Welcome to this week's Data Breaches Digest, a catalogue of links concerning Data Breaches and Cyber Security that were published on the Internet during the period between 31st August and 6th September 2026.📅 6th September
1.4 million stolen Berlin government files dumped on the dark web, triggering crisis response
Attackers conceal phishing lures using invisible Unicode characters
Attackers Hijack MikroTik Routers Through Internet-Exposed SSH Without Authentication
Beyond Phishing: How AI is Advancing Enterprise Payment Fraud
FBI investigates data breach possibly linked to New Orleans cybersecurity firm
FBI looking into driver’s license data breach possibly linked to New Orleans ID-verification firm
FBI probes potential data breach of millions of drivers' licenses
FBI Warns a Password Reset Won't Save Your Hacked Email in New Scam
Four REVSTEALER-Linked Modules Disable Windows Update and Defender to Run a Crypto Miner
Global Phishing Campaign Abuses Google Infrastructure to Evade Security and Steal Credentials
Houston-Based Genetics Firm Suffers Data Breach, Potentially Exposing Medical Data of 2,810,878 Patients and Staff
Identity-based attacks responsible for 85% ransomware in education
Is your forgotten login a hacker's backdoor?
Large-Scale Phishing Campaign Uses Invisible Unicode and ActiveCampaign to Evade Email Security Filters
Mathspace Data Breach Exposes Info of Over 1 Million Students, Parents, Staff
Medusa Ransomware Hits 500 US Firms, FBI Warns
Microsoft exposes phishing campaign using invisible Unicode characters
Microsoft finds an AI jailbreak trick fueling a 2.37 million email phishing wave
Microsoft has uncovered phishing attacks featuring invisible characters in the text that bypass email security measures
More than 150 million driver’s licenses may have been exposed in massive dark web data breach
Thousands of CARS24 records exposed as customer leads allegedly go for just $11
Top cybersecurity expert on Manchester Airports Group cyber attack risks - and what you can do about it
📅 5th September
8.8 Million Airport Records Were Published - Phishing Is Now the Immediate Risk
Attackers Breached JetBrains Cadence via Unpatched TeamCity, Extracting AWS Credentials
Attackers Exploit PaperCut Flaws to Steal Credentials From Schools and Universities
Berlin launches crisis response after hackers publish stolen data
Claude, DeepSeek, and Qwen AI agents used to target governments across Asia
Critical VMware Workstation and Fusion Flaw Lets VM Admins Execute Host Code
Cybersecurity Crisis: Berlin Departments Hit by Ransomware
First Belgian bank to face criminal court for non-repayment of phishing victim
Hackers are exploiting another Chrome zero-day - Google rolls out urgent patch
If you see this iCloud message on your iPhone, don’t click it - it’s a scam
Meta sued over using “perv glasses” recordings to feed its AI
Natural Resources Wales confirms data breach
OpenAI admits it didn't disclose rogue AI wiki hijacking incident
OpenAI confirms ‘wiki incident,’ says it’s ‘working on a framework’ for more disclosure
Over 5,400 hacked sites serve ClickFix payloads stored on the blockchain
Post-Quantum Security Standards Exist, Migration Remains the Challenge
Ransomware’s weakest link is still the person clicking
Stolen Session Tokens Can Survive Password Resets: How Should Enterprises Respond?
The Netherlands: Fraudehelpdesk sees sharp rise in phishing attacks tied to Booking.com
Thousands of OpenAI Agents Quietly Turned an Abandoned Wiki Into Their Coordination Channel
Trezor Says ShipMonk Breach Exposed 67,000 U.S. Customers' Data It Said Was Deleted
Trezor Says ShipMonk Data Breach Exposes 67,000 More US Customers
Trezor Warns 67,000 U.S. Customers As Data Breach Discovery Expands
Unpatched Magento and Adobe Commerce Zero-Day Exploited to Backdoor Online Stores
What Are 'Zombie' Accounts? Why Your Old Logins Are No Longer Safe
📅 4th September
14 Trojanized macOS Installers Linked to DPRK’s Contagious Interview Campaign Deliver OtterCookie
215 Exploited CVEs in H1 2026 as Android NFC Attacks Surge, AsyncRAT Leads Malware Data
67,000 more Americans using Trezor exposed to data breach
67,000 More Trezor Customers Exposed as Data Breach Widens
A German city may soon ban smart glasses on public transport, pools
Another swarm of OpenAI agents reached the open internet without the frontier lab’s knowledge
Bennett College in Greensboro struck by dark web data breach
Binance Warns of Phishing Scam Targeting Crypto Users With Fake Account Security Alerts
Binance warns users as phishing texts increase
California to Regulate AI Chatbot Toys Marketed at Children
CameraSwarm Hackers Compromise 14,500+ Dahua Cameras, Backdoor 1,900 Devices
CISA Flags Old ownCloud Flaw After Reported Philippine Nuclear Data Theft
Critical Citrix NetScaler auth bypass now leveraged in attacks
Crooks Behind Manchester Airports Group Hack Leaked Data of 8.8 Million People
Crystal Coast Pain Management Data Breach: SSNs Exposed
