< ciso
brief />
Incidents and Data Breaches Banner

All news in category “Incidents and Data Breaches”

3607 articles · page 13 of 181

JetBrains Cadence breach after TeamCity exploit

🔒 JetBrains warns Cadence users to immediately revoke and rotate all credentials after threat actors exploited a critical TeamCity vulnerability (CVE-2026-63077) to breach a Cadence server. The attackers accessed a 2024 backup and may have obtained email addresses, project source code, AWS IAM credentials, and S3-stored files. JetBrains invalidated Cadence plugin tokens and provided IOCs, urging review of connected systems and treating all executions as untrusted.
read more →

Trezor: ShipMonk breach exposed 67,000 US customers

📣 Trezor disclosed that 67,000 additional U.S. customers were impacted by a ShipMonk breach, exposing names, emails, phone numbers, shipping addresses, and order numbers from Nov 2019 to Aug 2021. The company emphasized that hardware wallet security was not affected and that it had repeatedly requested deletion of customer data. ShipMonk reportedly used a Metabase instance vulnerable to CVE-2026-72898, and the incident is tied to the ShinyHunters extortion gang.
read more →

Lawsuits Filed After IDScan Driver’s License Leak

🔎 Multiple lawsuits and investigations target identity verification vendor IDScan after a dark-web service reportedly advertised over 153 million driver’s license scans and millions of other documents. The leak was traced to IDScan by Brian Krebs, and the FBI’s New Orleans office is reported to be investigating. IDScan has not publicly commented, and affected businesses and consumers may face exposure; law firms are pursuing potential class actions.
read more →

New 'ted' backdoor hidden in trojanized HAProxy

🛡️ A previously undocumented Linux toolkit named ted was compiled into trojanized HAProxy binaries on two South Korean hosts, intercepting web traffic and serving altered pages to selected visitors. Rapid7 links the implant with medium confidence to North Korean state actors and identifies victims in the automotive and media sectors. The implant uses specially crafted requests to enter C2 mode, erases its activity from HAProxy counters and returns operator responses over ordinary HTTP headers. Rapid7 shared IoCs and recommended network correlation, memory analysis and binary integrity checks.
read more →

FBI probes massive ID scan breach at IDscan.net

🔍 A large cache of 153 million digital driving-license scans and other ID documents was listed for sale on the dark web, traced to identity verification provider IDscan.net. The haul also included millions of ID cards, travel documents and medical cards, and affected high-profile individuals. IDscan.net has not issued a full public statement while an FBI investigation into the source of the images is underway, raising supply-chain security concerns for organizations that rely on third-party verification services.
read more →

Bidding over Spirit Airlines employee data continues

📰 A dispute over the sale of archived Spirit Airlines employee data persists months after the carrier sought bankruptcy protection. Reportedly including hundreds of millions of emails and chats, OneDrive and SharePoint items, and millions of recorded calls, the dataset has drawn competing bids from AI training firms and at least one major cloud company. Former employees and unions object, citing privacy and unpaid compensation concerns. Stakeholders are considering anonymization as a possible compromise.
read more →

CrowdStrike FalconFlank zero-day grants SYSTEM access

🛡️ An anonymous researcher called "Nightmare Eclipse" released a zero-day named FalconFlank that escalates privileges on fully patched Windows 11 and Windows Server systems by abusing CrowdStrike Falcon's Office malicious macros remediation. Successful exploitation spawns a command prompt with SYSTEM privileges, and CrowdStrike is investigating while advising customers to disable the Microsoft Office File Suspicious Macro Removal policy. The advisory is available to customers via the CrowdStrike support portal only.
read more →

Exchange Online outage triggers email delays

📧 Microsoft is investigating an Exchange Online outage (EX1467029) that began at 02:19 AM EDT and is causing intermittent "Server busy" errors for users sending to and receiving from external domains. The company noted anti-spam protections may be aggravating delays for a subset of accounts and said it is analysing service telemetry to identify the root cause. No timeline for full remediation or affected regions and user counts have been provided.
read more →

AI Coding Agents Install Untrusted Code on Networks

🔍 Researchers scanned 6,214 live domains of defense contractors, Fortune 500, and Big Tech firms and found 8,265 llms.txt and llms-full.txt files. They registered several unclaimed package names referenced in those files and hosted payloads; within an hour a Fortune 500 system phone‑homed to their server, and dozens more followed. The chain of parent processes showed agent involvement from Claude, OpenAI’s Codex, and Nous Research’s Hermes, illustrating a broken trust model.
read more →

French hospital fined €500k after data breach

🔒 France’s data protection authority (CNIL) fined Hôpital privé de la Loire €500,000 after a 2025 breach exposed sensitive records for 727,113 people, including 524,867 patients and 202,246 trusted third parties. The investigation found failures including lack of VPN/MFA for external users, weak access controls, and absent real-time monitoring, enabling extensive data exfiltration. The hospital informed affected patients but did not directly notify all third parties; a teen hacker claiming responsibility sold the data attempt reportedly failed.
read more →

