Welcome to this week's Data Breaches Digest, a catalogue of links concerning Data Breaches and Cyber Security that were published on the Internet during the period between 24th August and 30th August 2026.📅 30th August
29CM data breach exposes 160,000 records; Korea probes as users warned
A hacker with no history sells the data of 41,300 clients of the marketer Yaluz on Telegram
Already patched PaperCut? You need to do it again
Anthropic warns infostealer malware is hijacking Claude sessions to drain usage
ATF Hacked: Qilin Claims Breach, 885 Victims
Berlin Under Cyber Siege as Hackers Threaten to Auction 5.79TB of Stolen Data
Berlin won’t pay its hackers - now 5.8TB of government data could go up for auction
CareCloud Breach Hits 3.75 Million People
Chrome Web Store extensions caught stealing crypto, browser data
Fake Claude apps fuel new wave of AI cyberattacks
Florida hospitals warn patients about 'MyChart' phishing scam targeting portal users
FulcrumSec claims Manchester Airports hack, theft of 86 GB of data
Hasbro breach exposes employees’ addresses, IDs, and financial information
Healthcare data breach exposes 3.75 Million patient records
Hong Kong: WhatsApp hijacking cases surge 154% to 2,020; manager loses $12 million
How Hackers Build Advanced Phishing Pages to Steal Credentials
Human Rights Writers Association of Nigeria (HURIWA) faults Inspector-General of Police (IGP), National Data Protection Commission (NDPC) over delay in probing alleged National Institute for Policy and Strategic Studies (NIPSS) data breach involving naval officer
Human Rights Writers Association of Nigeria (HURIWA) faults police, National Data Protection Commission (NDPC) over alleged National Institute for Policy and Strategic Studies (NIPSS) data breach probe
Human Rights Writers Association of Nigeria (HURIWA) tackles Police, National Data Protection Commission (NDPC) over alleged National Institute for Policy and Strategic Studies (NIPSS) data breach involving naval officer
Manchester Airports Group breach exposes data of 8.7 million airport customers
Musinsa subsidy 29CM's data breach affects 159,000 customers
Musinsa's 29CM Suffers Data Breach Affecting 160,000 Customers, Including 20,000 with Shipping Details
Rhysida Claims Berlin Government Hack: 5.79 TB, 30 BTC
Tax Season Phishing Scheme Spreads New PackClient Malware Across Asia
TerminalFix Uses Fake Cloudflare CAPTCHAs to Deploy Reverse-Tunnel Backdoor
Ticket Resale Platform Tixel Warns Users Of Data Breach In Metabase Zero-Day Attack
📅 29th August
2 PaperCut NG/MF Zero-Days Exploited in Attacks, Emergency Patch Released
30 Bitcoin or leak - ransomware gang extorts Berlin
A Russian Ransomware Gang Says It Broke Into the ATF's Investigation Files
Attorney general warns Pennsylvanians of phishing scam targeting online healthcare portal
Baylor Genetics data breach hits 2.8 Million
Berlin‘s government faces a Rhysida ransomware attack
Carhartt data breach exposed information from 12.9 million user accounts
Chinese Hackers Deploy PackClient RAT via Tax-Themed Phishing Attacks to Steal Data
Cl0p Ransomware Hits Shell, GE, Philips via PTC Bug
Critical Gogs Path Traversal Flaw Enables Remote Code Execution via Git Hooks
Five Critical WordPress Plugin and Theme Flaws Enable Site Takeover or RCE
Hacker Group Threatens to Auction Berlin Government Data
Hacker Shows Anyone Near a Unitree G1 Robot Can Seize Root Control
Hackers Steal €152,000 From Crete Regional Authority in Elaborate Bank Fraud Scheme
Hasbro Data Breach Exposed Employee Personal Information
Hasbro Discloses Employee Data Breach: 436 SSNs Hit
India Tops Weekly Infostealer-Infected Machine Count as Experts Outline Remediation
Penn Medicine Warns Patients as MyChart Phishing Scam Spreads
Second-hand ticket marketplace Tixel confirms customer information stolen in data breach
Microsoft Warns TerminalFix ClickFix Campaign Uses Fake CAPTCHA to Deploy Reverse Tunnel
MyDr data breach: Poles rush to government service to check whether their data were exposed
Norcross Ransomware Attack Hit City Systems Weeks Before Officials Went Public
Over 335 Million records breached as cyber attacks rise in the Philippines in H1 2026
Phishing scams reported targeting MyChart users
Ransomware group says it stole Berlin data, offers it for auction
Rhysida Ransomware Group Targets Berlin Government Ahead of Vote
Robert Burns farm charity warns members after cyberattack data breach
Supply Chain Worm Hits Popular TanStack Query Code Generator to Steal Developer Credentials
TA4922 Hackers Use Tax Phishing to Deploy PackClient RAT Across Asia
US healthcare giant McKesson breached, ShinyHunters claims 284 million patient records
US insider-threat hunter admits leaking state secrets to foreign government
📅 28th August
8.7 million customers’ data accessed in cyber attack against three UK airports - including one in the Midlands
8.7 million people exposed in Manchester Airports Group cyber attack
19 Chrome and Edge Extensions Found With Wallet-Stealing and Crypto-Draining Code
700 OpenAI AI Agents Coordinate Hugging Face Hack and Achieve Remote Code Execution
A Backup Isn’t Enough: How Small Businesses Can Recover From Ransomware
AI Agent Instruction Files Let Attackers Execute Code Inside Fortune 500 Networks
AI Ransomware Can Now Run Much of an Attack Without Human Help
AI scams make phishing harder to spot
Alan Gordon Data Breach Exposes Social Security Numbers
American Vision Partners Settles Data Breach Litigation for $1.75 Million
Android 17 adds new protections against sneaky Wi-Fi tracking and web snooping
Android 17 Adds OS-Wide Encrypted Client Hello (ECH) to Hide Website Visits From Network Providers
APT28-Linked HOOKEDGE Backdoor Targets European Government and Diplomatic Organizations
Arrests Hinder TeamPCP, But the Threat is Still Out There, Researchers Say
ATF Confirms Cyber Incident After Ransomware Group Claims Attack
ATF confirms cyberattack hit system containing info on its investigation targets
ATF Confirms Major Cyber Incident Amid Qilin Claim
ATF declares cyberattack a ‘major incident’ after ransomware claim
Attackers Chain Two PaperCut Flaws to Execute Code Without Authentication
Aurora ransomware actors leverage AI tool for exploitation campaigns
Aurora ransomware gang used Cursor to speed up attacks: 30% to 50% faster intrusions
Aur0ra ransomware tricked Cursor's AI agent into hacking seven companies
Berlin is being blackmailed by hackers, mayor says
Berlin Refuses to Pay Hackers Who Stole Data From the City's State Network
Castle Point Council sees personal information data breach
China-Made ZBT Routers Ship With Two Implants Giving Unauthenticated Attackers Root Access
Chinese-Speaking Hackers Target Indian Firms With Hindi Tax Phishing
