Welcome to this week's Data Breaches Digest, a catalogue of links concerning Data Breaches and Cyber Security that were published on the Internet during the period between 21st September and 27th September 2026.📅 26th September
16,000 Supabase databases exposed as vibe-coded apps leak sensitive user data
A Hacker Took Control Of A BYD For TV, But Should Should You Be Worried?
Attackers Bypass WAFs to Exploit Oracle PeopleSoft Flaw and Deploy Web Shells
Dyfed-Powys Cyber Attack: 11-Day Staff Data Probe
Elementor CSRF Flaw Lets Attackers Take Over Sites After Admin Clicks Crafted Link
FBI employees' medical records among data stolen in ShinyHunters hack
FBI Investigates Massive Data Breach Targeting Staff Personal Records
GitHub Actions re-enabled with Mini Shai-Hulud payload still active
Inside the FBI hack: Agents fearful and angry after 'dangerous' data breach
Kiteworks to customers: shut down your systems; cyberattack imminent
Kiteworks Urges Customers to Shut Down Systems for 9 Hours Over Possible Cyber Attack
Lunex Stealer Abuses AMD Driver to Disable Security Monitoring and Steal Browser Credentials
Meta deceived Facebook users about privacy protections, jury finds
Nepal: Central Investigation Bureau (CIB) widens probe into alleged contractor-hacker network behind tender fraud
OpenAI Australia data breach reinforces Prime Minister Albanese’s AI safeguards push
OpenAI's AI agents accidentally uploaded user-provided images to third-party sites
Pentagon Personnel Data Breach Exposes Sensitive Military Records, Raises National Security Concerns
Placeholder Domains Used by 349 AI Agent Skills Found Redirecting to Scams
Qantas off the hook for data breach they could have seen coming
Rogue OpenAI agents leaked dozens of ChatGPT user images online
SharePoint RCE and MikroTik RouterOS Flaws Actively Exploited in the Wild
ShinyHunters Bypass WAF Rules to Resume Oracle PeopleSoft Attacks
ShinyHunters targeting Oracle zero-day days after FBI attack, Google warns
ShinyHunters uses WAF bypass trick in Oracle PeopleSoft attacks
Small Businesses, Big Targets: The Evolving Cyber Threat Landscape For SMEs
The Philippines: Department of Information and Communications Technology (DICT) probes possible data breach involving 48 firms in accreditation program
Thousands of Latvians Fall for Phishing: How Easy It Is to Extract a Password
Why The FBI Data Breach Should Terrify Every Single Agent
Zero Trust for AI Agents Starts With Fixing Zero Visibility
📅 25th September
5G-Shark Lures Phones to Rogue 5G Cells Without Network Jamming
AI Security Awareness is the New Frontline of Cybersecurity
AI tools help hacker break in for $25 per target
Americold Logistics $5.25 Million Settlement Resolves Twin Data Breach Suits
Andover Hired Ransomware Specialists On First Night Of Cyberattack
Another week, another data breach for Revolut customers
Armenian Man Extradited to the United States Sentenced to Federal Prison for Ransomware Extortion Scheme
Asus eShop customers warned of data breach
Attackers Could Abuse SafeBleed in Salesforce Agentforce to Steal Data
Attackers Target Unpatched Roundcube Servers With CVE-2026-48842
Australia: Government 36 times slower to detect data breach than private sector
Australia-based finance app Stake caught in data breach: What you need to know
Australian trading platform Stake caught in data breach
Bitget Confirms $351.6 Million Hack, Suspects North Korea’s Lazarus Group
Bitget hit by $352 million hack with North Korea suspected
Bitget Says Suspected North Korean Hackers Stole $351.6M After Backend Compromise
Burnaby Schools Hit by Cyberattack, Disrupting Networks and Phone Lines
CISA warns of Sharepoint, WSO2, Adobe Commerce flaws exploited in attacks
Cloudflare Fixes Cross-Tenant Data Exposure Bug in Containers
Cloudflare Fixes Flaw That Let One Container Read Another Customer's Leftover Disk Data
Columbia University agrees to $16.1 million settlement over 2025 data breach
Compromised GitHub Actions Came Back Online and Resumed Executing Mini Shai-Hulud Malware
