Welcome to this week's Data Breaches Digest, a catalogue of links concerning Data Breaches and Cyber Security that were published on the Internet during the period between 7th September and 13th September 2026.📅 13th September
Attackers Use Passkey Phishing to Hijack Microsoft Cloud Accounts and Exfiltrate Data
Cell C warns fibre customers about possible data breach
Conti Hacker Who Built Malware and Attacked Victims Gets Four-Year Sentence
Environment body that regulates waste sites across Wales apologises over its own data breach
Florida Driver License Agency Admits Hacker Attack
Hackers exploit Tencent app flaw to deploy GrayRabbit malware
Kochi Metro office hit by data breach; police probe
OpenAI agents attacked RubyGems months before rogue Hugging Face hack
Revolut confirms customer data breach after falling for fake government requests
Revolut confirms customer data breach ahead of Israel launch
Revolut confirms sensitive customer data breach, falling for fake government requests
Revolut Data Breach Exposes Customers’ Passport Copies and Full Transaction Histories to Hackers
Revolut says customer data exposed in government email domain scam
📅 12th September
AI agents being tested by OpenAI involved in cyber-attack on another service, say researchers
Anthropic tightens safeguards to prevent AI-powered phishing and data theft by hackers
BigBear 2.0 Phishing Network Exposes Over 5,000 Credential Records Across 461 Organisations
Brevo Login Flaw Exposes 138 Client Accounts in Trezor Phishing Attack
Chinese Hackers Chain Chrome and Windows Zero-Days to Deploy Backdoors and Steal Credentials
CISA Adds 5 Actively Exploited Artifactory, ScreenConnect, and RouterOS Flaws to Known Exploited Vulnerabilities (KEV)
CISA Warns of Critical GitLab Path Traversal Flaw Exploited to Read Arbitrary Server Files
Cisco Firewall Manager Hacked by Sandworm Espionage Implant and Qilin Ransomware
Clop Claims Harley-Davidson Breach, 270 GB Stolen via Windchill Bug
Conti Hacker Lytvynenko Gets 4 Years
Data Breach at AdaptHealth Exposes Personal Information of Over 4.1 Million Individuals
Dutch Nationaal Cyber Security Centrum (NCSC): Critical Check Point VPN flaws exploitation is imminent
EasyEquities informs customers about possible data breach
Florida DMV: Driver database breach confirmed
Hackers Abuse Windows Mshta.exe in Phishing Attacks to Deploy HTML Application (HTA) Malware and Steal Credentials
Harley-Davidson breach claimed by Cl0p gang with 270GB internal data dump
Microsoft 365 Accounts Are Being Hijacked Through Fake Passkey Alerts
OpenAI AI Agents Flood RubyGems With 2,000 Packages and Achieve Remote Code Execution
OpenAI Agents Linked to RubyGems Campaign That Gained RCE on RubyDoc Servers
Qilin leaks 6.3GB of ATF investigation files, then pulls it all within 24 hours
Ransomware group claims GenSan hospital as victim, demands 8 bitcoins
Revolut confirms customer data breach from fake government requests
Revolut confirms customer data breach through fake government requests
Revolut confirms it handed customer data to scammers posing as government agency
Revolut confirms sensitive customer data breach, falling for fake government requests
Revolut Data Breach: Am I Affected, and What About My Bitcoin History?
Revolut Gave Customer Data to Scammers After Fake Government Requests
Riding the Waves of the Revolut Data Breach
South African bank notifies customers of data breach
Threat Actors Use Claude AI Agents to Automate Cyberattacks, Exploitation and Data Theft
Trezor Phishing Attack Used Its Own Email Channel to Target 347,000 Customers
Ukrainian Gets 4 Years for Conti’s $150 Million Ransomware
Unsanctioned OpenAI Agent Activity Targeted RubyGems
📅 11th September
A Fourth Claude Model Escaped Guardrails
A new Android attack combines malware and ransomware in a cocktail of cybercrime
A Ukrainian hacker was convicted in Switzerland for ransomware attacks
AI agents exploited PaperCut flaws to breach 395 organizations
AI is changing what Salesforce security needs to govern
Alleged Booking.com 2,300+ Payment Card Dataset Offered for Sale Online
Anthropic caught Russia-linked spies using Claude in hacking operations
Anthropic Finds Fourth Claude Cyber Incident After Model Accessed Third-Party Computer
Anthropic Says Seven China-Based AI Labs Ran Industrial-Scale Claude Distillation Attacks
Anthropic's new threat report shows one hacker with AI now equals a state-backed team
Artifactory flaws chained in attacks deploying backdoor malware
Attackers Chain JFrog Artifactory Flaws to Gain Admin Control and Plant Backdoors
Attackers Exploit Critical Cisco Firewall Management Center (FMC) Flaw to deploy Qilin ransomware
Attackers exploit fake STM32 vulnerability alert to target Trezor and BitBox holders
August Cyber Threats Rise as Ransomware Nearly Doubles and GenAI Data Exposure Becomes a New Enterprise Risk
Australian Signals Directorate (ASD) Urges Organizations to Secure the Layer Behind Agentic AI, Here’s Why
Azle Cube Smiles Data Breach Impacts 2,940: PHI and PII Exposed
Brevo login flaw enabled phishing email targeting 347K Trezor subscribers
Busted! Conti ransomware member cops 4-year prison term
Canada: ‘Unauthorized activity’ affecting Ontario courts leads to data breach
Central Maine Medical Center & Susan B. Allen Memorial Hospital Settle Data Breach Lawsuits
ChatGPT flaw allows attackers to secretly steal Gmail data
Check Point red-flags heightened attacks on Africa’s energy and utilities sectors
China-Linked UNC3569 Exploited Sogou Input Method Flaw to Deploy GRAYRABBIT Backdoor
CISA Warns MikroTik RouterOS Flaw Is Exploited to Escalate Privileges
Cisco Firewall Management Center (FMC): Vulnerabilities used to develop Qilin Ransomware
Cisco Firewall Management Center (FMC) Flaws Exploited to Steal Credentials and Deploy Qilin Ransomware
Claude Used to Automate Exploitation and Data Theft Across Multiple Victims
Colorado: Phishing emails targeting permit applicants, Boulder County officials warn
