< ciso
brief />
Incidents and Data Breaches Banner

All news in category “Incidents and Data Breaches

3296 articles · page 14 of 165

Forg365 phishing service lowers M365 takeover barrier

🔒 A phishing-as-a-service platform called Forg365 is lowering the technical barrier to Microsoft 365 account takeovers by offering AI-assisted lure creation, device-code abuse, and adversary-in-the-middle techniques. Distributed via Telegram with subscription pricing and a free trial, the service automates phishing workflows, email delivery, mailbox monitoring, and post-compromise persistence. Researchers advise restricting device-code authentication, deploying phishing-resistant MFA such as FIDO2/WebAuthn, and thoroughly revoking tokens, sessions, and unauthorized devices after compromise.
read more →

Lidl warns customers after third‑party data theft

🛡️ Lidl has alerted customers in Germany, Belgium and the Netherlands after personal data was stolen from a third‑party IT provider. The retailer said the online shop itself was not affected but a separately stored file containing names, phone numbers, emails, birth dates and customer numbers was accessed. Lidl stated passwords, payment details and delivery addresses are not impacted and urged vigilance against phishing. Forensics experts and authorities have been engaged and customers are advised to verify senders and avoid clicking unknown links.
read more →

Ransomware Negotiator Betrays Victims, Sentenced

🔒 A trusted ransomware negotiator secretly aided the BlackCat/ALPHV gang, sharing victims' insurance limits and negotiation strategies in exchange for cuts of ransom payments. Angelo John Martino III, a DigitalMint negotiator, funneled sensitive negotiation details through a hidden panel to attackers, inflating ransoms and enabling multimillion-dollar payouts. He and accomplices also acted as affiliates, deploying ransomware and siphoning proceeds; authorities seized assets and secured convictions and prison sentences.
read more →

148 npm Packages Masked as Student Proxies Abused

🔍 JFrog researchers found 148 npm packages posing as student web proxies that converted visitors' browsers into a DDoS botnet for roughly two weeks in May. The packages hosted a proxy UI but loaded a mutable remote script and a WebSocket flood generator, allowing attackers to run volumetric and control-plane attacks from unsuspecting users' tabs. Many packages have since been removed, but remnants and mutable loaders remain active, so network and build mitigations are advised.
read more →

Microsoft maps year-long OAuth access campaigns

🔎 Microsoft mapped a year-long series of campaigns, running mid-2025 to mid-2026, that gave attackers access to corporate Salesforce environments without exploiting platform bugs. The intrusions relied on OAuth trust: vishing to approve malicious connected apps, theft of vendor OAuth tokens, and misconfigured guest access to Experience Cloud. Microsoft and Salesforce added detection and governance features in Defender for Cloud Apps and improved real-time event visibility to expose connected-app activity and reduce over-permissioned integrations.
read more →

Defending SaaS OAuth Abuse Targeting Salesforce

🔒 Microsoft observed campaigns from mid-2025 to mid-2026 where actors using tradecraft linked to ShinyHunters abused OAuth trust relationships to access Salesforce instances, exfiltrate CRM data, and maintain persistence. Three intrusion paths were identified: vishing-induced OAuth consent, supply-chain compromises of integrations (e.g., Salesloft, Gainsight), and misconfigured guest access via Aura/GraphQL. Microsoft enhanced Defender for Cloud Apps telemetry and controls, coordinated with Salesforce, and introduced posture, visibility, and risk-scoring features to help detect and mitigate these threats.
read more →

Japan’s largest taxi operator halts systems after attack

🚨 Nihon Kotsu, Japan's largest taxi and chauffeur operator, has shut down parts of its IT infrastructure after detecting unauthorized external access and a malware infection early Saturday. The outage has affected the taxi dispatch system, web booking, reservation management, phone dispatch services, and some internal systems, leaving key services offline while the company investigates. Nihon Kotsu has engaged external cybersecurity experts, warned customers to avoid suspicious attachments and links, and has not yet confirmed any data leakage or any claim of responsibility by ransomware groups.
read more →

Jscrambler npm package compromised with infostealer

🛡️ Jscrambler disclosed that a threat actor published malicious npm releases (8.14, 8.16, 8.17, 8.20) containing an info-stealer executed via the preinstall hook. The tampered package was live for two hours, downloaded 1,479 times, and affected four dependent packages that were deprecated and replaced. Jscrambler revoked compromised publishing credentials and urged users to rotate secrets and update to the safe release.
read more →

CrashStealer macOS info stealer uses signed dropper

🛡️ Jamf Threat Labs discovered a new native C++ macOS information stealer named CrashStealer that harvests credentials, browser data, cryptocurrency wallet extensions, password manager entries, and keychain material. The campaign uses a signed and Apple-notarized disk image dropper served from a gated site and persists via LaunchAgent after re-signing itself. Collected files are AES-GCM encrypted before exfiltration to an attacker-controlled server, and the malware employs multiple analysis-resistance techniques.
read more →

ModHeader removed after hidden browsing-history collector

🛡️ Google and Microsoft removed the popular ModHeader extension after researchers found a dormant browsing-history collector embedded in the official store builds. The collector, confirmed by Stripe OLT to be in the genuine Chrome package, stored encrypted domain lists and device fingerprints locally and was designed to upload them to api.stanfordstudies[.]com on a schedule if an internal allow-list were populated. While the allow-list shipped empty and no evidence shows data was exfiltrated, the extension still pinged extensions-hub[.]com and logged request metadata locally. Users are advised to uninstall ModHeader, rotate exposed secrets, and defenders should block the implicated domains and hunt for related indicators.
read more →

