< ciso
brief />
Incidents and Data Breaches Banner

All news in category “Incidents and Data Breaches

3300 articles · page 26 of 165

China-linked JDY botnet broadens US military focus

🛡️ JDY is a distributed reconnaissance botnet tied to China-nexus actors that has expanded from ~650 to over 1,500 compromised SOHO and IoT devices, with a heavy focus on U.S. military and associated networks. Researchers at Black Lotus Labs observed JDY rapidly scanning for newly disclosed vulnerabilities, collecting banners, TLS certificates, and protocol fingerprints. The botnet uses Tor-hidden services and a central Dispatch Service to receive scanning tasks and exfiltrate results, and supports TCP/SSL/UDP/ICMP scanning plus service fingerprinting.
read more →

Investigation Identifies Alleged Administrator of The Gentlemen

🔍 Check Point and other cyber intelligence firms have been tracking The Gentlemen, a fast-growing RaaS operation that offers affiliates a 90/10 revenue split and has become the second most active ransomware group by victim count. Researchers link the group’s administrator to the handles Hastalamuerte and Zeta88, and trace forum registrations, email addresses, Telegram IDs, and phone numbers to a likely real-world identity in Izhevsk, Russia. Open-source and breach data suggest the suspect may be Alexander Yapaev, who lists employment at Uralenergo Udmurtia; he did not respond to requests for comment.
read more →

Why schools remain favourite cybercriminal targets

🔒 Recent ransomware incidents have shown that schools are year-round targets for cybercriminals. Evanston Township High School closed after an attack disrupted critical systems, while Powys County Council in Wales confirmed student and staff data were accessed at multiple schools. Districts are engaging external experts and notifying authorities, highlighting schools' limited budgets and reliance on networked systems.
read more →

ServiceNow flaw exploited to gain deeper access

🔒 ServiceNow disclosed a security incident after unidentified actors exploited a vulnerability to obtain unauthorized, deeper access to some customer instances. On June 5, 2026, the company applied a security update to hosted instances to restrict access to an endpoint so only authenticated users can reach it. ServiceNow detected anomalous activity and confirmed successful queries against instance tables for a subset of customers, who have been notified. The issue affects customers on the Australia platform release or those with specific pre-Australia configuration changes.
read more →

Proof-of-Concept for Defender RoguePlanet Zero-Day

🛡️ An anonymous researcher known as Chaotic Eclipse published a proof-of-concept for a Microsoft Defender zero-day dubbed RoguePlanet, a race-condition exploit that can yield SYSTEM-level shells on Windows 10 and 11 with June 2026 patches. The PoC is inconsistent across systems and currently fails on Windows Server due to ISO mounting restrictions. The disclosure follows prior Defender flaws from the same researcher and a public conflict with Microsoft over coordinated disclosure and account revocation.
read more →

Military used GPS to distribute cryptographic keys

🔍 Steven Murdoch uncovered that U.S. military satellites have been broadcasting hidden codes via public GPS for nearly two decades, effectively turning each satellite into a covert distribution channel. He identified synchronized transmissions across all 31 operational satellites on May 26, 2011, matching the rollout timeline of the military’s Over-the-Air Distribution (OTAD) and Over-the-Air Rekeying (OTAR) systems. This mechanism allowed remote rekeying of military GPS receivers, replacing manual key distribution.
read more →

French government messaging platform breached by hijack

🔐 DINUM warned that a hijacked user account was used to breach Tchap, the French government's encrypted messaging platform. Developed with ANSSI in 2018 on the Matrix protocol, Tchap serves the French public sector and has grown rapidly since its mandated adoption in August 2025. DINUM and CNIL were alerted after ANSSI detected the intrusion and the compromised account was promptly blocked while investigations continue. A threat actor claimed responsibility and shared samples, alleging large-scale data and message exfiltration.
read more →

JLR CISO Ordered In-Person Password Resets

🔒 At Infosecurity Europe, Ashish Shrestha, then group CISO of Jaguar Land Rover, recounted the September 2025 cyber-attack response that required over 30,000 staff to reset passwords on site. He said the in-person resets ensured trusted identities for communications after the incident and validated Microsoft 365 integrity. The firm also reset MFA and validated users’ identities physically to mitigate risks of remote account takeover.
read more →

NFCShare Android malware spreads via fake app updates

🛡️ New variants of the NFCShare Android malware are being distributed as fake updates for legitimate banking apps hosted on GitHub, targeting customers across Europe. The campaign tricks victims into performing an NFC ‘verification’ that captures card data and a 4-digit PIN via Android’s IsoDep interface, then exfiltrates it to a C2 server over WebSocket. D3Lab, which first documented NFCShare in January 2026, notes the malware uses malformed APK packaging to hinder automated analysis and that repositories have hosted dozens of spoofed banking APKs for Italian and Spanish banks.
read more →

SoFi Hong Kong confirms third-party data breach

🔒 SoFi Hong Kong reported a third-party data breach after detecting unauthorized access to a vendor-hosted database on April 30, 2026. The company engaged a third-party cybersecurity firm and is investigating while notifying affected customers. SoFi has not disclosed the vendor identity, the number of impacted customers, or the exact data exposed. Customers were advised to monitor accounts, enable two-factor authentication, and take extra precautions.
read more →