Cosmos EVM Flaw Exploited After Cosmos Labs Knew Every Blockchain Running It Was Vulnerable
Critical cPanel Flaw Could Let One Hosting Customer Take Root Control of a Whole Server
Cyber Attack Hits Manchester Airport Group as Data of 8.7 Million Customers Accessed
Cyber attack targeted customers at Stansted Airport
Cyber Threats Explained: What They Are and Why They’re Growing
Cyberattack on Three UK Airports Exposes Data of 8.7 Million Customers
Cyberattack on UK Airport Operator Manchester Airports Group (MAG) Exposes Data of 8.7 Million Customers Across Three Airports
Cybersecurity alert: phishing campaigns increasingly target hotel staff
East Midlands Airport hackers demand ransom after passenger data stolen
Encryption Expiration: How AI and Quantum are Defining New Boundaries for Data Security
Epic MyChart Phishing Scam Hits Health Systems: What Providers Should Do
Europe’s Cyber Risk: Ransomware and Critical Systems
Fake Indeed apps infecting Android-using job seekers with malware
Fake North Korean IT workers are rampant: Here’s how to spot the telltale signs a new hire is a hacker
Fake Voicemail SVG Attachments Fuel Large-Scale Phishing Campaign
Fraud alert: Phishing emails purporting to be from the Law Society of Scotland
GiveWP WordPress donation plugin flaw lets hackers execute server commands
Hackers Exploit AI and Deepfakes to Breach Fiji Businesses, Expert Warns
Hackers Make Phishing Pages Change Their Code Every Time Someone Opens Them
Hackers say they know where nearly half a million diamond customers live
Hackers steal data linked to 8.7 million customers across three UK airports
Hackers steal personal data of 8.7 million customers in cyber attack on three UK airports
Health systems warn of phishing scams using Epic’s MyChart name and logo
How Recruitment Phishing Puts Employee Credentials at Risk on Smaller Mobile Screens
Hungry Lion fast food chain hit by ransomware attack claimed by MeduzaLocker
Identity-Based Attacks Drive 85% of Education Ransomware
Is Your Home-Based Business Ready for a Cyber Attack
Latvia: Huge cyberattack affects two-thirds of country’s population
Linux accounts for half of CISA’s latest actively exploited flaws
Love Electric Breach: 877,000 Driver Records Offered for $600
Over 8,300 Gitea servers vulnerable to code execution attacks
Manchester Airport Data Breach Exposes 8.7 Million Travellers
Manchester Airport Group Suffers Data Breach of Customer Info
Manchester Airport hackers demand ransom after 8.7 million passengers' data stolen in major cyber attack
Manchester Airports Breach Impacts 8.7 Million
Manchester Airports Group breached, millions of customers’ data stolen
Manchester and Stansted owner claims hackers demanded ransom during cyber-attack
Manchester HIV charity George House Trust warns users of data breach
Manchester, Stansted and East Midlands airports hit by cyber attack
Manchester, Stansted and East Midlands cyber attack: Operational Technology (OT) security lessons for engineers
McKesson discloses breach after ShinyHunters claims patient data theft
Millions of patients warned after DNA testing data breach
Mirage2FA: The Phishing Service Turning a Stolen Microsoft 365 Cookie Into Full Account Takeover
Morocco's DGSN-DGST security hub formally refutes data breach allegations
MP gives update on cyber attack at East Midlands Airport impacting millions of travellers
MyChart patient portal users warned of phishing scams
National Cyber Security Centre (NCSC) warns of growing cyber threat to exposed OT and edge devices
New campaign targets Cambodia with Spark RAT using Bring Your Own Vulnerable Driver (BYOVD) technique
New exploit tricks Claude Code into running malicious code despite Auto Mode
North Korean remote workers are broadening their job hunt beyond IT
Nvidia’s Error Correction Code (ECC) was supposed to stop memory corruption, but attackers can hammer their way to root
ownCloud Flaw Exploited to Steal Nuclear Records From Philippine Research Body
Palo Alto Networks Researchers Say First Wave of AI-Enabled Attacks Has Begun
PaperCut releases second emergency patch for exploited flaws
PaperCut warns of hackers using printer management software flaw in attacks
PaperCut Zero-Day Exploited in Attacks, Affecting All NG and MF Versions
Pennsylvania Attorney General Warns of MyChart Phishing Scam
Phishing and ransomware attacks rise in the Philippines during 1H 2026
Polymorphic Phishing Attack Generates Unique Credential-Stealing Page on Every Visit
Punch & Associates Data Breach Exposes Financial Information
Ransomware Activity Hits 2026 High as Attacks Rise 22%
Ransomware attack targets Norcross city computer systems, officials say
Ransomware Attacks on Industrial Control Systems Rose in Q2 2026
Ransomware Gang Claims AI Can Analyze 700GB of Stolen Data Every Hour
Ransomware group auctions stolen Berlin data after ransom refusal
Ransomware Is Changing Shape. What India’s Threat Landscape Reveal
Report Finds AI Security Fails to Match AI Usage
RMM Phishing Campaign Spans 46 Countries as Attackers Abuse Trusted IT Tools
Russian-Linked Hacker Group Breaches Seven Companies by Exploiting AI From SpaceX-Backed Cursor
ServiceNow Patches Critical Flaws Enabling Unauthenticated RCE and SQL Injection
ServiceNow warns of three max severity security vulnerabilities
Sharp Motor Group confirms third-party cyber incident in wake of ransomware claims
ShinyHunters claims McKesson data breach exposing 284 million patient records
South Korea: Phone Numbers Used in Voice Phishing and Other Crimes to Be Suspended Within 24 Hours
Spectrum Laboratory Data Breach Exposes Social Security Numbers
St. Luke’s University Health Network warns patients of phishing scam using MyChart name, branding
Stansted Airport cyber attack: Millions of passengers' details accessed by hackers
SVG attachments used in widespread phishing campaign
TA4922 uses PackClient malware in tax phishing attacks
The ATF Was Just Hit by a ‘Major’ Hacker Breach - And Investigation Targets Were Exposed
Threat Actors Abuse Cursor Agent AI to Assist Ransomware Operations
Three CVSS 10.0 ServiceNow Flaws Could Let Unauthenticated Attackers Execute Code and SQL
Toy-making giant Hasbro disclose data breach affecting employees
Two Unitree G1 EDU Humanoid Robot Flaws Enable Root RCE, One Starts Over Bluetooth
UK airport operator confirms data breach affecting 8.7 million customers
Unitree G1 Humanoid Robot Flaws Enable Unauthenticated Root RCE Over Bluetooth
US Disrupts Global Botnet Used by China-Linked QTFY Hackers
US government alcohol and firearms agency ATF declares ‘major incident’ after ransomware gang claims cyberattack
US thwarts major Chinese hacker cyberattack targeting Senate and NASA
What the NHS Cyber Attack Taught Us About Business Continuity
When does a cyber attack count as an act of war?
