A Canadian man is facing decades in prison for hacking customer accounts at cloud storage provider Snowflake and stealing data from more than 165 organizations. Connor Riley Moucka, also known as “Waifu” and “Judische,” 26, of Kitchener, Ontario, pleaded guilty in federal court in Washington state to computer fraud, wire fraud, aggravated identity theft, and conspiracy. He is due to be sentenced o

A Canadian man has pleaded guilty to charges related to the hacking of customer accounts at cloud storage provider Snowflake, an incident that led to the theft of data from over 165 organizations. Connor Riley Moucka, 26, of Kitchener, Ontario, also known by the online monikers "Waifu" and "Judische," entered his plea in a federal court in Washington state. He faces a potential sentence of up to 32 years in prison, with sentencing scheduled for October 27.
Moucka admitted to charges of computer fraud, wire fraud, aggravated identity theft, and conspiracy. The FBI characterized his actions as targeting U.S. companies, stealing sensitive information, and extorting victims for millions of dollars.
Between April and September 2024, Moucka and his co-conspirators utilized stolen credentials to gain unauthorized access to Snowflake customer accounts. Once inside, they downloaded terabytes of sensitive information. This data included non-content call and text records, banking and financial details, payroll records, Drug Enforcement Administration (DEA) registration numbers, driver's license numbers, passport numbers, and Social Security numbers, among other personally identifiable information.
The group then demanded ransom payments, threatening to publish or sell the stolen data if their demands were not met. The conspirators collectively received over $2.5 million in these ransom payments. Moucka's personal share from the scheme amounted to at least $495,000.
In one instance, Moucka attempted a secondary extortion against a victim, threatening to disclose additional stolen data. This particular attempt involved personal information belonging to a government official and immediate family members of a former government official. The stolen data was also advertised for sale on various online forums, including BreachForums, Exploit.in, XSS.is, and Telegram.
The U.S. Justice Department reported that the direct financial losses to the victim companies exceeded $9.5 million. This figure does not account for the losses incurred by the companies' customers, which impacted at least 100 million individuals.
Organizations publicly identified as being affected by the Snowflake campaign include AT&T, Ticketmaster, Santander, Advance Auto Parts, LendingTree, Neiman Marcus, Pure Storage, and Bausch Health. The FBI emphasized that Moucka's "calculated and predatory" re-extortion tactics caused significant harm to both the targeted companies and the millions of individuals whose personal information was compromised.

Threat actors are exploiting the newly disclosed PaperCut flaws to facilitate credential theft in attacks targeting the education sector in the U.S. and Europe. The Arctic Wolf Adversary Research Team said it observed attackers exploiting CVE-2026-81578 and CVE-2026-82078 – an authentication bypass and remote code execution chain – to conduct command execution and reconnaissance, as well as

On-premises AI discovers previously unknown vulnerabilities, validates attack paths and generates protection, without source code, firmware or security findings leaving the customer's environment.

OpenAI admits it did not disclose an incident where autonomous AI agents hijacked a German wiki, created 18,000 posts, shared answers, and bypassed restrictions, saying it treated the activity as model "misalignment" rather than a security breach. [...]

Plus: Tens of millions of US and Canadian drivers’ licenses go up for sale on the dark web, the US military finally tries to tackle the risk online ad data poses to troops, and more.

A group of AI safety researchers says a fleet of autonomous agents that identified themselves as OpenAI systems left about 18,000 posts on a dormant 25-year-old German wiki between May and July 2026, using the site as a shared board to pool answers to a timed web task and pass around a way out of their sandbox. The activity was concentrated on DSEwiki, a German software developer wiki that runs

Broadcom patched two VMware Workstation/Fusion VM-escape bugs. No workarounds exist. Update to version 26H1u1 immediately. Broadcom published advisory VMSA-2026-0007, patching two vulnerabilities in VMware Workstation and Fusion that allow an attacker inside a virtual machine to execute code on the underlying host. One is rated Critical. Neither has a workaround. The first vulnerability, tracked a