Crypto CEO accuses North Korea of stealing $387 million from Bitget platform
Crypto Exchange Bitget Exploited for $351M as Hacker Swaps Funds for Ethereum
CYBER ATTACK: Dyfed-Powys Police hit, and the force still can’t say whether staff data was accessed
Cyber attack on Dyfed-Powys Police force confirmed
Cyber attack on Dyfed-Powys Police may have compromised staff data
Cyber-attack on Dyfed-Powys police ‘may have accessed staff information’
Cyberattack hits Welsh police force, may have affected staff data
Data Breach at Pentagon Exposes Personal Information of Military Personnel
Doctor's Choice Home Care discloses data breach tied to WellSky vendor
Doubts grow over claims OpenAI agent hacked Australian Medicare portal
DriveWealth Blames Social Engineering Campaign for Revolut Customer Data Breach
Duelbits Hit by $7 Million Hack as Crypto Stolen Across Four Blockchains
Dyfed-Powys Police confirms cyber attack investigation
Dyfed-Powys Police force confirms it was victim of cyber-attack
Dyfed-Powys Police hit by cyber attack
Dyfed-Powys Police hit by cyber attack as information at risk
Dyfed-Powys Police hit by major cyber attack where staff data could have been taken
Dyfed-Powys Police in Wales Hit by Cyber Attack
Dyfed-Powys Police investigates possible staff data breach after cyber attack
Dyfed-Powys Police says it has suffered a cyber attack
Elementor WordPress flaw lets attackers create admin accounts
Email attacks evade detection by generating phishing pages directly inside the victim's browser
EU proposal could let AI companies train on Europeans’ data by default, NOYB warns
Expecting cyber attack, Kiteworks tells users to turn off servers
Fake payroll desktop apps hand attackers a route to company paychecks
Fake Post Office Notices Fuel New Voice Phishing Wave in Korea
For months, OpenAI’s agent swarms have been attacking online databases to find obscure facts
Ghana Cybersecurity Industry Forum (GCIF) cautions public as criminals deploy AI in phishing attacks
Google Chrome 154 Fixes 108 Security Flaws: 11 Are Rated Critical
Hacker ‘IamNotAVillain’ Leaks 150 GB of Alleged Italian Government Data
Hackers steal $351.6 million in Bitget crypto exchange hack
Half of threat hunters say bad data is their biggest problem
How to prove ransomware recovery works: clean-room restoration and recovery assurance
How to Spot a Phishing Email in 2026
Individuals sent ransom notes after cybercriminals steal Flink customer & worker data
Jury finds Facebook liable for deceiving users in Cambridge Analytica case
Kiteworks urges 6-hour server shutdown over potential zero-day attacks
Kiteworks urges customers to shut down their servers amid ‘imminent’ threat of cyberattack
Kiteworks urges customers to stop using platform after warning from federal intelligence agencies
LabCorp reaches $2.3 Million multistate settlement over patient data breach
Labcorp Settles Multistate Data Breach Investigation for $2.3 Million
Labcorp to overhaul data security practices, pay $2.3 million fine for cybersecurity failings
Luxembourg City warns of phishing emails masquerading as municipal administration
MacSync info-stealing malware hides malicious commands in an iCloud calendar
MacSync macOS Stealer Returns With Binary Payloads and iCloud Tricks
Microsoft disrupts EvilTokens device code phishing operation
Microsoft Finds Ransomware Group Using Same Attack Blueprint Across Multiple Malware Families
Microsoft Tracks Storm-2570 Ransomware Affiliate Behind Qilin, DragonForce and Anubis Attacks
Microsoft, Cloudflare disrupt EvilTokens phishing service
Nearly 2 million Quest customers affected by data breach
New Russian Infostealer Targeting Ukrainian Users
NFL romance scammers strike again - Pittsburgh Steeler impersonator dupes women out of cash
North Korean hackers suspected in $351 Million crypto theft, the largest so far this year
One bad Android app could hijack your OnePlus 15, researcher warns
Only 26% of Detected CISA Known Exploited Vulnerabilities Were Fully Remediated
OpenAI Agent Bypasses Medicare Portal, Causing a Data Breach
OpenAI Keeps Hacking and Hacking and...
