Tag: theft
-
EHR Vendor Notifying 3.8 Million Patients of Data Theft Hack
CareCloud Said Compromise Involved One of Its AWS Cloud Environments. CareCloud, a provider of cloud-based, artificial intelligence-powered electronic health records, is notifying nearly 3.8 million individuals that their personal and health information was potentially stolen in a March hacking incident involving one of its Amazon Web Services environments. First seen on govinfosecurity.com Jump to article:…
-
Rising Number of Cyberattacks Have AI-Assisted Fingerprints
Claude Code Especially Tied to Semi-Automated Intrusions, Data Theft, Ransomware. Attackers’ operational security fails reveal they’re increasingly wielding artificial intelligence tools in semi-autonomous ways to help them conduct reconnaissance and perpetrate ransomware infections and data exfiltration at greater speed and scale than ever before – albeit with mixed results. First seen on govinfosecurity.com Jump to…
-
US charges Iranian hackers over $3.4 billion intellectual property theft
The U.S. has charged 17 Iranians, alleged members of a hacking-for-hire company called Mabna Institute, involved in years-long operations that stole data from American organizations. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/us-charges-iranian-hackers-over-34-billion-intellectual-property-theft/
-
The long tail of Clop’s PTC hack is just beginning to emerge
The data theft extortion group likely compromised a critical vulnerability affecting PTC’s product lifecycle management software in June, a month before it sent threatening emails to victims. First seen on cyberscoop.com Jump to article: cyberscoop.com/clop-zero-day-attacks-ptc-windchill-flexplm/
-
Balonx PhaaS Steals Bank OTPs in Real Time While AI Calls and Android RAT Target Victims
Mexico’s banking sector is facing a more industrialized fraud threat as the Balonx Sistema phishing-as-a-service (PhaaS) operation combines real-time OTP theft, Android malware, and AI-generated vishing calls. Balonx is not a conventional credential-harvesting kit. It operates as a subscription-based criminal service that rents access to affiliates, lowering the barrier for telemarketing fraud groups and inexperienced…
-
Microsoft Links 30+ Domains to MacSync Stealer’s Credential-Theft and Data-Exfiltration Infrastructure
More than 30 domains tied to MacSync Stealer, exposing a rotating macOS-focused infrastructure that supports payload delivery, command-and-control, credential theft, staging, and chunked data exfiltration. The investigation shows why defenders should prioritize repeatable endpoint and network behavior over static domain-based detections. Observed executions originate from interactive zsh sessions and use curl to fetch payloads from…
-
RAVEN Tool Steals Entire Elasticsearch Databases and Rebuilds Deleted Backdoors
The RAVEN offensive framework can turn compromised Elasticsearch and Kibana environments into durable data-theft and persistence operations. RAVEN, short for Reconnaissance & Attack on Vulnerable Elasticsearch Nodes, is an open-source modular framework built to assess Elasticsearch and Kibana security posture across reconnaissance, exploitation, exfiltration, persistence, and cleanup workflows. Its latest walkthrough focuses on post-exploitation against…
-
Clop created custom web shell for Windchill data theft attacks
A custom Java web shell likely linked to the Clop ransomware gang was designed specifically for PTC Windchill and FlexPLM servers, with built-in features to decrypt credentials, enumerate file repositories, and steal files. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/clop-created-custom-web-shell-for-windchill-data-theft-attacks/
-
Law Firms Increasingly Targeted By Ransomware/Vishing Attacks
Law firms face growing ransomware and data-theft threats as attackers target privileged client information, exposing firms to cybersecurity, ethical and legal risks. First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/08/law-firms-increasingly-targeted-by-ransomware-vishing-attacks/
-
JWR Phishing-as-a-Service Kit Uses WebSockets and AES to Run Real-Time Banking Fraud
JWR, an undocumented phishing-as-a-service (PhaaS) framework that turns conventional credential theft into an operator-led, real-time banking and payment fraud operation. Rather than waiting for a victim to submit a form, JWR streams keystrokes to an attacker over an AES-CTR-encrypted WebSocket channel, allowing the operator to react while card numbers, passwords and one-time codes are still…
-
New Mirai-Based Evooo1Bot Botnet Targets Linux Devices
Evooo1Bot is a Mirai-based Linux botnet that hijacks routers and IoT devices for DDoS attacks, credential theft and criminal proxy services. Fortinet’s FortiGuard Labs disclosed Evooo1Bot in mid-August, a previously undocumented Linux botnet that’s been active since July 2026. The bot borrows Mirai’s DDoS engine but adds encrypted command-and-control communications, an SSH brute-force scanner, a…
-
Hackers Turn Claude Code and Codex Into AI-Powered Tools for Credential Theft and Cloud Attacks
Threat actors are increasingly using coding assistants as operational tools. Detailed research from Gambit Security highlights three campaigns where Claude Code, OpenAI Codex, and large language models facilitated activities ranging from ransomware preparation to the harvesting of secrets on a large scale and exploiting cloud accounts. These cases demonstrate how AI can speed up attackers’…
-
Shadow hVNC Malware Kit Gives Hackers Hidden Windows Desktop for Covert Remote Control
A newly advertised malware-as-a-service toolkit named Shadow hVNC combines browser credential theft, hidden virtual desktop control, reverse proxying, and extensive persistence into a single Windows-focused payload. Marketed by a user known as “RemoteX” in March 2026, the kit gives operators a parallel Win32 desktop where they can browse, run tools, and interact with hijacked sessions…
-
Clop Claims Data Theft From More Than 40 Companies
Victims Are Assessing Claims of Stolen Databases, CAD Files and Backups. Russia-linked Clop claims it stole databases, engineering files, backups and other sensitive corporate data from more than 40 organizations in a breach wave tied to exploitation of a critical remote code execution flaw in PTC Windchill and FlexPLM. First seen on govinfosecurity.com Jump to…
-
Hack on Med Software Firm Hits Half of Poland’s Population
19M Patients Affected by Data Theft Including National ID Numbers. A hack into IT systems of MyDr, a Polish provider of electronic medical documentation software, has affected more than 12,000 healthcare facilities and nearly 19 million individuals in Poland, about half the country’s population. Government officials have launched an investigation. First seen on govinfosecurity.com Jump…
-
Philips and GE Investigate Clop Ransomware Data Theft Claims
Philips and GE are investigating Clop data theft claims potentially linked to a PTC vulnerability. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/threats/philips-and-ge-investigate-clop-ransomware-data-theft-claims/
-
Apple Mac Malware Lets Attackers Control Browser Sessions After Infection
AmnesiaStealer malware targets macOS with data theft and remote browser-session control, potentially exposing accounts already open on compromised Macs. The post Apple Mac Malware Lets Attackers Control Browser Sessions After Infection appeared first on TechRepublic. First seen on techrepublic.com Jump to article: www.techrepublic.com/article/news-amnesiastealer-mac-malware/
-
Linux Botnet Evooo1Bot Expands Mirai Capabilities Well Beyond DDoS
The botnet adds exploitation modules, credential theft, and reverse SOCKS relays to turn compromised devices into persistent attacker infrastructure. First seen on darkreading.com Jump to article: www.darkreading.com/cyber-risk/linux-botnet-evooo1bot-mirai-capabilities-beyond-ddos

