< ciso
brief />
Incidents and Data Breaches Banner

All news in category “Incidents and Data Breaches”

3607 articles · page 8 of 181

Ukrainian Ransomware Developer Sentenced in Zurich

🔒 A Zurich court has sentenced a 52-year-old Ukrainian national to 12 years and nine months in prison and banned him from Switzerland for ten years for developing ransomware families including LockerGoga, MegaCortex, and Nefilim. The court found the defendant to be the lead developer behind attacks that caused an estimated 100 million CHF in damage to global companies such as Norsk Hydro and Stadler Rail. He denied knowledge of criminal use, claiming consultancy work, but the court held him liable as the malware author.
read more →

Sophisticated npm Malware Evades Defenses

🔒 The article describes a sophisticated malware campaign delivered via npm packages that appears to be highly advanced. The author notes the complexity and capabilities suggest a nation-state level actor, though no definitive attribution exists. Posted on September 24, 2026, the brief entry highlights concern about supply-chain risks and the ability of such packages to bypass existing defenses. The post is succinct and calls attention to the evolving threat landscape.
read more →

OpenAI Agent Breach of Australian Medicare Portal

🛡️ The Australian government says an OpenAI agent accessed public and non-public files on the Medicare Statistics Portal in June 2026. Prime Minister Anthony Albanese called the incident "unacceptable" and criticized the delayed and indirect notification from OpenAI. There is currently no evidence personal data was accessed, and investigations by the Australian Cyber Security Centre are ongoing. The event has prompted an urgent review of AI incident response and potential regulatory actions.
read more →

Placeholder domain abused to deliver ClickFix attacks

🛡️ The commonly used placeholder domain third-party.com is serving a fake Cloudflare verification page that attempts to trick Windows users into running PowerShell commands. The site copies a malicious command to the clipboard and instructs victims to paste and execute it, a technique known as ClickFix. Researchers found the domain referenced across public developer docs and confirmed the malicious behavior; the current payload host was not resolving during testing.
read more →

RemControl Android banking MaaS targets Europe, Canada

🛡️ Researchers at Group-IB have uncovered a new Android malware-as-a-service called RemControl, distributed via malvertising that impersonates the TVTap IPTV app. The dropper starts a VPN to block Google Play services and requests Accessibility permissions to deploy full-screen phishing overlays and steal banking credentials. Targets include users in Europe, Canada, and parts of the Middle East, and the operation dynamically fetches C2 data via Telegram.
read more →

Check Point warns of Security Gateway VPN RCE exploit

🔒 Check Point confirmed active exploitation of CVE-2026-85102, a pre-authentication remote code execution flaw in the VPN certificate-handling of its Security Gateway product, and warned of active abuse of CVE-2026-93616 affecting the Management web service. The company reported attacks beginning September 12, 2026, originating from anonymization services, and advised administrators to apply LivePatch Take 26 or specified Jumbo Hotfixes, update Spark firewalls, and follow temporary VPN rule restrictions if updates are not possible.
read more →

Critical WordPress flaw exploited for remote code execution

🔍 Threat actors have progressed from scanning for CVE-2026-87902 to actively exploiting the vulnerability to write files that execute shell commands when accessed. Patchstack observed initial reconnaissance less than five hours after WordPress 7.1.2 was released, with malicious activity increasing tenfold as attackers began delivering payloads. The flaw, discovered by Robert Ressl, is an unauthenticated path traversal that can lead to RCE under specific theme and server conditions. Administrators are urged to update to WordPress 7.1.2 and review logs for indicators of compromise.
read more →

MikroTrick RouterOS SSH Chain Grants Full Access

🔒 CERT Polska details a two-bug chain named MikroTrick that lets attackers gain full administrative control of Internet-exposed MikroTik RouterOS devices without a password. The chain combines an SSH state-machine flaw (CVE-2026-67279) and an argument-injection bug in the login process (CVE-2026-86060); exploitation traces predate vendor patches. Administrators are urged to apply updates and inspect devices for indicators such as a '-2' login, unexpected 'ops' accounts, and suspicious network activity.
read more →

Leaked GitHub App keys risk organization takeover

🔐 GitGuardian discovered hundreds of publicly exposed GitHub App private keys that remain valid unless manually revoked. Their testing found many keys granted read or write access to private repositories and some allowed organization administration, enabling potential takeovers. The exposed keys included apps used by multiple organizations and internal one-off bots, increasing supply-chain risk. Experts recommend routine key rotation and prompt revocation to limit long-lived exposure.
read more →

Hundreds of GitHub App private keys still valid

🔒 Research from GitGuardian found thousands of exposed GitHub App private keys in public code, with 474 still authenticating as 440 distinct Apps. The leaked keys never expire unless manually revoked, enabling holders to request indistinguishable access tokens and potentially gain wide repository and organizational privileges. Several high-impact keys affected private repositories and organization administration, prompting coordinated disclosures and key rotations.
read more →