Cyber attack wave hits three more major US law firms
Data at law firms Quinn Emanuel, McDermott exposed in cyber breaches
DaVita to pay $15 million to settle data breach lawsuit affecting millions of dialysis patients
DPRK-Linked Hackers Use Trojanized macOS Installers to Deploy OtterCookie RAT
Egypt: InstaPay users warned of new phishing scam targeting bank accounts
FalconFlank Proof-of-Concept (PoC) Claims CrowdStrike Falcon Zero-Day Enables Privilege Escalation on Windows
FBI investigating potential data breach of more than 153 million driver’s license records
FBI issues warning about OAuth consent phishing
FCCI Data Breach: Protected Health and Personal Information Compromised
French Hospital Data Breach Draws €500,000 Fine Over 727,000 Records
French hospital hit with €500,000 fine after data breach exposes over 500K patient records
French Police Arrest Suspected ZeroBytes Hacker Over Tax Data Theft
G7 Urges Fast-Track on Quantum-Safe Cybersecurity Rules
G7 urges organizations to prepare for quantum cyber threats
Golden State Orthopedics Data Breach: 150GB Compromised
Google Chrome V8 Flaw Exploited in the Wild to Execute Arbitrary Code
Google patches actively exploited Chrome zero-day (CVE-2026-85046)
Google Releases Chrome Update to Patch Actively Exploited V8 Zero-Day
Google warns of new Chrome zero-day flaw exploited in attacks
Hacker from Northumberland sentenced for stealing virtual gold
Hacker used AI agents for the entire attack chain, then mocked the victim company, leaving behind an 80-page security audit
Hacker used role at gaming giant Jagex in Cambridge to steal game wealth
Hackers Abuse AI-Era ASCII Smuggling to Hide Phishing Content in Millions of Emails
Hackers Abuse Leaked Amazon Web Services (AWS) Identity and Access Management (IAM) Keys to Hijack Amazon Bedrock AI Model Access
Hackers Bypass Microsoft 365 RejectDirectSend With Empty SMTP Sender to Spoof Internal Emails
Hackers Exploit Critical Super Forms WordPress Flaw to Upload Webshells and Execute Code
Hackers Hijack Amazon Web Services (AWS) Account to Run Paid AI Models in LLMjacking Attack
Hackers Use Claude, Qwen and DeepSeek AI Agents to Attack Government Networks
IDScan sued over alleged data breach affecting 153 million drivers
Immutable backup gap leaves firms exposed to ransomware
Ireland: Púca Festival warns of phishing scam
Kentucky Appellate Court Data Caught in Multi-State Cyber Data Breach
Ledger Is Being Sued for $500 Million Over a Data Breach It Sat On
MECCHA CHAMELEON Flaw Lets Malicious Custom Maps Achieve Remote Code Execution
Microsoft 365 Phishing Technique Uses Empty Envelope Sender to Evade Direct Send Blocking
Microsoft Teams Adds QR Code Protection to Block Phishing and Fraud
Microsoft Teams is about to make QR code phishing much harder
Microsoft Warns ASCII Smuggling Is Being Used to Hide Phishing Keywords From Email Filters
Midwest Spine and Brain Institute Impacted by Vendor Ransomware Attack
Minnesota court system data breach went undetected for months
Most of the bugs Claude Mythos found have never been checked by a human
New CrowdStrike 'FalconFlank' zero-day grants SYSTEM privileges
New ransomware gang claims Boeing and Airbus supplier breach
New Ted Backdoor Hides Inside Victims' Own HAProxy Builds to Intercept Web Traffic
OpenAI’s rogue agents keep escaping, with no formal process to investigate them
Over 440,000 Exploit Attempts Target Super Forms and Elementor Pro RCE Flaws
Pegasus spyware hits Serbian students and politicians in zero-click attack
Pegasus, New NoviSpy Variant Found on Serbian Students and Opposition Figures
Phishing Campaign Sends Millions of Emails Using Invisible Unicode to Evade Filters
Plex issues urgent patch warning, 300,000 media servers can be found online
Plex Urges Immediate Updates After Patching Multiple Undisclosed Security Flaws
Plex Urges Users to Update Media Server as Multiple Security Flaws Are Discovered
Pocket Bitcoin Data Breach Exposes Personal and Financial Information of 5,411 Customers
Pocket Bitcoin Reports Data Breach Affecting 5,411 Customers, Including KYC Documents
PostgreSQL Fixes 12-Year-Old Logical Decoding Flaw Enabling Replication-Role Code Execution
Quinn Emanuel and McDermott Confirm Breaches - Both US Law Firms Traced to a Single Hacked Employee
Researcher Releases Exploit of Claimed CrowdStrike Falcon Zero-Day
Roanoke tells city residents about data breach three months after it happened
RuneScape hacker stole and sold ‘virtual gold’ for more than £300k on black market
Saint-Étienne Hospital hit with $580,000 fine after data breach exposed 727,000 people's records
Sality Botnet Linked to 11 Million IPs Disrupted After 23 Years
Sality botnet taken down after 2 decades in service
Samsung Union Leaders Investigated for Alleged Data Breach
Scammers have figured out the best time to text you
September 2026 Patch Tuesday forecast: All we need is more time
ShipMonk Data Breach Exposes Personal Data of 67,000 Additional Trezor Customers
