Editor's Message

Welcome to DBD. On March 8th 2026, DBD celebrated it's sixth anniversary and PRiSM celebrated it's third anniversary. Both projects have made a huge impact on my life and I'd like to thank each and everyone of you who have supported me, with special thanks to those individuals and communities who have helped me build up my knowledge on cybercrime and ransomware over the years. Thanks again for all your continued support. Stay safe. :)


“Data Breaches Digest and its PRiSM portal provide Dentons Global Security Team with valuable insights into the ransomware landscape, from the latest incidents to trends over time, as well as the ability to customize visual analytics. Timely reports and tracking by Data Breaches Digest help inform cyber intelligence for the world’s largest law firm and thus our cybersecurity posture across more than 80 countries worldwide.”
Dentons Senior Analyst, Washington D.C.



Monday, 15 June 2026

Data Breaches Digest - Week 25 2026

Welcome to this week's Data Breaches Digest, a catalogue of links concerning Data Breaches and Cyber Security that were published on the Internet during the period between 15th June and 21st June 2026.


17th June

3 Recently Patched Fortinet FortiSandbox Vulnerabilities in Hacker Crosshairs

7-Year-Old OpenBSD Flaw Enables Complete PAP Authentication Bypass

15 Malicious JetBrains Plugins Caught Stealing DeepSeek, OpenAI API Keys

24 billion records, including usernames and passwords, exposed in colossal data leak: What does that mean for you?

144 Mastra npm Packages Compromised via Hijacked Contributor Account

Android Banker Rokarolla Uses Fake Overlays to Steal PINs, Passwords, and Crypto Wallet Data

Apple makes “Hide My Email” easier to block, raising privacy concerns

Australia: NSW government pours cold water on ransomware claims

Bluekit Phishing-as-a-Service (PhaaS)

Chinese hackers behind massive AI-powered phishing network that stole millions of cards

CISA Issues Alert on Oracle PeopleSoft Vulnerability Exploited by Ransomware Groups

CISA orders feds to patch max severity Joomla plugin flaw by Friday

CISA Warns of Actively Exploited Joomla JCE Flaw Allowing PHP Code Execution

Critical Chrome Vulnerabilities Enable Arbitrary Code Execution Attacks

Critical Fortra Access Manager Flaw Exposes Systems to Command Injection

Critical LiteLLM Flaw Enables Authentication Bypass via Host Header Injection

Critical NVIDIA NeMo Vulnerability Enables OS Command Injection

Cyber insurance delivers meaningful financial protection, with a majority of data breach and first-party losses covered

Data Breach Exposes Personal Information of 137,000 School Staff at Infinite Campus

Data leak fears after ransomware attack hits Hong Kong’s Kee Wah Bakery

Deno-Based Malware Abuses CloudFront WebSocket C2 for Remote Access and Internal Pivoting

DragonForce Exploits Microsoft Teams Relays via Backdoor.Turn

DragonForce Ransomware Group Hid Inside U.S. Firm for Two Months Using Microsoft Teams Relays

ErrTraffic ClickFix Framework Abuses Compromised WordPress Sites to Deliver Infostealers

EU Security Experts to Support Ukrainian Organizations in Case of Cyber-Attacks

Experts analyse University of Nottingham cyber-attack

FBI warns Microsoft 365 users of dangerous Kali365 phishing scam: How it works and how to stay safe

FIFA World Cup API Authorization Bug Let Anyone Hijack the Live TV Stream

Fifteen JetBrains Marketplace Plugins Found Stealing API Keys

FishMonger Uses TCP, UDP, and WebSocket C2 Channels in SprySOCKS Windows Attacks

Frontier AI Models Point to a Shift Defenders Are Not Ready For

Ghostwriter Hackers Abuse Gmail Admin-Themed Emails to Steal Credentials and 2FA Codes

GitHub dismissed security reports on flaws now exploited by supply-chain worm, researchers say

Google Lawsuit Cites 9,000 Fake Websites Linked to Phishing Operation

Google sues Chinese AI scam ring over fake texts and phishing sites

Hacker group claims 1TB data theft from pharmaceutical giant Novo Nordisk

Hackers Abuse SheetBest API to Exfiltrate Banking Credentials Into Google Sheets

Hackers Claim 1TB Data Theft from Wegovy and Ozempic Maker Novo Nordisk, Demand $25 Million

Hackers Compromise 140+ Mastra npm Packages to Steal Credentials

Hackers Use Potemkin Loader to Deliver RMMProject RAT in ClickFix Intrusion

Holiday season is here - but watch out, hackers are launching more phishing scams and attacks than ever before

How DragonForce Ransomware Hid in Plain Sight Using Microsoft Teams Infrastructure

Infinite Campus Breach Exposes 137,000 Staff Accounts - What Is A Data Breach?

INTERPOL Warns India Among Top Targets of Cyber Attacks, Deepfake Fraud and Ransomware

Kodak confirms data breach claimed by ShinyHunters extortion gang

Kodak Confirms Data Breach Following ShinyHunters Claims of 2.2 Million Records Theft

Kodak investigates data breach after ShinyHunters cyberattack

Mackay Sugar cyber attack flagged as broader risk to Australia’s food supply chain

macOS Users Targeted by Sapphire Sleet Campaign Using Script Editor and Fake Update Dialogs

Malicious JetBrains Plugins Caught Harvesting AI API Keys from Developers

Malicious JetBrains Plugins Steal AI API Keys as Chrome Extensions Capture Chatbot Chats

Microsoft working on Defender patch for RoguePlanet zero-day

Microsoft working on patch for RoguePlanet Defender zero-day (CVE-2026-50656)

New INTERPOL report highlights escalating cyber threats across Asia and South Pacific

Nintendo employee Data reportedly stolen in Cyberattack and Hackers demand $2 Million Ransom

Nintendo faces $2 Million ransom after employee data breach via TinyPulse

Nintendo issues statement on data breach after hackers demanded $2 Million ransom

Nintendo Of America Dismisses Data Breach, Says No Personal Or Financial Info Were Accessed

Nintendo Officially Responds To $2 Million Hacker Ransom, Assures That No Customer Data Was Stolen

Novo Nordisk Data Breach: Cyber Extortion Group FulcrumSec Claims Theft of 1.3 TB of Sensitive Data After USD 25 Million Ransom Demand

Novo Nordisk Data Breach: FulcrumSec Demands $25 mn, Allege Theft of 1.3TB of Drug, Trial and Patient Data

Novo Nordisk hackers turn to private sale after Ozempic maker refuses $25 Million ransom demand

Novo Nordisk Hit by Data Breach: Hackers Steal One Terabyte, Company Refuses $25 Million Ransom

Novo Nordisk IT Security Incident Exposes Limited Patient and HCP Data

Oracle PeopleSoft Zero-Day Exploited in Ransomware Attacks, Warns CISA

Organizations’ Emergency Response Fails to Match Confidence Levels

Phishing falls as attackers turn to AI & encryption

Phishing scam targets Microsoft Teams, Outlook, and OneDrive

Ransomware Group Demands $2 Million From Nintendo After Getting Access to Sensitive Information

Ransomware group wants $2 million from Nintendo for Tinypulse hack, Nintendo says its aware

Researcher found a way to hijack FIFA World Cup streams but didn't touch it

SK Telecom (SKT), Korean National Police Agency identify 475 phishing crime servers with AI

That AI chatbot you secretly use at work? It may be a security risk

The checklist problem behind critical infrastructure cyber safety

The SOC’s visibility gap comes down to staffing

Troy Hunt (Have I Been Pwned) Flags 455,000 Emails in University Of Nottingham Data Breach

Ukraine can now tap EU cyber support during major attacks

Ukrainian pleads guilty to role in Conti ransomware group

Understanding OAuth Risks: From Device Code Phishing to Token Abuse

What Is A Data Breach? Infinite Campus Leak Hits 137,000 Staff Accounts

What is Kali365? FBI warns of Telegram-based phishing toolkit targeting Microsoft 365 users

16th June

84% of professional football clubs have become victims of attacks, now the World Cup 2026 could also become a hacker paradise

94% of Incidents Involve Anonymized Infrastructure. Teams Are Still Reactive

Amos Stealer Targets macOS Keychain Files and Browser Passwords

Anyone Can Be a Hacker Now: FBI Exposes Microsoft 365 Phishing Toolkit That Gives Amateurs the Keys to Cybercrime

Apple plans to change its Hide My Email privacy feature that could make it less effective

Asian firms scrutinise cyber insurance limits as ransomware losses climb

Attackers are exploiting FortiSandbox vulnerabilities

Attackers Exploit Three Fortinet FortiSandbox Flaws, One Patched Last Week

Australian Medical Council denies ransomware attack in wake of false claim

Australian mortgage broker Keylend warns of phishing incident following single account breach

Belarus-Linked UNC1151 Launches Gmail Phishing Campaign to Steal 2FA Codes

Boots impersonated in phishing scam targeting nearly 9 million shoppers

Bug in FIFA World Cup internal system gave anyone ability to modify TV stream

Cal Water investigates alleged hacker breach affecting Chico customer data

Canada: Ford government scolded agency over cyber attack. Documents show it knew a month earlier

Cardiac patients’ medical data stolen and held to ransom

China Spent Over a Year Inside U.S. Medical Research Networks - And Used Google’s Own Email Rules to Steal Data

China-Linked SprySOCKS Backdoor Expands to Windows with Driver-Based Stealth

CISA Flags LiteSpeed cPanel Plugin Flaw Exploited for Root Privilege Escalation

CISA warns of another cPanel plugin flaw exploited in attacks

Cisco discloses second exploited SD-WAN vulnerability in two weeks (CVE-2026-20262)

Cisco Releases Security Updates for Actively Exploited SD-WAN Manager Flaw

ClickFix Campaigns Expand Malware Delivery With New Loaders and Fake Update Lures

Compromised WordPress Site Uses Traffic Direction System to Target Windows Users With GULoader

Conti Ransomware Loader Developer Pleads Guilty in $150 Million Operation Riptide Case

Conti ransomware operator pleads guilty to wire fraud conspiracy and cyber extortion scheme

Cost of ransomware recovery too high? Here’s how to stop footing the bill

Council of Europe investigates ShinyHunters data breach allegations

Critical Fortinet FortiSandbox flaws now exploited in attacks

Critical Microsoft 365 Copilot Flaw Enables One-Click Data Theft

Critical SearchLeak Flaw in Microsoft 365 Copilot Exposed Sensitive Enterprise Data

Crypto scammers are sending couriers to victims’ homes to collect cash

Cyber attack on Southern Illinois Ob-Gyn hospital impacted thousands of patients

Cyber Crooks Hit Long Island Legal Aid, Expose Clients’ Sensitive Data

Cybercriminals mask malicious communications through Microsoft Teams relays

Cybercriminals Use The Quarry Toolkit to Launch IRS and SSA Phishing Attacks

Cybersecurity Awareness and Digital Forensics: Safeguarding the Digital World

Did Jaguar Land Rover (JLR) force brands to rethink cyber for their dealers?

