Editor's Message

Welcome to DBD. On March 8th 2026, DBD celebrated it's sixth anniversary and PRiSM celebrated it's third anniversary. Both projects have made a huge impact on my life and I'd like to thank each and everyone of you who have supported me, with special thanks to those individuals and communities who have helped me build up my knowledge on cybercrime and ransomware over the years. Thanks again for all your continued support. Stay safe. :)


“Data Breaches Digest and its PRiSM portal provide Dentons Global Security Team with valuable insights into the ransomware landscape, from the latest incidents to trends over time, as well as the ability to customize visual analytics. Timely reports and tracking by Data Breaches Digest help inform cyber intelligence for the world’s largest law firm and thus our cybersecurity posture across more than 80 countries worldwide.”
Dentons Senior Analyst, Washington D.C.
0
Data-Leaking Ransomware Attacks Tracked This Month
0
Data-Leaking Ransomware Attacks Tracked This Year



Monday, 31 August 2026

Data Breaches Digest - Week 36 2026

Welcome to this week's Data Breaches Digest, a catalogue of links concerning Data Breaches and Cyber Security that were published on the Internet during the period between 31st August and 6th September 2026.


📅 2nd September

A battery storage cyberattack would look exactly like a badly tuned controller

A Single Digital Trap Costs Trader Rs 3 Crore in Whale Phishing Scam

ATF Major Incident Following Qilin Ransomware Claim

Attackers are going after prominent individuals through OAuth phishing, FBI warns

Attackers Exploit Critical Switchvox Flaw to Deploy Reverse Shells Without Credentials

Attackers Exploit Two SonicWall SMA 1000 Zero-Days That May Form an Attack Chain

Australian organisations may soon face a 72-hour data breach reporting deadline

Authorities Turn Sality's P2P Network Against Itself, Cutting Off New Malware Payloads

Clark County warns of phishing scam targeting planning permit applicants

Critical JFrog Artifactory Vulnerability Exploited Days After Disclosure

Dropbox Breach Traces Back to a Broken Sign-In Feature You Probably Never Knew Existed

Educational Institutions Face Cyber Risks Far Beyond Phishing

Exposed ransomware server reveals automated $4 cyberattacks

Extradited Russian Hacker Faces Charges Over Excel Malware Campaign That Infected Thousands

Facebook Ads Promote Fake Streaming Apps Delivering PanDa RAT

Fake IT Support Hackers Abuse Microsoft Teams and Quick Assist to Deploy Reverse Shell

FBI has a 'Public Service Announcement' for everyone on the internet: You may be targeted by...

FBI Warns Hackers Are Impersonating Officials and Media in OAuth Phishing Attacks

FulcrumSec Claims Responsibility for Manchester Airport Group Breach

GeoNetwork Fixes Unauthenticated RCE Chain Affecting Government Geoportal Backends

Global sinkhole operation ends Sality botnet’s 23-year run

Hackers Chain Two New SonicWall Zero-Day Vulnerabilities

Hackers Exploit Critical SonicWall SMA 1000 SSRF and RCE Flaws in Active Attacks

Hackers Exploit LiteLLM Admin API Flaw to Turn Read-Only Access Into Full Server Takeover

Hackers Use AI Malware to Break Into Brazilian Banks and Make Fraudulent Transfers

Ireland: HSE fined over data breach at former Midlands hospital

Kaspersky Uncovers LinkedIn Recruitment Phishing and New Cross-platform Spyware Targeting Africa, Others

Manchester Airports Group Breach: FulcrumSec Publishes Alleged Stolen Data - Future Travel, Marketing Platform Details

Nutex Health Says Patient Data Stolen, Hackers Threaten Leak

Ransomware group The Gentlemen claims Glassdoor breach, sets deadline for alleged data release

Ransomware Hackers Built Their Own C2 Framework to Steal Passwords and Kill Security Tools

Reports on alleged massive IDScan.net data breach: 153 million driver’s licenses for sale

Sality botnet infrastructure dismantled in joint global takedown

Silver Fox Hackers Target China-Based Organizations With Counterfeit Software Installers

SonicWall SMA 1000 appliances under attack via zero-day flaws

SonicWall warns of actively exploited SMA1000 zero-day flaws

South Korea: Voice phishing cases plunge 40% after crackdown

South Korea: Voice phishing measures cut cases and losses by about 40 percent

The Philippines: Chinese national nabbed over alleged rogue cell site, phishing scheme

TVING Data Breach: 20 Million Records vs. 5 Million Subscribers - Korea's Largest Was 104 Million in 2014 Card Leak

U.S. or Korea? Coupang's data breach lawsuit faces key jurisdiction question

US charges Russian for infecting 80,000 freelancers with malware

Venezuelans plead guilty to hacking ATMs: "Jackpotting bandits are sweeping the nation"

Wave of X password reset emails could be hiding a sneak phishing attack

X Users Get Flooded With Password Reset Requests, Raising Fresh Data Breach Fears

X Users Hit By Wave Of Password Reset Requests, Triggers Fresh Data Breach Concerns

📅 1st September

9.5 Million Impacted by Aesto Health Data Breach

13 Malicious Packagist Packages Target Unpatched iPhones to Steal Crypto Wallet Seeds

65% of Enterprises Have Seen AI Agents Act Out of Scope

A Coordinated Cyber Attack by Suspected Iranian Hackers Affected Over 100 Water Systems

Aesto Health says data breach affects over 9.5 million patients

Aesto healthcare data breach impacts 9.5 million people

AI Agents Are Now Orchestrating Entire Ransomware Attacks, Signaling a New Threat Era

AI Helps Drive Number of Linux Kernel CVEs to Near 2,000 Per Release

AI-Powered Phishing Is Making Traditional Email Security Less Effective

Anthropic: Attackers Using Infostealers to Hijack Claude Sessions

Anthropic boots users, wipes payment info to protect against malware attack

Attackers Abuse Trusted Cloud Services to Hide Phishing Attacks Against Financial Organizations

Attackers Exploit Critical JFrog Artifactory Flaw to Mint Admin Tokens Days After Disclosure

Attackers Exploit Critical Langflow and Rails Flaws in Credential-Probing and C2 Activity

Attackers Steal METR API Key and Burn $600,000 in AI Credits

Attackers Steal METR API Key and Consume AI Credits Worth About $600,000

Baptist Health warns patients of MyChart phishing scam

Berlin refuses to be blackmailed after network breach

Berlin’s Seven-Day Ransomware Isolation Gap Let Rhysida Steal Critical Infrastructure Data

Biggest Cyberattacks Changing the Security Landscape

Breeze Comet Executes Hundreds of Fraudulent Transactions via Brazilian Payment Systems

Canada: ‘All levels of government’ being impersonated by scammers, says Municipalities Newfoundland and Labrador (MNL)

Charity supporters’ warned after cyber attack exposes personal data

Chicago Family Health Center Data Breach Affects 90,000

China-Nexus Fire Ant Hackers Target Cisco Routers, TACACS Servers for Espionage

China's 'Fire Ant' campaign used compromised Cisco routers as platform for more attacks

City of Missoula warns of ongoing phishing scam

Clark County warns of phishing scam impersonating Planning Department

Critical Langflow flaw exploited to steal OpenAI and AWS keys

Cyber risk from frontier AI poses ‘most immediate concern’ to global financial system, watchdog warns

Cybersecurity experts issue warning after Winona County pays $128k following ransomware attack

Dark web listing contradicts Dodo Payments’ data breach disclosures

eBay Disables Community Messages After Wave of Phishing Scams

Fake Claude Opus 5 app delivers malware and wipes its own tracks

FBI raises alarm over deceptive phishing campaign targeting prominent people

Fidelity Data Breach Costs $3.75 Million in Combined Fines

Financial Stability Board Sounds the Alarm Over Frontier AI Risks

Five Venezuelan Nationals Plead Guilty After Kansas ATM Jackpotting Attempts, FBI Reports 1,900 US Incidents Since 2020

Five Venezuelans plead guilty to ATM jackpotting attacks in US

Flock backlash turns into statewide fight as Florida pushes cameras off roads

Florida and Texas move to block Flock cameras over privacy concerns

FulcrumSec Leaks Manchester Airports Group Customer and Booking Data

Hacker breaches creators of Hello Neighbor horror game and blackmails them - demands game be removed from sale

Hackers abuse Faronics Deploy admin tool to install ScreenConnect

Hackers are using fake MP4 video files to smuggle payloads past security filters

Hackers breach 5,000 Dropbox accounts using only victims’ email addresses

Hackers Demand Ransom After Berlin Data Breach

Hackers give Glassdoor 172 hours to stop dump of allegedly sensitive data

Hackers push malicious Virtualizor update in BGP hijacking attack

Healthcare facilities operator Nutex says patient, employee data stolen in August incident

Healthcare Giant McKesson Investigates Data Breach Incident

Hong Kong: E-commerce data breach affects more than 33k

Identity-based attacks involved in 85% of education ransomware incidents

India: Told to stop posting flaws, teen hacker uses government email ID to troll Cert-In

