< ciso
brief />
Incidents and Data Breaches Banner

All news in category “Incidents and Data Breaches”

3607 articles · page 5 of 181

Citrix NetScaler exploitation drops web shells, steals configs

🛡️ LevelBlue observed threat actors exploiting a critical pre-auth command injection in Citrix NetScaler ADC and NetScaler Gateway to deploy web shells and exfiltrate configuration data. The activity weaponizes CVE-2026-88771 and included attacker-supplied authentication strings, payload retrieval via curl/wget, and second-stage scripts that establish reverse shells, create privileged accounts, and upload archived configs. The incidents follow recent disclosures of CVE-2026-88771 and CVE-2026-88772 amid active exploitation reports.
read more →

DIVD: Zammad zero-days enabled AI-driven breach

🔒 The Dutch Institute for Vulnerability Disclosure (DIVD) reports its network was compromised via a chain of two zero-day vulnerabilities in the open-source Zammad ticketing system. The attacker used an autonomous AI agent to perform session hijacking, remote code execution, and privilege escalation to root in seconds. DIVD, working with Merlon Security, advised users to upgrade to version 7 or take instances offline while investigations continue.
read more →

Over 543,000 Valid Credentials Exposed on GitHub

🔒 Truffle Security scanned 224 million GitHub repositories and found 543,699 unique credentials that remained valid in July, appearing across more than 1.1 million files and forks. The median exposure time for a credential was 784 days, with about 10% older than 6.3 years and some dating back to 2009. GitHub's Push Protection reduced exposures in covered categories by 53%, but many secrets (like DB strings and Google API keys) remain outside its default scope. Researchers urge immediate rotation, history cleanup, and automated expiration of secrets.
read more →

Zimbra RCE Exploited to Deploy Web Shells and Steal Mail

🛡️ Microsoft found threat actors exploiting CVE-2026-73570 in Zimbra Collaboration Suite to deploy JSP web shells, establish reverse shells, escalate privileges, and exfiltrate mailbox data. The unauthenticated command injection flaw affected systems with SNMP notifications enabled and the optional zimbra-snmp package installed, and was patched in Zimbra 10.1.20 in July 2026. Attackers used varied persistence and lateral-movement techniques, including systemd services, cron jobs, SSH identity reuse, and custom Go-based tooling to harvest credentials and export mailbox databases. Organizations are urged to patch, remove the zimbra-snmp package if necessary, restrict SNMP/SMTP access, rotate secrets, and hunt for web shells and other artifacts.
read more →

Unauthenticated command injection in Zimbra SNMP path

🔒 Microsoft Threat Intelligence tracked exploitation of CVE-2026-73570, an unauthenticated OS command-injection vulnerability in the Zimbra Collaboration Suite SNMP notification path. Exploitation occurs via specially crafted SMTP requests against internet-facing Zimbra servers with the optional zimbra-snmp package installed and SNMP notifications enabled. Observed impacts included JSP web shells, reverse shells, privilege escalation, persistent tooling, and exfiltration of email and authentication data. Activity spanned multiple regions and industries and combined automated probes with hands-on-keyboard operations.
read more →

CSuite phishing campaign escalates to account and endpoint access

🔍 ANY.RUN researchers traced a US-focused CSuite phishing campaign across hundreds of sandbox analyses, finding 51% of submissions from the United States and heavy exposure in technology, manufacturing, government, and consulting. The operation uses business-themed lures (Adobe, DocuSign, Zoom, Microsoft 365) to either harvest credentials or deliver droppers that install legitimate remote-access tools like ScreenConnect and Action1. This dual path enables mailbox takeover, financial fraud, persistent RMM access, and lateral misuse of trusted identities, expanding impact beyond typical phishing.
read more →

Pentagon personnel data breach affects millions

🛡️ The US Department of Defense confirmed a breach at the Defense Manpower Data Center (DMDC) exposing just over three million records, including Social Security numbers, names, birth dates, contact details, and some job information. Unauthorized access occurred between October 2025 and July 16, 2026, remaining undetected for nine months until a file‑sharing vulnerability was patched. The Pentagon says it has seen no evidence of misuse and is offering 12 months of identity protection and credit monitoring to those affected. The incident raises concerns about espionage, targeted spear‑phishing, and the risks posed when personnel records include job details.
read more →

Critical Citrix NetScaler DTLS Overflow Under Active Exploitation

🔒 Researchers disclosed details of a critical memory overflow in Citrix NetScaler ADC and Gateway, tracked as CVE-2026-88772 (CVSS 9.5). The flaw stems from improper DTLS fragment parsing in the NetScaler Packet Processing Engine, allowing crafted records to overflow a scratch buffer and enable remote code execution or denial-of-service. Vendor and researchers show how reassembly of many small fragments can produce a large NSB chain, enabling shellcode execution by bypassing NX protections with mprotect().
read more →

Phishing abuses RMM tools to secure persistent access

🛡️ Microsoft observed July 2026 phishing campaigns that distributed a masqueraded, digitally signed MSP360 RMM installer via diverse social-engineering lures and hosting services. The installer established persistent MSP360 services after UAC elevation and was used to silently download and install a ConnectWise ScreenConnect client as a secondary remote-access channel. Threat actors then used these legitimate administration platforms to deploy additional tooling for credential access and information collection while blending into normal IT workflows.
read more →