Does the jailbreak that got Anthropic’s Fable 5 pulled exist in every AI model?

DragonForce Ransomware Exploited Microsoft Teams to Hide in Attack Against Major Company

DragonForce ransomware uses Microsoft Teams for covert command and control

Easterly Properties Data Breach: Social Security Numbers Exposed

Error in Breach Notice Leaves Victims Confused, Skeptical

Estonia to quarantine emails sent from Russian .ru domain before they reach government officials

EU Cybersecurity Act 2.0: When good regulation goes bad

EvilTokens: Phishing-as-a-Service (PhaaS) Kit Abusing OAuth Device Code Flow on Microsoft 365

Experts Say Google's Recent Scam Lawsuit May Have Limited Impact

Fake Microsoft Alerts Used to Deploy North Korean NarwhalRAT Malware

FBI Issues Urgent Scam Alert for Microsoft Teams, Outlook and OneDrive Users

FBI issues warning about Kali365 phishing scam that bypasses MFA in Microsoft 365 accounts

FBI Warns Courier Cash Pickups Are Driving Crypto Scams

FBI Warns Microsoft 365 Users About 'Kali365' Phishing Scam That Can Bypass MFA

FBI warns Microsoft 365 users of new Kali365 phishing scam: What it is, how it works

FBI warns Microsoft 365 users of phishing scam. How to stay safe

Federal Government dismisses report of cyber attack on Nigeria education management information system

Federal Trade Commission (FTC) warns of record $3.5 billion losses to imposter scams in 2025

Former LockBit and Qilin Operators Launch New RaaS Programs With AI-Based Victim Analysis

Gentlemen Ransomware targets Mackay Sugar in Australia

Ghana: Cyber Security Authority (CSA) urges Universities to strengthen cybersecurity following university of Nottingham cyber-attack

Ghana: Cyber Security Authority (CSA) warns educational institutions to strengthen cybersecurity following major UK data breach

Global Ransomware Incidents Increase 48% in May 2026

Google and FBI join forces to combat AI-generated phishing scams targeting smartphone users

Google Takes Legal Action Against Chinese Hackers Accused Of Weaponising Gemini AI For Massive Scam Operation

Google Vertex AI SDK Flaw Let Attackers Hijack Model Uploads via Bucket Squatting

Hacker: 'I Could Have Rickrolled the World Cup'

Hacker Group Demands $2 Million from Nintendo

Hackers Abuse Legitimate RMM Tools in The Quarry IRS and SSA Phishing Campaigns

Hackers Abuse Microsoft Teams to Conceal Ransomware Activity

Hackers boast of data dump involving 5.4 million Swedes, but there’s a catch

Hackers Hijack Terminal Server to Launch 8.9 Million-Email Boots Phishing Campaign

Hackers Use The Quarry PhaaS Ecosystem to Target U.S. Victims With IRS Phishing

Hackers Weaponize Microsoft Teams Relay to Hide Ransomware Traffic

Hacking group claims major hack of Novo Nordisk and attempted $25 million extortion

Hidden in Teams: DragonForce Attackers Weaponize Microsoft Teams Relays to Stay Hidden

How could the Ransomware Bill be diminished without compromising on Cybersecurity

How to protect yourself from online scams, phishing, and identity theft

India: Did hackers access ICAI's exam portal? Alleged data breach sparks concern days before Chartered Accountants (CA) Inter, Final results 2026

Infinite Campus Data Breach Exposes 137,000 Users Personal Details

Interlock and Rhysida Ransomware Operations Share Supper Backdoor and Malware Codebase

INTERPOL-Backed Operation Dismantles Decade-Long Phishing Platform, Arrests Alleged Administrator

Ireland: Cork man extradited to US pleads guilty to involvement in global ransomware fraud

Ireland: HSE Fined €300k Over Data Breach At Offaly Hospital

Ireland: HSE hit with €300,000 fine over Tullamore hospital patient data breach

iRhythm Discloses Data Breach After Threat Actor Claims Protected Health Information (PHI) Theft

iRhythm discloses data breach, says hackers stole patient info

iRhythm Hit by Cyberattack, Patient Data Stolen and Ransom Demanded

iRhythm Holdings Discloses Third-Party Data Breach via Social Engineering

iRhythm Technologies Data Breach Potentially Exposes Protected Health Information

Jackpocket Casino Data Breach Exposes Sensitive Personal Information

Kali365 Phishing Attack Bypasses Microsoft 365 MFA Using Real Login Pages, No Fake Site Needed

Kee Wah Bakery hit by ransomware attack; customer and staff data compromised

Mackay Sugar cyber attack claimed by The Gentlemen ransomware

Maine takes down its data breach notification portal after it is flooded by fake claims

Malicious JetBrains Marketplace plugins steal AI API keys from developers

Malwarebytes Finds Ad Scams Hidden in 40+ World Cup Streaming Sites

Microsoft 365 Device Code Phishing Campaign Bypasses Password Theft With Legitimate Login Flow

Microsoft 365 Users Targeted by Device Code Phishing Campaign Using OAuth 2.0 Flow

More than 40 World Cup streaming sites caught pushing scam ad networks

Murray County paid hackers $200K after ransomware attack in May

New Phishing Scam Targets Microsoft Teams, Outlook, and OneDrive

New Rokarolla Android Malware Steals PINs, SMS Codes, and Crypto Wallet Funds

New Rokarolla Android malware targets 217 banking, crypto apps

New Rokarolla Android Trojan Found Targeting 217 Crypto and Banking Apps

Nigeria: Federal Government Denies Cyber Attack on Education Data Platform

Nintendo Is ‘Aware Of An Issue’ Involving Third-Party Hack As Group Allegedly Tries To Ransom Employee Info For $2 Million

Nintendo says hacker group’s stolen employee data is ‘limited and old’ despite $2 Million ransom threat

Novo Nordisk Confirms Cyberattack Exposing Patient Data and AI Assets

Novo Nordisk Data Breach Exposes Clinical Trial Patient Data

Oak View Group Data Breach Exposes Social Security Numbers

OnionDrop Loader Uses Nation-State-Grade Evasion to Deliver LegionLoader, CGrabber, and Vidar

OptinMonster Plugin Flaw Exposes 1.2 Million WordPress Sites to Attacks

Over Two-Thirds of Security Pros Say Cyber Is Getting Harder

Ozempic maker Novo Nordisk hit with $25 million ransom demand after claimed data breach

People’s Republic of China (PRC)-Linked Hackers Exploit REDCap Servers to Target US Research Institutions

Phishing No Longer Looks Wrong: What Security Leaders Should Do Next

Phishing scam victim loses $3,456 claim against bank after failing to act on notification alerts

Planning a trip? Fake travel sites are multiplying this summer

Ransomware Ecosystem Consolidates Around LockBit Alumni, Qilin, Hyflock, and The Gentlemen

Ransomware gang abuses Microsoft Teams relays to hide malicious traffic

Reform Wales faces data breach questions after Tory members receive party emails

Rockstar Games Targeted by ShinyHunters in Massive Cloud Data Breach

Rokarolla Trojan Combines Banking Fraud With Device Surveillance

Samsung boosts Galaxy security, blocks malicious apps and scam calls

Samsung Electronics boosts Galaxy security, blocks phishing apps from installation to execution

Samsung to Block Execution of Phishing Apps on Future Galaxy Devices

Scam Alert: FBI issues warning for Teams, Outlook, OneDrive users

ShinyHunters Claims 297 GB Council of Europe Data Breach

ShinyHunters Claims Council of Europe HR Data, Threatens Leak

ShinyHunters claims theft of 2.2 million records from Kodak in ransomware ultimatum

ShinyHunters exploited Oracle PeopleSoft flaw to victimise hundreds of organisations

ShinyHunters publishes data stolen from school software provider Infinite Campus, 137K users exposed

Shocking New Phishing Scam Lets Hackers Break Into Outlook and Teams Without Stealing Login Details

Silent Ransom Group Threatens US Law Firms With LEAKEDDATA Data Leak Site

SimpleHelp RMM flaw could give attackers full access to managed endpoints (CVE-2026-48558)

Singapore: Man lost S$3,800 in card phishing scam after clicking on TikTok ad; tribunal finds him liable, not bank

South Korea: Police Arrest 23 in Cambodia-Linked Phishing Crypto Laundering Crackdown

South Korea: Police Bust Phishing Money-Laundering Ring Using Tether

South Korea Busts Crypto Laundering Ring Tied to Cambodian Phishing Group

South Korea Fines Coupang $409 Million Over Massive Data Breach

South Korea slaps Coupang with a record ₩624.7 billion data breach penalty

SprySOCKS Backdoor Expands From Linux to Windows

Steam Workshop abused to spread malware via Wallpaper Engine app

Superior Drywall Data Breach Exposes Financial Account Information and Social Security Numbers

Sysco hit by second extortion claim over 61 Million records, weeks after Qilin ransomware threat

The Gentlemen Ransomware-as-a-Service (RaaS) Scales to 166 Victims as Ransomware Groups Compete for Affiliates

The Hacker Group That Once Targeted BMW and Google Play May Have Changed Its Mission

The Handala hacker group uses cyberterrorism as psychological warfare, study finds

