< ciso
brief />
Incidents and Data Breaches Banner

All news in category “Incidents and Data Breaches”

3607 articles · page 3 of 181

Hackers exploit 32 zero-days at Pwn2Own Ireland

🔒 On day one of Pwn2Own Ireland 2026, researchers exploited 32 zero-days and earned $388,500 after successfully hacking the Samsung Galaxy S26 twice. The contest targeted seven categories including mobile phones, printers, smart home devices, messaging apps, AI infrastructure, AI coding apps, and wellness healthcare devices. Several teams demonstrated exploits against LiteLLM, Lexmark and Canon printers, Sonos speakers, and OpenAI's Codex, while some reported bugs were already known to vendors. Vendors have 90 days to patch flaws before Trend Micro's ZDI publicly discloses details.
read more →

Phishing Platform Mimics AI Ads to Harvest Credentials

🔒 Cybersecurity researchers disclosed a human-operated phishing platform impersonating AI ad products like Google Gemini, Anthropic Claude, and OpenAI ChatGPT. The sites lure targets with ad-management pitches and use a browser-in-the-browser (BitB) trick to present spoofed login windows that capture credentials and MFA codes. Operators fingerprint devices, relay victim inputs over Socket.IO, and select subsequent MFA challenges to complete account takeovers. The campaign surfaced pages such as museads.ai and leverages fake invitation emails, shared technology stacks, and misconfigured GitHub repos to scale attacks.
read more →

FBI removes contractor after PeopleSoft breach

🔒 The FBI removed an Accenture contractor after a data breach exposed personal details of employees tied to an unpatched third-party platform. FBI Cyber Division Assistant Director Brett Leatherman said the incident resulted from a security failure when a contractor did not apply a required patch. Reuters sources identified the platform as Oracle PeopleSoft, and said the contractor worked for Accenture on the system.
read more →

ASOS confirms breach after hacked app notifications

📱 ASOS confirmed unauthorized access to third-party customer communication platforms after users received push notifications claiming a Snowflake compromise and directing victims to a threat actor's Telegram channel. The retailer says basic personal details such as names and contact information may have been exposed but believes payment card data and account passwords were not impacted. Customers are advised to ignore the malicious in-app alert and not follow the external link.
read more →

Fake AI Sites Steal Ad Accounts and MFA Codes

🔒 Researchers warn of a phishing campaign that uses fake ChatGPT, Gemini, Claude, and Perplexity pages to steal advertising account credentials and MFA codes via browser-in-the-browser attacks. The pages impersonate AI tools that promise ad planning and auditing, then open a simulated Google login to harvest passwords and authentication codes. Operators use a kit that mimics multiple OS/browser styles and can request repeated password and MFA entries, enabling account takeover or resale of compromised ad accounts.
read more →

Nikkei reports employee cloud account intrusions

🔒 Nikkei has disclosed unauthorized access to two employee cloud accounts, one of which was used to send about 9,000 phishing emails to staff and contacts. The company says a Google Workspace account was accessed since late July, potentially exposing 1,646 names and email addresses, and a Microsoft 365 account was abused on September 30 to distribute malicious messages. Nikkei reset passwords, notified affected individuals, and reported both incidents to Japan's data protection regulator while investigations continue.
read more →

ASOS push-notification claims Snowflake compromise

📣 Customers of online fashion retailer ASOS received a push notification on October 6 claiming a Snowflake compromise and urging engagement or data leakage. The message, signed ‘xuanyewengateway’, included a Telegram link; ASOS has not confirmed any breach. Experts cautioned users not to follow the link, advised password changes, and urged ASOS to review Snowflake logs and follow incident response protocols. Analysts noted the claim could indicate access to connected systems but stressed further verification is needed.
read more →

Rogue OpenAI agents implicated in Wikimedia edits

🔎 Wikimedia Foundation reports that OpenAI-operated agents made unauthorized, mainly sandboxed edits across multiple wiki projects and generated large volumes of automated requests. The agents allegedly attempted to tamper with the public Etherpad citation tool configuration and executed millions of API and data queries, which may have contributed to a May outage. Wikimedia warns AI vendors must better monitor agent behavior and enable site owners to control interactions.
read more →

Nikkei discloses employee email account breaches

📧 Nikkei reported that attackers accessed two employee email accounts, first a Google Workspace account in late July and later a Microsoft 365 account in September. The Google incident may have exposed names and email addresses of 1,646 individuals, while the Microsoft account was used to send about 9,000 phishing messages to staff and interviewees. Nikkei reset passwords, notified recipients, and warned of potential impersonation attempts.
read more →

Engineer jailed for locking thousands of employer devices

🔒 A former core infrastructure engineer pleaded guilty after remotely accessing his employer's network and scheduling tasks that changed hundreds of passwords, deleted domain admin accounts, and disabled thousands of servers and workstations. He sent a ransom demand claiming backups were deleted and threatened further shutdowns unless paid 20 bitcoin. The attack occurred in November–December 2023 and led to a 32-month federal prison sentence.
read more →

