< ciso
brief />
Incidents and Data Breaches Banner

All news in category “Incidents and Data Breaches

3296 articles · page 3 of 165

Manic Android Malware Targets Banks and Messaging

🛡️ Manic is a recently observed Android threat combining banking malware and mobile spyware to target Ukrainian banks, government and identity services, messaging apps, and financial institutions across Europe. It is distributed via phishing sites and dropper apps impersonating utilities and abuses Android accessibility and notification permissions to capture credentials and perform device takeover. The family includes wrappers and implants with enhanced anti-analysis checks and can exfiltrate data via a novel multi-hop Wi‑Fi mesh relay using nearby compromised devices. ThreatFabric attributes active development to early 2026 with new deployments in July that introduced stronger lock-screen phishing and expanded capabilities.
read more →

AI-assisted attacks target Siemens S7 PLCs

🚨 A joint US government advisory warns that threat actors are using AI to generate exploitation scripts and tools targeting Siemens S7 Series programmable logic controllers (PLCs), placing critical sectors such as water, energy and manufacturing at heightened risk. The agencies say attackers are leveraging public scanning services to find internet-exposed PLCs, using AI to assist lateral movement and to craft tools that mimic legitimate OT monitoring, enabling read/write access via the S7comm protocol. Operators are urged to inventory systems, patch devices, block internet access to PLCs, segregate OT/IT networks, restrict remote access with MFA, disable unused services and engage with vendors for model-specific hardening to mitigate disruption, safety incidents and data compromise.
read more →

ToxicPanda 2.0 and GoldDigger Expand Global Targeting

🛡️ Zimperium zLabs and IBM Trusteer detail updated Android banking trojans: ToxicPanda 2.0 and a new GoldDigger campaign. ToxicPanda now includes 167 remote commands, enhanced PIN-harvesting for over 140 banking and crypto apps, and ADB-based escalation techniques. GoldDigger leverages sophisticated packing and accessibility abuse to drive fraud, with active campaigns in South Africa and the U.K.
read more →

Manic Android malware steals data via nearby devices

🛡️ Manic is a multifaceted Android malware active since at least February that combines spyware, banking fraud, and remote-control features, primarily targeting users in Ukraine and across Europe. It abuses Android Accessibility and notification access to capture PINs, SMS codes, credentials, files, and location, and uses transparent overlays to log keypad input. When direct C2 access is unavailable, Manic can exfiltrate encrypted data through nearby compromised devices over Wi‑Fi Direct or Bluetooth, using multi‑hop relays. Users should avoid installing APKs from untrusted sources, deny Accessibility permissions to untrusted apps, and run Play Protect scans.
read more →

ToxicPanda 2.0 Expands Targeting of Financial Apps

🔒 Security researchers at zLabs discovered ToxicPanda 2.0, an Android banking Trojan that now targets 140 banking and cryptocurrency apps and uses overlay-based credential theft against 349 financial institutions. The variant abuses the Android Accessibility Service to enable wireless debugging and attempts to obtain shell access via ADB, bypassing runtime prompts and enforcing persistence. New capabilities include stealing device lock credentials through screen overlays. Recommended defenses include blocking sideloading, treating accessibility grants as privileged events, and alerting on developer options or wireless debugging via MDM.
read more →

Police Conceal Use of Flock License Plate Cameras

🚨A usage policy for Flock automated license plate reader (ALPR) cameras in Wapello County, Iowa, instructs officers to refrain from informing vehicle occupants or routinely documenting ALPR use in reports. The document explicitly orders: “DO NOT MENTION ALPR USAGE TO THE OCCUPANTS OF THE VEHICLE” and to avoid mentioning it in reports unless absolutely necessary. This secrecy echoes prior law enforcement efforts to conceal surveillance tools such as IMSI-catchers.
read more →

Critical Zimbra RCE Flaw Actively Exploited Now

🛡️ CERT Polska warns that attackers are actively exploiting a critical Zimbra Collaboration Suite vulnerability (CVE-2026-73570). The flaw, patched in Zimbra 10.1.20 on July 20, enables unauthenticated remote code execution via command injection in the SNMP notification processing when SNMP notifications are enabled. Shadowserver reports over 12,100 Zimbra servers exposed online, and administrators are urged to check logs and specific directories for signs of compromise. Zimbra has been a frequent target of APT groups in past campaigns.
read more →

40 Malicious Firefox Extensions Target Web3 Wallets

🛡️ A cluster of 40 malicious Mozilla Firefox extensions has been identified stealing cryptocurrency wallet secrets by impersonating popular Web3 products like OKX, Rabby Wallet, and TronLink. Socket Threat Research attributes the extensions to a broader set of 77 related add-ons with shared code and infrastructure, a campaign they call Offside Wallet Theft Factory, active since March 2026. The threat actors used Supabase projects, Cloudflare Workers, and hard-coded C2 to exfiltrate recovery phrases, private keys, and credentials, often hiding malicious payloads behind benign sports-score or utility shells. Researchers warn the economics of disposable extensions and repurposing identities make the Firefox Add-ons ecosystem an attractive target.
read more →

Rogue ransomware affiliate posing as recovery firm

🛡️ GuidePoint Security's GRIT warns that a suspected ransomware affiliate calling itself "Ransom Busters" has been contacting victims before attacks are publicly disclosed, offering decryption keys and data deletion for fees. The group claims to exploit vulnerabilities in RaaS admin panels and demanded $20,000–$60,000 to remove stolen data. Evidence from two incidents suggests the entity is likely the affiliate behind the intrusions, using consistent tools, account patterns, and attacker-controlled hostnames across multiple attacks.
read more →

