< ciso
brief />
Incidents and Data Breaches Banner

All news in category “Incidents and Data Breaches

3296 articles

FBI Disrupts China-Linked QTFY Botnet Operations

🔒 The U.S. Department of Justice and FBI announced the disruption of two hacking platforms, QScan and QTRouter, used by the China-linked group QTFY to target U.S. critical infrastructure and sensitive networks. Lumen Black Lotus Labs, which tracked the group since 2018, collaborated with the FBI after observing extensive targeting of research and public sector organizations. QScan infected IoT devices to build a proxy mesh while QTRouter and associated services obfuscated attack origins using compromised routers, commercial proxy services, and leased VPSs. The court-authorized seizure of hard-coded domains caused the platforms to cease operations.
read more →

Boston Scientific hit by cyberattack disrupting operations

🔒 Boston Scientific reported a cyberattack detected on August 25 that disrupted IT systems and caused global operational impacts, including difficulties processing and shipping customer orders. The company activated its incident response plan and engaged external cybersecurity experts to investigate and contain the intrusion. Boston Scientific said it does not yet know when all affected systems will be fully restored and continues to assess the scope and consequences of the incident. The SEC filing offered no details on the attacker, initial access, or whether data was exposed.
read more →

Attackers Target SharePoint RCE Chain and PoC Exploits

🛡️ Defused warns attackers are chaining two Microsoft SharePoint flaws — CVE-2026-55040 and CVE-2026-63520 — to achieve remote code execution on unpatched servers. Public proof-of-concept exploits were published in August and were quickly weaponized, with probes observed against honeypots and large-scale internet-exposed SharePoint instances. CISA has issued directives to secure SharePoint servers while Microsoft monitors exploitation activity.
read more →

Tortoiseshell expands toolkit with backdoor, SSH tunnel

🛡️ Group-IB identified new Tortoiseshell activity, uncovering a reverse SSH tunneling utility and a C++ backdoor disguised as wtsapi32.dll. The SSH tool leverages Windows OpenSSH to create reverse tunnels into compromised networks, while the backdoor supports HTTPS C2 communications, file and shell execution, and in-memory DLL loading. Researchers also linked domains resolving to servers with regional subdomains, suggesting possible targeting across Europe and the Middle East and urging enhanced threat hunting and monitoring.
read more →

CISA red team reveals starkly different SOC outcomes

🛡️ CISA released dual red team reports showing two critical infrastructure organizations were fully domain-compromised using similar tradecraft. Organization A suffered extensive undetected access due to default machine account quotas, misconfigured AD CS templates, cleartext credentials, static cloud keys, and fragmented SOC visibility. Organization B detected and isolated initial footholds quickly, limiting spread despite similar underlying weaknesses, illustrating the decisive role of people and processes.
read more →

INTERPOL Operation Jackal IV Targets West African Crime

🛡️ An eight-month INTERPOL operation has led to 58 arrests and the identification of 263 suspects linked to West African organized crime groups, including Black Axe. The effort, involving 22 countries across six continents, targeted cyber-enabled fraud, romance and investment scams, and money laundering. Investigations uncovered a major crime-as-a-service network and disrupted call-center and syndicate operations responsible for large-scale thefts and laundering.
read more →

Phishing-as-a-Service Exploits AI Calls to Strip Activation Lock

📣 SOCRadar researchers uncovered a PhaaS platform called AnonyMousKIT that uses rented AI voice agents and multi-channel lures to trick owners of recently lost or stolen Apple devices into revealing passcodes, Apple ID credentials, and live 2FA codes. The service is credit-metered across email, SMS, WhatsApp, recorded calls, and AI calls, and its capture pages show device model and Find My status to increase believability. Calls—mostly to Brazil—ran between August 2025 and May 2026, and the kit is offered through multiple storefronts with shared infrastructure and operational features resembling a small criminal SaaS business.
read more →

LACMA breach exposed Social Security and medical data

🔒 The Los Angeles County Museum of Art (LACMA) disclosed a data breach discovered in July 2025 after suspicious activity began four days earlier. The investigation, updated in February 2026 and finalized over a year later, determined that attackers may have accessed sensitive customer and employee records. Exposed elements include full names, dates of birth, Social Security numbers, government IDs, partial financial and card data, health insurance details, and medical treatment information. LACMA has notified law enforcement and affected individuals, offered one year of identity protection through Financial Shield, and set up a dedicated support line while recommending monitoring and credit protections.
read more →

Attackers Abuse npm Mirrors to Host Phishing Pages

📄 Threat actors are abusing npm packages and public mirrors to host malicious HTML that impersonates Cloudflare CAPTCHA pages and redirects visitors to attacker-controlled sites. Security researchers found multiple npm packages containing a single index.html that, when served through mirrors like unpkg, renders from legitimate domains and executes obfuscated JavaScript to redirect users. Some payloads fetch remote configuration (via api.keyval.org) allowing attackers to change redirect targets without republishing packages. OX Security warns mirrors can act as free frontend hosts for phishing content and recommends treating direct HTML requests to npm mirrors as suspicious.
read more →

AnonyMousKIT PhaaS Uses Voice AI to Phish iPhones

🔍 Researchers uncovered AnonyMousKIT, a phishing-as-a-service platform active since early 2024 that automates retrieval of codes to unlock stolen Apple devices and bypass Activation Lock. The service powers a broad ecosystem of 168 reseller storefronts and 506 linked domains. SOCRadar investigators recovered call records and transcripts showing voice AI agents impersonating Apple support to extract passcodes and account credentials, with most calls targeting Brazil.
read more →

