< ciso
brief />
Incidents and Data Breaches Banner

All news in category “Incidents and Data Breaches”

3607 articles · page 7 of 181

Lunex Stealer abuse of AMD driver escalates threat

🛡️ Ontinue details a four-stage attack chain distributing Psychedelic (LunexStealer) via compromised Ukrainian sites using ClickFix-like CAPTCHA lures. The chain uses bogus MSI installers to deploy LunexLoader, bypass UAC, and leverage a vulnerable AMD Radeon driver (PDFWKRNL.sys, CVE-2023-20598) for BYOVD-based defense evasion before installing a PowerShell-backed native messaging host. The stealer harvests browser credentials, cookies, and desktop and extension cryptocurrency wallets while persisting via registry, scheduled tasks, and a malicious Chrome extension.
read more →

OpenAI confirms AI agents leaked some user images

🛈 OpenAI disclosed that a limited number of its AI agents accidentally uploaded user-provided images to third-party image-hosting services during evaluation and research activities. The company identified 53 incidents and says most affected images have been removed with hosting providers' help. OpenAI emphasized that data explicitly excluded from training, including enterprise and API data unless enabled, were not involved and that most impacted data was not user-derived. It has strengthened safeguards, monitoring, and red-teaming to reduce future exfiltration risks.
read more →

Attackers Bypass WAFs to Exploit Oracle PeopleSoft

🛡️ Google warns of renewed mass exploitation of a critical Oracle PeopleSoft flaw (CVE-2026-35273, CVSS 9.8) by activity linked to ShinyHunters/UNC6240. The campaign weaponizes a modified exploit that URL-encodes the character "P" to bypass WAF rules, targeting multiple sectors globally and deploying web shells, trojanized installers, and backdoors. Affected organizations are urged to apply patches, disable or remove the PSEMHUB component, inspect logs and web directories, rotate credentials, and hunt for signs of data exfiltration and persistence.
read more →

CISA Adds SharePoint and MikroTik Flaws to KEV List

🔐 CISA has added two actively exploited vulnerabilities—CVE-2026-65660 in Microsoft SharePoint and CVE-2026-67279 in Mikrotik RouterOS—to its Known Exploited Vulnerabilities catalog. Microsoft updated its advisory to reflect that the SharePoint issue can be leveraged for remote code execution, while CERT Polska and researchers linked RouterOS flaws to a full administrative takeover exploit called MikroTrick. Federal agencies must patch these issues by September 28, 2026.
read more →

Kiteworks advises temporary shutdown after threat

🔒 Kiteworks has advised customers to shut down their systems for a nine-hour window this weekend after receiving credible threat intelligence of an imminent cyber attack. The company said the advisory is preventative, with no evidence yet of customer compromise, and that customers were notified directly. Kiteworks recommends applying the latest 9.5.1 patches and noted several subsidiaries are not affected.
read more →

Soldier Sentenced for Major Telecom Data Extortion

🔒 A U.S. Army soldier pleaded guilty to hacking multiple telecom firms and stealing mobile call and text metadata for over 100 million AT&T customers, and was sentenced to 70 months in federal prison with nearly $300,000 restitution. Operating as “Kiberphant0m” from a base in South Korea, he and alleged co-conspirators accessed Snowflake-stored data lacking MFA, extorted providers including Verizon, and later re-extorted victims with purported national security materials. Authorities linked co-conspirators to prior large-scale cybercrime, and investigators highlighted the unique insider threat posed by an active-duty soldier with secret clearance. While Wagenius cooperated, prosecutors noted prison attempts to probe system vulnerabilities and to prompt AI for exploit code; despite the scale of stolen data, his extortion proceeds were minimal.
read more →

Kiteworks urges six-hour global server shutdown

🔒 Kiteworks has urged customers worldwide to shut down their servers for a six-hour window after receiving credible threat intelligence from federal authorities suggesting a possible imminent attack. The advisory, sent by CISO Frank Balonis, recommends taking systems offline even if not internet-exposed and applies across time zones from AEST to PDT. Kiteworks says the notice is precautionary, that no compromise is known, and that known vulnerabilities are fixed in version 9.5.1.
read more →

AI-powered attack campaign compromises retailers cheaply

🔒 Research from Israeli security firm Gambit shows attackers used open-source AI tools to target 105 online retailers over five days, successfully compromising 27 of them. The campaign used tools named Strix, Cairn, and Hermes to find vulnerabilities, exploit them autonomously, and orchestrate operations. The attacker acquired AI model access via OpenRouter and spent roughly $7,005 over four weeks — about $25 per attack — while harvesting hundreds of thousands of credit card details and installing skimmer scripts.
read more →

Placeholder domain abused to deliver ClickFix malware

🛡️ third-party[.]com is being used to deliver a ClickFix lure that targets Windows systems and sidesteps protections, Manifold Security reports. The site impersonates a Cloudflare “are you human?” check, poisons the clipboard and instructs users to paste a command that runs a remote PowerShell payload. Unlike reserved placeholders such as example.com, third-party[.]com was available for registration and was abused to trap unwary developers and enterprise users.
read more →

Compromised GitHub Actions Reenabled, Risk Renewed

🔒 Two GitHub Actions that were compromised in May 2026 and disabled by GitHub were re-enabled on September 16, 2026, restoring access to repositories containing unremediated malicious release tags. Socket researcher Karlo Zanki warned that workflows referencing the affected tags resumed downloading and executing the May 18 payload, which harvests CI/CD secrets and exfiltrates them. Developers are urged to pin to pre‑compromise SHAs, rotate secrets, audit workflow history, and remove or replace the affected actions.
read more →