Companies may be measuring phishing resilience the wrong way
Conduent Data Breach Claims Settlement Ends Fight Over 44 Million Exposed Records
Conti ransomware developer sentenced to four years in US prison
Conti ransomware gang member sentenced to 4 years in prison
Conti Ransomware Hacker Sentenced After Group Attacked Over 1,000 Victims Worldwide
Conti ransomware hacker sentenced to four years in US after attacks on 1,000+ victims
Critical Brevo Security Flaw Exposes 347K Trezor Subscribers to Phishing Attack
Critical Check Point VPN Flaws Let Unauthenticated Attackers Execute Remote Code
Critical ConfigServer Security & Firewall Flaw Lets Remote Attackers Execute Arbitrary Commands
Critical Infrastructure Cyberattack Encrypts Central IT Structures
Crypto customers targeted by scammers after email marketing provider breach
Cyber attack disrupts operations at Malaysia’s Port of Tanjung Pelepas
Cyber attack targets Moldovan government websites
Cyber Resilience Act (CRA) Reporting Rules Take Effect: How to Ensure Your Organization is Ready
Cyber-attack halts operations at Malaysia’s Tanjung Pelepas Port
Data Breach Hits Medical Supply Chain Giant McKesson, Exposing 284 Million Patient Records
Fake Sexual Misconduct Emails Target Universities with Zoho RAT
FBI unveils Cyber Strategy as state-backed actors target critical infrastructure and ransomware threats escalate
Flock Cameras Suspended in Wisconsin County, Data Concerns Cited
Florida confirms DMV database breached via stolen police account
Florida DMV says it was hacked shortly after major driver’s license breach
Florida highway safety agency confirms data breach
Florida says motor vehicle data breach tied to credentials stolen from officer’s personal device
German police read Signal, Telegram, WhatsApp messages without breaking encryption
GitLab CVSS 10 File-Read Flaw Draws In-the-Wild Probes After Disclosure
GitLab urges users to patch max severity path traversal flaw
Google Play Early Access Abused to Push Deceptive Android Apps
GuardBreaker Malware Uses Code Comments to Trip AI Security Guardrails and Evade Analysis
Hackers abused Claude to extract secrets from 1.8 Million Android apps
Hackers Deploy New SloppyRAT via ClickFix to Enable Ransomware Lateral Movement
Hackers Exploit Critical Cisco Firewall Management Center (FMC) Flaws to Gain Root Access and Deploy Malware
Hackers Favor US Eastern Business Hours in M365 Phishing Campaign
Hackers Turn Claude AI Agents Into Autonomous Tools for Exploitation, Data Theft and Malware Evasion
Hackers Use AI-Assisted CEO Emails to Trick Finance Teams Into Sending $50,000 Payments
Harley-Davidson Alleged Breach - CL0P Ransomware Adds Motorcycle Maker to the List
Heywood Healthcare Data Breach Exposes PHI and PII
How CISOs Should Navigate a Growing UK-EU Cyber Compliance Squeeze
Hundreds of AI-powered attacks exploit PaperCut flaws
ID Verification Firm IDScan.net Confirms Data Breach
IDScan confirms breach after 153 million driver’s licenses leak on dark web
IDScan Confirms Data Breach Following 153 Million Driver’s Licenses Leaked on the Dark Web
IDScan Data Breach Exposes Driving License and Personal Information of US and Canadian Citizens
In Switzerland, a Ukrainian hacker was sentenced to almost 13 years in prison for cyberattacks worth millions of dollars
Interim HealthCare Hit by 2 Ransomware Gangs
Iranian hacker group claims Dallas AT&T outage; AT&T blames cable theft
Israeli company finds over one million online fraud cases, including fake hostage forum listings
Jabaroot: Behind the hacker group's claim of a 70,000‑name leak in Morocco's police and intelligence
Kids Company Data Breach Compromises PHI and PII
LG says its smart TVs aren’t spying on you
Mantax OTAX Android Ransomware Spies on Users, Steals OTPs and Encrypts Files
Mantax OTAX Combines Android Ransomware and Spyware for Double-Extortion Attacks
Massive hack gives scammers access to over 150 million drivers licenses
Microsoft sees some new wrinkles in invoice-scam emails
Most Organizations Skip Permissions Reviews Before Deploying AI Tools
Nearly 1 in 3 Tech Workers Fell for a Phishing Test. The Biggest Predictor Was 1 Habit
New Android Ransomware Records Screens, Steals OTPs and Secretly Takes Photos of Victims
New PuzzleMask Attack Hides Malicious Prompts in Plain English to Bypass AI Guardrails
New SloppyRAT Malware Uses ClickFix and Blockchain C2 to Help Ransomware Hackers
New Zealand: Cybersecurity experts raise alarm after back-to-back data breaches
Nintendo Switch players urged to update now over QR code security flaw
Novo Nordisk Data Breach Tied to Stolen GitHub Access Tokens
Ontario Court Data Breach: Protect Your Information
Ontario court rules XL Specialty ransomware retention applies to Panasonic claim
Open a website, and your Mac crashes instantly: researcher reveals “Deathray” exploit
PaperCut Replaces Emergency Patches With Fixes for Two Actively Exploited Flaws
Passkey-themed phishing attacks lead to Microsoft 365 data theft
Phishing, weapons and spying: Top 5 misuses of AI flagged by Anthropic
Plain English, Hidden Instructions: Inside PuzzleMask - Plain-Prose Attack Bypasses AI Gatekeepers
Plant City police employee credentials led to Florida DMV data breach
Ransomware attack reaches Victorian business through external technology provider
Ransomware group claims cyberattack on Dunedin clinical trial company
Rhysida Hits Berlin: 6TB Leaked After 30 BTC Refusal
Russian Hacker Extradited From Georgia in Massive Bank Fraud Scheme
Russian State-Sponsored Hackers Use Claude to Rebuild Malware After Detection
Scammers Hit 347K Crypto Owners After Trezor Breach
Scammers target hundreds of thousands of crypto owners after Trezor confirms data breach of email provider
Scammers Target MyChart Patients With Phishing Scheme
Sheriff’s Office in Wisconsin suspends Flock cameras over data breach
Should You Replace Your Driver’s License After the Massive Data Breach at IDScan?