Sakura Internet breach exposes up to 1.36M accounts

🔒 Japanese cloud provider Sakura Internet disclosed unauthorized access to its sales management system storing customer contract and membership data. The company said the incident was discovered during a separate investigation into a smaller breach at its Sakura Rental Server service and that up to 1,360,563 accounts may have been affected. Sakura reported no confirmed data exfiltration, noted stored passwords are hashed and no credit card data is kept in the compromised system, and is notifying affected customers and authorities.
read more →

CareCloud data breach impacts 3.7M patients

🩺 CareCloud, a U.S. healthcare IT provider, disclosed a March breach that disrupted services and exposed patient data. The company said an unauthorized third party accessed an AWS environment between March 10 and March 16, 2026, and claimed to have exfiltrated database contents. Notifications began July 25, and impacted individuals are offered identity protection via IDX. No group has claimed responsibility and investigations continue.
read more →

Remote Spectre leak against Cloudflare Workers revealed

🔐 Researchers disclosed a remote Spectre attack against Cloudflare Workers that leaked a JSON Web Token (JWT) from a co-located Worker at up to 12 bits per second, far exceeding the 2021 rate. The experiment used attacker and victim Workers controlled by researchers, with Cloudflare confirming mitigations deployed in production and reporting no signs of active exploitation. Cloudflare improved Dynamic Process Isolation (DyPrIs), integrated the V8 Sandbox, and added MPK-based in-process isolation to address the weakness.
read more →

U.S. warns of AI-driven attacks on Siemens PLCs

🔒 U.S. cybersecurity agencies issued a joint advisory warning that threat actors are using AI-generated Python scripts to exploit Siemens S7 Series programmable logic controllers (PLCs) within U.S. critical infrastructure. The agencies—NSA, CISA, FBI, DOE, and EPA—noted ongoing activity that targets exposed PLCs by abusing vulnerabilities, outdated software, and weak authentication to gain read/write access and disguise tools as legitimate OT monitoring software. Operators are urged to inventory devices, apply updates, block internet access, and strengthen monitoring and access controls to reduce risk.
read more →

US Charges Iranian Hackers in Massive IP Theft Case

🛡️ The U.S. Justice Department charged eight additional alleged members of the Mabna Institute, bringing the total to 17 Iranians accused of a years-long campaign that stole academic research, intellectual property, emails, and proprietary data from U.S. and international organizations. The DoJ says the operation began around 2013 and compromised roughly 8,000 accounts—targeting over 100,000 professors worldwide—and extracted about 31.5 TB of data valued at $3.4 billion. Rewards of up to $10 million are offered for information on five defendants, and the defendants face multiple charges including conspiracy and aggravated identity theft.
read more →

Medusa Ransomware Hits 500+ Critical Infrastructure

🛡️ The FBI, CISA and HHS issued an updated advisory on August 18, 2026, stating Medusa ransomware has affected over 500 critical infrastructure organizations, with healthcare heavily targeted. The advisory notes the operation has accelerated exploitation of unpatched vulnerabilities—sometimes within 24 hours or before public disclosure—and expanded post-exploitation tooling. Medusa uses stealthy PowerShell techniques, legitimate RMM tools, credential theft methods like Mimikatz, and exfiltration tools such as Bandizip and Rclone to support a double-extortion model.
read more →

ICE Collecting DNA Samples Sparks Privacy Debate

🧬 The post questions the ethics of widespread state DNA collection, citing examples in the US and other democracies. It challenges the practice of collecting saliva from children and frames such programs as erosions of liberty and privacy. The author uses poetic language to warn that mass genetic databases risk turning justice into surveillance and raises concerns about historical injustice and future accountability.
read more →

Data Analyst Sentenced for Extortion Using Stolen Payroll Data

📰 A contract data analyst misused privileged access to steal sensitive corporate and payroll records after learning his contract would not be renewed. Adopting the alias "Loot," he sent over 60 extortion emails demanding $2.5 million in cryptocurrency and attached screenshots of employee personal data to pressure his employer. Forensic evidence and metadata tied the emails and a Coinbase payment trail to the analyst, leading to his arrest, conviction on six counts of transmitting interstate communications with intent to extort, and a 24-month federal prison sentence.
read more →

Wiz AI Agent Finds Critical Script Injection in Snowflake

🔎 Security researchers at Wiz, part of Google Cloud, discovered a critical script injection vulnerability in Snowflake’s public GitHub repository that GitHub Advanced Security missed. The issue, found by Wiz Research’s autonomous Red Agent on June 23, allowed unauthenticated command execution in a GitHub Actions runner via a crafted issue title. Snowflake patched the workflow and rotated the Jira token after being notified via HackerOne, reporting no evidence of unauthorized access.
read more →

StopAndProtect: Operation Exposed by OPSEC Failures

🔍 Check Point Research uncovered a unique case where OPSEC mistakes exposed a global cyber crime operation named StopAndProtect. The investigation revealed accessible victim logs, screenshots, source code, and references to nearly 2,000 compromised WordPress domains, showing how attackers repurposed legitimate sites to host malware and manage campaigns. Researchers warn organizations to beware of unexpected CAPTCHA prompts and to keep systems and security software updated.
read more →

UT San Antonio IT Systems Taken Offline After Incident

🔒 The University of Texas San Antonio took several IT systems offline after detecting attempted unauthorized activity at the network edge, prompting containment measures by University Technology Solutions and partners. Officials say there is no evidence of data access or exfiltration so far, though the outage disrupted online registration, tuition payments and phone systems ahead of term start. Students were granted extensions and instructed to reset passphrases as remediation steps continue.
read more →