< ciso
brief />
Incidents and Data Breaches Banner

All news in category “Incidents and Data Breaches

3296 articles · page 15 of 165

Multiple nation-linked groups target Pakistani police

🛡️ Cybersecurity researchers disclosed sustained espionage targeting Pakistani law enforcement between February 2024 and April 2026, impacting Balochistan Police and other agencies. Compromised assets included network appliances, web servers for police applications, and a Fortinet FortiMail gateway, with a Complaint Management System used to host implants. Four threat clusters deployed PlugX, ShadowPad, Cobalt Strike, and Remcos RAT, linking the activity to China- and India-nexus actors. The dual targeting by adversaries and partners underscores the high intelligence value of law enforcement systems.
read more →

Australia alerts on global CMS exploitation campaign

⚠️ The Australian Cyber Security Centre (ACSC) warned of a global campaign exploiting vulnerabilities in multiple content management systems and plugins, with many Australian small and medium businesses affected. Threat actors are deploying webshells to maintain persistence, steal credentials, and escalate access. The campaign targets several CMS platforms and specific plugins, and the ACSC cautions that AI may be used to accelerate attacks. Administrators are urged to apply patches, remove unused components, and tighten web-server protections.
read more →

The Gentlemen ransomware: rise and operational profile

🔒 Unit 42 details the emergence and tactics of The Gentlemen (aka Storm-2697), a Ransomware-as-a-Service active since mid‑2025 and scaling rapidly through 2026. The group uses C and Go variants, offers affiliates a 90% payout, and employs diverse initial access methods including exploited edge devices, brute force, stolen credentials and IAB partnerships. Researchers note custom tooling such as a Go backdoor, an EDR killer called GentleKiller, and likely zero-day exploitation to evade defenses.
read more →

Ryuk Operative Pleads Guilty, Faces 15 Years

🛡️ Karen Serobovich Vardanyan, 34, pleaded guilty to hacking U.S. companies and deploying Ryuk ransomware after being extradited from Kyiv. She provided initial access to corporate networks and helped deploy ransomware between November 2019 and April 2020, leading to large ransom payments including a Michigan firm that paid 200 BTC. Prosecutors say the group collected about 1,610 BTC (≈$15 million then).
read more →

Injective Labs SDK compromise exposes wallet keys

🔐 Unknown actors compromised the Injective Labs SDK repository and published a malicious npm package, @injectivelabs/sdk-ts@1.20.21, to exfiltrate cryptocurrency private keys and mnemonic phrases. The backdoored release, deployed on July 8, 2026, was embedded with fake telemetry that captured sensitive wallet data and transmitted it to an external server. The attacker pushed identical poisoned versions across 17 additional @injectivelabs-scoped packages to reach transitive users. A clean update (1.20.23) is now available and users are urged to rotate any exposed keys and check dependencies.
read more →

Police point to Dutch suspects in Odido breach

🔎 The Dutch National Police report strong indications that Dutch-speaking attackers were involved in the February breach of telecom provider Odido. Investigators recovered traces including a phone call where an impersonator posing as an Odido IT employee used social engineering to enable a phishing-based data theft. Odido disclosed the incident affected millions of customers and that exposed records may include names, addresses, contact details, IBANs, and some ID numbers, while call records, billing data and passwords were not exposed. The extortion group ShinyHunters claimed responsibility and released a large archive of stolen records, and the gang has been linked to multiple vishing and SSO-targeting campaigns affecting major providers.
read more →

Progress orders ShareFile Storage Zones offline

🔒 Progress Software has told ShareFile customers to shut down Windows servers running their Storage Zone Controllers in response to a "credible external security threat." The company has temporarily disabled access to affected accounts and says it has no indication of unauthorized access to ShareFile accounts or data while it investigates with internal and external experts. The disruption was made public via a customer post on Reddit and confirmed on Progress's status page; only self-hosted Storage Zone Controllers are affected, not cloud-only ShareFile accounts.
read more →

Progress warns ShareFile customers to shut servers

🛑 Progress Software has alerted ShareFile customers using on-premise Storage Zone Controllers to immediately shut down the Windows servers hosting those controllers after identifying a "credible external security threat." The company temporarily disabled access to Storage Zone Controller–backed accounts and says manual shutdown is required in addition to cloud-side restrictions. Progress is investigating with cybersecurity partners and will update customers within 24 hours while the ShareFile status page shows affected controllers are nonoperational.
read more →

CISA Details Response to Exposed AWS GovCloud Keys

🔒 The US Cybersecurity and Infrastructure Security Agency (CISA) detailed its response after a contractor’s personal GitHub repository exposed AWS GovCloud credentials and internal build code. CISA’s OCIO began incident response on May 15, quickly mitigating exposure and confirming no customer data was leaked or credentials used outside CISA environments. The agency emphasized lessons learned, including stronger repo controls, improved logging, adoption of zero trust principles, and clearer reporting channels for researchers.
read more →

Critical Gitea Docker auth bypass actively exploited

🔒 A critical authentication bypass (CVE-2026-20896) in the official Gitea Docker image is being actively exploited to impersonate any user, including administrators, when reverse-proxy authentication headers like X-WEBAUTH-USER are trusted from all sources. Sysdig reported the first in-the-wild exploitation roughly two weeks before public disclosure, and around 6,200 Gitea instances are internet-exposed. Gitea released versions 1.26.3 and 1.26.4 to address the issue and advises immediate upgrades or restricting REVERSE_PROXY_TRUSTED_PROXIES to known IPs.
read more →

