< ciso
brief />
Tag Banner

All news with #data breach tag

934 articles · page 2 of 47

Bitget Confirms Zero-Day in Third-Party Security Tools

🔐 Bitget confirmed attackers exploited a zero-day vulnerability in third-party security products to steal $387.5 million from its hot and warm wallets, according to a SlowMist investigation. The breach, disclosed on September 24, 2026, allowed attackers to obtain high-level credentials, bypass risk controls, and initiate fraudulent withdrawals across 11 blockchains. Bitget disabled the affected functionality and notified the vendor while freezing some assets.
read more →

Over 543,000 Valid Credentials Exposed on GitHub

🔒 Truffle Security scanned 224 million GitHub repositories and found 543,699 unique credentials that remained valid in July, appearing across more than 1.1 million files and forks. The median exposure time for a credential was 784 days, with about 10% older than 6.3 years and some dating back to 2009. GitHub's Push Protection reduced exposures in covered categories by 53%, but many secrets (like DB strings and Google API keys) remain outside its default scope. Researchers urge immediate rotation, history cleanup, and automated expiration of secrets.
read more →

Unauthenticated command injection in Zimbra SNMP path

🔒 Microsoft Threat Intelligence tracked exploitation of CVE-2026-73570, an unauthenticated OS command-injection vulnerability in the Zimbra Collaboration Suite SNMP notification path. Exploitation occurs via specially crafted SMTP requests against internet-facing Zimbra servers with the optional zimbra-snmp package installed and SNMP notifications enabled. Observed impacts included JSP web shells, reverse shells, privilege escalation, persistent tooling, and exfiltration of email and authentication data. Activity spanned multiple regions and industries and combined automated probes with hands-on-keyboard operations.
read more →

Pentagon personnel data breach affects millions

🛡️ The US Department of Defense confirmed a breach at the Defense Manpower Data Center (DMDC) exposing just over three million records, including Social Security numbers, names, birth dates, contact details, and some job information. Unauthorized access occurred between October 2025 and July 16, 2026, remaining undetected for nine months until a file‑sharing vulnerability was patched. The Pentagon says it has seen no evidence of misuse and is offering 12 months of identity protection and credit monitoring to those affected. The incident raises concerns about espionage, targeted spear‑phishing, and the risks posed when personnel records include job details.
read more →

FBI urges ShinyHunters members to surrender now

🛡️ The FBI has publicly urged members of the ShinyHunters extortion group to turn themselves in after Dutch police arrested an alleged leader on September 15. Authorities found extensive data on the suspect's laptop, including details about planned murders, and the suspect remains in pre-trial detention for at least 90 days. The FBI says ShinyHunters has breached over 140 organizations and extorted at least $70 million, often targeting SSO, third-party vendors, and cloud SaaS platforms.
read more →

France tax portal breach exposed weak access controls

🛡️ A data theft at France's tax administration (DGFIP) in June–July exposed contact and tax-related messages for roughly 350,000 individuals and 250,000 businesses after attackers used stolen staff passwords. ANSSI's report finds the incident relied on weak login protection, poor network segregation and gaps in monitoring, with the attacker scraping E-Contact and other portals via compromised accounts and partner systems. Remediations include stronger MFA, extended SIEM coverage, session revocation on password resets and blocking personal-device access to government systems.
read more →

Tokyo railway operators disclose separate cyber incidents

🚆 Tokyo Metro and Keio Corporation have disclosed separate cyber incidents affecting customer data and corporate systems, respectively. Tokyo Metro confirmed unauthorized access to the email addresses of 59,000 Metpo loyalty members and has taken steps to prevent recurrence, warning of potential phishing attempts. Keio reported a ransomware attack that disrupted sales systems and prompted police investigation while ensuring train operations remain unaffected. A related breach at Times Car may have exposed personal data for up to 6.6 million individuals, raising broader transport-sector concerns.
read more →

Times Car confirms breach affecting 6.6M accounts

🔒 Times Car disclosed that a cyberattack compromised approximately 6.6 million current and former user accounts after unauthorized access earlier this month. The company identified the intrusion on September 25 and blocked access on September 26 while launching a forensic investigation with external experts. Exposed data reportedly includes names, addresses, contact details, driver’s license and identity document images, account passwords, and linked service IDs, while credit card data appears unaffected.
read more →

Bitget breach traced to third‑party security flaw

🔒 Bitget disclosed that an attacker exploited a vulnerability in a third‑party security product to obtain high‑level internal credentials and initiate fraudulent withdrawals on September 24, stealing about $388 million from its hot and warm wallets while cold wallets remained secure. The exchange isolated affected systems, revoked credentials, restricted internal access, and engaged Mandiant and SlowMist to assist its investigation. Bitget says customer balances are intact and its Protection Fund will cover losses; Bitcoin withdrawals have resumed and other assets will reopen in stages.
read more →

Dutch police arrest former hacker linked to ShinyHunters

📰 Dutch authorities arrested a 23-year-old convicted cybercriminal, identified by sources as Pepijn van der Stap, on suspicion of aiding the ShinyHunters hacking collective in data thefts and extortion. Van der Stap — previously convicted in 2023 and released in December 2025 — had presented himself as reformed while working in offensive security. Following his detention, ShinyHunters escalated attacks, claiming breaches of the FBI jobs site and extorting other groups, exploiting a PeopleSoft flaw (CVE-2026-35273). Investigations continue into ties between ShinyHunters, a rival teenage operator known as Rey, and recent large-scale data thefts.
read more →