Think your Microsoft 365 account is safe? This new scam may prove otherwise

UAE's most dangerous cyber threat: Why credential phishing is getting harder to detect

Ubeo Data Breach: SSNs and Driver's License Information Compromised

UK watchdog now investigating smart TVs collecting your personal data

UNC1151 Ghostwriter Hackers Target Gmail Users With 2FA-Stealing Phishing Campaign

Update on the California Water Service (Cal Water) Hacking Incident

US restricts Anthropic Mythos and Fable AI models over fears foreign military will use them

“We hit the UK hard:” 9 million targeted in Boots gift scam hosted on hacked government website

What Is Kali365 & How Is It Targeting Microsoft 365 Users With Automated Phishing Attacks

What Is Kali365? Everything You Need to Know About the MFA-Bypassing Phishing Scam

Willis finds cyber insurance coverage adequate for most breach and first-party losses

Windows version of SprySOCKS Linux malware used to attack government organizations

15th June

4 major Iranian banks suffer cyber attack, no customer data impacted

23andMe data breach victims get $46.75 million settlement

152 Chrome Wallpaper Extensions with 105K Installs Linked to Adware and Fake Traffic

A hacker has allegedly stolen employee data from Nintendo

A hardware neural network backdoor that hides in plain sight

Adriatic Port Cyber-Attack by Anubis Sparks Warning Over Maritime Security Risks

AI vulnerability discovery is pushing 2026 CVEs toward 66,000

Akira ransomware spotted using LimeWire service for data theft

Alleged Dark Web Leak Exposes Data on 62,208 Paris Transit Workers, Raising Fresh Cybersecurity Fears

Anthropic says US government forced it to disable cybersecurity AI models

Anthropic's most advanced AI models blocked worldwide: US cites cyberattack risks

APT37 Hackers Use NarwhalRAT Malware With Microsoft-Themed Phishing and Dead-Drop C2

Attackers Hijack Popular WordPress Plugins to Deploy Backdoors

Australian Sugar Producer Mackay Sugar Reports Cyber Incident

Belarus-linked hackers target Gmail accounts of Polish public figures and their families

Breaking Down the Novo Nordisk Data Breach

Caldwell Sutter Capital discloses data breach tied to third-party software provider

California Water Systems Secure Despite Hacker Claims

China-linked spies backdoored authentication stack to stay hidden for years

Chinese Hackers Abused Google Workspace Rules to Steal Research and Defense Emails

Chinese hackers breach REDCap servers, steal medical research

Chinese hackers breached North American research institutions via REDCap servers

Cisco fixes SD-WAN vManage flaw exploited in zero-day attacks

Council of Europe investigates ShinyHunters data breach claims

Coupang Faces Record $470 Million Fine, Class Actions Loom Over Data Breach

Cyber Attack on Oracle Exposes Data of Higher-Ed Clients

Cyber threats shift focus to people as AI-driven scams and identity attacks rise in 2026

Cyberattack on Russian tech firm Astral disrupts business, government services for a week

Cybersecurity Experts Urge US to Lift Ban on Anthropic's Frontier AI Models

Cybersecurity veterans protest ‘dangerous’ US government ban on Anthropic’s most powerful models

Cyberwar At the Front Line: Why Enterprises Must Prepare for Digital Conflict

Data Breach Portal Shut Down After Fake Filings Expose Unverified Auto-Publish Flaw

Department of Justice (DOJ) seizes CFAKE, SOCFAKE deepfake nude sites under TAKE IT DOWN Act

Don’t just recover from ransomware; recover well, and you could cut your ransomware bill too

FBI: Fraudsters use couriers to steal money in crypto scams

FBI alerts users to Microsoft Teams, Outlook phishing risk

FBI And Google Crush AI Scam Ring Behind 1.59 Million Phishing URLs

FBI Destroys Massive AI Phishing Empire Linked to $1.9 Billion Theft

FBI dismantles Chinese phishing service that coached buyers to generate scam sites using AI - $88 cybercrime product linked to $1.9 billion in losses, 3.87 million stolen cards

FBI takes down Chinese phishing operation

FBI takes out huge AI-powered phishing service: Outsider Enterprise was using over a million phishing URLs to steal credit card data and passwords

FBI warns of Kali365 phishing scam targeting Microsoft 365 users

FBI Warns Of Phantom Hacker Scams Targeting Bank Accounts

FBI, Google Dismantle ‘Outsider Enterprise’ Phishing Service

FBI, Google Take Down AI-Powered Cybercrime Ring That Was Using Over A Million Phishing URLs To Steal Data

Feds Seize CFAKE and SOCFAKE Over Explicit Deepfakes of Famous Women

Global crackdown exposes €336m crypto laundering linked to ransomware gangs

Google files lawsuit over AI-assisted phishing operation abusing Gemini

Google says Chinese-linked hackers stole defence and AI data from US and Canadian labs for a year

Google Sues Chinese Crime Ring for Using Gemini AI in Mass Phishing Scams

Google sues Chinese network accused of impersonating Google with AI

Google sues Chinese network over AI text phishing scams

Google Sues Operators of AI-Powered ‘Outsider’ Phishing Kit Linked to 1.5 Million URLs

Hacker claims to have stolen Nintendo employee data and more

Hacker claims to have stolen Nintendo HR data from TINYpulse systems

Hacker claims to have stolen roughly 859 MB of data from Nintendo

Hacker drops Needlework Tours customer data on underground forum

Hacker Group Claims To Have Stolen Nintendo Data, Posts $2 Million Ransom

Hackers claim massive Council of Europe breach: troves of personal data exposed

Hackers demand $2 Million from Nintendo over alleged data breach

Hackers Use Microsoft Account Security Alert Lures to Deliver NarwhalRAT Malware

Handala Hacking Group Claims Breach of California Water Service

How a Chinese hacker group used Google’s AI to scam thousands of users

HSBC Payment Advice Phishing Email Aims to Steal Passwords

Humanity Protocol Hack Linked to Suspected North Korean Actors

Humanity Protocol loses $36 Million in phishing hack linked to North Korean cyber operatives

Infinite Campus: Data breach affects 137,000 school staff accounts

Infinite Campus data breach affects 137,000 school staff accounts

Infostealers, AI, and a 90% Affiliate Cut Fuel The Gentlemen group’s Rise

Ireland: HSE fined €300k over data breach at Midland Regional Hospital Tullamore

Kaspersky identifies phishing campaign using AI web hosting platform

Kimsuky targets South Korea with spear phishing using data-leak lures

Korean Ecommerce Giant Hit With Record-Setting Fine Over Massive Data Breach

Labcorp Agrees to Pay $35 Million to Settle American Medical Collections Agency (AMCA) Data Breach

Legal Services of Long Island Data Breach Exposes Sensitive Personal and Health Information

LiteLLM Vulnerability Chain Lets Low-Privilege Users Take Over AI Gateway Servers

Maine closes data breach portal to the public after fake reports

Maine Data Breach Reporting Portal Abused, Taken Offline

Maine Disables Data Breach Portal Due to Fake Submissions

Maine forced to take down data breach portal after fake notices filed with authorities

Maine Takes Breach Reporting Portal Offline After Fake Entries

Maine Takes Data Breach Reporting Portal Offline After Fake Discord and VRChat Filings

Microsoft’s workplace check-in via Wi-Fi tracks who’s in the office, and not everyone’s happy

New attack turned Microsoft 365 Copilot into 1-click data theft tool

Nintendo Alleged Data Breach: Threat Actor Demands $2 Million Ransom

Nintendo Data Breach: Hacker Claims Stealing Approximately 860 MB via TINYpulse Systems

Nintendo Employees’ Private Workplace Confessions May Now Be On a Criminal Forum After Hacker Targets HR Vendor TINYpulse

Nintendo hit with data breach, hacker steals 859MB of data via TINYpulse

North Korean Hackers Are Turning Developer Tools Into Malware Delivery Channels

North Korean hackers steal $36 Million from blockchain service using phishing email

One-Click Microsoft 365 Copilot Flaw Could Have Let Attackers Steal Emails, Files, and MFA Codes

OptinMonster WordPress plugin hacked in CDN supply-chain attack

Oracle Warns PeopleSoft Customers After Critical Zero-Day Exploited

Orthopaedic Specialists of Massachusetts (OSM) Data Breach Exposes PHI and PII for 20,147 Patients

Over 50 Android Apps Found Spreading MagicAd Trojan via Official Stores

Over 73K accounts caught up in breach of France’s government messaging platform Tchap

Ozempic Maker Novo Nordisk Says Hackers Breached IT Systems

Palo Alto Warns of Active Exploitation of PAN-OS GlobalProtect VPN Flaw

Paylogix data breach exposes sensitive employee and client information in ransomware attack

Phantom Hacker Swindlers Zero In On New Yorkers After $1 Billion Nationwide Heist

Phishing Alert - Beware of Booking.com Phishing Messages Exploiting Suspected Leaked Booking Data

Phishing Through Bithumb Leads to $36 Million Theft From Humanity

Popular WordPress Plugin Scripts Tampered to Plant Hidden Backdoors on Sites

Power Without Control: What Anthropic’s Claude Fable 5 and Mythos 5 Mean for Enterprise Security, AI Governance, and Risk

Protecting Public Safety Networks: A Deep Dive into the Ransomware Threat and Emerging AI Risks

Ransomware Attack Shuts Down Mills of Australia’s Second-Largest Sugar Producer

Ransomware Hits Australia’s Sugar Mills, Shutting Down Operations

Ransomware Insider Betrayal: Guilty Plea In BlackCat Cybercrime Scheme

Ransomware Preparedness Must Be a Boardroom Priority: NCSC (National Cyber Security Centre) Chief

SearchJack Adware Campaign Exposes 758,000 Users to Privacy and Phishing Risks

Senior engineers are spending their week cleaning up AI-generated code

SHADOWBYT3$ Allegedly Claims Nintendo Breach and Theft of Sensitive Data

SHADOWBYT3$ Claims Nintendo Data Breach, Alleges $2 Million Ransom Demand Through HR Platform Exploit

