< ciso
brief />
Incidents and Data Breaches Banner

All news in category “Incidents and Data Breaches

3300 articles · page 52 of 165

BKA Identifies REvil Leaders Behind 130 Attacks in Germany

🕵️ Germany's Federal Criminal Police Office (BKA) has named the alleged primary operators of the REvil (aka Sodinokibi) ransomware ring as Daniil Maksimovich Shchukin and Anatoly Sergeevitsch Kravchuk. Shchukin, widely known by aliases including UNKN and Oneiilk2, is accused of acting as a group leader while Kravchuk is alleged to have served as a developer. The BKA links the two to 130 attacks in Germany, €1.9 million in paid ransoms across 25 cases, and total losses exceeding €35.4 million, situating the announcement within earlier international actions that disrupted REvil.
read more →

Germany Identifies 'UNKN' as Head of REvil and GandCrab

🔍 German authorities have identified 31‑year‑old Daniil Maksimovich Shchukin as the hacker known as 'UNKN', alleging he led the GandCrab and REvil ransomware operations. The Bundeskriminalamt says Shchukin and an associate extorted nearly €2 million in roughly two dozen attacks between 2019 and 2021, causing over €35 million in damage. Investigators cite cryptocurrency traces, forum links and a mugshot match; he is believed to be abroad, likely in Russia.
read more →

Traffic violation phishing texts switch to QR codes

🚨 Scammers are sending fake "Notice of Default" traffic violation texts impersonating state courts and urging recipients to scan an embedded QR code to pay a $6.99 balance. Scanning the code leads to an intermediary site with a CAPTCHA, then redirects to phishing pages posing as state DMVs that harvest personal and credit card data. These campaigns have targeted multiple states; ignore unexpected payment texts and never provide payment details to unknown senders.
read more →

Drift $285M Solana Heist Linked to DPRK UNC4736 Campaign

🔍 Drift says the April 1, 2026 Solana exploit that stole $285 million was a months-long, targeted social-engineering operation attributed with medium confidence to DPRK-linked UNC4736. Attackers cultivated in-person trust at crypto conferences and via Telegram, seeded funds, and shared repositories and tools that embedded malicious code. Investigators suspect a weaponized Visual Studio Code project and an Apple TestFlight wallet were used to compromise contributors, and Drift is working with law enforcement and forensic partners to remediate.
read more →

Automated Credential Theft via React2Shell in Next.js

🔒 Cisco Talos reports attackers are exploiting React2Shell (CVE-2025-55182) in vulnerable Next.js applications to run an automated credential-harvesting campaign. The operation uses a framework called NEXUS Listener and deploys scripts into standard temporary directories to extract environment secrets, SSH keys, cloud tokens, API keys, and command histories. Researchers observed at least 766 hosts compromised across multiple cloud providers, with sensitive data exfiltrated in chunks to a C2 server over HTTP. Administrators should apply React2Shell patches, rotate exposed credentials immediately, enforce IMDSv2, enable secret scanning, and deploy WAF/RASP protections and least-privilege controls.
read more →

36 Malicious npm Packages Exploited Redis and PostgreSQL

SafeDep researchers disclosed 36 malicious npm packages masquerading as Strapi v3 plugins that execute payloads via the postinstall hook. Uploaded by four sockpuppet accounts over 13 hours, the packages weaponized Redis and PostgreSQL to deploy reverse shells, harvest credentials, and install a persistent implant targeting a hostname named prod-strapi. The postinstall script runs with the installing user's privileges, creating acute risk for CI/CD pipelines and containers. Users who installed any listed package are advised to assume compromise and rotate all credentials.
read more →

Axios npm compromise used fake Teams update to hijack

⚠️ The maintainers of Axios report a targeted social engineering attack that allowed threat actors to publish malicious npm releases (1.14.1 and 0.30.4) which added a dependency, plain-crypto-js, that deployed a remote access trojan across macOS, Windows, and Linux. The tainted packages were available for roughly three hours before removal; any systems that installed them should be treated as compromised and have credentials and keys rotated. Google links the operation to North Korea‑aligned UNC1069, while researchers say the same playbook targeted multiple high‑impact Node.js maintainers. Axios maintainers have wiped affected hosts, reset credentials, and are adding safeguards to reduce future supply chain risk.
read more →

LinkedIn's Hidden Script Scans 6,000+ Chrome Extensions

🔍 LinkedIn was found to inject hidden JavaScript that fingerprints visitors' browsers, testing for over 6,000 Chrome extensions and collecting device and system details such as CPU cores, memory, screen resolution, timezone, battery status, audio information, and storage features. Researchers say the script links extension presence to identifiable profiles; LinkedIn confirms extension detection but insists it is used to stop scraping and protect platform stability. BleepingComputer observed a randomized script file performing the checks but could not verify claims about downstream sharing or commercial use.
read more →

React2Shell exposure reveals large-scale credential theft

🔍 Researchers at Cisco Talos discovered that an apparent security lapse exposed the backend of a campaign exploiting the four-month-old React2Shell (CVE-2025-55182) Next.js flaw. A password-protected database and web application holding harvested credentials, tokens, SSH keys, and API secrets was briefly accessible, letting analysts view the attackers' dashboard. The automated campaign compromised hundreds of hosts in a single day and prompted notifications to affected providers while urging immediate patching.
read more →

Core infrastructure engineer pleads guilty in insider attack

🔒 A core infrastructure engineer, Daniel Rhyne, pleaded guilty on April 1 after launching an insider extortion attack that used routine admin tools and techniques to disable systems and accounts. He initiated unauthorized RDP sessions, deleted administrator accounts, changed passwords, and scheduled tasks on the domain controller, then claimed to have erased backups while demanding roughly $750,000 in bitcoin. Security experts say the methods were alarmingly predictable and could have been prevented by immutable backups, strict least privilege controls, and behavioral alerts for high‑risk tools.
read more →

