Tag: theft
-
Medtronic Notifying Patients Affected by Data Theft Hack
Ransomware Gang ShinyHunters Gang Claimed It Stole 9M Records From Device Maker. Medical device maker Medtronic has begun notifying a yet undisclosed number of patients that their information, including health records and Social Security numbers – was compromised in an April cyber incident. ShinyHunters had earlier claimed to steal more than 9 million of the…
-
New BioShocking attack manipulates AI browser into data theft
A new prompt injection attack dubbed “BioShocking” could trick AI-powered browsers into treating real-world risky actions as part of a fictional scenario, causing them to ignore any safety guardrails. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/new-bioshocking-attack-manipulates-ai-browser-into-data-theft/
-
Nissan Traces Data Breach to PeopleSoft Zero-Day Exploit
Extortionists Add National Association of Insurance Commissioners to Breach List. Japanese automotive giant Nissan and the U.S. National Association of Insurance Commissioners are the latest organizations to confirm they fell victim to cyber extortionists who recently wielded a zero-day exploit against Oracle PeopleSoft, leading to the theft of data. First seen on govinfosecurity.com Jump to…
-
Boss Scam Uses DLL Sideloading to Hijack WhatsApp Web and Defraud Enterprises
The new “Boss Scam” is a sharp escalation in CEO fraud: attackers now combine impersonation, Windows DLL sideloading, and WhatsApp Web session theft to turn trusted executive channels into fraud infrastructure. The campaign was highlighted in advisories tied to India’s I4C and NCTAU, which warned that attackers pose as regulators or senior bosses, deliver malicious…
-
Nissan discloses employee data breach linked to Oracle zero-day attacks
Nissan is warning that it suffered a data breach affecting current and former employees after threat actors exploited an Oracle PeopleSoft vulnerability in data theft attacks previously linked to the ShinyHunters extortion group. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/nissan-discloses-employee-data-breach-linked-to-oracle-zero-day-attacks/
-
Amazon Q VS Extension Flaw Leads to Cloud Credential Theft
Adversaries could plant a malicious repository that can execute arbitrary code and steal cloud credentials by exploiting the vulnerability, which showcases growing MCP risk. First seen on darkreading.com Jump to article: www.darkreading.com/cloud-security/amazon-q-vs-extension-flaw-leads-cloud-credential-theft
-
4 arrested in Poland for SIM-swapping and cryptocurrency theft
First seen on scworld.com Jump to article: www.scworld.com/brief/four-arrested-in-poland-for-sim-swapping-and-cryptocurrency-theft
-
NAIC confirms cyberattack after ShinyHunters claims 3.1TB data theft
First seen on scworld.com Jump to article: www.scworld.com/brief/naic-confirms-cyberattack-after-shinyhunters-claims-3-1tb-data-theft
-
Grand Theft Auto VI hype fuels new wave of scams targeting gamers
First seen on scworld.com Jump to article: www.scworld.com/brief/grand-theft-auto-vi-hype-fuels-new-wave-of-scams-targeting-gamers
-
Third-Party Breach at Polymarket Leads to $2.94M Crypto Theft
Polymarket confirmed hackers stole funds from some users after attackers injected malicious code through a compromised third-party vendor. Polymarket confirmed that a security breach at a third-party vendor allowed attackers to inject malicious code into its website, leading to the theft of funds from an undisclosed number of users. The company said it has contained…
-
CMC Releases Analysis and Guidance for Education Sector After Canvas Data Breach
The UK Cyber Monitoring Centre reviews the Canvas breach affecting 160 UK universities, highlighting data theft risks and financial impacts of cyber incidents First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/cmc-analysis-education-canvas-data/
-
Iranian Hacker Arrested Over Alleged $3.4 Billion Cyberattack on USA Infrastructure
An alleged Iranian hacker accused of hacking US infrastructure has been arrested in Montenegro following a joint operation by Montenegrin police and the U.S. Federal Bureau of Investigation (FBI). The suspect is expected to face charges related to computer fraud, hacking, conspiracy, and identity theft after authorities linked him to a years-long cyber campaign that…
-
AI Firms Seek US Help Against China Model Distillation
Anthropic Says Legal Gaps Leave Frontier Labs Vulnerable to LLM Copying. U.S.-based AI companies are urging the U.S. government to crack down on alleged illicit model distillation by Chinese AI developers, arguing current protections lack enforcement. Anthropic and others say legal reforms and clearer antitrust rules are needed to deter theft of frontier AI models.…
-
Poland busts SIM-swapping gang tied to millions in crypto theft
Authorities in Poland have arrested four members of an organized cybercrime group accused of breaching telecommunications partners and hijacking email accounts to carry out SIM-swapping attacks. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/poland-busts-sim-swapping-gang-tied-to-millions-in-crypto-theft/
-
GTA 6 Early Access Scam Uses Fake VIP Pages to Steal Cryptocurrency Payments
A fresh wave of scam websites is exploiting the fevered anticipation for Grand Theft Auto VI, offering “VIP early access” in exchange for cryptocurrency payments and delivering nothing in return. These pages are carefully designed to look legitimate neon Vice Citystyle art, official-looking logos, luxury-car imagery and polished layouts then instruct victims to pay hundreds…
-
LastPass Confirms Customer Data Breach After Klue OAuth Token Theft
