Tag: data-breach
-
LLMjacking Attack Abuses Leaked AWS Credentials to Hijack Amazon Bedrock AI Models
Threat actors are increasingly converting stolen cloud credentials into access to costly generative AI services, a technique known as LLMjacking. FortiGuard Labs reported an incident involving Amazon Bedrock in which a leaked, long-lived AWS IAM access key with AdministratorAccess permissions was used to create a new identity, subscribe to foundation models, and run inference at…
-
Sangoma Switchvox Flaw Under Attack: 4,000 VoIP Systems Exposed
Hackers are exploiting a critical Sangoma Switchvox flaw that enables unauthenticated remote code execution. Admins should patch and check for compromise. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/threats/news-sangoma-switchvox-cve-2026-9586-rce/
-
Sangoma Switchvox Flaw Under Attack: 4,000 VoIP Systems Exposed
Hackers are exploiting a critical Sangoma Switchvox flaw that enables unauthenticated remote code execution. Admins should patch and check for compromise. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/threats/news-sangoma-switchvox-cve-2026-9586-rce/
-
Manchester Airport Breach: What 8.7M Customers Should Do
Manchester Airports Group customer data is now public. Here’s what was exposed, why it raises scam risks, and what affected travelers should do next. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/threats/news-manchester-airport-breach-what-customers-should-do/
-
Thomson Reuters reveals breach that exposed U.S. and Canadian court records
Thomson Reuters has disclosed a data breach affecting C-Track, a court case management platform operated by its subsidiaries, exposing court records and sensitive personal … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/09/03/thomson-reuters-reveals-breach-that-exposed-u-s-and-canadian-court-records/
-
US and Canadian court data exposed in Thomson Reuters breach
Sealed court information and sensitive personal data were exposed in a breach of a Thomson Reuters records platform affecting courts in at least 12 U.S. states, the U.S. Virgin Islands and Canada. First seen on therecord.media Jump to article: therecord.media/thomson-reuters-cyberattack-data
-
StreamRAT Abuses Android Accessibility, MediaProjection and HVNC for Full Device Takeover
StreamRAT, a newly identified Android banking trojan distributed through fake free-TV streaming advertisements on Meta and TikTok. The campaign, tracked as “Steamtv Esp.,” primarily targeted Spanish-speaking Android users and exposed an estimated 570,000 Meta users between June 11 and July 3, 2026. The operation highlights the continued effectiveness of piracy-themed social engineering. Victims who clicked…
-
Sangoma Switchvox RCE Flaw Actively Exploited in Wild via Unauthenticated SQL Injection
Tags: cve, cyber, data-breach, exploit, flaw, injection, Internet, rce, remote-code-execution, sql, voip, vulnerabilitySecurity researchers have reported active exploitation attempts targeting a critical vulnerability in Sangoma Switchvox, allowing unauthenticated attackers to execute code remotely via SQL injection. This vulnerability, tracked as CVE-2026-9586, affects internet-exposed Switchvox enterprise VoIP systems and was addressed in Switchvox version 8.4.0.2. Sangoma Switchvox RCE Flaw Zach Hanley, a researcher at Horizon3.ai, revealed that this…
-
2,000 Leaked Documents Reveal How Russia Turns Engineering Students Into GRU Cyber Operators
2,000 leaked files expose Bauman University’s hidden Department No. 4, which trained GRU-linked hackers and propagandists linked to APT28 and Sandworm. Leaked Documents Expose Bauman University’s Hidden Department That Trained Hackers, Propagandists, and Malware Developers for the GRU More than 2,000 internal documents from Bauman Moscow State Technical University have been reviewed by an international…
-
2,000 Leaked Documents Reveal How Russia Turns Engineering Students Into GRU Cyber Operators
2,000 leaked files expose Bauman University’s hidden Department No. 4, which trained GRU-linked hackers and propagandists linked to APT28 and Sandworm. Leaked Documents Expose Bauman University’s Hidden Department That Trained Hackers, Propagandists, and Malware Developers for the GRU More than 2,000 internal documents from Bauman Moscow State Technical University have been reviewed by an international…
-
2,000 Leaked Documents Reveal How Russia Turns Engineering Students Into GRU Cyber Operators
2,000 leaked files expose Bauman University’s hidden Department No. 4, which trained GRU-linked hackers and propagandists linked to APT28 and Sandworm. Leaked Documents Expose Bauman University’s Hidden Department That Trained Hackers, Propagandists, and Malware Developers for the GRU More than 2,000 internal documents from Bauman Moscow State Technical University have been reviewed by an international…
-
Ransomware Hackers Can Go From Network Access to Encryption in Less Than 24 Hours
Tags: access, breach, business, credentials, cyber, data-breach, encryption, hacker, infrastructure, network, ransomware, service, threatThe Gentlemen ransomware-as-a-service operation can move from confirmed access inside a victim network to encryption in under 24 hours. Demonstrating how rapidly modern affiliates can turn stolen credentials or exposed infrastructure into a full-scale business disruption. Counter Threat Unit researchers tracking the operation as GOLD SHERWOOD found that the Gentlemen affiliates follow a repeatable post-compromise…
-
Leaked documents reveal Russian military cyber recruitment pipeline
First seen on scworld.com Jump to article: www.scworld.com/brief/leaked-documents-reveal-russian-military-cyber-recruitment-pipeline
-
UK airport hackers leak stolen customer data