Hims & Hers Discloses Zendesk Support Ticket Breach

🔒 Hims & Hers says support tickets were exfiltrated from its Zendesk instance after threat actors accessed a third-party customer service platform via a compromised Okta SSO account. The company reports the activity occurred Feb 4–7, 2026, was first noticed on Feb 5, and that an internal investigation concluded on March 3 that certain tickets were accessed or acquired without authorization. Potentially exposed information includes names, contact details, and other request-related data; the company states no medical records or doctor communications were affected and is offering 12 months of credit monitoring to impacted individuals.
read more →

China-linked TA416 Targets European Diplomatic Networks

🔍 A China-aligned threat cluster identified as TA416 has resumed focused operations against European government and diplomatic entities since mid-2025, according to Proofpoint. The campaign combined web bugs and malware delivery to deploy the PlugX backdoor via Azure Blob, Google Drive, compromised SharePoint, and attacker-controlled domains. Attackers repeatedly altered infection chains—abusing Cloudflare Turnstile pages, OAuth redirection through Microsoft Entra ID, and MSBuild-based C# project files with DLL side-loading—to enhance stealth and persistence. The group also expanded targeting to Middle Eastern governments following the February 2026 regional conflict.
read more →

Protecting the Software Supply Chain: 2026 Guidance

🔒 Recent weeks have seen multiple high-profile supply chain compromises, including malicious modifications to Axios and repository hijacks by TeamPCP that impacted tools such as Trivy. These incidents highlight how widely used libraries can rapidly propagate risk and complicate inventory and remediation efforts. The report emphasizes securing identity and CI/CD pipelines, maintaining accurate software inventories, prioritizing rapid patching, and reinforcing fundamentals like segmentation, robust logging, and multi-factor authentication to limit impact and lateral movement.
read more →

Axios npm Supply Chain Compromise Deploys Malicious Builds

🔐 Cisco Talos is investigating a March 31, 2026 supply chain attack that briefly replaced the official Axios npm package with two malicious releases (v1.14.1 and v0.30.4). The tainted packages were available for about three hours, and Talos strongly advises rolling back to known safe versions (v1.14.0 or v0.30.3) and auditing any systems that installed them. The injected runtime dependency executes at post-install and fetches platform-specific RAT payloads for Linux, MacOS, and Windows.
read more →

Die Linke Confirms Data Stolen by Qilin Ransomware

🔒 Die Linke, a German democratic socialist party, has confirmed that the Russian-speaking ransomware group Qilin stole data from its network and is threatening to leak it. The party stated its membership database was not impacted, but attackers sought sensitive internal documents and employee personal information. Die Linke notified German authorities, filed a criminal complaint, and retained independent IT experts to restore affected systems. Qilin added the party to its leak site on April 1 but had not published any data samples.
read more →

CERT-EU Attributes Europa.eu Breach to Trivy Supply-Chain

🔒 CERT‑EU traced the Europa.eu data theft to a supply‑chain compromise of Trivy, the open‑source vulnerability scanner, which exposed an AWS API key and led to the theft of approximately 350 GB of web data (91.7 GB compressed). The actor, publicly linked to TeamPCP, exploited a GitHub Actions misconfiguration (CVE-2026-33634) to force CI/CD pipelines to pull credential‑stealing malware via manipulated Trivy tags. Stolen material was later passed to ShinyHunters. CERT‑EU urges updating to safe Trivy releases, rotating cloud credentials, auditing CI/CD usage, and binding GitHub Actions to immutable SHA‑1 hashes.
read more →

Evolution of Ransomware: Multi-Extortion Threats Rise

🔒 Ransomware's shift to multi-extortion is producing real operational harm across healthcare, finance, and manufacturing, with widespread incidents and patient-care disruptions reported in 2025–2026. Attackers now routinely exfiltrate data before encrypting systems, making backups alone insufficient and increasing regulatory and business risk. The article highlights D.AMO from Penta Security, an integrated platform combining kernel-level folder encryption, process-based access control, and independent recovery to render stolen files unreadable, block unauthorized access, and speed restoration.
read more →

Company Secretly Records and Publishes Public Zoom Meetings

📹 WebinarTV discovers public Zoom invites, joins meetings, secretly records the streams, and posts the videos on 404 Media. It does not use Zoom’s built‑in recording feature, so Zoom’s administrative controls and recording logs cannot detect or block these captures. This behavior raises significant privacy and consent concerns for organizers and participants of publicly announced meetings.
read more →

UNC1069 Social Engineering Compromises Axios npm Package

🔒 The maintainer of Axios confirmed a supply chain compromise caused by a targeted social engineering campaign attributed to North Korean actors tracked as UNC1069. Attackers impersonated a legitimate company's founder, lured the maintainer into a branded Slack workspace and a fraudulent Teams call, then deployed a RAT to steal npm credentials. Two malicious releases (1.14.1 and 0.30.4) carried the WAVESHAPER.V2 implant.
read more →

Nigerian Romance Scammer Sentenced After Exposure in US

⚖️ Saheed Sunday Owolabi, 35, was sentenced to 15 years in a U.S. federal prison after a jury convicted him of conspiracy to commit wire fraud and money laundering. Prosecutors described how he posed as women online to cultivate romantic relationships, then persuaded victims to transfer funds and provided bank accounts used to launder proceeds—more than $1.5 million sent to Nigeria. Chat logs showing he had attempted to swindle another fraudster undermined his claim of being a mere middleman, and images recovered from his phone displayed luxury purchases made with stolen funds.
read more →