< ciso
brief />
Incidents and Data Breaches Banner

All news in category “Incidents and Data Breaches

3296 articles · page 9 of 165

Amazon Links npm Supply-Chain Attacks to DPRK Actor

🔍 Amazon tied several high-profile npm supply-chain compromises to the Sapphire Sleet group, attributing trojanized packages like typo-crypto, debug, chalk, and axios to North Korea–linked hackers. The campaign began in March 2025 and escalated into 2026, leveraging social engineering of maintainers to push malicious updates that propagated automatically. Amazon reported medium confidence attribution based on shared TTPs, C2 infrastructure, and operational similarities while noting a likely financial motive and AI-enabled enhancements to attack techniques.
read more →

Ad fraud and proxy risk in generic TV streaming sticks

🛡️ Security researchers uncovered that inexpensive, off‑brand TV streaming sticks not only run residential proxy software but also impersonate mobile phones to click ads on AI‑generated sites. Bitsight TRACE researcher Pedro Falé analyzed telemetry from an expired domain tied to H96 devices and found apps linked to Zhejiang Fengwo IoT Technology that coordinate ad‑fraud campaigns. These devices switch roles between proxying traffic when in use and executing ad‑clicking jobs when idle, enabling large‑scale monetization and deceptive marketing claims.
read more →

ShinyHunters claims Brinks Home breach and data threat

🔒 Brinks Home disclosed a security intrusion identified on July 20 and activated incident response procedures while engaging leading forensics experts. The company said alarm monitoring and system functionality were not impacted. Extortion group ShinyHunters claims to have stolen millions of Salesforce records and threatened to publish the data, though BleepingComputer has not verified the claims.
read more →

Analog Devices reports system breach but operations steady

🔒 Analog Devices disclosed unauthorized access to some corporate systems discovered on June 23, 2026, and said it activated incident response procedures and engaged external cybersecurity experts. The company reported no evidence so far of leaked or fraudulently used data, informed law enforcement, and will notify affected parties and regulators. Analog Devices stated business operations remain unaffected and it does not expect a material impact on its finances; an unrelated cybersecurity matter and claims by the data extortion group ExfilSquad were also noted and are under assessment.
read more →

AiTM Phishing Now Leading Entry Point for Law Firms

🛡️ eSentire's legal sector report shows Adversary-in-the-Middle (AiTM) phishing is now the primary initial access vector for law firms, responsible for 28.57% of incidents and surpassing conventional credential theft. The firm also noted a 20% YoY rise in attacks against legal organizations, with credential and identity-focused threats comprising 56.3% of all activity. The report highlights specific services and lures—such as the Tycoon2FA platform, ClickFix fake browser-error campaigns, and Microsoft Teams abuse—and urges adoption of phishing-resistant MFA like FIDO2 and conditional access controls.
read more →

Hidden prompts let Copilot alter and copy report data

📝 Security researcher Håkon Måløy disclosed that hidden, white-on-white instructions inside a Word document can make Microsoft 365 Copilot both rewrite report figures and copy those same instructions into the finished file. Microsoft acknowledged the behavior in March and deployed mitigations, including blocking the original prompt wording and upgrading the underlying model, but Måløy showed modified payloads still worked against later model versions. The technique requires a Copilot drafting or editing operation and that the malicious document enter the model's context, and it does not rely on conventional malware or zero-click exploitation.
read more →

Russian hackers exploit Exchange OWA to hijack mailboxes

📧 A Russia-aligned group, tracked as TA488 (Void Blizzard/Laundry Bear), began a campaign on July 22 using a “half-click” exploit in Microsoft Exchange Outlook Web Access to install a browser-based backdoor when recipients viewed specially crafted emails. The attackers abused CVE-2026-42897, a cross-site scripting flaw allowing JavaScript to run inside OWA without clicking links or opening attachments. The implant, named OWAReaper, removes evidence from stored messages, harvests account data, and can leverage Outlook add-ins to obtain OAuth tokens and owner-level mailbox access, creating server-side persistence that typical endpoint-focused defenses may miss.
read more →

North Korean hackers accused of robbing state banks

🔒 North Korea's state-trained hackers, long known for stealing from foreign banks and crypto exchanges, are reported to have targeted their own country's central financial institutions. Arrests on 12 July by the National Intelligence Agency allegedly disrupted a scheme to siphon funds from the Chosun Central Bank and the Foreign Trade Bank using encrypted communication and crypto laundering. The suspects are said to be discharged veterans trained by the same military unit behind Lazarus Group, and equipment and phones were seized during raids.
read more →

Health-ISAC warns of rising ShinyHunters data theft

🔒 Health-ISAC warns healthcare and medtech organizations of an uptick in successful attacks by the extortion group ShinyHunters, which leverages supply-chain and identity attacks to breach cloud SaaS and storage platforms. Attacks commonly begin with vishing and social engineering to compromise SSO accounts (Okta, Microsoft Entra, Google), granting access to services like Salesforce, Microsoft 365, SharePoint, and others. The advisory urges hardening helpdesk and SSO procedures, adopting phishing-resistant MFA, treating SSO as Tier 0, and centralizing audit logs to detect large-scale cloud data theft.
read more →

