< ciso
brief />
Incidents and Data Breaches Banner

All news in category “Incidents and Data Breaches”

3607 articles · page 6 of 181

Device Linking Enables Eavesdropping on Messaging Apps

🔐 Modern messaging apps permit linking a phone account to desktop clients like WhatsApp Web and Signal Desktop, and authorities are abusing this to surveil suspects. Germany’s Customs Office reportedly connects a police-controlled computer to a target’s account, receiving messages without breaking encryption. Access is obtained via physical phone access or by intercepting verification codes through phishing or telephone surveillance. The key point is that these methods rely on obtaining user consent or one-time codes, and users need clearer visibility of connected devices.
read more →

Tokyo railway operators disclose separate cyber incidents

🚆 Tokyo Metro and Keio Corporation have disclosed separate cyber incidents affecting customer data and corporate systems, respectively. Tokyo Metro confirmed unauthorized access to the email addresses of 59,000 Metpo loyalty members and has taken steps to prevent recurrence, warning of potential phishing attempts. Keio reported a ransomware attack that disrupted sales systems and prompted police investigation while ensuring train operations remain unaffected. A related breach at Times Car may have exposed personal data for up to 6.6 million individuals, raising broader transport-sector concerns.
read more →

Kiteworks Restores Customer Systems After Advisory

🔔 Kiteworks has lifted a temporary shutdown notice it issued after receiving threat intelligence from federal authorities, allowing customers to bring systems back online. Self-hosted Advanced Forms users should contact Customer Support for assistance, while Kiteworks-hosted systems are reported to be operating normally. The vendor recommended customers run the latest release, 9.5.1, and said there were no confirmed breaches. Industry observers noted this precautionary action amid speculation of a potential zero-day exploit targeting MFT platforms.
read more →

Kiteworks lifts shutdown warning after patching flaw

🔔 Kiteworks, formerly Accellion, notified customers to temporarily shut down systems after receiving an intelligence warning of an imminent cyberattack, then restored hosted systems after patching a critical vulnerability and finding no evidence of compromise. The company said the flaw affected less than 1% of customers and urged self-hosted Advanced Forms users to contact support. Continuous monitoring reportedly showed no abnormal activity, and no CVE has been assigned yet.
read more →

Dutch Police Arrest Suspect Linked to ShinyHunters

🔒 Dutch authorities confirmed the arrest of a 24-year-old Amsterdam resident in an investigation into the hacker group ShinyHunters. The suspect is due to appear before the Rotterdam District Court on September 29, 2026, after being taken into custody on September 15. Independent reporting identified the individual as Pepijn van der Stap (aka Umbreon), who previously worked in cybersecurity and was linked to earlier data thefts.
read more →

Times Car confirms breach affecting 6.6M accounts

🔒 Times Car disclosed that a cyberattack compromised approximately 6.6 million current and former user accounts after unauthorized access earlier this month. The company identified the intrusion on September 25 and blocked access on September 26 while launching a forensic investigation with external experts. Exposed data reportedly includes names, addresses, contact details, driver’s license and identity document images, account passwords, and linked service IDs, while credit card data appears unaffected.
read more →

Over 16,000 Supabase Databases Exposed by Misconfiguration

🔍 Researchers discovered more than 16,000 misconfigured Supabase databases that publicly exposed readable tables containing personally identifiable information, passwords, or authentication tokens. Analysis of around 300,000 domains showed AI-assisted development accounted for a majority of new databases, and exposures ranged from plaintext passwords to customer records and private messages. UpGuard notified affected owners and urged users to review Supabase security guidance.
read more →

NeedyMantis malware enables persistent access

🔒 Microsoft analyzed a malware family called NeedyMantis, used to maintain long-term access in targeted intrusions affecting telecoms, universities, medical nonprofits, intergovernmental organizations, and contractors. The activity dates back to at least October 2025 and was discovered while investigating the DAEMON Tools supply chain compromise. NeedyMantis operates via DLL sideloading: a legitimate program, a malicious DLL, and an encrypted archive load in sequence to unpack and run a main component that connects to a C2 over HTTPS and WebSocket. Microsoft published file hashes, domains, file paths, hunting queries, and Defender detection names to help defenders identify and remediate infections.
read more →

Bitget breach traced to third‑party security flaw

🔒 Bitget disclosed that an attacker exploited a vulnerability in a third‑party security product to obtain high‑level internal credentials and initiate fraudulent withdrawals on September 24, stealing about $388 million from its hot and warm wallets while cold wallets remained secure. The exchange isolated affected systems, revoked credentials, restricted internal access, and engaged Mandiant and SlowMist to assist its investigation. Bitget says customer balances are intact and its Protection Fund will cover losses; Bitcoin withdrawals have resumed and other assets will reopen in stages.
read more →

RatHat Android banking trojan console exposed

🛡️ Cleafy links the RatHat Android banking trojan to a web-based control console used in nearly 100 deployments since April 2026. The console stores stolen data from infected phones and can build, sign, and publish malicious apps automatically. Its latest variant uses Google's Gemini AI to estimate victims' bank balances and prioritize high-value targets. Operators gain one-click shell access via ADB and a Go-based agent that streams the screen without permission prompts on older Android versions.
read more →