The cyber gang that attacked Manchester Airports Group has leaked data on 8.7 million travellers after its victim refused to pay a ransom. First seen on computerweekly.com Jump to article: www.computerweekly.com/news/366649824/UK-airport-hackers-leak-stolen-customer-data
-
I rented a car, and within hours, my driver’s license was for sale
The FBI is reportedly investigating a massive data breach that is unfolding in real time. First seen on arstechnica.com Jump to article: arstechnica.com/security/2026/09/my-drivers-license-is-one-of-153-million-for-sale-on-a-new-dark-website/
-
Hackers Steal Metr API Key, Burn $600K in AI Credits
Separate Database Flaw Could Have Exposed Sensitive Model Data. Attackers in March stole a Metr API key and used it for three weeks to consume about $600,000 worth of AI model credits. In a separate May campaign, hackers probed a public Metr service with a bug that could have exposed unpublished and sensitive model data.…
-
Health data of more than 9.5 million people leaked from Aesto record system
The healthcare data company Aesto informed federal regulators this week that more than 9.5 million people had sensitive information leaked during a cyberattack last December. First seen on therecord.media Jump to article: therecord.media/health-data-aesto-cyberattack-leak
-
OWASP Top 10 CI/CD Security Risks Explained: Why Credential Hygiene Decides the Outcome
TL;DRCredentials are the multiplier: OWASP’s Top 10 CI/CD Security Risks cover ten distinct trust failures, but exposed or overprivileged credentials (CICD-SEC-6) make nearly every other risk more dangerous once attackers gain a foothold.Attacks are accelerating: Since 2025, worms like Shai-Hulud,… First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/owasp-top-10-ci-cd-security-risks-explained-why-credential-hygiene-decides-the-outcome/
-
Nearly 22,000 Microsoft Exchange servers remain exposed to critical security flaw (CVE-2026-62911)
Nearly 22,000 Microsoft Exchange servers remain unpatched against CVE-2026-62911, a critical authentication bypass vulnerability, according to daily scans from the … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/09/02/microsoft-exchange-cve-2026-62911-critical-authentication-bypass-flaw/
-
Datenleck bei US-Gesundheitsdienstleister – Cyberangriff auf Unlimited Technology Systems betrifft 3,8 Millionen Patienten
First seen on security-insider.de Jump to article: www.security-insider.de/datenleck-unlimited-technology-systems-38-millionen-betroffen-a-90531a6309a44f718672e1124b1fca3b/
-
Exploitation of Sangoma Switchvox flaw is underway (CVE-2026-9586)
A threat actor is actively targeting internet-exposed Sangoma Switchvox instance through a recently patched SQL injection flaw (CVE-2026-9586), and organizations running them … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/09/02/exploitation-of-sangoma-switchvox-flaw-underway-cve-2026-9586/
-
427 or 4 Devices?: Measuring Internet-Exposed Industrial Infrastructure in the UK
By Adrian Cheek, Senior Cybercrime Researcher On August 22, 2026, The Telegraph reported that a small UK power generator had been shut down for four days in July following a cyberattack by hackers linked to Iran. The government confirmed that… First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/427-or-4-devices-measuring-internet-exposed-industrial-infrastructure-in-the-uk/
-
Scareware ads keep running on Google’s transparency tool, even after they’re reported
A team of NYU and Radboud University researchers spent a year building a tool to find deceptive software ads inside Google’s public ad archive. It works. It also exposed … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/09/02/google-scareware-ads-research/
-
31th August Threat Intelligence Report
Manchester Airports Group, the UK operator of Manchester, London Stansted, and East Midlands airports, has disclosed a cyberattack that exposed data belonging to about 8.7 million customers. The compromised information includes contact details, […] First seen on research.checkpoint.com Jump to article: research.checkpoint.com/2026/31th-august-threat-intelligence-report/
-
Australia introduces new digital identity strategy amid rising data breach and surveillance risks
First seen on scworld.com Jump to article: www.scworld.com/brief/australia-introduces-new-digital-identity-strategy-amid-rising-data-breach-and-surveillance-risks
-
McKesson discloses data breach after ShinyHunters claims theft of 284 million records
First seen on scworld.com Jump to article: www.scworld.com/brief/mckesson-discloses-data-breach-after-shinyhunters-claims-theft-of-284-million-records
-
Aesto Health says data breach affects over 9.5 million patients
Aesto LLC, operating as Aesto Health, disclosed that a data breach discovered recently affects more than 9.5 million individuals. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/aesto-health-says-data-breach-affects-over-95-million-patients/
-
Leaked Russian Cyber-Operations Training Materials
This is interesting: The records describe a force-generation mechanism for several General Staff components, including the GRU, Main Operational Directorate, and 8th Directorate, which is associated with protected communications, cryptography, and information security….The reporting also linked a 2024… First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/leaked-russian-cyber-operations-training-materials/
-
Leaked Russian Cyber-Operations Training Materials
This is interesting: The records describe a force-generation mechanism for several General Staff components, including the GRU, Main Operational Directorate, and 8th Directorate, which is associated with protected communications, cryptography, and information security….The reporting also linked a 2024… First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/leaked-russian-cyber-operations-training-materials/