Custom ChatGPT variants used to push RAT malware

🔒 Researchers at Huntress found threat actors publishing malicious custom GPTs on OpenAI that steer users to a Google Sites page hosting a fake Cloudflare check and a PowerShell command. If executed, the command installs an MSI that sideloads a modified DLL to deliver a remote access trojan (RAT) with remote desktop, audio/camera capture, reconnaissance and persistence functionality. OpenAI removed one GPT by September 25, but variants persisted; the campaign leverages legitimate ChatGPT hosting to increase credibility and employs an encrypted custom archive to conceal components.
read more →

FBI urges ShinyHunters members to surrender now

🛡️ The FBI has publicly urged members of the ShinyHunters extortion group to turn themselves in after Dutch police arrested an alleged leader on September 15. Authorities found extensive data on the suspect's laptop, including details about planned murders, and the suspect remains in pre-trial detention for at least 90 days. The FBI says ShinyHunters has breached over 140 organizations and extorted at least $70 million, often targeting SSO, third-party vendors, and cloud SaaS platforms.
read more →

Ex-Air Force Members Sentenced for BEC Fraud

🔒 Two former U.S. Air Force airmen were sentenced to a combined 189 months in federal prison for conducting multi-year business email compromise (BEC) and phishing campaigns while stationed at Dover Air Force Base. They stole employee email credentials, used spoofed addresses to redirect corporate payments, and laundered funds through accomplices in the U.S. and abroad. The pair diverted millions in wire transfers and were also ordered to pay substantial restitution and serve supervised release after prison.
read more →

France tax portal breach exposed weak access controls

🛡️ A data theft at France's tax administration (DGFIP) in June–July exposed contact and tax-related messages for roughly 350,000 individuals and 250,000 businesses after attackers used stolen staff passwords. ANSSI's report finds the incident relied on weak login protection, poor network segregation and gaps in monitoring, with the attacker scraping E-Contact and other portals via compromised accounts and partner systems. Remediations include stronger MFA, extended SIEM coverage, session revocation on password resets and blocking personal-device access to government systems.
read more →

Star Blizzard uses event lures to deploy CosmicPulse backdoor

🛡️ Microsoft says Russian-linked actor Star Blizzard has used fake event invitations and replying email threads to trick targets into running a Windows backdoor installer. Campaigns since January have targeted organizations tied to Ukraine, mainly in the U.S. and U.K., using hacked WordPress and cPanel accounts and a technique called RedFlick to install the CosmicPulse backdoor via scheduled tasks.
read more →

Compromised Identity Leads to Broad DevOps and Cloud Access

🔒 Microsoft DART investigated an incident where the Storm-3068 actor turned a self-service password reset into persistent access across Azure DevOps, development pipelines, and Kubernetes. The actor used legitimate identity and cloud services to enumerate repositories, create malicious pipelines to harvest kubeconfig files, and deploy remote access tools like Atera and Chisel. DART worked with the customer to contain the intrusion, reconstruct activity from audit logs and Git history, and provide remediation guidance to reduce future identity-driven risks.
read more →

Automated AI agent breaches Dutch cybersecurity nonprofit

🔍 The Dutch Institute for Vulnerability Disclosure (DIVD) reported an autonomous, AI-driven intrusion that it described as “loud and very, very messy.” Evidence suggests a technical vulnerability was exploited to gain access, after which an automated AI agent carried out post-exploitation actions, often making obvious errors. DIVD has launched an investigation, notified authorities, and will publish further details on October 1 while working to identify and inform other potential victims.
read more →

Star Blizzard adopts RedFlick to streamline malware delivery

🛡️ Since January 2026, Microsoft observed Russian state-affiliated actor Star Blizzard refine large-scale phishing, use compromised-site accounts, and adopt a novel malware delivery technique called RedFlick. RedFlick leverages scheduled tasks to deploy the actor’s Python backdoor CosmicPulse, reducing required user interaction to a single response and improving evasion. Microsoft details observed TTPs, IOCs, mitigations, and detection guidance to help organizations defend against this evolving threat.
read more →

RatHat C2 evolves into malware-as-a-service hub

🔍 Research shows the RatHat Android banking trojan's backend evolved far more than the implant itself, with successive C2 panels that can build malware, manage infected devices and use AI to prioritize victims. Cleafy observed three panel generations and a rebrand from BlackCat to Panda Workshop between late 2025 and September 2026, with nearly 100 deployments since April 2026. Panels now support operator 2FA, phishing page builders, role-based accounts and the ability to deploy a native Go service for shell-level persistence outside app permissions.
read more →

Kiteworks fixes critical vulnerability after shutdown

🛡️ Kiteworks worked with federal intelligence authorities during a scheduled precautionary shutdown to identify and fix a critical vulnerability affecting fewer than 1% of customers. The company developed and deployed a patch and added an extra protective layer across all environments, and said there is no evidence the flaw was exploited. Customers were advised to bring systems back online after the threat window passed and no anomalies were observed.
read more →

Vietnamese Man Charged in $16M Crypto Scam

📰 A Vietnamese national was charged with money laundering for his role in a large "pig butchering" crypto fraud that defrauded a victim of about $16 million. The suspect, 37-year-old Trung Nguyen Van, was arrested in September 2024 while attempting to leave the U.S. after entering at San Ysidro. Court filings link transfers directly to Van's crypto wallet and to a broader scheme involving more than $125 million in stolen cryptocurrency. Victims were lured via online relationships and directed to fake investment platforms where they lost access to funds.
read more →