A Canadian man pleaded guilty today to his role in accessing company accounts at cloud storage provider Snowflake and stealing data from at least 165 organizations in a scheme to extort millions of dollars from victims. [...]

A Canadian man has pleaded guilty to charges related to a widespread data theft scheme targeting accounts at cloud storage provider Snowflake. Connor Riley Moucka, 26, also known as Alexander Moucka and "Waifu," admitted to his involvement in accessing customer accounts and stealing data from at least 165 organizations, with the goal of extorting millions from victims. Moucka was arrested on October 30, 2024, following a series of attacks that occurred between February and October 2024.
Moucka and an alleged co-conspirator, John Erin Binns, exploited Snowflake accounts that lacked multi-factor authentication (MFA). They gained access using usernames and passwords previously compromised by infostealer malware. With MFA disabled, only valid credentials were required to log into customer accounts. Once inside, they reportedly used custom software to identify valuable information within cloud storage instances, including organization names, user roles, and IP addresses.
The stolen data, which spanned terabytes, included sensitive personal and financial information. Specific categories of data compromised were call and text history records (excluding content), banking and financial details, payroll records, Drug Enforcement Administration (DEA) registration numbers, driver's license numbers, passport numbers, Social Security numbers, and other personally identifiable information (PII).
Moucka and Binns attempted to extort numerous companies, ultimately receiving at least $2.5 million in Bitcoin from at least three victims. Moucka also sold stolen data on various hacker forums, earning at least $495,000 in fiat currency or cryptocurrency through these sales. In one instance, Moucka re-extorted a victim, threatening further disclosure of their stolen data, and reportedly used the stolen information of a government officer and immediate family members of a former government officer in this attempt.
According to the U.S. Department of Justice, victim companies incurred losses exceeding $9.5 million, and over 100 million individuals were affected by these Snowflake attacks. Moucka pleaded guilty to four counts: computer fraud, wire fraud, aggravated identity theft, and a related conspiracy. His sentencing is scheduled for October 27, and he faces a maximum sentence of 32 years in prison.
John Erin Binns, who resided in Turkey at the time of the attacks, was arrested there. While a local court approved an extradition request from U.S. prosecutors, the decision has been contested.
Among the organizations reported to be impacted by these breaches are AT&T, Ticketmaster, Santander, Pure Storage, Advance Auto Parts, Los Angeles Unified School District, QuoteWizard/LendingTree, and Neiman Marcus. In response to these incidents, Snowflake announced plans to enforce MFA protection and mandate a minimum password length of 14 characters for all accounts.

Attackers are exploiting two new PaperCut flaws to steal credentials and gain privileged access in education-sector attacks across the U.S. and Europe. Attackers are exploiting two recelty disclosed PaperCut flaws, CVE-2026-81578 and CVE-2026-82078, in attacks targeting schools and other education organizations in the U.S. and Europe, as reported by TheHackerNews. Arctic Wolf researchers observed

JetBrains is urging Cadence users to revoke and rotate all credentials following a security incident last month in which unidentified threat actors exploited a recently disclosed critical vulnerability in TeamCity to breach its own environment. "Cadence users should immediately revoke or rotate all credentials and secrets that may have been used to run their Cadence executions," JetBrains said.
A weakness has been identified in Tenda CP3 27.5.57.101. This issue affects some unknown processing of the file Net/NetCheckPing.cpp. This manipulation of the argument interface_name/host causes os command injection. The attack can be initiated remotely.
A security flaw has been discovered in Tenda CP3 27.5.57.101. This vulnerability affects the function SystemAsh of the file Apis/system.c of the component Kylin. The manipulation of the argument AlarmVoiceURL results in os command injection. It is possible to launch the attack remotely.

OpenAI has announced a $1 billion commitment to provide subsidized access to its Daybreak AI cybersecurity tools for under-resourced critical infrastructure defenders. The initiative, named Daybreak for Frontline Defenders, will offer AI models, training, and technical support over the next six months, prioritizing water and wastewater utilities, electric grid operators, and local government entities. This move aims to equip organizations with limited budgets and staff against increasingly sophisticated cyber threats.

Attackers are exploiting a new unpatched vulnerability in Magento Open Source and Adobe Commerce that lets them run malicious code on an online store's server without logging in, Dutch e-commerce security company Sansec said in an advisory published on September 5. Sansec, which discovered the flaw and named it StyleSmuggler, said attacks started on September 4. "Sansec is publishing early