ShinyHunters Claims Council of Europe Hack

ShinyHunters claims Kodak hack, threatens to leak 2.2 Million records

ShinyHunters Publishes Infinite Campus Data in Extortion Campaign Linked to Salesforce, 137,000+ Emails Exposed

SimpleHelp bug lets hackers create rogue remote support accounts

Sniper Dz Scams Target MENA Users via Fake Facebook Offers and Browser Alerts

South Korea: 'Business-Crushing' Ransomware...National Police Agency to Launch Dedicated Investigation Team

South Korea: Privacy Watchdog Probes CU Convenience Store Delivery Data Breach

South Korea Fines Coupang Record £300 million Over Data Breach

Spectrum Sued After Data Breach Exposes 40 Million Customers

Splunk Urges Immediate Patching of Critical Flaw Enabling Arbitrary File Operations

The FBI just issued an urgent warning for anyone using Microsoft Teams, Outlook, or OneDrive over a new phishing scheme

The Philippines: Hacker of government websites identified

The Shared Language Needed to Secure and Govern AI Systems

The US government’s Anthropic models ban was never about an AI jailbreak

Travel Phishing and Cyber Attacks are Surging in 2026, Growing 122% over the last 3 years. Here’s What Cyber Criminals Are Actually Doing

UK Government Finds 400+ Vulnerabilities in AI Hackathons

Ukrainian Man Pleads Guilty in US to Conti Ransomware Charges

Ukrainian national pleads guilty in connection with Conti ransomware

US export controls on Anthropic’s AI models catch Europe unawares

Virta Health Data Breach Exposes Sensitive PHI and PII

What Is Phishing? How It Works, Types, and How to Spot It in 2026

Friday, 12 June 2026

Ransomware Operator Claims - Week 23 2026

Welcome to last week's ROC Report, an exclusive summary of Ransomware Operator's global victims that were claimed during the period between 1st June and 7th June 2026, kindly assisted by our partners.

DBD discovered and researched 132 Ransomware Victims over 37 Countries and Islands claimed by 30 Data-Leaking Ransomware Operators, including 1 Newly Discovered Ransomware Operator last week.

For further analysis on these (and any historic) Ransomware Operator Claims, including the Victim Names and Industry Sectors attacked, please use our PRiSM application.

Download PDF



Data Source: Data Breaches Digest. Flag Icons created by Freepik and provided by Flaticon.


Monday, 8 June 2026

Data Breaches Digest - Week 24 2026

Welcome to this week's Data Breaches Digest, a catalogue of links concerning Data Breaches and Cyber Security that were published on the Internet during the period between 8th June and 14th June 2026.


14th June

Anthropic shuts down top AI models after US restricts foreign access

Cyberattack hits four major Iranian banks, officials say

Europol and US Intelligence Agencies Took Down AudiA6 Crypto Service - Ukrainian and Russian Citizens Arrested

FBI disrupts massive AI-powered phishing service using a million URLs

Google Slaps 'Outsider' Gemini Scam Ring With Massive Phishing Lawsuit

Google Sues Chinese Threat Group Using Gemini AI in Phishing Scams

Hackers Hide New Argamal Malware Inside Working Hentai Games

Handala Announces New Attacks Against Targets in Israeli Territory Within Hours

Iran banks hit by major cyber attack

Iran denies leaking customer data following a cyber attack targeting four banks

Open Arms Care Notifies Clients After Email Data Breach

Securing Critical Infrastructure Against Early-Stage Ransomware: Proactive Steps for Prevention

Spectrum Faces a Massive Class Action Lawsuit Over A Data Breach Exposing 40 Million Customers’ Data

Turkey’s Retired Millions Are Targets: How Fake e-Devlet Links Are Draining Bank Accounts

Ukrainian Extradited from Ireland Pleads Guilty Over Role in Conti Ransomware Scheme

University Of Nottingham says hackers accessed student data in cyber-attack

VRChat Denies Filing Data Breach Notice Amid User Data Claims

VRChat says reported data breach never happened

13th June

40 fake FIFA World Cup 2026 ticket sites linked to fraud network

California water systems hit by Iranian hackers in terrifying threat to drinking supply

Chinese hackers hijack authentication flow, spy on isolated network for a decade

Criminal probe launched into University of Nottingham cyber attack as student addresses leaked

Critical Splunk Enterprise Flaw Lets Attackers Run Code Without Authentication

Crypto Laundering Network Crushed: $389 Million AudiA6 Operation Linked to 15 Ransomware Cases

Ex-school district employee jailed for hacks on former employer

Extradited Ukrainian Man Admits Role in Conti Ransomware Attacks

Google sues Chinese AI phishing ring as FBI seizes domains and $100,000 in Operation Ghost Hook

Google Sues Chinese Crime Group for Allegedly Using Gemini AI for Mass Phishing Scams

Google Sues Chinese Cybercrime Group Behind 'Phishing-for-Dummies' Software

Google Sues Cybercrime Network Over Gemini-Powered Phishing

Google Sues Scammers Using Gemini to Build Fake Government and Brand Sites

Google Targets China-Based Cybercrime Ring After Hackers Turn Gemini Into Phishing Weapon

New Agentjacking Attack Hijacks Your AI Coding Agent to Run Code From a Hacker’s Server

HDFC AMC Data Breach: Fund House Alerts Mutual Fund Investors on SIM Swaps and Password Resets

New York Firm Handing Out Up To $10,000 Per Person in Settlement Over Data Breach That Exposed Personal Information

Paylogix Data Breach Exposes Social Security Numbers

Phone battery draining fast? Malware is one of 8 possible factors - how to tell for sure

Ransomware Gangs Cut Off From EUR336 Million ‘AudiA6’ Crypto Laundering Pipeline

South Korea fines Coupang $409 million in country's largest data breach penalty

U.S. Orders Anthropic to Suspend Fable 5 and Mythos 5 Access for Foreign Nationals

University of Nottingham: Students 'scared and anxious' after cyber-attack

University of Nottingham Student’s Personal Data Compromised in Cyber-Attack

US Government asks Anthropic to ban 'foreign national' access to Fable, Mythos

Warning to watch for convincing email after major hotel chain data breach

12th June

$17 Million in escrow funds gone overnight: Palm Beach law firm sues bank over cyber attack

163 Organizations Hit by Thai Gambling SEO Poisoning Campaign

American College Testing (ACT) exam moved to Lane Tech High School as Evanston Township High School continues recovering from ransomware attack

Africa remains among most targeted by cyber crime

After Lansing Community College (LCC) Data Breach, Expert Warns Cybercriminals Turn Stolen Information Into Scams

Agentjacking Attack Tricks AI Coding Agents Into Running Malicious Code

AI sovereignty makes data centers strategic targets for cyber operations

APT28 Weaponizes Outlook Zero-Click Flaw to Steal Net-NTLMv2 Hashes From NATO Targets

Atomic Arch Campaign Hijacks 20+ Linux AUR Packages to Deliver Malware

Authorities dismantle crypto laundering service that moved €336 million for cybercriminals

Authorities Dismantle Cryptocurrency Laundering Services ‘AudiA6’ Used by Ransomware Gangs

Bankruptcy administrator approves settlement fund of $47 million for 23andMe data breach victims

Britons largely unaware how smart devices are quietly harvesting personal data, survey finds

Check Point reports ransomware attacks jump 48% year over year despite decline in overall cyberattack activity

China-Linked Hackers Backdoored Linux Login Software to Hide for Nearly a Decade

Chinese cybercrime operation that used AI to scam ‘hundreds of thousands of victims’ sued by Google

Chinese hackers use fake FIFA sites to steal card data in Facebook-targeted scam

CISA Orders Federal Agencies to Patch High-Risk Vulnerabilities Within 3 Days Under New Directive

CISA orders feds to patch actively exploited Ivanti flaw by Sunday

Conti ransomware group member pleads guilty, faces up to 20 years in prison

Coupang Faces Data Breach Settlement as 37.56 Million Users Affected

Coupang faces record $410 million in fine over data breach

Coupang Fined 624.7 Billion Won After Personal Data Breach

Coupang hit with record 624.7 billion won fine by Korean regulator over privacy violations

Coupang to Challenge Record $460 Million Data Breach Fine, Warns of Profit Hit

Criminal hacker group threatens to publish Nottingham students’ data online if university doesn’t pay

Critical LangGraph Vulnerability Chain Enables Full Server Takeover

Critical Microsoft Outlook and Word Flaws Enable Malicious Code Execution

Critical Microsoft Teams for Android Vulnerability Could Lead to Sensitive Information Disclosure

Critical Palo Alto PAN-OS Flaw Enables Root-Level Command Execution

Crypto Laundering Network Shut Down, How a Ransomware Cash-Out Service Fell

Cyber Incidents Rarely Start With a Hacker: The Weak Links Businesses Overlook

Cybercriminals are moving away from mass phishing campaigns

Data stolen from patients at Norfolk and Norwich hospital

Delaware North cyber attack affects more than 1,000 New Hampshire residents

Europe’s digital identity wallet gets its first set of standards

European Data Protection Board (EDPB) adopts common data breach notification template for GDPR compliance

Europol dismantles AudiA6 crypto laundering network used by gangs

Europol Dismantles AudiA6 Crypto Laundering Network Used by Ransomware Gangs

Europol Disrupts AudiA6 Crypto Laundering Service Used by Ransomware Gangs

Europol Takes Down AudiA6 Crypto Laundering Service

Europol-backed operation dismantles crypto laundering service used by ransomware gangs

Everett-based Fluke Corp. failed to prevent data breach, lawsuit says

Fake Spotify Premium Tutorials Use PowerShell Commands to Infect Windows Users With Malware

FBI takes down massive China-based cybercrime network that caused $1.9 Billion in losses

Feds Seize AudiA6 and Dark2Web in $389 Million Crypto Laundering Case

FIFA World Cup 2026 Scams: Fake Websites, Ticket Fraud, and Job Scams Already Active

Forget phishing: This dangerous hacker group is physically walking into offices to steal data

GitHub to Update npm to Thwart Software Supply Chain Attacks

Google files lawsuit against suspected Chinese cybercrime operation over 2 million scam texts

Google links ShinyHunters to Oracle PeopleSoft zero-day extortion campaign targeting universities

