Tag: theft
-
Services Firm ApolloMD Settles Hack Lawsuit for $4M
Settlement With Revenue Cycle Vendor Stems From Qilin Gang Attack Affecting 627,000. Revenue cycle management services firm ApolloMD Business Services has agreed to pay just over $4 million to settle proposed class action litigation stemming from a 2025 data theft claimed by ransomware gang Qilin that affected nearly a dozen physician practices and 627,000 of…
-
Craneware Confirms Data Theft After Cyberattack, Investigations Underway
Healthcare software vendor Craneware confirmed attackers stole data during a cyberattack, underscoring growing cybersecurity risks facing healthcare suppliers. The post Craneware Confirms Data Theft After Cyberattack, Investigations Underway appeared first on TechRepublic. First seen on techrepublic.com Jump to article: www.techrepublic.com/article/news-craneware-cyberattack-data-theft-2026/
-
AsyncAPI Supply Chain Attack Deploys Miasma Backdoor Through Trusted npm Workflows
AsyncAPI’s npm ecosystem suffered a coordinated supply chain compromise on July 14, 2026, delivering a Miasma”‘associated Node.js backdoor through trusted GitHub Actionsdriven release workflows and exposing high”‘value developer and CI/CD environments to remote access, credential theft, and further lateral movement. Malicious versions were shipped for @asyncapi/generator@3.3.1, @asyncapi/generator-helpers@1.1.1, @asyncapi/generator-components@0.7.1, and @asyncapi/specs@6.11.2 and 6.11.2-alpha.1, together accounting for…
-
Craneware, Abbott Probe Separate Health Data Theft Incidents
Cyberattacks Are Latest to Target Third-Party Healthcare Vendors. Cybercriminals are keeping up with their data theft assaults and other cyberattacks on a favorite target – major third-party vendors and suppliers to the healthcare sector. The most recent victims include U.K.-based software firm Craneware and U.S.-based lab testing and medical device maker Abbott. First seen on…
-
FBI Arrests Florida Man in $220,000 Steam Crypto Theft Case
FBI agents arrested a Florida man accused of spreading Steam game malware that stole $220,000 in crypto, including $32,000 from a terminally ill cancer patient. First seen on hackread.com Jump to article: hackread.com/fbi-arrests-florida-man-steam-crypto-theft-case/
-
GoldenEyeDog Threat Group Behind DigiCert Code-Signing Certificate Attack
GoldenEyeDog, a Chinese cybercrime group increasingly tracked as an advanced threat cluster, has been linked to a sophisticated intrusion into DigiCert that enabled the theft and abuse of legitimate code-signing certificates. The group has been active since at least 2015 and, since 2024, has consistently leveraged stolen or abused code-signing certificates to bypass Windows SmartScreen…
-
GoldenEyeDog Subgroup Linked to DigiCert Breach and Code-Signing Certificate Theft
Cybersecurity researchers have attributed the April 2026 DigiCert security incident to a threat activity cluster dubbed CylindricalCanine.Expel, which shared technical details of the event, described the threat actor as a sub-group of GoldenEyeDog (aka APT-Q-27, Dragon Breath, and Miuuti Group), a Chinese cybercrime group known for its targeting of the gambling and gaming sectors using…
-
TP-Link Kasa Camera Flaws Let Attackers Steal Admin Credentials and Geolocation Data
TP-Link has revealed several serious vulnerabilities affecting its Kasa EC70 and EC71 smart camera models, which could expose users to credential theft and geolocation data leakage. These vulnerabilities are CVE-2026-9770 and CVE-2026-13230 and specifically affect version 4 of both devices. Attackers with access to the same local network could exploit these flaws, raising concerns about…
-
New Spirals ransomware encrypts victim network in under 24 hours
A new ransomware actor called Spirals completed a corporate intrusion, from initial access to data theft and encryption, in less than 24 hours. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/new-spirals-ransomware-encrypts-victim-network-in-under-24-hours/
-
Hackers Pair Stolen Wallet Databases With Keychain Passwords for Offline Crypto Theft
A macOS-focused information stealer is combining stolen wallet databases with credentials harvested from the Apple Keychain, browsers, and Apple Notes to conduct offline cryptocurrency theft attempts. Detected by the MistEye security monitoring system, the malware appears designed for broad data collection rather than a single targeted objective. Its collection scope includes macOS Keychain files, Safari…
-
New tutorials on underground hacking forums have roughly doubled
Underground hacking forums are producing more original tutorials again, with growing attention on financial fraud, particularly the theft and fraudulent use of payment card … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/07/14/underground-hacking-forums-tutorials-research/
-
Microsoft Maps Year-Long ShinyHunters-Linked Salesforce Data Theft Across Three Paths
Attackers whose methods line up with the data-extortion group ShinyHunters have spent the past year walking into corporate Salesforce environments without exploiting a single flaw in the platform.The way in has been the trust the organization had already extended, usually through the OAuth connections that tie Salesforce to the apps and third-party vendors around it.In…
-
Microsoft Maps Year-Long ShinyHunters-Linked Salesforce Data Theft Across Three Paths
Attackers whose methods line up with the data-extortion group ShinyHunters have spent the past year walking into corporate Salesforce environments without exploiting a single flaw in the platform.The way in has been the trust the organization had already extended, usually through the OAuth connections that tie Salesforce to the apps and third-party vendors around it.In…
-
ModHeader Chrome Extension Exposes 900,000 Users to Potential Browsing History Theft