SloppyRAT Malware Uses Advanced Evasion to Aid Ransomware Attacks
Some Telus customers report personal information exposed in data breach
Spike in cyber attack insurance enquiries from care providers
Springfield Schools Prepare for Return After Cyberattack Disruption
Springfield to Reopen Schools Monday After Closing Them Due to Cyber Attack
Surfshark Confirms September Security Incident Did Not Affect VPN Users or User Data
The Next Agentic Security Failure May Begin With Permission
There’s a hole in Android’s VPN tunnel: apps can leak real IP address
Trezor: 347,000 users targeted in phishing attacks after Brevo breach
Trezor: Phishing attack targeted 347,000 emails
Trezor breach exposes 347,000 emails in phishing attack
Trezor Confirms Email Breach, 347K Emails Sent
Trezor Data Breach Exposes Hundreds of Thousands of Crypto Users to Scammers
Trezor phishing attack tied to Brevo breach hits 347,000 users
Trezor phishing attack traced to Brevo login authorization flaw
Trezor Says 347,000 Users Received Phishing Emails After Brevo Hack
Ubuntu 24.04.5 LTS release patches security bugs across ten flavors
UK Firms Hit By Over 1,500 Cyber Attacks A Week As Ransomware Nearly Doubles Globally
Ukrainian Conti Ransomware Developer Gets 4 Years in US Prison
Ukrainian Conti Ransomware Developer Sentenced to 4 Years in US Prison
Ukrainian hacker gets four years in US prison over Conti ransomware attacks
Ukrainian hacker jailed in Switzerland over ransomware attacks
Ukrainian National Sentenced to Four Years Over Conti Ransomware Connections
Unicoi County Schools warns community after phishing attack compromises staff account
Vernon & Waldrep Data Breach Impacts 16,876 Patients: Medical Info Exposed
VLC Media Player Flaws Let Attackers Corrupt Memory and Leak Sensitive Data
VNS Health Data Breach Exposes Social Security Numbers
Why Knowing About Cybersecurity Isn't the Same as Being Good at it
WordPress Launches AI-Powered Security Review to Block Malicious Plugin Updates
‘You’ve been attacked’: The group linked to a major New Zealand cyber crime - and its ransom note
Your Newest Privileged Identity Is An AI Agent
📅 10th September
4.1 Million Impacted by AdaptHealth Data Breach
12 Koreans arrested in Thailand over alleged voice phishing operation
AI adoption brings new security headaches for already stretched CISOs
AI-fueled cyberstalking earns Ohio man 15 years behind bars
AI-powered attack exploited PaperCut flaws to hack 395 organizations
Anthropic details distillation campaigns from Alibaba, Moonshot AI, and DeepSeek
Anthropic Discloses Fourth AI Hacking Incident Involving Claude Opus 4.6
Anthropic discloses fourth AI hacking incident missed in earlier review
Anthropic Discloses Fourth Claude AI Hacking Incident, Involving a Claude Opus 4.6 Version
Anthropic Finds 4th Claude AI Hacking Incident Missed in Earlier Review
Anthropic Reveals Yet Another Cybersecurity Incident
Attackers call employees’ personal phones to break into Microsoft 365 accounts
August Cyber Threats Rise as Ransomware Nearly Doubles and GenAI Data Exposure Becomes a New Enterprise Risk
Barracuda spots blob URL phishing in Microsoft browser
Beware - these new phishing attacks use a convincing fake Adobe Reader pages to trick victims into installing malware
BlueMoon Exploit Kit Chains Chrome, Windows Zero-Days in Espionage Campaigns
Check Point Discloses Two 9.8-Rated VPN Certificate Flaws Enabling Unauthenticated RCE
Chrome getting major releases every 2 weeks as Google races to outpace attackers
CISA Flags Exploited Cisco, Citrix, Fortinet Flaws, Sets September 12th Federal Patch Deadline
CISA Updates Insider Threat Guide With New Mitigation Advice
CISA’s ChatGPT Incident Exposes a Bigger AI Governance Problem
Cisco Firewall Bugs Let in Sandworm, Qilin
Cisco Firewall Management Center (FMC) bugs exploited by nation-state and ransomware actors (CVE-2026-20079, CVE-2026-20316)
Cisco Firewall Management Center (FMC) flaws exploited by ransomware gang, state-sponsored hackers
Cisco Secure Firewall Management Center Vulnerabilities Under Active Exploitation
Conti ransomware crew member sentenced to four years in prison
Could AI Agents Be the Next Insider Threat?
Cyber researchers issue warning over 'phishing pages that exist only inside the victim’s browser'
Cyberattack in Berlin: 1.4 million files on the dark web
Cybercriminals are building phishing pages that exist only inside victims’ browsers
Cybersecurity Readiness Doesn't Match Confidence Levels
Data breach hits Weverse, exposing confidential data of over 420,000 accounts
Data Sovereignty in the AI Era: Who Holds the Keys?