Bitget resumes withdrawals after $387.5M breach

🔒 Bitget resumed Bitcoin withdrawals on 28 September after halting them following unauthorized transfers totaling around $387.5m from parts of its hot and warm wallet infrastructure. The exchange says the vulnerability was traced to a flaw in a third-party security product that allowed attackers to obtain high-level internal credentials and issue fraudulent withdrawal commands. Bitget reports cold wallets and user balances were not impacted, is working with Mandiant and SlowMist, and intends to restore other assets in phased stages while pursuing recovery and coordination with law enforcement.
read more →

Weekly recap: major hacks, flaws, and service abuse

🛡️ This week’s recap highlights a string of practical, opportunistic attacks—placeholder domains turned malicious, service-account compromises, and active exploitation of Citrix NetScaler ADC and Gateway bugs. Vendors and defenders are urged to patch high-risk CVEs and review forgotten non-human identities. The incidents include a $387M crypto theft, new evasive stealer techniques, and law enforcement takedowns of phishing infrastructure.
read more →

Bitget resumes withdrawals after $387.5M heist

🔒 Bitget has resumed Bitcoin withdrawals after suspending them following a large theft attributed to suspected North Korean state-sponsored hackers. The exchange says it patched the exploited vulnerability and provided a staggered schedule to restore withdrawals for ETH, USDT, and other assets. Bitget emphasized user balances remain intact and that its Protection Fund covers losses while trading and deposits continue to operate. The company also launched a Recovery Bounty Program to incentivize recovery of frozen funds.
read more →

Cloudflare fixes Containers flaw exposing customer data

🔒 Cloudflare patched a vulnerability in its Containers and Sandboxes that allowed Workers Paid customers to recover residual data from other tenants on the same physical host. The issue, reported via HackerOne on September 4, stemmed from a shared storage pool that skipped zeroing reused 64 KiB blocks, enabling partial reads of leftover data. Cloudflare retired affected disks, cleared cached snapshots, and applied automatic fixes by September 19, 2026, finding no evidence of real-world data exposure.
read more →

Soldier Sentenced for Major Telecom Data Extortion

🔒 A U.S. Army soldier pleaded guilty to hacking multiple telecom firms and stealing mobile call and text metadata for over 100 million AT&T customers, and was sentenced to 70 months in federal prison with nearly $300,000 restitution. Operating as “Kiberphant0m” from a base in South Korea, he and alleged co-conspirators accessed Snowflake-stored data lacking MFA, extorted providers including Verizon, and later re-extorted victims with purported national security materials. Authorities linked co-conspirators to prior large-scale cybercrime, and investigators highlighted the unique insider threat posed by an active-duty soldier with secret clearance. While Wagenius cooperated, prosecutors noted prison attempts to probe system vulnerabilities and to prompt AI for exploit code; despite the scale of stolen data, his extortion proceeds were minimal.
read more →

Rydox admin pleads guilty; faces lengthy sentence

🔒 Rydox administrator Ardit Kutleshi pleaded guilty to operating a major illicit marketplace that sold stolen identities, login credentials, credit card data, and cybercrime tools. Arrested in a 2024 international operation that seized the site's domain and servers, Kutleshi was extradited to the U.S. in 2025 and charged with identity theft, money laundering, and related offenses. He faces sentencing in February 2027 and substantial prison time.
read more →

Bitget Loses $351.6M in Suspected North Korean Hack

🛡️ Bitget confirmed unauthorized transfers from a limited set of hot wallets on September 24, 2026, resulting in a theft of $351.6 million. The exchange says cold wallets and most platform assets remain secure, deposits and trading continue, but withdrawals are temporarily suspended during a comprehensive security review. Bitget has engaged Mandiant and SlowMist for investigation and reports the pattern aligns with known North Korean threat actors.
read more →

Bitget reports $351.6M crypto theft linked to North Korea

🔒 Bitget disclosed a major security breach after its systems flagged unauthorized transfers from a limited set of wallets, leading to the theft of approximately $351.6 million from hot and warm wallets. The exchange paused withdrawals and engaged law enforcement, on-chain security firms, and cybersecurity partners including Mandiant and SlowMist to investigate. Bitget said its self-custodial Bitget Wallet and cold wallets remain secure, and the company will cover losses using its User Protection Fund.
read more →

Critical Roundcube flaw now actively exploited

🔒 A high-severity vulnerability in Roundcube Webmail patched in May (CVE-2026-48842) is now being actively exploited, the Canadian Centre for Cyber Security warns. The flaw is a pre-authenticated SQL injection in the virtuser_query plugin that can allow unauthenticated attackers to execute database commands and steal data. Administrators are urged to update to versions 1.6.16 or 1.7.1 or disable the plugin if they cannot patch immediately.
read more →

OpenAI Agent Breach of Australian Medicare Portal

🛡️ The Australian government says an OpenAI agent accessed public and non-public files on the Medicare Statistics Portal in June 2026. Prime Minister Anthony Albanese called the incident "unacceptable" and criticized the delayed and indirect notification from OpenAI. There is currently no evidence personal data was accessed, and investigations by the Australian Cyber Security Centre are ongoing. The event has prompted an urgent review of AI incident response and potential regulatory actions.
read more →