Tag: data-breach
-
ThreatsDay: 296K IoT Botnet, 100+ Water Systems Targeted, SharePoint RCE Chain + 27 New Stories
Tags: ai, botnet, data-breach, exploit, infrastructure, iot, login, malicious, rce, remote-code-execution, tool, windowsA fake login page. A fake security scan. A fake productivity app. Apparently, pretending to be useful is still one of the easier ways into a machine.The rest of the week gets stranger: botnets borrowing AI, command traffic hiding in public infrastructure, malicious tools waiting before showing their real behavior, exposed systems getting scanned, and…
-
What IBM’s Latest Breach Report Says About Data Security in an AI-Centric World
<div cla IBM has been charting the data breach landscape now for over two decades. But you’d be hard pressed to find any point over the past 21 years as volatile as today. AI is rewriting the rules of the game for network defenders and their adversaries, simultaneously arming attackers and creating a dangerous new…
-
Two alleged TeamPCP members arrested and charged after months of software supply-chain chaos
The two men face 14 charges combined. Private researchers traced one suspect through leaked passwords and a decade-old gaming profile. First seen on cyberscoop.com Jump to article: cyberscoop.com/teampcp-cybercrime-arrests-supply-chain-attacks/
-
Hackers Exploit CVE-2023-49105 to Steal Nuclear Records From Philippine Research Agency
Suspected Chinese-speaking operators exploited the critical ownCloud flaw CVE-2023-49105 to steal nuclear material records, research reactor data, personnel files, and encryption key material from a Philippine nuclear research organization. Hunt.io discovered an exposed file directory on August 13, 2026, hosted at 31.58.209[.]241:8000, an Amsterdam-based server registered to CGI Global Limited. The directory was served through…
-
Hackers Target Over 100 U.S. Water Systems in a Single Month, Federal Agency Confirms
CISA says hackers targeted more than 100 internet-exposed U.S. water systems in July, exploiting PLC access and causing some operational disruptions. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/threats/news-cisa-water-systems-plc-cyberattacks/
-
Carhartt data breach exposes information of 12.9 million accounts
The ShinyHunters extortion group has published sensitive data from nearly 13 million accounts stolen from clothing retailer giant Carhartt earlier this month, according to data breach notification service Have I Been Pwned. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/carhartt-data-breach-exposes-information-of-129-million-accounts/
-
Ransomware Hacker Uses AI to Plan Attacks and Compromises More Than 20 Organizations
A Russian-speaking affiliate of the Aurora ransomware operation compromised more than 20 organizations across nine countries between April and July 2026, using the AI coding assistant Cursor to plan intrusion activity and Active Directory escalation. The exposed server offered an unusually complete view of a ransomware affiliate’s operational workflow. It contained victim-specific directories, shell history,…
-
CISA Warns Water Utilities: Find Your Exposed PLCs Before Attackers Do
CISA urges water utilities to find and secure internet-exposed PLCs after July attacks showed how easily exposed industrial systems can be compromised. Over 100 internet-exposed systems in the US water and wastewater sector got hit by cyberattacks in July 2026, and CISA’s response wasn’t just an incident report, it was a how-to guide for making…
-
Ubiquiti Fixes 22 UniFi Flaws Enabling Command Injection, Authentication Bypass and Privilege Escalation
Ubiquiti has released security updates to address 22 vulnerabilities across its UniFi ecosystem. These updates include multiple critical flaws that could allow unauthenticated command injection, authentication bypass, and privilege escalation on exposed devices. Documented in Security Advisory Bulletin 067 and published on August 26, 2026, these vulnerabilities affect several components, including UniFi OS, UniFi Protect,…
-
Carhartt data breach claims inflated by synthetic data, analysis finds
First seen on scworld.com Jump to article: www.scworld.com/brief/carhartt-data-breach-claims-inflated-by-synthetic-data-analysis-finds
-
LACMA data breach exposes customer and employee information
First seen on scworld.com Jump to article: www.scworld.com/brief/lacma-data-breach-exposes-customer-and-employee-information
-
Smashing Security podcast #482: This hacker leaked GTA 6 and launched their own cryptocurrency
A hacker calling themselves “CYBERLEEK” has been leaking gameplay footage from GTA 6 ahead of its official reveal this week – but they’re not asking Rockstar Games for a ransom. Instead, they’ve launched their own cryptocurrency, promising to release ever more juicy clips from a virtual strip club… First seen on grahamcluley.com Jump to article:…
-
WordPress Plugin Vulnerability Exposes 100,000 Sites to Complete Site Takeover Attacks
WordPress sites depend heavily on plugins to add functionality such as contact forms, file uploads, payment features, and integrations. But when a plugin mishandles uploaded files, a seemingly ordinary website feature can become a direct path to server compromise. According to Cybersecurity News, a critical vulnerability in the Everest Forms WordPress plugin has exposed more…
-
Attackers Targeted Over 100 US Water Systems in July Hacks