India Catches Meta Running Malware-Laced ‘Adult’ Ads on Facebook and Instagram That Drain Bank Accounts

Integrated Specialty Coverages Data Breach Exposes Driver's Licenses

Investigation opened on OpenAI by Montana Attorney General Austin Knudsen following data breach

Iranian cyber spies target aviation, fintech developers with new malware

Iranian Hackers Pose as Recruiters to Deliver Cross-Platform RATs Through Coding Tests

Ireland: HSE fined €645,000 over data breach affecting Westmeath hospital

Kiewit discloses data breach affecting employees and contractors after email account compromise

Majority of Senior Cybersecurity Leaders Have Limited Trust in AI

Manchester Airports Group hit by cyber attack

McKesson Confirms Data Breach as ShinyHunters Claims 284 Million Records Stolen

McKesson Confirms Data Breach, Experts Weigh In

McKesson data breach exposes prescribing physicians and their patients to fallout from a third-party attack

Mira Partners Suffers Personal Data Breach, Encryption Key Exposure Unclear

Nearly 22,000 Microsoft Exchange servers exposed as exploit goes public

Nearly 22,000 Microsoft Exchange servers vulnerable to hijack attacks

Nephrology Associates Data Breach Affects 24k Patients

Novocure data breach affects more than 1,400 cancer patients

Omdia Study Highlights Declining Ransomware Recovery Rates and the Immutability Gap in Backup Storage

P&O ferry passengers hit by data breach during sailing

Qilin hackers leak ATF data, exposing criminal investigations and phone records

Qilin Leaks 6.3GB of Alleged ATF Files, Then Pulls Download Links

Ransomware Gang Claims Nutex Health Data Breach

Ransomware gang leaks sensitive files from ATF investigations

Ransomware Group Claims Andover As Victim Following Cyberattack

Ransomware in 2026

Recently patched PaperCut zero-days used in data theft attacks

Russia-Aligned UAC-0099 Plants Nuclear Weapon Prompt in Malware to Disrupt AI Analysis

Scammers Running Fake Cryptocurrency AML Wallet-checking Sites Hoodwink Users, Drain Wallets

Some seek compensation following Road Traffic Safety Directorate (CSDD) cyber attack in Latvia

South Africa: Gert Sibande Municipality issues urgent warning over phishing emails

Stronger Security Drives Ransomware Groups to Recruit From Within

The Gentlemen come calling as Nutex confirms sensitive data theft

The Most Immediate Threat to the Global Financial System Is AI Cyberattacks

They prey where kids play: how gaming phishing scams now target kids

Threat Actors Don’t Want Better Attacks. They Want Repeatable Ones

TVING data breach exceeds subscriber base, raising questions over 19.53 million figure

Ungentlemanly behavior: Insights into a ransomware operation

Vishing campaign abuses Microsoft Teams to give attackers a foothold in company networks

White House Launches Pilot Program in Texas to Protect Water Infrastructure

Why are Ransomware Hackers giving victims only 7 days to pay the Ransom

Winona County Paid $128,000 Following Ransomware Attack

Winona County, Minnesota, Paid $128K Ransom to Restore Services

X Data Breach? Users Are Getting Flooded With Password Reset Emails Nobody Requested

X says attackers are targeting user accounts after the launch of X Money

📅 31st August

85% of Education Ransomware Starts with Stolen Identities

'128 Billion Won Fine' GS Retail Apologizes for Data Breach, Vows to Strengthen Security System

AI agent in Cursor linked to ransomware breaches at 7 companies

AI agents read legitimate llms.txt files from trusted companies and proceed to install malware

AI AppSec tools agree on just 5% of security findings

AI killed the typo. Now it’s time to rewrite phishing training

Anthropic locks out Claude users after infostealers hijack login sessions

Anthropic Warns Commodity Infostealers Are Hijacking Claude Sessions to Drain Paid Usage

Apple shares ‘shocking evidence’ against former employee accused of stealing company data for OpenAI

AshSqlite Vulnerability (CVE-2026-77846) Exposes Hidden JSON Fields

Attackers plant remote access tools on compromised PaperCut servers

Aurora Ransomware Hackers Use Cursor AI Agent for Hands-On Exploitation and ESXi Attacks

Aurora Ransomware Hackers Used AI to Attack Companies Across Nine Countries

Aurora Ransomware Operators Use Cursor AI in Attacks Against 10 Targets

Australian app developer DigiGround investigating ransomware claims

Boston Scientific Cyberattack Limited to Unauthorized Access on Certain On-Premises Systems

Bureau of Alcohol, Tobacco, Firearms and Explosives Discloses Cyber Incident

Berlin Confirms Data Theft After Rhysida Attack: 5.79TB

Berlin confirms data theft after Rhysida ransomware attack claims

Berlin Won’t Pay Extortion Group Claiming Data Theft

Blind Eagle-Linked Loader Uses GitHub, VBScript, PowerShell and InstallUtil to Deploy AsyncRAT

CareCloud data breach affects more than 3.75 million people

CarGurus Data Breach Exposes 12.5 Million Accounts; Here's What Hackers Got

China-Linked Fire Ant Hijacks Cisco Routers to Steal Credentials and Blind Security Logs

Chinese Fire Ant hackers turn Cisco routers into spying platforms

Court upholds firing of Korea Food Research Institute (KFRI) executive for crypto mining and data breach in Korea

Cronos blockchain restarts after $74 million Tectonic exploit

Cybersecurity's “Hiring Crisis” is Fueling the Cybercrime Talent Pipeline

Darksiders Publisher THQ Nordic Named on DireWolf Ransomware Leak Site

Data Breach & Blind Spots: The Cyber Risk for Supply Chains

Data Breach at Los Angeles County Museum of Art. What Was Leaked?

Delta School District reports website cyber attack

Department of Justice (DoJ) Corrects China Hacking Claim, Says U.S. Agencies Were Targets, Not Victims

Extortion Group Claims Manchester Airports Group Data Breach

Fake Claude Opus 5 App Spreads New RevStealer Windows Malware

Fake MyChart messages target patients across Pennsylvania

Fidelity’s $2.5 Million Data-Breach Settlement Puts A Price On Losing Control Of Customer Data

Five plead guilty in latest federal ATM jackpotting case

Fogo Blockchain Halts Operations Due to Hacker Attack and $3 Million Theft

Fraudsters steal $6 million from Tectonic crypto platform after inflating token price

Free Cloudflare DNS Tweak Blocks Malware and Phishing Across Home Networks

Free Router DNS Tweak Blocks Malware and Phishing Across Home Networks

FulcrumSec Hackers Claim Manchester Airports Group Data Breach

GS Retail fined $9.3 Million following customer data breach

GS Retail fined 12.8 billion won over data breach affecting 1.66 million users

Guernsey: Doctor's appointment phone call led to data breach

Hacker puts data of 820 million Alipay users up for sale

Hackers claim millions of patient records stolen during data breach at healthcare giant McKesson

Hackers demand €2 million from Berlin, threaten data leak

Hackers Steal Identity, Vehicle Data from Latvia’s Road Traffic Safety Directorate

Hackers threaten to spill the secrets behind America’s food safety giant Neogen

Hackers’ Own Malware Infection Exposes Their RATs, Phishing Kits and Attack Infrastructure

Hasbro Breach Exposes Employee Information

Hasbro Data Breach Exposed Employee SSNs and Driver's License Data

Hong Kong police arrest two men allegedly linked to HK$500,000 phishing scam

How AI could make it harder for governments to use hacking tools

How to Prepare for AI-Driven Cyberattacks

Human Rights Writers Association of Nigeria (HURIWA) faults police, National Data Protection Commission (NDPC) over delay in probe of alleged National Institute for Policy and Strategic Studies (NIPSS) data breach involving naval officer

Identity theft attacks account for 85% of ransomware cases in education

Identity-based attacks account for 85% of ransomware incidents in education

Identity-Based Attacks Are Responsible for 85% of Ransomware in Education

India: Hyderabad publisher hit by ransomware, €20m ransom sought

Infostealer Malware Steals Claude Session Cookies to Hijack Accounts and Bypass 2FA

Iranian-Linked Cyber Attack Shuts Down a UK Power Plant

Law Society of Scotland issues fraud alert after phishing email

Ledger Phishing Scam: Fake Wallet Website Targets Crypto Users - What You Need to Know

Manchester Airports Group Data Breach: FulcrumSec Claims the Theft of 86 GB via Exposed Iterable API Credentials

McKesson confirms cyber incident after ShinyHunters claims patient-data theft

McKesson Confirms Breach: 284 Million Records, $55 Million Demand

McKesson Confirms Data Breach as Attacker Deadline Looms

McKesson discloses data breach after ShinyHunters claims theft of 284 million records

Microsoft warns of TerminalFix attacks deploying reverse tunnels

Microsoft Warns of TerminalFix Campaign Hiding Malware in PNG Images

National Health Insurance Service (NHIS) phishing scam exposes gaps in South Korea fraud insurance

