< ciso
brief />
Incidents and Data Breaches Banner

All news in category “Incidents and Data Breaches”

3607 articles · page 14 of 181

Pegasus zero-click iMessage exploit hits Serbian activists

🔍 The Citizen Lab and SHARE Foundation found that an iPhone linked to Serbia's student protest movement was infected via an iMessage zero-click exploit delivering NSO Group's Pegasus spyware. Analysis showed high-confidence indicators of infection between December 2025 and January 2026, and Apple addressed the exploited vulnerability in iOS 18.4.1. Multiple activists, politicians and students in Serbia have been targeted with advanced spyware amid the 2026 election period.
read more →

International Operation Disrupts Long‑Running Sality Botnet

🛡️ A coordinated law enforcement action on August 31 disrupted the Sality P2P botnet, active for over 20 years. Authorities from the US, Bulgaria, Hungary and Romania, supported by Europol and private partners CrowdStrike and the Shadowserver Foundation, used sinkholing and protocol manipulation to redirect infected machines and enable remediation. The operation targeted Sality’s decentralized peer lists to remove malicious super peers and insert sinkhole entries, while ISPs and CSIRTs helped identify and notify victims.
read more →

Researcher Publishes FalconFlank PoC for CrowdStrike

🔒 A security researcher known as Chaotic Eclipse released a zero-day PoC called FalconFlank that enables local privilege escalation by abusing CrowdStrike Falcon's office malicious macros remediation. The researcher says the exploit works on fully updated Windows 11 25H2 and Windows Server 2025 systems with Falcon installed, and cautions defenders may need to add exclusions or obfuscate detection to test it. This release follows recent PoCs targeting Kaspersky and Microsoft Defender, with the researcher criticizing vendor engagement.
read more →

AI-assisted iPhone theft and criminal 'SaaS' service

🔍 On Smashing Security episode 483, Graham Cluley and guest James Ball discuss how AI is being used to help thieves bypass protections and steal Apple iPhones. They outline the evolution of Apple's Activation Lock and how criminal groups like AnonymousKit operate as a criminal SaaS with customer support and Telegram testimonials. The hosts recount personal phone-theft experiences and highlight the ongoing challenges despite Apple's strengthened safeguards.
read more →

Impersonating IT Support to Gain Enterprise Access

🛡️ Microsoft Threat Intelligence observed a human-operated campaign abusing Microsoft Teams external collaboration to impersonate IT support and socially engineer users into granting interactive remote sessions. Attackers install a malicious MSI that stages a portable Node.js runtime and an obfuscated JavaScript implant to provide persistent C2-driven command execution. The operators perform extensive host and Active Directory reconnaissance and pivot enterprise-wide via WinRM, using legitimate tooling to blend into normal operations.
read more →

Critical JFrog Artifactory Authentication Bypass Exploited

🛡️ A critical authentication bypass (CVE-2026-82329) in self-managed JFrog Artifactory is being actively exploited to mint admin tokens. The flaw exists in default configurations and allows unauthenticated attackers with network access to obtain administrative privileges. JFrog released fixes on August 28 for multiple Artifactory 7.x versions and says cloud instances were already protected.
read more →

Russian Extradition in Major Freelance Platform Malware Case

📰 A Russian national, Searzhudin Tamirlanovich Aktulaev, has been extradited to the US and appeared in federal court on charges alleging he helped distribute malware to roughly 80,000 users of a freelance employment platform between 2016 and 2017. The indictment accuses him and co-conspirators of using fake messaging accounts to send malicious Excel attachments that installed remote access trojans, harvesting credentials and PII to support fraud. He faces multiple charges including conspiracy, unauthorized access and aggravated identity theft and remains in federal custody pending further proceedings.
read more →

Revolut-targeted phone scams hit Jersey residents

📞 Police in Jersey warn residents to be vigilant after a spike in phone scams targeting Revolut accounts. Over a four-week period, 75% of reported scam incidents involved Revolut, with victims losing roughly £180,000. Callers impersonate bank staff, request security details, or ask victims to transfer funds to purportedly "safe" accounts. Revolut urges customers to use its secure in-app chat and never share passwords; police remind the public to report suspected fraud.
read more →

Chinese-speaking group weaponises Brazilian sites

🛡️ Check Point Research attributes a sustained SEO fraud and phishing campaign to a Chinese-speaking cluster dubbed Gambling Goblin, active since mid-2025. Attackers implanted custom Apache modules to act as reverse proxies on compromised Brazilian government, education and commercial websites, redirecting specific visitors to localized phishing pages that impersonated app stores and promoted betting. The operation leveraged a broad Linux malware toolkit including AlphaAgent, oRAT and credential stealers, plus reconnaissance tools to map targets.
read more →

Malicious Apache Modules Hijack High‑Reputation Sites

🔍 A Chinese-speaking cybercrime cluster called Gambling Goblin has been observed installing malicious Apache modules on compromised Brazilian government and educational servers to redirect visitors to attacker-controlled pages promoting online gambling. Check Point Research has tracked the campaign since mid-2025 and found modules that reverse-proxy traffic while stripping security headers so injected content can run. The actors use multiple Linux and reconnaissance tools including DownPro, AlphaAgent, oRAT, and a 3snake-based credential stealer, and the operation appears aimed at large-scale SEO manipulation using high-reputation domains.
read more →