Google Sues Alleged AI Phishing Network Over Scam Texts

Google sues China-based scammers over Gemini AI abuse

Google Sues Chinese Cybercrime Network for Using Gemini AI to Fuel Scams

Google Sues Chinese Cybercrime Network for Using Gemini AI to Launch Cyberattacks

Google Sues Chinese Cybercrime Ring Over AI-Powered “Outsider” Phishing Kit

Google Sues Chinese Phishing Service Over Gemini Abuse

Google Sues Chinese Smishing Network Accused of Using Gemini AI in Phishing

Google sues the cybercrime ring that turned Gemini AI into a phishing machine

Google sues to dismantle AI-powered cybercrime operation

Google targets AI-powered phishing in New York lawsuit

Hacker group linked to Iran claims breaching FBI drones to threaten FIFA World Cup

Hackers Abuse Google Sheets Tabs to Control 91 Victims in SHEETCREEP Campaign

Hackers Abuse Legitimate NinjaOne RMM Software to Bypass Traditional Malware Detection

Hackers Abuse NinjaOne RMM Agent to Gain Remote Access to Brazilian Organizations

Hackers claim theft of source code from AI giant Dynatrace

Hackers Spread GoFlateLoader Through Cracked Software and Malicious TDS Campaigns

Hackers Use Fake Fiscal Documents to Deliver NinjaOne RMM Agent for Remote Access

Hackers Use Fake Windows Update Installers to Deliver OnyxC2 Credential Stealer

Healthcare Data Fuels Cybercrime Economy

Hong Kong: Phishing Alert - Beware of Fraudulent “WhatsApp Security Centre” Pages Hijacking Accounts

How Microsoft Copilot Studio Creator Permissions Expand the Blast Radius of Prompt Injection Attacks

How to Prevent a Data Breach: A Practical Playbook

International authorities dismantle Crypto laundering network tied to $380 million in ransomware proceeds

International Operation Dismantles EUR 336 Million Ransomware Laundering Pipeline AudiA6

INTERPOL Operation Takes Down Sniper Dz Phishing Platform, Arrests Administrator

Iran-linked group claims hack of FBI drones, threatens World Cup

Iran-Linked Hacker Group Makes Serious Threat To Attack FIFA World Cup With Drones

Iran-linked hackers claim breach of California water systems

Japan Data Breach: Kyushu Electric Loses Unencrypted SSD with 10.9 Million Customer Records

Japan Hotel Association Warns Booking.com Users About Phishing Messages

Labcorp Agrees to $35M Settlement to Resolve American Medical Collection Agency (AMCA) Data Breach Litigation

LangGraph Flaw Chain Exposes Self-Hosted AI Agents to Remote Code Execution

Law enforcement involved in University of Nottingham cyber attack

Mackay Sugar mills shut by cyber attack hope to reopen next week

Maine disables data breach notification portal after fake disclosures

Major Cybercrime Operation Dismantles Money Laundering Service Linked to Ransomware Attacks

Major US surveillance program poised to lapse after legislative deadlock

Malicious npm Packages Abuse Postinstall Scripts to Steal Ethereum Private Keys and Mnemonic Phrases

MonsterInsights Website Compromised And Sending Phishing Emails

Murray County pays $200k to ransomware attackers to ‘resolve’ cyber breach

Murray County restores systems after ransomware attack, pays $200,000 fee

New Windows Zero-Day Claims BitLocker Bypass Amid Microsoft Disclosure Fight

Nottingham University cyber attack: Everything we know so far as ShinyHunters claims responsibility

Novo Nordisk: Cyberattack exposed clinical trial data

Novo Nordisk Data Breach Exposes Patient and Healthcare Professional Data

Novo Nordisk discloses data breach affecting patient and healthcare professional information

Novo Nordisk discloses data breach impacting clinical trial participants

Novo Nordisk flags patient data breach from some clinical trials in cyberattack

Oracle Issues Emergency Guidance as PeopleSoft Flaw Linked to Widespread Data Theft

Oracle PeopleSoft 0-Day RCE Flaw Under Active Exploitation by ShinyHunters

Organizations Think They Know Who’s Visiting Their Sites. They Don’t

Over 80% of Sports Organizations Targeted by Hackers in the Last Year

Over 400 Arch Linux AUR Packages Hijacked to Deploy Infostealer and eBPF Rootkit

Over 400 Arch Linux packages compromised to push rootkit, infostealer

Over 73,000 French government employees affected in Tchap messenger breach

Oxford University Confirms Third-Party Data Breach Impacting CareerConnect Platform Exposed Personal Information

Ozempic maker Novo Nordisk says clinical trial patient data copied in cyberattack

Passco Companies Data Breach Exposes Personal Info of 8,335 People

Pharma giant Novo Nordisk discloses breach of clinical trials data

Phishing Attack Volume Down 20%, But Risk Still Rising

phpBB forum fixes auth bypass bug lurking for a decade

Ralph Lauren suffers ransomware attack, 220 GB of data leaked

Ransomware Payment Crypto Laundering Platform Taken Out by FBI and Europol

Record fine for Coupang is only the beginning of its troubles

Researchers release details, Proof-of-Concept (PoC) for exploited Check Point VPN flaw (CVE-2026-50751)

Rethinking MDR as Attackers and Defenders Embrace AI

Russia Claims US Is Hunting Its Citizens After FSB Hacker Extradited From Thailand

Scammers used Gemini AI to power a massive phishing operation and Google just sued them

Security Experts Discuss Validity of Handala’s California Water Service (Cal Water) Hacking Claim

ShinyHunters claim JCPenney retail data theft involving SSNs and payroll files

ShinyHunters Target Universities in Oracle PeopleSoft Zero-Day Attack

Solana FakeFix Campaign Uses 25 Malicious npm and PyPI Packages to Steal Developer Secrets

South Korea Fines Coupang US$409 Million Over Major Customer Data Breach

South Korea Fines Coupang Record $409 Million for Data Breach

South Korea hits Coupang with record $409 million fine over data breach

South Korea Slaps Coupang with Record $409 Million Fine Over Unprecedented Data Breach

Spectrum class action alleges over 40 Million customer records exposed in data breach

Spectrum customers: Your personal information may have been compromised in this massive data breach

Supply Chain Incidents Reveal the True State of Incident Response as Security, IT, and OT Teams Struggle to Assign Accountability

Tchap Messenger Breach Exposes Data of 73,000+ French Government Employees

The assembly line behind 1.5 million malicious domains

The Gentleman Ransomware Gang Claims 478 Victims, Security Study Reveals

The Gentlemen ransomware with 478 victims spreads like a worm

Threat actors look beyond inbox in phishing attacks

Ukrainian national pleads guilty to role in Conti ransomware operation

UNC1151/Ghostwriter phishing campaign targeting Gmail accounts

University of Nottingham confirms data breach exposing records of 454,600 students

University of Nottingham Data Breached by ShinyHunters

US charges suspected Russian hacker with facilitating cyber campaign

US surveillance law to expire for first time after lawmakers reject Trump’s controversial pick to lead spy agencies

VRChat data breach exposes 2.4 Million users, but they say it’s fake

VRChat says Data Breach notification filed with Maine Attorney General was Fake

Was New York Knicks owner breached? ShinyHunters say so

What The FIFA World Cup 2026 Means For Fraud

World Cup Kicks Off With Player Passport Leak, Active Phishing Operations

11th June

2.4 billion TikTok user records leaked online, hackers claim

2.4 Million Impacted by VRChat Breach

5 Ways Quantum and AI Will Rewrite the Rules of Cyberattacks

9 out of 10 people can no longer distinguish real from AI-generated content

AudiA6 cryptocurrency service dismantled for allegedly laundering over $380 million

Authorities dismantle 'AudiA6' ransomware crypto-laundering service

British high school sends students home following cyberattack

Celebrities’ and influencers’ private communications exposed in stalkerware data breach

China-linked JDY botnet rapidly exploits new flaws, raising fresh Volt Typhoon concerns

CISA gives federal agencies 72 hours to fix critical flaws as AI speeds up cyberattacks

CISA Orders Agencies to Patch by Risk, Not Severity

CISA orders federal agencies to “patch smarter”

CISA Sets 72-Hour Patch Window for Federal Systems Facing Highest Cyber Risks

CISA tells government agencies to patch critical exploited flaws in 3 days

CISA Warning: LiteLLM Flaw Could Expose Enterprise AI Gateways

Clinical Registry Solutions Data Breach Exposes Sensitive Patient Data

Coupang faces record fine as data breach exposes millions of users

Coupang Fined 624.7 Billion Won Over Data Breach, Nearly Wiping Out 2024 Profit

Coupang fined a record $409 million over massive data breach affecting 33 million users

Coupang hit by massive $456 million fine for 2025 data breach incident

Coupang hit with record $409 million data breach fine in Korea

Coupang hit with 624.7 billion won fine over personal data breach, largest ever

Coupang Hit With Record 624.6 Billion Won Fine Over Data Breach of 37.5 Million

Coupang Hit With Record Fine on Revenue Basis Over Massive Data Breach

Coupang pledges legal action against record $409 million fine over massive data breach

Coupang to Pursue Legal Action Against 624.6 Billion Won Data Breach Fine

Crypto laundering service “AudiA6” shut down, leaving ransomware gangs without crypto cleaner

Cyber attack forces shutdown of two Mackay sugar mills in Australia

Cyber-Attack Disrupts Exams At Buckinghamshire School

Cybercriminals Use Fake AI Guides and Dev Tools to Spread AsyncRAT Malware

Decade-Long SniperDz Phishing Network Disrupted in Operation Ramz

Dutch women launch mass lawsuit over cervical cancer screening data breach

Elmwood Home Care Data Breach Exposes Personal and Medical Information

Encrypted chats expose criminal network

Extortion-Only Attacks Increase, With Data Theft Dominating Ransomware Claims

Fake Spotify Premium tutorials on TikTok and Instagram Reels spread malware

FBI seizes 13 websites linked to alleged Chinese intelligence-gathering effort

Finding More Vulnerabilities Won’t Fix AppSec’s Biggest Challenge if AI Can’t Explain What’s at Risk

