Tag: data-breach
-
Daily OT Security News: September 01, 2026
Viakoo Daily OT Security News, September 01, 2026: concise summaries of five stories affecting OT operators, device manufacturers, and industrial software supply chains. UK NCSC Warns of Growing Risk From Internet-Exposed OT The UK National Cyber Security Centre warned… First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/daily-ot-security-news-september-01-2026/
-
Attackers Access Aesto Health AWS Infrastructure, Exposing 9.5 Million Records
Aesto Health suffered a breach exposing personal and health data of more than 9.5 million people after attackers accessed its AWS infrastructure. Aesto Health, a U.S. healthcare technology company, disclosed a data breach that exposed personal and health information belonging to more than 9.5 million people. The company discovered the incident on December 18, 2025,…
-
Novocure data breach affects more than 1,400 cancer patients
Healthtech company Novocure says the data of an undisclosed number of employees and more than 1,400 U.S. cancer patients has been exposed in a mid-August cyberattack. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/novocure-data-breach-affects-more-than-1-400-cancer-patients/
-
EtherHiding Exposed: What Security Leaders Need to Know
EtherHiding Exposed: What Security Leaders Need to Know September 1, 2026 Jean-Pierre Mouton BLOG 5 min. TL;DR A malware campaign has compromised at least 31 organizations’ websites to deploy a persistent backdoor. It identifies its command and control (C2) infrastructure using… First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/etherhiding-exposed-what-security-leaders-need-to-know/
-
Nearly 22,000 Microsoft Exchange servers vulnerable to hijack attacks
Nearly 22,000 Microsoft Exchange servers exposed online remain unpatched against a high-severity authentication bypass vulnerability that allows attackers to hijack all user mailboxes. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/nearly-22-000-microsoft-exchange-servers-vulnerable-to-hijack-attacks/
-
Passwörter geleakt: Berliner Senatsverwaltungen schränken Homeoffice ein
Nach einem Cyberangriff auf die Berliner Landes-IT werden die VPN-Zugänge der Mitarbeiter gekappt. Der Grund: Passwörter sind an die Öffentlichkeit gelangt. First seen on golem.de Jump to article: www.golem.de/news/passwoerter-geleakt-berliner-senatsverwaltungen-schraenken-homeoffice-ein-2609-212485.html
-
Fake OpenAI, Anthropic and DeepSeek Crawlers Target .env Files and Cloud Credentials
Threat actors are impersonating AI web crawlers from organizations such as OpenAI, Anthropic, DeepSeek, Google, Perplexity, and Amazon to scan internet-facing servers for exposed secrets, according to a GreyNoise research report published on August 28, 2026. This activity involves automated scanners that use forged crawler user-agent strings to request sensitive files, including .env configurations, AWS…
-
Healthcare Giant McKesson Investigates Data Breach Incident
ShinyHunters claims to have stolen 284 million records from McKesson First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/healthcare-mckesson-investigates/
-
What Stood Out to Me at This Year’s DEF CON
Ferdinand Mudjialim, Penetration Tester September 1, 2026 “In many cases, they returned to familiar problems around trust, access, authentication, and what happens when a system is exposed in unexpected ways.” Key Takeaways Restricted systems are only as locked down as… First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/08/what-stood-out-to-me-at-this-years-def-con/
-
Bot detection arrives in CrowdSec 1.8.0, along with two DoS fixes
Failed SSH logins pile up in an auth log, and a scanner walks a website looking for exposed admin paths. CrowdSec reads log sources and HTTP requests, works out which … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/09/01/crowdsec-1-8-0-bot-detection/
-
Hackers Exploiting Internet-Exposed OT, Warns UK NCSC
Industrial Operators Face Growing Risk From Directly Connected Control Devices. Britain’s NCSC warned that rising OT attack activity is making internet-exposed industrial systems an increasingly attractive entry point, as weak credentials, aging firmware and overlooked connections give threat actors simpler routes into operational networks. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/hackers-exploiting-internet-exposed-ot-warns-uk-ncsc-a-32706