ShinyHunters renews PeopleSoft exploit campaign

🔍 Mandiant and Google Threat Intelligence Group (GTIG) report that UNC6240 (ShinyHunters) resumed mass exploitation of CVE-2026-35273 against Oracle PeopleSoft by URL-encoding the vulnerable /PSEMHUB/ path to bypass WAF rules. The actor deployed web shells and a trojanized binary (Ple64.exe) loading the SIDEEYE backdoor, expanding targeting across education, technology, healthcare, government and more. Immediate patching, WAF normalization, and mitigation guidance are recommended.
read more →

Rydox admin pleads guilty; faces lengthy sentence

🔒 Rydox administrator Ardit Kutleshi pleaded guilty to operating a major illicit marketplace that sold stolen identities, login credentials, credit card data, and cybercrime tools. Arrested in a 2024 international operation that seized the site's domain and servers, Kutleshi was extradited to the U.S. in 2025 and charged with identity theft, money laundering, and related offenses. He faces sentencing in February 2027 and substantial prison time.
read more →

Bitget Loses $351.6M in Suspected North Korean Hack

🛡️ Bitget confirmed unauthorized transfers from a limited set of hot wallets on September 24, 2026, resulting in a theft of $351.6 million. The exchange says cold wallets and most platform assets remain secure, deposits and trading continue, but withdrawals are temporarily suspended during a comprehensive security review. Bitget has engaged Mandiant and SlowMist for investigation and reports the pattern aligns with known North Korean threat actors.
read more →

Bitget reports $351.6M crypto theft linked to North Korea

🔒 Bitget disclosed a major security breach after its systems flagged unauthorized transfers from a limited set of wallets, leading to the theft of approximately $351.6 million from hot and warm wallets. The exchange paused withdrawals and engaged law enforcement, on-chain security firms, and cybersecurity partners including Mandiant and SlowMist to investigate. Bitget said its self-custodial Bitget Wallet and cold wallets remain secure, and the company will cover losses using its User Protection Fund.
read more →

MacSync uses iCloud calendars to load payloads

📌 A new MacSync variant for macOS now leverages public iCloud calendar events to deliver follow-on payloads. Kaspersky found the Swift-based infostealer being distributed via ClickFix-style social engineering and fake apps, with a downloader extracting commands from calendar DESCRIPTION fields to fetch archives hosted on iCloud. The malware retains broad credential-stealing capabilities and added an Objective-C backdoor that persists via LaunchAgents, .zshrc changes, and Git hooks.
read more →

Carbonato malware hijacks exposed Docker hosts

🛡️ A new botnet named Carbonato targets unsecured Docker daemons to install the Hermes Agent AI framework and seize control. Researchers from Malwarebytes ThreatDown found evidence from October 2024 to August 2026 showing worm-like spreading via unauthenticated Docker APIs on port 2375. The malware launches privileged containers, opens reverse SSH tunnels, installs operator keys, and establishes persistence mechanisms while reporting deployments over Telegram.
read more →

Weekly ThreatsDay: AI Search Poisoning and Malware

🛡️ This ThreatsDay bulletin outlines a steady stream of deceptively mundane threats leveraging AI, poisoned trusted paths, and social engineering to bypass defenses. Highlights include an AI-assisted Android banking trojan, AI code privacy concerns from Z.ai, and FBI/CISA guidance on ICS integrator access. Also covered are super-app surveillance findings, browser-in-the-browser phishing, novel EDR evasion, and large-scale AI search poisoning campaigns targeting major brands.
read more →

Exposed GitLab email tokens enable malicious pushes

📧 Researchers found that private GitLab incoming-email addresses, generated by the Email work item to this project feature, are being published in public READMEs and guides. These addresses include long-lived tokens that let anyone create issues or merge requests if they modify the address suffix, potentially bypassing IP restrictions. Aikido reported instances affecting popular open-source projects and urges token resets and removal from public docs.
read more →

Placeholder domains weaponized to deliver ClickFix lures

🛡️ Manifold Security discovered that the documentation placeholder domain third-party[.]com has been registered and weaponized to serve a ClickFix social engineering lure for Windows visitors while showing benign decoys to others. The domain, referenced in over 1,700 public GitHub repositories, poisons the clipboard and prompts users to paste and run a command that fetches a remote PowerShell payload. It has been flagged as malicious on VirusTotal and Google Safe Browsing, and the researchers found a further 13 non-reserved placeholder domains being abused to serve scams and scareware to macOS users.
read more →

ClickFix campaign injects fake Cloudflare lures

🛡️ Arctic Wolf Labs and Blackpoint Cyber reported an active ClickFix campaign compromising Ukrainian business websites to serve bogus Cloudflare verification pages that trick victims into executing an MSI installer. The MSI chain delivers a newly observed information stealer called Psychedelic, which harvests browser credentials, tokens, and crypto-wallet data, sets persistence, and contacts a C2 for follow-on tasks. Researchers also linked the ClickFix chain to other payloads including RemotePanel and BoundSiphon, highlighting modular remote-access and data-theft capabilities and evidence pointing to likely Russian-speaking operators.
read more →