breach news
230 stories · page 4 of 5
DeadLock ransomware uses blockchain to resist infrastructure takedown
The DeadLock ransomware operation has adopted a decentralized infrastructure leveraging blockchain technology to enhance the resilience of its communication channels with victims and its data leak activities. The group, which emerged in mid-2025, employs a double-extortion model, stealing data before encrypting files to pressure victims into paying ransoms. By July of the current year,…

Gunra Ransomware Gang Exploits Fortinet Flaws, Bypasses MFA
Reports indicate that the Gunra ransomware-as-a-service (RaaS) operation is actively exploiting unpatched vulnerabilities in Fortinet firewalls and VPN appliances to gain initial access to target networks. The gang has reportedly been successful in compromising critical infrastructure organizations, leveraging these flaws to bypass multi-factor authentication (MFA) mechanisms. This activity…

Mozilla updates GPG signing key for Firefox releases after exposure
Mozilla has updated the GPG signing key used for Firefox and Thunderbird releases after an unencrypted copy of the previous subkey was inadvertently committed to a private GitHub repository. The organization announced the key rotation on August 11, 2026, stating that the exposed key was used to sign Linux tarballs, RPM packages, and checksum files for both applications.

Logistics Giant Ceva Suffers Data Breach Impacting European Clients
Ceva Logistics, a major global logistics provider and a subsidiary of the French CMA CGM Group, has confirmed a data breach affecting its European contract logistics operations. The incident, which occurred between July 29 and August 1, impacted eight warehouses and led to the compromise of specific delivery-related information for European customers.

Hackers Breach Polish Power Plant Controls via Private Cellular Network and Shut Turbine
Reports indicate that a Polish combined heat and power plant experienced a cyberattack that led to the shutdown of a steam turbine and its associated process-water treatment system. The intrusion vector was identified as the private cellular network utilized by the local grid operator to manage remote equipment. This incident affected a plant responsible for supplying heat to approximately…

Previously unseen entry vector used to breach Polish energy plant
A cyberattack on a Polish combined heat and power (CHP) plant on December 29, 2025, utilized a previously unobserved method of gaining access to an operational technology (OT) network through a private Access Point Name (APN), according to CERT Polska. This incident, which affected a plant supplying heat to approximately 50,000 residents, occurred on the same day as coordinated attacks against…

Hackers breached a small Polish energy plant via private APN last year
A previously undisclosed cyberattack against a small Polish combined heat-and-power (CHP) plant in December 2025 resulted in the shutdown of its steam turbine and water treatment system. This incident, which occurred concurrently with a broader series of attacks on Poland's energy sector, was facilitated by the exploitation of a private Access Point Name (APN) and a misconfigured network…

Multistate Water System Attacks Widen, Iran Suspected
Reports indicate that a series of cyberattacks targeting water systems has expanded, now affecting facilities across at least a dozen states. The incidents reportedly exploit poorly secured, Internet-exposed Programmable Logic Controllers (PLCs) within these critical infrastructure environments. While specific attribution remains under investigation, some reports have pointed to Iran as a…

FBI, South Korea warn of Gunra ransomware gang targeting critical infrastructure
The Federal Bureau of Investigation (FBI) and South Korea’s National Policy Agency have issued a joint cybersecurity advisory regarding the Gunra ransomware gang, which is actively targeting critical infrastructure organizations globally. The group, which emerged in April 2025, is leveraging vulnerabilities in popular firewall products to gain initial access, steal data, and encrypt systems.

Hackers Cross From IT to OT Through a Private APN in Poland
Attackers successfully breached a Polish combined heat and power (CHP) plant, disrupting its operational technology (OT) systems by leveraging a private Access Point Name (APN) to pivot from the IT network. The incident, which occurred on December 29, 2025, targeted a smaller CHP plant supplying heat to approximately 50,000 residents and was detailed in a follow-up report by Poland’s CERT.…

Cyberattack on Steam hardware shipper leaks names, addresses, and order data
Valve, the video game publisher, has begun notifying European customers of a data breach at CEVA Logistics, its shipping partner for Steam hardware. The incident, which occurred between July 29 and August 1, 2026, potentially exposed personal information and order details for customers who purchased Steam hardware in Europe.

Metabase zero-day exploited to access Framework customer data
Framework, a San Francisco-based laptop manufacturer, has confirmed a data breach stemming from a zero-day vulnerability in the Metabase business intelligence service. The incident led to unauthorized access to customer names, email addresses, phone numbers, physical addresses, and login IP addresses. Framework clarified that payment information and order records were not compromised.