White River Junction Veterans Affairs (VA) reports data breach of veterans’ information
Window to Tackle Surge in AI-Enabled Cyber Attacks Narrowing, Tech Giants Warn
Winona County Confirms $128,539 Ransomware Payment After January Cyberattack
📅 27th August
8.7 million customers affected by data breach at Manchester, Stansted and East Midlands airports
8.7 million customers hit as Manchester Airports Group breach exposes airport WiFi sign-ups
8.7 million customers’ data accessed in cyber attack against three UK airports
8.7 million passengers affected by cyber attack on three UK airports
8.7 million people exposed in Manchester Airports Group cyber attack
12.9 Million Exposed by Carhartt Data Breach
A cyber attack affected three airports in the United Kingdom, compromising the personal data of 8.7 million customers
Account Takeover Flaw Hits TranslatePress Plugin Used on 400K WordPress Sites
Aerospace Alloys Data Breach Exposes Social Security Numbers
Africa Faces 3,008 Cyberattacks Weekly as Ransomware Groups Hit Record 93
AI a 'force multiplier' for low-skilled threat actors: 4 ways organizations should respond
AI Models are Finding Vulnerabilities Faster
Alleged TeamPCP Hackers Charged in Australia Over Major Supply Chain Attacks
Amazon Kiro Prompt Injection Can Exfiltrate Sensitive Data Through Kiro Powers
Android 17 adds Encrypted Client Hello (ECH) support to make web browsing harder to track
Applebee's Franchisee in Independence Sued Over Employee Data Breach Cover-Up Claims
ATF Confirms Major Cyberattack After Qilin Claim - Were Gun-Owner Records Exposed?
ATF confirms “major incident” after recent Qilin breach claims
ATF declares ‘major incident’ as ransomware gang claims hack
ATF investigates ‘major’ cybersecurity incident as ransomware group claims attack
ATF investigating ‘major’ cybersecurity incident
ATF investigating ‘major’ cyber incident after ransomware group claim
ATF responds to 'major' cybersecurity incident after ransomware gang's claims
Attackers are moving faster than security experts can patch, Microsoft warns
Aurora Ransomware Affiliate Uses Cursor AI to Plan Attacks Against 20+ Organizations
Australia Arrests 2 Alleged TeamPCP Hackers
Australia arrests alleged TeamPCP hackers behind supply-chain attacks
Australia charges two men for TeamPCP supply-chain hacking spree
Australian police arrest two over TeamPCP hacks targeting Mercor, OpenAI, and others
Barracuda Ransomware Syndicate Leaks 850,000 Files from US Water Infrastructure Supplier Micro-Comm
Bell American Group Data Breach Exposes SSNs and Medical Records
Beyond the Hype: AI, Ransomware and Business Models
Boston Scientific Confirms Cyberattack That Affected Network Communications, Disrupting Global Operations
Boston Scientific Cyberattack Disrupts Order Processing, Shipping Worldwide
Boston Scientific Reveals Global Disruption After Cyber Incident
Boston Scientific's IT team continues its 'recovery efforts' after cyber attack
Carhartt data breach exposes information of 12.9 million accounts
Carhartt hit by data breach claimed by hacking group ShinyHunters
Chinese and Russian spies stepping up cyberattacks, German companies report
Chinese Hacker Group QTFY Uses Custom-Built Platforms to Target US Infrastructure, FBI Warns
Chinese Hacking Operation Targeted U.S. Senate, NASA, Federal Reserve
CISA Adds Six Exploited Flaws to KEV, Including NetScaler, Linux, and SQL Server Bugs
CISA orders feds to patch Citrix NetScaler RCE flaw by Saturday
CISA Warns of Six Exploited Flaws in Microsoft, Linux, Red Hat and Citrix Products
Claude Opus 4.6 Found a Gym API Flaw - Then Exploited It in 9 of 10 Tests
Customer data accessed in cyber attack affecting East Midlands Airport
Cyber attack at Windsor-Essex Children's Aid Society under investigation
Cyber attack hits Manchester, Stansted and East Midlands airports as customer data stolen
Cyber Attack Hits Three UK Airports, Exposes Millions Of Customers’ Data
Cyber attack targeting Hachette Australia subsidiary hurts bookshops and authors
Cyberattack causes network outage at Boston Scientific, disrupts global operations
Cyberattack on Manchester Airports Group exposes data of 8.7 million customers
Data Breach Affects 8.7 Million Customers of Three UK Airports
Data of 8.7 million customers stolen in cyber attack on Manchester, Stansted and East Midlands Airports
Data stolen from 8.7 million customers after three airports targeted in cyber attack
Department of Justice (DOJ) and FBI Seize Chinese Hacking Platforms QScan and QTRouter
Department of Justice (DOJ) Confirms Ransomware Attack On ATF Claimed By Russian Cyber Gang
Department of Justice (DOJ) firearms agency says hackers breached system containing investigation targets
Department of Justice (DOJ), NASA, Others Among Victims of Chinese State-Sponsored Hack
E.ON Energie Romania warns about a phishing campaign with false messages regarding "unpaid bills"
East Midlands Airport hit by cyber attack, millions of customers affected
East Midlands Airport issues advice to customers after cyber attack affecting millions
Everything we know about the Boston Scientific cyber attack so far
Exposed Aurora ransomware server reveals AI-assisted attacks, stolen credentials and crypto laundering
FBI Seizes China State-Sponsored Hacker Platforms Used to Target U.S. Critical Infrastructure
FBI Seizes Chinese Hacker Platforms That Targeted NASA And The Senate
Former Los Angeles County Museum of Art (LACMA) Curator Sues Museum, Says It Sat on Data Breach for a Year
GoCaracal Malware Uses Ethereum Smart Contract to Fetch Replacement C2 Address
HD Hyundai Units Fined Over Employee Data Breach
HIV charity warns users of data breach after cyber attack
How Threat Research and MDR Help SMBs Build a Defensive Edge
Huge cyber-attack sees 8.7 million UK airport passenger details stolen
Is Stansted Airport parking affected by the cyber attack?