South Africa: Rand Water Hit By Cyber Attack
StormEncryptor Hits N-able Bug: 50% Unpatched
The Gentlemen claims Nutex Health cyber attack as company faces lawsuit
TP-Link Archer AX55 Flaws Enable Remote Code Execution and Admin Password Theft
Trezor Confirms ShipMonk Data Breach Exposed 67,000 Additional US Customers
Trezor data breach expands to over 80,000 customers after ShipMonk kept old records
Trezor Data Breach Exposed Personal Information of 67,000 Additional US Customers
Trezor Data Breach Widens: 67,000 More US Customers Exposed Through ShipMonk
Two Citrix NetScaler Flaws Put Enterprise Edge Devices at Risk
UK account-hack losses surge as new reporting system exposes hidden cases
US and UK Join Forces Against Global Scam Centers and Cyber-Enabled Investment Fraud
US military disabled ad tracking on troops’ devices following reports of targeted attacks
US offers $10 million for info on Iranian allegedly behind cyberattacks on critical infrastructure
US, Britain to coordinate on scam center takedowns
What Okta and Microsoft’s Approaches Tell Us About the Future of Identity Security
📅 3rd September
2.8 million people affected by data breach at Baylor Genetics testing and diagnostic firm
3 Healthcare Breaches in Quick Succession Raises Concerns
150 Million Driver’s Licenses Exposed, Security Experts Discuss
412,000 The Town 2025 Ticket Buyers’ Data Hits the Dark Web
Aesto Health cyber attack impacts more than 9.5 million people
Agentic Ransomware Took Down Enterprise in Ten Hours: AI Left 80-Page Audit
AI agents help compress ransomware intrusion to under 10 hours, raising stakes for CISOs
AI is Making Phishing Scams Almost Impossible to Spot - 5 Steps Employers Should Take to Combat Latest Threat
AI-powered ransomware has arrived: Cybercriminals can now launch attacks for less than the cost of a coffee
American Vision Partners faces $1.75 Million settlement over 2023 cyber attack
As X Money expands, attackers target accounts through a wave of password reset requests
ASCII smuggling crosses over from AI prompt injection to phishing evasion
Attackers are Using Microsoft Teams Calls to Gain Access to Corporate Networks
Attackers Behind UK Airport Cyberattack Release Stolen Data
Attackers Turn Trusted Node.js Runtime Into Malware Delivery Tool in Targeted Attacks
Bain Capital Data Breach Exposes Personal and Financial Information
BraZetsu Malware Turns Compromised Windows Hosts Into Criminal Marketplace Inventory
CISA Adds Seven Exploited Flaws as Attackers Deploy Reverse Shells and Crypto Miners
CISA, FBI Urge Clearer Communication During Major Outages
Coder's registry infrastructure compromised to push malicious modules
Critical Cisco Nexus 9000 Flaw Lets Unauthenticated Remote Attackers Run Code as Root
Critical Elementor Pro flaw exploited to take over WordPress sites
CrowdStrike Disrupts Sality Botnet After More Than 20 Years
CVE-2026-84115 in Cleo Harmony: JWT Refresh Token Handler Flaw Exposes Remote Attack Risk
Cyber Attack Hits Cardiac Device Maker Boston Scientific, Disrupting Global Operations
DaVita settles ransomware attack lawsuit for $15 Million
Department of Justice (DOJ) Investigates Cyberattack Targeting Hundreds of Thousands of X Users
Department of Justice (DOJ) Joins X Investigation Into Attack on Hundreds of Thousands of Users to Identify Perpetrators
Don’t Take The Bait: The New Phishing Threats To Asset Managers
Dropbox Data Breach: 5,000 Accounts Hit Via Lenovo ID Flaw
Education Sector Faces Highest Per-Device Cyber Attack Intensity
FBI looking into potential data breach on the dark web
FBI Probes Data Breach Exposing 153 Million Driver’s License Scans on Dark Web
FBI Probes Possible Breach of 153 Million Driver’s Licenses
FBI reportedly opens inquiry into suspected IDScan.net data breach
Fewer attacks, more force: Link11’s European Cyber Report finds new DDoS records for the first half of 2026
Five Healthcare Providers Report Ransomware-Related Data Breaches
French hospital fined €500,000 after breach exposes data of 727,000
Group of UK politicians wants “AI kill switch” in case of national security threat
Hacker uses AI agents for entire attack chain, mocks victim with detailed security audit
Hackers Accessed 5,000 Dropbox Accounts Through Lenovo ID Flaw
Hackers Use QR Codes in Phishing Emails to Steal Login Credentials
Health data breach: EUR 500,000 fine against HÔPITAL PRIVÉ DE LA LOIRE
Hewlett Packard Enterprise (HPE) patches critical ArubaOS-CX remote code execution flaw
HumanEdge Data Breach: Social Security Numbers Exposed
International Operation Disrupts Sality P2P Botnet
IT-OT convergence: When ransomware hits the factory floor
Large group of Serbian opposition, activist figures targeted with spyware
Ledger sued for $500 Million over alleged data breach and crypto theft
Microsoft uncovers malware campaign using counterfeit installers to disable security defenses
Montana court filing system part of nationwide ‘data breach’
MyDr data breach: can affected patients seek compensation together?