Dropbox accounts breached via Lenovo ID email flaw

🔒 Dropbox warns some users that unauthorized actors accessed accounts by exploiting a flaw in Lenovo's email verification to register fraudulent Lenovo IDs. Although many users had no Lenovo accounts, Dropbox's integration with Lenovo Identity Provider Services allowed attackers to use those fake IDs to access accounts without passwords. Dropbox says the intrusions occurred between August 4 and 21 and has since expired sessions authenticated via Lenovo IDs and added a password requirement for Lenovo ID logins.
read more →

Critical JFrog Artifactory Bug Sparks Supply-Chain Alarm

🔒 A critical authentication bypass in JFrog Artifactory (CVE-2026-82329) is being actively exploited, allowing unauthenticated attackers under default configuration to obtain administrative privileges. Threat actors were observed creating admin tokens and enumerating users, groups and credentials, prompting urgent advisories to upgrade affected self-hosted versions and fortify cloud instances. Organizations are urged to patch exposed systems, revoke potentially compromised tokens, inspect logs and verify artifact integrity to mitigate downstream risks.
read more →

Meta ad campaign pushed new StreamRat Android trojan

🛡️ ThreatFabric disclosed StreamRat, a sophisticated Android banking trojan promoted via fake streaming ads targeting Spanish-speaking users on Meta. The campaign, active from June 11 to July 3, 2026, reached roughly 570,950 EU Meta accounts and lured victims to sideload a malicious APK that requests Accessibility and VPN-like permissions. Once granted, the malware can capture keystrokes, take screenshots, display overlays, and remotely control devices.
read more →

SonicWall SMA zero-day flaws exploited in attacks

🔒 SonicWall released hotfixes for two critical vulnerabilities in its Secure Mobile Access (SMA) 1000 series appliances after confirming active exploitation. The flaws — a pre-authentication SSRF (CVE-2026-83548) and a post-authentication command injection (CVE-2026-83549) — affect SMA 6210, 7210, and 8200v on older platform-hotfix builds. SonicWall recommends upgrading to the latest fixes, searching for IoCs, and re-imaging or resetting credentials if compromises are detected.
read more →

Nutex Health Discloses Patient Data Theft

🔒 Nutex Health reported unauthorized access to its servers that resulted in the exfiltration of sensitive patient, employee and business information, and the attacker has threatened to publish the data online. The company notified the SEC and is investigating the scope while preparing breach notifications for affected patients. Nutex says there has been no material operational or financial impact identified to date.
read more →

AI-Assisted Ransomware: Rapid Agentic Intrusion

🛡️ Unit 42 investigated an incident where a human operator used frontier AI agents to autonomously breach an enterprise network and execute a ransomware-style operation. The attack compressed weeks of tradecraft into under 10 hours by orchestrating >50 MITRE ATT&CK techniques via parallel LLM calls, structured agent communication, and AI-generated scripts. Agents performed reconnaissance, secrets harvesting, privilege takeover, CI/CD abuse, and hijacking of cloud AI endpoints to sustain post-compromise operations.
read more →

Gambling Goblin hijacks government sites for SEO fraud

🔍 Check Point Research details a campaign by a Chinese-speaking actor dubbed Gambling Goblin that compromises Brazilian government web servers and repurposes them as invisible reverse proxies for phishing pages. The operation installs malicious Apache modules and toolkits to proxy trusted domains to attacker-controlled pages impersonating major app stores, using borrowed reputation to boost SEO and push online gambling. The campaign is linked to the Earth Berberoka cluster and demonstrates an industrialized, scalable fraud model.
read more →

Extradited Russian Hacker Charged Over 2016–2017 Campaign

🔍 The U.S. Department of Justice has charged Searzhudin Tamirlanovich Aktulaev, extradited from Cyprus on August 28, for operating roughly 255 fake accounts on a freelance platform to distribute malware-laced Excel attachments to about 80,000 users in 2016–2017. The indictment, unsealed after his August 31 appearance in San Francisco, alleges use of TVRAT and DarkVNC to gain remote control, steal data, and facilitate fraud. Aktulaev denies the charges; the DoJ notes allegations are unproven until conviction.
read more →

Russian Charged for Malware Campaign Targeting Freelancers

🛡️ A U.S. federal grand jury indicted Russian national Searzhudin Aktulaev for a phishing campaign that infected thousands of freelancers with TVRAT and DarkVNC malware. Extradited from Cyprus, Aktulaev allegedly used hundreds of fake accounts between 2016 and 2017 to send malicious Excel attachments that deployed remote-access malware to roughly 80,000 targets. The malware exfiltrated credentials and PII to command-and-control servers, many hosted in the U.S., and half of victims were in the United States.
read more →

How China Industrialized State Hacking Infrastructure

🛡️ Last week the US Justice Department and FBI seized domains tied to QScan and QTRouter, platforms used by PRC-linked group QTFY to target US agencies and critical infrastructure. QTFY, operated by Nanjing Xinjiuwei, provided scanning, exploitation, and obfuscation services—turning IoT devices into routing infrastructure for state clients. The takedown highlights how marketized contractors and shared services scale Chinese offensive operations while creating choke points for law enforcement. Experts urge CISOs to shift from IP-based defenses to behavioral visibility, rapid patching, and stronger edge controls.
read more →