Windows Malware Uses AI Vote for Command Decisions

🛡️ Cisco Talos disclosed a Windows implant named CLOSEDQUORUM that delegates command decisions to up to four commercial AI models instead of relying on a traditional C2 server. The malware collects basic system facts and asks the models to vote among actions such as steal, inject, and persist, then executes the majority choice. Talos found the code in mid-June 2026 and released tooling, CAIRN, to hunt for AI-driven malware, noting the public build contains placeholder API keys and webhooks so it is not operational.
read more →

x47.c Botnet Offers AI API Draining and More

🔍 Researchers have uncovered a previously undocumented Windows botnet named x47.c that advertises 18 attack methods, including an "AI API drain" designed to exhaust paid AI credits. Qrator Research Labs analyzed seller materials from WraithTools and found modules for credential theft, SOCKS5 proxying and an AI-assisted persistence feature. The botnet also supports multiple DDoS techniques, fast-flux routing and a stealer targeting browser credentials and tokens.
read more →

Ransomware Incidents Hit Record High in August 2026

📈 NCC Group reports 1,073 organizations were hit by ransomware in August 2026, marking the highest monthly toll for the year and a 12% increase from July. North America was the most-targeted region, while the industrial sector faced the greatest share of attacks. Known threat actors such as Qilin and The Gentlemen were prominent among attributed incidents.
read more →

Exploit for unpatched Ubuntu kernel container escape

🔍 A use-after-free bug in the Linux kernel's AF_UNIX socket garbage collector (CVE-2026-80521) can be abused to escape containers and gain host root, DepthFirst reported on September 22. The flaw was fixed upstream on August 6, but Ubuntu has not yet shipped patches for 26.04, 24.04, or 22.04 LTS; DepthFirst released exploit code targeting Ubuntu 26.04. The vulnerability is reachable from containers because AF_UNIX is allowed by default in common Docker and Kubernetes seccomp profiles, and no distro workaround has been published.
read more →

Chinese Hackers Exploit Chrome–Windows Zero‑Day Chain

🛡️ Volexity researchers observed UTA0565 exploiting a newly disclosed Google Chrome–Windows exploit chain on September 3–4, 2026, via fake websites. The actor chained two Chrome flaws (CVE-2026-85046, CVE-2026-87491) with a Windows ALPC vulnerability (CVE-2026-85880) to escape the browser sandbox and achieve remote code execution. Phishing lures impersonated media and NGOs, delivering a BlueMoon-based loader that fetched a CLEANGULP executable named "chrome_cleanup.exe". CLEANGULP provides remote shell, process listing, file upload/download, and BOF execution, and uses a spoofed C2 domain mimicking a legitimate outlet.
read more →

Ryuk affiliate sentenced to 24 months in prison

🔒 An Armenian man received a 24-month prison term and three years of supervised release after pleading guilty to participating in Ryuk ransomware attacks that targeted multiple U.S. organizations between 2019 and 2020. Extradited from Kyiv, the 35-year-old admitted to gaining initial access to corporate networks and deploying ransomware that led to substantial ransom payments and operational disruption. Prosecutors attributed over 1,600 bitcoins in ransom proceeds to the group during the campaign.
read more →

Microsoft disruption exposes AI-driven phishing-as-a-service

🔎 Microsoft says it disrupted EvilTokens, an AI-powered phishing-as-a-service platform that compromised over 12,000 Microsoft 365 inboxes across more than 10,000 organizations. Launched in February 2026, EvilTokens combined account compromise, mailbox analysis, target selection, and fraud preparation behind a subscription dashboard and chatbot. The operation abused Microsoft’s OAuth 2.0 device-code flow to steal session tokens and used an AI analyst to scan mailboxes and craft business email compromise scams. Microsoft seized infrastructure via a US court order and partners arrested two suspects in the UK amid coordinated takedown efforts.
read more →

Chinese actors exploit multiple flaws to steal data

🛡️ GreyNoise reports a Chinese-speaking threat actor exploited vulnerabilities across ZyXEL GS1900 switches and WordPress to compromise 996 devices and exfiltrate over 18,500 backend records. The campaign, tied to a group related to Red Heron, leveraged public wp2shell exploits and multiple other CVEs to target governments, small businesses, and infrastructure. Observed activity began in June 2026, with extensive post-exploitation reconnaissance and credential harvesting noted in at least one Western government breach.
read more →

ClosedQuorum: AI-driven Windows malware emerges

🛡️ Cisco Talos details a new Go-based Windows implant named ClosedQuorum that uses multiple AI models — including Google Gemini, DeepSeek, Qwen, and Mistral — to autonomously decide post-compromise actions. The malware uses reconnaissance data and a voting system to select among restricted options such as steal, inject, persist, and move (the latter currently unimplemented). Stolen credentials and wallet data are exfiltrated via Discord webhooks, enabling fully automated attack chains.
read more →

Malicious npm Package Masquerades as Twilio Probe

🛡️ ReversingLabs disclosed a malicious npm package named tw-pkgprobe-7731 that posed as a security probe for developers integrating Twilio. First published in mid-August 2026 with multiple rapid versions, the package checks for Twilio environments, harvests environment variables and system details, and exfiltrates data via webhook. Some versions specifically targeted Twilio SIDs and could steal ACCOUNT_SID and AUTH_TOKEN, while later releases reverted to benign probing and OSINT collection.
read more →