< ciso
brief />
Incidents and Data Breaches Banner

All news in category “Incidents and Data Breaches”

3607 articles · page 12 of 181

WeChat zero-click worm hijacks accounts via calls

🛡️ A Palo Alto startup, Calif, developed a tool called WeWorm that exploits a remote code execution flaw in WeChat's VoIP stack to compromise Android and iOS devices via incoming calls. Researchers say the zero-click exploit required no user interaction and can hijack accounts to read/send messages and make calls. Tencent patched the vulnerability in Android 8.0.77 and iOS 8.0.76 after being notified, and Calif warns the worm could scale further when combined with other bugs.
read more →

Gigabud Uses Work Profiles to Clone Banking Apps

🔒 Group-IB researchers revealed that the Gigabud Android banking trojan has been paired with a weaponized fork of the cloning app Shelter called Vwork, enabling attackers to clone banking apps into isolated Android work profiles. This separation hides malicious activity from signature-based detection in the personal profile and allows fraudsters to perform transactions that appear to originate from clean devices. The campaign was observed primarily in Indonesia but targets users across 11 countries and exploits accessibility and overlay permissions to capture credentials and one-time codes.
read more →

ShinyHunters claims Florida DMV data breach

🔒 ShinyHunters says it accessed the Florida Department of Highway Safety and Motor Vehicles' DAVID system and stole over 200,000 records, publishing a screenshot tied to Jeffrey Epstein as proof. The group set a September 11 deadline to negotiate before releasing additional data and claims to have exploited a password-reset weakness to compromise multiple DMV accounts. The alleged intrusion could expose sensitive personal identifiers that enable identity theft and fraud. While IDScan has confirmed a related Nexus ID-scan exposure, the Florida DMV has not publicly verified ShinyHunters' claim.
read more →

F5 BIG-IP APM in-memory PHP web shell analysis

🛡️ Sophos on September 7 detailed malware targeting F5 BIG-IP Access Policy Manager that injects a PHP web shell into memory rather than writing it to disk. The malware hooks Apache and libphp, rewrites file-handling calls, and places a web shell in-memory when specific .php3 scripts are loaded, evading file-based detection. Related installer components modify /usr/sbin/httpd and other binaries and may persist through install images, with links to CVE-2025-53521 and mitigation guidance.
read more →

ChatGPT prompt flaw allowed covert data exfiltration

🔒 Check Point Research disclosed that a single hidden instruction placed in a ChatGPT conversation could cause the model to perform covert tasks for an attacker while responding normally. In the proof of concept, ChatGPT read a user's connected Gmail and passed data to another ChatGPT account via a hidden channel, without the visible reply revealing the transfer. The channel exploited an internal package cache service used by containers to exchange metadata, effectively turning it into a shared clipboard between isolated conversations. OpenAI confirmed the internal service was taken offline after disclosure.
read more →

WeChat zero-click worm hijacked accounts via calls

📱 Researchers at security firm Calif created a worm that hijacks WeChat accounts via an incoming call and demonstrated it spreading across three test phones without user interaction. The attacker must already be one of the victim's WeChat contacts, and Calif says Tencent blocked the exploit on its servers after being notified in July. Calif withheld technical details pending a conference presentation and reported using AI to help locate the flaw and build the initial exploit.
read more →

Packed Android RAT with ADB worm spreads via exposed services

🔍 Dark Atlas researchers detailed a packed Android remote access trojan (RAT) tracked as THost9 that conceals a loader inside an app and loads a second-stage payload, tc9.dex. The loader decodes and decompresses an embedded asset, starts a foreground service, and can enable an accessibility service when permissions allow. The second stage adds shell execution, file transfer, tunneling, reverse shell and downloadable modules, and includes a worm that scans for exposed Android Debug Bridge (ADB) services to propagate. Analysts linked infections to public ADB and Redroid exposures and recommend removing public ADB access and auditing accessibility services and persistent Redroid data.
read more →

Trezor supply-chain breach expands affected customers

📣 Trezor has revealed that a supply-chain breach at shipping partner ShipMonk exposed additional customer order data, expanding the impacted cohort by 67,000 users. The company updated its notification after discovering records from November 2019 to August 2021 were included, revising earlier timelines and increasing the victim count significantly. Trezor warned of heightened phishing and fraud risks and said it is considering legal action while pushing for anonymized delivery options.
read more →

BengalSEO campaign poisons Bing to deliver malware

🔍 Cybersecurity researchers disclosed a long-running SEO poisoning campaign, codenamed BengalSEO, which has been active since at least 2015 and operates out of Rajasthan, India. The group uses black hat SEO techniques, malicious lure pages, and a sophisticated traffic distribution system to deliver a custom malware called MayaBot or to funnel victims into tech-support scams. The campaign leverages legitimate hosting and analytics services to fingerprint visitors and evade detection before delivering payloads or social-engineering victims into calling scam call centers.
read more →

Help‑desk vishing fuels Microsoft 365 token theft

📣 Threat hunters warn of a broad data theft and extortion campaign targeting Microsoft 365 and other SaaS platforms via help‑desk vishing, adversary‑in‑the‑middle token theft, and residential‑proxy sign‑ins. Tracked by Arctic Wolf as PREY‑0058 and linked to activity groups like UNC6671 and Cinder, the actors impersonate IT staff to lure executives to authentication‑themed pages and capture MFA approvals. Attacks culminate in SharePoint, OneDrive, Exchange, and Box data exfiltration and extortion without deploying endpoint malware. Organizations are urged to adopt Conditional Access, phishing‑resistant MFA, and tighter SharePoint access controls.
read more →