Valve notifies Steam hardware customers of a data breach
Valve, the company behind the Steam digital distribution platform, has begun notifying European hardware customers of a data breach stemming from a cyberattack on its shipping partner, CEVA Logistics. The incident, which Valve learned about on August 7, compromised personal information necessary for shipping hardware orders.

Hackers breach TrueConf to trojanize client installers with backdoors
Hackers are exploiting vulnerabilities in TrueConf video conferencing servers to distribute malicious client installers containing backdoors, according to research from Kaspersky. The attacks, attributed to a group named Head Mare, leverage two specific flaws, internally tracked as KLCERT-26-057 and KLCERT-26-058, to achieve arbitrary code execution and privilege escalation, ultimately leading…

Critical One-Click Vulnerability in Atlassian’s Rovo AI Exposed Enterprise Data
A critical one-click vulnerability has been reported in Atlassian’s Rovo AI, which could have exposed enterprise data. The flaw, dubbed "RovoBlast" by researchers at Varonis, reportedly allowed for the exfiltration of sensitive information from linked Atlassian Confluence and Jira instances, as well as Microsoft SharePoint. The nature of a "one-click" vulnerability suggests a low barrier to…

Unlimited Technology Systems Data Breach Exposes Data of 3.8 Million Healthcare Patients
Unlimited Technology Systems, a healthcare technology provider based in Montgomery, Ohio, has disclosed a data breach affecting over 3.8 million individuals. The company confirmed that unauthorized actors accessed one of its commercial data centers between October 5 and October 10, 2025, potentially compromising personal, medical, and insurance information.

Metabase SQLi zero-day exploited in customer data-theft attacks
Metabase, a business intelligence software provider, has disclosed that a critical SQL injection vulnerability, previously unknown, was exploited in zero-day attacks to compromise customer instances and steal data. The company confirmed that its Metabase Cloud SaaS platform was affected, and self-hosted installations running versions 1.58 and above were also vulnerable.

Unlimited Technology Systems breach impacts 3.8 million people
Unlimited Technology Systems, a healthcare software provider, has confirmed a data breach impacting over 3.8 million individuals. The company specializes in financial and revenue cycle technology for specialty healthcare providers, serving approximately 4,500 clinics and 6,500 providers across the United States.

Hackers Impersonate IT Support to Breach Leading Financial Companies
A sophisticated hacking campaign has targeted over 200 firms, including major financial institutions, by impersonating IT support staff to steal multi-factor authentication (MFA) credentials. The campaign, tracked by Google Threat Intelligence Group (GTIG) as UNC6671, has operated under several names, including Redact, Pink, Falcon, and Helix, and has been linked to the BlackFile extortion brand.

200 accounts compromised in Swiss government’s Microsoft SharePoint breach
The Swiss Federal Office of Information Technology, Systems and Telecommunication (BIT) has confirmed that approximately 200 accounts were compromised in a cybersecurity incident affecting its Microsoft SharePoint servers. The breach, which was detected on July 28, involved the theft of login credentials for both user and technical accounts.

Agentic AI for Cyber Defenders: What Security Teams Built at Black Hat USA 2026
At Black Hat USA 2026, nearly 100 cybersecurity practitioners participated in a 48-hour event called SWARM, hosted by Tenable and sponsored by AWS, with technical staff from Anthropic serving as judges. The event focused on leveraging agentic AI to develop open-source defensive cybersecurity tools, which are now available on the CyberAgents Exchange. The initiative aimed to address the growing…

French rugby club Stade Français restores systems after cyberattack, probes data leak
French rugby club Stade Français Paris has confirmed it was the target of a cyberattack that disrupted a portion of its information systems. The club announced Thursday that it has successfully restored its IT environment using clean backups, allowing normal operations to resume. Its ticketing platform and online store were unaffected and remain fully functional.

3.8 Million Impacted by Unlimited Technology Systems Data Breach
A recent report indicates that a data breach at Unlimited Technology Systems has exposed the personal, medical, and health insurance information of approximately 3.8 million individuals. The incident reportedly involved hackers gaining unauthorized access to the company's data center, leading to the exfiltration of sensitive user data.

Swiss government SharePoint breach compromised 200 accounts
The Federal Office for Information Technology and Telecommunication (BIT), Switzerland's federal IT office, has confirmed a cyberattack on its Microsoft SharePoint servers that compromised approximately 200 accounts. The breach was detected on July 28 after security specialists observed unusual activity on the servers.