First Sight Family Vision Data Breach: Personal and Health Information Compromised

France’s Tchap Breach: 650,000 Messages, 73,000 Accounts Exposed

GitHub to Disable npm Install Scripts by Default to Stop Supply Chain Attacks

Got hacked? The EU wants every company to explain data breaches using the same reporting form

Hacker Drained $1.34 Million From Raydium by Faking Ownership of Abandoned Pools

Hacker group boasts about Ralph Lauren data breach: 220GB allegedly stolen

Hacker linked to Void Blizzard faces charges over cyberespionage campaign

Hackers claim massive Wise data breach affecting 4.9 Million records

Hackers Use Fake Claude Code Guide and AI PDFs to Spread AsyncRAT Malware

Hackers use “free Spotify Premium” TikTok videos to steal passwords

How scammers use "scraped New York Times content" to trick security scanners - and exploit "free" Google Cloud links to flood your inbox

How Time Bomb Ransomware has emerged as a severe Cyber Threat to Backup Engines

IBM and AT&T Accused of Covering Up Foreign Hacks

Identity Crimes Have Become Multi-Layered

Interpol Dismantles SniperDz Phishing-as-a-Service Platform

Jamaica: Opposition calls for speedy cybersecurity law following possible data breach at National Health Fund (NHF)

Japanese energy firm loses drive with data of 10.9 million clients

Kaspersky Identifies Sophisticated World Cup Phishing Campaigns and Ticket Fraud

Korea fines e-commerce giant $400m over data breach affecting millions

Mackay Sugar Security Incident Forces Mill Shutdowns and Halts Harvesting Operations

Maine breach portal abused to publish fake data breach disclosures

Max severity Ivanti Sentry vulnerability now exploited in attacks

Microsoft is limiting employee use of Anthropic’s Claude AI over concerns about how it stores company data

Microsoft Restricts Claude Fable 5 Access Amid AI Safety Review

Most Cybersecurity Teams Struggle to Find Time for Training on New Cyber Threats

New “Agentjacking” Attacks Could Hijack AI Coding Agents

New Attacks Trick OpenClaw AI Agent Into Running Code and Leaking Secrets

New GreatXML Exploit Bypasses Windows BitLocker via Recovery Partition XML Files

Nottingham University data breach affects over 450,000 students

Novo Nordisk flags patient data breach from some clinical trials in cyberattack

Novo Nordisk hit by cyber incident, probes data

Novo Nordisk reports patient data breach in clinical trial cyberattack

Novo reports data breach, tells clinical trial patients to 'remain vigilant'

OceanLotus Hits Vietnam Investors With SPECTRALVIPER in FireAnt Attack

Open Arms Care Data Breach Exposes Sensitive Personal Information

Oracle mitigates PeopleSoft zero-day exploited in data theft attacks

Oracle PeopleSoft servers under attack, Oracle pushes out-of-band security alert

Oracle warns of security bug that hackers abused to breach 100+ companies

Organizations can’t see much of their mobile AI activity

Organizations Take Too Long to Fix Application Vulnerabilities

Phishing attack put VHC Health patients’ medical records, personal information at risk

Pro-Iran hacker group claims imminent cyber warfare operations against US

Prompt injection still drives most agentic AI security failures in production

Ransomware attacks hit near-record high

Ransomware group The Gentlemen linked to Russian national

ServiceNow Fixes Flaw That Could Lead to Unauthorized Access to Instances

ServiceNow Flaw Exploited by Threat Actors to Access Customer Instances

ShinyHunters Exploits Oracle PeopleSoft Zero-Day (CVE-2026-35273) to Breach Universities

ShinyHunters Leak 40GB of University of Nottingham Student Data

Someone Filed A Fake VRChat Data Breach Notice To Maine's Attorney General

South Korea: Another Data Breach Hits Customers...Why Are Retailers Prime Targets for Hackers?

South Korea Drops a $409 Million Fine on Coupang in Historic Data Breach Ruling

South Korea fines Coupang $409 million in country's largest data breach penalty

South Korea fines Coupang S$526.5 million in country’s largest data breach penalty

South Korea fines Coupang record $409 million for data breach

South Korea Fines Coupang Record 625 Billion Won Over Data Breach

South Korea hits Coupang with $400 Million+ fine for data breach that affected millions

South Korea Hits Coupang With Record Fine For Massive Data Breach

South Korea hits e-commerce giant Coupang with record US$409 million fine for data breach

South Korea imposes record $410 million fine on Coupang over data breach

South Korea Imposes Record Fine on E-Commerce Giant Coupang After Massive Data Breach

Student data compromised in second University of Western Australia data breach in 6 months

Suspected Void Blizzard Hacker Charged After Boston Court Appearance

The Gentlemen Ransomware Claims 478 Victims, Can Spread Like a Worm

The Hidden Security Risks of Poor Software Testing

The Philippines: Hacker group claims attack on official Senate website

Threat actors are recruiting the people who hold cloud logins

Towerpoint Wealth Data Breach Exposes Social Security Numbers of Clients and Their Dependents

University of Nottingham confirms cyber incident as Shiny Hunters group claims data theft

US charges Russian hacker over cyber espionage targeting US companies and NATO

US seizes 13 website domains tied to alleged Chinese intelligence collection

VRChat says reported data breach never happened

When a data breach is more than an inconvenience: understanding serious privacy harm

Why AI-driven threats are exposing the limits of MSP security stacks

10th June

1 in 5 Enterprise Phishing Attacks Go Completely Undetected by the Security Tools Built to Stop Them

3 ways to respond to time bomb ransomware

Anthropic Releases Claude Fable 5, Its Most Powerful AI Yet, With Cyber Safeguards

Anthropic’s Claude Fable 5 is out for public use, with safeguards for high-risk requests

Australia: Cyber attack shuts down two Mackay Sugar mills

Australian travel agency FirstClass hit by alleged data breach

Autonomous AI agents duped into leaking sensitive data in phishing test

Banking Association of Georgia warns of rising phishing and messaging scams

Buckinghamshire school closed after cyber attack

China-linked JDY botnet expands targeting of U.S. military networks

China-Linked JDY Botnet Expands to 1,500+ Devices for Cyber Reconnaissance

Chinese Cyber Campaigns Intensify as AI Becomes Strategic Target

CISA Adds Cisco, Chrome, and Arista Flaws to Known Exploited Vulnerabilities (KEV) Catalog Amid Active Exploitation

City of York, Pennsylvania, reports data breach

Companies using Fable 5 beware: it’s collecting your data, and there are no exceptions

Criminals have accessed the data of Nottingham University students in cyber attack

Critical Ivanti Sentry flaw allows root-level remote code execution (CVE-2026-10520)

Critical Veeam Vulnerability Enables RCE on Backup Servers

Cyber attack closes Great Marlow School in Buckinghamshire

Cyberattack shuts down major Australian sugar mills, disrupting harvest

Cybercriminals claim breach of Oracle PeopleSoft servers at 100-plus organizations

Cybersecurity researchers aren’t happy about the guardrails on Anthropic’s Fable

Cybersecurity Software Fails to Detect Fifth of Brower-Based Phishing Attacks

Delaware North data breach compromised customers' driver's licences and state IDs

Every set of AI guardrails can be broken by the right prompt

Fake Software Tutorials on TikTok Spread Vidar Stealer

FBI Seizes China-Linked Fake Consulting Sites Targeting US Clearance Holders

FIFA World Cup 2026 Scams Are Already Active: Fake Domains, Phishing Sites, and How to Stay Safe

Fortinet FortiSandbox Flaw Enables Unauthorized Command Execution

French government internal messaging tool Tchap hit by data breach - but it doesn't know if any data was compromised

French Government’s Tchap Messaging Platform Breached via Compromised Account

GitHub announces npm security changes to tackle supply-chain attacks

Global cyber attacks fall but ransomware jumps 48%

Global Interest in AI Exploited as Social Engineering Lure

Hackers Exploit Viral Reels and TikToks to Promote Malware-Laced Software Downloads

Hackers Use Tax Phishing Emails to Deploy In-Memory Malware on Windows Systems

How AI APIs are strengthening phishing detection and email security across industrial enterprises

How Scammers are Using AI to Target Football Fans

Humanity Protocol Hack Drains $36 Million After Compromised Laptop Exposes Bridge Controls

Identity Is the New Attack Surface: How Infostealers Are Reshaping Enterprise Risk

Identity theft is turning into a chain reaction for victims

Ivanti: Max severity Sentry flaw allows code execution as root

Ivanti, Fortinet, and SAP Release Patches for Multiple Critical Vulnerabilities

Kenya: Betika Faces DCI Probe Over Alleged 29.5 million Safaricom Data Breach

Linux Kernel Bug Caused by Single Character Opens Path to Root Access

Microsoft Defender RoguePlanet Zero-Day Grants SYSTEM Access on Updated Windows

Microsoft Fixes 200 CVEs in June Patch Tuesday

Microsoft June 2026 Patch Tuesday Fixes 206 Flaws and 3 Zero-Days

Microsoft patches Exchange Server zero-day exploited in attacks

Microsoft patches record 198 Windows bugs in June update - and 3 are zero days

Microsoft Patches Record 200 Vulnerabilities in June 2026 Patch Tuesday

Microsoft Patches Record 206 Flaws, Including Three Zero-Days and Critical RCE Bugs

Microsoft patches YellowKey, GreenPlasma, MiniPlasma zero-days

Microsoft ships largest Patch Tuesday on record, with one bug under active attack

Microsoft’s Record-Breaking Patch Tuesday Fixes Over 200 Security Flaws

New Browser-in-the-Browser phishing uses fake login popups to steal Microsoft 365 credentials

New ClickFix Campaign Delivers MLTBackdoor Malware in Multi-Stage Attacks

New Fable 5 Is a "Mythos-Class" LLM Available to All, Anthropic Announces

New SilabRAT Trojan Hijacks Sessions to Steal Crypto

North Koreans behind nearly half of US tech industry hacks, says CrowdStrike

OANDA Japan Targets Phishing With Passkeys Following Planned Web-Based MetaTrader Exit