Life Bridges Data Breach Exposes Personal and Medical Information
Los Angeles County Museum of Art (LACMA) Data Breach Exposed Social Security and Medical Data
Los Angeles County Museum of Art (LACMA) Sued Over Extensive Data Breach
Major cyber attack at UK airports with 8.7 million customers' data compromised
Major cyber attack on Manchester Airports Group sees 8.7 million customer's data stolen
Major Manchester Airports Group cyber attack as 8.7 million customers' data accessed
Manchester Airport Breach Hits 8.7 Million Customers
Manchester Airport cyber attack: What you must do if you think you're affected
Manchester Airport Data Breach: Manchester Airport Cyber Attacked 8.7 Million Customers’ Data - Check Current Status, Customer Guidance & What to do If Affected
Manchester Airport Group hit by cyber attack
Manchester Airport Group Hit By Cyber Attack With 8.7 Million Customers’ Data Stolen
Manchester Airport group hit with data breach as millions of passengers impacted
Manchester Airports Group Hit by Cyber Incident
Manchester Airports Group says hackers stole travelers' data
Manchester Airports Group (MAG) confirms cyber attack exposed customer emails, phone numbers and vehicle details
Manchester Airports Group cyber attack - all we know so far as 8.7 million customers affected
Manchester Airports Group hit by major cyber attack as 8.7 million customers affected
Manchester Airports Group suffers data breach exposing customer data
Manchester, East Midlands and Stansted airport cyber attack: Data of 9 million passengers 'obtained' by hackers as warning issued
Manchester, Stansted and East Midlands Airports Hacked in Major Data Breach
Medical Device Manufacturer Boston Scientific Faces Cyberattack
Millions of customers hit by cyber attack on East Midlands Airport owner
Millions of customers' data accessed after cyber attack on Manchester Airports Group
Mirage2FA: The Phishing Service Turning a Stolen Microsoft 365 Cookie Into Full Account Takeover
Mobile networks expose IMEI and other phone data to attackers
mTrade Data Breach Exposes Social Security Numbers
NCC Group logs record July ransomware cases as AI rises
Nearly 700 rogue AI agents coordinated in the Hugging Face attack
Nearly nine million holidaymakers' data stolen after cyber attack on three UK airports - including Stansted and Manchester - with phone numbers, vehicle registrations and postcodes among seized data
New GPUThor Rowhammer Defeats ECC on NVIDIA RTX A6000 to Gain Host Root Access
Next.js Patches Critical AVIF and Windows Flaws Enabling Unauthenticated RCE
Nutex Health Data Breach - Hackers Gained Access to Network and Exfiltrated Data
OpenAI: Hugging Face Incident a “Warning Shot” to the World
OpenAI Report Explains How Its AI Agents Breached Hugging Face Systems
OpenAI reveals the true scale of AI cyberattack on Hugging Face
OpenAI Says Reward Hacking Drove AI Agents to Exploit Zero-Days and Breach Hugging Face
OpenAI, Anthropic, Warn of ‘Limited Window’ for AI Cyber Defense
Pan American Group Data Breach Exposes Social Security Numbers
Pan American Group discloses data breach after suspicious network activity
PaperCut warns of NG, MF flaw exploited in zero-day attacks
Passenger data stolen in Manchester Airports Group (MAG) data breach
Phishing scam targets Edmond Santa Fe High School
Pokémon Responds After Hacker Compromises Its X Account to Hawk MemeCoin
Poland Accuses Meta of Poor Handling of Scams and False Ads, Seeks €250 Million EU Fine
Police Arrest Two Alleged TeamPCP Members Linked to Shai-Hulud Attacks
Previously patched Citrix NetScaler flaw exploited in the wild (CVE-2026-8452)
Pro-Russian hackers claim cyberattack on Norway
Qilin Ransomware Gang claims Cyber Attack on U.S. ATF
Ransomware Attack on three UK Airports leads to Data Breach affecting 8.7 Million customers
Ransomware attacks hit 894 as AI boosts cyber crime
Ransomware Gang Qilin Claims To Have Hacked ATF - But Where’s the Proof?
