< ciso
brief />
Incidents and Data Breaches Banner

All news in category “Incidents and Data Breaches”

3607 articles · page 10 of 181

AI-aided chain let researchers hijack OpenAI staff accounts

🔎 Three Hacktron researchers used Anthropic's Claude Opus 5 to chain a Discourse libheif image bug with an OpenAI login weakness and take over ChatGPT and Codex accounts of several OpenAI employees. The team reported the issue, created a benign pull request to prove access, and stopped; OpenAI patched and awarded a $6,500 bounty. The exploit relied on an outdated libheif in the forum VM and the shared SSO between the forum and internal tools, highlighting risks for services that accept HEIF/AVIF images and reuse sign-on across trust boundaries.
read more →

Critical Pre‑Auth RCE in Orkes Conductor Actively Exploited

🛡️ Fortinet and other telemetries report active exploitation of CVE-2026-58138, a critical unauthenticated remote code execution flaw in Orkes Conductor. The vulnerability affects versions 3.21.21 through 3.30.1 and allows attackers to execute arbitrary OS commands by submitting crafted workflow definitions containing JavaScript or Python expressions to the workflow API. Exploits leverage unsandboxed GraalVM evaluators with unrestricted host access, and multiple vendors have observed in-the-wild attempts. Users are urged to upgrade to Conductor 3.30.2 or later and apply network mitigations if immediate patching is not possible.
read more →

Gyazo breach exposes millions of user records

🛡️ Gyazo, a cloud-based screenshot and screen-recording service, confirmed a data breach after attackers exploited a server vulnerability on September 11, 2026, stealing roughly 23.62 million user records. The company detected the activity on September 12, patched the flaw, and has taken the service offline for maintenance while investigating with external experts. Exposed data may include names, emails, password hashes, session tokens, image metadata, and more, prompting recommendations that users change reused credentials and watch for suspicious communications.
read more →

GhostCode device-code phishing targets Microsoft 365

🔒 Researchers at eSentire discovered GhostCode, a phishing kit that abuses Microsoft’s OAuth 2.0 device authorization flow to trick users into granting attacker-controlled devices access to Microsoft 365 accounts. Victims are lured via procurement-themed social engineering to enter device codes on legitimate Microsoft sign-in pages, completing MFA for the attacker’s session. Stolen tokens enabled automated device registration, Intune enrollment and acquisition of Primary Refresh Tokens (PRTs), persisting access even after token revocation. eSentire recommends restricting device-code flow via Conditional Access, monitoring device registrations and Python-based user agents, and auditing Entra ID for suspicious device patterns.
read more →

RatHat Android malware uses AI for adaptive control

🛡️ Zimperium zLabs discovered RatHat, an Android malware that leverages an AI-powered subsystem to remotely navigate compromised devices. Distributed via malvertising, SMS, and phishing sites hosting APKs, RatHat abuses Accessibility permissions to enable Developer Options and Wireless Debugging. It installs a Go-based agent for ADB-level commands, persistence, and self-restoration, and a second agent for persistent FRP reverse-proxy tunnels. The malware overlays HTML on banking and crypto apps, intercepts SMS and notifications, captures credentials and unlock patterns, and uses anti-analysis techniques to evade detection.
read more →

US agencies investigate cyber intrusion on supertanker

🚢 The US Coast Guard and FBI boarded the Liberian-flagged VL Prosperity after indications its network may have been compromised during a voyage from Egypt to Galveston. The alleged intrusion reportedly affected fuel systems, engine speed and communications for about 30 hours before a specialised team spent four days eradicating the threat. Authorities report no injuries or environmental impact while urging stronger cyber hygiene and network segmentation.
read more →

Gyazo breach exposes millions of user records

🔒 Helpfeel's image-sharing service Gyazo disclosed a breach that exposed about 23.62 million user records and roughly 490 million image metadata records, mostly from January 2019 or earlier. The attacker exploited a vulnerability in Gyazo's image upload server to run arbitrary commands and access the database; Helpfeel has disabled some image viewing and urged users to change passwords and watch for suspicious messages. The company says no payment data was exposed and external forensics are ongoing.
read more →

Cisco alerts on exploited ISE authentication bypass zero-day

🔒 Cisco has issued urgent updates for a maximum-severity Identity Services Engine vulnerability being actively exploited in the wild. The flaw (CVE-2026-76460) allows remote attackers to bypass authentication via a vulnerable API in Cisco ISE and ISE-PIC, enabling unauthorized access to the web-based management interface. Cisco PSIRT recommends immediate upgrades to fixed releases, and no workarounds are available.
read more →

Windows 11 update breaks domain trust for some

🔒 Microsoft is investigating reports that the Windows 11 KB5124008 security update is breaking domain trust on some enterprise systems, preventing valid domain logins. Administrators report that affected devices lose their secure channel with Active Directory after reboot and observed Kerberos and NTLM failures. The issue may be linked to the Machine Identity Isolation setting, especially when set to enforcement mode, and some have restored access by adjusting registry values and repairing the secure channel.
read more →

Iranian CHOSEN BRICK Windows malware targets dissidents

🛡️ Joint advisories warn that Iranian state-linked hackers deploy a Windows malware called CHOSEN BRICK to spy on dissidents, activists, and journalists. The malware harvests email, Telegram, and WhatsApp data, captures screenshots and audio, and establishes persistence via Registry Run keys while adding Microsoft Defender exclusions. Attacks begin with social engineering on WhatsApp or Telegram and malicious files masquerading as trusted apps. Stolen data is exfiltrated via Telegram or cloud services and sometimes published on pro-Iranian leak sites.
read more →