PamStealer macOS Malware Adds Live C2 Payload Decryption and Multi-Layer Persistence
Park Place Behavioral Healthcare Data Breach Exposes PHI and PII
Party Invite Phishing Scams Are the New Missed Connections
PC maker Asus hacked, user data potentially at risk:Told customers that the breach could have exposed contact and order details
Pentagon Data Breach May Have Exposed Personal Records of Up to 4 Million US Service Members
Pentagon data breach of military personnel raises national security concerns
Phishing attacks with real hotel booking data
Police staff data feared stolen in Welsh cyber raid
Quest Hotels data breach exposes nearly 2 million customers
Redfin Data Breach Exposes Social Security Numbers
RemControl Banking Trojan Gives Attackers Remote Control of Android Devices
Researchers Identify AliExpress Phishing Domains Before Registration
Revolut Customers Caught in DriveWealth Data Breach After Third-Party Security Incident
Revolut Data Breach at DriveWealth Follows Impersonation Incident
Revolut Hacker Used Blockchain Analytics to Identify Targets in Data Breach
Roundcube Pre-Auth SQL Injection Flaw Actively Exploited in the Wild
Rydox Cybercrime Marketplace Operator Pleads Guilty in Pittsburgh
Rydox marketplace admin pleads guilty, faces 22 years in prison
Ryuk ransomware raider sentenced to two years prison
Salesforce Agentforce Flaws Enabled Zero-Click CRM Data Theft and Phishing
Salesforce Agentforce vulnerabilities allowed 0-click CRM data theft, anonymous phishing
Scam hotel booking sent family to Wetherspoon pub
SectopRAT Abuses Legitimate Audio Software Files to Steal PC Data
ShinyHunters hacked Clop leak site using Grav CMS path traversal flaw
ShinyHunters hackers say they stole psychiatric and medical records of FBI staff
Some Supabase customers are publicly exposing reams of people’s data to the web
South Korea: Chuseok Voice Phishing Losses Top 100 Billion Won for First Time
Stake data breach exposes customer details after hack at partner DriveWealth
Sweden’s IMY Fines Miljödata SEK 1.8 Million for Data Breach That Exposed Sick Leave and School Records
Swedish software provider fined after data breach exposed data of 2.2 Million people
TD Bank discloses new data breach affecting Massachusetts customers
The FBI Data Breach Is a Counterintelligence Disaster
The Philippines: GenSan hospital admits ‘data breach’ after ransomware group’s claims
The US Department of War relied on software built in Russia and linked to Russia’s Federal Security Service (FSB)
Threat detection dashboards are masking security coverage gaps
UK police force hit by cyber attack as fears erupt of 'compromised' information
Ukraine Warns Consumers About Fake Electricity Bills and Phishing Scams
Using Threat Intelligence to Track and Disrupt Ransomware Attacks
Wales: Cyber attack on police force may have 'compromised' staff information
Wales: Police force confirms it has been hit by cyber attack as investigation under way
Wales: Police force is hit by cyber attack that has disrupted systems and may have left staff information 'accessed or compromised'
Wayne Memorial Hospital; Regional Urology Settle Data Breach Lawsuits
Welsh police cyberattack sparks probe into possible staff data breach
Where Organizations Fail in Cyberattack Recovery and How They Can Prepare Better
Why ransomware is so dangerous for healthcare
Wisconsin Department of Justice (DOJ) announces $2.3 million Labcorp settlement over 2019 data breach
Wisconsin Joins $2.3 Million Labcorp Settlement, 16,615 Hit
WordPress Flaw Under Active Attack: Hackers Target CVE-2026-87902 for Code Execution
WSO2 and Adobe Commerce Flaws Exploited in Attacks, Added to CISA Known Exploited Vulnerabilities (KEV)