Nigeria: Rights Group Decries Delay In Probe Of Alleged Data Breach By National Institute for Policy and Strategic Studies (NIPSS)

Nigerians extradited to US for sextortion, deaths of two teens

North Korean Job Fraud Expands Beyond IT Into Healthcare and Sales

Only 33% of AI Agents Provisioned With Least-Privilege Access

Open ATF criminal case files leaked by Russian ransomware hackers

OpenAI Warns Astra AI Could Develop Zero-Day Exploits and Launch Autonomous Cyberattacks

P&O Ferries data blunder as it sends out passengers' personal details by text message

PaperCut Issues Second Emergency Patch as Researchers Break Fix for Exploited Zero-Days

Pharmaceutical giant McKesson warns of 'service degradation' following cyberattack

Phishing scam is targeting 'MyChart' patient portal users

Phishing scam spreading around Pennsylvania involving fake alerts from MyChart

Qilin hackers leak ATF data, exposing criminal investigations and phone records

Ransomware attack hits Norcross' computer systems, leaving disruptions, officials say

Ransomware attack reportedly exposes Carhartt data

Ransomware Gang Names ATF; Department of Justice (DOJ) Calls Breach ‘Major’

Ransomware-as-a-Service democratizes hacking

Rhysida Ransomware puts Berlin Government Data up for sale for 30 BTC

Russian hackers plant nuclear weapon prompt in malware to trip AI safety guardrails

Security Leaders Weigh in on Recent PaperCut Vulnerabilities

ShinyHunters claims it stole 284 million patient records from McKesson

ShinyHunters Claims Theft of 284 Million Records from Healthcare Giant McKesson

Simple Router DNS Tweak Blocks Malware and Phishing Across All Connected Devices

Slovenian casinos reopen after cyberattack knocked gaming systems offline

Small businesses and cyberattacks: why phishing is still the threat to watch

'Sophisticated' AI swarm attacks are months away, OpenAI warns: What experts say businesses must do

South Korea fines GS Retail $9.2 million over data breach affecting 1.66 million customers

Steam Data Breach Exposes Over 12TB of Source Code, Unreleased Projects

Steam leak that exposed a decade of game history wasn’t even a hack

TerminalFix Attack Uses Fake Cloudflare CAPTCHA to Deploy Reverse Tunnel Into Corporate Networks

Threat actors are posing as AI crawlers to hunt for exposed credentials

US cities cancel Flock contracts at record pace in August

US healthcare giant McKesson breached, ShinyHunters claims 284 million patient records

ValleyRAT Backdoor Hides in Signed Adware That Users Add to Antivirus Exclusions

What a Financial Data Breach Actually Costs a Fintech in 2026

What vulnerability prioritization looks like when KEV, EPSS, and CVSS disagree

When a Cyber Loss Has No Conventional Hacker

Wippy Data Breach Exposes 736 Users' Height, Blood Type; South Korea Fines nRiZE ₩118 Million

Your Money and Data Are at Risk as Phishing Attacks Rise

ZeroBytes breaches Zéro Logement Vacant, data of nearly 48 million French property owners exposed

Tuesday, 25 August 2026

Ransomware Operator Claims - Week 34 2026

Welcome to last week's ROC Report, an exclusive summary of Ransomware Operator's global victims that were claimed during the period between 17th August and 23rd August 2026, kindly assisted by our partners.

DBD discovered and researched 251 Ransomware Victims over 48 Countries and Islands claimed by 48 Data-Leaking Ransomware Operators, including 3 Newly Discovered Ransomware Operators last week.

For further analysis on these (and any historic) Ransomware Operator Claims, including the Victim Names and Industry Sectors attacked, please use our PRiSM application.

Download PDF



Data Source: Data Breaches Digest. Flag Icons created by Freepik and provided by Flaticon.


Monday, 24 August 2026

Data Breaches Digest - Week 35 2026

Welcome to this week's Data Breaches Digest, a catalogue of links concerning Data Breaches and Cyber Security that were published on the Internet during the period between 24th August and 30th August 2026.


📅 30th August

29CM data breach exposes 160,000 records; Korea probes as users warned

A hacker with no history sells the data of 41,300 clients of the marketer Yaluz on Telegram

Already patched PaperCut? You need to do it again

Anthropic warns infostealer malware is hijacking Claude sessions to drain usage

ATF Hacked: Qilin Claims Breach, 885 Victims

Berlin Under Cyber Siege as Hackers Threaten to Auction 5.79TB of Stolen Data

Berlin won’t pay its hackers - now 5.8TB of government data could go up for auction

CareCloud Breach Hits 3.75 Million People

Chrome Web Store extensions caught stealing crypto, browser data

Fake Claude apps fuel new wave of AI cyberattacks

Florida hospitals warn patients about 'MyChart' phishing scam targeting portal users

FulcrumSec claims Manchester Airports hack, theft of 86 GB of data

Hasbro breach exposes employees’ addresses, IDs, and financial information

Healthcare data breach exposes 3.75 Million patient records

Hong Kong: WhatsApp hijacking cases surge 154% to 2,020; manager loses $12 million

How Hackers Build Advanced Phishing Pages to Steal Credentials

Human Rights Writers Association of Nigeria (HURIWA) faults Inspector-General of Police (IGP), National Data Protection Commission (NDPC) over delay in probing alleged National Institute for Policy and Strategic Studies (NIPSS) data breach involving naval officer

Human Rights Writers Association of Nigeria (HURIWA) faults police, National Data Protection Commission (NDPC) over alleged National Institute for Policy and Strategic Studies (NIPSS) data breach probe

Human Rights Writers Association of Nigeria (HURIWA) tackles Police, National Data Protection Commission (NDPC) over alleged National Institute for Policy and Strategic Studies (NIPSS) data breach involving naval officer

Manchester Airports Group breach exposes data of 8.7 million airport customers

Musinsa subsidy 29CM's data breach affects 159,000 customers

Musinsa's 29CM Suffers Data Breach Affecting 160,000 Customers, Including 20,000 with Shipping Details

Rhysida Claims Berlin Government Hack: 5.79 TB, 30 BTC

Tax Season Phishing Scheme Spreads New PackClient Malware Across Asia

TerminalFix Uses Fake Cloudflare CAPTCHAs to Deploy Reverse-Tunnel Backdoor

Ticket Resale Platform Tixel Warns Users Of Data Breach In Metabase Zero-Day Attack

📅 29th August

2 PaperCut NG/MF Zero-Days Exploited in Attacks, Emergency Patch Released

30 Bitcoin or leak - ransomware gang extorts Berlin

A Russian Ransomware Gang Says It Broke Into the ATF's Investigation Files

Attorney general warns Pennsylvanians of phishing scam targeting online healthcare portal

Baylor Genetics data breach hits 2.8 Million

Berlin‘s government faces a Rhysida ransomware attack

Carhartt data breach exposed information from 12.9 million user accounts

Chinese Hackers Deploy PackClient RAT via Tax-Themed Phishing Attacks to Steal Data

Cl0p Ransomware Hits Shell, GE, Philips via PTC Bug

Critical Gogs Path Traversal Flaw Enables Remote Code Execution via Git Hooks

Five Critical WordPress Plugin and Theme Flaws Enable Site Takeover or RCE

Hacker Group Threatens to Auction Berlin Government Data

Hacker Shows Anyone Near a Unitree G1 Robot Can Seize Root Control

Hackers Steal €152,000 From Crete Regional Authority in Elaborate Bank Fraud Scheme

Hasbro Data Breach Exposed Employee Personal Information

Hasbro Discloses Employee Data Breach: 436 SSNs Hit

India Tops Weekly Infostealer-Infected Machine Count as Experts Outline Remediation

Penn Medicine Warns Patients as MyChart Phishing Scam Spreads

Second-hand ticket marketplace Tixel confirms customer information stolen in data breach

Microsoft Warns TerminalFix ClickFix Campaign Uses Fake CAPTCHA to Deploy Reverse Tunnel

MyDr data breach: Poles rush to government service to check whether their data were exposed

Norcross Ransomware Attack Hit City Systems Weeks Before Officials Went Public

Over 335 Million records breached as cyber attacks rise in the Philippines in H1 2026

Phishing scams reported targeting MyChart users

Ransomware group says it stole Berlin data, offers it for auction

Rhysida Ransomware Group Targets Berlin Government Ahead of Vote

Robert Burns farm charity warns members after cyberattack data breach

Supply Chain Worm Hits Popular TanStack Query Code Generator to Steal Developer Credentials

TA4922 Hackers Use Tax Phishing to Deploy PackClient RAT Across Asia

US healthcare giant McKesson breached, ShinyHunters claims 284 million patient records

US insider-threat hunter admits leaking state secrets to foreign government

📅 28th August

8.7 million customers’ data accessed in cyber attack against three UK airports - including one in the Midlands

