Tag: data-breach
-
Großes Datenleck bei Nextcloud: Kundenskripte und Rechnungen standen offen im Netz
Neben internen Unternehmensdaten ließen sich durch die Sicherheitslücke bei Nextcloud auch für Kunden angefertigte Skripte einsehen. First seen on golem.de Jump to article: www.golem.de/news/grosses-datenleck-bei-nextcloud-kundenskripte-und-rechnungen-standen-offen-im-netz-2607-210659.html
-
Accenture acknowledges security incident following 35GB data theft claim
Accenture appears to have suffered a data breach, the extent of which is currently unknown. On Monday, a threat actor going by the handle >>888<< posted on the … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/07/08/accenture-data-breach-2026/
-
Telco giant KDDI says data breach affects over 12 million people
Japanese telecommunications giant KDDI says that millions of people had their email addresses and passwords exposed after attackers breached an email platform used by five internet service providers (ISPs) in the country. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/japanese-telecom-giant-kddi-says-data-breach-affects-12-million-people/
-
Exposed Banana RAT Infrastructure Reveals Payload Generator and Obfuscator Tooling
A publicly indexed server at 198[.]245[.]53[.]26, discovered via Shodan, exposed more than simple staging files it revealed an active payload-generation backend and obfuscation tooling tied to two distinct Banana RAT branches. The host served static stages (st.txt, payload.php) and a FastAPI-based builder (servidor_completo_pool.py) plus an ofuscador.py helper. Enabling researchers to compare an older ETW-themed branch…
-
Over 70% of Public WordPress Sites Running Outdated PHP Exposed to Cyberattacks
A new analysis has revealed a significant security gap within the global web ecosystem. Over 70% of publicly accessible WordPress sites are running outdated, end-of-life (EOL) PHP versions, significantly increasing their vulnerability to cyberattacks. These findings highlight a systemic issue in how organizations manage their backend infrastructure, particularly given that WordPress remains the leading content…
-
Januscape Flaw in Linux KVM’s MMU Code Enables VM Escape on Intel and AMD
A newly disclosed Linux kernel vulnerability, CVE-2026-53359, dubbed Januscape, has exposed a critical weakness in the Linux Kernel-based Virtual Machine (KVM) hypervisor. The flaw resides in the shadow MMU code and allows attackers to escape a virtual machine (VM), compromise the underlying host, and potentially execute arbitrary code. First seen on thecyberexpress.com Jump to article: thecyberexpress.com/cve-2026-53359-januscape/
-
Google Dialogflow CX Flaw Lets Attackers Bypass VPC-SC and Steal Sensitive Chatbot Data
A critical vulnerability in Google Cloud’s Dialogflow CX platform allowed attackers to bypass VPC Service Controls (VPC-SC) and silently exfiltrate sensitive chatbot data, raising significant concerns about the security of enterprise AI deployments. Discovered by Varonis Threat Labs and dubbed “Rogue Agent,” the flaw exposed a serious design gap in how Dialogflow CX executes custom…
-
Accenture Data Breach Exposes 35GB Source Code and Azure DevOps Credentials
Accenture is currently investigating a potential data breach after a threat actor using the alias “888” claimed to be selling approximately 35GB of stolen data, including source code and sensitive credentials, on a cybercrime forum. This listing, posted on July 6, 2026, alleges that the breach resulted in the exfiltration of proprietary assets, including source…
-
Major Japanese telco says cyberattack exposed 12 million emails
The company said the breach affected an email system used to manage customer email accounts, webmail services and email storage for five Japanese internet service providers. First seen on therecord.media Jump to article: therecord.media/major-japanese-telco-cyberattack-12-million-emails
-
Berechtigungen in der Lieferkette werden zum kritischen Einfallstor
Regulierung schützt nicht vor Angriffen mit kompromittierten Identitäten und Zugangsdaten Identitäts-Sicherheit hingegen schon. Exemplarische Vorfälle im Juni, wie bei der V-Bank, bei dem Hacker über einen IT-Dienstleister Zugriff auf Systeme erlangten und einen Datenabfluss verursachten, oder das Datenleck bei Lastpass, das durch eine Schwachstelle bei einem Drittanbieter ausgenutzt wurde, zeigen exemplarisch eine bittere Wahrheit: […]…