Ransomware Hacker Uses AI to Plan Attacks and Compromises More Than 20 Organizations
Ransomware Hacker Uses AI to Plan Cyberattacks Against More Than 20 Organizations
Ransomware Operator Ran Cursor Agent Inside Ten Victim Networks
Rhodes, Young, Black & Duncan Data Breach Exposes Financial Info
Rockwood Data Breach Compromises Medical Information
Rogue Fabrication Data Breach Impacts 35,000 Individuals
Rookie Mistake: Hacker's Attachment to Screen Name Made Him Easy to Catch
Russia-Linked Cyber Espionage Clusters Use OAuth Phishing to Target U.S. and European Organizations
Russian Cyber Espionage Infrastructure Uses Evilginx and OAuth Phishing to Steal Accounts
Russian Hackers Claim ATF Breach, Agency Says Investigation Files Were Hit
Russian hackers unleashed Cursor AI agent to infiltrate nearly a dozen corporate networks
Russian Hackers Use Fake Google Drive and Diplomatic Lures to Steal Online Account
Russian-Speaking Hackers Told Cursor AI It Was a 'Test,' Then Used It To Attack Seven Companies
Secret Neighbor taken offline after hacker deletes player data and blackmails publisher
Slack and Teams phishing surges, Unit 42 finds
Spark RAT Targets Cambodia, Abuses Vulnerable OPSWAT Driver to Disable Security Tools
Stansted Airport cyber attack: Millions of passengers' details accessed by hackers
Stansted Airport data breach exposes customer contact details
Stansted Airport hit by cyber attack exposing customer data
Stansted Airport owner hit with cyber attack as millions of customers’ data stolen
Suspected TeamPCP hackers arrested over supply chain attacks
Swarms of OpenAI Agents Collaborated in Attack on Hugging Face
The Apollo Global Management Data Breach and the UNC6671 / Cordial Spider Campaign
The Hacker That Never Sleeps: AI Is Changing Cyberattacks
The notice regarding a personal data breach has taken effect
Three major UK airports are hit by cyber attack with millions of passengers affected
Three major UK airports hacked as 8.7 million customer records stolen in cyber attack
Three UK airports hit by cyber-attack with data of 8.7 million customers accessed
Travala Discloses Data Breach Exposing Customer Profile and Passport Details
Travala Reports Data Breach Exposing Customer Names, Emails and Hashed Passwords
Two alleged TeamPCP hackers arrested over global supply chain attacks
U.S. Dismantles Chinese Hacker Network Targeting Department of Justice (DOJ), Senate and NASA
UK Airports Hacked: Millions of Passengers’ Data Accessed in Major Cyber Attack
Unknown PaperCut NG/MF vulnerability is under active attack
US federal agency confirms data breach in wake of claims by ransomware group
US Probe into 850,000-File Breach at Kansas Water Infrastructure Firm
What to do if your personal information was exposed in a data breach
White House bans foreign-made equipment for power generation over cyber backdoor concerns
Why Ransomware Economics Favor Volume Over Prestige Attacks
Your AI agent can be hijacked just by visiting a website
📅 26th August
24 Malicious npm Packages Abuse Mirror Infrastructure to Host Obfuscated ClickFix Phishing Pages
24 Malicious npm Packages Abuse Trusted Mirrors to Host ClickFix Phishing Pages
100+ Internet-Exposed Water Systems Faced Cyberattacks Last Month
A Look Inside the Phishing Service Attacking Organizations
A massive phishing campaign has hit over 9,000 organizations worldwide
AI-Powered Balonx Sistema Phishing-as-a-Service (PhaaS) Harvests Credentials From Over 1,100 Banking Users
AI vulnerability discovery scores the highest impact of 20 emerging risks
AnonyMousKIT phishing service targets Apple credentials and Activation Lock
AnonyMousKIT phishing-as-a-service uses AI voice calls to steal iPhone passcodes
ATF confirms breach hours after Qilin ransomware gang claims US firearms agency
ATF hit by ransomware attack, Department of Justice (DOJ) says
Atlanta Law Giant Troutman Pepper Locke Hit by Breach, Faces 37,000-Person Suit
Average Cyber Insurance Losses Increase Despite Fewer Claims
Balonx Sistema Phishing-as-a-Service (PhaaS) Targets 20+ Mexican Banks With AI Vishing and Android RAT
Bogus recruiters go after high-value corporate credentials on mobile
Boston Scientific hit by massive cyber attack as shares plummet
Boston Scientific says cyberattack disrupted operations globally
CareCloud data breach now affects personal data of 3.75 Million patients
Carhartt data breach affects 12.9 Million, half of what ShinyHunters claimed
Carhartt data breach claims inflated by synthetic data, analysis finds
Carhartt’s ShinyHunters Breach Was Almost Half What It First Looked Like, Exposing 13 Million Emails - Here’s Why
Central Maine Healthcare Reaches $1.3 Million Settlement in Data Breach Lawsuit
Check Point Blocks Massive Debt-Relief Phishing Campaign Targeting 9,000+ Organizations
CISA Red Team Compromised Two Critical Infrastructure Orgs, One Detected Nothing
CISA Warns Agencies to Patch Actively Exploited Oracle WebLogic Proxy Flaw
Claude Opus 4.6 Bypasses Gym Booking Limit, Cancels Other Users' Reservations in Tests
Comcast Paying $117,500,000 To Settle Data Breach Claims Affecting 31,700,000 Customers
Critical Avada WordPress theme flaw enables zero-click RCE
Critical Gitea RCE Actively Exploited as Reported Attack Drops Miner-Like Payload
Critical Gitea vulnerability now exploited in the wild (CVE-2026-60004)
Cyber-attack on oil parastatal exposes Malawi vulnerabilities
DDoS Attack Hits Norwegian Government Services
Fake Apple Support AI Calls Target Stolen-Device Owners for Passcodes and 2FA Codes
Fake Cloudflare CAPTCHA Campaign Abuses npm Mirrors to Push ClickFix Phishing
Fake Grand Theft Auto 6 (GTA 6) Demo Spreads Malware: How to Spot the Scam
FBI Disrupts China-Linked QTFY Infrastructure Used to Steal Data From U.S. Organizations
FBI disrupts proxy network enabling Chinese espionage operations
Federal Reserve, NASA and Department of Justice (DOJ) among victims of Chinese state-sponsored hacker group, FBI says
Former Los Angeles County Museum of Art (LACMA) Employee Sues Over Recently Announced Data Breach
Four in Five AI Tools Run with No IT Oversight, New Research Finds
Global Crackdown on West African Crime Networks Leads to 58 Arrests
Hack of Water Sector Supplier in Kansas Draws FBI Scrutiny
Hackers Abuse Legitimate RMM Tools in 46-Country Phishing Campaign to Gain Remote Access
Hackers claim massive 4TB haul from AI firm serving OpenAI, Google, and Meta
Hackers now exploit critical Gitea flaw in code injection attacks
Hackers target Microsoft SharePoint RCE chain with Proof-of-Concept (PoC) exploit
Hackers Targeted Over 100 Internet-Exposed Water Systems
Health Systems Warn Patients About Epic MyChart Patient Portal Phishing Scam
India tops APAC in mobile threat detections as attacks turn more targeted
Interpol Operation Jackal IV Identifies 263 Cybercrime Suspects
Ireland: Cyber attack delays sports grants for Kilkenny but clubs told 'don't panic!'
