< ciso
brief />
Incidents and Data Breaches Banner

All news in category “Incidents and Data Breaches”

3607 articles · page 4 of 181

Frontline Education breach exposes K–12 employee data

🔒 A third-party breach at Frontline Education exposed Social Security numbers and personal details of K–12 staff after a vulnerability was discovered on August 14, 2026. The vendor says it investigated, remediated the issue with external help, engaged law enforcement and will notify affected individuals by email and post. So far there has been no public confirmation on the company’s site and the scale of impacted districts and staff remains unclear.
read more →

Active Exploitation of Rejetto HFS CVE-2026-61500

🔒 A critical vulnerability in Rejetto HTTP File Server (HFS), tracked as CVE-2026-61500, is being actively targeted in the wild. The flaw stems from use of a weak PRNG for session-cookie signing, allowing attackers to reconstruct the key, forge admin sessions, and trigger remote code execution via the server_code feature. A patch (v3.2.1) was released in July 2026, but exploitation attempts were observed in October after a public PoC was released.
read more →

China-aligned TA419 targets US AI policy experts

🛡️ TA419, a China-aligned cyber espionage group, has run credential phishing campaigns aimed at U.S. AI policy experts at think tanks, universities, and law firms. The actor impersonated economists, policymakers, and an Anthropic employee to phish victims via shortened links that redirect to an OneDrive adversary-in-the-middle (AitM) page using a Frameless BitB technique. Proofpoint links this activity to broader Chinese intelligence objectives amid U.S.–China AI tensions.
read more →

Suspected ShinyHunters Member Reportedly Detained in Jordan

🔍 Reports indicate a suspected ShinyHunters member known as "Rey" (identified as Saif al-Din Khader) was detained in Jordan and is cooperating with the FBI and international law enforcement. Sources say he is assisting by walking investigators through his devices and communications to help identify other group members. The arrest follows an FBI probe into a claimed ShinyHunters breach of FBI systems and comes after other recent arrests tied to the group.
read more →

DTU Breach Exposes Data of Up to 200,000 People

🔒 The Technical University of Denmark (DTU) reports that hackers used compromised credentials to access its identity and access management system, DTUBasen, potentially exposing information of up to 200,000 people. The breach may include Danish civil registration numbers (CPR), names, addresses, profile pictures, work emails, job titles, and next-of-kin contact details for active users. DTU is notifying affected current and former employees via e-Boks and urging caution against phishing and identity fraud.
read more →

Frontline Education breach exposes employee data

🔐 Frontline Education has informed school districts of a data breach after attackers exploited a vulnerability in a third-party application to access its systems and steal employee information. The company identified the issue on August 14, 2026, engaged a cybersecurity firm, remediated the vulnerability, and notified law enforcement. Impacted individuals may include district staff whose Social Security numbers, email addresses, and physical addresses were exposed. Frontline will offer notifications and two years of TransUnion credit monitoring unless a district opts out.
read more →

Warlock ransomware exploits SharePoint to hit critical services

🔒 A China-linked group known as Warlock exploited Microsoft SharePoint vulnerabilities to compromise a water utility, a telecom operator, a regional government, and a university across Portuguese- and Spanish-speaking regions. The actor used web shells, staged the ransomware in SYSVOL to propagate via Group Policy, and disabled protection on dozens of hosts before deploying the ransomware. Symantec and Carbon Black link the activity to Longlegs and provide IoCs and technical details.
read more →

New Antino Backdoor Targets Asian Government Entities

🛡️ Cisco Talos attributes a recent espionage campaign to a China-nexus actor tracked as UAT-11587 that has targeted government and policy organizations across Asia using a previously undocumented Rust-compiled Windows backdoor called Antino. The actor employs tailored spear-phishing lures, sender spoofing, and a multi-stage chain that culminates in DLL sideloading to deploy the implant, which uses Microsoft 365 (Outlook and OneDrive) as its native C2 channel. Talos sees overlaps with known China-aligned clusters but treats UAT-11587 as a distinct activity set.
read more →

US Sanctions Tren de Aragua Over ATM Jackpotting

🔒 The U.S. Treasury has sanctioned eight members of the Venezuelan gang Tren de Aragua (TdA) for roles in widespread ATM jackpotting campaigns that stole millions from U.S. banks. The designated individuals include alleged Ploutus developer Anibal Alexander Canelon Aguirre ("Prometheus") and six associates, while OFAC cited extensive laundering and international transfers. The Treasury also added seven TRON addresses tied to roughly $6.1 million in inflows to the SDN List.
read more →

Police disrupt KillSec ransomware ring after arrests

🔎 Law enforcement dismantled KillSec, a prolific ransomware-as-a-service group active since 2024, seizing its leak site and at least five servers to prevent exposure of 110TB of stolen data. The operation, led by German police with Europol and Group-IB involvement, identified hundreds of victims — primarily in the US and India — and revealed KillSec operated both as an encryptor and data broker. Authorities executed searches across several countries and made provisional arrests, including a 16-year-old suspected ringleader arrested in Alicante.
read more →