F5 BIG-IP APM Linux Malware Hides PHP Web Shell in Apache Memory
Fake Grand Theft Auto VI (GTA 6) download delivers malware-packed bundle to impatient gamers
Fake Grand Theft Auto VI (GTA 6) Downloads Infect Gamers With Password Stealers, RATs and File-Wiping Malware
Fake Trezor Warning Claims 25% of Devices Are Vulnerable in Latest Phishing Campaign
Families respond online to Springfield schools 'cyber attack'
FBI Publishes First-Ever Cyber Strategy, With Focus on Disrupting Threat Actors
Federal Trade Commission (FTC) withdraws health app data breach notification policy
FinWise Bank settles data breach lawsuit for $2.8 million
Gigabud Creates Android Work Profiles to Hide From Banking App Malware Checks
Google Play Early Access Abused to Push Thousands of Deceptive Android Apps
Hack-for-hire firms face potential ban in the US
Hacker claims database of 40,000 Twitch streamers is up for sale
Hackers Create Phishing Pages Inside Your Browser With No Malicious Website to Block
Hackers Use Blob URLs and Microsoft Teams to Create Phishing Pages Inside Victims’ Browsers
Hackers Use Hundreds of AI Agents to Exploit PaperCut Zero-Days
Hackers Use Passkey-Themed Phishing to Hijack Microsoft 365 Accounts and Steal Cloud Data
Hibbett Discloses Employee Data Breach
Hong Kong Monetary Authority warns customers over banking phishing scams
ID verification giant IDScan confirms data breach with more than 150 million driver’s licenses stolen
IDScan confirms breach after hackers offer 153 million driver’s license scans for sale
IDScan confirms breach tied to 153 million stolen driver’s licenses
IDScan confirms data breach, 150 million driver’s licences potentially exposed
IDScan Confirms Massive Data Breach of Drivers License Records
Iran takes credit for AT&T outage
Japan hits record high in ransomware attacks, with 123 cases in the first half of 2026
Japan Ransomware Cases Hit Record 123 in H1 2026
Japan Ransomware Hits Record High: 123 Cases in H1 2026
Japanese Ransomware Attack Sets Record, 123 Cases in Six Months
Liquid Network resumes transactions as hacker keeps 600 BTC
Leaving Online Reviews Could Make You a Phishing Target, According To Study
MantaxOtax Android Malware Combines Ransomware With Spyware
Miami University warns students over SMS phishing campaign
Multiple crypto companies warn customers of phishing emails after alleged provider breach
Nearly 1 in 10 Exposed LiteLLM Gateways Accepted the Example "sk-1234" Admin Key
New Android malware encrypts files, steals data, and harasses victims
New 'BlueMoon' kit exploited Windows and Chrome zero-day flaws
New Phishing Attack Uses Blob URLs to Hide Malicious Pages From Security Scanners
New Zealand: Kiwi payroll firm caught up in 'global' data breach
Norcross officials limit details on early August cyberattack
Office of Foreign Assets Control (OFAC) Sanctions Chinese Scam Platform Xinbi Guarantee
Ongoing exploitation of Cisco vulnerabilities: hackers drop web shells
OpenAI Agents Bypassed Web Posting Restrictions To Communicate Across Multiple Sites
OpenAI's rogue agents used at least 10 more sites for unauthorized comms, researchers say
Panzer ransomware targets Italian manufacturer as ESXi capability raises industrial security concerns
PaperCut Attacker Uses Hundreds of AI Agents to Compromise 440+ Instances
Ransomware attacks in Japan hit record 123 cases in 1st half of 2026
Ransomware cases in Japan hit new high in first half of 2026
Ransomware Cases in Japan Hit Record High in January-June
Ransomware group claims breach at Dunedin clinical research firm ZenTech
Russian e-commerce giant Wildberries says DDoS attack delayed payments to sellers
September Is the Most Dangerous Month for AI Phishing - What Should Schools Focus on the First Weeks Back
Skullcandy Dime 3 Earbuds, Vulnerable to Silent Bluetooth Hijacking (CVE-2025-20701)
South Korea raises data breach fines to 10% of revenue
Surfshark VPN says hackers breached internal testing, proxy servers
Suspected hacker behind cyberattack on French tax authority arrested
Thailand police arrest 12 South Koreans in voice phishing call centre raid
The token that could have broken the internet: major supply chain attack averted
Thousands of LiteLLM instances exposed: 1 in 10 uses default password
Treasury urges banks to file cyber scam reports, noting nearly $13 billion in losses since 2023
Trezor Hack Scare: That STM32 Entropy Email Is a Phishing Attack
Trezor Reported a Hack of a Third-party Email Provider Amid a Phishing Attack
Trezor Says Third-Party Email Breach Let Attackers Send Phishing From Its Own Domain
Trezor Warns of Phishing Emails After Third-Party Email Provider Breach
Trezor warns users of email provider breach, phishing attacks
Trezor, BitBox users targeted in newsletter phishing spree
Trezor, BitBox Warn of Phishing After Third-Party Email Breach
Trezor, BitBox Warn Users After Phishing Emails Exploit Legitimate Mailing Systems
Trezor’s summer of hacks continues with Brevo email breach
TVING Faces Backlash Over Inadequate Data Breach Compensation
Two Ransomware Gangs Claim Interim HealthCare, 1TB
Ukrainian man gets 4 years in prison for role in Conti ransomware scheme
Ukrainian National Sentenced to Four Years in Prison for Wire Fraud Conspiracy in Connection with Conti Ransomware
US Accuses Six Chinese AI Firms of Distilling Frontier Models
Veradigm Data Breach: Gang Claims 3.5 Million Records
Veradigm discloses data breach after vendor's systems compromised
Veradigm Discloses Third Party Data Breach as Hackers Threaten to Publish Data
WatchGuard Firebox bug exploited in ransomware campaigns
WatchGuard RCE flaw now exploited in ransomware attacks
Welsh environmental watchdog hit by data breach
Why Is Japan seeing an extreme surge in Ransomware Cases
Windows 11 just dropped the tool ransomware abused, Microsoft says don’t restore WMIC
WordPress adds automated security checks to block risky plugin releases
📅 9th September
82% of Canada's top AI companies won't say how long they keep your data
$245 million in stolen crypto funded racketeering crew’s lavish lifestyle