LastPass has confirmed it was affected by the Klue supply chain incident, saying an unauthorised actor used stolen… First seen on hackread.com Jump to article: hackread.com/lastpass-customer-data-breach-klue-oauth-token/
-
GTA 6 early access offers are taking gamers’ crypto
Scam websites are circulating across the internet with a pitch aimed at millions of gamers: a way to play Grand Theft Auto VI before its release. The pages promise early … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/06/23/gta-6-early-access-scam/
-
GTA 6 early access offers are taking gamers’ crypto
Scam websites are circulating across the internet with a pitch aimed at millions of gamers: a way to play Grand Theft Auto VI before its release. The pages promise early … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/06/23/gta-6-early-access-scam/
-
GTA 6 early access offers are taking gamers’ crypto
Scam websites are circulating across the internet with a pitch aimed at millions of gamers: a way to play Grand Theft Auto VI before its release. The pages promise early … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/06/23/gta-6-early-access-scam/
-
GTA 6 early access offers are taking gamers’ crypto
Scam websites are circulating across the internet with a pitch aimed at millions of gamers: a way to play Grand Theft Auto VI before its release. The pages promise early … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/06/23/gta-6-early-access-scam/
-
North Korean Hackers Poison Mastra AI Framework
Tags: ai, attack, backdoor, credentials, framework, hacker, malicious, microsoft, north-korea, software, supply-chain, theft, toolMore Than 140 npm Packages Carried Credential-Stealing Code. Microsoft says North Korean-linked BlueNoroff compromised a Mastra npm maintainer account and published more than 140 malicious packages, using a software supply-chain attack to distribute infostealers, backdoors and credential theft tools through AI development environments. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/north-korean-hackers-poison-mastra-ai-framework-a-32042
-
JaredFromSubway MEV bot hacked in $15 million crypto theft
The JaredFromSubway Ethereum MEV (Maximal Extractable Value) bot suffered a $15 million loss after an attacker manipulated the opportunity-detection logic by creating fake cryptocurrency trading opportunities. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/jaredfromsubway-mev-bot-hacked-in-15-million-crypto-theft/
-
Lawsuits Already Getting Filed in Drug Maker’s Data Thefts
Proposed Class Action Litigation Allege Negligence by Novo Nordisk, Other Claims. Attorneys have filed the first of undoubtedly many proposed class action lawsuits against drug maker Novo Nordisk by a patient and a former employee who say the company was negligent in failing to protect their sensitive information from cybercriminals. First seen on govinfosecurity.com Jump…
-
Salesforce Disables Klue Integration After OAuth Token Theft Hits Customer Data
Icarus extortion group used a legacy Klue Battlecards credential to bypass security and steal bulk Salesforce records from affected companies. First seen on hackread.com Jump to article: hackread.com/salesforce-disables-klue-integration-oauth-token-data/
-
Salesforce Disables Klue Integration After OAuth Token Theft Hits Customer Data
Icarus extortion group used a legacy Klue Battlecards credential to bypass security and steal bulk Salesforce records from affected companies. First seen on hackread.com Jump to article: hackread.com/salesforce-disables-klue-integration-oauth-token-data/
-
Salesforce Disables Klue Integration After OAuth Token Theft Hits Customer Data
Icarus extortion group used a legacy Klue Battlecards credential to bypass security and steal bulk Salesforce records from affected companies. First seen on hackread.com Jump to article: hackread.com/salesforce-disables-klue-integration-oauth-token-data/
-
Fortinet Warns of Active FortiBleed Credential Theft Attacks on FortiGate Devices
Tags: advisory, attack, authentication, credentials, cyber, data-breach, exploit, fortinet, theft, threatFortinet has issued a security warning about ongoing credential-harvesting attacks targeting FortiGate devices in a campaign known as “FortiBleed.” Threat actors are exploiting weak authentication practices rather than any newly disclosed vulnerabilities. A PSIRT advisory released on June 19, 2026, by Carl Windsor indicates that the attackers are reusing previously exposed credentials from earlier incidents,…
-
Nintendo America Employee Data Exposed After Shadowbyt3$ Targets TinyPulse
Nintendo America employee records were exposed via TinyPulse after Shadowbyt3 claimed theft of HR files, tax forms, bank data, and staff survey responses. First seen on hackread.com Jump to article: hackread.com/nintendo-america-employee-data-shadowbyt3-tinypulse/
-
Klue Confirms OAuth Token Theft Led to Salesforce Data Heist
‘Compromised Legacy Credential’ Wielded by Extortion Group Calling Itself Icarus. Marketing intelligence platform Klue confirmed an attacker breached its infrastructure, saying they used a compromised legacy credential to obtain OAuth access tokens for integrated services and stole data directly from Klue customers’ Salesforce and Gong instances. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/klue-confirms-oauth-token-theft-led-to-salesforce-data-heist-a-32024
-
Klue breach lead to Salesforce data theft, Huntress affected
Cybersecurity vendor Huntress was among multiple companies hit by a breach originating at Klue, a market intelligence platform used to integrate CRM and sales data across … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/06/19/klue-salesforce-data-breach-huntress/