Massive DDoS Disrupts Norway’s Government Services

🔒 A large DDoS attack began at 03:38 CEST, disrupting the Norwegian Digitalization Agency (Digdir) and its provider Vivicta, affecting public-service logins, electronic IDs and signatures, secure digital mail, and inter-agency data exchange. Several services were briefly unavailable and some, including ID-porten and eSignering, remain partially inaccessible, causing login errors and slow responses. Digdir reports stabilization of many systems, no evidence of a security breach or personal data compromise, and has notified NSM and Datatilsynet. This is the third recent DDoS against Digdir; there is no official attribution but media have speculated about Russian involvement.
read more →

Nutex Health confirms data exfiltration after breach

🛡️ Nutex Health disclosed a cyberattack in an SEC filing after discovering that an unauthorized third party accessed and exfiltrated data from company servers. The company, which operates 28 facilities across 12 states, engaged external incident-response and forensic teams, activated its cybersecurity plan, and notified law enforcement. Nutex is still determining the types of data affected and whether patients, employees, or partners were impacted.
read more →

ZeroTokens phishing platform enables live session control

🔒 A phishing platform named ZeroTokens gives attackers live visibility into victim sessions and lets operators change prompts in real time to steer interactions. The campaign, analyzed by Abnormal AI on August 25, sent over 45,000 messages to more than 24,000 recipients across 700+ organizations, using convincing pretexts and legitimate-looking email authentication. The platform replicated financial institutions' verification flows, collected credentials and codes, and used persistent WebSocket connections to relay victim inputs to operator consoles for adaptive attacks.
read more →

Large-Scale Debt-Relief Phishing Campaign Blocked

📧 Check Point detected and blocked a widespread email phishing campaign that used fraudulent debt-relief and financial hardship offers to trick recipients into calling attacker-controlled phone numbers. Over 14 days, about 24,700 messages targeted users at more than 9,000 organizations, highlighting phishing tactics that rely on social engineering and phone-based conversion rather than malicious links or attachments. Check Point Email Security uses AI, threat intelligence, and intent analysis to stop such campaigns before users engage.
read more →

Fake recruiter phishing targets corporate mobile logins

🔍 Researchers at Zimperium’s zLabs uncovered recruitment-themed phishing campaigns that target corporate credentials on mobile devices by presenting full-screen counterfeit login pages and rejecting personal email domains to prioritize enterprise accounts. The activity, linked to RecruitTrap, impersonated major employers and persisted across cloud, hosting and domain-parking providers, exposing gaps in URL blocklists. Zimperium recommends securing mobile identity touchpoints and dynamically inspecting network traffic to detect credential harvesting.
read more →

Mirage2FA Surge: Microsoft 365 Session Hijacks Rise

🛡️ The Mirage2FA campaign (2024–2026) has impacted thousands of organizations by abusing legitimate Microsoft 365 login flows to bypass two-factor authentication. ANY.RUN research links the activity to 4,532 unique organization domains, with 63.7% of victims in the US and others across multiple regions. Attackers steal passwords and session cookies to hijack authenticated sessions, enabling impersonation, fraud, and access to SSO-connected services.
read more →

Global cybercrime crackdown leads to dozens of arrests

📰 International law enforcement actions led to the identification of 263 suspects and 58 arrests connected to West African-organized cybercrime networks during Operation Jackal IV, conducted from November 2025 to June 2026. The operation targeted the Black Axe syndicate and related groups involved in romance, cryptocurrency, investment scams and business email compromise, with arrests and seizures across Argentina, South Africa, Romania and Italy. Authorities disrupted money-laundering services, blocked accounts and confiscated millions while highlighting the use of Crime-as-a-Service and coercion tactics against victims.
read more →

ReliaQuest: ShinyHunters Social Engineering Incident

🛡️ ReliaQuest disclosed a social engineering campaign by ShinyHunters that briefly exposed its identity dashboard but said claims of a compromise or ransomware targeting are false. The attacker used a lookalike domain and fake SSO page, convincing one employee to approve a push and gain a brief, view-only session. ReliaQuest emphasized robust controls—device trust, session termination, password expiry and auth resets—prevented access to applications or customer data.
read more →

US Imposes Sanctions Targeting Mabna Cyber Unit

🔒 The US announced Operation Economic Outcast on August 24, targeting nearly 60 individuals and entities to disrupt financial flows sustaining Iran. Five people linked to the Mabna Institute were sanctioned, following a Department of Justice indictment of 17 alleged members for long-running cyber-espionage. OFAC also published 30 crypto addresses tied to four defendants, with blockchain analysis tracing roughly $16.8m of funds. The measures expand sectoral sanctions, increasing compliance burdens for crypto and financial firms.
read more →

miniOrange SAML plugin under active exploitation

🔒 Patchstack and DigitalOcean reported active exploitation attempts against miniOrange SAML 2.0 Single Sign On, where two unauthenticated flaws allow attackers to authenticate as any WordPress user, including admins. The issues are tracked as CVE-2026-61979 and CVE-2026-15981 and have been fixed in recent Standard edition updates. Owners are urged to update immediately due to available PoC code and observed opportunistic scanning from multiple IPs.
read more →