JadePuffer agentic AI attacks target Azure tenants

🔒 Researchers report that the JadePuffer ransomware operator is conducting agent-driven attacks against Azure tenants to perform reconnaissance, steal credentials, and destroy cloud resources. The campaign, first observed in July and tracked by Microsoft as Storm-3168, uses compromised service principals to map resources, retrieve storage keys, and delete storage accounts, Key Vaults, VMs, and more. Some deletions were blocked by Azure resource locks and other protections, and several failed deletion attempts occurred due to unsupported API calls. Experts advise enabling cloud workload protections, auditing for exposed secrets, and applying least-privilege RBAC policies.
read more →

Dutch police arrest former hacker linked to ShinyHunters

📰 Dutch authorities arrested a 23-year-old convicted cybercriminal, identified by sources as Pepijn van der Stap, on suspicion of aiding the ShinyHunters hacking collective in data thefts and extortion. Van der Stap — previously convicted in 2023 and released in December 2025 — had presented himself as reformed while working in offensive security. Following his detention, ShinyHunters escalated attacks, claiming breaches of the FBI jobs site and extorting other groups, exploiting a PeopleSoft flaw (CVE-2026-35273). Investigations continue into ties between ShinyHunters, a rival teenage operator known as Rey, and recent large-scale data thefts.
read more →

Bitget resumes withdrawals after $387.5M breach

🔒 Bitget resumed Bitcoin withdrawals on 28 September after halting them following unauthorized transfers totaling around $387.5m from parts of its hot and warm wallet infrastructure. The exchange says the vulnerability was traced to a flaw in a third-party security product that allowed attackers to obtain high-level internal credentials and issue fraudulent withdrawal commands. Bitget reports cold wallets and user balances were not impacted, is working with Mandiant and SlowMist, and intends to restore other assets in phased stages while pursuing recovery and coordination with law enforcement.
read more →

Autonomous agents destroy Azure resources using identities

🛡️ Microsoft warns that an autonomous attacker known as Jadepuffer (Storm-3168) has expanded into Azure, using compromised service principals to enumerate resources, delete cloud assets and harvest credentials. The campaign involved two service principals splitting reconnaissance and destructive duties, with rapid automated actions that deleted storage accounts, a Key Vault, Function App and other resources. After destruction the actors requested storage account keys, raising concerns about recovery and potential future exfiltration. Microsoft urges securing workload identities, enforcing least privilege and protecting backup and recovery controls.
read more →

Weekly recap: major hacks, flaws, and service abuse

🛡️ This week’s recap highlights a string of practical, opportunistic attacks—placeholder domains turned malicious, service-account compromises, and active exploitation of Citrix NetScaler ADC and Gateway bugs. Vendors and defenders are urged to patch high-risk CVEs and review forgotten non-human identities. The incidents include a $387M crypto theft, new evasive stealer techniques, and law enforcement takedowns of phishing infrastructure.
read more →

Carbonato botnet exploits exposed Docker daemons

🔍 Cybersecurity researchers disclosed a new botnet named Carbonato that targets unauthenticated Docker daemons to deploy the open-source Hermes Agent AI framework. The malware installs the agent, overwrites its SOUL.md persona to accept Telegram commands, and uses privileged containers, reverse SSH tunnels, cron jobs and watchdogs to maintain persistence and propagate. ThreatDown traced artifacts to an exposed Docker registry and found the campaign includes other malicious operations such as trojanized crypto wallets.
read more →

Bitget resumes withdrawals after $387.5M heist

🔒 Bitget has resumed Bitcoin withdrawals after suspending them following a large theft attributed to suspected North Korean state-sponsored hackers. The exchange says it patched the exploited vulnerability and provided a staggered schedule to restore withdrawals for ETH, USDT, and other assets. Bitget emphasized user balances remain intact and that its Protection Fund covers losses while trading and deposits continue to operate. The company also launched a Recovery Bounty Program to incentivize recovery of frozen funds.
read more →

Transfer stations fuel a growing LLM proxy economy

🔒 Security researchers report a surge in proxy "transfer stations" used to hide origin of requests to frontier AI models, enabling credential abuse and model distillation. Team Cymru identified tens of thousands of relay servers running open-source platforms like CRS and sub2api that authenticate users with pooled stolen API keys and subscriptions. Activity links include China and Hong Kong, with many relays hosted on U.S. VPS providers, and evidence suggests heavy upload traffic consistent with extraction attempts. Organizations are advised to treat AI credentials as sensitive secrets, use short-lived tokens, monitor usage, and have playbooks to revoke compromised keys.
read more →

Former soldier jailed for hacking and extortion

🔒 A former U.S. Army soldier was sentenced to 70 months in prison and ordered to pay $294,978 in restitution after admitting to hacking and extorting at least 10 U.S. technology and telecommunications firms between April 2023 and December 2024. The 21-year-old, known online as kiberphant0m, stole login credentials using an SSH brute tool he helped develop and coordinated with accomplices via Telegram. Stolen data was threatened for public release on cybercrime forums and sold to facilitate SIM-swapping and other frauds, with attempted extortion demands totaling around $1 million. Two associates were tied to larger Snowflake breaches affecting hundreds of organizations and millions of individuals.
read more →

Two Unpatched Citrix NetScaler Zero-Days Exploited

🔔 Security firm watchTowr reported on September 26 that two new unpatched zero-day vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway allow remote code execution and are being actively exploited. Citrix has not confirmed the flaws or released a fix, and some administrators have taken appliances offline as a precaution. The vulnerabilities are distinct from the earlier CVE-2026-19490 authentication bypass patched on August 19.
read more →