WhatsApp disrupts alleged NSO spear‑phishing attacks

🔒 WhatsApp says it detected and disrupted spear‑phishing campaigns it attributes to the NSO Group after investigating user reports of social‑engineering attacks. Meta reports the phishing lures redirected targets to external websites and that test accounts and groups linked to the activity were removed. The company provided three domains as indicators of compromise and urged users to update apps and enable protections such as Advanced Protection on Android and Lockdown Mode on iOS.
read more →

Critical Check Point VPN Flaw Actively Exploited

🔒 Check Point has reported active exploitation of a critical logic flaw in certificate validation affecting Remote Access and Mobile Access VPNs configured to use deprecated IKEv1. The issue, tracked as CVE-2026-50751 (CVSS 9.3), lets unauthenticated attackers bypass user authentication and establish VPN sessions without valid passwords. Exploitation requires IKEv1 enabled, legacy clients accepted, and no machine certificate requirement; activity was first observed in early May 2026 and has targeted a few dozen organizations globally.
read more →

Weekly cyber recap: supply chain worm and hacks

⚠️ Last week saw a range of high-impact incidents, from the Miasma worm compromising 73 Microsoft GitHub repositories to targeted mailbox espionage and an Instagram account compromise via an AI support tool. Vendors patched active Android flaws, researchers flagged malicious npm packages and a compromised Hola Browser installer, and U.S. agencies disrupted transnational investment fraud. Multiple threat clusters, including China-linked espionage groups and financially motivated actors, broadened their geographic scope and tactics, while many critical CVEs remain urgent for defenders to patch.
read more →

Oxford University reports CareerConnect credential breach

🔒 Oxford University disclosed a data breach after its third-party provider, Group GTI, reported that the CareerConnect platform was compromised on May 28. The attackers accessed users' first and last names, email addresses, and encrypted passwords for accounts not using Single Sign-On; GTI has invalidated those passwords and will require resets. The university said no course materials, uploaded files, appointments, or financial data appear affected, but warned users to watch for phishing attempts.
read more →

Meta: 20,225 Instagram Accounts Exposed by Bug

🔒 Meta disclosed that a bug in its AI-powered High Touch Support (HTS) tool allowed attackers to request password reset links to email addresses not associated with targeted Instagram accounts, enabling unauthorized access where two-factor authentication was not enabled. The issue was discovered on May 31, affecting 20,225 users and exposing contact details, profile data, posts, messages and activity history. Meta disabled the HTS tool, invalidated reset links, enforced mandatory security checkpoints on impacted accounts, and instructed users to reset passwords and enable 2FA while it reviews recovery flows.
read more →

Meta AI support flaw led to large Instagram account hijacks

🔒 Meta disclosed that a vulnerability in its AI-assisted High Touch Support (HTS) tool allowed threat actors to reset passwords and hijack over 20,000 Instagram accounts. Attackers exploited HTS by submitting email addresses not verified against target accounts, obtaining reset links for accounts without 2FA. Meta disabled the HTS system, invalidated generated reset links, secured impacted accounts, and required affected users to reset passwords and re-authenticate. The company said it will fix the verification check and review similar recovery flows across its platforms.
read more →

Silent Ransom Group Targets U.S. Law Firms Now

🛡️ Mandiant reports the Silent Ransom Group (UNC3753) is targeting U.S. law firms and professional services with invoice-themed phishing followed by voice calls impersonating IT staff. Attackers use callback phishing to trick victims into installing remote support tools like AnyDesk or Zoho Assist, granting access to networks and enabling rapid data theft and extortion. The campaign involves phishing domains, self-destructing messaging, and fast-flux infrastructure to host leak sites.
read more →

Critical Everest Forms Pro Flaw Lets Site Takeover

⚠️ A critical vulnerability (CVE-2026-3300) in Everest Forms Pro versions 1.9.12 and earlier allows unauthenticated attackers to execute arbitrary PHP on affected WordPress sites via the plugin's Complex Calculation feature. The issue stems from user-supplied values being inserted into an eval() string without properly escaping single quotes, enabling code injection. Wordfence telemetry shows active exploitation creating rogue administrator accounts, and a patch was issued by the developer on March 18.
read more →

Research shows free apps turn smart TVs into proxies

🔍 A reverse-engineered iOS SDK from Bright Data reveals free apps can turn devices, including always-on smart TVs, into exit nodes that relay web-scraping traffic. The SDK, embedded behind opt-in screens, uses peer channels with weak authentication and can bypass VPNs on iOS, allowing background relays that consume home bandwidth. Blocking a handful of SDK domains at the router or scanning apps on managed devices can stop the behavior.
read more →

Miasma worm compromises 73 Microsoft GitHub repos

🛡️ Microsoft's GitHub organizations — including Azure, Azure-Samples, Microsoft, and MicrosoftDocs — were hit by the self-replicating Miasma supply chain campaign that affected 73 repositories, prompting GitHub to disable access. The incident notably re-compromised the durabletask package previously infected by TeamPCP, suggesting lingering credential exposure. Miasma, a variant of the Mini Shai-Hulud worm, has mutated rapidly and pushed malicious payloads both to registries and directly to GitHub source repos, leveraging AI coding tools and developer workflows to execute payloads. Security firms warn the campaign exploits trust in maintainers and signing rather than platform vulnerabilities, allowing widespread propagation across the open-source ecosystem.
read more →