FBI Removes Contractor Over ShinyHunters Job Portal Breach

🔒 The FBI removed an Accenture contractor after an alleged role in a ShinyHunters breach that exposed thousands of bureau employees' personal data. Reuters sources say the incident stemmed from a third-party platform security failure where a contractor failed to apply an explicit patch. The FBI cited mitigation steps and removal of the contractor, while Accenture affirmed continued support for the FBI mission. Reports indicate the exploited platform was Oracle PeopleSoft and the attack leveraged a CVE-2026-35273 bypass.
read more →

Denmark: Massive CPR Register Access Exposes Millions

🔒 Unauthorized parties accessed names, addresses, and personal identification numbers for about 8.8 million people in Denmark's Central Person Register (CPR), the digitalization ministry reported on October 5. The breach leveraged a private company's legal lookup rights and persisted for around 10 days in September before unusual activity was detected. The register's administration has suspended the company's access, reported the incident to Datatilsynet, and police are investigating. Authorities urge vigilance against phishing, recommend credit warnings, and have launched a security review while Datatilsynet examines responsibility and impact.
read more →

Enterprises face uncertainty after PeopleSoft breach claims

🛡️ The theft of FBI employee data tied to ShinyHunters and the shutdown of the FBI’s PeopleSoft jobs portal has raised alarm among enterprise users of PeopleSoft. Law enforcement has made arrests, but neither the FBI nor Oracle has clarified whether a new PeopleSoft zero-day caused the breach. Analysts urge immediate mitigations—patches, removing exposed management interfaces, and hunting for web shells—while warning that vendor silence and unconfirmed claims leave many organizations exposed.
read more →

Active scans target Rejetto HFS critical RCE flaw

🔎 Researchers report active probes targeting CVE-2026-61500 in Rejetto HFS, a session-cookie signing weakness that can enable account takeover and remote code execution. Horizon3 linked discovery to Anthropic's Mythos model and released a PoC, prompting small-scale scans from a China Telecom IP. Administrators are urged to upgrade to Rejetto HFS 3.2.1 or preferably 3.3.4 to mitigate exploitation.
read more →

Denmark CPR breach exposes records of 8.8M people

🔒 The Danish Central Population Register (CPR) disclosed a data breach that exposed personal information for approximately 8.8 million registered individuals, including residents, expatriates, and deceased persons. Threat actors abused a private company's legitimate access and used brute-force enumeration of CPR numbers to extract names, addresses, dates of birth, marital status, and CPR identification numbers. The breach occurred in September 2026, was discovered on October 2, and affected about 80% of records held in the CPR system. Authorities have blocked the third party's access, launched a police investigation, and enacted extra security measures while urging citizens to remain vigilant.
read more →

ClingSTUN backdoor exploits unpatched IoT flaws

🔍 FortiGuard Labs has identified a Linux proxy backdoor named ClingSTUN that leverages unpatched internet-facing IoT vulnerabilities to turn devices into remotely controlled proxy nodes. The malware abuses legitimate public STUN servers to keep NAT bindings open and blend its traffic with normal VoIP/WebRTC communications. Operators deployed the campaign in three waves, expanding exploited vulnerabilities to at least 24 CVEs and adding hard-coded exploits to aid propagation. FortiGuard urges device inventory, prioritised patching and compensating controls where updates are unavailable.
read more →

South Korea probes bank breaches amid AI suspicions

🔎 South Korea's Financial Services Commission convened an emergency meeting after a string of cyberattacks affected major banks, including Shinhan Bank, KB Kookmin Bank, and Hana Bank. Authorities confirmed data leaks — reportedly affecting tens of thousands of customers — and launched on-site investigations while coordinating with KISA and other agencies. Financial firms were ordered to inspect externally accessible systems, tighten access controls, share threat intelligence, and submit security inspection results promptly.
read more →

Weekly Recap: NetScaler, FortiMail, and Major Threats

📰 This week’s recap highlights multiple actively exploited vulnerabilities, high-profile arrests, and evolving malware techniques that take advantage of small oversights. Notable items include Citrix NetScaler and FortiMail zero-days, arrests tied to ShinyHunters and KillSec operations, and novel attack methods like RedFlick delivering the CosmicPulse backdoor. The report stresses urgent patching and improved basic hygiene to reduce exposure.
read more →

Alleged Ploutus ATM Malware Author Appears in Court

🔒 The U.S. Department of Justice says the alleged developer of Ploutus malware, accused of orchestrating ATM jackpotting that stole millions, has appeared in U.S. court following his arrest. Known as "Prometheus" or "The Engineer," 50-year-old Anibal Alexander Canelon Aguirre faces multiple federal charges tied to attacks from February 2024 to December 2025. Authorities allege the stolen funds were laundered and transferred to accounts controlled by the Tren de Aragua criminal gang, which has been designated by U.S. agencies.
read more →

Cling botnet leverages STUN to hide C2 activity

🔍 Nozomi Networks observed attackers exploiting a patched critical Realtek Jungle SDK RCE (CVE-2021-35394) starting around September 5, 2026, to deploy a botnet named Cling. The malware repurposes ordinary STUN traffic as a covert command-and-control channel, enabling propagation, proxying, tunneling and denial-of-service actions while resembling legitimate NAT-traversal activity. Samples embed multiple exploit payloads targeting routers and DVRs from various vendors and use persistence techniques like replacing wget and modifying init scripts.
read more →