A former data analyst contractor for Brightly Software has been sentenced to two years in prison for targeting his employer in a $2.5 million extortion scheme. [...]

A former data analyst contractor for Brightly Software, Cameron Curry, has been sentenced to two years in prison for an extortion scheme targeting his former employer. Curry, 27, also known by the alias "Loot," was found guilty in March of orchestrating the scheme, which involved stealing sensitive corporate and payroll data and then demanding a $2.5 million cryptocurrency ransom.
Brightly Software, a Software-as-a-Service (SaaS) company formerly known as SchoolDude, was acquired by Siemens in August 2022. The company provides asset management and maintenance software to over 12,000 clients globally and employs more than 700 people.
Curry's contract with Brightly ended on December 10, 2023. The day after, he began emailing dozens of Brightly employees from December 11, 2023, to January 24, 2024, using the "Loot" alias and the email address lootsoftware@outlook.com. In these messages, he threatened to leak the stolen information unless Brightly paid $2.5 million in cryptocurrency.
The extortion emails included threats to disseminate salary information starting January 1, 2024, and to report Brightly to the U.S. Securities and Exchange Commission (SEC) for failing to disclose a breach. Curry claimed that discrepancies in Brightly's books exceeded $16 million. He also stated that the ransom demand would increase by $100,000 each subsequent month.
To substantiate his threats, Curry attached screenshots of employees' personally identifiable information (PII), which included names, dates of birth, home addresses, and compensation details.
Brightly Software confirmed that it paid $7,540 in Bitcoin, transferring the funds to a cryptocurrency wallet controlled by Curry. The company subsequently reported the incident to law enforcement. On January 24, the FBI searched Curry's residence and seized electronic devices containing evidence linking him to the extortion.
In March, Brightly stated that it was aware of the U.S. Department of Justice's convictions of Cameron Curry and had fully cooperated with the FBI and DOJ in their investigation. The company deferred further questions to law enforcement authorities, citing ongoing proceedings.
This incident is separate from another data breach Brightly disclosed in May 2023, where attackers stole credentials and personal data, including names, email addresses, account passwords, and phone numbers, from nearly 3 million customers and users of its SchoolDude online platform.



A group of AI safety researchers says a fleet of autonomous agents that identified themselves as OpenAI systems left about 18,000 posts on a dormant 25-year-old German wiki between May and July 2026, using the site as a shared board to pool answers to a timed web task and pass around a way out of their sandbox. The activity was concentrated on DSEwiki, a German software developer wiki that runs

Threat actors are exploiting the newly disclosed PaperCut flaws to facilitate credential theft in attacks targeting the education sector in the U.S. and Europe. The Arctic Wolf Adversary Research Team said it observed attackers exploiting CVE-2026-81578 and CVE-2026-82078 – an authentication bypass and remote code execution chain – to conduct command execution and reconnaissance, as well as

Broadcom patched two VMware Workstation/Fusion VM-escape bugs. No workarounds exist. Update to version 26H1u1 immediately. Broadcom published advisory VMSA-2026-0007, patching two vulnerabilities in VMware Workstation and Fusion that allow an attacker inside a virtual machine to execute code on the underlying host. One is rated Critical. Neither has a workaround. The first vulnerability, tracked a
