A small county government in Ohio reportedly paid a cyber extortion group one million dollars. The payment was made to prevent the public release of data stolen during a cyberattack.

A county government in Ohio has reportedly paid a $1 million ransom to a cyber extortion group. The payment was made to prevent the public disclosure of sensitive data that was stolen during a recent cyberattack.
The specific county and the identity of the cyber extortion group have not been publicly disclosed. However, the incident highlights the growing threat of ransomware attacks against local government entities and the difficult decisions they face when their data is compromised.
While the exact nature of the stolen data has not been revealed, it is common for cybercriminals to target personal information of residents, financial records, and other sensitive government documents. The threat of public release, often referred to as "doxxing," can be a powerful motivator for organizations to pay ransoms, even when it is not recommended by cybersecurity experts.
Cybersecurity best practices generally advise against paying ransoms. Law enforcement agencies and security professionals often state that paying ransoms does not guarantee the return of data or prevent its eventual release. Furthermore, such payments can fund future criminal activities and encourage further attacks.
However, the decision to pay a ransom is often a complex one for affected organizations, particularly for smaller government bodies with limited resources and potentially less robust cybersecurity defenses. The potential consequences of a data breach, including reputational damage, legal liabilities, and the impact on public trust, can be severe.
The incident in Ohio raises questions about the preparedness of local governments to defend against sophisticated cyber threats and their incident response strategies. It underscores the need for increased investment in cybersecurity infrastructure, employee training, and comprehensive data backup and recovery plans.
Many cybersecurity experts recommend that organizations focus on prevention and resilience rather than relying on ransom payments as a solution. This includes implementing strong access controls, regular security awareness training for staff, patching systems promptly, and maintaining offline, immutable backups of critical data.
The reported payment in Ohio serves as a stark reminder of the financial and operational risks associated with cyberattacks. It is likely to prompt further discussions among government officials about how to better protect sensitive information and respond to extortion demands in the future.
A weakness has been identified in Tenda CP3 27.5.57.101. This issue affects some unknown processing of the file Net/NetCheckPing.cpp. This manipulation of the argument interface_name/host causes os command injection. The attack can be initiated remotely.
A security flaw has been discovered in Tenda CP3 27.5.57.101. This vulnerability affects the function SystemAsh of the file Apis/system.c of the component Kylin. The manipulation of the argument AlarmVoiceURL results in os command injection. It is possible to launch the attack remotely.

OpenAI has announced a $1 billion commitment to provide subsidized access to its Daybreak AI cybersecurity tools for under-resourced critical infrastructure defenders. The initiative, named Daybreak for Frontline Defenders, will offer AI models, training, and technical support over the next six months, prioritizing water and wastewater utilities, electric grid operators, and local government entities. This move aims to equip organizations with limited budgets and staff against increasingly sophisticated cyber threats.

Attackers are exploiting a new unpatched vulnerability in Magento Open Source and Adobe Commerce that lets them run malicious code on an online store's server without logging in, Dutch e-commerce security company Sansec said in an advisory published on September 5. Sansec, which discovered the flaw and named it StyleSmuggler, said attacks started on September 4. "Sansec is publishing early
In BPF instructions that load/store a value from/to a scratch memory register the register index is an unsigned 32-bit integer and must not exceed 15, but libpcap BPF interpreter does not validate the value. In particular uncommon use cases a crafted filter program can cause the interpreter to try reading and writing the OS process memory in the 16GiB starting at the current stack frame on 64-bit architectures and in the entire address space on 32-bit architectures.

Attackers are exploiting two new PaperCut flaws to steal credentials and gain privileged access in education-sector attacks across the U.S. and Europe. Attackers are exploiting two recelty disclosed PaperCut flaws, CVE-2026-81578 and CVE-2026-82078, in attacks targeting schools and other education organizations in the U.S. and Europe, as reported by TheHackerNews. Arctic Wolf researchers observed