-
Auch Android betroffen: Exploit für gefährliche Root-Lücke im Linux-Kernel geleakt
Eine Lücke im Epoll-Subsystem des Linux-Kernels verleiht Angreifern auf anfälligen Systemen Root-Rechte. Inzwischen gibt es auch einen Exploit dafür. First seen on golem.de Jump to article: www.golem.de/news/auch-android-betroffen-exploit-fuer-gefaehrliche-root-luecke-im-linux-kernel-geleakt-2607-210571.html
-
Google Gemini Live API Flaw Allows RCE via Unconstrained Ephemeral Tokens
Tags: ai, api, cyber, data-breach, endpoint, flaw, google, rce, remote-code-execution, vulnerabilityA significant security vulnerability in Google’s Gemini Live API has exposed applications to remote code execution (RCE) due to misconfigured ephemeral tokens. This flaw allows attackers to inject client-controlled setup frames and execute arbitrary code within AI voice sessions. The issue stems from the improper use of the “Constrained” WebSocket endpoint, particularly when developers neglect…
-
Moody Bible Institute data breach exposes 2.3 million individuals
First seen on scworld.com Jump to article: www.scworld.com/brief/moody-bible-institute-data-breach-exposes-2-3-million-individuals
-
Major medical device manufacturer notifies nearly 4 million of breach
Information like Social Security numbers and health-related data was accessed, but the company said it had “no evidence that impacted information has been publicly posted or exposed on the internet.” First seen on therecord.media Jump to article: therecord.media/medical-device-maker-notifies-nearly-4-million-of-breach
-
Azure CLI Password Spray Attack Exposes Microsoft 365 MFA Gap
A password spray campaign targeting Azure CLI sign-ins exposed how narrow Conditional Access policies can leave Microsoft 365 accounts vulnerable even when MFA is enabled. The post Azure CLI Password Spray Attack Exposes Microsoft 365 MFA Gap appeared first on TechRepublic. First seen on techrepublic.com Jump to article: www.techrepublic.com/article/news-azure-cli-mfa-gap/
-
How to prioritize AI agent security by business impact
Your CEO calls about an AI agent security incident in finance. He wants to know whether money moved, whether financial data was exposed, who owned the agent and why it had … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/07/06/prioritize-ai-agent-security-business-impact/
-
Medtronic Notifies 3.8 Million After ShinyHunters Data Breach
Medtronic says a ShinyHunters attack exposed the personal and medical data of over 3.8 million people. Products and operations were unaffected. Medtronic is notifying 3,834,294 individuals after a cyberattack by the ShinyHunters extortion group exposed personal and medical information. In April 2026, Medtronic confirmed a cyberattack on its corporate IT systems after the hacker group ShinyHunters claimed…
-
U.S. Government Agency Paid $1M to Data Extortion Group Kairos
Tags: blockchain, data, data-breach, extortion, government, group, ransom, ransomware, theft, threatA U.S. government agency paid $1M to Kairos, a group focused on data theft and extortion rather than ransomware, Ransom-ISAC reports. A new case study from Ransom-ISAC reconstructs a complete data-extortion incident involving a U.S. government body and a threat actor called Kairos, using a leaked negotiation transcript and blockchain tracing of the ransom payment.…
-
U.S. Government Entity Paid Kairos $1 Million in Data-Theft Extortion Case
Tags: blockchain, breach, data, data-breach, extortion, government, group, ransom, ransomware, theftA U.S. government entity paid about $1 million to keep stolen files from being leaked, according to a new case study by Rakesh Krishnan for Ransom-ISAC, built on a leaked negotiation chat and the blockchain trail the payment left.The odd part: the group that took the money calls itself Kairos, but it may not be…
-
Hackergruppe ‘World Leaks” – Details des iPhone 18 Pro bei Cyberangriff geleakt
First seen on security-insider.de Jump to article: www.security-insider.de/cyberangriff-tata-iphone-18-pro-daten-darknet-a-d177087e6319dd1007dc1a75012f3f31/
-
