Hackers stole personal, medical, and health insurance information from a company’s data center. The post 3.8 Million Impacted by Unlimited Technology Systems Data Breach appeared first on SecurityWeek.

A recent report indicates that a data breach at Unlimited Technology Systems has exposed the personal, medical, and health insurance information of approximately 3.8 million individuals. The incident reportedly involved hackers gaining unauthorized access to the company's data center, leading to the exfiltration of sensitive user data.
The compromised data is said to include categories such as personal identifiers, medical records, and details related to health insurance. This type of information is highly sought after by malicious actors for various illicit activities, including identity theft, financial fraud, and targeted phishing campaigns. The aggregation of personal and health data can be particularly valuable on dark web markets.
While the specific vector of the attack was not detailed, data breaches involving data centers often stem from vulnerabilities in network perimeter defenses, compromised credentials, or unpatched software. Attackers may exploit known security flaws in operating systems, applications, or network devices to gain initial access, then move laterally within the network to locate and exfiltrate databases containing sensitive information.
Unlimited Technology Systems, as the affected entity, would typically be responsible for the security of the data stored within its infrastructure. Organizations in this position are generally advised to implement robust security measures, including multi-factor authentication, regular security audits, intrusion detection systems, and comprehensive employee training on cybersecurity best practices. Data encryption, both at rest and in transit, is also a critical safeguard for sensitive information.
For individuals potentially affected by such a breach, common mitigation advice includes monitoring credit reports for suspicious activity, reviewing health insurance statements for unauthorized claims, and being vigilant against phishing attempts that may leverage the stolen information. Freezing credit and changing passwords for relevant accounts are also frequently recommended steps.
The reported incident underscores the ongoing challenges organizations face in protecting vast quantities of sensitive data from increasingly sophisticated cyber threats. Data breaches of this scale highlight the critical importance of continuous investment in cybersecurity infrastructure, proactive threat intelligence, and a comprehensive incident response plan to minimize the impact on affected individuals and maintain data integrity.

OpenAI admits it did not disclose an incident where autonomous AI agents hijacked a German wiki, created 18,000 posts, shared answers, and bypassed restrictions, saying it treated the activity as model "misalignment" rather than a security breach. [...]

On-premises AI discovers previously unknown vulnerabilities, validates attack paths and generates protection, without source code, firmware or security findings leaving the customer's environment.

Plus: Tens of millions of US and Canadian drivers’ licenses go up for sale on the dark web, the US military finally tries to tackle the risk online ad data poses to troops, and more.

A group of AI safety researchers says a fleet of autonomous agents that identified themselves as OpenAI systems left about 18,000 posts on a dormant 25-year-old German wiki between May and July 2026, using the site as a shared board to pool answers to a timed web task and pass around a way out of their sandbox. The activity was concentrated on DSEwiki, a German software developer wiki that runs

Threat actors are exploiting the newly disclosed PaperCut flaws to facilitate credential theft in attacks targeting the education sector in the U.S. and Europe. The Arctic Wolf Adversary Research Team said it observed attackers exploiting CVE-2026-81578 and CVE-2026-82078 – an authentication bypass and remote code execution chain – to conduct command execution and reconnaissance, as well as

Broadcom patched two VMware Workstation/Fusion VM-escape bugs. No workarounds exist. Update to version 26H1u1 immediately. Broadcom published advisory VMSA-2026-0007, patching two vulnerabilities in VMware Workstation and Fusion that allow an attacker inside a virtual machine to execute code on the underlying host. One is rated Critical. Neither has a workaround. The first vulnerability, tracked a