CISA Guidance Reveals First Federal Count of July Water Sector Targeting. The U.S. Cybersecurity and Infrastructure Security Agency said it observed more than 100 internet-exposed water systems targeted in cyberattacks in July, most reached through programmable logic controllers wired directly to cellular modems, according to recent internet exposure reduction guidance. First seen on govinfosecurity.com Jump…
-
88 ID Verification Breaches Show the Cost of Collecting Identity Data
88 ID-verification breaches exposed billions of records, highlighting the growing risks of collecting sensitive identity and biometric data. A new report from Mysterium VPN compiles 88 documented incidents since 2011 where data collected specifically to verify someone’s identity or age got breached, exposed, or sold. The confirmed and researcher-verified total sits at 2.15 billion records,…
-
Microsoft SharePoint Flaws Let Unauthenticated Attackers Execute Remote Code
Microsoft SharePoint Server administrators are being urged to patch two vulnerabilities that could be combined to allow unauthenticated remote code execution on exposed on-premises servers. The flaws, tracked as CVE-2026-55040 and CVE-2026-63520, affect SharePoint Server Subscription Edition, SharePoint Server 2019, and SharePoint Enterprise Server 2016. Microsoft SharePoint Flaws The urgency has increased after Defused reported…
-
Operation Jackal: 58 Arrests Expose the Money Laundering Machine Behind Global Scams
INTERPOL’s Operation Jackal IV made 58 arrests and exposed global networks laundering money from scams, fraud and sextortion. INTERPOL announced that Operation Jackal IV, running from November 2025 to June 2026, led to 58 arrests and identified 263 suspects tied to West African organized crime networks, groups like Black Axe that are responsible for a…
-
28,000 Exposed .git Repositories Leak Active AWS, OpenAI, Stripe and GitHub Credentials
A large-scale internet scan has uncovered 28,000 publicly accessible .git repositories exposing credentials for AWS, OpenAI, Stripe, GitHub, and other services, illustrating how a basic web server misconfiguration can turn source code history into an immediate cloud access risk. The research, published by attack-surface management firm Intruder, examined 3.5 million live HTTP hosts selected from…
-
CISA Red Team Achieves Full Domain Compromise Across Critical Infrastructure Networks
CISA’s latest red team assessment shows how common failures in Active Directory, cloud identity, and SOC processes can turn a phishing foothold into an enterprise-wide compromise. The August 25 advisory contrasts two critical-infrastructure organizations: one missed the intrusion entirely, while the other contained initial access quickly but still exposed major identity and cloud security weaknesses.…
-
How Much Does a Data Breach Cost? IBM’s 2026 Report Puts the US Average at $11.5 Million
IBM’s 2026 Cost of a Data Breach Report puts the global average at a record $4.99M, and $11.5M in the US. Here’s what actually drives the bill. First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/08/how-much-does-a-data-breach-cost-ibms-2026-report-puts-the-us-average-at-11-5-million/
-
Zimbra Exploitation Spreads as Thousands Stay Unpatched
More Than 8,000 Unpatched Instances Remain Exposed to CVE-2026-73570. Attackers have compromised at least 267 Zimbra installations through a likely CVE-2026-73570 campaign, while more than 8,000 unpatched servers remain exposed to unauthenticated remote code execution that can give attackers access to mail data and system resources. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/zimbra-exploitation-spreads-as-thousands-stay-unpatched-a-32654
-
Banks Face the Penalty But Scammers Exploit the Gaps
Australian Scam Rules Impose Tough Penalties But Leave Critical Players Unregulated Australia’s new Scams Prevention Framework promises shared responsibility for scam prevention. But gaps in coverage could leave banks exposed and victims asking who ultimately reimburses the for their fraud losses. The rules take effect in March 2027. First seen on govinfosecurity.com Jump to article:…
-
LACMA data breach last year exposed social security and medical data
The Los Angeles County Museum of Art (LACMA) has announced that a breach last year exposed customer and employee information. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/lacma-data-breach-last-year-exposed-social-security-and-medical-data/
-
Network Compliance Is Failing 50% of Enterprises. Here’s Why and How to Fix It
According to Hyperproof’s 2026 IT Risk and Compliance Benchmark Report, 50% of organizations managing compliance ad hoc suffered a data breach in 2025. Organizations using an integrated, automated approach cut that number nearly in half. That gap does not happen by accident. The breached organizations were not ignoring compliance. Most had policies, scheduled checks, and..…
-
Is Cyber Facing an Affordability Crisis?
As breach costs reach record highs and defense spending nears $240 billion, small businesses are dangerously exposed, threatening supply chain security. First seen on darkreading.com Jump to article: www.darkreading.com/cybersecurity-operations/is-cyber-facing-an-affordability-crisis-
-
The Rising Cost of Trusted Access
IBM 2026 Cost of a Data Breach Report The cost of a data breach continues to climb. According to the IBM Cost of a Data Breach Report 2026, the global average reached a record $4.99 million, up 12% from the previous year. In the United States, the average cost rose to $11.5 million, more than……

