentials From Exposed Dev Servers
Tags: cloud, credentials, cybersecurity, data-breach, exploit, flaw, infrastructure, Internet, microsoft, serviceCybersecurity researchers have disclosed details of a mass-scanning campaign that has targeted Vite deployments siphon sensitive data.The first is an automated effort aimed at internet-exposed Vite development servers that’s designed to steal cloud credentials, configurations from Amazon Web Services (AWS) and Microsoft Azure instances, and infrastructure state files, per F5 Labs.The First seen on thehackernews.com…
-
NonDay VPN Flaw Left Japan ‘s Government Shared Network Platform Exposed: 246,000 Records at Risk
Tags: access, breach, data-breach, exploit, flaw, government, network, risk, service, vpn, vulnerability, zero-dayJapan ‘s Digital Agency disclosed a VPN breach exposing 246,000 government employee records across 23 ministries. Detected June 25, publicly disclosed September 11. Japan ‘s Digital Agency disclosed that attackers exploited a vulnerability in a VPN device to access its Government Solution Service (GSS), potentially leaking personal information belonging to approximately 246,000 government employees, public…
-
Japan Government Network Breach Puts 246,000 People at Risk
A vulnerability in Japan’s shared government network may have exposed personal information tied to 246,000 workers across 23 organizations. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/cybersecurity/news-government-network-breach-apac-japan/
-
11 Best CSPM Tools Compared (2026): Features Pricing
Quick Answer: Wiz leads agentless attack-path CSPM; Prisma Cloud leads breadth; Microsoft Defender for Cloud offers a free foundational tier plus published per-resource plans; Orca pioneered agentless SideScanning. Consolidation note: Ermetic is now Tenable Cloud Security and Lacework is now Fortinet’s FortiCNAPP our list reflects both. Misconfiguration a public bucket, an over-permissive role, an exposed…
-
Japan’s Digital Agency says VPN flaw exposed 246,000 personnel records
Japan’s Digital Agency has discovered a data breach that may have exposed around 246,000 record rows containing personal information of government employees. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/japans-digital-agency-says-vpn-flaw-exposed-246-000-personnel-records/
-
Japan’s Digital Agency says VPN flaw exposed 246,000 personnel records
Japan’s Digital Agency has discovered a data breach that may have exposed around 246,000 record rows containing personal information of government employees. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/japans-digital-agency-says-vpn-flaw-exposed-246-000-personnel-records/
-
Revolut Reveals Data Breach Tied to Faked Official Request
Financial Platform Was Socially Engineered Into Disclosing Sensitive Customer Data. Digital financial platform Revolut is notifying customers that it suffered a data breach exposing their personal details after it fell for an official-looking impersonation scam involving a request for customer information sent using a legitimate government agency domain email. First seen on govinfosecurity.com Jump to…
-
Revolut Reveals Data Breach Tied to Faked Official Request
Financial Platform Was Socially Engineered Into Disclosing Sensitive Customer Data. Digital financial platform Revolut is notifying customers that it suffered a data breach exposing their personal details after it fell for an official-looking impersonation scam involving a request for customer information sent using a legitimate government agency domain email. First seen on govinfosecurity.com Jump to…
-
Hackers target exposed Vite dev servers to steal AWS, Azure secrets
A mass-scanning campaign targeting internet-exposed Vite development servers is attempting to steal cloud credentials and configurations from AWS and Azure deployments. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/hackers-target-exposed-vite-dev-servers-to-steal-aws-azure-secrets/
-
âš¡ Weekly Recap: Rogue AI Agents, WeChat Worm, PaperCut Attacks, AI Espionage, and Rootkits
AI keeps showing up in the wrong places. Attackers are using it to speed up exploits, test defenses, and automate more of the job. Some models are also crossing lines on their own. That is not a great combination.The rest of the week is more familiar: old bugs still working, fresh exploit chains, exposed systems,…
-
SpiderSilk Hunts External Threats With AI-Based Scanner