AdaptHealth confirms 4.1 million people exposed in July cyberattack
AI Workflow Flaw Could Let Attackers Access Sensitive Data by Simply Asking
AI-driven hack snags 375 Brazil government employee logins
Alby Hub Critical Flaw Could Let Attackers Take Over Internet-Exposed Bitcoin Wallets
As Ransomware Attacks become common, recovery rates Worsen
Backdoor Discovered in AI Workflows, Security Leaders Discuss
BigBear 2.0 phishing campaign compromises MFA-protected Microsoft accounts
Boston Scientific cyber-attack puts medical supply chains in the spotlight
CEVA cyber-attack shows how provider disruption spreads
Check Point Research Exposes Cross-Account Data Leak in ChatGPT
Check Point warns of rising attacks & AI data leak risk
Chinese AI firms are siphoning capabilities from American models, CISA warns
Chrome V8 Zero-Day Exploited in the Wild Enables Code Execution Inside Sandbox
Cisco confirms CVE-2026-20079 Secure FMC flaw exploited in attacks
ClickFix Crypto Scam Hides Its Command Server Inside Google Sheets
ClickFix Moves into the Browser to Steal Cryptocurrency
Columbus Man Sentenced in First Take It Down Act Conviction for Cyberstalking and AI-Generated Obscene Material
COMHAR Data Breach Exposes Social Security Numbers
Consent Phishing: The Attack That Doesn’t Need Your Password
Coupang data breach hits 200,000 Taiwan users; consumer group calls for stricter oversight
Cyber Attack at Three UK Airports Leaks PII of 8.7 Million Customers
DeepSeek Harness Flaw Let AI Agents Disable Their Own File Sandbox Without Approval
Department of Information and Communications Technology (DICT) said Philippine Ports Authority (PPA) ransomware report was false positive
eAssist Dental reportedly struck by ransomware attack
Electronic health record company says customer data stolen in breach
F5 BIG-IP APM Malware Injects a PHP Web Shell Into Memory, Evading Disk Scans
Fake GTA6 ‘Leaked Download’ Caught Spreading RATs, Infostealer and Wiper Ransomware
FBI warns of cyber actors deceiving individuals through ‘OAuth consent phishing’
Federal Trade Commission (FTC) rescinds policy requiring health apps to notify customers after a breach
Financial Services Data Exposure Doubles as Cyber Attack Recovery Costs Hit $2.4 Million
Former AT&T Employee Jailed For Helping Hacker Steal From Customers
Four Spy Groups Used the Same Chrome and Windows Exploit Kit Within a Week
Gigabud Uses Android App Cloning to Evade Fraud Detection
Google fixes yet another actively exploited Chrome zero-day (CVE-2026-87491)
Google warns of new Chrome zero-day bug exploited in attacks
Grindr settles privacy lawsuit tied to disclosure of users’ HIV statuses for $35 million
Group of bipartisan lawmakers ask US government to ban several hack-for-hire firms
Hacker Steals Around US$320 Million In Bitcoin Then Returns Most Of It
Hackers deploy Linux rootkit on F5 BIG-IP APM devices, hiding web shell in memory
Hasbro Data Breach Reveals Employee Personal and Financial Information
Healing Paper Compensates 220,000 After Gangnam Unni Data Breach
Healthcare Tech Company Veradigm Exposed in Third-Party Breach
Hibbett Data Breach Exposes Employee Social Security Numbers
How Ransomware negotiations work in the Real World
Huntress Uncovers Phishing Attacks Using Fake Browser Pages and Rogue RMM Tools
HYBE's Weverse Hit by Another Data Breach...Information Security Investment Drops Despite Return to Profit
Infostealer Logs Expose Replayable AI Tokens That Can Bypass MFA
Iranian hacker group claims responsibility for Dallas internet outage, AT&T blames cable theft
Isle of Man: Information Commissioner investigating Treasury data breach
Kaspersky survey reveals SMBs face increasing cyber threats
Lawmakers demand more safeguards on OpenAI, following cyber attack
Lincoln National Data Breach Exposes Social Security Numbers
Luminis cybersecurity incident highlights ‘concerning’ rise in attacks on healthcare
Luxembourg: Fake Wero text messages currently circulating
Man gets 15 years for extorting women with AI-generated porn videos
Manchester Airports Group Data Breach Caused by Four-Year API Key Exposure
Microsoft Fixes 974 CVEs in Record Patch Tuesday Release
Microsoft Patch Tuesday Fixes 966 Vulnerabilities, Including 2 Exploited 0-Days
Microsoft Patch Tuesday Hits Record 974 CVEs, Two Exploited
Microsoft Patches Record 974 Flaws, Including Two Exploited Windows Zero-Days
Microsoft Shatters Patch Tuesday Record With 974 CVE Fixes in September 2026
Multiple Chinese hacking groups seen using identical Chrome zero-day exploit
N-able N-central Pre-Auth RCE Flaw Exploited in the Wild
New cPanel Flaw Lets a Hosting Account With Mail Privileges Run Code as Root
New Mexico’s trial against Facebook for alleged role in Cambridge Analytica data breach begins
New Microsoft Defender 'ShieldCrash' zero-day grants SYSTEM access
New Phishing Attack Creates Malicious Pages Inside the Victim’s Browser
Nigeria: Publisher laments hacking of website
Non-Human Identities (NHIs) Now the Number One Corporate Entry Point for Hackers
NovoCure Data Breach Reported to Securities and Exchange Commission (SEC): Details Limited
Odido hackers mock the police and hint at another major hack
Open Directory Blunder Exposes Redis Cryptomining Botnet Hitting 3,500+ Servers
Over 36,000 exposed Plex servers vulnerable to recent flaws
Over 150 million driver’s licenses posted on dark web after data breach
Ransomware attacks rise as backup recovery worsens
Ransomware gangs turn on each other
Ransomware group claims LA Metro as latest target, threatens data leak
Ransomware in 2026: Attacks Up, Payments at 23% Low
Researcher Drops New Microsoft Defender Proof-of-Concept (PoC) Showing ShieldBreak Patch Can Be Bypassed
Researchers Build WeChat Zero-Click Worm Hijacking Phones via Calls
Researchers find hidden backdoor in PC firmware that bypasses Secure Boot
Researchers Trace Risks in Claimed Condé Nast Data Exposure After Contacting Seller
Roanoke City data breach: What happened and how to protect your information
Russian Web Developer Extradited in Multimillion-Dollar Bank Fraud Scheme