-
Finding the Fleet: What SNMP Finds in the Satellite Ground Segment that HTTP Misses
By Adrian Cheek, Senior Cybercrime Researcher Ask an internet-wide scanning index how many satellite mission-control systems are exposed and you can get the answer 1,776. All but 18 of those results turn out to be the same static web page,… First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/08/finding-the-fleet-what-snmp-finds-in-the-satellite-ground-segment-that-http-misses/
-
Hackers claim millions of patient records stolen during data breach at healthcare giant McKesson
The company, which distributes medicines and medical devices to hospitals and healthcare practices across the U.S., said it was hacked and expects intermittent service degradation. First seen on techcrunch.com Jump to article: techcrunch.com/2026/08/31/hackers-claim-millions-of-patient-records-stolen-during-data-breach-at-healthcare-giant-mckesson/
-
âš¡ Weekly Recap: Chinese Spy Proxy, AI Agents Go Off-Task, Router Backdoors and More
The boring parts caused most of the trouble.A router shipped ready to listen. A fake check turned the user into the installer. Trusted systems collected traffic and passwords, then cleaned the logs. Old bugs formed new attack chains. Even an AI agent decided its assigned task was optional.Elsewhere, fake apps, helpful support calls, cheap banking…
-
Threat actors are posing as AI crawlers to hunt for exposed credentials
Attackers are disguising automated scanning as traffic from AI crawlers operated by OpenAI, Anthropic, Google, Perplexity and other companies while searching websites for … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/08/31/ai-crawlers-scan-exposed-credentials/
-
Aurora Ransomware Operators Use Cursor AI in Attacks Against 10 Targets
Tags: ai, attack, cybercrime, data-breach, group, infrastructure, intelligence, network, ransomware, russia, threatThreat actors associated with Aurora (aka Aur0ra) ransomware have been observed using SpaceX’s artificial intelligence (AI)-powered coding assistant Cursor to break into target networks, according to findings from CloudSEK and Gambit Security.The two independent analyses are based on exposed infrastructure associated with the Russian-speaking cybercrime group, leading to the discovery of its First seen on…
-
NCSC Warns of Physical Disruptions from Cyberattacks on OT Systems
The UK NCSC warns of rising cyberattacks on operational technology, urging organizations to secure internet-exposed industrial systems against physical disruptions. First seen on securityonline.info Jump to article: securityonline.info/ncsc-warns-physical-disruptions-ot-systems/
-
Extortion Group FulcrumSec Claims 86GB Manchester Airports Group Data Theft
Extortion group FulcrumSec claims they stole 86GB of Manchester Airports Group data after finding API credentials exposed in client-side JavaScript. Manchester Airports Group (MAG) disclosed a data breach on August 27 affecting customers of Manchester, London Stansted, and East Midlands airports. Two days later, BleepingComputer reports the extortion group FulcrumSec claimed responsibility, saying it stole…
-
LACMA Data Breach: A 4-Day Attack, a Year of Fallout
LACMA says a four-day cyberattack may have exposed Social Security, financial, and medical data, prompting public disclosure and a proposed lawsuit. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/threats/news-lacma-data-breach-four-day-attack-year-fallout/
-
Cyberattack on Three UK Airports Exposes Data of 8.7 Million Customers
A cyberattack on Manchester Airports Group exposed information belonging to about 8.7 million customers across three UK airports. The post Cyberattack on Three UK Airports Exposes Data of 8.7 Million Customers appeared first on TechRepublic. First seen on techrepublic.com Jump to article: www.techrepublic.com/article/news-uk-airport-cyberattack-8-7-million-customers-emea/
-
Cyberattack on Three UK Airports Exposes Data of 8.7 Million Customers
A cyberattack on Manchester Airports Group exposed information belonging to about 8.7 million customers across three UK airports. The post Cyberattack on Three UK Airports Exposes Data of 8.7 Million Customers appeared first on TechRepublic. First seen on techrepublic.com Jump to article: www.techrepublic.com/article/news-uk-airport-cyberattack-8-7-million-customers-emea/
