< ciso
brief />
Incidents and Data Breaches Banner

All news in category “Incidents and Data Breaches

3296 articles · page 12 of 165

U.S. seizes over 1,000 FIFA streaming domains

🔒 The U.S. Justice Department seized more than 1,000 websites and blocked 1,970 domains used to stream FIFA World Cup 2026 matches without authorization. Law enforcement worked with partners including FIFA, the Motion Picture Association's ACE, beIN, NBCUniversal, UFC, and Warner Bros. These actions, led by the IPR Center and HSI Washington, are part of Operation Offsides and related efforts such as Operation Red Card.
read more →

Critical GlobalProtect VPN Bug Now Used in Ransomware

🔒 Palo Alto Networks patched a critical PAN-OS GlobalProtect authentication bypass (CVE-2026-0257) on May 13 after Rapid7 observed active exploitation from May 17. Arctic Wolf reports the Qilin ransomware gang is leveraging the flaw to gain unauthorized VPN access and deploy ransomware, with incidents in June resulting in domain-wide encryption. CISA added the vulnerability to its Known Exploited Vulnerability catalog and ordered federal agencies to remediate within three days.
read more →

Fake CAPTCHA Click-Fraud Used to Activate Malware

🔒 Ukraine's CERT-UA warns that Russian-linked Sandworm actors are using fake CAPTCHA prompts on compromised sites to trick users into pasting and executing PowerShell commands on their PCs. The campaign, attributed to UAC-0145, began surging in June and has compromised at least ten websites, deploying a reconnaissance tool called ScoutCurl. These "ClickFix" attacks coerce victims to run legitimate tools like PowerShell, making them effective and dangerous.
read more →

Craneware reports file-name data theft incident

🛡️ Craneware disclosed a cyber incident on July 20 after unauthorized access to parts of its data environment resulted in the exfiltration of a significant volume of file names. The firm said much of the data was non-sensitive or public regulatory material, but admitted some employee, customer and partner records were also accessed. No customer service disruption occurred; regulators in the UK and US have been notified and the company is working to identify affected parties.
read more →

Widespread wp2shell WordPress RCE and exploitation

🛡️ Attackers are actively exploiting two critical WordPress flaws, CVE-2026-63030 and CVE-2026-60137, together dubbed wp2shell, enabling unauthenticated remote code execution on default installations. Researchers report rapid abuse following public exploit release, extensive scanning, and post-exploitation activity including malicious plugin uploads, web shells, and creation of backdoor admin accounts. Organizations are urged to patch and inspect sites for indicators of compromise.
read more →

Estée Lauder discloses Oracle E‑Business Suite breach

🛡️ Estée Lauder is notifying individuals after discovering that an unauthorized actor accessed its Oracle E-Business Suite HR system on or around August 9, 2025, exposing personal information. The company's investigation concluded on June 19, 2026, and the exposed data may include names, contact details, SSNs, passport numbers, bank account and health information. The breach correlates with mass exploitation tied to CVE-2025-61882 and activity by the Clop group; affected individuals are being offered 24 months of identity monitoring through Kroll.
read more →

Sandbox escapes impact major AI coding agents

🛡️ Security researchers demonstrated sandbox escape techniques against four popular AI coding agents—Cursor, OpenAI's Codex CLI, Google's Gemini CLI and Antigravity—by having the agent write files that trusted host tools later execute. Pillar Security reproduced the bypasses over months and published them as a daily series, identifying four failure modes including denylist limitations, executable workspace configs, permissive command allowlists, and privileged daemons. Most issues have been patched and vendor-acknowledged, though Google classified two Antigravity findings as lower-severity due to required social engineering.
read more →

Exposed server reveals AI-assisted phishing toolkit

🧩 Rapid7 found an exposed delivery server containing 1,048 files: lure templates, tests, droppers, builder notes, and two campaign chains. One campaign targeted Windows users in Mexico via a fake government ID lookup and delivered an infostealer through a WebDAV-hosted exploit. The artifacts included README notes, test matrices, and logs that indicate the operator used generative AI (an open-source coding agent) to create, test, and document phishing delivery at scale. The kit heavily probed a WebDAV working-directory hijack (CVE-2025-33053) and contained tests for other file-handling flaws, while active delivery logs showed thousands of launch events concentrated in Mexico.
read more →

HollowGraph: Malware Using Microsoft 365 Calendar C2

🛡️ Group-IB discovered a .NET espionage implant called HollowGraph that uses a hijacked Microsoft 365 calendar as a covert command-and-control channel, reading operator instructions from a calendar event dated 2050-05-13 and exfiltrating stolen files as attachments. The implant uses the Microsoft Graph API to blend with legitimate traffic and avoids contacting attacker-owned servers directly. A secondary DNS-based channel supplies Entra ID client credentials via IPv6 AAAA records, written to a log file named logAzure.txt. Group-IB links the malware to the Cavern code family and recommends monitoring calendar events, application-driven Graph activity, and suspicious DNS AAAA queries.
read more →

Mistaken arrests from Flock license-plate tracking

🚨 A viral account describes a writer wrongly identified and arrested after Flock camera data matched a partial plate. The system recorded only the main characters (e.g., "34 DTM") and ignored a small intervening number, causing nationwide false alerts for vehicles with similar plate structures. Flock defended its ML as working as designed and said police request partial-plate alerts; its CEO has since apologized for inflammatory remarks. Reporting also shows Flock cameras are frequently used to search for people by appearance, raising abuse concerns.
read more →