'It is significant, and it’s something many organisations haven't accounted for': The phishing threats hiding in your calendar invites
Jabaroot, the hacker who has dealt the biggest blow to Morocco
July was the worst month for ransomware victim claims in 2026 - or was it?
Los Angeles County Museum of Art (LACMA) data breach exposes customer and employee information
Massive security flaws plague Ubiquiti’s UniFi ecosystem: 22 vulnerabilities, 21 critical
Medical device firm Boston Scientific says cyberattack has disrupted shipment processes
Meta adds three new features to keep WhatsApp accounts secure
Mirage2FA Phishing Kit Bypasses MFA to Hijack Microsoft 365 Sessions, Targeting 3,500+ Organizations
New 'AnonyMous' phishing campaign targets iPhone users with fake AI Apple support calls
New GPUThor attack defeats NVIDIA ECC protection for root access
Newly SLEEPWALKER Backdoor Waits for One Crafted Packet, Then Runs Its Own Bytecode
Nimbus Manticore Expands Toolset With TWOSTROKE-Like Backdoor and SSH Tunneler
NovaCookies Campaigns Abuse Genuine Docusign Notifications to Steal Microsoft 365 Sessions
Nutex investigating data breach after unauthorized access to servers
Paylogix TPA data breach puts benefits brokers on notice
Pro-Russian hackers claim responsibility for major cyberattack on Norway’s public digital services
Ransomware Hits 2026 Peak: Is Your Channel Ready for AI-Driven Attacks?
Ransomware surges as criminals deploy AI tools
Rockstar breaks silence after Grand Theft Auto 6 (GTA 6) is plagued with leaks and hacker warnings ahead of extended look
Russian hacker group claims responsibility for cyberattack targeting Norway
Sensitive Information Exposed in Nutex Health Data Breach
Taco Bell, and Pizza Hut operator discloses breach after suspicious network activity
TeamSystem Data Breach Exposes Customer IBANs and Accounting Records
This Android toolkit turns selfies into live photos to hijack KYC verification
Tortoiseshell Expands Malware Toolset With New Backdoor, SSH Tunnel
Ubiquiti patches three max severity security vulnerabilities
Unpatched Kaltura mwEmbed Flaws Could Let Remote Attackers Read Files and Run Code
US Navy tells 600,000 sailors and staff to scrub socials of military ties
US water sector supplier hack draws FBI scrutiny as Iran-linked cyber concerns grow
Your Firewall Benchmarks Are Reassuring, That's the Problem
📅 25th August
24 npm Packages Abuse unpkg Mirrors to Host Fake Cloudflare CAPTCHA Pages
24,700 Fake Debt Relief Emails Target Over 9,000 Organizations in 14 Days
A Malicious Webpage Could Poison Your Local AI Model Behind NVIDIA NemoClaw
Actively Exploited Oracle WebLogic Flaw Lets Unauthenticated Attackers Access Critical Data
AI supply chain risk is showing up in developer workflows first
Alabama subpoenas OpenAI over alleged data breach
Amazon’s New Order Confirmation Emails Seen Boosting Phishing Risk
AnonyMousKIT PhaaS uses voice AI agents to phish iPhone passcodes
Apollo Global Management data breach exposes personal information
Apple rescues Hide My Email feature from the privacy scrap heap
ASOS Warns Customers of Data Breach Following Credential-Based Account Takeovers
Attackers Target miniOrange SAML Flaws That Can Grant WordPress Admin Access
Australia Warns of Active Exploitation of Critical TeamCity Server Flaw
Australia’s transport sector under-prepared for risk of cyber attack
Bankwest: Phishing accounting for majority of banking scam activity
Can You Hear Me Now? Show Me Your Papers
Charlotte-based parking company data breach impacts more than 61,000 North Carolinians
Check Point Blocks Large-Scale Debt-Relief Email Phishing Campaign Targeting More Than 9,000 Organizations
Chinese Hackers Accelerate Cyberattacks Using Low-Cost AI Tools
CISA and the FBI Are Sounding the Alarm on Ransomware
E4del and PINHOLE RATs Turn FTP Banners Into Dead Drops for Malware Commands
Employee benefits platform Paylogix says hackers stole financial and health data
Epic, American Hospital Association (AHA) warn of phishing schemes in MyChart
Epic’s MyChart phishing wave is pushing patient-access teams to treat portal identity as a security perimeter
Fake Minecraft Clients Deliver WeedHack Malware Despite Infrastructure Takedown
Fake OpenAI Codex download tricks macOS users into installing malware
Fake Recruiter Scams Target Corporate Credentials on Mobile
FBI, CISA, and HHS Warn about Medusa Ransomware Targeting Over 500 Critical Infrastructure Organizations
Gig Harbor council member’s email locked down after suspicious message Tuesday
Hacker Group Claims Identities Of 70,381 Moroccan Agents
Hackers abuse npm mirrors to host phishing redirect pages
Hackers breached over 270 Zimbra servers in ongoing attacks
Hackers litter NPM with packages that don’t infect computers - they host phishing pages instead
Health data of North Dakota developmental disability clients potentially exposed in phishing attack
Hospital operator Nutex Health says data stolen in cyberattack
How Much Does a Data Breach Cost? IBM’s 2026 Report Puts the US Average at $11.5 Million
INTERPOL crackdown on West African crime rings uncovers troubling new trend
Iran-linked cyber attack on UK power plant was inevitable
Join a lobby, get pwned: critical remote code execution bug found in Konami’s Metal Gear Online 3
Large DDoS attack knocks Norwegian public services offline
Ledger Fixes Ethereum App Flaw as Disclosure Timeline Is Disputed
Los Angeles County Museum of Art (LACMA) data breach last year exposed social security and medical data
Malicious Firefox extensions steal your crypto wallet seed phrases and browser credentials
Marimo Notebook Flaw Could Run MCP Commands Before Cells Execute in Edit Mode
Massive DDoS attack disrupts Norway’s government digital services
Microsoft Teams’ New Policy Lets Admins Automatically Block Meeting Bots
Microsoft’s and Meta’s data center may have been breached in $13 million extortion attempt
Mirage2FA Surge Hits 4,500 US and EU Companies, Abusing Microsoft 365 Login Flows
North Carolina: Latest Charlotte data breach ensnares about 73,000 Preferred Parking customers
NVIDIA NemoClaw Flaw Lets Malicious Websites Hijack OpenClaw AI Agents
PavinLoader Is Everywhere: One Malware Family Is Powering ClickFix Scams, Fake Games, and Fake Software Downloads
Phishing Ring That Even Intercepted 112 Emergency Calls Busted for Stealing 10 Billion Won Using Check Cards as Bait
Phishing, data breaches surge in the Philippines in first half of 2026
Police arrests dozens of suspects in global cybercrime crackdown
