< ciso
brief />
Incidents and Data Breaches Banner

All news in category “Incidents and Data Breaches”

3607 articles · page 15 of 181

FulcrumSec Leak Claims Extensive Manchester Airport Data

🛡️ FulcrumSec has published approximately 549GB of alleged customer data stolen from MAG, the operator of Manchester, Stansted and East Midlands airports. The group says it gained access via Iterable admin keys exposed in frontend JavaScript on the airports’ root domains. The post claims nearly 8.7 million customer profiles, marketing events, purchase records and future bookings were exfiltrated, raising risks of phishing and physical targeting.
read more →

Global takedown dismantles long-running Sality botnet

🔒 International law enforcement and private partners seized and sinkholed infrastructure tied to the Sality P2P botnet to disrupt operations and isolate infected hosts. The DOJ, FBI, and DCIS seized U.S. domains while authorities in Bulgaria, Hungary, and Romania seized European-hosted domains. CrowdStrike coordinated a peer-to-peer sinkhole that blocked Sality's super peers and payload distribution, ending operator control.
read more →

Law enforcement disrupts long‑running Sality botnet

🔒 The U.S. Department of Justice, working with international partners and industry, executed a sinkhole operation on August 31, 2026, to disrupt the Sality P2P botnet. CrowdStrike and Shadowserver collaborated with authorities from the U.S., Bulgaria, Hungary, and Romania to isolate peers and seize Sality-linked domains. The takedown prevents further payload distribution, though already infected machines still require remediation. Agencies advise reviewing network logs for beaconing to a designated sinkhole IP.
read more →

Counterfeit installers enable persistent system compromise

🛡️ Microsoft Defender Experts are tracking an active campaign that uses counterfeit software-download sites impersonating trusted vendors to distribute malicious installers. The campaign targets users seeking popular software and has caused compromises across multiple industries, with a concentration on China-based operations and Chinese-speaking users. The malicious installers establish persistence, evade defenses, and communicate with attacker infrastructure; Microsoft disrupted activity and recommends enabling protections such as SmartScreen, network protection, tamper protection, and Microsoft Defender XDR.
read more →

Aesto Health breach impacts over 9.5 million patients

🔒 Aesto Health disclosed a data breach affecting more than 9.5 million individuals after unauthorized access to a portion of its AWS infrastructure. The intrusion occurred in December 2025 and was confirmed on May 26, 2026, following a forensic investigation. Exposed data includes names, dates of birth, medical details, government IDs, and Social Security numbers; affected patients began receiving notification and credit monitoring offers in August.
read more →

Unsolicited praise emails puzzle newsletter author

📧 Bruce Schneier reports a sudden influx of brief, flattering replies to his newsletter confirmation emails. The messages are single-line praises and originate from apparently random Gmail addresses that never subscribed to Crypto-Gram. He initially replied to a few genuine-looking notes before realizing the volume and uniformity suggested AI-generated content. Schneier is uncertain of the senders' motive and asks readers for hypotheses about the possible scam.
read more →

Leaked Russian cyber operations training materials

📄 The leaked Bauman records describe a structured force-generation mechanism across General Staff components, including the GRU and Department No. 4, linked to units such as Military Unit 74455 (Sandworm). The material reframes Russian cyber capability as an institutional system—showing a pathway from university recruitment to military cyber roles—and clarifies that reported assignments are unit placements, not proof of individual operations.
read more →

Novocure breach exposes data of over 1,400 patients

🔒 Novocure, a global oncology company, reported a mid‑August incident in which unauthorized actors accessed certain information systems, exposing data for more than 1,400 U.S. cancer patients and an undisclosed number of employees. The company says most patient records contained ID numbers without names, while fewer than 50 patients in the western U.S. had identifying and provider contact details exposed. Novocure confirmed no medical devices were accessed and its operations remain functional, and it is evaluating regulatory notification obligations.
read more →

PaperCut zero-days exploited for data theft

🛡️ Two recently patched vulnerabilities in PaperCut NG and MF print management software, tracked as CVE-2026-81578 and CVE-2026-82078, are being abused in live data theft campaigns. PaperCut issued emergency patches and IOCs after confirming exploitation, while defenders report attackers dumping Derby database tables rather than pursuing public RCE paths. Shadowserver currently tracks over 800 exposed servers, and the vendor has not yet attributed the intrusions.
read more →

Cronos Restarts After Tectonic $74M Exploit

🔔 The Cronos blockchain resumed trading after a rapid price-manipulation attack on the Tectonic lending platform allowed an attacker to borrow $74 million. The attacker inflated the TONIC token price by 100x within 20 minutes and used it as collateral; only about $6 million in ETH was withdrawn while the rest remained on Cronos. Cronos halted the chain, restored state to before the exploit, and resumed block production while investigations continue.
read more →