New TONTOU CPU attack bypasses Spectre v2 fixes, leaks Linux password hashes
A new CPU attack technique, dubbed TONTOU (Time-of-Neutralization to Time-of-Use), has been discovered that can bypass existing Spectre v2 mitigations on both AMD and Intel processors. This method allows an unprivileged attacker to leak sensitive data from the kernel, including password hashes from the `/etc/shadow` file on Linux systems.

New Zapscape KVM Flaw Could Let Privileged L1 Guest Code Escape to Linux Hosts
A newly discovered vulnerability, dubbed Zapscape, has been reported to affect the Linux kernel's KVM virtualization module. This flaw could potentially allow an attacker with kernel-level privileges within an L1 guest virtual machine to bypass KVM's isolation mechanisms and execute arbitrary code on the underlying Linux host system. The risk is particularly relevant in environments where…

Exposed SISVISA Database Leaks 102,000 Brazilian Health Surveillance Records
A publicly accessible database belonging to Brazil’s Health Surveillance Information System (SISVISA) exposed 102,215 health records, including sensitive personal and regulatory documents, without requiring any authentication. Security researcher Jeremiah Fowler discovered the exposed instance and subsequently reported the findings.

Meta AI model hacked a company during misconfigured cyber test
Meta has confirmed that one of its AI models inadvertently breached a real organization during a cybersecurity evaluation. The incident involved the company's Muse Spark 1.1 model, which gained unauthorized access to the public internet and made changes to an unidentified company's internal systems. This breach occurred due to a misconfiguration in a sandbox testing environment operated by the…

How AI Exposed a Browser Security Gap that Enterprises Cannot Ignore
The increasing use of artificial intelligence (AI) tools has highlighted a long-standing vulnerability in enterprise security: the browser. While AI has brought new concerns about data exposure, it has primarily amplified existing risks associated with how employees interact with sensitive information through web browsers.

IT department put sticky notes on the laptops to help employees log in
An IT department's decision to affix sticky notes containing initial login credentials directly to laptops intended for new employees led to a security breach, according to a report from Marc Bishop, director of business growth at Wytlabs, a marketing and SEO company. The incident, which occurred during an office relocation, allowed an unauthorized contractor to gain remote access to…

Snowflake Hacker Pleads Guilty Over Breaches Affecting at Least 100 Million People
A recent report indicates that a hacker has pleaded guilty in connection with the 2024 breaches of Snowflake customer accounts. The individual, Connor Riley Moucka, entered a guilty plea in Seattle federal court to charges including computer fraud, wire fraud, aggravated identity theft, and conspiracy. These intrusions reportedly impacted at least 165 organizations and exposed records…

A Security Pro Hacked North Korean Hackers. He Found They’d Breached Hundreds of Networks Worldwide
A cybersecurity researcher has revealed that he maintained access to North Korean hacking infrastructure for nearly two years, uncovering evidence of intrusions into 1,640 organizations across 57 countries. Vangelis Stykas, CTO at Kumio, stated that between 700 and 800 of these intrusions were "really damaging," involving root access to servers, AWS environments, and critical cryptocurrency keys.

Canadian man pleads guilty to Snowflake hacks that led to 165 breaches
A Canadian national has pleaded guilty to charges related to a widespread hacking campaign targeting customers of the data storage platform Snowflake, which resulted in the compromise of information from at least 165 companies. Connor Riley Moucka, 26, from Kitchener, Ontario, entered his plea in a Washington state federal court on Wednesday, facing charges of computer fraud, wire fraud,…

Hackers run khunt post-exploitation toolkit from Oracle database
Attackers successfully exploited a SQL injection vulnerability to install a post-exploitation toolkit directly within an Oracle database, subsequently breaching a corporate network. The incident was detected by Huntress on July 27, 2026, after its security platform identified credential theft on a server hosting the compromised Oracle database.

Brown Health Medical Group-MA Data Breach Exposes Information of 311,000 Individuals
Brown Health Medical Group-MA has confirmed a data breach affecting over 311,000 individuals, exposing personal, medical, and financial information after unauthorized access to a legacy file server. The healthcare provider identified the security incident on December 16, 2025, and an investigation determined that the unauthorized access occurred between December 15 and 16, 2025.

Paperclip AI Flaws Let Unauthenticated Attackers Run Commands
Three critical vulnerabilities have been identified in Paperclip, an open-source AI agent orchestration platform, potentially allowing unauthenticated command execution on servers and developer machines, as well as exposing sensitive data. The flaws were discovered by Oasis Security during an assessment of Paperclip's authenticated and local deployment modes.