Weekly recap: ShareFile warning and broad threats

🛡️ Progress urged ShareFile customers to shut down Windows Storage Zone Controllers amid a credible external threat, temporarily disabling access while investigating; there are no signs of account or data compromise. Other top stories include a critical Zimbra XSS patch, a compromised Jscrambler npm package distributing a multi-platform Rust stealer, and Microsoft detailing the destructive GigaWiper backdoor. Large-scale web shell operations (SHELLSTORM), HalluSquatting attacks against AI assistants, and many actively exploited CVEs round out the week's threats.
read more →

Rival Chinese and Indian Cyber Espionage Hits Pakistan

🔒 SentinelLabs reports that suspected China- and India-linked cyber operators targeted multiple Pakistani law enforcement systems between February 2024 and April 2026, focusing on Balochistan Police. The compromise affected servers hosting biometric records, case files and tenant registrations, and included implants in a public Complaint Management System. Analysts linked PlugX, ShadowPad and Cobalt Strike to China-nexus activity and Remcos to a suspected India-nexus actor. The incidents underscore risks from centralized police IT systems and concentrated intelligence value.
read more →

Lidl discloses online shop customer data breach

🔒 Lidl notified customers in Germany, Belgium, and the Netherlands that attackers accessed a separately stored file at a third‑party service provider and stole personal data from users of its online shop. The retailer said the shop's systems were not affected, but it cannot yet exclude the theft of passwords, billing or payment details. Lidl and the service provider have reported the incident to authorities and engaged forensic experts, while warning customers to watch for phishing and identity fraud.
read more →

Forg365 PhaaS Targets Microsoft 365 Accounts

🛡️ A new phishing-as-a-service operation named Forg365 targets Microsoft 365 by combining device-code phishing, AitM tactics, antibot evasion, AI-assisted lure creation, and post-compromise mailbox operations. Distributed via Telegram and offered as a subscription, the kit uses legitimate delivery infrastructure like Amazon SES and SendGrid to blend into normal email flows before redirecting victims to attacker-controlled domains. The platform includes a clearnet operator panel, OAuth and token handling, and a Chromium extension called ForgCookie that automates cookie refresh and sustained access to compromised accounts.
read more →

AI-assisted PowerShell used for noisy AD reconnaissance

🛡️ Huntress investigators reported an early-June 2026 intrusion where an unknown actor used a vibe-coded PowerShell script to enumerate Active Directory. The attacker gained RDP access with pre-compromised credentials, staged tools under C:\ProgramData\, and executed an AI-suspected payload that mapped DCs, users, groups, OUs, trusts, and produced an AD_Report.html. After harvesting data into CSVs and archiving them, files were exfiltrated to a remote server, with additional enumeration using s5cmd and SharpShares.
read more →

FSB Centre 16 Targets Routers Using Weak SNMP

🔒 Cyber agencies from 12 countries warn that Russian FSB Centre 16 (aka Berserk Bear/Static Tundra) is scanning the internet for routers using default or weak SNMP credentials and occasionally exploiting known CVEs in Cisco devices. Sectors such as communications, defence, energy, finance, government and healthcare are urged to adopt SNMPv3, patch affected systems and disable vulnerable features like Smart Install when patching is not possible. The advisory links Centre 16’s tactics to broader disruptive campaigns and coincides with UK/EU attribution of late 2025 attacks on Poland’s energy grid to the group.
read more →

US and Allies Share Guidance on Russian Router Attacks

🔒 Cybersecurity agencies from the US and eight partner nations issued a joint advisory warning that Russian state-linked hackers (FSB Centre 16) are exploiting poorly configured routers and default SNMP credentials to breach critical infrastructure networks. The advisory attributes scanning and exfiltration activity to groups tracked as Berserk Bear and others, and highlights exploitation of Cisco Smart Install (CVE-2018-0171). Agencies urged mitigation steps including upgrading to SNMPv3, disabling Cisco Smart Install, enforcing strong passwords, blocking TFTP/SNMP at the perimeter, and updating firmware to protect energy, communications, healthcare, finance, and government sectors.
read more →

Extradited Hacker Pleads Guilty in Ryuk Ransomware Case

🔒 An Armenian national extradited from Ukraine has pleaded guilty in a Portland federal court to conspiracy and computer fraud for his role in deploying Ryuk ransomware between November 2019 and April 2020. The defendant, Karen Serobovich Vardanyan, admitted to compromising multiple US organizations, including a Michigan firm that paid 200 bitcoin and other victims in Oregon and Texas. Under a plea deal he agreed to pay over $1.1m in restitution but faces potential prison terms and fines. The case underscores growing US success in prosecuting ransomware actors who traditionally operated from former Soviet states.
read more →

Australia warns of widespread CMS exploitation

🛡️ The Australian Cyber Security Centre (ACSC) has warned of a large-scale campaign scanning and exploiting vulnerabilities in content management systems worldwide, impacting many SMBs in Australia. The actors deploy webshells via flaws allowing unauthenticated file upload, remote code execution, SSRF or deserialization, affecting products like WordPress, Joomla, Craft CMS and others. The ACSC advises inspecting servers for compromise, isolating and remediating infected hosts, patching vulnerable systems, and restoring from known-good backups.
read more →

RedHook Android Malware Abuses Wireless ADB

🛡️ Researchers at Group-IB describe a new RedHook Android malware variant that abuses Wireless ADB to gain shell-level (UID 2000) privileges without a wired computer connection. The malware tricks victims into granting Accessibility permissions to enable Developer Options and Wireless Debugging, retrieves the pairing code, and connects via the loopback interface. It leverages a Shizuku-based framework to execute shell commands, silently install apps, modify protected settings, and perform RAT functions like screen streaming and keystroke interception. Distribution relies on social engineering directing victims to fake Play stores; users are urged to install apps only from official sources, review permissions, and enable Play Protect.
read more →