OpenClaw AI Agent Leaks Credentials in Phishing Simulation

OpenClaw AI Agent Leaks Sensitive Credentials in New Phishing Attack Simulation

OpenClaw AI agent tricked into phishing attacks, with user data compromised

Oracle PeopleSoft servers hacked in ShinyHunters data theft attacks

Over a Quarter of Identity Crime Victims Hit by Multiple Incidents

Path traversal flaw in AI dev platform Langflow exploited in attacks

Petrovits, Patrick, Smith & Company Data Breach Exposes Sensitive Personal and Financial Info

Phishing costs rise to USD $51,948 per security analyst yearly

Ransomware group The Gentlemen linked to Russian national

Record Microsoft Patch Tuesday, fresh zero-day

Researchers Expose OpenClaw AI Agent Credential Leak During Phishing Simulation

Scammers use short videos on social media to spread Vidar infostealer

Scammers Use TikTok and Instagram Reels to Spread Vidar Infostealer

Scams now operate like real businesses with budgets and targets

Security breach hits French government chat app Tchap, investigators check for possible data leaks

ServiceNow Data Breach: Gated Advisory Left Customers Unaware of Exploited Zero-Auth API

ServiceNow data breach: security issue gives attacker access

ServiceNow Discloses Security Incident Exposing Customer Data

ServiceNow Flaw Exploited to Gain Unauthorized Access to Customer Instances

ServiceNow tells customers a bug left some of their data exposed to the internet

Shadow AI is Exposing the Same Governance Failures Cybersecurity Teams Have Ignored For Years

Six Proto6 Vulnerabilities in protobuf.js Expose Node.js Apps to RCE and DoS

SoFi Hong Kong discloses data breach tied to third-party vendor

Station Casinos Sued After Hackers Went Undetected for Months in Data Breach

Students' data taken in major University of Nottingham cyber-attack

Survey Shines Spotlight on Risks Created by Identity Blind Spots

Tax Phishing Emails Deliver In-Memory Malware to Windows Systems

Tax-Themed Phishing Emails Deliver In-Memory Malware to Windows Users

The ‘Miasma’ worm source code briefly leaked on GitHub

The security in smartphones is helping send them to landfills

The Vercel incident and the phishing campaigns already hiding in plain sight

Thousands of university students placed at financial risk after vicious cyber attack

UK cracks down on Iran, Russia, North Korea, China cyber operations

UK weakens proposed telecoms defenses against Chinese hackers after industry pushback

University of Nottingham hit by cyber attack

Unpatched Langflow Flaw CVE-2026-5027 Exploited for Unauthenticated RCE

Vengeful researcher repeats Microsoft Patch Tuesday sucker punch, posts new RoguePlanet exploit on GitHub

Who Runs the Ransomware Group ‘The Gentlemen?’

Xsolis data breach exposes patient and health plan member information following phishing attack

Zscaler Research Finds Cybercrime Economics Are Shifting as AI Trades Mass Volume for Lethal Precision

9th June

10 million Discord users named in data breach report nobody can explain

75% of Firms Deploy Vulnerable Code Amid Pressure on CISOs

A giant Instagram phone number database just surfaced. Should you be worried?

AI being used to diversify attacks beyond phishing and email

AI Coding Adoption Hits 97% but Governance Lags Behind

AI Heads to UK Courts, Bringing New Cybersecurity and Governance Challenges

AI strengthens phishing fraudsters by making ‘dodgy’ invoice emails word-perfect

Android Malware MagicAd Delivers Aggressive Ad Flooding Campaign

Anthropic’s Mythos Can Serve Up N-Day Exploits in Minutes or Hours

Anubis group claims a ransomware attack on Singing River Health System

Anubis ransomware gang claims credit as Mississippi hospital reveals attack impacted 54K patients

Australian farming group launches investigation following Qilin cyber attack claims

Belgium: Limburg police test app to help phishing victims faster

Budget Saudi detects limited customer data breach on app

Check Point says VPN attacks caused by Qilin ransomware group - who had a month's head start on them

Check Point VPN 0-Day Exploited to Deploy Ransomware Attacks

Check Point VPN Zero-Day Exploited in Qilin Ransomware Attacks

Check Point Warning: Actively Exploited VPN Zero-Day Linked to Qilin Ransomware

Check Point Warns Critical Auth Bypass Bug Exploited in the Wild

Check Point warns of ransomware-linked attacks exploiting outdated VPN protocol

Check Point warns of zero-day flaw targeted by ransomware affiliate

Chrome V8 Zero-Day CVE-2026-11645 Exploited in the Wild - Patch Now

CISA gives feds 3 days to patch Check Point VPN bug exploited as zero-day

CISA gives US federal agencies three days to fix a VPN bug under attack by a ransomware gang

Critical Check Point zero-day exploited in the wild, Qilin ransomware already at work

Critical phpBB Flaw Lets Attackers Hijack Any Account with One Request

Cyber Governance: The Pressure Point in Ransomware Incidents

Cybercriminals Abuse AI Brand Trust to Launch Sophisticated Credential Harvesting Scams

Cybercriminals Weaponize Banking Apps to Spread NFCShare Malware

Data from 35 Million OkCupid users leaked online, hackers claim everyone’s exposed

Decade-old login opens door to massive 10 Million student data breach

Discord data breach claim filed with Maine Attorney General raises red flags

Email and text phishing scams have moved to calendar invites

Expired domains let hacker snoop through debt clients’ emails

Fake Grand Theft Auto 6 (GTA 6) Malware Campaigns Spread Globally Ahead of Launch

French government messaging platform breached through account hijacking

French government messaging service breached in account hijacking attack

Ghost-Sender Flaw Enables Sender Spoofing in Exchange Online

GitHub disables Microsoft repos pushing password-stealing malware

Global Cyber Attacks Ease in May 2026, But Ransomware Surges 48% As Threats Reorganize

Google patches Chrome zero-day exploited in the wild (CVE-2026-11645)

Google patches new Chrome zero-day flaw exploited in the wild

Google Releases Patch for Chrome Vulnerability Exploited in the Wild

Hacker claims breach of Australian travel agency FirstClass, 53k customers potentially impacted

Hackers hijack Microsoft packages to steal developer logins

Hackers pose as women seeking romance to spy on Russian soldiers

Hackers steal $1.7 Million worth of condoms after hijacking Walmart shipment - here’s how they did it

Hacktivist Groups 4BID, Hakerskii Kit, and C.A.S. Broaden Attack Geography

Hades PyPI Attack: 19 Packages Poisoned to Auto-Run Bun Credential Stealer

Handala Claims Israeli Radar Hack, But Evidence Shows Phone Admin Panel

Healthcare data fuels underground cybercrime economy

Hidden camera found in ceiling of government building renews UK’s spying fears

How Enterprises are Adapting Governance, Risk and Compliance (GRC) For a More Complex Risk Environment

How to protect your business from cyber attacks

Indonesian Media Outlet Tempo Targeted by 24.9 Million DDoS Requests

Japan: Improper hard drive disposal triggers major data breach at Hokkaido hospitals

Japan: Massive data breach feared at Kyushu Power as SSD missing

Kuwait and Oman Sign Cybersecurity Pact to Counter Rising Digital Threats

Lansing Community College data breach impacts more than 170K people

Law firm Fox Rothschild hit with class action over data breach

LiteLLM Flaw CVE-2026-42271 Exploited in the Wild, Chains to Unauthenticated RCE

LiteLLM RCE Vulnerability Exploited in the Wild to Run Commands

LiteLLM vulnerability under active attack, CISA warns (CVE-2026-42271)

Maine Government Portal Lists 10 Million Discord Data Breach Notice, But Filing Shows Red Flags

Malware ships with bugs that defenders could use against it

Manzil Data Breach Exposes Social Security Numbers

Marin County, California, warns of phishing scam targeting building permit applicants

Meta accuses Israeli spyware firm of again targeting WhatsApp users

Meta AI data breach impacts over 20,000 Instagram users

Meta blasts facial recognition claims, then deletes the code from its app

Meta Instagram Recovery Flaw Exposed More Than 20,000 Accounts

Meta Moves to Hold NSO Group in Contempt Over New WhatsApp Phishing Campaign

Meta to Use Off-Site Business Data for Feed and AI Personalization

Microsoft Defender 'RoguePlanet' zero-day grants SYSTEM privileges

Microsoft June 2026 Patch Tuesday fixes 3 zero-day, 200 flaws

Microsoft Restores Some GitHub Repos, Keeps Others Offline as Miasma Probe Continues

Microsoft shuts down its open source projects hosted on GitHub as it investigates a data breach

MP staffer’s account sent almost 2,000 phishing emails after suspected hack

New Browser-in-the-Browser Phishing Attack Targets Microsoft 365 Login Credentials

New Browser-in-the-Browser (BitB) Phishing Attack Targets Microsoft 365 Logins

New FROST Attack Lets Websites Track What Sites and Apps You Open via SSD Timing

New Linux Kernel Vulnerability Enables Root Privilege Escalation

New PyPI Wave in Mini Shai-Hulud, Miasma, and Hades Campaign: 23 New Malicious PyPI Artifacts

New Veeam vulnerability exposes backup servers to RCE attacks

New WhatsApp Phishing Attempts Rekindle High-Profile Spyware Fight

NHS Trust reveals thousands of records were stolen during cyber attack

North Korea-Linked Hackers Infect Developers via GitHub

North Korean hackers are at it again - phishing scheme targets hundreds of workers to try and steal crypto and more

OEConnection Data Breach: Social Security Numbers Compromised

OpenClaw AI agent found falling for phishing attacks, spills user data

Operational Technology (OT) Cybersecurity Is Maturing, But Visibility Is Still a Challenge

Oxford University Discloses Data Breach

Oxford University discloses second data breach of 2025 after career services platform compromised

Privacy complaints spike in the Netherlands, driven by data breaches and camera surveillance

