Employee benefits platform Paylogix has confirmed a cyberattack that occurred in the fall, during which hackers accessed its systems and stole sensitive personal and financial data. The breach, which impacted tens of thousands of individuals across multiple states, involved the theft of Social Security numbers, financial account information, health data, and more. The Akira ransomware gang has claimed responsibility for the attack, and federal law enforcement has been notified.

Paylogix, a technology company specializing in employee benefits management, has confirmed a data breach that resulted in the theft of sensitive personal, financial, and health information belonging to tens of thousands of individuals. The New York-based firm, which provides benefits administration tools to employers and insurance companies, disclosed the incident through state regulatory filings and its own public notice.
The cyberattack, which disrupted Paylogix systems, occurred in the fall, with an internal investigation pinpointing the data exfiltration period between November 13 and November 18. While Paylogix has not publicly identified the perpetrators, the Akira ransomware gang added the company to its leak site in January, claiming responsibility for the breach.
The stolen data includes a wide array of highly sensitive information: Social Security numbers, electronic signatures, financial account details, health insurance information, medical data, passport numbers, and taxpayer identification numbers. Paylogix has reported the incident to federal law enforcement and stated its cooperation with the ongoing investigation.
Paylogix acts as a third-party administrator, facilitating complex processes such as benefit deductions and payroll integration for its clients. This role grants it access to highly sensitive employee data.
While the total number of affected individuals across all states has not been publicly disclosed by Paylogix, specific figures have emerged from state regulatory filings. Reports indicate that 64,383 individuals in South Carolina, 2,304 in New Hampshire, and 1,102 in Vermont were impacted. Breach notices have also been filed in California, Massachusetts, New Jersey, and several other states.
The Akira ransomware group, which has claimed responsibility for numerous high-profile attacks, was identified by Google incident responders as the second most frequently observed malware family in 2025. By late 2025, the FBI and European law enforcement agencies estimated that Akira had amassed over $244 million in ransomware proceeds. Previous victims attributed to Akira include Stanford University, the Toronto Zoo, a South African state-owned bank, and London Capital Group.
In the wake of the breach, several law firms are reportedly organizing class-action lawsuits against Paylogix.
A weakness has been identified in Tenda CP3 27.5.57.101. This issue affects some unknown processing of the file Net/NetCheckPing.cpp. This manipulation of the argument interface_name/host causes os command injection. The attack can be initiated remotely.
A security flaw has been discovered in Tenda CP3 27.5.57.101. This vulnerability affects the function SystemAsh of the file Apis/system.c of the component Kylin. The manipulation of the argument AlarmVoiceURL results in os command injection. It is possible to launch the attack remotely.

OpenAI has announced a $1 billion commitment to provide subsidized access to its Daybreak AI cybersecurity tools for under-resourced critical infrastructure defenders. The initiative, named Daybreak for Frontline Defenders, will offer AI models, training, and technical support over the next six months, prioritizing water and wastewater utilities, electric grid operators, and local government entities. This move aims to equip organizations with limited budgets and staff against increasingly sophisticated cyber threats.

Attackers are exploiting a new unpatched vulnerability in Magento Open Source and Adobe Commerce that lets them run malicious code on an online store's server without logging in, Dutch e-commerce security company Sansec said in an advisory published on September 5. Sansec, which discovered the flaw and named it StyleSmuggler, said attacks started on September 4. "Sansec is publishing early
In BPF instructions that load/store a value from/to a scratch memory register the register index is an unsigned 32-bit integer and must not exceed 15, but libpcap BPF interpreter does not validate the value. In particular uncommon use cases a crafted filter program can cause the interpreter to try reading and writing the OS process memory in the 16GiB starting at the current stack frame on 64-bit architectures and in the entire address space on 32-bit architectures.

Attackers are exploiting two new PaperCut flaws to steal credentials and gain privileged access in education-sector attacks across the U.S. and Europe. Attackers are exploiting two recelty disclosed PaperCut flaws, CVE-2026-81578 and CVE-2026-82078, in attacks targeting schools and other education organizations in the U.S. and Europe, as reported by TheHackerNews. Arctic Wolf researchers observed