RecruitTrap Scam Uses Fake Interview Invites to Steal Corporate Logins
ReliaQuest Rejects Compromise Claims After ShinyHunters Incident
ShinyHunters taunts ReliaQuest after its own employee falls for social engineering attack
SickKids Data Breach Exposes Employee and Job Applicant Records
Sometimes Even a Great Cybersecurity Pedigree Can’t Save a Pedestrian Business Model
South Korea: Police bust China-based phishing ring with local police
South Korea: Voice Phishing Gang Arrested for Stealing 10.2 Billion Won via Call Interception
Surgeons Choice Data Breach Exposes Social Security Numbers
That fake Grand Theft Auto VI demo is actually just malware
The Grand Theft Auto VI (GTA VI) leaks are breaking the internet. Security researchers have seen this before
The Health Trust Data Breach: Personal and Health Information Exposed
The Netherlands: New phishing scam alert - Fake email from iDeal-Wero doing the rounds
Third-Party Website Scripts Can Become a Hidden Payment-Skimming Risk
TikTok phishing: How to spot fake login and verification pages
Traditional Security Training is Obsolete in the Age of AI
U.S. Sanctions Iran-Linked Hackers Behind Critical Infrastructure Breaches
UK government seeks powers to secretly block risky tech suppliers
UK seeks supply chain security overhaul following Iran-linked cyber attack
Unpatched Zimbra servers are falling to CVE-2026-73570 attacks
US cities rush to replace Flock with Verkada cameras: Are they any better?
US jails ATM thief behind $3.5 Million heist amid investigation into violent cybercrime conspiracy
US sanctions Iranian cyber actors as UK discloses power plant attack
US Sanctions Mabna Institute Hackers for Iranian Cyber-Attacks
US Treasury Launches Major Campaign to Disrupt Iran’s Global Networks
WhatsApp Adds Multiple Passkeys for Phishing-Resistant Sign-Ins Across iOS and Android
WhatsApp adds stronger two-step verification, multiple passkeys
WhatsApp tightens account security with stronger two-step verification and more
When Cyber Meets Physical: Rethinking Data Management for a New Threat Landscape
Your stolen iPhone can now call you back - pretending to be Apple Support
Zero-click email attacks: What businesses need to know
ZeroTokens Phishing Platform Steers Attacks in Real Time
📅 24th August
Actively Exploited Zimbra Flaw Lets Unauthenticated Attackers Execute Shell Commands
After targeting water infrastructure in US, report claims Iran-linked hackers behind cyber attack on power plant in UK
Alibaba’s AliExpress caught tracking user audio systems
Android car head units infected with proxy botnet malware through built-in software updaters
Apollo Confirms Data Breach Amid Cyberattacks Targeting Financial Firms
Apollo Confirms Data Breach as Wall Street Hacking Wave Widens
Apollo Global hit by hacker attack, personal data leaked?
Apollo Global reveals data breach after hackers target financial firms
Associated Endocrinologists Data Breach Affects 4,979 Individuals
Barracuda Networks Analysis Finds 20 Vulnerabilities on Average Per Web App
British energy firms put on alert
California Department of Financial Protection and Innovation (DFPI) orders mortgage company to pay $825K for alleged cybersecurity failures preceding ransomware attack
Canvas Ransomware Attack Locks Out University of Manchester Students
Central Maine Healthcare reaches $1.3 million settlement agreement for data breach
Chinese hacker who broke into stock account of BTS's Jungkook gets 20 years
CISA orders urgent patching of actively exploited Zimbra flaw
CISA’s logging guidance works beyond government
“Cognizable damage” required for data breach claims, Massachusetts appeals court says in a first
Connecticut Medicaid data breach exposes payment information of 41,000 HUSKY Health members
Critical Keycloak Password Reset Flaw Could Let Unauthenticated Attackers Take Over Any Account
Critical Node.js Sandbox Flaw Exposes AI Agents to Host Code Execution
Critical WordPress Pods Flaw Lets Unauthenticated Attackers Gain Admin Access
Cudy WR3000 Router Flaws Can Be Chained to Gain Root Access
Cyber attack on North Wales mental health charity sees sensitive data accessed
Cybersecurity job ads demanding AI skills double in a year
Data breach notifications in Australia rise by 8%
Data breach reported by Grafton City Hospital officials
Data Breach Settlement Deadline Nears for Central Maine Healthcare Patients
Doubloon Dredger Abuses Notion to Harvest Authentication Tokens
Does AI Create New Cybersecurity Risks? What Actually Changes
Egypt’s Financial Regulatory Authority (FRA) pursues criminal charges and suspends consumer finance firm over data breach
Employee Databases from Multiple Fortune 500 Companies Affecting 3.6 Million Employees Listed on the Dark Web
Encrypted Prompts Defeat Grok and Gemini Guardrails; Chat Histories Stolen
Experts Weigh in on the Medusa Ransomware Gang
Fake bank websites play dead to evade security scanners
Fake Codex Download Uses Google Sites to Deliver macOS Malware
Fake Minecraft Clients Spread WeedHack Malware on Windows to Steal Passwords
FBI, HHS warn against Medusa ransomware
Genesis Healthcare Data Breach Exposes Sensitive Patient Info
German Digital Rights Group Takes Aim at Meta Glasses in Criminal Complaint
Golf Canada Breach Exposes Nearly 570,000 Accounts, the Governing Body Isn’t Talking
Google and Bing Search Results Used to Deliver Hidden Banking Phishing Pages
Google Threat Intelligence Group (GTIG), Doppel & Gigamon: The Apollo Data Breach Explained
Hacker group claims 6 million Bangladeshi CVs for sale on dark web
Hackers infecting Android car systems to build proxy botnet
Hackers Poison Google and Bing Results to Deliver Cloaked Banking Phishing Pages
Hackers target WordPress sites in miniOrange auth bypass attacks
Hackers Use Chameleon SEO Poisoning to Hide Banking Phishing Pages From Security Scanners
Health systems warn of coordinated phishing targeting Epic’s patient portal
Health systems warn patients of MyChart phishing scam
Hospitals warn of phishing scam targeting 'MyChart' patient portal
How email masking prevents phishing & spam attacks across the workforce
iAuthFlow v2: The $10,000 Phishing Toolkit That Survives Your Password Reset
Indian man who fled US arrested on charges he helped scammers siphon $7.5 million from the elderly
Integrative Emergency Services (IES) Data Breach Exposes Medical Records of Patients
Iran hackers vow to target US allies after 4-day UK power plant attack
Iran-linked cyber attack reportedly shuts UK energy generator for four days
Iranian Cyber Attack: Are UK Power Plants Safe from Hackers?