Weekly cyber recap: zero-days, router exploits

🛡️ This week’s recap highlights active zero-days, credential‑stealing supply‑chain code, and novel attack vectors that bypass simple user precautions. Notable incidents include an actively exploited Chrome V8 zero-day, MikroTik RouterOS exploit chains dubbed "MikroTrick," and a Magento/Adobe Commerce zero-day called StyleSmuggler used to backdoor storefronts. The briefing summarizes patches, observed exploitation activity, and trending CVEs to prioritize.
read more →

Mathspace data breach exposes over 1 million records

🔒 Mathspace disclosed that attackers exploited a vulnerability in its self-hosted Metabase reporting system, gaining administrator access and stealing personal information belonging to students, staff, and parents in Australia and New Zealand. The company confirmed the intrusion was first leveraged on August 10, with data downloaded on August 27 and a breach confirmed on September 3, 2026. Mathspace says 1,079,819 people were affected but asserts that no passwords, authentication tokens, SSO or API credentials, or academic records were exposed. The firm warned those affected to monitor for suspicious account activity and noted the incident is part of a wider series of Metabase compromises linked to threat actors like ShinyHunters.
read more →

NoName057(16) Relaunches DDoS Campaigns Against Japan

🛡️ On August 24, 2026, pro-Russian hacktivist collective NoName057(16) announced the relaunch of #OpJapan, a DDoS campaign targeting Japanese organizations in response to Japan's support for Ukraine and NATO. The group claimed 66 attacks against 26 entities across maritime, logistics and government sectors between August 24 and 30, using both volumetric floods and targeted requests against costly site functions. Activity has mostly been DDoS, with opportunistic intrusions against small- to medium-sized businesses and no observed data theft or backend compromises. By August 31, activity slowed as attention shifted to #OpEstonia, while coalition partners like Dark Storm Team joined the wave.
read more →

Trezor Data Breach Now Affects 81,000 Customers

🚨 Trezor disclosed that an August data breach at its logistics partner ShipMonk has expanded to affect 81,000 customers after an additional 67,000 U.S. customers were found impacted. The exposed data includes full names, shipping addresses, email addresses, phone numbers, and order numbers for customers who ordered during specific periods between 2019 and 2026. Trezor confirmed its own systems and devices were not compromised and warned customers to expect increased phishing and fraud risk. The incident stems from a Metabase vulnerability and extortion attempts linked to the ShinyHunters gang.
read more →

Lazarus Reorganized Into Six Distinct Cyber Clusters

🔎 Sekoia and Kudelski Security report that North Korea's long-running Lazarus umbrella has been reorganized into six distinct cyber clusters focused on espionage, financial operations and sanctions evasion. The groups—TEMP.Hermit, Citrine Sleet, CryptoCore, Jade Sleet, Moonstone Sleet and Famous Chollima—were identified by TTPs and activity patterns. Researchers note extensive use of fake IT workers, front companies and third-country infrastructure to fund operations and gain access to targets.
read more →

MikroTik RouterOS SSH flaws exploited in wild

🔒 Hackers are actively exploiting two recently disclosed MikroTik RouterOS vulnerabilities to hijack routers with internet-exposed SSH. The chain combines an SSH authentication bypass (CVE-2026-67276) that lets attackers log in if they know a username and the public modulus, and an SSH privilege escalation (CVE-2026-86060) that grants full administrative rights via specially crafted usernames. Poland's CERT, aided by GPT-5.5-cyber and GPT-5.6-sol, named the campaign “MikroTrick” and confirmed active exploitation; MikroTik released patches and added compromise-detection measures in recent RouterOS updates.
read more →

Lenovo ID flaw let attackers access Dropbox accounts

🔒 Dropbox confirmed roughly 5,000 accounts were accessed in August after attackers abused a legacy Lenovo ID login integration. The issue involved Lenovo allowing new IDs to be registered with someone else's email without verifying inbox ownership, enabling sign-ins to linked Dropbox accounts without a Dropbox password. Dropbox and Lenovo say they collaborated to mitigate the risk, and Dropbox has revoked Lenovo-ID sessions and now requires Dropbox passwords and 2FA.
read more →

Class-action suits follow alleged IDScan.net mega-breach

🔍 Several class-action lawsuits have been filed against IDScan.net after reports of a potential large-scale leak of driver’s license and identity document data. The FBI is investigating following reporting that linked stolen records to a Russian forum listing called “Nexus.” Plaintiffs seek damages and improved security, while law firms are contacting potential victims and advising steps to determine exposure and preserve evidence.
read more →

Zero-day Privilege Escalation Reported in CrowdStrike

🛡️ A security researcher known as “Nightmare Eclipse” published a GitHub proof-of-concept on September 3 for a zero-day privilege escalation called FalconFlank that targets CrowdStrike Falcon Sensor. The exploit abuses the Microsoft Office file malicious macro remediation feature and reportedly works on fully updated Windows 11 25H2 and Windows Server 2025 when specific CrowdStrike settings are enabled. CrowdStrike advised customers to disable the Microsoft Office File Suspicious Macro Removal policy while it investigates and referenced a customer-only tech alert. No CVE has been assigned yet, and the researcher has also published other vendor zero-days previously.
read more →

Compiled V8 JavaScript Malware Evades Defenses

🔒 Check Point Research analyzed JSCeal, a sophisticated compiled V8 JavaScript malware used to harvest credentials, surveil victims, and intercept traffic. Operators deliver JSCeal via malvertising and fake trading sites, using Node.js runtimes and obfuscated payloads assembled in memory. The malware targets many Chromium-based browsers to extract cookies, passwords, OAuth tokens, and can replay sessions to access Google accounts. JSCeal also sets up local proxies, installs certificates, and applies service-specific request and response modifications to target crypto platforms and trading services.
read more →