8.7 million people exposed in Manchester Airports Group cyber attack

19 Chrome and Edge Extensions Found With Wallet-Stealing and Crypto-Draining Code

700 OpenAI AI Agents Coordinate Hugging Face Hack and Achieve Remote Code Execution

A Backup Isn’t Enough: How Small Businesses Can Recover From Ransomware

AI Agent Instruction Files Let Attackers Execute Code Inside Fortune 500 Networks

AI Ransomware Can Now Run Much of an Attack Without Human Help

AI scams make phishing harder to spot

Alan Gordon Data Breach Exposes Social Security Numbers

American Vision Partners Settles Data Breach Litigation for $1.75 Million

Android 17 adds new protections against sneaky Wi-Fi tracking and web snooping

Android 17 Adds OS-Wide Encrypted Client Hello (ECH) to Hide Website Visits From Network Providers

APT28-Linked HOOKEDGE Backdoor Targets European Government and Diplomatic Organizations

Arrests Hinder TeamPCP, But the Threat is Still Out There, Researchers Say

ATF Confirms Cyber Incident After Ransomware Group Claims Attack

ATF confirms cyberattack hit system containing info on its investigation targets

ATF Confirms Major Cyber Incident Amid Qilin Claim

ATF declares cyberattack a ‘major incident’ after ransomware claim

Attackers Chain Two PaperCut Flaws to Execute Code Without Authentication

Aurora ransomware actors leverage AI tool for exploitation campaigns

Aurora ransomware gang used Cursor to speed up attacks: 30% to 50% faster intrusions

Aur0ra ransomware tricked Cursor's AI agent into hacking seven companies

Berlin is being blackmailed by hackers, mayor says

Berlin Refuses to Pay Hackers Who Stole Data From the City's State Network

Castle Point Council sees personal information data breach

China-Made ZBT Routers Ship With Two Implants Giving Unauthenticated Attackers Root Access

Chinese-Speaking Hackers Target Indian Firms With Hindi Tax Phishing

Cosmos EVM Flaw Exploited After Cosmos Labs Knew Every Blockchain Running It Was Vulnerable

Critical cPanel Flaw Could Let One Hosting Customer Take Root Control of a Whole Server

Cyber Attack Hits Manchester Airport Group as Data of 8.7 Million Customers Accessed

Cyber attack targeted customers at Stansted Airport

Cyber Threats Explained: What They Are and Why They’re Growing

Cyberattack on Three UK Airports Exposes Data of 8.7 Million Customers

Cyberattack on UK Airport Operator Manchester Airports Group (MAG) Exposes Data of 8.7 Million Customers Across Three Airports

Cybersecurity alert: phishing campaigns increasingly target hotel staff

East Midlands Airport hackers demand ransom after passenger data stolen

Encryption Expiration: How AI and Quantum are Defining New Boundaries for Data Security

Epic MyChart Phishing Scam Hits Health Systems: What Providers Should Do

Europe’s Cyber Risk: Ransomware and Critical Systems

Fake Indeed apps infecting Android-using job seekers with malware

Fake North Korean IT workers are rampant: Here’s how to spot the telltale signs a new hire is a hacker

Fake Voicemail SVG Attachments Fuel Large-Scale Phishing Campaign

Fraud alert: Phishing emails purporting to be from the Law Society of Scotland

GiveWP WordPress donation plugin flaw lets hackers execute server commands

Hackers Exploit AI and Deepfakes to Breach Fiji Businesses, Expert Warns

Hackers Make Phishing Pages Change Their Code Every Time Someone Opens Them

Hackers say they know where nearly half a million diamond customers live

Hackers steal data linked to 8.7 million customers across three UK airports

Hackers steal personal data of 8.7 million customers in cyber attack on three UK airports

Health systems warn of phishing scams using Epic’s MyChart name and logo

How Recruitment Phishing Puts Employee Credentials at Risk on Smaller Mobile Screens

Hungry Lion fast food chain hit by ransomware attack claimed by MeduzaLocker

Identity-Based Attacks Drive 85% of Education Ransomware

Is Your Home-Based Business Ready for a Cyber Attack

Latvia: Huge cyberattack affects two-thirds of country’s population

Linux accounts for half of CISA’s latest actively exploited flaws

Love Electric Breach: 877,000 Driver Records Offered for $600

Over 8,300 Gitea servers vulnerable to code execution attacks

Manchester Airport Data Breach Exposes 8.7 Million Travellers

Manchester Airport Group Suffers Data Breach of Customer Info

Manchester Airport hackers demand ransom after 8.7 million passengers' data stolen in major cyber attack

Manchester Airports Breach Impacts 8.7 Million

Manchester Airports Group breached, millions of customers’ data stolen

Manchester and Stansted owner claims hackers demanded ransom during cyber-attack

Manchester HIV charity George House Trust warns users of data breach

Manchester, Stansted and East Midlands airports hit by cyber attack

Manchester, Stansted and East Midlands cyber attack: Operational Technology (OT) security lessons for engineers

McKesson discloses breach after ShinyHunters claims patient data theft

Millions of patients warned after DNA testing data breach

Mirage2FA: The Phishing Service Turning a Stolen Microsoft 365 Cookie Into Full Account Takeover

Morocco's DGSN-DGST security hub formally refutes data breach allegations

MP gives update on cyber attack at East Midlands Airport impacting millions of travellers

MyChart patient portal users warned of phishing scams

National Cyber Security Centre (NCSC) warns of growing cyber threat to exposed OT and edge devices

New campaign targets Cambodia with Spark RAT using Bring Your Own Vulnerable Driver (BYOVD) technique

New exploit tricks Claude Code into running malicious code despite Auto Mode

North Korean remote workers are broadening their job hunt beyond IT

Nvidia’s Error Correction Code (ECC) was supposed to stop memory corruption, but attackers can hammer their way to root

ownCloud Flaw Exploited to Steal Nuclear Records From Philippine Research Body

Palo Alto Networks Researchers Say First Wave of AI-Enabled Attacks Has Begun

PaperCut releases second emergency patch for exploited flaws

PaperCut warns of hackers using printer management software flaw in attacks

PaperCut Zero-Day Exploited in Attacks, Affecting All NG and MF Versions

Pennsylvania Attorney General Warns of MyChart Phishing Scam

Phishing and ransomware attacks rise in the Philippines during 1H 2026

Polymorphic Phishing Attack Generates Unique Credential-Stealing Page on Every Visit

Punch & Associates Data Breach Exposes Financial Information

Ransomware Activity Hits 2026 High as Attacks Rise 22%

Ransomware attack targets Norcross city computer systems, officials say

Ransomware Attacks on Industrial Control Systems Rose in Q2 2026

Ransomware Gang Claims AI Can Analyze 700GB of Stolen Data Every Hour

Ransomware group auctions stolen Berlin data after ransom refusal

Ransomware Is Changing Shape. What India’s Threat Landscape Reveal

Report Finds AI Security Fails to Match AI Usage

RMM Phishing Campaign Spans 46 Countries as Attackers Abuse Trusted IT Tools

Russian-Linked Hacker Group Breaches Seven Companies by Exploiting AI From SpaceX-Backed Cursor

ServiceNow Patches Critical Flaws Enabling Unauthenticated RCE and SQL Injection

ServiceNow warns of three max severity security vulnerabilities

Sharp Motor Group confirms third-party cyber incident in wake of ransomware claims

ShinyHunters claims McKesson data breach exposing 284 million patient records

South Korea: Phone Numbers Used in Voice Phishing and Other Crimes to Be Suspended Within 24 Hours

Spectrum Laboratory Data Breach Exposes Social Security Numbers

St. Luke’s University Health Network warns patients of phishing scam using MyChart name, branding

Stansted Airport cyber attack: Millions of passengers' details accessed by hackers

SVG attachments used in widespread phishing campaign

TA4922 uses PackClient malware in tax phishing attacks

The ATF Was Just Hit by a ‘Major’ Hacker Breach - And Investigation Targets Were Exposed

Threat Actors Abuse Cursor Agent AI to Assist Ransomware Operations

Three CVSS 10.0 ServiceNow Flaws Could Let Unauthenticated Attackers Execute Code and SQL

Toy-making giant Hasbro disclose data breach affecting employees

Two Unitree G1 EDU Humanoid Robot Flaws Enable Root RCE, One Starts Over Bluetooth

UK airport operator confirms data breach affecting 8.7 million customers

Unitree G1 Humanoid Robot Flaws Enable Unauthenticated Root RCE Over Bluetooth

US Disrupts Global Botnet Used by China-Linked QTFY Hackers

US government alcohol and firearms agency ATF declares ‘major incident’ after ransomware gang claims cyberattack

US thwarts major Chinese hacker cyberattack targeting Senate and NASA

What the NHS Cyber Attack Taught Us About Business Continuity

When does a cyber attack count as an act of war?

