< ciso
brief />
Incidents and Data Breaches Banner

All news in category “Incidents and Data Breaches

3300 articles · page 25 of 165

International takedown of AudiA6 crypto laundering service

🔎 An international law enforcement operation dismantled the AudiA6 cryptocurrency laundering service, suspected of moving more than €336m for ransomware gangs and other cybercriminals between 2022 and 2025. The probe identified an industrial-scale laundering scheme that used thousands of stolen identities and money mules to obfuscate funds. Arrests, domain seizures and frozen crypto followed coordinated actions across Europe, the US and Georgia.
read more →

Novo Nordisk discloses clinical trial data breach

🔒 Novo Nordisk disclosed an unauthorized access incident affecting internal IT systems and pseudonymized patient data from some clinical trials. The breach exposed trial participant IDs and health, biomarker, lifestyle, and demographic details, while the company says direct identifiers were not accessed. Healthcare professionals' contact details were also compromised, prompting warnings about phishing and impersonation risks. Novo Nordisk has isolated affected systems, engaged external cybersecurity experts, and is investigating the scope and impact.
read more →

Google sues to dismantle AI-powered scam networks

🛡️ Google is taking legal, technical, and legislative steps to disrupt large-scale AI-enabled phishing and smishing campaigns. The company filed a civil lawsuit against the China-based “Outsider Enterprise,” coordinated with the FBI and telecom partners to block malicious texts, and is advocating bipartisan federal legislation to strengthen protections. Google also leverages AI-driven detection on Android and messaging defenses to intercept malicious messages at scale.
read more →

CISA orders three-day patch for Ivanti Sentry flaw

🔒 The U.S. Cybersecurity and Infrastructure Security Agency (CISA) ordered federal agencies to patch an actively exploited Ivanti Sentry flaw (CVE-2026-10520) within three days under Binding Operational Directive BOD 26-04. The vulnerability, an OS command injection in Ivanti's security gateway appliance, has been confirmed exploited and added to CISA's Known Exploited Vulnerabilities Catalog. Shadowserver reports multiple Sentry gateways have already been backdoored and warns unpatched systems are likely compromised.
read more →

French Tchap breach exposed over 73,000 public sector accounts

🔒 DINUM disclosed that a breach of the Tchap encrypted messaging platform impacted over 73,000 French public sector accounts after a compromised user account was used to access the service. The attacker accessed data shared in public chat rooms, which are not encrypted, potentially exposing names, email addresses, avatars, and affiliated organizations. Private conversations remain encrypted and protected, and the malicious account has been blocked while an investigation continues. A threat actor has claimed responsibility and released samples of stolen files.
read more →

Japanese energy firm loses drive with 10.9M accounts

🔒 Kyushu Electric Power disclosed a physical security incident after an external backup drive containing private data for up to 10.9 million accounts went missing from a server room cabinet. The company said the drive was used on April 27 due to storage capacity limits and was found absent on May 26 when staff returned. The lost data reportedly includes customer names, addresses, usage data, phone numbers, and retail provider names, but not bank or credit card details. Authorities and Japan’s privacy commission have been notified, and an investigation and individual notifications are underway.
read more →

ShinyHunters exploited Oracle PeopleSoft zero‑day

🔒 The ShinyHunters extortion group exploited an unpatched Oracle PeopleSoft remote code execution zero‑day (CVE-2026-35273) to compromise enterprise servers, steal data, and extort victims. Mandiant links the activity to UNC6240 and observed attacks from May 27 to June 9, before Oracle published its advisory on June 10. The flaw requires no authentication and exposes PeopleTools 8.61 and 8.62 installations with externally reachable Environment Management Hub endpoints. Universities were heavily targeted; mitigations focus on disabling or blocking PSEMHUB and hunting for post‑exploit indicators.
read more →

Analysis: The Gentlemen ransomware group's evolution

🔎 A new PRODAFT report traces The Gentlemen (aka Phantom Mantis) from an affiliate of multiple RaaS families to an independent, enterprise-focused extortion operation led by a Russian-speaking actor tracked as LARVA-368. Active since March 2025 and claiming 478 victims, the group uses AI, diverse tooling, multi-platform ransomware, and aggressive affiliate incentives while targeting VPNs, firewalls, VMware, and other internet-facing systems.
read more →

Fake AI Guides Used to Deliver AsyncRAT Trojan

🛡️ Fortinet researchers uncovered a campaign where threat actors disguise malware as AI study guides and developer resources to deliver a multi-stage attack culminating in the AsyncRAT trojan. The booby-trapped archives contain shortcut (LNK) files and hidden documents that trigger staged scripts, using trusted system tools and AutoHotkey repurposed as an execution engine to evade detection. Attackers deploy scheduled tasks disguised as Realtek services, process hollowing to run payloads inside legitimate .NET processes, and hide components in decoy files to keep victims unaware while PowerShell stages execute silently.
read more →

Interpol operation dismantles long‑running PhaaS platform

🛡️ An Interpol-led operation, Operation Ramz, targeted cybercrime across 13 MENA countries from October 2025 to February 2026, yielding 201 arrests and the seizure of 53 servers. Group-IB disclosed that the crackdown resulted in the takedown of the SniperDz phishing-as-a-service platform and the arrest of its primary developer in Algeria. SniperDz operated since at least 2015, offering phishing kits and hosting, and was linked to tens of thousands of fake domains and hundreds of thousands of phishing pages. Investigators attributed the platform through OpSec failures, social media traces and shared intelligence that enabled law enforcement disruption.
read more →