ModHeader version 7.0.187.0.187.0.18, a popular Chrome extension used for modifying HTTP headers, contained dormant code capable of collecting and exfiltrating browsing history data from an estimated 900,000 users, according to research disclosed on July 13, 2026. Google removed the extension from the Chrome Web Store on Friday, July 10, following a responsible disclosure. Organizations should…
-
UK and EU impose sanctions on hacking groups linked to Kremlin
Tags: attack, credentials, group, hacker, hacking, infrastructure, intelligence, router, russia, theft, vulnerabilityHackers linked to Russian intelligence behind attack on Poland’s energy infrastructure, theft of credentials and using vulnerable routers to attack critical national infrastructure First seen on computerweekly.com Jump to article: www.computerweekly.com/news/366645662/UK-and-EU-impose-sanctions-on-hacking-groups-linked-to-Kremlin
-
Forg365 PhaaS Targets Microsoft 365 with Device Code and AitM Session Theft
A new phishing-as-a-service (PhaaS) operation called Forg365 is using a combination of device code phishing, adversary-in-the-middle (AitM) tactics, antibot evasion, artificial intelligence (AI)-assisted lure creation, and post-compromise mailbox operations targeting Microsoft 365 accounts.Distributed via Telegram and costing $400 a month (or $3,800 per year), attack chains leverage phishing First seen on thehackernews.com Jump to article:…
-
AssuranceAmerica Breach Exposes 7 Million Driver’s Licenses After Employee Account Hack
AssuranceAmerica confirmed a breach exposing nearly 7 million driver’s licenses after hackers compromised an employee account and stole customer data. U.S. auto insurer AssuranceAmerica has confirmed a data breach affecting nearly 7 million people, making it the largest known theft of Americans’ driver’s license information in 2026. >>In a data breach notice sent to customers…
-
GodDamn Ransomware Attack Uses PsExec Lateral Movement and NirSoft Toolkit for Credential Theft
A targeted GodDamn ransomware incident shows the payload is not entirely new but the latest rebrand of a long-running family. Analysis reveals strong code overlap with Beast (the 2024 rebrand of Monster), and the operational playbook mirrors earlier Hyadina campaigns. Stealthy foothold, credential harvesting using NirSoft utilities, kernel-level defense subversion, remote-access tooling, and PsExec-driven lateral…
-
RedHook Abuses Accessibility Service to Enable Developer Options and Wireless Debugging
RedHook, an Android Remote Access Trojan (RAT) first profiled in July 2025, has resurfaced with a markedly more dangerous capability: autonomous abuse of Android’s ADB Wireless Debugging to acquire shell-level privileges (uid 2000). While its baseline toolkit screen streaming, keylogging, Accessibility-driven UI manipulation and credential theft remains intact, the latest RedHook builds demonstrate a deliberate…
-
RedHook Abuses Accessibility Service to Enable Developer Options and Wireless Debugging
RedHook, an Android Remote Access Trojan (RAT) first profiled in July 2025, has resurfaced with a markedly more dangerous capability: autonomous abuse of Android’s ADB Wireless Debugging to acquire shell-level privileges (uid 2000). While its baseline toolkit screen streaming, keylogging, Accessibility-driven UI manipulation and credential theft remains intact, the latest RedHook builds demonstrate a deliberate…
-
Accenture Confirms Breach After Hacker Claims 35GB Data Theft
The Accenture breach reinforces the need to secure development environments. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/threats/accenture-confirms-breach-after-hacker-claims-35gb-data-theft/
-
Vidar Infostealer Hammers SMBs via Malvertising Campaign
A financially motivated operation uses lures of cracked or pirated software to deliver a malware two-for-one combo for data theft and cryptomining. First seen on darkreading.com Jump to article: www.darkreading.com/cyberattacks-data-breaches/vidar-infostealer-smb-malvertising-campaign
-
Accenture acknowledges security incident following 35GB data theft claim
Accenture appears to have suffered a data breach, the extent of which is currently unknown. On Monday, a threat actor going by the handle >>888<< posted on the … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/07/08/accenture-data-breach-2026/
-
AI-as-a-Service Botnet Routes Malicious Workloads Across Compromised Windows and Linux Hosts
The underground advertisement for the so-called Mycelium Framework reads like another feature”‘packed botnet sales pitch: cross”‘platform payloads, encrypted C2, persistence, exploit modules, credential theft, and lateral movement. Those building blocks are not new. What makes Mycelium notable is its advertised purpose to treat compromised endpoints not as disposable bots but as a capability”‘aware. AI compute…
-
Dialogflow CX ‘Rogue Agent’ Flaw Enabled AI Chatbot Data Theft
Varonis reported the flaw to Google in late 2025 and it has been addressed, but it reminds defenders to take a fresh look at their AI Infrastructure security. First seen on darkreading.com Jump to article: www.darkreading.com/application-security/dialogflow-cx-rogue-agent-flaw-enabled-ai-chatbot-data-theft
-
Opera GX browser vulnerability could allow data theft and DoS attacks
First seen on scworld.com Jump to article: www.scworld.com/brief/opera-gx-browser-vulnerability-allows-data-theft-and-dos-attacks
-
U.S. Government Agency Paid $1M to Data Extortion Group Kairos
Tags: blockchain, data, data-breach, extortion, government, group, ransom, ransomware, theft, threatA U.S. government agency paid $1M to Kairos, a group focused on data theft and extortion rather than ransomware, Ransom-ISAC reports. A new case study from Ransom-ISAC reconstructs a complete data-extortion incident involving a U.S. government body and a threat actor called Kairos, using a leaked negotiation transcript and blockchain tracing of the ransom payment.…