White River Junction Veterans Affairs (VA) reports data breach of veterans’ information

Window to Tackle Surge in AI-Enabled Cyber Attacks Narrowing, Tech Giants Warn

Winona County Confirms $128,539 Ransomware Payment After January Cyberattack

📅 27th August

8.7 million customers affected by data breach at Manchester, Stansted and East Midlands airports

8.7 million customers hit as Manchester Airports Group breach exposes airport WiFi sign-ups

8.7 million customers’ data accessed in cyber attack against three UK airports

8.7 million passengers affected by cyber attack on three UK airports

8.7 million people exposed in Manchester Airports Group cyber attack

12.9 Million Exposed by Carhartt Data Breach

A cyber attack affected three airports in the United Kingdom, compromising the personal data of 8.7 million customers

Account Takeover Flaw Hits TranslatePress Plugin Used on 400K WordPress Sites

Aerospace Alloys Data Breach Exposes Social Security Numbers

Africa Faces 3,008 Cyberattacks Weekly as Ransomware Groups Hit Record 93

AI a 'force multiplier' for low-skilled threat actors: 4 ways organizations should respond

AI Models are Finding Vulnerabilities Faster

Alleged TeamPCP Hackers Charged in Australia Over Major Supply Chain Attacks

Amazon Kiro Prompt Injection Can Exfiltrate Sensitive Data Through Kiro Powers

Android 17 adds Encrypted Client Hello (ECH) support to make web browsing harder to track

Applebee's Franchisee in Independence Sued Over Employee Data Breach Cover-Up Claims

ATF Confirms Major Cyberattack After Qilin Claim - Were Gun-Owner Records Exposed?

ATF confirms “major incident” after recent Qilin breach claims

ATF declares ‘major incident’ as ransomware gang claims hack

ATF investigates ‘major’ cybersecurity incident as ransomware group claims attack

ATF investigating ‘major’ cybersecurity incident

ATF investigating ‘major’ cyber incident after ransomware group claim

ATF responds to 'major' cybersecurity incident after ransomware gang's claims

Attackers are moving faster than security experts can patch, Microsoft warns

Aurora Ransomware Affiliate Uses Cursor AI to Plan Attacks Against 20+ Organizations

Australia Arrests 2 Alleged TeamPCP Hackers

Australia arrests alleged TeamPCP hackers behind supply-chain attacks

Australia charges two men for TeamPCP supply-chain hacking spree

Australian police arrest two over TeamPCP hacks targeting Mercor, OpenAI, and others

Barracuda Ransomware Syndicate Leaks 850,000 Files from US Water Infrastructure Supplier Micro-Comm

Bell American Group Data Breach Exposes SSNs and Medical Records

Beyond the Hype: AI, Ransomware and Business Models

Boston Scientific Confirms Cyberattack That Affected Network Communications, Disrupting Global Operations

Boston Scientific Cyberattack Disrupts Order Processing, Shipping Worldwide

Boston Scientific Reveals Global Disruption After Cyber Incident

Boston Scientific's IT team continues its 'recovery efforts' after cyber attack

Carhartt data breach exposes information of 12.9 million accounts

Carhartt hit by data breach claimed by hacking group ShinyHunters

Chinese and Russian spies stepping up cyberattacks, German companies report

Chinese Hacker Group QTFY Uses Custom-Built Platforms to Target US Infrastructure, FBI Warns

Chinese Hacking Operation Targeted U.S. Senate, NASA, Federal Reserve

CISA Adds Six Exploited Flaws to KEV, Including NetScaler, Linux, and SQL Server Bugs

CISA orders feds to patch Citrix NetScaler RCE flaw by Saturday

CISA Warns of Six Exploited Flaws in Microsoft, Linux, Red Hat and Citrix Products

Claude Opus 4.6 Found a Gym API Flaw - Then Exploited It in 9 of 10 Tests

Customer data accessed in cyber attack affecting East Midlands Airport

Cyber attack at Windsor-Essex Children's Aid Society under investigation

Cyber attack hits Manchester, Stansted and East Midlands airports as customer data stolen

Cyber Attack Hits Three UK Airports, Exposes Millions Of Customers’ Data

Cyber attack targeting Hachette Australia subsidiary hurts bookshops and authors

Cyberattack causes network outage at Boston Scientific, disrupts global operations

Cyberattack on Manchester Airports Group exposes data of 8.7 million customers

Data Breach Affects 8.7 Million Customers of Three UK Airports

Data of 8.7 million customers stolen in cyber attack on Manchester, Stansted and East Midlands Airports

Data stolen from 8.7 million customers after three airports targeted in cyber attack

Department of Justice (DOJ) and FBI Seize Chinese Hacking Platforms QScan and QTRouter

Department of Justice (DOJ) Confirms Ransomware Attack On ATF Claimed By Russian Cyber Gang

Department of Justice (DOJ) firearms agency says hackers breached system containing investigation targets

Department of Justice (DOJ), NASA, Others Among Victims of Chinese State-Sponsored Hack

E.ON Energie Romania warns about a phishing campaign with false messages regarding "unpaid bills"

East Midlands Airport hit by cyber attack, millions of customers affected

East Midlands Airport issues advice to customers after cyber attack affecting millions

Everything we know about the Boston Scientific cyber attack so far

Exposed Aurora ransomware server reveals AI-assisted attacks, stolen credentials and crypto laundering

FBI Seizes China State-Sponsored Hacker Platforms Used to Target U.S. Critical Infrastructure

FBI Seizes Chinese Hacker Platforms That Targeted NASA And The Senate

Former Los Angeles County Museum of Art (LACMA) Curator Sues Museum, Says It Sat on Data Breach for a Year

GoCaracal Malware Uses Ethereum Smart Contract to Fetch Replacement C2 Address

HD Hyundai Units Fined Over Employee Data Breach

HIV charity warns users of data breach after cyber attack

How Threat Research and MDR Help SMBs Build a Defensive Edge

Huge cyber-attack sees 8.7 million UK airport passenger details stolen

Is Stansted Airport parking affected by the cyber attack?

Life Bridges Data Breach Exposes Personal and Medical Information

Los Angeles County Museum of Art (LACMA) Data Breach Exposed Social Security and Medical Data

Los Angeles County Museum of Art (LACMA) Sued Over Extensive Data Breach

Major cyber attack at UK airports with 8.7 million customers' data compromised

Major cyber attack on Manchester Airports Group sees 8.7 million customer's data stolen

Major Manchester Airports Group cyber attack as 8.7 million customers' data accessed

Manchester Airport Breach Hits 8.7 Million Customers

Manchester Airport cyber attack: What you must do if you think you're affected

Manchester Airport Data Breach: Manchester Airport Cyber Attacked 8.7 Million Customers’ Data - Check Current Status, Customer Guidance & What to do If Affected

Manchester Airport Group hit by cyber attack

Manchester Airport Group Hit By Cyber Attack With 8.7 Million Customers’ Data Stolen

Manchester Airport group hit with data breach as millions of passengers impacted

Manchester Airports Group Hit by Cyber Incident

Manchester Airports Group says hackers stole travelers' data

Manchester Airports Group (MAG) confirms cyber attack exposed customer emails, phone numbers and vehicle details

Manchester Airports Group cyber attack - all we know so far as 8.7 million customers affected

Manchester Airports Group hit by major cyber attack as 8.7 million customers affected

Manchester Airports Group suffers data breach exposing customer data

Manchester, East Midlands and Stansted airport cyber attack: Data of 9 million passengers 'obtained' by hackers as warning issued

Manchester, Stansted and East Midlands Airports Hacked in Major Data Breach

Medical Device Manufacturer Boston Scientific Faces Cyberattack

Millions of customers hit by cyber attack on East Midlands Airport owner

Millions of customers' data accessed after cyber attack on Manchester Airports Group

Mirage2FA: The Phishing Service Turning a Stolen Microsoft 365 Cookie Into Full Account Takeover

Mobile networks expose IMEI and other phone data to attackers

mTrade Data Breach Exposes Social Security Numbers

NCC Group logs record July ransomware cases as AI rises

Nearly 700 rogue AI agents coordinated in the Hugging Face attack

Nearly nine million holidaymakers' data stolen after cyber attack on three UK airports - including Stansted and Manchester - with phone numbers, vehicle registrations and postcodes among seized data

New GPUThor Rowhammer Defeats ECC on NVIDIA RTX A6000 to Gain Host Root Access

Next.js Patches Critical AVIF and Windows Flaws Enabling Unauthenticated RCE

Nutex Health Data Breach - Hackers Gained Access to Network and Exfiltrated Data

OpenAI: Hugging Face Incident a “Warning Shot” to the World

OpenAI Report Explains How Its AI Agents Breached Hugging Face Systems

OpenAI reveals the true scale of AI cyberattack on Hugging Face

OpenAI Says Reward Hacking Drove AI Agents to Exploit Zero-Days and Breach Hugging Face

OpenAI, Anthropic, Warn of ‘Limited Window’ for AI Cyber Defense

Pan American Group Data Breach Exposes Social Security Numbers

Pan American Group discloses data breach after suspicious network activity

PaperCut warns of NG, MF flaw exploited in zero-day attacks

Passenger data stolen in Manchester Airports Group (MAG) data breach

Phishing scam targets Edmond Santa Fe High School

Pokémon Responds After Hacker Compromises Its X Account to Hawk MemeCoin

Poland Accuses Meta of Poor Handling of Scams and False Ads, Seeks €250 Million EU Fine

Police Arrest Two Alleged TeamPCP Members Linked to Shai-Hulud Attacks

Previously patched Citrix NetScaler flaw exploited in the wild (CVE-2026-8452)

Pro-Russian hackers claim cyberattack on Norway

Qilin Ransomware Gang claims Cyber Attack on U.S. ATF

Ransomware Attack on three UK Airports leads to Data Breach affecting 8.7 Million customers

Ransomware attacks hit 894 as AI boosts cyber crime

Ransomware Gang Qilin Claims To Have Hacked ATF - But Where’s the Proof?