Your incident count is missing a few incidents
Zero-Click Vulnerabilities in Salesforce Agentforce Expose Wider AI Agent Risk
📅 24th September
17,000 URLs Reveal How ClickFix Turns Trusted Websites Into Malware Traps
A Hacker Put AI Agents to Work - and 600,000 Credit Cards Were Stolen
Aeromexico Confirms Customer Data Exposed in Cyberattack
AI data breach exposes gaps in Australia's government cyber defences
Astrana Health Data Breach Impacts Private, Confidential Information
Astrana latest healthcare tech firm to report data breach to Securities and Exchange Commission (SEC)
Asus hacked, company is telling customers their data potentially at risk
Attackers Exploit WordPress CVE-2026-87902 Within Hours of Disclosure
Australia: New South Wales Premier Chris Minns urges caution with AI after government health data breach
Australia says OpenAI agent hacked government website, checks for more breaches
Australia to investigate if OpenAI hack of government health website broke the law
Australia's Prime Minister rebukes OpenAI after AI agent breached Medicare health portal
Beyond the ransomware: Tracking Storm-2570’s consistent tradecraft across deployments
Biglaw Firm Claims Employee Was ‘Deceived’ Into Sending Client Documents To Hacker
Brooklyn man sentenced to 12 years for $16 Million Coinbase phishing scheme
Canada investigates IDScan.net after millions of driver’s licenses leak online
CISA Charts New "Quality Era" for Global CVE Program
Corp MDM Spyware Targets Logistics Firms, Steals New SMS and Redirects Calls
Critical 9.8 JetBrains TeamCity RCE exploited by ransomware, says CISA
Cyber recovery plans lag behind AI, ransomware threats
Data breach victims are staying silent, leaving insurers with less visibility
Deepfake Attacks Are Moving Phishing from the Inbox to Video Calls
Deepfakes, Voice Cloning & AI Phishing Put Indian Enterprises at Risk
Digital forensics firm with US federal contracts covered up ties to Russia, Department of Justice (DOJ) alleges
Elsevier LAPSUS$ Redirect Attack: Visitors Sent to Leak Page Instead of Journals
Emerging Ransomware Gang Uses Backup Destruction Threats to Pressure Victims
"Entire systems could collapse:" OpenAI government breach is a stark warning for national security
Europe’s technology backbone is becoming a cyber target
EvilTokens Turns Genuine Microsoft Login Into a Phishing Trap
Exposed GitLab project email addresses let attackers push code
FBI hack: ShinyHunters countdown ticks down, claims "we got what we wanted" in new post
FBI says source of its jobs portal breach still unknown as hackers allege employee data compromised
Galago Ransomware Emerges With Shared Infrastructure Ties to Panzer
GNOME 50.5 security patch fixes a gvfs CVE and Epiphany code injection
Hacked FBI data has sensitive information about employees' intelligence roles
Hacked Ukrainian Sites Serve Fake Cloudflare ClickFix Lures for Psychedelic Stealer
Hacker claims 7.49 Million customer records stolen from major utility
Hacker Finds This Chinese BYD Pickup Shockingly Easy to Break Into and Control Remotely
Hackers Claim Major FBI Data Breach in Apparent Retaliation Against the Bureau
Hackers now exploit critical Roundcube flaw in code injection attacks
Hackers sell AI token draining as a service: DDoS shift threatens massive direct losses
Homoglyph Attacks Turn Lookalike Domain Names Into Convincing Phishing Traps
Indiana woman suing CenterPoint over data breach, court records say
Indonesia Loses US$6.2 billion from Cyber Attacks This Year
Irish Revolut customers affected by data breach at US broker
Irish Revolut customers among those affected by third-party data breach
Irish Revolut customers hit in second data breach