-
28,000 Exposed Git Repositories Found Leaking Credentials
Researchers found 28,000 exposed Git repositories containing active AWS, Stripe, OpenAI and GitHub credentials. Learn the risks and defenses. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/threats/news-28000-exposed-git-repositories-leak-credentials/
-
Cyberattack on 3 UK Airports Exposes Data of 8.7 Million Customers
A cyberattack on Manchester Airports Group exposed information belonging to about 8.7 million customers across three UK airports. The post Cyberattack on 3 UK Airports Exposes Data of 8.7 Million Customers appeared first on TechRepublic. First seen on techrepublic.com Jump to article: www.techrepublic.com/article/news-uk-airport-cyberattack-8-7-million-customers-emea/
-
Attackers Exploit MCP RCE, Blind Prompt Injection and Memory Credential Theft Against AI Infrastructure
Tags: ai, cloud, credentials, cyber, data-breach, exploit, framework, infrastructure, injection, rce, remote-code-execution, service, theftAttackers are increasingly treating AI infrastructure as a high-value cloud entry point, exploiting exposed Model Context Protocol (MCP) services, agent frameworks, and AI gateways to execute code, validate prompt injection, deploy cryptominers, and steal credentials from process memory. The campaigns show that attackers are no longer using only generic web-server tradecraft; they are tailoring reconnaissance,…
-
Over 8,300 Gitea servers vulnerable to code execution attacks
Over 8,300 Internet-exposed Gitea instances are still unpatched against a critical security flaw exploited in ongoing remote code execution attacks, according to cybersecurity watchdog Shadowserver. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/over-8-300-gitea-servers-vulnerable-to-code-execution-attacks/
-
Toy-making giant Hasbro disclose data breach affecting employees
Hasbro, one of the world’s largest toy and game companies, has disclosed that attackers have accessed the personal and financial information of an undisclosed number of employees. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/toy-making-giant-hasbro-disclose-data-breach-affecting-employees/
-
Cyberattack on UK Airport Operator MAG Exposes Data of 8.7 Million Customers Across Three Airports
A cyberattack on Manchester Airports Group exposed data of 8.7 million customers across Manchester, Stansted, and East Midlands airports. Manchester Airports Group disclosed that an unauthorised third party accessed customer data belonging to approximately 8.7 million people across three of England’s busiest airports: Manchester, London Stansted, and East Midlands. >>Manchester, London Stansted and East Midlands…
-
Leaked University Files Reveal How Russia Trains Hackers for Military Cyber Operations
A cache of leaked internal records has exposed what appears to be a structured Russian military cyber-operator pipeline embedded inside Bauman Moscow State Technical University. The documents indicate that the university’s concealed Department No. 4 trained students for intelligence collection, offensive cyber operations, information warfare, and technical defense before moving selected graduates into GRU-linked units.…
-
PaperCut Warns of Actively Exploited Vulnerability Affecting NG and MF Servers
PaperCut has issued an urgent security advisory after confirming the active exploitation of a vulnerability affecting all versions of its PaperCut NG and PaperCut MF print-management servers. Organizations with Application Servers exposed to the internet are urged to immediately restrict web access to trusted internal IP addresses and deploy emergency updates for versions 25 and…
-
Two Australian Men Charged in TeamPCP Supply Chain Attacks
Alleged Global Supply Chain Campaign Compromised More Than 1,000 Organizations. Australian authorities charged two men accused of leading TeamPCP, a cybercrime group linked to supply chain attacks that potentially compromised more than 1,000 organizations, exposed 500,000 credentials and drove global cleanup costs into the hundreds of millions. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/two-australian-men-charged-in-teampcp-supply-chain-attacks-a-32675