New phishing trick gives hackers persistent access to your account, FBI warns
New ‘Spring Ring’ operation uses vishing via Microsoft Teams
NFI North Data Breach: 49,540 Individuals Impacted
Node.js: Old Technique Makes a Comeback
OpenAI Releases GPT-6 Astra Amidst Frontier AI Cybersecurity Concerns
Organizations Struggle to Detect, Contain Out-of-Scope AI Agents
Outsider Phishing Kit Survives Takedown With 700 New Pages
P&O Ferries apologises to passengers impacted by data breach
P&O ferry passengers hit by data breach during sailing
Passengers of P&O Ferries Hit by Data Breach During Strait of Dover Sailing
Pegasus Zero-Click Exploit Infects Serbian Student Activist's iPhone
Pegasus Zero-Click Spyware Exploit Infects Serbian Student Movement Member's iPhone
Pemberton Township Falls Victim to ‘Phishing Scam,’ with $195K Wired to Unintended Recipient
Phishing campaign targets widely used RMM platforms in 46 countries
Plex warns users to patch security vulnerabilities immediately
Radiology vs. ransomware: How to defend imaging departments against cyberattacks
Researcher Releases FalconFlank PoC Showing Privilege Escalation in CrowdStrike Falcon
Russian man indicted for spreading malware to 80,000 freelancers
Russian national indicted after malware sent to 80,000 freelancers
Saskatchewan Health Authority (SHA) confirms patient data breach at Nipawin hospital
Scammers target Revolut users on wealthy British island Jersey
Serbia Faces Largest Documented Spyware Wave as Activists, Students Targeted with NSO Group’s Pegasus
Serious Data Breach in Montana’s Highest Court
Shai-Hulud's Reach Just Grew to 469 Credential Locations. Here's What That Means
SonicWall SMA 1000 under attack: critical zero-day enables complete compromise without authentication
SonicWall Warns of Two Actively Exploited SMA1000 Zero-Days, One Rated Maximum Severity
‘Spring Ring’ Vishing Attack Uses Fake IT Calls on Microsoft Teams to Install Malware
Swiss Bitcoin Service Pocket Bitcoin Reports Data Breach Affecting More Than 5,400 Users
Tech company ignored ethical hacker’s emails, so he contacted himself from their account
Thomson Reuters breach hit court systems in US and Canada
Thomson Reuters Court Software Breach May Have Exposed SSNs and Sealed Data
Thomson Reuters Discloses Court Records Breach Spanning 11 States, the Virgin Islands, and Ontario
Thomson Reuters hit by cyberattack that saw court documents across 11 states accessed by a hacker
Thomson Reuters reveals breach that exposed U.S. and Canadian court records
Thomson Reuters' court data breach is a reminder of a risk clients think someone else is managing
TVING to Pay ₩3 Million Per Customer Over Data Breach; Security Investment to Quadruple
US and Canadian court data exposed in Thomson Reuters breach
US and Canadian Court Records Breached Following Thomson Reuters Incident
US Becomes Top Target in RMM Phishing Campaign Spanning 46 Countries
Why Stopping Upstream Scams Before Money Moves Is a Cybersecurity Problem
Your AI agent’s system prompt is not a security control
Your threat feed is someone else’s database: What ingesting malware intel at scale takes
📅 2nd September
A battery storage cyberattack would look exactly like a badly tuned controller
A Single Digital Trap Costs Trader Rs 3 Crore in Whale Phishing Scam
ATF confirms major cyberattack after Qilin claim: Were gun owners' records exposed?
ATF Major Incident Following Qilin Ransomware Claim
Attackers are going after prominent individuals through OAuth phishing, FBI warns
Attackers Exploit Critical Switchvox Flaw to Deploy Reverse Shells Without Credentials
Attackers Exploit Two SonicWall SMA 1000 Zero-Days That May Form an Attack Chain
Australian organisations may soon face a 72-hour data breach reporting deadline
Authorities Turn Sality's P2P Network Against Itself, Cutting Off New Malware Payloads
Battery storage cyber attack 'could cause national blackout' and £10 billion in damage
BGP Hijack Delivers Malicious Virtualizor Update That Establishes Persistent Root Access
Clark County warns of phishing scam targeting planning permit applicants
Critical JFrog Artifactory Vulnerability Exploited Days After Disclosure
Dropbox accounts breached through Lenovo email verification flaw
Dropbox Breach Traces Back to a Broken Sign-In Feature You Probably Never Knew Existed
Dropbox Data Breach: 5,000 Accounts Compromised
Educational Institutions Face Cyber Risks Far Beyond Phishing
Exploitation of Sangoma Switchvox flaw is underway (CVE-2026-9586)
Exposed ransomware server reveals automated $4 cyberattacks
Extradited Russian Hacker Faces Charges Over Excel Malware Campaign That Infected Thousands
Facebook Ads Promote Fake Streaming Apps Delivering PanDa RAT
Fake IT Support Hackers Abuse Microsoft Teams and Quick Assist to Deploy Reverse Shell
Fake Software Installers Disable Windows Update and Weaken Microsoft Defender
FBI has a 'Public Service Announcement' for everyone on the internet: You may be targeted by...