Irish Revolut customers impacted by data breach
Latvia Hacker Arrested Over TSC Data Theft and Extortion Attempt
MacSync malware uses public iCloud calendars to deliver new payloads
Massive security flaws affect entire Tor network: critical patches released
Microsoft Password Reset Portal Can Leak Account Verification Details
Microsoft, Cloudflare disrupt AI-powered EvilTokens phishing service
Millstone Medical Outsourcing Data Breach Exposes SSNs and Health Records
Mobile App Security in HealthTech: Safeguarding Patient Data Against Cybersecurity Threats
Nevada reaches settlement with Labcorp over 2019 data breach
New Android malware RemControl steals banking PINs and blocks removal attempts
New AvisLoader Windows Malware Uses ClickFix Lure and Tox P2P for C2
New Carbonato malware uses AI agents to hijack exposed Docker hosts
New Galago Ransomware Operation Emerges With Links to Panzer Group
New Galago Ransomware Operation Emerges With Links to Panzer Extortion Group
New Jersey joins $2.2 million multistate LabCorp settlement over 2019 data breach
New ransomware group n0n escalates threats by targeting backups
New RemControl Android Banking Trojan Steals PINs Using AI-Built Phishing Overlays
New York Attorney General James Secures $2.3 Million and Reforms to Protect Consumers After Labcorp Data Breach
Oculus Pathology Notifies 20,000 Patients About April 2026 Security Incident
OpenAI Agent Breached Australia’s Medicare Data Portal, Government Says
OpenAI agent breached Australian government health website, Prime Minister Anthony Albanese says
OpenAI Agent Breached Australian Medicare Statistics Portal
OpenAI Agent Breaches Australian Government Health Service
OpenAI AI Agent Breaches Australian Government Website, Prime Minister Anthony Albanese Demands Answers
OpenAI Agent Bypassed Australian Medicare Portal Controls to Access Non-Public Files
OpenAI agent hacking spree widens to Australia, targeting government website
OpenAI Agent Hacks Australian Medicare Portal
OpenAI data breach latest in long list of hacks in Australia
OpenAI hacked Australian Medicare govt site, probed data providers
Opportune Data Breach Exposes Social Security Numbers
Over 75% of Organizations Experience Microsoft 365 Governance Issues
Over 77 Percent of Ransomware Groups are targeting the Healthcare Sector
Passkey phishing attacks: Why Microsoft 365 security can't stop at sign-in
PC hardware giant ASUS warns customers of eShop data breach
Pennington County Provides New Details on July Ransomware Attack
Pennsylvania getting $43K in settlement from 2019 data breach
Pennsylvania to Get Part of $2.2 Million Settlement in Data Breach
Pharmacies a Hot Target for Phishing, Vishing, and Other Cyberattacks
Placeholder third-party[.]com Referenced Across 1,700+ Repositories Now Serves Malicious Content
Ransomware gangs now exploiting critical TeamCity flaw
Ransomware gets physical
Ransomware Report Confirms Manufacturing as Top Target
Ransomware risks rise as enterprise recovery capabilities erode
Reconnaissance-First Attacks: The Next Evolution of Phishing
Redesigning Security Architecture in the Agentic AI Era
Revolut confirms some Irish customers affected by new ‘third party’ data breach
Revolut Customers Hit by Second Data Breach in Just One Month
Revolut customers impacted by new data breach
Revolut customers in Ireland affected by ‘third-party’ data breach
Revolut Data Breach Notices Hit Former US Trading Users as DriveWealth Confirms Hack: What Was Exposed
Revolut: Hackers threaten ‘We’re selling customer data’. At least 15 Italians affected
Rydox cybercriminal marketplace operator pleads guilty following co-conspirator brothers’s deportation
'Salesbleed' Exploits Salesforce Agents to Enable Slack Phishing
