Welcome to this week's Data Breaches Digest, a catalogue of links concerning Data Breaches and Cyber Security that were published on the Internet during the period between 24th August and 30th August 2026.📅 24th August
Actively Exploited Zimbra Flaw Lets Unauthenticated Attackers Execute Shell Commands
After targeting water infrastructure in US, report claims Iran-linked hackers behind cyber attack on power plant in UK
Alibaba’s AliExpress caught tracking user audio systems
Android car head units infected with proxy botnet malware through built-in software updaters
Apollo Confirms Data Breach as Wall Street Hacking Wave Widens
Apollo Global hit by hacker attack, personal data leaked?
Apollo Global reveals data breach after hackers target financial firms
Barracuda Networks Analysis Finds 20 Vulnerabilities on Average Per Web App
British energy firms put on alert
California Department of Financial Protection and Innovation (DFPI) orders mortgage company to pay $825K for alleged cybersecurity failures preceding ransomware attack
Canvas Ransomware Attack Locks Out University of Manchester Students
Central Maine Healthcare reaches $1.3 million settlement agreement for data breach
CISA orders urgent patching of actively exploited Zimbra flaw
CISA’s logging guidance works beyond government
“Cognizable damage” required for data breach claims, Massachusetts appeals court says in a first
Connecticut Medicaid data breach exposes payment information of 41,000 HUSKY Health members
Critical Keycloak Password Reset Flaw Could Let Unauthenticated Attackers Take Over Any Account
Critical Node.js Sandbox Flaw Exposes AI Agents to Host Code Execution
Critical WordPress Pods Flaw Lets Unauthenticated Attackers Gain Admin Access
Cudy WR3000 Router Flaws Can Be Chained to Gain Root Access
Cyber attack on North Wales mental health charity sees sensitive data accessed
Cybersecurity job ads demanding AI skills double in a year
Data breach notifications in Australia rise by 8%
Data breach reported by Grafton City Hospital officials
Data Breach Settlement Deadline Nears for Central Maine Healthcare Patients
Doubloon Dredger Abuses Notion to Harvest Authentication Tokens
Does AI Create New Cybersecurity Risks? What Actually Changes
Experts Weigh in on the Medusa Ransomware Gang
Fake bank websites play dead to evade security scanners
Fake Codex Download Uses Google Sites to Deliver macOS Malware
Fake Minecraft Clients Spread WeedHack Malware on Windows to Steal Passwords
Genesis Healthcare Data Breach Exposes Sensitive Patient Info
German Digital Rights Group Takes Aim at Meta Glasses in Criminal Complaint
Golf Canada Breach Exposes Nearly 570,000 Accounts, the Governing Body Isn’t Talking
Google and Bing Search Results Used to Deliver Hidden Banking Phishing Pages
Google Threat Intelligence Group (GTIG), Doppel & Gigamon: The Apollo Data Breach Explained
Hacker group claims 6 million Bangladeshi CVs for sale on dark web
Hackers infecting Android car systems to build proxy botnet
Hackers Poison Google and Bing Results to Deliver Cloaked Banking Phishing Pages
Health systems warn patients of MyChart phishing scam
Hospitals warn of phishing scam targeting 'MyChart' patient portal
How email masking prevents phishing & spam attacks across the workforce
iAuthFlow v2: The $10,000 Phishing Toolkit That Survives Your Password Reset
Iran-linked cyber attack reportedly shuts UK energy generator for four days
Iranian Cyber Attack: Are UK Power Plants Safe from Hackers?