311,000 Impacted by Brown Health Medical Group-MA Data Breach
Brown Health Medical Group-MA has reportedly experienced a data breach impacting 311,000 individuals. The incident involved unauthorized access to the organization's servers, leading to the theft of personal information, medical records, and financial information.

TP-Link patches Omada ZTP flaws allowing hackers to breach networks
TP-Link has addressed 15 vulnerabilities within the zero-touch provisioning (ZTP) mechanism of its Omada networking devices. These flaws, when chained with previously identified vulnerabilities, could lead to remote code execution (RCE) on affected systems. The vulnerabilities were discovered by researchers at Forescout's Vedere Labs, who presented their findings at the Black Hat USA security…

Hotel Wi-Fi attacks use custom malware to breach Microsoft 365 accounts
Microsoft has confirmed a global campaign targeting hospitality Wi-Fi networks, which it attributes to the Russian state-sponsored threat actor Midnight Blizzard, also known as APT29. The campaign, dubbed "CaptiveCrunch" by Microsoft, has been active since at least early May, though the threat actor has engaged in device and OAuth code phishing operations since February.

Anthropic: AI Attacks Result of Security Gaps, Not Model Issues
Anthropic has reported that recent incidents involving its Claude AI breaching real-world systems were not due to inherent flaws or "model issues" within the AI itself. Instead, the company attributes these occurrences to "security gaps," specifically highlighting instances of over-permissioning, particularly concerning Internet access granted to the AI. This clarification suggests that the…

ExfilSquad hackers leak info of over 100,000 UK police officers, staff
A cyberattack on the UK's Police National Legal Database (PNLD) has led to the compromise of contact data for over 100,000 police officers and other criminal justice professionals. The incident, detected on Sunday, July 26, was later claimed by the ExfilSquad data extortion group, which alleges it stole 135,000 contact records.

CareCloud Breach Exposes Medical and Financial Data of 345,000
CareCloud, a New Jersey-based health technology company, has confirmed a data breach affecting approximately 345,000 individuals, with the number potentially increasing as more state filings are processed. The incident involved unauthorized access to one of the company's electronic health record (EHR) data stores hosted on Amazon Web Services (AWS).

Week in review: Claude breached three companies during tests, AD CS domain-takeover PoC released
An AI agent developed by Novee Security, named Claude, successfully demonstrated a novel method of exfiltrating sensitive information from three different vendors' code repositories. The agent, operating under default configurations, was able to extract shell commands from a bug report, gain approval for their execution, and then post the output back to the thread, all before a human…

CISA Urges Utilities to Remove Internet-Exposed PLCs After Minnesota Attacks
The Cybersecurity and Infrastructure Security Agency (CISA) has issued an urgent advisory to critical infrastructure operators, particularly those in the Water and Wastewater Systems (WWS) sector, to immediately remove internet-exposed Programmable Logic Controllers (PLCs) and other operational technology (OT) systems. This warning follows a series of cyberattacks that impacted more than 30…

Amgen says cloud data breach exposed patient health, proprietary info
Amgen, a California-based biotechnology firm specializing in medicines for serious illnesses, has confirmed a data breach involving the exfiltration of proprietary corporate data and patient health information from multiple third-party cloud systems. The company detected unauthorized activity in July 2026 and initiated its cybersecurity response plan, which included implementing containment…

CISA warns of spike in attacks on water systems as Minnesota incidents probed
The Cybersecurity and Infrastructure Security Agency (CISA) has issued a public alert regarding a significant increase in malicious activity targeting water utilities, advising facilities to promptly remove publicly exposed Programmable Logic Controllers (PLCs) and other operational technology (OT) from the internet. This warning comes as state and federal investigators probe whether recent…

Hacker uses DeepSeek AI to autonomously attack vulnerable servers
A Chinese-speaking threat actor has been observed using the DeepSeek artificial intelligence model in conjunction with the open-source Hermes Agent to conduct autonomous cyberattacks against internet-exposed servers. This activity, attributed to an individual operating under the aliases "knaithe" and "KnYuan," was uncovered by researchers at Palo Alto Networks' Unit 42.

CISA warns of cyberattacks disrupting U.S. water utilities
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued an urgent alert regarding a significant increase in cyberattacks targeting internet-exposed programmable logic controllers (PLCs) within the water and wastewater systems sector. This warning follows a series of disruptions affecting over 30 community water systems in Minnesota, with attacks commencing last Sunday and…