Qilin NHS breach tally grows as Essex trust confirms stolen records

Rethink phishing training for the age of AI

SAP fixes critical flaws in NetWeaver and Commerce Cloud

Security Debt Rarely Arrives All at Once but its Consequences Often Do

ServiceNow discloses security incident exposing customer data

Shai-Hulud Attack Compromises 23 PyPI Packages Targeting MCP Developers

ShinyHunters Secret to Success: Breaking the Trust Barrier

Signal, DuckDuckGo, NordVPN threaten to pull services if Canada passes “surveillance” bill

SoFi Hong Kong warns of data breach after third-party vendor compromise

South Africa: Official suspended as labour department probes job seekers’ data breach

Spyware Alert: WhatsApp thwarts NSO Group-sponsored spear phishing attack

Stolen NHS Patient Data linked to Synnovis Data Breach reportedly appears on Dark Web

Suspicious Assistive Agent Behavior Detected Through Microsoft Entra Agent ID Logs

The security questions around Chinese AI coding models in U.S. software

Threat Actors Abuse ChatGPT, Claude, and DeepSeek Brands as Phishing Lures to Steal Credentials

Ultrahuman data breach compromised users' contact info and health data

Veeam Backup & Replication RCE Flaw Lets Domain Users Run Remote Code

Vulnerabilities Can Be Found in Minutes While Safe Remediation Requires More Than Speed

Wales: Conwy Council's website down as pro-Russia group makes cyber attack claim

Wales: Conwy high school investigates data breach

Wales: School investigating data breach after parent received files on pupils

Weedhack Malware Targets Minecraft Players in Credential Theft Campaign

Wells Fargo Phishing Scam Seeks Banking, Email, and Identity Details

WhatsApp Claims NSO Group-Linked Entity Unsuccessfully Carried Out Fresh Phishing Attacks Against Users

WhatsApp Discovers NSO Group-Linked Spearphishing Attempts

WhatsApp Disrupts New NSO Group Spyware Campaign, Files Contempt Order

WhatsApp Disrupts NSO-Linked Pegasus Spyware Campaign

WhatsApp Flags New Spyware-Linked Attacks Targeting Users

Why Jaguar Land Rover’s CISO Enforced In-Person Password Resets Following Cyber-Attack

WinRAR Flaw Exploited by Russia-Aligned Groups to Deploy Stealers in Ukraine

8th June

52% of direct-to-IP threats are missing from intelligence feeds

America's Healthcare Data Breach Problem Has Reached Its Worst Level in History - And Chicago's Hospital Systems Are Among the Most Frequent Targets

BGF Networks Reports Personal Data Breach in CU Convenience Store Delivery Service

CenterWell Data Breach Impacts 9,651 Patients

Check Point links VPN zero-day attacks to Qilin ransomware gang

Chicago-Area High School Closed After Ransomware Attack

CISA: Patch actively exploited SolarWinds Serv-U DoS vulnerability (CVE-2026-28318)

Cisco Warns of Active Exploitation of Catalyst SD-WAN Flaw With No Patch Available

Critical Check Point VPN Flaw Exploited to Bypass Passwords in IKEv1 Setups

Critical UniFi OS bug lets hackers gain root without authentication

Cyber Attack Exposes Vulnerabilities as Hackers Target Kenyan Investment Platform

Cyber-attack targets Gaza aid recipients

Cybercriminals create 19,000 FIFA-themed domains ahead of 2026 World Cup

Cybercriminals Exploit 2026 FIFA World Cup With Phishing, Fake Stores, and Ticket Scams

Did Handala Disrupt Israeli Radar Systems?

Evanston Township High School (ETHS) to reopen Wednesday after ransomware attack forces two-day closure

Even your physical offices aren't safe from hackers - experts warn of Silent Ransom Group breaking into businesses to launch ransomware and extortion campaign

Everything in One Place: Best Practices for Keeping Mobile Devices Secure

Fake Stores and Phishing Campaigns Exploit 2026 FIFA World Cup Hype

Federal Trade Commission (FTC) orders Illuminate Education to improve data security after student data breach

Fintech Holdco Data Breach: Social Security Numbers Exposed

Forget Phishing: This Dangerous Hacker Group Is Physically Walking Into Offices to Steal Data - How the Scheme Works

Fraud Operations Rebuild Faster Than Accounts Disappear While Their Behavior Remains Consistent

Gogs patches critical zero-day enabling remote code execution

Google Patches 429 Chrome Vulnerabilities in Major Browser Update

Gulf enterprises face the resilience gap ransomware is exposing

Hackers Clone Ghidra, dnSpy and Other Tool Sites to Spread Malware

Hackers Exploit 2026 FIFA World Cup With Phishing and Ticket Scams

Hackers Exploit Claude Code MCP to Steal OAuth Credentials

Hackers used Meta’s AI support system to hijack over 20,000 Instagram accounts

How Department of Science, Innovation and Technology (DSIT) Protects Thousands of UK Orgs from Cyber Vulnerabilities

Hull school in data breach over new pupils' details

India: Central Board of Secondary Education (CBSE) Re-Evaluation Portal Goes Live After Final Cybersecurity Clearance

India: IIT-Roorkee denies JEE Advanced data breach, calls report 'misleading'

Instagram Glitch Reportedly Exposed Contact Info of Zuckerberg and Other Users

Instagram Recovery Tool Bug Exposed 20,225 Accounts to Password Reset Abuse

Is OpenAI’s New Lockdown Mode an Admission That Default ChatGPT Was Never Safe Enough?

LinkedIn, Indeed and Upwork Leveraged for Chinese Spying Threat

Massachusetts votes to pass new privacy rights bill that bans sale of precise location data

Meta: NSO Tried Targeting WhatsApp Users Despite Court Order

Meta AI Bug Exposes Over 20,000 Instagram Accounts

Meta AI Support Data Breach Affects Over 20,000 Instagram Accounts

Meta Blocks NSO Group's New WhatsApp Phishing Attack, Files Contempt Order

Meta claims NSO Group still targets WhatsApp users despite court order

Meta confirms critical vulnerability in account recovery tool exposed over 20K Instagram users

Meta escalates legal battle with Israeli spyware firm NSO over WhatsApp attacks

Meta Says Israeli Spyware Firm Targeted WhatsApp Users in Spear-Phishing Campaign

Microsoft’s open source tools were hacked to steal passwords of AI developers

New Shai-Hulud attack trojanizes 19 science-focused PyPI packages

NFCShare Android malware spreads via fake banking app updates on GitHub

NJ Pain Care Specialists Data Breach Exposes PHI and PII

No backdoor shenanigans: Grindr denies data breach claims

North Korean Hackers Use Fake Coding Tasks to Steal Crypto

One-Character Linux Kernel Flaw Enables Local Root Access, Exploits Now Public

OpenAI Expands ChatGPT Lockdown Mode to Millions of Eligible Users

OpenAI is locking down parts of ChatGPT to reduce data theft risks

OpenAI Unveils ChatGPT Account Security Controls

Operation FlutterBridge Uses Fake Google Ads to Spread macOS Backdoor

Over 20,000 Instagram accounts stolen in Meta AI support hack

Over 20,000 Instagram Accounts Hijacked via the Meta AI Support Tool Exploit

Oxford University discloses data breach after careers platform hack

Password Reset Bug Leaked Instagram Emails and Phone Numbers

pfSense Firewall Compromised in VerdantBamboo Cyberattack Deploying BRICKSTORM

PhishByte warns spear phishing drives payment fraud losses

Prompt Injection Remains Unsolved, OWASP Researcher Warns

Qilin ransomware affiliate exploited Check Point VPN zero-day (CVE-2026-50751)

Qilin ransomware claims hack of major New York/New Jersey Shipping Association

Ransomware Attack Knocks Evanston Township High School (ETHS) Offline, Scraps Summer School In Evanston

Research says Phishing overtakes Dark Web as primary source of stolen Personal Information

Russia upgrades rules for its digital spy system to better track citizens online

Second theft: How scammers use a lost iPhone to steal your identity

Securing the AI-Driven Public Sector: Why Data Governance and Trust Must Come First

ShinyHunters dump 400K BCD Travel customers data online

Silent Ransom Group Uses Fast Flux Botnet to Hide Law Firm Leak Sites

Sitefinity Vulnerabilities Allow Hackers to Steal Plaintext Credentials

Smart TV Apps Found Converting Samsung and LG Devices Into AI Proxy Nodes

SoFi confirms third-party data breach at Hong Kong subsidiary

South Africa: Cyber Attack Disrupts AVBOB Funeral Services’ Digital Platforms

South Africa: Cyber attack hits funeral services provider AVBOB as systems go offline

South Korea: Police Launch Probe Into CU Convenience Store Parcel Data Breach

South Korea police probe CU parcel data breach, pursue hacker

Strategic Education data breach exposes social security numbers of more than 176,000 people

Summer classes canceled at Evanston Township High School after ransomware attack

Sun Life subsidiary faces lawsuits after mass data breach

Texas Capital Bank data breach puts 91,000 customers' social security numbers at fraud risk

The hacking mastermind behind the 2026 FIFA World Cup

The Hidden Security Risks Behind Popular AI Tools

The New Face of Cybercrime: When the Criminal Isn’t the Hacker

Thousands of Essex NHS patient records taken in cyber attack

Thousands of NHS patient test results stolen in cyber attack

Trinidad and Tobago: New Ministry of Finance (MoF) based phishing scheme in play

Two-Thirds of Open Source Community Unaware of Cyber Resilience Act

UNC3753 Targeted US Law Firms in Vishing Extortion Campaign, Possibly Used Physical Access

UNC3753 Used Vishing and Physical Intrusions in U.S. Data Theft Extortion Campaign

University of Oxford discloses data breach via third-party career platform

Upper Township, New Jersey, Data Breach Exposed Personal Info

VerdantBamboo Deploys BSD Variant of BRICKSTORM on Linux Appliances

VS Code Adds 2-Hour Extension Auto-Update Delay to Limit Supply Chain Attacks

WhatsApp Says It Blocked Pegasus Spyware Campaign Linked to NSO

WhatsApp says it disrupted new NSO spyware phishing attacks

WhatsApp says NSO targeted users with spearfishing attacks in violation of court order

Whistleblower Accuses IBM, AT&T of Covering Up Breaches

Xsolis Data Breach Exposes Social Security Numbers and Medical Information