Ransomware Hacker Uses AI to Plan Attacks and Compromises More Than 20 Organizations

Ransomware Hacker Uses AI to Plan Cyberattacks Against More Than 20 Organizations

Ransomware Operator Ran Cursor Agent Inside Ten Victim Networks

Rhodes, Young, Black & Duncan Data Breach Exposes Financial Info

Rockwood Data Breach Compromises Medical Information

Rogue Fabrication Data Breach Impacts 35,000 Individuals

Rookie Mistake: Hacker's Attachment to Screen Name Made Him Easy to Catch

Russia-Linked Cyber Espionage Clusters Use OAuth Phishing to Target U.S. and European Organizations

Russian Cyber Espionage Infrastructure Uses Evilginx and OAuth Phishing to Steal Accounts

Russian Hackers Claim ATF Breach, Agency Says Investigation Files Were Hit

Russian hackers unleashed Cursor AI agent to infiltrate nearly a dozen corporate networks

Russian Hackers Use Fake Google Drive and Diplomatic Lures to Steal Online Account

Russian-Speaking Hackers Told Cursor AI It Was a 'Test,' Then Used It To Attack Seven Companies

Secret Neighbor taken offline after hacker deletes player data and blackmails publisher

Slack and Teams phishing surges, Unit 42 finds

Spark RAT Targets Cambodia, Abuses Vulnerable OPSWAT Driver to Disable Security Tools

Stansted Airport cyber attack: Millions of passengers' details accessed by hackers

Stansted Airport data breach exposes customer contact details

Stansted Airport hit by cyber attack exposing customer data

Stansted Airport owner hit with cyber attack as millions of customers’ data stolen

Suspected TeamPCP hackers arrested over supply chain attacks

Swarms of OpenAI Agents Collaborated in Attack on Hugging Face

The Apollo Global Management Data Breach and the UNC6671 / Cordial Spider Campaign

The Hacker That Never Sleeps: AI Is Changing Cyberattacks

The notice regarding a personal data breach has taken effect

Three major UK airports are hit by cyber attack with millions of passengers affected

Three major UK airports hacked as 8.7 million customer records stolen in cyber attack

Three UK airports hit by cyber-attack with data of 8.7 million customers accessed

Travala Discloses Data Breach Exposing Customer Profile and Passport Details

Travala Reports Data Breach Exposing Customer Names, Emails and Hashed Passwords

Two alleged TeamPCP hackers arrested over global supply chain attacks

U.S. Dismantles Chinese Hacker Network Targeting Department of Justice (DOJ), Senate and NASA

UK Airports Hacked: Millions of Passengers’ Data Accessed in Major Cyber Attack

Unknown PaperCut NG/MF vulnerability is under active attack

US federal agency confirms data breach in wake of claims by ransomware group

US Probe into 850,000-File Breach at Kansas Water Infrastructure Firm

What to do if your personal information was exposed in a data breach

White House bans foreign-made equipment for power generation over cyber backdoor concerns

Why Ransomware Economics Favor Volume Over Prestige Attacks

Your AI agent can be hijacked just by visiting a website

📅 26th August

24 Malicious npm Packages Abuse Mirror Infrastructure to Host Obfuscated ClickFix Phishing Pages

24 Malicious npm Packages Abuse Trusted Mirrors to Host ClickFix Phishing Pages

100+ Internet-Exposed Water Systems Faced Cyberattacks Last Month

A Look Inside the Phishing Service Attacking Organizations

A massive phishing campaign has hit over 9,000 organizations worldwide

AI-Powered Balonx Sistema Phishing-as-a-Service (PhaaS) Harvests Credentials From Over 1,100 Banking Users

AI vulnerability discovery scores the highest impact of 20 emerging risks

AnonyMousKIT phishing service targets Apple credentials and Activation Lock

AnonyMousKIT phishing-as-a-service uses AI voice calls to steal iPhone passcodes

ATF confirms breach hours after Qilin ransomware gang claims US firearms agency

ATF hit by ransomware attack, Department of Justice (DOJ) says

Atlanta Law Giant Troutman Pepper Locke Hit by Breach, Faces 37,000-Person Suit

Average Cyber Insurance Losses Increase Despite Fewer Claims

Balonx Sistema Phishing-as-a-Service (PhaaS) Targets 20+ Mexican Banks With AI Vishing and Android RAT

Bogus recruiters go after high-value corporate credentials on mobile

Boston Scientific hit by massive cyber attack as shares plummet

Boston Scientific says cyberattack disrupted operations globally

CareCloud data breach now affects personal data of 3.75 Million patients

Carhartt data breach affects 12.9 Million, half of what ShinyHunters claimed

Carhartt data breach claims inflated by synthetic data, analysis finds

Carhartt’s ShinyHunters Breach Was Almost Half What It First Looked Like, Exposing 13 Million Emails - Here’s Why

Central Maine Healthcare Reaches $1.3 Million Settlement in Data Breach Lawsuit

Check Point Blocks Massive Debt-Relief Phishing Campaign Targeting 9,000+ Organizations

CISA Red Team Compromised Two Critical Infrastructure Orgs, One Detected Nothing

CISA Warns Agencies to Patch Actively Exploited Oracle WebLogic Proxy Flaw

Claude Opus 4.6 Bypasses Gym Booking Limit, Cancels Other Users' Reservations in Tests

Comcast Paying $117,500,000 To Settle Data Breach Claims Affecting 31,700,000 Customers

Critical Avada WordPress theme flaw enables zero-click RCE

Critical Gitea RCE Actively Exploited as Reported Attack Drops Miner-Like Payload

Critical Gitea vulnerability now exploited in the wild (CVE-2026-60004)

Cyber-attack on oil parastatal exposes Malawi vulnerabilities

DDoS Attack Hits Norwegian Government Services

Fake Apple Support AI Calls Target Stolen-Device Owners for Passcodes and 2FA Codes

Fake Cloudflare CAPTCHA Campaign Abuses npm Mirrors to Push ClickFix Phishing

Fake Grand Theft Auto 6 (GTA 6) Demo Spreads Malware: How to Spot the Scam

FBI Disrupts China-Linked QTFY Infrastructure Used to Steal Data From U.S. Organizations

FBI disrupts proxy network enabling Chinese espionage operations

Federal Reserve, NASA and Department of Justice (DOJ) among victims of Chinese state-sponsored hacker group, FBI says

Former Los Angeles County Museum of Art (LACMA) Employee Sues Over Recently Announced Data Breach

Four in Five AI Tools Run with No IT Oversight, New Research Finds

Global Crackdown on West African Crime Networks Leads to 58 Arrests

Hack of Water Sector Supplier in Kansas Draws FBI Scrutiny

Hackers Abuse Legitimate RMM Tools in 46-Country Phishing Campaign to Gain Remote Access

Hackers claim massive 4TB haul from AI firm serving OpenAI, Google, and Meta

Hackers now exploit critical Gitea flaw in code injection attacks

Hackers target Microsoft SharePoint RCE chain with Proof-of-Concept (PoC) exploit

Hackers Targeted Over 100 Internet-Exposed Water Systems

Health Systems Warn Patients About Epic MyChart Patient Portal Phishing Scam

India tops APAC in mobile threat detections as attacks turn more targeted

Interpol Operation Jackal IV Identifies 263 Cybercrime Suspects

Ireland: Cyber attack delays sports grants for Kilkenny but clubs told 'don't panic!'

'It is significant, and it’s something many organisations haven't accounted for': The phishing threats hiding in your calendar invites

Jabaroot, the hacker who has dealt the biggest blow to Morocco

July was the worst month for ransomware victim claims in 2026 - or was it?