FBI Investigates Nexus Dark Web Service Selling Over 153 Million US and Canadian Driver’s Licenses
FBI Warns Hackers Are Impersonating Officials and Media in OAuth Phishing Attacks
FulcrumSec Claims Responsibility for Manchester Airport Group Breach
Gambling Goblin Turns Brazilian Government Sites Into SEO Weapons
GeoNetwork Fixes Unauthenticated RCE Chain Affecting Government Geoportal Backends
Global sinkhole operation ends Sality botnet’s 23-year run
Hackers Chain Two New SonicWall Zero-Day Vulnerabilities
Hackers exploit critical JFrog Artifactory flaw to forge admin tokens
Hackers Exploit Critical SonicWall SMA 1000 SSRF and RCE Flaws in Active Attacks
Hackers Exploit LiteLLM Admin API Flaw to Turn Read-Only Access Into Full Server Takeover
Hackers exploit Sangoma Switchvox flaw to deploy reverse shells
Hackers expose donor data from Russian fundraisers for Ukrainians, political prisoners
Hackers Use AI Malware to Break Into Brazilian Banks and Make Fraudulent Transfers
Health data of more than 9.5 million people leaked from Aesto record system
How Industry Coalitions Are Rallying to Secure Open Source Software for the AI Era
Ireland: HSE fined over data breach at former Midlands hospital
It sure looks like hackers breached a major ID card verification service
Kaspersky Uncovers LinkedIn Recruitment Phishing and New Cross-platform Spyware Targeting Africa, Others
Lessons From the Aftermath: Building Security that Fits the Environment You Have
Malicious .git Configs Can Make Claude, Codex, Cursor, and Other AI Agents Run Attacker Code
Malicious Apache Modules Hijack Brazilian Government Site Traffic to Push Betting Pages
Manchester Airports Group Breach: FulcrumSec Publishes Alleged Stolen Data - Future Travel, Marketing Platform Details
Meta Ads Push StreamRat Android Trojan That Can Gain Near-Complete Device Control
Nearly 22,000 Microsoft Exchange servers remain exposed to critical security flaw (CVE-2026-62911)
New pro-Ukraine hacker group targets Russian companies with custom ransomware
New report shows AI-related scams are costing Nevadans thousands of dollars
Nutex Health Says Patient Data Stolen, Hackers Threaten Leak
OpenAI’s agents exploited a patched Linux bug in Hugging Face incident: 6 steps to take ASAP
Ransomware group The Gentlemen claims Glassdoor breach, sets deadline for alleged data release
Ransomware Hackers Built Their Own C2 Framework to Steal Passwords and Kill Security Tools
Reports on alleged massive IDScan.net data breach: 153 million driver’s licenses for sale
Russian Man Extradited Over Malware Campaign Targeting Freelancers
Russian national facing 20 years for malware campaign that infected 80,000 freelancers
Sality botnet infrastructure dismantled in joint global takedown
Sality P2P Botnet’s Remarkable 23-Year Run Has Come to an End
Sality, one of the longest-running botnets, finally gets disrupted
Silver Fox Hackers Target China-Based Organizations With Counterfeit Software Installers
SonicWall SMA 1000 appliances under attack via zero-day flaws
SonicWall warns of actively exploited SMA1000 zero-day flaws
South Korea: Voice phishing cases plunge 40% after crackdown
South Korea: Voice phishing measures cut cases and losses by about 40 percent
The Philippines: Chinese national nabbed over alleged rogue cell site, phishing scheme
TVING Data Breach: 20 Million Records vs. 5 Million Subscribers - Korea's Largest Was 104 Million in 2014 Card Leak
U.S. or Korea? Coupang's data breach lawsuit faces key jurisdiction question
US charges Russian for infecting 80,000 freelancers with malware
Venezuelans plead guilty to hacking ATMs: "Jackpotting bandits are sweeping the nation"
Wave of X password reset emails could be hiding a sneak phishing attack
White hat hackers post UK prime minister’s residence on Booking.com - and people actually try to book it
WordPress backup plugin flaw exposes millions of sites to takeover attacks
X Investigates Password Reset Attack After X Money Launch, No Evidence of Breach
X Users Get Flooded With Password Reset Requests, Raising Fresh Data Breach Fears
X Users Hit By Wave Of Password Reset Requests, Triggers Fresh Data Breach Concerns
📅 1st September
9.5 Million Impacted by Aesto Health Data Breach
13 Malicious Packagist Packages Target Unpatched iPhones to Steal Crypto Wallet Seeds
65% of Enterprises Have Seen AI Agents Act Out of Scope
A Coordinated Cyber Attack by Suspected Iranian Hackers Affected Over 100 Water Systems
Aesto Health says data breach affects over 9.5 million patients
Aesto healthcare data breach impacts 9.5 million people
AI Agents Are Now Orchestrating Entire Ransomware Attacks, Signaling a New Threat Era
