< ciso
brief />
Incidents and Data Breaches Banner

All news in category “Incidents and Data Breaches

3300 articles · page 27 of 165

Suspicious polyfill login prompts hit major Japanese sites

🔐 Toshiba and Muji warned visitors about unexpected sign-in pop-ups generated by the external service polyfill.io, advising users to cancel and change passwords if they entered credentials. The prompts were caused by remnants of a 2024 incident when the polyfill domain served malicious scripts after changing hands; the domain began responding again in late May 2026 with HTTP 401 requests. Both companies suspended the service and removed the offending code, and other Japanese sites were also affected.
read more →

Chinese APT UNC5221 uses new backdoors to persist

🛡️ Volexity researchers attribute prolonged intrusions to the Chinese espionage group UNC5221 (aka VerdantBamboo), which used the Brickstorm backdoor plus previously undocumented malware Plenet and AgentPSD to maintain access. The actor compromised an MSP and victim systems, remaining undetected for at least 18 months and returning after remediation. Plenet is a cross-platform .NET backdoor; AgentPSD is a Python reverse shell used as fallback persistence.
read more →

Vendor Sentenced for Selling Drugs on Nemesis Market

🔍 A California man received a 26-year federal prison sentence after trafficking fentanyl and methamphetamine through Nemesis Market. Darren Hughes, 39, was convicted in November 2025 and sentenced on May 26 for operating a dark web store that offered free samples and sold drugs to undercover agents for cryptocurrency. Authorities arrested Hughes on June 28, 2023, seizing 672 grams of methamphetamine and a loaded ghost gun during his arrest. The case was part of a broader international investigation that took down Nemesis Market in March 2024.
read more →

Agencies Warn of LinkedIn Recruitment for Espionage

🛡️ A joint bulletin from the FBI, MI5, ASIO, CSIS and NZSIS warns that Chinese military intelligence is using professional networking sites and job platforms to recruit Western workers into sharing sensitive information. The advisory details fake cover companies, targeted outreach on platforms like LinkedIn, and staged hiring processes that escalate from innocuous reports to requests for privileged material via encrypted messaging. Targets include military personnel, academics, journalists, and think-tank staff, and payments are made through common money-transfer and crypto services. The agencies urge scepticism toward unsolicited, well-targeted approaches and rapid moves to encrypted apps.
read more →

Asin Android spyware targets Arabic-speaking users

🛡️ ESET has identified a new Android spyware family named Asin that targets Arabic-speaking users through multiple campaigns observed since early 2025. The malware was distributed via fake websites impersonating a government news source, a PDF editor, and a live war map, and was promoted on social platforms like Facebook and Telegram. Infections require manual APK installation and permission grants, with samples found on devices in Türkiye and on Xiaomi devices running Android 15. Attribution and precise objectives remain unknown, though journalists and OSINT researchers are likely targets.
read more →

Malware threats imperil automated tank gauges

🔒 CISA warns that ongoing cyber-attacks on automated tank gauges (ATGs) could allow attackers to drain fuel tanks or hide theft and leaks, affecting gas stations, military bases, hospitals, and industrial sites. The attacks exploit authentication bypasses, hardcoded credentials, OS command execution, SQL injection, and privilege escalation to gain full control. Administrators are urged to remove public serial connections, change default passwords, apply patches, report incidents to CISA, and push supply-chain partners to adopt defenses.
read more →

FIFA World Cup 2026: Rising ticket and streaming scams

🛡️ Security researchers and law enforcement warn that FIFA-themed fraud is already targeting World Cup 2026 fans ahead of the June 11 kickoff. Threat actors have registered thousands of lookalike domains, deployed phishing kits that clone FIFA's login pages, and hidden banking trojans inside pirate streaming apps. Scams include counterfeit ticket sales, fake merchandise shops, malicious streaming apps that install banking malware, and social-media ad campaigns driving victims to phishing pages.
read more →

Magecart campaign abuses Stripe and GTM for skimming

🛡️ A Magecart campaign uses Google Tag Manager and Stripe's API to host both the card‑stealing payload and exfiltrated payment data. The skimmer, delivered via legitimate‑looking GTM containers, targets Magento/Adobe Commerce checkouts and reads a specific Stripe customer record to retrieve and execute obfuscated JavaScript. Stolen card details are XOR‑obfuscated, stored locally, then uploaded into fake Stripe customer metadata, with variants using Google Firestore as an alternative backend.
read more →

DentaQuest breach exposed data of 2.6 million accounts

🔒 DentaQuest, a major US dental benefits administrator, disclosed a cybersecurity incident after the extortion group ShinyHunters posted and later leaked over 234 GB of stolen data. The company confirmed limited disruption to services on June 2 and said it engaged external experts to investigate and contain the breach. Analysis by Have I Been Pwned found records for 2.6 million accounts in the leaked dataset, including emails, names, phone numbers, government IDs, insurance details, genders, and dates of birth.
read more →

WFP registration breach exposes Gaza household data

⚠️ The United Nations World Food Programme (WFP) confirmed a breach of its Palestine self-registration application (SRA) that exposed beneficiaries' personal data across the Gaza Strip, including names, ID numbers, phone numbers, and neighborhood locations. The SRA has been temporarily suspended while WFP implements urgent security improvements and investigates the incident. The organization warned recipients to be cautious of impersonation or phishing attempts and said assistance programs will continue as normal for registered beneficiaries.
read more →

