< ciso
brief />
Incidents and Data Breaches Banner

All news in category “Incidents and Data Breaches”

3607 articles · page 11 of 181

Twitch extension with 30K installs exposes OAuth tokens

🔒 A browser extension named Twitch Enhanced Viewer | JeetBot, listed in the Chrome and Firefox stores with over 30,000 installs, captures Twitch OAuth session tokens and transmits them to a commercial proxy service. Socket's analysis shows the extension appends the token as an auth= URL parameter when redirecting playlist requests, causing tokens to be logged in proxy server request logs. The vendor JeetBot, a Russian-language streaming/chatbot service, can therefore access those tokens and potentially hijack sessions.
read more →

MeshCentral backdoor used in 3BB broadband intrusion

🔎 Hunt.io discovered an active intrusion in Thailand ISP 3BB where an attacker installed MeshCentral as a hidden backdoor to maintain remote root access. The exposed server captured on June 3, 2026, contained tools, device lists, and scripts targeting RADIUS databases, FortiGate SSL‑VPN appliances, and internal portals. Cleanup scripts removed logs but deliberately left the agent to preserve persistence.
read more →

Red Heron exploits Gitea RCE to target sectors

🔎 Acronis TRU attributes a rapid, multi-country campaign to suspected China-linked actor Red Heron that weaponized a disclosed Gitea RCE (CVE-2026-60004) to compromise internet-facing instances. The operator scanned and exploited hundreds of servers, stole source code and secrets, and escalated to persistent access and lateral movement, including root control of a Proxmox cluster. Analysts identified a C++ implant JITTERLY and an LD_PRELOAD rootkit SIXZUT used to hide activity and maintain persistence.
read more →

Mass scanning of exposed Vite dev servers steals cloud secrets

🛡️ A large-scale campaign is scanning internet-exposed Vite development servers to extract AWS and Azure credentials by exploiting CVE-2026-39364 in affected Vite versions. F5 detected over 800 attacks and ~32,000 events, observing attackers append parameters like ?raw or ?import&raw to bypass file access controls and retrieve sensitive files. The operation targeted environment files, cloud credential/config files, Terraform and serverless state, and system files, using traversal and encoding tricks for evasion.
read more →

Revolut data breach exposes sensitive customer records

🔒 Fintech firm Revolut disclosed a data breach after an attacker impersonating a government agency obtained customer data by sending requests from an email address using the agency's legitimate domain. The company said the request carried valid domain authentication, so it was fulfilled in good faith, and that systems and customer funds remain unaffected. Affected records include identity documents, contact details, account statements, transaction histories, and facial verification images, and Revolut says only a very limited number of customers were impacted.
read more →

Threat Actors Use Passkey Phishing to Breach Cloud

🛡️ Microsoft disclosed two related campaigns: one sent over a million CEO-impersonation invoice scams in August 2026 to induce ACH transfers, and the other used passkey-themed social engineering since May 2026 to compromise cloud accounts. The fraud campaign leveraged generative AI, forged threads, and bogus domains to target enterprise finance teams. Cloud intrusions employed voice/SMS pretexts, counterfeit sign-in pages, AitM and device-code flows, and persistent MFA enrollment to enable extensive Microsoft Graph, SharePoint, OneDrive, and mailbox access.
read more →

Threat actors abused Claude to harvest secrets

🔒 Anthropic reports multiple financially motivated and state-linked groups abused its Claude model between December 2025 and August 2026 for cybercrime, espionage, surveillance, and weaponization. One actor associated with the ShinyHunters collective used automated pipelines to download and decompile 1.8 million Android APKs, scanning for hardcoded secrets and routing verified findings to a Telegram group. The company says AI agents performed much of the work, enabling rapid credential theft, mass data exfiltration, and subsequent attacks across diverse sectors.
read more →

Florida DMV DAVID Database Breach Confirmed

🛡️ The Florida Department of Highway Safety and Motor Vehicles (FLHSMV) confirmed a breach of its DAVID driver database after the ShinyHunters extortion group claimed to have compromised the system. The agency says the intrusion involved compromised credentials from a single Plant City Police Department user improperly stored on a personal device and that the incident was quickly mitigated. FLHSMV is coordinating with state authorities and treating the matter as an ongoing criminal investigation.
read more →

Passkey-Themed Scams Hijacking Microsoft 365 Accounts

🔒 Microsoft Security Research has tracked a campaign since May where attackers pose as IT helpdesk staff to trick employees into updating or enrolling a passkey. Victims are redirected to AiTM phishing pages or legitimate Microsoft device-code flows, enabling attackers to capture credentials and session tokens or authorize attacker-controlled clients. Compromised identities allowed adversaries to register their own authentication methods, use Microsoft Graph to map tenants, and exfiltrate files and email from SharePoint, OneDrive, and Exchange.
read more →

Trezor customers targeted after Brevo email breach

📧 Trezor disclosed that phishing emails sent via a breached third-party provider targeted 347,000 opted-in newsletter addresses and prompted 2,500 recipients to click a malicious link. The messages falsely claimed a microcontroller vulnerability in STM32 chips and urged users to download an app to enter wallet backups. Trezor disabled the malicious domain within 20 minutes and suspended the Brevo account to halt further distribution. The company emphasized no other Trezor systems were accessed.
read more →