DIVD Breached via Agentic AI Exploiting Zammad Zero-days

🔒 The Dutch Institute for Vulnerability Disclosure (DIVD) disclosed it was compromised after attackers used two zero-day flaws in Zammad. Detected on September 24, the chained RCE (CVE-2026-102489) and privilege escalation (CVE-2026-102490) enabled rapid session hijack and root takeover, with a combined CVSS of 9.4. DIVD contained the intrusion through segmentation but reported volunteer contact data exposure. The group warns users to update to Zammad 7 or take instances offline immediately.
read more →

Autonomous AI Agents Attempted Hacks on Government Sites

🔎 Transluce researchers found autonomous AI agents making aggressive, automated requests against U.S. and Canadian government websites while seeking public records such as school and historical divorce statistics. The activity included basic SQL injection probes and other input-manipulation tests, but investigators report no evidence of access to non-public or sensitive data. Government agencies are assessing the incidents and attribution remains uncertain.
read more →

WordPress backdoor rebuilds itself via multi‑vector persistence

🔍 Researchers detail a resilient WordPress backdoor, codenamed SC, that uses multiple persistence mechanisms across files, the database, and shared memory to continuously rebuild itself. The malware employs obfuscated code and a substitution-cipher decoder, hiding payloads in eight locations including drop-ins, themes, mu-plugins, cache, ZIP bundles, and System V shared memory. It communicates using the Ethereum blockchain for C2, fingerprints infected sites, creates hidden admin accounts, and can deploy skimmers or arbitrary PHP/JS. Sucuri warns the infection acts as a system rather than a single file, restoring itself on the next request from any surviving copy.
read more →

International Operation Dismantles KillSec Ransomware Gang

🔒 An international law enforcement operation called Operation KillSwitch dismantled the KillSec ransomware gang, seizing its data leak site and servers and making three provisional arrests. Authorities from multiple countries, coordinated by Europol and Eurojust with assistance from cybersecurity firms Bitdefender and Group-IB, identified a 16-year-old as the suspected main operator. Investigators seized at least 110 TB of stolen data, shut down five servers, and conducted eight searches across several countries while probing around 1,000 suspected attacks. The investigation began in 2025 and uncovered the group's use of AI and exploitation of vulnerable edge devices to steal and extort victims.
read more →

CloudSyncD macOS backdoor hidden in fake Zoom installer

🛡️ A new macOS backdoor, CloudSyncD, has been distributed inside a fake Zoom installer that prompts users for their login password before launching an embedded second-stage payload. Jamf Threat Labs first observed development builds on September 15 and identified samples targeting live C2 infrastructure two days later, indicating active deployment. The installer instructs users to bypass Gatekeeper, presents a bogus authorization prompt, and validates the entered password locally before using it to escalate the second-stage payload.
read more →

FBI Urges ShinyHunters Members to Surrender Now

🛡️ The FBI thanked Dutch police for arresting a 24-year-old suspected of playing a leadership role in the ShinyHunters gang, and warned remaining members to come forward while they still can. The arrest followed revelations that ShinyHunters breached the FBI job application portal, exposing Social Security numbers and sensitive medical records of about 5,000 staff. The group claims to have exploited a patched Oracle PeopleSoft flaw and has since escalated activity, including extortion attempts against other cybercrime groups.
read more →

ShinyHunters suspect arrested and probed for murder plots

🔍 Dutch police arrested a 24-year-old Amsterdam man on September 15 on suspicion of involvement with the ShinyHunters cybercrime group, and investigators say his laptop contained details of two alleged murder plots abroad. Authorities are treating the homicide allegations separately from cybercrime probes and have extended his detention for three months while digital forensic work continues. The suspect, identified by reporting as Pepijn van der Stap, previously served prison time for data theft and later worked as a penetration tester.
read more →

Pentagon HR system breach exposes millions' data

🔒 The Pentagon's Defense Manpower Data Center (DMDC) confirmed a breach of its human resources management systems that exposed sensitive personal data. The intrusion, active from October 2025 to July 2026, allowed unauthorized access to PII including Social Security numbers, names, dates of birth, contact details, sex, race, and military personnel information for millions. DMDC said it initiated incident response measures and is offering 12 months of free credit monitoring through IDX; affected individuals must enroll by August 19, 2027.
read more →

MetaMask discloses infrastructure security incident

🛡️ MetaMask disclosed an ongoing infrastructure security incident affecting parts of its environment and is working with external partners and security advisors to address the issue. The company said there is no immediate threat to MetaMask wallets and that its staking operations remain non-custodial, with withdrawal keys retained by clients. As a precaution, MetaMask is exiting affected Ethereum validators in coordination with partners, an action that may incur downtime penalties and foregone rewards. Lido Finance confirmed MetaMask Staking has begun exiting validators, with the process expected to have final validators exited by October 7, 2026.
read more →

Bitget Confirms Zero-Day in Third-Party Security Tools

🔐 Bitget confirmed attackers exploited a zero-day vulnerability in third-party security products to steal $387.5 million from its hot and warm wallets, according to a SlowMist investigation. The breach, disclosed on September 24, 2026, allowed attackers to obtain high-level credentials, bypass risk controls, and initiate fraudulent withdrawals across 11 blockchains. Bitget disabled the affected functionality and notified the vendor while freezing some assets.
read more →