Coder registry compromise delivered malicious Terraform modules

🔒 Coder disclosed that an attacker gained access to its Cloudflare-backed registry infrastructure and added unauthorized IPs that served a tampered copy of the project's package registry. Between 07:35 UTC and 21:45 UTC on August 31, some requests were routed to attacker-controlled servers that delivered modified Terraform modules containing credential-stealing code. The malicious modules searched for a wide range of secrets and exfiltrated data to a lookalike domain; Coder advises rotating affected secrets, examining logs, and purging cached packages prior to upgrading to patched releases.
read more →

BraZetsu malware fuels access-as-a-service market

🛡️ Cybersecurity researchers detail a Python-based Windows malware framework named BraZetsu that powers an underground marketplace selling access to compromised hosts. The modular toolkit, linked to the Exilware group, targets Iberian and Latin American organizations and uses generative AI for reconnaissance, triage, and prioritization. BraZetsu harvests browser histories, certificates, and CNAB financial files and maintains persistent communication with the marketplace via WebSocket.
read more →

Pegasus zero-click iMessage exploit hits Serbia protester

🛡️ A forensic investigation by Citizen Lab and the SHARE Foundation found high-confidence indicators that a member of Serbia's student protest movement was infected with NSO Group's Pegasus spyware via an iMessage zero-click exploit. The infection indicators spanned December 2025 and January 2026, and the attack method is believed to have been patched in iOS 18.4.1. The case is part of broader documented targeting of Serbia's civil society ahead of key 2026 elections, with recommendations that notification recipients seek expert assistance and enable protective measures.
read more →

Critical Elementor Pro flaw exploited to hijack sites

⚠️ A critical vulnerability (CVE-2026-32475) in Elementor Pro was patched on August 19 after active exploitation that uploads webshells and enables remote command execution. The flaw affects versions 4.2.1 and earlier and abuses faulty file-upload array validation in forms with a File Upload field. Wordfence blocked nearly 200,000 attempts and advises immediate upgrade to 4.2.2 and checks for rogue PHP files in uploads.
read more →

Thomson Reuters C-Track Breach Affects Multiple Courts

🔒 Thomson Reuters disclosed that unauthorized access to its C-Track court case management platform occurred in March 2026, impacting courts across 11 U.S. states, the U.S. Virgin Islands, and Ontario. West Publishing detected the activity on June 30 and says some records may include names, SSNs, driver's license numbers, dates of birth, and medical or insurance details. Affected individuals are being offered credit monitoring services and vendor and court notices have been issued while investigations continue.
read more →

Thomson Reuters C‑Track Breach Impacts Courts in US and Canada

🔍 Thomson Reuters disclosed a cybersecurity incident affecting its C-Track court management software, detected on June 30, that resulted in unauthorized access to court records in Canada and multiple US jurisdictions. An investigation found files tied to three Ontario courts and appellate courts in 11 US states and the US Virgin Islands may have been exposed, potentially including names, identification numbers and medical information. Thomson Reuters and affected courts say some redacted or sealed content may be impacted; investigations continue and there is no evidence of financial systems being affected or misuse of the data to date.
read more →

Counterfeit installers enable enterprise breaches

🔒 Microsoft warns that attackers are compromising enterprises via counterfeit download sites imitating vendors like Microsoft Edge, Kaspersky, and Razer, delivering trojanized installers that establish persistence and weaken security. The campaign, tied to the public Silver Fox/Yinhu activity, uses look-alike domains and server-generated payloads whose hashes change on each download to evade file-based detection. Once executed, installers abuse legitimate Windows components and scheduled tasks to persist, modify Defender settings, and stage further payloads.
read more →

AI-enabled intrusions target Latin American organizations

🔎 We analyzed two multi-stage intrusion and data-exfiltration campaigns targeting Latin America that leverage AI to streamline operations. One cluster (CL-CRI-1131) targeted Mexican transportation and government entities using LotL techniques and self-hosted NextChat, while a second (CL-CRI-1163) targeted Brazil’s financial sector with custom RATs and a Go-based SOCKS5 proxy. Both clusters share proxy infrastructure and evidence of commercial LLMs aiding attackers.
read more →

AI agents compress ransomware intrusion timelines

🛡️ Palo Alto Networks’ Unit 42 found an attacker using AI agents to traverse an enterprise network in under 10 hours, a process that could have taken human operators about two weeks. Agents conducted automated reconnaissance, searched code repositories for credentials, accessed secrets-management systems, and leveraged stolen cloud keys to abuse the victim’s AI services. The intrusion combined familiar MITRE ATT&CK techniques with agentic orchestration, highlighting the need for faster containment and stronger controls over non-human identities.
read more →

FBI Probes Massive Nexus Identity Data Breach

🔍 The FBI is investigating a reported breach tied to a service called Nexus that allegedly exposed over 153 million driver’s licenses and other identity documents across the US and Canada. The trove was first reported by journalist Brian Krebs, who traced activity to identity verification provider IDScan.net, which is investigating. Security experts warn the breach could have long-lasting consequences because government IDs are immutable and widely used for verification.
read more →