Iranian cyber attack on power plant was "warning shot" amid threat to critical British national infrastructure
Iranian cyber attack on UK power plant ‘should concern every organization responsible for keeping this country running’
Iranian Cyberattack Shuts Down UK Power Generator
Iranian-linked cyber attack exposes UK energy flaws
Iranian-Linked Hackers Disrupt UK Energy Infrastructure in Four-Day Attack
Ireland: Survey finds consumers receive more than five scam or phishing communications per month
Kern Psychiatric Data Breach Exposes Social Security Numbers and Medical Info
Latvia: The hacker who attacked the Road Traffic Safety Directorate attempted to penetrate other government systems
Latvian Road Traffic Safety Directorate (CSDD) was late to report cyber attack
Medical Data Breach on Medical Technology Firm MyDr Impacts Half of Polish Population
Medusa Ransomware Targets Healthcare Sector Through Unpatched Software Vulnerabilities
Microsoft Reverses Its Own ‘Exploitation’ Warning on Entra ID Flaw CVE-2026-69836
Microsoft Teams Phishing Deploys New SynkLoader Malware to Steal Windows Passwords
Monitor, microphone, webcam, light – all gadgets can be hacked, researcher shows
MyChart warns of phishing schemes using fraudulent emails, other messages
National Institute of Standards and Technology (NIST) Warns of Unique Security Risks in Multi-Cloud Environments
New Guidance Helps Businesses Verify Quantum-Safe Hardware Claims
North Dakota Health and Human Services (HHS) warns Developmental Disabilities clients of data breach after phishing attack
North Dakotans receiving developmental disability services affected by phishing attack on state
Operation QUICSILVER Targets Myanmar Government and IT with QUICAgent Backdoor
Organizations turn to AI as data breach costs jump 12%
Origin Energy cyber attack traced to former Accenture employee in Manila
Oz Hair & Beauty hit by data breach, customer names and contact details exposed
Patient data was breached in AnMed attack
Personal Information Exposed in Apollo Global Data Breach
Phishing Emails Impersonating South Korean Government Agencies Target Naver Accounts - 'Do Not Click Links'
Practical Privacy Habits That Reduce Everyday Exposure
Preferred Parking breach exposes credit card data
Premier Medical Group Data Breach Exposed Sensitive PHI and PII
Private equity giant Apollo confirms data breach saw personal info stolen
Ransomware Affiliate Poses as Recovery Firm to Steal Ransom Payments
Ransomware attackers are zeroing in on mid-market companies
Ransomware Is Changing Even When Crypto Payments Fall
Ransomware’s Real Target Isn’t the Giants. It’s the Squeezed Middle
ReliaQuest confirms failed data-theft attack after ShinyHunters breach
ReliaQuest Confirms ShinyHunters Hack, but Says Impact Was Limited
ReliaQuest Says Device Trust Held Against Phishing Attack
Researchers Uncover Thousands of Leaked Amazon Web Services (AWS) Keys
Scammers exploit hype around Grand Theft Auto 6 (GTA 6), post fake pre-release build to spread malware
Shell Confirms Investigation Following Cl0p Ransomware Data Theft Claims Tied to PTC Windchill Zero-Day
ShinyHunters Claims CyrusOne Breach, Demands $13 Million for 640+ GB of Data
Social Engineering Scheme Led to Apollo Data Breach
South Korea: Loan-Baited Accounts Launder Voice Phishing Proceeds
South Korea: Phishing Emails Impersonate Government Agencies to Target Naver
South Korea: Phishing emails mimic Korea agencies to steal Naver accounts, Naver warns
South Korea: Phishing Emails Targeting Naver Accounts Prompt Warning
South Korea: Seoul bike users sue after massive Ttareungi data breach
South Korea: Seoul Bike-Share Data Breach Victims Seek 300,000 Won Each
South Korea Data Breach Exposes Startup Applicants’ Personal Data
Southern Illinois University (SIU) Data Breach: Addresses and Social Security Numbers Exposed
Suspected Iran-linked attack knocked UK power plant offline for days
SynkLoader Malware Spreads Through Microsoft Teams Phishing and Steals Windows Passwords
The Asthma Center Data Breach: PHI and PII Exposed
The Outsized Shadow: Why 5% of AI Users Are Your Biggest Security Risk
Town of Pittsboro Alerts Public to Phishing Scam
Town of Pittsboro Alerts Residents to Phishing Scam Targeting Developers
Tricky 'SynkLoader' Multitool May Herald Ransomware
UAT-10147 Uses AI to Scale Server Attacks, Deploys SPECTRE With EDR Bypass and Linux Rootkit
UK briefs energy chiefs after Iran-linked cyber attack reports
UK energy alert issued after Iranian cyber attack on power plant
UK informs energy chiefs on Iran cyber attack
UK power plant cyber attack
United Language Group Data Breach Exposes Social Security Numbers
Unpatched Calix flaw lets hackers bypass NAT to expose internal devices
Wake-Up Call for Critical National Infrastructure (CNI) After Iranian Attack Shuts Down UK Power Plant
Weedhack Malware Spreads via Fake Minecraft Clients and SEO Poisoning
Westco Motors Cairns suffers alleged ransomware attack
What The Ransomware Business Model Means For Your Risk Strategy
WordlistLoader Delivers Amatera via ClickFix, SynkLoader Phishes Windows Passwords
Welcome to DBD. On March 8th 2026, DBD celebrated it's sixth anniversary and