AI Helps Drive Number of Linux Kernel CVEs to Near 2,000 Per Release
AI-driven voice phishing is on the rise: what organizations need to do to defend themselves
AI-Powered Phishing Is Making Traditional Email Security Less Effective
Anthropic: Attackers Using Infostealers to Hijack Claude Sessions
Anthropic boots users, wipes payment info to protect against malware attack
Attackers Abuse Trusted Cloud Services to Hide Phishing Attacks Against Financial Organizations
Attackers Exploit Critical JFrog Artifactory Flaw to Mint Admin Tokens Days After Disclosure
Attackers Exploit Critical Langflow and Rails Flaws in Credential-Probing and C2 Activity
Attackers Steal METR API Key and Burn $600,000 in AI Credits
Attackers Steal METR API Key and Consume AI Credits Worth About $600,000
Baptist Health warns patients of MyChart phishing scam
Berlin refuses to be blackmailed after network breach
Berlin’s Seven-Day Ransomware Isolation Gap Let Rhysida Steal Critical Infrastructure Data
Biggest Cyberattacks Changing the Security Landscape
Breeze Comet Executes Hundreds of Fraudulent Transactions via Brazilian Payment Systems
Canada: ‘All levels of government’ being impersonated by scammers, says Municipalities Newfoundland and Labrador (MNL)
Charity supporters’ warned after cyber attack exposes personal data
Chicago Family Health Center Data Breach Affects 90,000
China-Nexus Fire Ant Hackers Target Cisco Routers, TACACS Servers for Espionage
China's 'Fire Ant' campaign used compromised Cisco routers as platform for more attacks
City of Missoula warns of ongoing phishing scam
Clark County warns of phishing scam impersonating Planning Department
Cornerstone Healthcare Data Breach: 14,830 Patients Exposed
Critical Langflow flaw exploited to steal OpenAI and AWS keys
Cyber risk from frontier AI poses ‘most immediate concern’ to global financial system, watchdog warns
Cybersecurity experts issue warning after Winona County pays $128k following ransomware attack
Dark web listing contradicts Dodo Payments’ data breach disclosures
eBay Disables Community Messages After Wave of Phishing Scams
Fake Claude Opus 5 app delivers malware and wipes its own tracks
FBI raises alarm over deceptive phishing campaign targeting prominent people
Fidelity Data Breach Costs $3.75 Million in Combined Fines
Financial Stability Board Sounds the Alarm Over Frontier AI Risks
Five Venezuelan Nationals Plead Guilty After Kansas ATM Jackpotting Attempts, FBI Reports 1,900 US Incidents Since 2020
Five Venezuelans plead guilty to ATM jackpotting attacks in US
Flock backlash turns into statewide fight as Florida pushes cameras off roads
Florida and Texas move to block Flock cameras over privacy concerns
FulcrumSec Leaks Manchester Airports Group Customer and Booking Data
Hacker breaches creators of Hello Neighbor horror game and blackmails them - demands game be removed from sale
Hackers abuse Faronics Deploy admin tool to install ScreenConnect
Hackers are using fake MP4 video files to smuggle payloads past security filters
Hackers breach 5,000 Dropbox accounts using only victims’ email addresses
Hackers Demand Ransom After Berlin Data Breach
Hackers give Glassdoor 172 hours to stop dump of allegedly sensitive data
Hackers push malicious Virtualizor update in BGP hijacking attack
Healthcare facilities operator Nutex says patient, employee data stolen in August incident
Healthcare Giant McKesson Investigates Data Breach Incident
Hong Kong: E-commerce data breach affects more than 33k
Horizon Eye Care Data Breach: PHI Potentially Exposed
Identity-based attacks involved in 85% of education ransomware incidents
India: Told to stop posting flaws, teen hacker uses government email ID to troll Cert-In
India Catches Meta Running Malware-Laced ‘Adult’ Ads on Facebook and Instagram That Drain Bank Accounts
Integrated Specialty Coverages Data Breach Exposes Driver's Licenses
Investigation opened on OpenAI by Montana Attorney General Austin Knudsen following data breach
Iranian cyber spies target aviation, fintech developers with new malware
Iranian Hackers Pose as Recruiters to Deliver Cross-Platform RATs Through Coding Tests
Ireland: HSE fined €645,000 over data breach affecting Westmeath hospital
Kiewit discloses data breach affecting employees and contractors after email account compromise
Majority of Senior Cybersecurity Leaders Have Limited Trust in AI
Manchester Airports Group hit by cyber attack
McKesson Confirms Data Breach as ShinyHunters Claims 284 Million Records Stolen
McKesson Confirms Data Breach, Experts Weigh In
McKesson data breach exposes prescribing physicians and their patients to fallout from a third-party attack