Iranian cyber attack on power plant was "warning shot" amid threat to critical British national infrastructure
Iranian cyber attack on UK power plant ‘should concern every organization responsible for keeping this country running’
Iranian-linked cyber attack exposes UK energy flaws
Iranian-Linked Hackers Disrupt UK Energy Infrastructure in Four-Day Attack
Ireland: Survey finds consumers receive more than five scam or phishing communications per month
Kern Psychiatric Data Breach Exposes Social Security Numbers and Medical Info
Latvia: The hacker who attacked the Road Traffic Safety Directorate attempted to penetrate other government systems
Latvian Road Traffic Safety Directorate (CSDD) was late to report cyber attack
Medical Data Breach on Medical Technology Firm MyDr Impacts Half of Polish Population
Medusa Ransomware Targets Healthcare Sector Through Unpatched Software Vulnerabilities
Microsoft Teams Phishing Deploys New SynkLoader Malware to Steal Windows Passwords
Monitor, microphone, webcam, light – all gadgets can be hacked, researcher shows
National Institute of Standards and Technology (NIST) Warns of Unique Security Risks in Multi-Cloud Environments
New Guidance Helps Businesses Verify Quantum-Safe Hardware Claims
North Dakota Health and Human Services (HHS) warns Developmental Disabilities clients of data breach after phishing attack
Operation QUICSILVER Targets Myanmar Government and IT with QUICAgent Backdoor
Organizations turn to AI as data breach costs jump 12%
Origin Energy cyber attack traced to former Accenture employee in Manila
Oz Hair & Beauty hit by data breach, customer names and contact details exposed
Patient data was breached in AnMed attack
Personal Information Exposed in Apollo Global Data Breach
Preferred Parking breach exposes credit card data
Premier Medical Group Data Breach Exposed Sensitive PHI and PII
Private equity giant Apollo confirms data breach saw personal info stolen
Ransomware attackers are zeroing in on mid-market companies
Ransomware Is Changing Even When Crypto Payments Fall
Ransomware’s Real Target Isn’t the Giants. It’s the Squeezed Middle
ReliaQuest confirms failed data-theft attack after ShinyHunters breach
ReliaQuest Says Device Trust Held Against Phishing Attack
Researchers Uncover Thousands of Leaked Amazon Web Services (AWS) Keys
Scammers exploit hype around Grand Theft Auto 6 (GTA 6), post fake pre-release build to spread malware
Shell Confirms Investigation Following Cl0p Ransomware Data Theft Claims Tied to PTC Windchill Zero-Day
ShinyHunters Claims CyrusOne Breach, Demands $13 Million for 640+ GB of Data
Social Engineering Scheme Led to Apollo Data Breach
South Korea: Loan-Baited Accounts Launder Voice Phishing Proceeds
South Korea: Phishing Emails Impersonate Government Agencies to Target Naver
South Korea: Phishing emails mimic Korea agencies to steal Naver accounts, Naver warns
South Korea: Phishing Emails Targeting Naver Accounts Prompt Warning
South Korea: Seoul bike users sue after massive Ttareungi data breach
South Korea: Seoul Bike-Share Data Breach Victims Seek 300,000 Won Each
South Korea Data Breach Exposes Startup Applicants’ Personal Data
Suspected Iran-linked attack knocked UK power plant offline for days
SynkLoader Malware Spreads Through Microsoft Teams Phishing and Steals Windows Passwords
The Asthma Center Data Breach: PHI and PII Exposed
The Outsized Shadow: Why 5% of AI Users Are Your Biggest Security Risk
Tricky 'SynkLoader' Multitool May Herald Ransomware
UAT-10147 Uses AI to Scale Server Attacks, Deploys SPECTRE With EDR Bypass and Linux Rootkit
UK briefs energy chiefs after Iran-linked cyber attack reports
UK power plant cyber attack
Wake-Up Call for Critical National Infrastructure (CNI) After Iranian Attack Shuts Down UK Power Plant
Westco Motors Cairns suffers alleged ransomware attack
What The Ransomware Business Model Means For Your Risk Strategy
WordlistLoader Delivers Amatera via ClickFix, SynkLoader Phishes Windows Passwords
Welcome to DBD. On March 8th 2026, DBD celebrated it's sixth anniversary and
Welcome to last week's ROC Report, an exclusive summary of Ransomware Operator's global victims that were claimed during the period between 10th August and 16th August 2026, kindly assisted by our partners.