SAP Patches CVSS 10.0 Kernel Flaw Enabling Unauthenticated Remote Code Execution
SAP Patches Maximum Severity “Overpass” Flaw
September 2026 Patch Tuesday: Record patch count, 2 zero-days, and a SigRed successor
ShinyHunters claims Florida DMV breach, puts data on the clock
Singapore extends Singpass passkey to Android users to curb phishing scams
Skullcandy Dime 3 earbuds expose users to Bluetooth hijacking
South Korean Payment Gateways Hit by Mass Credit Card Data Breach; Suspected Chinese Hacker Alerted Regulators First
Springfield schools closed as cyberattack locks access to student medical records
SpyCloud 2026 Identity Threat Report Finds Non-Human Identities Are Now the Leading Path into the Enterprise
Suisun City, California, Makes Progress After Cyber Attack
Two Ransomware Groups Claim Attacks on Nationwide Home Healthcare Provider
U.S. Agencies Accuse China AI Firms of Distilling Claude, GPT, Gemini, and Grok
U.S. Disrupts Xinbi Guarantee Scam Marketplace, Freezes $52.8 Million in Crypto
US disrupts Xinbi Guarantee marketplace fueling the cyber scam economy
US says Chinese firms extracted billions of tokens from frontier AI models
Vengeful researcher bypasses Microsoft’s Patch Tuesday fix with new Windows zero-day
Veradigm Confirms Patient Data Exposed in Third-Party Data Breach
Veradigm warns of patient data breach after ransomware gang claims attack
Veradigm’s 3rd Breach in 2 Years Exposes SSNs
Westchester Institute for Human Development (WIHD) Data Breach Compromises Protected Health and Personal Information
What breach and attack simulation needs to become in the AI era
Why Lower Phishing Volume Doesn't Mean Lower Cyber Risk for the Education Sector
📅 8th September
220 million traveler records exposed in Vietnam-linked APIS leak
A $10 Million Reward is the Latest U.S. Move to Slow Iranian Cyberattacks
A hacker stole $340 Million in a crypto heist, then returned most of it
Adobe fixes critical Magento zero-day exploited to backdoor servers
Adobe Patches Magento Zero-Day Exploited to Deploy Rust Backdoor and PHP Web Shell
AI Coding Tools Now a Prime Target for Threat Actors, Google Warns
AI Customer Service Agents Can Be Hacked to Bypass MFA, Steal OTPs and Expose User Data
Attackers Use Multi-Hop Google Redirects for Phishing Campaign
Autonomous AI Agents Compromise Thousands of Credentials in Under Six Hours
BigBear 2 Phishing-as-a-Service (PhaaS) Campaign Steals 5000+ Microsoft Credentials
BigBear 2.0 Evilginx2 Phishing Campaign Bypasses Microsoft 365 MFA With Session Cookie Theft
BigBear 2.0 phishing campaign hijacks Microsoft 365 sessions after MFA
BigBear 2.0 Phishing Campaign Hijacks Microsoft 365 Sessions to Bypass MFA
BigBear 2.0 Phishing Service Targets Microsoft 365 Accounts Worldwide
BigBear phishing crew nets thousands of Microsoft 365 credentials
Bimbo Bakeries USA Data Breach Exposes Social Security Numbers
Bimbo Bakeries USA Data Breach Exposes SSNs in Oracle E-Business Suite Zero-Day Attack
Bitcoin hacker returns most of $340 million stolen in crypto heist
Bitcoin hardware wallets Trezor and Ledger in hot water over data breaches
Boss says threat of cyber-attack to Stockton Council is 'constant'
Catalyst Brands Data Breach Exposes W-2 Information
ChatGPT Flaw Let a Planted Prompt Send a Victim's Gmail Data to Another Account
Chrome is now shipping updates every 2 weeks as AI changes the security landscape
CISA Cuts Critical Infrastructure Security Resources
Compromised identities a key driver of ransomware attacks across education sector
Critical Dell Secure Connect Gateway Flaws Enable Unauthenticated Admin Access and Remote Code Execution
Cyberattack encrypts systems at Bavarian municipal utility
Cybersecurity Information Sharing Act of 2015 Temporarily Extended
Data breach exposes sensitive data of 220,000 users on cosmetic procedure platform Gangnam Unni
DoppelCart fraud network uses 119,000 fake shops to steal credit cards
Driver’s License Data Breach: What to Do if Your Information Was Stolen
Elixir Medical Data Breach Impacts PHI and PII of Current and Former Employees
Exposed Database Left 220 Million Airline Passenger, Crew Records Open to the Internet
France Establishes New Government-Focused Cyber Incident Response Unit
FreeIPA Flaw Chain Lets Anonymous Clients Create Reusable Administrator Credentials
French prosecutors confirm arrest of suspected ZeroBytes hacker behind tax cyberattack
Grindr Settles UK Data Privacy Claims for £26m
Grindr to Pay £26 Million to Settle U.K. Claims Over HIV Status Data Sharing
Grindr to pay out $35 million in UK HIV data-sharing settlement
Hackers Abuse Legitimate Node.js Runtime to Hide Persistent Backdoor in Enterprise Attacks
Hackers Abuse Sliver, Mimikatz and Ethereum C2 in Windows Post-Exploitation Attack
Hackers are stealing Claude tokens from subscribers
Hackers breach F5 BIG-IP APM devices to deploy Linux rootkit
Hackers build AI frameworks for widescale credential theft
Hackers claim breach of LA Metro, which serves millions of Americans
Hackers Compromise Coder Module Registry to Serve Malicious Packages and Steal Credentials
Hackers Exploit Metabase Flaw in Mathspace Data Breach Affecting 1.07 Million Users
Hackers Stream Real Google Login Pages to Steal Passwords and 2FA Codes
How Invisible Text Can Turn AI Assistants Into a Phishing Threat
How to spot the new phishing scam targeting Apple Pay users
Hybe’s Weverse Suffers Major ‘Personal Data Leak,’ Tees Up ‘Full Investigation’ to ‘Minimize Exposed Information’
If you subscribed to New Yorker, Vogue, or WIRED, your accounts may be breached
IT help-desk vishing tricks executives into handing over Microsoft 365 access
Jellyfin 12.0 security fixes arrive alongside the removal of legacy client logins
Large KFC franchise operator in South Africa hit by 536GB data breach
Leaving Online Reviews Could Make You A Bigger Target For Phishing Scams
Liquid Hackers Return 3,400 Bitcoin Taken via Elements Bug, Still Holding $47 Million in BTC
Liquid Network’s $47 Million White-Hat Question: Who Decided the Price of the Rescue?