Los Angeles County Museum of Art (LACMA) data breach exposes customer and employee information

Massive security flaws plague Ubiquiti’s UniFi ecosystem: 22 vulnerabilities, 21 critical

Medical device firm Boston Scientific says cyberattack has disrupted shipment processes

Meta adds three new features to keep WhatsApp accounts secure

Mirage2FA Phishing Kit Bypasses MFA to Hijack Microsoft 365 Sessions, Targeting 3,500+ Organizations

New 'AnonyMous' phishing campaign targets iPhone users with fake AI Apple support calls

New GPUThor attack defeats NVIDIA ECC protection for root access

Newly SLEEPWALKER Backdoor Waits for One Crafted Packet, Then Runs Its Own Bytecode

Nimbus Manticore Expands Toolset With TWOSTROKE-Like Backdoor and SSH Tunneler

NovaCookies Campaigns Abuse Genuine Docusign Notifications to Steal Microsoft 365 Sessions

Nutex investigating data breach after unauthorized access to servers

Paylogix TPA data breach puts benefits brokers on notice

Pro-Russian hackers claim responsibility for major cyberattack on Norway’s public digital services

Ransomware Hits 2026 Peak: Is Your Channel Ready for AI-Driven Attacks?

Ransomware surges as criminals deploy AI tools

Rockstar breaks silence after Grand Theft Auto 6 (GTA 6) is plagued with leaks and hacker warnings ahead of extended look

Russian hacker group claims responsibility for cyberattack targeting Norway

Sensitive Information Exposed in Nutex Health Data Breach

Taco Bell, and Pizza Hut operator discloses breach after suspicious network activity

TeamSystem Data Breach Exposes Customer IBANs and Accounting Records

This Android toolkit turns selfies into live photos to hijack KYC verification

Tortoiseshell Expands Malware Toolset With New Backdoor, SSH Tunnel

Ubiquiti patches three max severity security vulnerabilities

Unpatched Kaltura mwEmbed Flaws Could Let Remote Attackers Read Files and Run Code

US Navy tells 600,000 sailors and staff to scrub socials of military ties

US water sector supplier hack draws FBI scrutiny as Iran-linked cyber concerns grow

Your Firewall Benchmarks Are Reassuring, That's the Problem

📅 25th August

24 npm Packages Abuse unpkg Mirrors to Host Fake Cloudflare CAPTCHA Pages

24,700 Fake Debt Relief Emails Target Over 9,000 Organizations in 14 Days

A Malicious Webpage Could Poison Your Local AI Model Behind NVIDIA NemoClaw

Actively Exploited Oracle WebLogic Flaw Lets Unauthenticated Attackers Access Critical Data

AI supply chain risk is showing up in developer workflows first

Alabama subpoenas OpenAI over alleged data breach

Amazon’s New Order Confirmation Emails Seen Boosting Phishing Risk

AnonyMousKIT PhaaS uses voice AI agents to phish iPhone passcodes

Apollo Global Management data breach exposes personal information

Apple rescues Hide My Email feature from the privacy scrap heap

ASOS Warns Customers of Data Breach Following Credential-Based Account Takeovers

Attackers Target miniOrange SAML Flaws That Can Grant WordPress Admin Access

Australia Warns of Active Exploitation of Critical TeamCity Server Flaw

Australia’s transport sector under-prepared for risk of cyber attack

Bankwest: Phishing accounting for majority of banking scam activity

Can You Hear Me Now? Show Me Your Papers

Charlotte-based parking company data breach impacts more than 61,000 North Carolinians

Check Point Blocks Large-Scale Debt-Relief Email Phishing Campaign Targeting More Than 9,000 Organizations

Chinese Hackers Accelerate Cyberattacks Using Low-Cost AI Tools

CISA and the FBI Are Sounding the Alarm on Ransomware

E4del and PINHOLE RATs Turn FTP Banners Into Dead Drops for Malware Commands

Employee benefits platform Paylogix says hackers stole financial and health data

Epic, American Hospital Association (AHA) warn of phishing schemes in MyChart

Epic’s MyChart phishing wave is pushing patient-access teams to treat portal identity as a security perimeter

Fake Minecraft Clients Deliver WeedHack Malware Despite Infrastructure Takedown

Fake OpenAI Codex download tricks macOS users into installing malware

Fake Recruiter Scams Target Corporate Credentials on Mobile

FBI, CISA, and HHS Warn about Medusa Ransomware Targeting Over 500 Critical Infrastructure Organizations

Gig Harbor council member’s email locked down after suspicious message Tuesday

Hacker Group Claims Identities Of 70,381 Moroccan Agents

Hackers abuse npm mirrors to host phishing redirect pages

Hackers breached over 270 Zimbra servers in ongoing attacks

Hackers litter NPM with packages that don’t infect computers - they host phishing pages instead

Health data of North Dakota developmental disability clients potentially exposed in phishing attack

Hospital operator Nutex Health says data stolen in cyberattack

How Much Does a Data Breach Cost? IBM’s 2026 Report Puts the US Average at $11.5 Million

INTERPOL crackdown on West African crime rings uncovers troubling new trend

Iran-linked cyber attack on UK power plant was inevitable

Join a lobby, get pwned: critical remote code execution bug found in Konami’s Metal Gear Online 3

Large DDoS attack knocks Norwegian public services offline

Ledger Fixes Ethereum App Flaw as Disclosure Timeline Is Disputed

Los Angeles County Museum of Art (LACMA) data breach last year exposed social security and medical data

Malicious Firefox extensions steal your crypto wallet seed phrases and browser credentials

Marimo Notebook Flaw Could Run MCP Commands Before Cells Execute in Edit Mode

Massive DDoS attack disrupts Norway’s government digital services

Microsoft Teams’ New Policy Lets Admins Automatically Block Meeting Bots

Microsoft’s and Meta’s data center may have been breached in $13 million extortion attempt

Mirage2FA Surge Hits 4,500 US and EU Companies, Abusing Microsoft 365 Login Flows

North Carolina: Latest Charlotte data breach ensnares about 73,000 Preferred Parking customers

NVIDIA NemoClaw Flaw Lets Malicious Websites Hijack OpenClaw AI Agents

PavinLoader Is Everywhere: One Malware Family Is Powering ClickFix Scams, Fake Games, and Fake Software Downloads

Phishing Ring That Even Intercepted 112 Emergency Calls Busted for Stealing 10 Billion Won Using Check Cards as Bait

Phishing, data breaches surge in the Philippines in first half of 2026

Police arrests dozens of suspects in global cybercrime crackdown

RecruitTrap Scam Uses Fake Interview Invites to Steal Corporate Logins

ReliaQuest Rejects Compromise Claims After ShinyHunters Incident

ShinyHunters taunts ReliaQuest after its own employee falls for social engineering attack

SickKids Data Breach Exposes Employee and Job Applicant Records

Sometimes Even a Great Cybersecurity Pedigree Can’t Save a Pedestrian Business Model

South Korea: Police bust China-based phishing ring with local police

South Korea: Voice Phishing Gang Arrested for Stealing 10.2 Billion Won via Call Interception

Surgeons Choice Data Breach Exposes Social Security Numbers

That fake Grand Theft Auto VI demo is actually just malware

The Grand Theft Auto VI (GTA VI) leaks are breaking the internet. Security researchers have seen this before

The Health Trust Data Breach: Personal and Health Information Exposed

The Netherlands: New phishing scam alert - Fake email from iDeal-Wero doing the rounds

Third-Party Website Scripts Can Become a Hidden Payment-Skimming Risk

TikTok phishing: How to spot fake login and verification pages

Traditional Security Training is Obsolete in the Age of AI

U.S. Sanctions Iran-Linked Hackers Behind Critical Infrastructure Breaches

UK government seeks powers to secretly block risky tech suppliers

UK seeks supply chain security overhaul following Iran-linked cyber attack

Unpatched Zimbra servers are falling to CVE-2026-73570 attacks

US cities rush to replace Flock with Verkada cameras: Are they any better?

US jails ATM thief behind $3.5 Million heist amid investigation into violent cybercrime conspiracy

US sanctions Iranian cyber actors as UK discloses power plant attack

US Sanctions Mabna Institute Hackers for Iranian Cyber-Attacks

US Treasury Launches Major Campaign to Disrupt Iran’s Global Networks

WhatsApp Adds Multiple Passkeys for Phishing-Resistant Sign-Ins Across iOS and Android

WhatsApp adds stronger two-step verification, multiple passkeys

WhatsApp tightens account security with stronger two-step verification and more

When Cyber Meets Physical: Rethinking Data Management for a New Threat Landscape

Your stolen iPhone can now call you back - pretending to be Apple Support

Zero-click email attacks: What businesses need to know

ZeroTokens Phishing Platform Steers Attacks in Real Time

📅 24th August

Actively Exploited Zimbra Flaw Lets Unauthenticated Attackers Execute Shell Commands

After targeting water infrastructure in US, report claims Iran-linked hackers behind cyber attack on power plant in UK

Alibaba’s AliExpress caught tracking user audio systems

Android car head units infected with proxy botnet malware through built-in software updaters

Apollo Confirms Data Breach Amid Cyberattacks Targeting Financial Firms

Apollo Confirms Data Breach as Wall Street Hacking Wave Widens

Apollo Global hit by hacker attack, personal data leaked?