Enhanced license plate tracking expands surveillance

🔎 A surveillance company proposes adding Bluetooth sensors to automatic license plate readers (ALPRs) so devices could capture both license plates and unique identifiers from phones, wearables, and other Bluetooth-enabled devices. Called SignalTrace, the technology would enable ALPRs to move from vehicle tracking to more direct tracking of specific people. ALPRs are widespread across the U.S., and SignalTrace would significantly increase the scope of data collected. While concerning, the proposal highlights broader issues given how much data smartphones already gather.
read more →

China-linked JDY botnet accelerates enterprise risk

🔍 Lumen’s Black Lotus Labs reports a China-linked botnet called JDY has grown to over 1,500 compromised SOHO and IoT devices used to rapidly discover and fingerprint internet-facing systems after public vulnerability disclosures. The activity, tied to nation-state actors including Volt Typhoon, enables persistent, distributed reconnaissance that can evade geofencing and IP-reputation controls. Researchers warn this marks a shift toward industrialized pre-exploitation scanning and undermines traditional perimeter patch and monitoring assumptions.
read more →

OceanLotus Targets Vietnamese Investors and Firms

🔍 ESET links the Vietnam-aligned APT group OceanLotus to two campaigns delivering the SPECTRALVIPER backdoor against a transport construction firm and stock investors via a FireAnt Metakit supply-chain compromise between mid-2024 and March 2026. The actor used DLL side-loading and update-server abuse to deploy loaders and steal host profiles, signaling a shift toward more selective domestic espionage.
read more →

Nottingham University student-records breach affects 454,600

🔒 The University of Nottingham confirmed a cyber incident that exposed a significant amount of student record data, affecting current students and alumni. The university reported the breach to the Information Commissioner's Office and Action Fraud and is working with the platform vendor on a forensic investigation. The ShinyHunters extortion group has claimed responsibility and posted an archive they say contains finance, payment, personal and academic data from multiple campuses.
read more →

Maximum-severity Ivanti Sentry flaw now exploited

🔒 Attackers are exploiting a recently patched maximum-severity OS command injection in Ivanti Sentry (formerly MobileIron Sentry), tracked as CVE-2026-10520, to achieve root code execution on Internet-exposed gateways. Ivanti released patches in Sentry R10.5.2, R10.6.2, and R10.7.1, but Shadowserver reports many publicly reachable appliances have already been backdoored. Shadowserver warned that their scans undercount exposures due to blocklisting and urged immediate patching, while Ivanti has not revised its advisory and maintains no evidence of customer exploitation at disclosure.
read more →

Path traversal in Langflow exploited to write files

🛡️ A high-severity path traversal flaw (CVE-2026-5027) in the AI development platform Langflow is being actively exploited to write arbitrary files to exposed servers. Tenable discovered the issue, which stems from unsanitized filenames in the POST /api/v2/files endpoint, and disclosed it on March 27, 2026. Patches were released in langflow-base 0.8.3 and Langflow 1.9.0, and users are urged to upgrade to version 1.10.0.
read more →

Miasma worm source code briefly leaked on GitHub

🛡️ The Miasma credential-stealing worm, an evolution of the Shai-Hulud toolkit, was briefly published on GitHub after threat actors uploaded it to multiple compromised accounts. The framework steals developer build and cloud credentials, compromises package registries and repositories, and propagates autonomously without C2 by abusing GitHub. Researchers note destructive 'dead-man switch' behavior and a build pipeline that randomizes payloads to evade detection, increasing supply-chain risk.
read more →

ShinyHunters Target Oracle PeopleSoft Instances

🛡️ ShinyHunters are actively stealing data from Oracle PeopleSoft instances, claiming breaches across 300 instances at over 100 organizations. The actor says they used a mix of old and zero-day vulnerabilities in a "gadget chain," with many victims in the education sector. Exposed tooling, scripts, and IOCs were found in online directories, and impacted organizations are urged to check logs and begin incident response immediately.
read more →

Attackers Use Short-Form Videos to Spread Vidar Stealer

🎯 New research from ReversingLabs reveals threat actors are using TikTok and Instagram Reels to distribute the Vidar infostealer by posing as tutorials for unlocking premium software. Campaigns manipulate platform algorithms to boost saves and shares, driving viewers to lookalike domains that deliver Vidar via PowerShell or gateware-filled download sites. ReversingLabs recommends auditing install privileges and expanding phishing training to include social feeds.
read more →

SilabRAT malware targets crypto via session hijacks

🛡️ Group-IB reports a new MaaS remote access trojan called SilabRAT, advertised since late 2025 and offered on dark web forums. The malware uses a hidden VNC (HVNC) and browser-profile cloning to hijack logged-in sessions and evade passwords and MFA, while operators spread it via spam and ClickFix lures. Its capabilities include keystroke logging, clipboard clippers, COM elevation to bypass Chrome app-bound encryption, and persistent access aimed at stealing cryptocurrency.
read more →