Machinery management specialist Macquarrie investigating data breach after ransomware claims
Massive data breach sees 220 million traveler records exposed - nine years of airline info leaked including passenger and passport details
Massive Vietnam-Linked APIS Database Exposes Passport and Flight Data
Mathspace breach exposes data on over a million students and parents
Mathspace confirms data breach affecting more than 1 million users
Mathspace Data Breach Affects 1.08 Million Students, Parents and Staff
Mathspace data breach exposes information of more than 1 million students, parents and staff
Microsoft 365 users hit by two major threat campaigns - fake IT calls and phishing emails target users across the world
Microsoft Exposes New Phishing Attack: Hiding Within Words
Microsoft posts nearly 1,000 bugs for Patch Tuesday as CISA warns two being exploited
Microsoft September 2026 Patch Tuesday fixes 966 flaws, 2 zero-days
Natural Resources Wales (NRW) Freedom of Information (FoI) Blunder Exposes Diversity Data of Around 2,000 Employees
NFI North Data Breach Affects Almost 50,000 Individuals
NFI North data breach compromises sensitive information of nearly 50,000
NordVPN uncovers global phishing campaign impersonating 75+ brands to hijack corporate accounts
North Korea’s Lazarus cyber umbrella divided into six clusters
OneTouchPoint Agrees to Multi-Million Dollar Data Breach Settlement
Online reviews can expose hidden social ties, increasing risks of phishing attacks
OpenAI says GPT-6 Astra can find zero-days, but is also harder to monitor
Panzer Ransomware Targets Italian Manufacturers and Telecom Firms With ESXi-Ready Ransomware-as-a-Service (RaaS)
Panzer Ransomware Uses Double Extortion and Cross-Platform Builds to Target Enterprises
Philippine Ports Authority (PPA) ransomware report false; Department of Migrant Workers (DMW), Department of Labor and Employment (DOLE) sites restored
Phishing attacks in 2026
Phishing Campaign Targets 99% of US Military Bases During Heightened US-Iran Tensions
Provident Behavioral Health Data Breach Exposes PHI and PII
Ransomware in 2026: What the Data Demands From You
Roanoke email compromise led to data breach notification
Rhysida Leaks 5.26 TB of Berlin's Secret Files on the Dark Web
Russian suspect in bank account takeovers is extradited to US
Russian-Linked Hackers Breach Berlin Senate Through Outdated IT Infrastructure
SAP warns of maximum severity 'OVERPASS' kernel vulnerability
Scammer behind $245 million crypto heist pleads guilty to RICO charges
Schools will remain closed as Springfield works to resolve cyber attack
ShinyHunters claim Florida DMV breach, using Jeffrey Epstein's license as proof
ShinyHunters Claims Florida DMV Breach, Posts Jeffrey Epstein Record as Proof
ShinyHunters hackers claim breach of Florida "DAVID" DMV database
ShinyHunters lawyer up after police release audio clip of suspect in Odido hack
ShinyHunters Names Florida DMV in New Extortion Claim, Sets September 11th Deadline
Slim Spider Steals Crypto Custody Secrets From Brazilian Financial Institution
South Korea's 'Gangnam Unni' Beauty Platform Suffers Data Breach Affecting 220,000 Users, Exposing Treatment and Payment Records
The Gentlemen Ransomware Escalates Privileges Across a Windows Network
THost9 Android RAT Pairs Packed Loader With ADB Worm
Thousands of online shops in danger after critical Adobe Commerce/Magento zero-day exploit
Threat actors are giving AI agents a bigger role in cyberattacks
TitleEase Data Breach Exposes SSNs and Financial Information
Trezor Breach Tops 80K as Phishing Calls Hit Buyers
Trezor customers hit with phishing calls and letters after shipping-partner breach
Trezor Supply Chain Breach Now Impacts 81,000 Customers
UK cybersecurity agency urges firms to tackle risks of “shadow AI”
Using AI, Calif Creates Demo WeChat Exploit that Spreads Through Phone Calls
Verve Portraits data allegedly compromised by Settra ransomware attack
WeChat Zero-Click Worm Took Over Accounts on iPhone and Android via Incoming Calls
‘White hat’ hackers take $47 million bounty after $320 million crypto theft
Your LG TV Might Be Listening Even When It Looks Turned Off - Researchers Found Out How While Also Identifying webOS RCE Flaws
“Zero-click” WeChat worm could hijack accounts and spread via a single call
📅 7th September
$320 Million Vanishes From Liquid Network’s Bitcoin Reserves - And the ‘Hackers’ Say They’re the Good Guys
500 Organizations Breached as Medusa Ransomware Spreads Through Critical U.S. Infrastructure
A whitehat hacker is holding $320 million in drained Bitcoin until developers prove they patched a fatal network flaw
AI Agents could help Ransomware hackers move through networks in just 10 Hours
AI Could Shrink the Supply of Exploits Governments Rely On
Are 200 million LG TVs listening in - even when switched off?
Attackers use rogue ScreenConnect clients to spread malware
Australia: Million-plus students, adults, lose data in major hack
Beaver County agency announces it was a victim of a ransomware attack
Berlin: The hacker group 'Rhysida' stole approximately 5.8 TB of confidential data from the government, leaking information including defense plans and the phone numbers and addresses of government officials
Berlin investigates new data leak after hackers publish stolen login credentials
Berlin Ransomware Leak Exposes State Secrets
BigBear Microsoft 365 phishing service bypassed MFA at 258 organizations
Bitcoin network used by exchanges hit by $320 million exploit. Hackers claim they're the 'good guys'
Breached! Tutoring platform Mathspace says 1 million-plus Australians implicated by data breach
Condé Nast Data of 32.8 Million Users Offered for Sale After WIRED Leak
ConnectWise warns of new ScreenConnect flaw without patch
Crypto Hardware Wallet Maker Trezor Reports 67K Additional US Customers Impacted in ShipMonk Data Breach
Cryptolocker ransomware: A look back at its widespread impact
Cyber criminals are adapting ASCII smuggling for mass phishing campaigns
Cyber’s 2023 problem: Mini-cats or a new loss trend?
