< ciso
brief />
Incidents and Data Breaches Banner

All news in category “Incidents and Data Breaches

3296 articles · page 4 of 165

CISA: Windows Task Host Flaw Now Exploited by Ransomware

🔒 CISA confirmed ransomware gangs are exploiting a high-severity Windows Task Host privilege escalation flaw, tracked as CVE-2025-60710, which Microsoft patched in November 2025. The vulnerability affects Windows 11 and Windows Server 2025 and allows local attackers with basic permissions to escalate to SYSTEM. Although Microsoft has not detailed active attacks, CISA added the flaw to its Known Exploited Vulnerabilities list and urged federal agencies to apply mitigations promptly.
read more →

SafePal order-tracking flaw exposed customer data

🔒 SafePal disclosed an authorization flaw in an order-tracking plug-in that exposed names, emails, shipping addresses, phone numbers, and purchase details for about 39,798 customers. The company said no wallet credentials or payment card data were included and that affected customers were notified on August 16. SafePal fixed the flaw, reduced retention, purged affected records from active servers, and engaged an independent firm to validate fixes and review systems.
read more →

Threat actor claims Azure employee data from firms

🛡️ A threat actor using the alias “TheHatman” is advertising employee databases allegedly exfiltrated from Microsoft Azure tenants of multiple large companies, claiming a total of 3.64 million records. The posted dumps, beginning July 31, target organizations such as McDonald’s, Tata Consultancy Services, Gap Inc., Vodafone, HCL, IHG, and Kyndryl and include names, emails, titles, phone numbers, addresses, and tenant account details. Several affected firms say investigations show no evidence of current breaches and that much of the data appears dated and non-sensitive, while cyber intelligence firm Hudson Rock assessed the samples as authentic and noted presence of service and admin accounts that could enable targeted attacks.
read more →

Pokémon Center breach exposes customer data, cancels orders

📣 Pokémon Center has notified UK and German customers that a third-party logistics provider, CEVA Logistics, suffered a cyberattack that exposed customer personal and order information. The breach affected CEVA systems between July 29 and August 1 and disrupted several European warehouses, causing shipping delays and cancellations. Pokémon Center says exposed data may include names, mailing addresses, phone numbers, email addresses, and order details, but not payment card information.
read more →

Snowflake GitHub Actions workflow injection exposed Jira token

🔒 Researchers at Wiz disclosed a GitHub Actions workflow injection in Snowflake's snowflakedb/snowflake-connector-net repo that allowed attacker-controlled issue fields to be expanded into a shell run: block, exposing JIRA_BASE_URL, JIRA_USER_EMAIL, and JIRA_API_TOKEN. The vulnerability stemmed from unsafe expression expansion in .github/workflows/jira_issue.yml and incorrect event property checks, which let a crafted public issue reach the job. Snowflake patched the workflow the same day Wiz reported it and rotated the exposed Jira token; no evidence of unauthorized access or affected releases was found.
read more →

Cavern C2 evolves, abusing DNS and Google Apps

🔍 Kaspersky researchers uncovered new components of the Cavern (CAV3RN) command-and-control framework used by Iranian-linked operators to target Israeli entities, revealing a module that switches between direct HTTPS and a Google Apps Script relay using DNS A-record responses. The modular toolkit supports extensive post-exploitation functions and minimizes forensic visibility, while additional reports show HOLLOWGRAPH abusing Microsoft 365 calendars and DNS tunneling to maintain and refresh Azure AD credentials. The findings highlight a shift to a plugin-based architecture and continued use of legitimate services to evade detection.
read more →

GitHub outage confirmed — widespread service errors

⚠️ GitHub confirmed a widespread outage on August 17, 2026, reporting elevated error rates across the website, API, Actions, Pull Requests, and related services. The company observed ~20% error rates for web and API traffic, and roughly 50% errors for archive and raw repository downloads. Authentication services such as SAML and OIDC, plus SCIM and Team Sync, are affected, and GitHub Actions and Copilot reported degraded availability. The incident is under investigation and the root cause has not been disclosed.
read more →

Weekly cyber recap: exploits, ransomware, and browser attacks

⚡ This week’s roundup highlights multiple active exploit chains, supply-chain ripple effects, and opportunistic attacks that abused exposed services and old vulnerabilities. Notable incidents include exploitation of a severe VMware vCenter directory-traversal flaw linked to a suspected China-nexus APT, a macOS Screen Sharing flaw used to drop crypto miners, and a Windows privilege-escalation zero-day deployed by Lazarus. The report emphasizes how access already present and weak assumptions about visibility continue to amplify small gaps into large intrusions.
read more →

New macOS infostealer hijacks browsers for remote control

🛡️ Jamf Threat Labs uncovered a multi-stage macOS infostealer named AmnesiaStealer that uses a fake GitHub download page to trick victims into running a Terminal command which installs malware. The Rust-based loader retrieves a password-protected ZIP, deploys a universal Mach-O payload and collects passwords, Keychain items, browser data and other sensitive files. A distinct stream_module converts the victim’s Chromium browser into a remotely controlled session via WebSocket, allowing attackers to export cookies and perform browsing actions.
read more →

GE and Philips probe alleged Clop ransomware breach

🔍 General Electric and Philips are investigating claims that the Clop ransomware gang breached their systems and stole data. Philips confirmed an attempted compromise of an internal enterprise server that has been contained and said there was no impact on customer environments. GE acknowledged awareness of the claim and is assessing the potential issue. The incidents are linked to Clop’s exploitation of a PTC Windchill and FlexPLM vulnerability (CVE-2026-12569) that has prompted emergency advisories and active threat confirmations.
read more →