Critical RCE in Everest Forms Pro Actively Exploited

🛡️ A critical remote code execution flaw in Everest Forms Pro for WordPress has been actively exploited to hijack sites. Wordfence analysis shows the vulnerability (CVE-2026-3300, CVSS 9.8) allows unauthenticated attackers to run PHP via the plugin's Calculation add-on when "Complex Calculation" is enabled. The bug affects all versions through 1.9.12 and was patched in 1.9.13; administrators are urged to update immediately. Wordfence telemetry recorded tens of thousands of blocked exploit attempts and identified indicators such as a rogue admin named "diksimarina" and a recurring source IP.
read more →

Police dismantle fake ID marketplace aiding smugglers

🔍 French and Spanish authorities dismantled an online marketplace selling counterfeit identity documents used by migrant smuggling rings across the EU. On May 27, police arrested a suspect in Alicante and seized document-production equipment and about 800 fake European IDs from an apartment rented under a false name. Europol said the platform provided forged physical and digital documents to facilitate border evasion, fraudulent residence claims, and secondary movements within the Schengen Area.
read more →

FlutterShell macOS backdoor spreads via malvertising

🛡️ Palo Alto Networks Unit 42 uncovered Operation FlutterBridge, a macOS malvertising campaign distributing a Flutter-built backdoor called FlutterShell. The campaign links to a cluster known as JSCoreRunner/FileRipple and an actor tracked as CL-CRI-1089, active since at least 2023. FlutterShell uses WebView and a JavaScript-to-native bridge to load malicious logic from attacker-controlled sites, supports command execution, file manipulation, and exfiltration, and has multiple evolving variants that passed Apple notarization.
read more →

Fake Sites Impersonate Open‑Source Tools to Deliver Malware

🛡️ Check Point researchers uncovered an operation that clones open-source and freeware project pages to funnel users through a Traffic Distribution System (TDS) that can deliver malware like Remus Stealer, AnimateClipper, and the SessionGate framework. The deceptive sites preserve real links and use CloudFront-hosted JavaScript to convert clicks into a gated redirection chain enforcing anti-bot and VPN checks. The campaign has been active since late 2025 and escalated to malware distribution in January 2026.
read more →

Attackers Exfiltrate Exchange Executive Mailbox

📧 Symantec and Carbon Black disclosed that unknown attackers maintained quiet access to a senior executive's Outlook mailbox at a major global stock exchange for at least five months, repeatedly copying messages and routing them through Dropbox and OneDrive to blend with normal cloud activity. The intruders used a mailbox stealer built on Aspose, ran binaries impersonating legitimate updaters and OneDrive, and staged additional backdoors before access likely ended in March 2026. Indicators point to espionage-focused credential theft and tunneling tooling rather than a financially motivated campaign.
read more →

Chinese hackers deploy new Atlas RAT across Europe

🔍 Proofpoint attributes a surge of financially motivated campaigns to TA4922, a Chinese-speaking cybercrime group now targeting organizations in Germany, Italy, the UK, and South Africa. The actor uses localized phishing lures and messaging apps to deliver a growing arsenal that includes the newly observed Atlas RAT, multiple custom loaders such as RomulusLoader and SilentRunLoader, and the ValleyRAT family. Researchers warn the toolset supports reconnaissance, credential theft, keylogging, audio/video capture, and plugin payloads, and note operational expansion and possible use of LLMs in development.
read more →

CISA warns of attacks on fuel tank monitoring systems

🔒 CISA and multiple US agencies warn that internet-exposed automatic tank gauge (ATG) systems used to monitor fuel and liquid storage tanks are being targeted by cyber actors. The advisory notes attackers exploit authentication bypasses, hardcoded credentials, command-execution flaws, SQL injection, and privilege-escalation vulnerabilities. If compromised, attackers can alter network and tank settings, disable alerts, and impair monitoring, increasing risk to safety and operations. Agencies recommend blocking public access, enforcing strong credentials and MFA, applying updates, and monitoring for unauthorized changes.
read more →

New HTTP/2 Bomb DoS Crashes Major Web Servers

🛡️ A newly discovered DoS technique called HTTP/2 Bomb can bring down default HTTP/2 deployments of major servers (NGINX, Apache, IIS, Envoy, Cloudflare Pingora) from a single machine in seconds. Discovered with assistance from OpenAI's Codex and reported by Calif researchers, it combines HPACK compression amplification with flow-control stalling to force massive memory allocations and prevent their release. Proof-of-concept exploits exist and patches or mitigations are partially available.
read more →

DoubleClick Redirects Used to Deliver DesckVB RAT

🛡️ Huntress researchers disclosed a malspam campaign that abuses Google DoubleClick redirectors to funnel victims to personalized phishing landing pages and drop a .NET remote access trojan called DesckVB RAT. The attack starts with an HTML attachment that redirects through DoubleClick, decodes a Base64 email, and serves a ZIP containing a JavaScript loader which executes a PowerShell script to fetch a .NET loader. The loader disables security controls, establishes persistence, and injects the RAT via process hollowing into Microsoft-signed processes to evade detection.
read more →

Inside C0XMO: Cross-Platform Gafgyt Propagation

🛡️ FortiGuard Labs details a new Gafgyt variant, C0XMO, which exploits CVE-2021-27137 in vulnerable DD-WRT firmware to gain remote control of devices. The malware separates scanning into a standalone Python scanner and distributes architecture-specific ELF payloads to multiple Linux platforms. C0XMO implements multi-stage persistence, kills competing botnets, supports extensive DDoS commands, and communicates with a C2 using a custom handshake. Organizations should update firmware, disable unnecessary remote services, and enforce strong credentials to mitigate risk.
read more →