LogoKit uses live site screenshots for phishing

🛡️ Barracuda researchers observed LogoKit phishing campaigns that build a unique login page for each victim in real time by pulling a live screenshot of the target organization’s website as the page background. The kit extracts the victim email from the URL, identifies the employer domain, and uses commercial services like Thum.io and Clearbit to assemble a convincing, per-victim page. Credential harvesting is routed via a Telegram bot, and victims are redirected to the genuine site, complicating detection and takedown.
read more →

ScreenConnect Abuse in Large-Scale Malware Campaign

🛡️ This analysis examines how threat actors abused the legitimate remote administration tool ScreenConnect in a broad malware distribution campaign. Attackers hosted convincing phishing sites that mimicked popular free utilities, bundling installers that triggered DLL sideloading to silently install ScreenConnect and deploy malicious scripts. Those scripts disabled protections, created Defender exclusions, installed AsyncRAT, and established persistence via scheduled tasks, enabling remote control and lateral movement.
read more →

Coordinated cyberattack hits 30+ Minnesota water systems

🔒 A coordinated cyberattack impacted operational technology at more than 30 Minnesota community water systems on July 26–27, prompting a statewide cybersecurity response. Several municipalities, including Braham, Plymouth, South St. Paul and Maple Plain, reported outages, communications failures or affected automated controls, with Maple Plain declaring a local emergency. Minnesota IT Services (MNIT) and federal partners are investigating, sharing intelligence and working to contain and recover systems while attribution and technical details remain under investigation.
read more →

Phishing Abuses Microsoft Trusted Login Flow

🛡️ Check Point researchers observed a widespread phishing campaign from June 25 through mid-July that impersonated Microsoft Teams notifications and directed recipients to genuine Microsoft sign-in pages. Victims were prompted to grant permissions to attacker-controlled applications, allowing abuse of the OAuth consent flow to access mail, files, Teams, SharePoint, OneDrive, and calendars. The campaign targeted roughly 120 organizations across multiple sectors and geographies before it ended.
read more →

Long-Lived Vulnerability in Microsoft Secure Boot

🔒 Microsoft’s Secure Boot contained a persistent weakness for most of its lifespan, researchers found. ESET analysts discovered 11 signed firmware images, including at least one from 2013, that were defective yet remained publicly signed. These images, known as shims, were intended to extend Secure Boot to Linux and utility software but can be abused to bypass protections via UEFI. The flaw arose because Microsoft failed to revoke the vulnerable shims after the defects were identified.
read more →

Critical Check Point Management Authentication Bypass

🔒 Rapid7 and other researchers disclosed technical details for CVE-2026-16232, a critical authentication bypass in Check Point Security Management Server and MDS. The flaw lets an unauthenticated attacker obtain an application login token and authenticate with full administrator privileges via SmartConsole. Exploitation requires network access to the Management Server and permissive Trusted Clients configuration. Check Point released Jumbo Hotfixes on July 22, 2026, and Rapid7 published a PoC for testing.
read more →

Ransomware report: VPNs targeted, AI agent observed

🔒 Ransomware activity rose year over year in June and remained elevated in Q2 2026, with VPNs and other network edge devices increasingly used as initial access vectors. Threat actors like Qilin and The Gentlemen led observed incidents, while emerging groups such as KryBit drew attention for ransomware-as-a-service operations. Researchers also documented an autonomous AI agent, JadePuffer, that completed an intrusion chain and delivered a ransom demand.
read more →

Source Code Leak Exposes Flying Eagle Android RAT

🛡️ Source code for the Flying Eagle Android RAT framework is circulating on criminal Telegram channels, with Hunt.io and researcher NetAskari tracing matching control panels and certificates to 170 internet servers. The toolkit is linked to a fake Chinese Public Security app that can capture payments, keystrokes, record screens, use cameras, and display phishing prompts for finance and government services. Chinese authorities urged removal, password changes, and reporting while investigators note the server count does not prove active infections.
read more →

Old BMC Vulnerability Exposes Data Center Management

🔒 Lava researchers found tens of thousands of internet-exposed Baseboard Management Controllers (BMCs) vulnerable to a 2013 IPMI authentication flaw, allowing rapid access by guessing weak or factory-set passwords. BMCs provide out-of-band control of servers and often sit outside standard monitoring, enabling persistent, hard-to-detect compromises that can span shared data center and AI/GPU infrastructure. Vendors including Supermicro and HPE were among the most impacted.
read more →

CubePilot suffers DNS hijack disrupting drone services

🛡️ CubePilot, an Australian drone flight-controller maker, reported a DNS hijacking on July 24 that redirected traffic to attacker-controlled infrastructure and allowed issuance of TLS certificates for all cubepilot.org subdomains. The firm regained domain control the same day, revoked the fraudulent certificates, preserved evidence, and informed authorities. Critical services including OEM portals, the community forum, and documentation remain offline while the company investigates and advises caution around credentials and recent firmware downloads.
read more →

MCBS network breach exposes over 1.26M records

🔒 Medical billing firm Medical Computer Business Services (MCBS) disclosed a 2025 network breach that exposed data for 1,261,464 individuals. The intrusion, occurring between September 22–26, 2025, potentially exposed sensitive information including Social Security numbers, dates of birth, medical histories, and insurance identifiers. MCBS identified seven covered entities whose patient records it processed and urges affected individuals to consider fraud alerts or credit freezes. The PEAR ransomware group claims responsibility and says 3.3 TB of data was exfiltrated and leaked.
read more →