The Dubai-based threat detection startup uses artificial intelligence tools to scan billions of IP addresses to find exposed assets, leaked data, and zero-day vulnerabilities. First seen on darkreading.com Jump to article: www.darkreading.com/endpoint-security/spidersilk-hunts-external-threats-ai-scanning
-
Revolut discloses data breach exposing financial info, passports
Fintech company Revolut has disclosed a data breach after sharing data from an undisclosed number of customers with a threat actor impersonating a government agency. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/revolut-discloses-data-breach-exposing-financial-info-passports/
-
Malicious Twitch Browser Extension Leaks OAuth Tokens From Nearly 31,000 Users
A malicious cross-store Twitch browser extension has leaked OAuth tokens associated with nearly 31,000 users to proxy servers operated by a Russian commercial bot service.The extension, named “Twitch Enhanced Viewer | JeetBot,” lists HISHIMIRO/jeetbot.cc as its developer and has the following identifiers on the Google Chrome Web Store and Mozilla Firefox Add-Ons store – Chrome…
-
What we know about the Revolut data breach so far
Someone impersonating a government agency, using an email address on that agency’s domain, obtained sensitive customer records from Revolut. The bank confirmed the … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/09/14/revolut-data-breach-privacy/
-
Revolut confirms customer data breach through fake government requests
Revolut said it notified affected customers and alerted the relevant government agency, law enforcement, and financial regulators. First seen on techcrunch.com Jump to article: techcrunch.com/2026/09/12/revolut-confirms-customer-data-breach-through-fake-government-requests/
-
ID Verification Firm IDScan.net Confirms Data Breach
IDScan.net Confirms Breach – But Leaves Victim Count and Point of Entry Unanswered. A Louisiana identity verification company has confirmed a breach reportedly tied to the darkweb sale of more than 153 million U.S. and Canadian driver’s licenses, but its notice does not say how many people were affected or how attackers got in. First…
-
Florida says motor vehicle data breach tied to credentials stolen from officer’s personal device
The Florida Department of Motor Vehicles confirmed a data breach claimed by the cybercrime group ShinyHunters, saying it originated with the theft of credentials stored on a police officer’s personal device. First seen on therecord.media Jump to article: therecord.media/florida-shiny-hunters-motor-vehicle
-
FTC rescinds policy statement requiring health apps to notify customers after a breach
The policy, passed under the Biden administration, forced health apps to disclose when users’ personal health records were exposed in a breach or shared without authorization. First seen on cyberscoop.com Jump to article: cyberscoop.com/ftc-rescinds-health-app-data-breach-policy/
-
FTC rescinds policy statement requiring health apps to notify customers after a breach
The policy, passed under the Biden administration, forced health apps to disclose when users’ personal health records were exposed in a breach or shared without authorization. First seen on cyberscoop.com Jump to article: cyberscoop.com/ftc-rescinds-health-app-data-breach-policy/
-
Florida confirms DMV database breached via stolen police account
The Florida Department of Highway Safety and Motor Vehicles (FLHSMV) has confirmed that its DAVID driver database suffered a data breach, saying the attackers gained access using credentials belonging to a police department employee. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/florida-confirms-dmv-database-breached-via-stolen-police-account/
-
Florida confirms DMV database breached via stolen police account
The Florida Department of Highway Safety and Motor Vehicles (FLHSMV) has confirmed that its DAVID driver database suffered a data breach, saying the attackers gained access using credentials belonging to a police department employee. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/florida-confirms-dmv-database-breached-via-stolen-police-account/
-
Novo Nordisk Data Breach Tied to Stolen GitHub Access Tokens
Tags: access, breach, cloud, credentials, cyber, data, data-breach, defense, exploit, extortion, github, group, infrastructureCyber Extortion Group Continues to Target Exposed Cloud-Based Data Over Endpoints. Cyber extortion group FulcrumSec continues to find hardcoded credentials in public-facing IT infrastructure and exploit them as part of what it’s dubbed a Hardcoded Horrorshow that counts Ozempic maker Novo Nordisk among its victims. Here are defenses organizations need to put in place now.…