Mira Partners Suffers Personal Data Breach, Encryption Key Exposure Unclear
Nearly 22,000 Microsoft Exchange servers exposed as exploit goes public
Nearly 22,000 Microsoft Exchange servers vulnerable to hijack attacks
Nephrology Associates Data Breach Affects 24k Patients
Novocure data breach affects more than 1,400 cancer patients
Omdia Study Highlights Declining Ransomware Recovery Rates and the Immutability Gap in Backup Storage
P&O ferry passengers hit by data breach during sailing
Qilin hackers leak ATF data, exposing criminal investigations and phone records
Qilin Leaks 6.3GB of Alleged ATF Files, Then Pulls Download Links
Ransomware Gang Claims Nutex Health Data Breach
Ransomware gang leaks sensitive files from ATF investigations
Ransomware Group Claims Andover As Victim Following Cyberattack
Ransomware in 2026
Recently patched PaperCut zero-days used in data theft attacks
Ross Township issues warning about phishing email claiming to be from planning commission
Russia-Aligned UAC-0099 Plants Nuclear Weapon Prompt in Malware to Disrupt AI Analysis
Scammers Running Fake Cryptocurrency AML Wallet-checking Sites Hoodwink Users, Drain Wallets
Some seek compensation following Road Traffic Safety Directorate (CSDD) cyber attack in Latvia
South Africa: Gert Sibande Municipality issues urgent warning over phishing emails
Stronger Security Drives Ransomware Groups to Recruit From Within
The Gentlemen come calling as Nutex confirms sensitive data theft
The Most Immediate Threat to the Global Financial System Is AI Cyberattacks
They prey where kids play: how gaming phishing scams now target kids
Threat Actors Don’t Want Better Attacks. They Want Repeatable Ones
TVING data breach exceeds subscriber base, raising questions over 19.53 million figure
Ungentlemanly behavior: Insights into a ransomware operation
Vishing campaign abuses Microsoft Teams to give attackers a foothold in company networks
White House Launches Pilot Program in Texas to Protect Water Infrastructure
Why are Ransomware Hackers giving victims only 7 days to pay the Ransom
Winona County Paid $128,000 Following Ransomware Attack
Winona County, Minnesota, Paid $128K Ransom to Restore Services
X Data Breach? Users Are Getting Flooded With Password Reset Emails Nobody Requested
X says attackers are targeting user accounts after the launch of X Money
📅 31st August
85% of Education Ransomware Starts with Stolen Identities
'128 Billion Won Fine' GS Retail Apologizes for Data Breach, Vows to Strengthen Security System
AI agent in Cursor linked to ransomware breaches at 7 companies
AI agents read legitimate llms.txt files from trusted companies and proceed to install malware
AI AppSec tools agree on just 5% of security findings
AI killed the typo. Now it’s time to rewrite phishing training
Anthropic locks out Claude users after infostealers hijack login sessions
Anthropic Warns Commodity Infostealers Are Hijacking Claude Sessions to Drain Paid Usage
Apple shares ‘shocking evidence’ against former employee accused of stealing company data for OpenAI
AshSqlite Vulnerability (CVE-2026-77846) Exposes Hidden JSON Fields
Attackers plant remote access tools on compromised PaperCut servers
Aurora Ransomware Hackers Use Cursor AI Agent for Hands-On Exploitation and ESXi Attacks
Aurora Ransomware Hackers Used AI to Attack Companies Across Nine Countries
Aurora Ransomware Operators Use Cursor AI in Attacks Against 10 Targets
Australian app developer DigiGround investigating ransomware claims
Boston Scientific Cyberattack Limited to Unauthorized Access on Certain On-Premises Systems
Bureau of Alcohol, Tobacco, Firearms and Explosives Discloses Cyber Incident
Berlin Confirms Data Theft After Rhysida Attack: 5.79TB
Berlin confirms data theft after Rhysida ransomware attack claims
Berlin Won’t Pay Extortion Group Claiming Data Theft
Blind Eagle-Linked Loader Uses GitHub, VBScript, PowerShell and InstallUtil to Deploy AsyncRAT
CareCloud data breach affects more than 3.75 million people
CarGurus Data Breach Exposes 12.5 Million Accounts; Here's What Hackers Got
China-Linked Fire Ant Hijacks Cisco Routers to Steal Credentials and Blind Security Logs
Chinese Fire Ant hackers turn Cisco routers into spying platforms
Court upholds firing of Korea Food Research Institute (KFRI) executive for crypto mining and data breach in Korea
Cronos blockchain restarts after $74 million Tectonic exploit
Cybersecurity's “Hiring Crisis” is Fueling the Cybercrime Talent Pipeline
Darksiders Publisher THQ Nordic Named on DireWolf Ransomware Leak Site
Data Breach & Blind Spots: The Cyber Risk for Supply Chains
Data Breach at Los Angeles County Museum of Art. What Was Leaked?
