LIVE · cybersecurity feed
Live wire
ASOS Hackers Hijack App Notifications, Claim Snowflake Data BreachKarina Portugal Makes the Case for Know Your AgentAlert: FortiBleed remains active campaign, can lock out users or lead to ransomware attacksCVE-2026-93836 · Ninja Forms plugin flaw exploited to hack WordPress sitesCVE-2026-86360 · Dell Urges Customers to Patch Critical DSU Flaw That Can Give Attackers Root AccessCVE-2026-21589 · Critical Atlassian Flaw Lets Unauthenticated Attackers Read Known Files Across 8 ProductsCVE-2026-88779 · Citrix NetScaler Hit by Third Actively Exploited Zero-DayClingSTUN Malware Turns IoT Devices Into Proxy NodesCVE-2026-61500 · Rejetto HFS servers now actively scanned for critical RCE flawCVE-2026-88779 · Citrix NetScaler Flaw Exploited Before CVE Publication
data breachhigh

ASOS Hackers Hijack App Notifications, Claim Snowflake Data Breach

ASOS is currently investigating a cybersecurity incident where unauthorized actors leveraged the company's official mobile application to disseminate threatening notifications to its customer base. The messages, sent directly through the app's notification system, asserted that the attackers had successfully breached Snowflake and subsequently gained access to ASOS customer data.

ZeroDay News ·

Source: HackRead

ASOS is currently investigating a cybersecurity incident where unauthorized actors leveraged the company's official mobile application to disseminate threatening notifications to its customer base. The messages, sent directly through the app's notification system, asserted that the attackers had successfully breached Snowflake and subsequently gained access to ASOS customer data.

The group claiming responsibility for the attack identified themselves as "Xuanye Group." In their notifications, they specifically stated that customer payment information remained secure and that the ASOS app itself was not compromised. However, they indicated that personal details such as names and contact information might have been exposed as a result of the alleged breach. The precise mechanism by which the attackers gained control over the app's notification system is a key focus of the ongoing investigation.

This type of incident, involving the hijacking of legitimate communication channels, typically exploits vulnerabilities in the backend systems responsible for managing and dispatching push notifications. Such flaws can range from compromised API keys or credentials to misconfigurations in notification service platforms, allowing unauthorized parties to craft and send messages appearing to originate from the legitimate entity. The claim of a Snowflake breach suggests a potential supply chain attack, where a third-party vendor's systems are compromised to indirectly impact their clients.

Snowflake, as a cloud data warehousing service, is widely used across various industries for storing and analyzing large datasets. A compromise of a client's Snowflake instance could potentially expose a wide array of sensitive customer or operational data, depending on what information the client stores within the service. Products in this category commonly implement robust access controls, encryption, and monitoring capabilities, but their security ultimately depends on how clients configure and manage their instances, including user authentication and network access policies.

The scope of impact from such an incident can be significant, extending beyond the immediate data compromise to include reputational damage and customer distrust. For customers, the primary mitigation guidance for this class of issue typically involves remaining vigilant for phishing attempts that may leverage the potentially compromised personal information. Users are generally advised to use strong, unique passwords for all online accounts and enable multi-factor authentication wherever possible.

ASOS has confirmed that it is actively investigating the claims made by the Xuanye Group. The UK's National Cyber Security Centre (NCSC) is providing assistance to ASOS in their efforts to understand the full extent of the incident and secure their systems. This collaboration with national cybersecurity authorities is a standard response for significant cyber incidents affecting critical services or large customer bases.

The incident underscores the evolving threat landscape, where attackers increasingly target not only direct corporate infrastructure but also third-party vendors and customer-facing communication channels. It highlights the critical importance of comprehensive security strategies that encompass supply chain risk management, robust application security, and continuous monitoring of all digital assets to detect and respond to unauthorized activity swiftly.

data breachmobile appnotification hijackingsnowflakexuanye group
ShareXLinkedInWhatsAppFacebook

More News

view all →
security

Anthropic reconfigures its cool kids security program

Anthropic has announced a restructuring of its cybersecurity initiatives, merging its Project Glasswing and Cyber Verification Program (CVP) into a single, tiered offering. This change, effective as of October 2026, aims to provide more security organizations with access to Anthropic's AI capabilities for system protection.

ai securityhigh

Karina Portugal Makes the Case for Know Your Agent

Karina Portugal, a Director at Prove Identity, has reportedly advocated for a new security paradigm termed "Know Your Agent" (KYA). This concept addresses the emerging challenges in verifying autonomous software agents, which traditional "Know Your Customer" (KYC) methodologies are not equipped to handle. The core argument is that existing KYC frameworks primarily focus on human user identity,…

fortinethigh

Alert: FortiBleed remains active campaign, can lock out users or lead to ransomware attacks

The FBI and Secret Service have issued a joint alert regarding "FortiBleed," a credential compromise campaign targeting Fortinet firewalls and VPN gateways. The agencies confirm that the campaign remains active and poses a significant threat, potentially leading to user lockouts and serving as an initial entry point for ransomware attacks.

CVE-2026-93836high

Ninja Forms plugin flaw exploited to hack WordPress sites

Cybersecurity researchers have identified an active exploitation campaign targeting two WordPress plugins, Ninja Forms and WPC Product Bundles for WooCommerce, leveraging stored cross-site scripting (XSS) vulnerabilities to compromise websites. The attacks, first observed on October 4 against WPC Product Bundles for WooCommerce users and then on October 5 against Ninja Forms users, involve the…

clickfix

ClickFix Attacks Evolve to Better Hide Malicious Payloads

Recent reports indicate a significant evolution in ClickFix attack methodologies, with cybercriminals now employing more sophisticated techniques to mask their malicious payloads. The updated tactics reportedly involve the use of DNS TXT records and browser cache pre-fetching, strategies designed to make the early detection of these threats considerably more difficult for security systems and…

patch

Wiretapping change sparks big privacy fight in the Golden State

California Governor Gavin Newsom has signed a bipartisan update to the state's wiretapping law, the California Invasion of Privacy Act (CIPA), which will eliminate the ability for private citizens to sue over certain internet-based surveillance. The amendment, known as SB 690, specifically targets the private right to sue websites and mobile applications for unauthorized use of "pen registers"…