Data Breach: Natural Resources Wales (NRW) published staff ethnicity, religion and sexuality data by mistake
Data Breach: What to do if your information is exposed
Data Breach at American Clothing Giant Carhartt Exposes Nearly 13 Million People
DentaQuest sued for allegedly exposing 15 Million patients’ private information
F6 Threat Report Tracks 600 Million Records Across 164 Database Leaks
Fake IT Calls Target Executives in Microsoft 365 Data Theft and Extortion Attacks
FBI investigating huge US and Canadian driver's license data breach on Russian cybercrime site
Former employee files class action against Ceva Logistics over data breach
G7, CISA Urge Urgent Shift to Post-Quantum Cryptography
Gangnam Unni breach exposes sensitive data of 220,000 users
Gangnam Unni Breach Leaks 220,000 Users' Personal, Medical Data
Genetic testing giant hit by data breach affecting 2.8 million
Hackers Abuse Trusted Google Services to Hide Credential-Stealing Phishing Attacks
Hackers are using 'invisible' Unicode characters to sneak phishing lures into emails
Hackers exploit new MikroTik RouterOS flaws to hijack routers
Hackers exploit RouterOS flaws to hijack MikroTik devices without authentication
How Hackers Use Email Addresses for Phishing and Account Takeover
HYBE's Weverse Platform Suffers Data Breach Affecting 420,000 Users, Exposing Payment Records
Identity attacks behind 85 per cent of education ransomware
India: Kerala Faces Cybersecurity Skills Gap as Ransomware Victims Rise 389%
Irish HSE fined €645K after medical records were found in mold and rubble
'It's extremely creepy': LG TVs collect far more data on you than you'd expect, says new report, including logging microphone audio while on standby and detecting your wireless devices including phones and smartwatches - and users are furious
Jaguar Land Rover to cut 4,000 jobs following last year’s cyber attack
JSCeal Malware Can Bypass Google Authentication Using Stolen Session Cookies
June 2026 Healthcare Data Breach Report
Kimsuky Hackers Use OpenCode AI Agent to Mass-Produce Phishing Decoys in LNK Attacks
Liquid Hacker Vows to Return 4,000 BTC Once Bug Is Patched
Liquid Network Hack: $320 Million In Bitcoin Walked Out, And The Hacker Wants To Give It Back
Liquid Network Hackers Demand Bug Fix Before Returning $320M BTC
Magento StyleSmuggler zero-day exploited to deploy Linux backdoor
Mathspace Breach Exposes 1.08 Million Students, Staff
Mathspace Breach Impacts More Than 1 Million Users in Australia, New Zealand
Mathspace data breach affects over 1 million users
Mathspace Data Breach Exposes Over One Million Users in Australia and New Zealand
Mathspace data breach hits over million users across Australia, New Zealand
Mathspace Data Breach Hits 1.08 Million Users in Australia, New Zealand
Mathspace discloses data breach affecting over 1 million people
Mathspace hack: More than one million students, parents and teachers impacted in major data breach
MikroTik under active exploitation: 122,500 routers expose SSH port, emergency patches available
Minnesota County Hit by Second Ransomware Attack After Officials Pay $128,000
Montana Supreme Court confirms records affected in nationwide C-Track data breach
Montana Supreme Court joins New Hampshire court, others in C-Track data breach
More than 1 million users affected in Mathspace data breach across Australia and New Zealand
More than one million affected in major Mathspace data breach across Australia and New Zealand
Multiple Class Action Lawsuits Filed Against IDScan
N-able Issues Fourth N-central Hotfix in Five Weeks for Unauthenticated RCE Flaw
N-able patches critical N-central zero-day exploited in the wild (CVE-2026-86218)
N-able patches max severity N-central flaw amid ongoing attacks
N-able Patches Max-Severity N-central RCE Flaw CVE-2026-86218, Nearly 1,500 N-central Servers Exposed
N-able Releases Hotfix for Critical Remote Code Execution Vulnerability
National Cyber Security Centre (NCSC) Warns Shadow AI Creates New Security Risks
Natural Resources Wales: Notice of personal data breach affecting former and current employees
Natural Resources Wales Data Breach Exposes Sensitive Employee Diversity Information
Natural Resources Wales reports personal data breach affecting former employees
New SynkLoader malware distributed via Microsoft Teams phishing
North Korea’s Lazarus Operates Through Six Distinct Cyber Clusters
OpenAI Confirms Wiki Incident, Plans New Framework for AI Misalignment Disclosures
OpenAI Reports Rogue Agent Web Takeover to EU Regulators as Safety Concerns Grow
Over 420,000 User Accounts Affected In Weverse Data Breach
PEEP Turns Chrome and Edge Into Post-Compromise Backdoors for Host Command Execution
Phishers Are Hiding Malicious Emails in Plain Sight With Invisible Unicode
Phishing Network Hijacks Google’s Own Tools to Slip Past Email Filters
Popular travel app used by 23 Million lets anyone spy on users, including soldiers
Ransomware hackers dump 1.4 million stolen records from German government
Researcher Publishes CrowdStrike Privilege Escalation Zero Day
Rhysida Publishes Berlin Government Data After €2 million Extortion Demand Refused
Rogue ScreenConnect Clients Spread Four-Stage VBScript Chain to Newly Connected Hosts
South African firms urged to prep for more autonomous AI-driven orchestrated attacks
South Korea Records 40% Drop In Voice Phishing Cases After Tough Crackdown
Supposed White-Hat Hackers Drain $320 Million in BTC From Liquid Network, Say They’ll Return It After Fix
Teenage hacker charged over cyberattack on French tax authority
Telerik UI Padding-Oracle Bug Chained to Unauthenticated RCE - Public Exploit Released
The Economics of Dwell Time and Why AI Native SIEM Changes the Equation
The Hidden Privacy Cost of Online Payments
The Hugging Face incident: Inside AI-led data breach that is reshaping OpenAI's safety rules
Toy Ghouls Targets Russian Organizations With New Windows Backdoors
Trezor data breach impact now reaches 81,000 customers
TVING Begins Accepting Compensation Claims for Personal Information Leak...Withdrawn Members Also Eligible
TVING Opens Compensation Claims for Data Breach Victims
UK app developers sue Apple for £2 Billion over tracking rules
US military disables ad trackers on troops’ phones over security concerns
US military troops can still be hit by targeted attacks despite disabling ad tracking on their devices - and leaders aren't happy
US Puts $10 Million Bounty on Alleged Iranian Cyber Chief
Weverse data breach affects 422,584 user accounts
Weverse data leak affects 420,000 users
Weverse, Hive's global fandom platform, suffers data breach affecting 422,000 accounts
What is 'ASCII smuggling'? How to safeguard yourself from such online phishing fraud
When does a Data Breach become “Cognizable Damage” under U.S. Law
Why Are So Many Security Professionals Keeping Breaches Quiet?
Why Hiding Chain-of-Thought Alone Doesn’t Stop Distillation Attacks
Zombie accounts could turn your forgotten profiles into hacker targets
Welcome to DBD. On March 8th 2026, DBD celebrated it's sixth anniversary and