Apollo Global reveals data breach after hackers target financial firms

Associated Endocrinologists Data Breach Affects 4,979 Individuals

Barracuda Networks Analysis Finds 20 Vulnerabilities on Average Per Web App

British energy firms put on alert

California Department of Financial Protection and Innovation (DFPI) orders mortgage company to pay $825K for alleged cybersecurity failures preceding ransomware attack

Canvas Ransomware Attack Locks Out University of Manchester Students

Central Maine Healthcare reaches $1.3 million settlement agreement for data breach

Chinese hacker who broke into stock account of BTS's Jungkook gets 20 years

CISA orders urgent patching of actively exploited Zimbra flaw

CISA’s logging guidance works beyond government

“Cognizable damage” required for data breach claims, Massachusetts appeals court says in a first

Connecticut Medicaid data breach exposes payment information of 41,000 HUSKY Health members

Critical Keycloak Password Reset Flaw Could Let Unauthenticated Attackers Take Over Any Account

Critical Node.js Sandbox Flaw Exposes AI Agents to Host Code Execution

Critical WordPress Pods Flaw Lets Unauthenticated Attackers Gain Admin Access

Cudy WR3000 Router Flaws Can Be Chained to Gain Root Access

Cyber attack on North Wales mental health charity sees sensitive data accessed

Cybersecurity job ads demanding AI skills double in a year

Data breach notifications in Australia rise by 8%

Data breach reported by Grafton City Hospital officials

Data Breach Settlement Deadline Nears for Central Maine Healthcare Patients

Doubloon Dredger Abuses Notion to Harvest Authentication Tokens

Does AI Create New Cybersecurity Risks? What Actually Changes

Egypt’s Financial Regulatory Authority (FRA) pursues criminal charges and suspends consumer finance firm over data breach

Employee Databases from Multiple Fortune 500 Companies Affecting 3.6 Million Employees Listed on the Dark Web

Encrypted Prompts Defeat Grok and Gemini Guardrails; Chat Histories Stolen

Experts Weigh in on the Medusa Ransomware Gang

Fake bank websites play dead to evade security scanners

Fake Codex Download Uses Google Sites to Deliver macOS Malware

Fake Minecraft Clients Spread WeedHack Malware on Windows to Steal Passwords

FBI, HHS warn against Medusa ransomware

Genesis Healthcare Data Breach Exposes Sensitive Patient Info

German Digital Rights Group Takes Aim at Meta Glasses in Criminal Complaint

Golf Canada Breach Exposes Nearly 570,000 Accounts, the Governing Body Isn’t Talking

Google and Bing Search Results Used to Deliver Hidden Banking Phishing Pages

Google Threat Intelligence Group (GTIG), Doppel & Gigamon: The Apollo Data Breach Explained

Hacker group claims 6 million Bangladeshi CVs for sale on dark web

Hackers infecting Android car systems to build proxy botnet

Hackers Poison Google and Bing Results to Deliver Cloaked Banking Phishing Pages

Hackers target WordPress sites in miniOrange auth bypass attacks

Hackers Use Chameleon SEO Poisoning to Hide Banking Phishing Pages From Security Scanners

Health systems warn of coordinated phishing targeting Epic’s patient portal

Health systems warn patients of MyChart phishing scam

Hospitals warn of phishing scam targeting 'MyChart' patient portal

How email masking prevents phishing & spam attacks across the workforce

iAuthFlow v2: The $10,000 Phishing Toolkit That Survives Your Password Reset

Indian man who fled US arrested on charges he helped scammers siphon $7.5 million from the elderly

Integrative Emergency Services (IES) Data Breach Exposes Medical Records of Patients

Iran hackers vow to target US allies after 4-day UK power plant attack

Iran-linked cyber attack reportedly shuts UK energy generator for four days

Iranian Cyber Attack: Are UK Power Plants Safe from Hackers?

Iranian cyber attack on power plant was "warning shot" amid threat to critical British national infrastructure

Iranian cyber attack on UK power plant ‘should concern every organization responsible for keeping this country running’

Iranian Cyberattack Shuts Down UK Power Generator

Iranian-linked cyber attack exposes UK energy flaws

Iranian-Linked Hackers Disrupt UK Energy Infrastructure in Four-Day Attack

Ireland: Survey finds consumers receive more than five scam or phishing communications per month

Kern Psychiatric Data Breach Exposes Social Security Numbers and Medical Info

Latvia: The hacker who attacked the Road Traffic Safety Directorate attempted to penetrate other government systems

Latvian Road Traffic Safety Directorate (CSDD) was late to report cyber attack

Medical Data Breach on Medical Technology Firm MyDr Impacts Half of Polish Population

Medusa Ransomware Targets Healthcare Sector Through Unpatched Software Vulnerabilities

Microsoft Reverses Its Own ‘Exploitation’ Warning on Entra ID Flaw CVE-2026-69836

Microsoft Teams Phishing Deploys New SynkLoader Malware to Steal Windows Passwords

Monitor, microphone, webcam, light – all gadgets can be hacked, researcher shows

MyChart warns of phishing schemes using fraudulent emails, other messages

National Institute of Standards and Technology (NIST) Warns of Unique Security Risks in Multi-Cloud Environments

New Guidance Helps Businesses Verify Quantum-Safe Hardware Claims

North Dakota Health and Human Services (HHS) warns Developmental Disabilities clients of data breach after phishing attack

North Dakotans receiving developmental disability services affected by phishing attack on state

Operation QUICSILVER Targets Myanmar Government and IT with QUICAgent Backdoor

Organizations turn to AI as data breach costs jump 12%

Origin Energy cyber attack traced to former Accenture employee in Manila

Oz Hair & Beauty hit by data breach, customer names and contact details exposed

Patient data was breached in AnMed attack

Personal Information Exposed in Apollo Global Data Breach

Phishing Emails Impersonating South Korean Government Agencies Target Naver Accounts - 'Do Not Click Links'

Practical Privacy Habits That Reduce Everyday Exposure

Preferred Parking breach exposes credit card data

Premier Medical Group Data Breach Exposed Sensitive PHI and PII

Private equity giant Apollo confirms data breach saw personal info stolen

Ransomware Affiliate Poses as Recovery Firm to Steal Ransom Payments

Ransomware attackers are zeroing in on mid-market companies

Ransomware Is Changing Even When Crypto Payments Fall

Ransomware’s Real Target Isn’t the Giants. It’s the Squeezed Middle

ReliaQuest confirms failed data-theft attack after ShinyHunters breach

ReliaQuest Confirms ShinyHunters Hack, but Says Impact Was Limited

ReliaQuest Says Device Trust Held Against Phishing Attack

Researchers Uncover Thousands of Leaked Amazon Web Services (AWS) Keys

Scammers exploit hype around Grand Theft Auto 6 (GTA 6), post fake pre-release build to spread malware

Shell Confirms Investigation Following Cl0p Ransomware Data Theft Claims Tied to PTC Windchill Zero-Day

ShinyHunters Claims CyrusOne Breach, Demands $13 Million for 640+ GB of Data

Social Engineering Scheme Led to Apollo Data Breach

South Korea: Loan-Baited Accounts Launder Voice Phishing Proceeds

South Korea: Phishing Emails Impersonate Government Agencies to Target Naver

South Korea: Phishing emails mimic Korea agencies to steal Naver accounts, Naver warns

South Korea: Phishing Emails Targeting Naver Accounts Prompt Warning

South Korea: Seoul bike users sue after massive Ttareungi data breach

South Korea: Seoul Bike-Share Data Breach Victims Seek 300,000 Won Each

South Korea Data Breach Exposes Startup Applicants’ Personal Data

Southern Illinois University (SIU) Data Breach: Addresses and Social Security Numbers Exposed

Suspected Iran-linked attack knocked UK power plant offline for days

SynkLoader Malware Spreads Through Microsoft Teams Phishing and Steals Windows Passwords

The Asthma Center Data Breach: PHI and PII Exposed

The Outsized Shadow: Why 5% of AI Users Are Your Biggest Security Risk

Town of Pittsboro Alerts Public to Phishing Scam

Town of Pittsboro Alerts Residents to Phishing Scam Targeting Developers

Tricky 'SynkLoader' Multitool May Herald Ransomware

UAT-10147 Uses AI to Scale Server Attacks, Deploys SPECTRE With EDR Bypass and Linux Rootkit

UK briefs energy chiefs after Iran-linked cyber attack reports

UK energy alert issued after Iranian cyber attack on power plant

UK informs energy chiefs on Iran cyber attack

UK power plant cyber attack

United Language Group Data Breach Exposes Social Security Numbers

Unpatched Calix flaw lets hackers bypass NAT to expose internal devices

Wake-Up Call for Critical National Infrastructure (CNI) After Iranian Attack Shuts Down UK Power Plant

Weedhack Malware Spreads via Fake Minecraft Clients and SEO Poisoning

Westco Motors Cairns suffers alleged ransomware attack

What The Ransomware Business Model Means For Your Risk Strategy

WordlistLoader Delivers Amatera via ClickFix, SynkLoader Phishes Windows Passwords