Prisoner accused of stealing seized cryptocurrency

💼 A Bulgarian national, Rossen G. Iossifov, has been charged with removing $290,000 in government-seized cryptocurrency while serving a 121-month prison sentence for his role in laundering millions from U.S. fraud victims. He appeared in federal court in the Eastern District of Kentucky on counts of removal of property to prevent seizure and conspiracy to commit money laundering. Prosecutors allege he conspired in January 2024 to move funds through exchanges and mixers to evade seizure, and he faces up to 25 years if convicted.
read more →

GigaWiper: Unified backdoor blends espionage and wiping

🛡️ Microsoft has identified GigaWiper, a versatile Golang backdoor that consolidates espionage and multiple destructive wiping capabilities into a single implant. The tool merges components from at least three prior malware families, enabling command-and-control, disk-level wiping, fake ransomware with unrecoverable keys, and multi-pass secure wiping. Researchers observed standalone wipers and larger backdoor binaries, and advise enabling tamper protection, cloud-delivered antivirus, EDR in block mode, and blocking known C2 infrastructure.
read more →

Laser fault resets Tangem crypto wallet PINs

🔬 Researchers at Ledger's Donjon team demonstrated that a precisely timed laser pulse aimed at the secure element inside a Tangem card can force the device to accept a new password without the old one. The invasive attack requires cutting the card open and a sophisticated lab setup costing roughly $250,000, so it cannot be done remotely or without obvious physical damage. Tangem cannot patch affected cards because their firmware is non-updatable, so the flaw is permanent; owners of lost or stolen cards holding significant value should move funds immediately.
read more →

New MODBEACON Rust RAT Uses gRPC Streaming

🛡️ QiAnXin attributes a new Rust-based remote access trojan named MODBEACON to the China-linked Silver Fox cluster. The memory-resident implant uses a modular, plugin-based architecture and leverages gRPC tunnel streaming with transport borrowed from open-source proxy tools (Xray/V2Ray) for its C2 channel. Distributors push the malware via counterfeit installers promoted through SEO poisoning and host C2 infrastructure on Amazon and Cloudflare CDNs.
read more →

Ransomware family exploits signed drivers to evade

🛡️ Symantec details how the GodDamn ransomware, a 2026 evolution of the Hyadina family, uses Microsoft-signed malicious drivers to disable endpoint defenses. The attackers deployed AnyDesk covertly, dropped a signed kernel driver named PoisonX disguised as a Symantec product, and used credential-stealing tools like Mimikatz to escalate access. After weakening defenses and harvesting credentials, the threat actors executed file encryption and displayed a ransom note, demonstrating continued tactical evolution.
read more →

Exposed server reveals mass WordPress backdoor campaign

🔍 Researchers found a cybercrime crew's unsecured server containing tools, logs, and target lists that revealed a large-scale webshell access brokerage dubbed WP-SHELLSTORM. The exposed files showed automated scanners exploiting known WordPress and Joomla plugin flaws, notably the Breeze caching and Joomla JCE bugs, and included lists naming over 1.4 million domains. Two security teams analyzed the leaked repository and measured confirmed compromises in the thousands, while also tracing earlier credential-stealing activity against corporate Nacos instances. The leak underscores how public exploits and poor operator hygiene enabled mass compromise at scale.
read more →

NHS warns staff over unlawful access to records

🔒 The NHS has warned staff they may face criminal prosecution and career-ending sanctions for accessing patient records without a legitimate reason. Head of the NHS Jim Mackey called such behaviour a “disgraceful breach of patient trust,” and the organisation has launched an awareness campaign alongside guidance for monitoring and preventing unauthorized access. The guidance urges technical controls such as least-privilege, MFA and role-based access, and notes real-time flags in modern electronic patient record systems. High-profile incidents and ICO action have prompted the drive to strengthen detection and deterrence.
read more →

Former negotiator sentenced in BlackCat ransomware case

🔒 A former DigitalMint incident response employee was sentenced to 70 months for participating in BlackCat (ALPHV) ransomware attacks that targeted U.S. organizations. Prosecutors say the group tied to BlackCat conducted over 60 breaches and collected at least $300 million in ransoms. Two other former negotiators received four-year sentences after pleading guilty to related charges. Victims included large financial and nonprofit organizations that paid multi‑million dollar ransoms.
read more →

Injective SDK npm package used to steal wallet keys

🔒 Security researchers discovered that the @injectivelabs/sdk-ts npm package (v1.20.21) was published with malicious code to capture cryptocurrency wallet private keys and mnemonic seed phrases. The compromise stemmed from a hijacked GitHub contributor account with suspicious commits appearing on June 8; the legitimate owner quickly reverted changes and released a clean 1.20.23. The malware activated when wallet-generation or import functions were called and exfiltrated secrets via HTTP POST to a public Injective Labs endpoint, and the tainted package had hundreds of dependent packages and thousands of downloads.
read more →

Dormant GitHub Accounts Exploited to Scrape Orgs

🔎 Datadog Security Labs warns of coordinated campaigns using dormant or compromised GitHub accounts and exposed personal access tokens to enumerate organizations via the GitHub API. Operators use automated scraping tools, aged "ghost" accounts, and legitimate-sounding user agents to blend into normal API traffic, primarily collecting public data but occasionally cloning private repositories. The activity leverages unauthenticated API surfaces and GraphQL queries to map repos, memberships, followers, and other artifacts for reconnaissance.
read more →