SafePal data breach exposes nearly 40,000 orders

🔒 SafePal reports a data breach affecting about 39,798 customers after an authorization flaw in an order-tracking plug-in was exploited to steal order information. The exposed data includes names, emails, shipping addresses, phone numbers, and purchase details for orders placed between March 2, 2025, and April 11, 2026. SafePal says sensitive wallet credentials, payment card numbers, and government IDs were not exposed and that it has fixed the vulnerability, notified affected customers, and launched a verification tool. A threat actor is now claiming to sell the stolen data on a cybercrime forum, and the company warns of targeted phishing and social engineering attempts.
read more →

AmnesiaStealer macOS malware hijacks browser sessions

🛡️ A new macOS infostealer called AmnesiaStealer uses ClickFix campaigns to deliver a Mach-O payload inside a password-protected archive. It copies Chromium profiles and launches hidden, headless browser instances to preserve authentication state while enabling remote operator control. The malware exfiltrates passwords, keychain items, crypto wallets, browser data across 16 Chromium-based browsers, and streams live screencasts and input via WebSocket channels. Researchers at Jamf warn the module abuses the Chrome DevTools Protocol to let attackers navigate and act in victims' authenticated sessions.
read more →

macOS Screen Sharing flaw exploited to install miner

🔒 The Netherlands' NCSC warns that a macOS Screen Sharing authentication bypass (CVE-2026-65400) is being actively exploited after public exploit code appeared. The flaw affects the built-in VNC-based Screen Sharing service (TCP 5900) and allows network attackers to authenticate without valid credentials. Apple fixed the issue in macOS Tahoe 26.6.1, Sequoia 15.7.9 and Sonoma 14.8.9; affected users should update or disable Screen Sharing in System Settings.
read more →

ExfilSquad leaks data from 13 organizations

🔍 New analysis links the ExfilSquad extortion group to leaked data from 13 victims across government, education, finance and manufacturing. Fortra Intelligence and Research Experts (FIRE) validated that public samples contained sensitive information, with published torrents totaling 382.64 GB and 27 million records. Researchers say misconfigured Microsoft Power Pages and unauthorized read access to Microsoft D365/Dataverse exports appear to be the primary cause, not a D365 vulnerability. FIRE identified numerous exposed Power Pages instances and highlighted the risk of the Anonymous Users web role.
read more →

Shell Probes Possible Data Theft After Clop Claims

🔎 Shell is investigating a potential security incident after the Clop ransomware gang claimed to have stolen 89GB of data, including engineering drawings and project plans. A Shell spokesperson confirmed awareness and said security teams and external experts are examining the matter. Clop listed Shell among 43 victims allegedly targeted via a PTC Windchill and FlexPLM vulnerability tracked as CVE-2026-12569. PTC, CISA, and other authorities have warned of active exploitation and urged urgent patching and mitigations.
read more →

RingCentral Breach Exposes Millions of Account Records

🔒 In July 2026, the ShinyHunters extortion group claimed to have stolen personal data from RingCentral accounts after a reported social engineering intrusion. RingCentral acknowledged a security incident and said remediation steps were taken, noting services continued to operate and only a portion of customers were affected. Have I Been Pwned confirmed leaked data tied to 1.6 million accounts, including names, emails, phone numbers, and addresses.
read more →

New macOS infostealer spreads via ClickFix lure

🛡️ Researchers at Jamf warn of a Rust-based macOS infostealer named AmnesiaStealer distributed through ClickFix social engineering. The malware harvests credentials, browser data and live sessions, uses OS version–specific bypasses, and includes a remote-controlled second stage to stealthily control Chromium-family browsers. Jamf recommends enabling threat prevention, advanced threat controls and web protection set to Block and Report.
read more →

Apple Alerts Users of Mercenary Spyware in 110 Countries

🔔 Apple has sent fresh threat notifications to an unspecified number of customers it suspects were targeted by mercenary spyware in 110 countries, adding to over 150 countries notified since late 2021. The company characterizes these as high-confidence alerts for individuals likely singled out due to their roles, such as journalists, activists, politicians, and diplomats. Apple declined to attribute the attacks to specific actors and cautioned that sharing diagnostic details could help attackers refine tactics. It provides notifications via iPhone alerts, email from "threat-notifications@email.apple[.]com," and a banner on the user's Apple Account page, and recommends security steps including updating software, enabling 2FA, and using Lockdown Mode.
read more →

Data analyst jailed for $2.5M extortion scheme

🛡️ A former Brightly Software contractor was sentenced to two years in prison after pleading guilty to orchestrating a $2.5 million extortion scheme. He stole payroll and corporate data, emailed employees threatening to leak PII, and demanded ransom in cryptocurrency after his contract ended. Brightly paid a small Bitcoin ransom before involving law enforcement; the FBI recovered devices linking the suspect to the crimes.
read more →

Apple issues new threat notifications over spyware

🔔 Apple sent a fresh batch of threat notifications on August 13 alerting select iPhone users to suspected mercenary spyware attacks. These high-confidence alerts, issued since 2021, target a small set of users such as journalists and activists and do not name specific spyware or attribution. Apple warns users to verify genuine messages via account.apple.com and avoid links or requests for credentials, recommending Lockdown Mode and expert help if affected.
read more →