Delta School District reports website cyber attack
Department of Justice (DoJ) Corrects China Hacking Claim, Says U.S. Agencies Were Targets, Not Victims
Extortion Group Claims Manchester Airports Group Data Breach
Fake Claude Opus 5 App Spreads New RevStealer Windows Malware
Fake MyChart messages target patients across Pennsylvania
Fidelity’s $2.5 Million Data-Breach Settlement Puts A Price On Losing Control Of Customer Data
Five plead guilty in latest federal ATM jackpotting case
Fogo Blockchain Halts Operations Due to Hacker Attack and $3 Million Theft
Fraudsters steal $6 million from Tectonic crypto platform after inflating token price
Free Cloudflare DNS Tweak Blocks Malware and Phishing Across Home Networks
Free Router DNS Tweak Blocks Malware and Phishing Across Home Networks
FulcrumSec Hackers Claim Manchester Airports Group Data Breach
GS Retail fined $9.3 Million following customer data breach
GS Retail fined 12.8 billion won over data breach affecting 1.66 million users
Guernsey: Doctor's appointment phone call led to data breach
Hacker puts data of 820 million Alipay users up for sale
Hackers claim millions of patient records stolen during data breach at healthcare giant McKesson
Hackers demand €2 million from Berlin, threaten data leak
Hackers Steal Identity, Vehicle Data from Latvia’s Road Traffic Safety Directorate
Hackers threaten to spill the secrets behind America’s food safety giant Neogen
Hackers’ Own Malware Infection Exposes Their RATs, Phishing Kits and Attack Infrastructure
Hasbro Breach Exposes Employee Information
Hasbro Data Breach Exposed Employee SSNs and Driver's License Data
Hong Kong police arrest two men allegedly linked to HK$500,000 phishing scam
How AI could make it harder for governments to use hacking tools
How to Prepare for AI-Driven Cyberattacks
Human Rights Writers Association of Nigeria (HURIWA) faults police, National Data Protection Commission (NDPC) over delay in probe of alleged National Institute for Policy and Strategic Studies (NIPSS) data breach involving naval officer
Identity theft attacks account for 85% of ransomware cases in education
Identity-based attacks account for 85% of ransomware incidents in education
Identity-Based Attacks Are Responsible for 85% of Ransomware in Education
India: Hyderabad publisher hit by ransomware, €20m ransom sought
Infostealer Malware Steals Claude Session Cookies to Hijack Accounts and Bypass 2FA
Iranian-Linked Cyber Attack Shuts Down a UK Power Plant
Law Society of Scotland issues fraud alert after phishing email
Ledger Phishing Scam: Fake Wallet Website Targets Crypto Users - What You Need to Know
Manchester Airports Group Data Breach: FulcrumSec Claims the Theft of 86 GB via Exposed Iterable API Credentials
McKesson confirms cyber incident after ShinyHunters claims patient-data theft
McKesson Confirms Breach: 284 Million Records, $55 Million Demand
McKesson Confirms Data Breach as Attacker Deadline Looms
McKesson discloses data breach after ShinyHunters claims theft of 284 million records
Microsoft warns of TerminalFix attacks deploying reverse tunnels
Microsoft Warns of TerminalFix Campaign Hiding Malware in PNG Images
National Health Insurance Service (NHIS) phishing scam exposes gaps in South Korea fraud insurance
Nigeria: Rights Group Decries Delay In Probe Of Alleged Data Breach By National Institute for Policy and Strategic Studies (NIPSS)
Nigerians extradited to US for sextortion, deaths of two teens
North Korean Job Fraud Expands Beyond IT Into Healthcare and Sales
Only 33% of AI Agents Provisioned With Least-Privilege Access
Open ATF criminal case files leaked by Russian ransomware hackers
OpenAI Warns Astra AI Could Develop Zero-Day Exploits and Launch Autonomous Cyberattacks
P&O Ferries data blunder as it sends out passengers' personal details by text message
PaperCut Issues Second Emergency Patch as Researchers Break Fix for Exploited Zero-Days
Pharmaceutical giant McKesson warns of 'service degradation' following cyberattack
Phishing scam is targeting 'MyChart' patient portal users
Phishing scam spreading around Pennsylvania involving fake alerts from MyChart
Qilin hackers leak ATF data, exposing criminal investigations and phone records
Ransomware attack hits Norcross' computer systems, leaving disruptions, officials say
Ransomware attack reportedly exposes Carhartt data
Ransomware Gang Names ATF; Department of Justice (DOJ) Calls Breach ‘Major’
Ransomware-as-a-Service democratizes hacking
Rhysida Ransomware puts Berlin Government Data up for sale for 30 BTC
Russian hackers plant nuclear weapon prompt in malware to trip AI safety guardrails
Security Leaders Weigh in on Recent PaperCut Vulnerabilities
ShinyHunters claims it stole 284 million patient records from McKesson
ShinyHunters Claims Theft of 284 Million Records from Healthcare Giant McKesson
Simple Router DNS Tweak Blocks Malware and Phishing Across All Connected Devices
Slovenian casinos reopen after cyberattack knocked gaming systems offline
Small businesses and cyberattacks: why phishing is still the threat to watch
'Sophisticated' AI swarm attacks are months away, OpenAI warns: What experts say businesses must do
South Korea fines GS Retail $9.2 million over data breach affecting 1.66 million customers
Steam Data Breach Exposes Over 12TB of Source Code, Unreleased Projects
Steam leak that exposed a decade of game history wasn’t even a hack
TerminalFix Attack Uses Fake Cloudflare CAPTCHA to Deploy Reverse Tunnel Into Corporate Networks
Threat actors are posing as AI crawlers to hunt for exposed credentials
US cities cancel Flock contracts at record pace in August
US healthcare giant McKesson breached, ShinyHunters claims 284 million patient records
ValleyRAT Backdoor Hides in Signed Adware That Users Add to Antivirus Exclusions
What a Financial Data Breach Actually Costs a Fintech in 2026
What vulnerability prioritization looks like when KEV, EPSS, and CVSS disagree
When a Cyber Loss Has No Conventional Hacker
Wippy Data Breach Exposes 736 Users' Height, Blood Type; South Korea Fines nRiZE ₩118 Million
Your Money and Data Are at Risk as Phishing Attacks Rise
ZeroBytes breaches Zéro Logement Vacant, data of nearly 48 million French property owners exposed
Welcome to DBD. On March 8th 2026, DBD celebrated it's sixth anniversary and