Critical ServiceNow RCE Flaw Now Observed Exploited

🛡️ Security researchers report active exploitation of a pre-auth sandbox escape and remote code execution bug (CVE-2026-6875) in the ServiceNow AI Platform. The vulnerability, disclosed in early April and patched for hosted and self-hosted instances in mid-July, allows unauthenticated actors to execute code by escaping the platform sandbox. Defused confirmed in-the-wild attacks days after patches were released, though ServiceNow states it is not currently aware of exploitation against instances and urges customers to apply updates immediately.
read more →

Hackers Abuse ViPNet Updates to Target Russian Agencies

🔍 Researchers at Kaspersky say an advanced threat actor, tracked as HelloNet, has abused the ViPNet update mechanism since at least May to deliver a loader and proxy targeting Russian organizations, including government agencies. Attackers dropped a malicious DLL (wtsapi32.dll, "HelloInjector") into the local ViPNet Update System to be sideloaded by the legitimate updater, gaining persistence and elevated privileges. The campaign delivers additional modules—HelloProxy, HelloExecutor, HelloCleaner, and a Rust-based HelloBackdoor—enabling command execution, file transfer, reconnaissance, and log removal. Kaspersky assigns low-confidence attribution to a Chinese-speaking APT and recommends close monitoring of systems running ViPNet, especially traffic on ports 5003, 5060, and 443.
read more →

Microsoft warns of surge in ACR Stealer attacks

🛡️ Microsoft reports a marked increase in attacks leveraging ACR Stealer, an info-stealing MaaS that exfiltrates browser passwords, tokens, and sensitive documents from enterprise environments. Between late April and mid‑June, threat actors used social engineering (ClickFix), WebDAV servers, and mshta.exe to deliver obfuscated PowerShell loaders, Python-based installers, and in-memory payloads. The actor abuses GUID-based WebDAV paths, steganographic JPEGs, and public blockchains as dead-drop resolvers to mask activity and maintain C2 communications. Microsoft recommends filters, application control, and limiting access to unnecessary web resources to reduce exposure.
read more →

Abbott investigates dual cybersecurity incidents amid claims

🔍 Abbott Laboratories is probing two separate cybersecurity incidents after confirming unauthorized access to legacy Exact Sciences systems within its Cancer Diagnostics business and investigating a separate claim of a breach of its LabCentral portal. The company says the Cancer Diagnostics intrusion does not affect operations, products, manufacturing, or patient services and that legacy systems are separate from Abbott's main environment. Abbott engaged incident response teams, notified law enforcement, and does not expect a material business impact. The extortion gang ShinyHunters and another actor, ShadowByt3$, each claim to have exfiltrated different sets of data, though Abbott disputes some characterizations.
read more →

OnlyFans creators help CISOs curb site abuse

🔒 Security researchers report that OnlyFans creators are using DMCA takedown rights and search engine mechanisms to disrupt scam networks that host stolen adult content on compromised government and university websites. These operations — called SEO parasites — route traffic from hijacked entry pages to monetized scam or malware sites. The takedowns not only remove illicit content from search results but also prompt site owners to investigate and remediate vulnerabilities.
read more →

Shadow Token via Remote Debug: OAuth mailbox hijack

🔒 Kaspersky researchers describe a covert technique named Shadow Token via Remote Debug (STRD) used by the ToddyCat APT to gain persistent access to Google Workspace mailboxes without user interaction. The attackers deploy malware (Umbrij) that duplicates a browser profile, launches a headless debugging browser, and programmatically authorizes a third-party OAuth app to obtain an access token. This approach can survive password resets and evades endpoint detection when properly executed.
read more →

Ransomware Now Disrupts a Government Every Day

🔒 Analysis from Comparitech finds ransomware attacks on government agencies rose in early 2026, averaging one incident per day. The study recorded 187 attacks from January to June 2026, a 13% increase from late 2025, with just over half publicly confirmed. The US was the most targeted country (31%), mean demands were around $100,000, and groups like The Gentlemen, Qilin and LockBit were prominent. Experts stress timely patching, backups and staff training to reduce risk.
read more →

Ernst & Young discloses support system data breach

🔒 Ernst & Young has notified clients of a data breach after a third-party support ticket system used by its IT staff was compromised. The company says support tickets may have contained documents with client tax information and that unauthorized access occurred between March 28 and April 12. EY detected anomalous activity on April 23, engaged external cybersecurity experts, secured systems, and notified law enforcement. Affected clients are offered 24 months of identity monitoring through Experian.
read more →

23andMe Agrees $18M Settlement and New Security Terms

🔒 A coalition of 42 US attorneys general has secured an $18m settlement with genetic testing firm 23andMe following the 2023 credential-stuffing breach that exposed profile and ancestry data for over six million individuals. The settlement, led by New York Attorney General Letitia James, includes more than $705,000 payable to New York and imposes new data protection requirements on the company and its successor. As 23andMe entered bankruptcy in March 2025, its customer data was transferred to TTAM Research; the agreement mandates risk analysis, an advisory board on data security, and continued consumer deletion rights to safeguard that information.
read more →

Armenia Detains Russian Tourist on U.S. Extradition Warrant

📰 Armenian authorities have detained a Russian tourist, Aleksandr Ermakov, at Yerevan's Zvartnots airport on June 28 after a U.S. extradition request tied to a REvil/Sodinokibi investigation. His lawyers claim Washington has targeted the wrong man, asserting the detained individual is Aleksandr Yuryevich Ermakov of Omsk, not the sanctioned Aleksandr Gennadievich Ermakov. The U.S. charging documents and an Interpol notice allege extensive ransomware activity, but Armenian officials have not commented publicly.
read more →