KREMLIN malware forces browser extension installs

🔒 Researchers at Elastic Security Labs uncovered a banking malware toolkit called KREMLIN that has been active since mid-2025 and installs malicious Chrome and Edge extensions to steal credentials, session tokens, and other sensitive data. The infection begins with a malicious JavaScript file posing as banking documents, which downloads Node.js, establishes persistence, and retrieves payload locations from an Ethereum smart contract. KREMLIN copies extensions into browser profile directories, regenerates integrity HMACs using browser keys, and enables them without user consent, while also operating as an info-stealer and delivering RATs like REMCOS.
read more →

Spain’s data agency reports first AI-powered breach

🔒 The Spanish Data Protection Agency (AEPD) was notified of an alleged attack carried out by an AI agent powered by a known large language model. The agent reportedly searched for flaws, logged into systems, probed applications, modified personal data, and accessed financial documents. The AEPD has not yet verified the incident but warns that AI-related breaches are now realistic and urges revised risk and response measures.
read more →

Three threat groups target Russian enterprises

🔒 Kaspersky reports three distinct threat clusters—NightEagle, Hacking Cat, and Toy Ghouls—are actively targeting Russian enterprises using novel persistence, lateral movement, and destructive techniques. NightEagle leverages GhostContainer against Microsoft Exchange and abuses tunnels and Active Directory exploits for persistence. Hacking Cat has shifted to Gorilla RAT and multiple Monkey ransomware variants, while Toy Ghouls deploys a custom Bird Agent backdoor using HiveMQ and Matrix for C2.
read more →

Attacker Hijacks AI Coding Assistant, Spreads Worm

🛡️ Mandiant reports an attacker hijacked an active AI coding-assistant session at an unnamed SaaS provider and used it to install an infostealer via a poisoned PyPI package. The attacker stole GitHub OAuth tokens and deployed the self-spreading Shai-Hulud worm across about 100 internal repositories, exfiltrating secrets and source code. Mandiant recommends verifying AI-recommended dependencies with checksums and allowlists, restricting extension access to secrets, and routing dependencies through controlled internal repositories to protect AI-assisted development.
read more →

Fake CAPTCHA Scams Target Windows Users Selectively

🛡️ A commentator describes encountering a fake CAPTCHA scam that fingerprinted devices and served different payloads based on user environment. The attacker’s TDS (Traffic Distribution System) delivered benign pages to datacenter IPs used by scanners, while residential and mobile IPs received malicious payloads. The scam prompted a pop-up asking users to press Windows key + R and execute code, and the poster notes they avoid this by using Linux without faked user agents.
read more →

Atomic macOS AMOS stealer activity snapshot

🔎 This Unit 42 analysis documents an AMOS stealer infection observed in a lab on Aug. 5, 2026, providing a snapshot of indicators seen at that time. The report outlines the infection chain beginning with a malicious webpage instructing copy/paste into Terminal, the Zsh scripts and Mach-O binaries used, and the persistence mechanisms under user Library directories. It also details collected artifacts, post‑infection HTTP POST traffic to C2 servers, and the frequent changes in indicators that characterize AMOS as an actively evolving threat.
read more →

Critical WooCommerce Plugin Flaw Enables PHP Webshells

🔒 Hackers are exploiting a critical vulnerability in the WooCommerce Wholesale Lead Capture premium plugin (CVE-2026-27540) to upload PHP webshells and execute code on affected WordPress sites. The unauthenticated arbitrary file-upload flaw affects versions 2.0.3.1 and older and was fixed in version 2.0.3.2 released February 20. Wordfence blocked over 100,000 related attacks and urges administrators to update, scan for unexpected PHP files, check logs for wwlc_file_upload_handler requests, and restore from clean backups if compromised.
read more →

CISA: Critical VMware vCenter RCE Now Exploited

🛡️ The U.S. Cybersecurity and Infrastructure Security Agency (CISA) warned that ransomware gangs are now exploiting a critical VMware vCenter vulnerability (CVE-2026-59310) patched by Broadcom on July 29. The flaw is a directory traversal issue in the vCenter Syslog server that allows unauthenticated attackers to execute arbitrary code; Broadcom urged emergency patching. Security firms reported widespread compromises and CISA added the CVE to its KEV Catalog, ordering rapid remediation across government systems.
read more →

Five Black Axe Members Extradited to US Courts

📰 Five alleged leaders of the Black Axe cybercrime syndicate were extradited from South Africa to the United States to face wire fraud, money laundering, and aggravated identity theft charges. Prosecutors allege the defendants ran romance and advance-fee scams targeting U.S. victims from Cape Town between 2011 and 2021, using aliases, social media, dating sites, and VoIP services to defraud and coerce victims. Arrested in 2021 at U.S. request, they face significant prison terms if convicted.
read more →

Maximum-severity GitLab flaw risks CI/CD trust

🚨 GitLab disclosed CVE-2026-85706, a maximum-severity path traversal flaw in its repository commits API that can allow unauthenticated attackers to read arbitrary files with a single HTTP request. The bug affected Community and Enterprise editions and has been patched; GitLab urged self-hosted, public-facing instances to patch immediately or remove access. CISA added the vulnerability to its Known Exploited Vulnerabilities catalog, and threat intel already reports in-the-wild probes. Experts warn this poses broad risk because GitLab often links to build, deployment, and secret-bearing files.
read more →