Breach of IBM-managed environment exposes personal data of 70,000 in Singapore
Unauthorised access to a development and testing environment managed by IBM has exposed the names, NRIC numbers and property addresses of about 70,000 people held by the Singapore Land Authority First seen on computerweekly.com Jump to article: www.computerweekly.com/news/366645414/Breach-of-IBM-managed-environment-exposes-personal-data-of-70000-in-Singapore
-
Non-interactive SSH attacks dominate after login
Anyone who runs a server with SSH exposed to the internet sees the same pattern in the logs. A steady stream of automated scanners tries to log in, hour after hour, from … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/07/03/research-non-interactive-ssh-attacks/
-
SharkLoader Malware Uses Perfect DLL Hijacking to Execute Cobalt Strike in Memory
SharkLoader, used by an intrusion cluster tracked as StrikeShark to deliver Cobalt Strike Beacon entirely in memory across a wide international footprint. The campaign combines opportunistic exploitation of exposed internet-facing infrastructure with custom droppers disguised as trusted installers to establish initial access, then relies on layered, memory-only execution techniques and “Perfect DLL Hijacking” to minimize…
-
SharkLoader Malware Uses Perfect DLL Hijacking to Execute Cobalt Strike in Memory
SharkLoader, used by an intrusion cluster tracked as StrikeShark to deliver Cobalt Strike Beacon entirely in memory across a wide international footprint. The campaign combines opportunistic exploitation of exposed internet-facing infrastructure with custom droppers disguised as trusted installers to establish initial access, then relies on layered, memory-only execution techniques and “Perfect DLL Hijacking” to minimize…
-
Breach Roundup: DeepSeek Sparks Browser Ransomware
Tags: ai, attack, breach, cisa, data, data-breach, fraud, india, iphone, oracle, penetration-testing, ransomwareAlso, False Negatives Causes Trust in AI Pentest to Drop. This week: a DeepSeek browser-only ransomware path, AI pen testing trust dropped, Mustang Panda targeted India, Tata breach exposed iPhone 18 data, CISA flagged BlueHammer in ransomware attacks, 950 Oracle EBS systems exposed, Amazon to pay U.S. Federal Trade Commission penalty over fraud records. First…
-
430,000 FortiGate Devices Exposed in FortiBleed Ransomware Link
FortiBleed exposed 430,000 FortiGate firewalls, linked to INC Ransom and Lynx, enabling domain compromise and at least 12 ransomware attacks. SOCRadar’s Threat Research Unit has connected FortiBleed, a large-scale campaign that harvested credentials from over 430,000 FortiGate firewalls worldwide, directly to two active ransomware operations: INC Ransom and Lynx. The link isn’t circumstantial. An operator…
-
430,000 FortiGate Devices Exposed in FortiBleed Ransomware Link
FortiBleed exposed 430,000 FortiGate firewalls, linked to INC Ransom and Lynx, enabling domain compromise and at least 12 ransomware attacks. SOCRadar’s Threat Research Unit has connected FortiBleed, a large-scale campaign that harvested credentials from over 430,000 FortiGate firewalls worldwide, directly to two active ransomware operations: INC Ransom and Lynx. The link isn’t circumstantial. An operator…
-
950 Oracle E-Business Suite Instances Exposed as CVE-2026-46817 Attacks Observed in the Wild
Around 950 internet-facing Oracle E-Business Suite (EBS) instances have been identified as exposed following enhanced scanning efforts. At the same time, active exploitation attempts tied to CVE-2026-46817 have already been observed in the wild. The findings were disclosed by The Shadowserver Foundation, which recently expanded its fingerprinting capabilities through domain-based scanning in collaboration with Validin.…
-
FortiBleed Campaign Linked to INC and Lynx Ransomware Operations
A direct operational link between the large-scale FortiBleed credential-harvesting campaign and two active ransomware-as-a-service (RaaS) groups: INC Ransom and Lynx. This finding provides the first confirmed evidence that mass theft of FortiGate credentials is being integrated into ransomware deployment processes, significantly increasing the threat posed by exposed firewall infrastructure. FortiBleed Campaign Linked to INC and…

