Accenture has acknowledged a security incident after a threat actor advertised what they claim is stolen internal data. The attacker, using the alias "888", says they took more than 35GB of source code and cloud credentials from the consulting giant and are offering it for sale. Accenture says it has addressed the source of the issue and that its operations were not disrupted.

Accenture has confirmed it is investigating a security incident after a cybercriminal put what they describe as a large trove of the company's internal data up for sale. The consulting and technology firm said it is aware of the matter and has already dealt with its source, but it has not confirmed that any data was actually taken.
The listing appeared in early July on a cybercrime forum, where a seller using the handle "888" claimed to have breached Accenture and walked away with just over 35GB of source code. The post advertised the material to potential buyers.
The seller says the cache extends well past source code. It supposedly also contains RSA and SSH keys, Azure personal access tokens, Azure Storage access keys, and a range of configuration files. As proof, the post included screenshots, one of which appeared to show a private Azure DevOps repository, named 121123_AtriasTalentAcademy, being cloned from a redacted address hosted on Accenture's own infrastructure.
A screenshot can lend weight to a claim of repository access, but it does not establish the total volume of stolen data or verify that every file type in the listing is genuine. For now, the seller's inventory remains unproven.
Accenture has characterized the situation as an isolated issue and said it remediated the source, adding that client operations and service delivery were not affected. Beyond that, the company has left key questions unanswered: it has not confirmed how much data was taken, whether the source code and keys are authentic, whether any of the exposed credentials were still active, how the attacker gained access, or whether customer data was involved. Until those details emerge, the confirmed incident is narrower than the seller's advertisement suggests.
The nature of the claimed data is what sets this apart from an ordinary breach. A leaked list of names and emails typically fuels phishing or fraud. Source code and cloud credentials are a different category of exposure. Code can reveal how internal tools are built and how systems connect, while tokens and storage keys, if still valid, can act like keys to live environments, potentially letting an intruder reach development tools or cloud storage without having to break in a second time.
That is also why stolen engineering data can keep causing harm long after an incident is declared contained. Attackers can comb source code for vulnerabilities, test whether old credentials still work, and borrow internal naming conventions to make future phishing far more convincing. Configuration files and connection details can point them toward vendors, customers, or shared infrastructure. In other words, a single breach can become the blueprint for the next one.
Firms like Accenture are attractive precisely because of where they sit. Large consulting and services companies operate close to the systems that keep major enterprises and governments running, from cloud platforms and identity tools to codebases and transformation projects. A single foothold can offer outsized insight into how those environments are assembled and secured, even when it does not translate into direct client compromise.
The company has weathered security scares before. In 2017, researchers discovered misconfigured cloud storage buckets exposing details about an Accenture platform and its customers. In 2021, the LockBit ransomware group struck the firm and threatened to publish stolen files. And in 2024, the same "888" persona attempted to sell what was billed as data on tens of thousands of employees, a claim Accenture later said was almost entirely inaccurate.
With the scope still unverified, the practical response for organizations that depend on outside development partners is familiar: rotate any credentials that could plausibly be exposed, much like changing the locks after losing a master key, tighten and review access to source-code repositories, and watch for unusual logins or unexpected changes to build and deployment settings while the situation is assessed.
A weakness has been identified in Tenda CP3 27.5.57.101. This issue affects some unknown processing of the file Net/NetCheckPing.cpp. This manipulation of the argument interface_name/host causes os command injection. The attack can be initiated remotely.
A security flaw has been discovered in Tenda CP3 27.5.57.101. This vulnerability affects the function SystemAsh of the file Apis/system.c of the component Kylin. The manipulation of the argument AlarmVoiceURL results in os command injection. It is possible to launch the attack remotely.

OpenAI has announced a $1 billion commitment to provide subsidized access to its Daybreak AI cybersecurity tools for under-resourced critical infrastructure defenders. The initiative, named Daybreak for Frontline Defenders, will offer AI models, training, and technical support over the next six months, prioritizing water and wastewater utilities, electric grid operators, and local government entities. This move aims to equip organizations with limited budgets and staff against increasingly sophisticated cyber threats.

Attackers are exploiting a new unpatched vulnerability in Magento Open Source and Adobe Commerce that lets them run malicious code on an online store's server without logging in, Dutch e-commerce security company Sansec said in an advisory published on September 5. Sansec, which discovered the flaw and named it StyleSmuggler, said attacks started on September 4. "Sansec is publishing early
In BPF instructions that load/store a value from/to a scratch memory register the register index is an unsigned 32-bit integer and must not exceed 15, but libpcap BPF interpreter does not validate the value. In particular uncommon use cases a crafted filter program can cause the interpreter to try reading and writing the OS process memory in the 16GiB starting at the current stack frame on 64-bit architectures and in the entire address space on 32-bit architectures.

Attackers are exploiting two new PaperCut flaws to steal credentials and gain privileged access in education-sector attacks across the U.S. and Europe. Attackers are exploiting two recelty disclosed PaperCut flaws, CVE-2026-81578 and CVE-2026-82078, in attacks targeting schools and other education organizations in the U.S. and Europe, as reported by TheHackerNews. Arctic Wolf researchers observed