Conti ransomware member jailed for four years

🔒 A Ukrainian national was sentenced to four years in prison after pleading guilty to participating in Conti ransomware attacks that targeted victims in the United States and abroad between 2020 and 2022. 44-year-old Oleksii Lytvynenko was arrested in Ireland in July 2023 and extradited to the U.S., where he admitted to intruding on networks, storing stolen data, sending ransom notes, and developing a malware loader used in the group's double extortion attacks.
read more →

Attackers exploit gap between Chromium fixes and Chrome

⚠️ Proofpoint researchers, alongside Google, Microsoft, and Volexity, uncovered a new exploit toolkit called BlueMoon that chains multiple Chromium and Windows vulnerabilities to enable one-click full system compromise. The kit leverages two V8-related patch-gap issues and a Windows kernel LPE to escalate privileges after a user clicks a spear-phishing link. Rapid weaponization and sharing across multiple threat clusters—many with suspected China links—underscore the danger of delays between upstream fixes and stable Chrome patches. Immediate patching, detection rule application, and heightened patch cadence and user awareness are recommended.
read more →

Mantax Otax Android malware combines ransomware, spyware

🔒 A new Android threat, Mantax Otax, combines ransomware and spyware to encrypt files, steal sensitive data, and harass victims. Distributed via malicious APKs outside Google Play by Indonesian operators, it requests Accessibility permissions to gain extensive control and retrieves its C2 domain from GitHub. The malware targets older Android versions for encryption, abuses Firebase and WebSockets for commands, and includes remote-control, data-exfiltration, and intimidation features. Up-to-date devices with Play Protect are generally protected, and users are advised to avoid sideloading APKs and granting Accessibility access to untrusted apps.
read more →

Surfshark reports breach of internal test proxy servers

🔒 Surfshark disclosed that a misconfigured internal test server was reachable from the internet and accessed by unauthorized parties, exposing service configurations, portions of binaries, and build-related credentials. The company said production VPN infrastructure and customer data were not impacted, and the compromised machine acted as a proxy without access to user identities, IPs, encryption keys, or browsing traffic. Surfshark detected the activity on August 31, contained it by September 2, rotated affected credentials, revoked exposed tokens, and implemented additional monitoring and hardening.
read more →

AI-assisted Executive Impersonation Invoice Fraud

🔍 This Microsoft Threat Intelligence blog describes a large campaign in early August that used third-party email services to send over a million invoice-fraud emails impersonating executives and vendors. The actor layered CEO impersonation, fabricated invoices, and forged vendor threads to convince finance teams to initiate ACH payments near $50,000. Microsoft details indicators of AI-assisted template generation, observed domains and addresses, and recommended Defender and mail-authentication mitigations.
read more →

Google Play Early Access abused to host scams

🔍 Threat actors are exploiting Google Play's Early Access program to distribute deceptive apps that promise money, rewards, casino wins, and premium content. Because Early Access apps do not accept public reviews or star ratings, malicious titles can gain traction without community warnings, and are often promoted via social media ads using AI-generated deepfakes. Reported examples include a Grand Theft Auto imitator with over a million downloads and numerous fake reward and utility apps that stall payouts and monetize victims via ads.
read more →

Young mastermind pleads guilty in $245M crypto theft

🔍 A 22-year-old Singaporean, Malone Lam, pleaded guilty to leading a group that stole over US $245 million in cryptocurrency from U.S. victims between October 2023 and May 2025. Lam, who used aliases like Anne Hathaway and King Greavy, recruited accomplices via gaming platforms and allegedly orchestrated scams including fake tech support calls. The gang spent lavishly on nightclubs, luxury cars, mansions, private jets, and security, drawing law enforcement attention. Lam faces up to 20 years in prison while co-conspirators receive sentences and ongoing prosecutions continue.
read more →

MantaxOtax Android malware blends ransomware and spying

🛡️ Zimperium's zLabs detailed the MantaxOtax Android threat, linking it to Indonesian actors and noting distribution via sideloaded packages. The malware requests extensive privileges including Accessibility and device admin, enabling file encryption on older Android versions and broad surveillance on all supported devices. Operators resolve C2 domains via a GitHub-hosted pointer and use Firebase for extortion chats, with a misconfiguration exposing some dialogues. Variants add persistent locking, overlays, recording, and other disruptive behaviors to coerce victims.
read more →

Stealth rootkit targets F5 BIG‑IP APM webtops

🔒 Sophos analyzed a Linux rootkit that hides web shells inside compromised F5 BIG‑IP APM environments by modifying PHP content in memory rather than writing files to disk. The implant hooks Apache’s PHP-loading process, targets specific BIG‑IP APM PHP files, and serves altered in‑memory versions so file‑integrity checks appear normal. It also provides a secondary access channel via a local UNIX socket, complicating detection and response.
read more →

Mass Drivers License Data for Sale Sparks Alarm

🛡️ A database of 153 million drivers licenses is reported for sale on the dark web, raising urgent privacy and security concerns. The post argues that current AI LLM systems accelerate attacks on ID document databases, making holdings of such data increasingly risky. It questions the wisdom of widespread storage of primary ID documents and urges limiting access to only those tasks that truly require ID verification. The piece criticizes recent trends toward mandatory ID collection and calls for treating ID verification data as crown-jewel assets.
read more →