North Korean job fraud expands beyond IT roles

🛡️ Researchers report DPRK-linked operators have broadened their employment fraud beyond IT into sales, marketing, and healthcare, using stolen and forged identities, VPNs, and proxy services to secure remote jobs at global firms. Investigations found evidence of PiKVM and USB capture hardware, synthetic personas aided by AI, and coordination via multi-account tools and facilitators who provision laptop farms. Agencies and firms are urged to strengthen identity verification and background checks to detect these sophisticated schemes.
read more →

Microsoft Exchange Online outage causes email failures

🛠️ Microsoft is investigating a widespread service issue causing authentication errors and email delays or failures for Exchange Online customers. The incident (EX1464935) was first acknowledged at 5:30 PM UTC after a surge of user reports; Downdetector indicates tens of thousands affected. Reported symptoms include delayed or failed message delivery, authentication errors, administration access issues, and intermittent mailbox operation failures. Microsoft says it has isolated a common failure pattern tied to authentication and protocol connectivity and is analyzing telemetry to determine remediation and scope.
read more →

OpenAI confirms ChatGPT outage affecting Work users

🛠️ OpenAI has acknowledged a partial outage affecting ChatGPT Work that began around 11:04 AM ET on Monday, August 31. Users across multiple subscription plans are seeing elevated latency and errors, with Plus subscribers particularly impacted because Work mode is unavailable for some. The company reported the issue on its status page and said engineers are working on mitigation, with the outage still ongoing as of 12:02 PM ET.
read more →

Weekly cybersecurity recap: espionage, AI, and breaches

⚠️ This week’s recap highlights major disruptions and ongoing campaigns, from an FBI takedown of a Chinese proxy network to AI agents and supply-chain failures. Coverage includes router backdoors, chained PaperCut flaws, malware delivered via fake CAPTCHAs, and the evolving tactics of China-linked actors like Fire Ant. Patch and verify trusted infrastructure controls to reduce risk.
read more →

Berlin confirms Rhysida ransomware data theft

🔒 Berlin’s city administration has confirmed a Rhysida ransomware incident after the gang listed the city on its leak site. The attack, discovered in mid‑August and publicly claimed on August 28, reportedly exfiltrated 5.79 TB across about 1.44 million files. Investigations involve the State Criminal Police Office, public prosecutor and federal agencies; officials say they will not pay the extortion demand. Authorities disconnected affected Senate departments and report no evidence that election systems were compromised.
read more →

ValleyRAT backdoor concealed in signed adware

🛡️ Kaspersky attributes a campaign to Silver Fox that hides the ValleyRAT backdoor inside a legitimately signed Chinese adware installer, QN Wallpaper. The attackers use DLL sideloading to run a malicious libcef.dll within the signed QnWallpaper.exe, disable Windows Defender, add autorun entries, and escalate privileges with runas. ValleyRAT can steal keystrokes and screenshots, mark its process as critical to induce BSOD on termination, and contacts several C2 servers and domains.
read more →

Aurora ransomware actors leveraging AI coding tools

🛡️ Threat actors tied to the Aurora (Aur0ra) ransomware have been observed using AI coding assistants like Cursor to plan and execute intrusions, according to CloudSEK and Gambit Security. Exposed infrastructure revealed months of activity targeting organizations across multiple countries between April and July 2026, with both Windows and Linux encryptors written in Zig. The attack chain includes credential theft, lateral movement, AD CS exploitation, and disabling recovery mechanisms before encryption. Investigators also identified affiliate payout splits and evidence of agentic use of Anthropic's Claude Sonnet for hands-on exploitation tasks.
read more →

Spring Ring: Voice Phishing Through Collaboration Tools

🛡️ Between January and April 2026, Unit 42 uncovered a coordinated vishing operation—named Spring Ring—using external Microsoft Teams accounts to impersonate IT help desk staff. The attackers contacted over 150 employees across at least 10 companies and employed live voice calls to coerce victims into installing RMM tools or custom malware. Two distinct campaigns were observed: one delivering an obfuscated PowerShell RAT and another using tailored executables that attempted NTLM relay attacks against domain controllers.
read more →

Trusted Chrome and Edge extensions weaponized

🔍 Researchers at Socket found a supply-chain campaign that turned 19 Chrome and Edge extensions into malware by acquiring or publishing updates to previously legitimate extensions. The attackers used automatic extension updates to push malicious JavaScript payloads that stole cryptocurrency, captured form input, hijacked active sessions, and exfiltrated social media access and browsing history. Several extensions had substantial user bases, underscoring the reach of the operation.
read more →

DoJ Revises Statement on China-Linked Hacking Targets

🛡️ The U.S. Department of Justice corrected a prior press release to state several federal agencies were "among the targets" of QTFY, a China-linked threat actor, rather than confirmed victims. The update clarifies the government affidavit and follows disruptions by the FBI of domains tied to QTFY's tools. The actor, tied to Nanjing Xinjiuwei and allegedly funded by the MSS, provided reconnaissance and proxy services to enable espionage.
read more →