Salesforce Agentforce vulnerabilities allowed 0-click CRM data theft, anonymous phishing
Scammers pose as Ville de Luxembourg in latest phishing email
ServiceTitan discloses health plan data breach affecting 4,851 people
ShinyHunters Claims Data Breach at FBI Through PeopleSoft Zero-Day
ShinyHunters Claims FBI Hack, Threatens To Leak Agent Data Over Warning
ShinyHunters FBI Data Breach: Leaked Spreadsheet Names Staff in China, Russia and HUMINT Roles
Some Irish Revolut customers affected by new data breach
South Korea: Chuseok Voice Phishing Damage Surges Past 100 Billion Won
South Korea's 10% breach fines raise global compliance challenges
TeamFiltration Campaign Compromises Seven Microsoft 365 Accounts Using Default Passwords
Tessco discloses data breach involving Social Security numbers of minors
The Hidden Security Risks of Devices You Forgot Were Connected
‘This kind of data has real utility in the wrong hands’: Cyber experts warn alleged FBI data breach could have serious real world consequences
Ubuntu kernel CVE fixes are moving to a weekly release schedule
UK Government Shifts to Service-Led Cyber Governance After Stinging Audit
UK warns AI gives hackers an advantage over defenders
Unpatched OnePlus Flaws Let Installed Android Apps Gain Root Without Permissions
US Court Sentences Armenian Man to Prison for Ryuk Ransomware Attacks
Veterans Affairs (VA) Slams Baylor Genetics Over Delayed Warning of Massive Patient Data Breach
What is known about latest data breach for Revolut users?
Why Australia chose the world's biggest political stage to reveal OpenAI hack
Wiltshire mum 'extremely worried' after daughter's data stolen
WordPress CVE-2026-87902 Under Active Attack: Critical RCE Flaw Exploited Within Hours
Your security program knows about the firewall, but does it know about the elevator?
Your TV is spying on you: here’s how to make it stop
📅 23rd September
30 million sensitive records leaked, numerous PepsiCo locations exposed
A Leaked GitLab Issue Email Address Lets Anyone Push Code and Run CI Jobs as You
A possible IDScan data breach has far-reaching implications
AI Attacks Enter New Era as Hackers Use Deepfakes and Automation to Scale Deception
AI Gives Hackers an Edge Defenders Still Can’t Match, National Cyber Security Centre (NCSC) Warns
Akira exploits two-year-old SonicWall flaw
Arista patches actively exploited VeloCloud Orchestrator zero-day
Attackers hit Check Point Management Servers and Spark firewalls, F5 BIG-IP APM instances
Attackers Keep Malware Campaigns Alive by Rotating Domains and Hosting Infrastructure
Attackers Use Malicious Terraform Providers to Deliver Go Malware via HashiCorp Registry
Canva reports data breach impacting more than 420 organisations
Check Point warns of hackers exploiting Security Gateway VPN RCE flaw
Chinese Hackers Exploit Chrome-Windows Zero-Day Chain to Deploy CLEANGULP Malware
Cloudflare & Microsoft disrupt EvilTokens phishing service
Cloudflare And Microsoft Lead Takedown Of Phishing Platform Built To Bypass Multi-Factor Authentication
Cloudflare, Microsoft dismantle AI-powered MFA phishing ring targeting Australia
Compromised MemTensor Packages Deliver sckit Credential Stealer via npm and PyPI
Critical Next.js ImageResponse Flaw Can Lead to Server Code Execution via Crafted SVG Input
Cyber attack on Ribon compromises BigCommerce, impacts Master of Malt
Cyber Attacks Increase in 2026: What's Driving the Global Threat?
Cyber risk is now operational risk for Australia’s energy sector
DarkMe RAT trades zero-days for plain phishing emails
Dutch privacy watchdog calls for camera glasses ban in hospitals and courts
EU Auditors Warn Information-Sharing Gaps Are Hindering Cyber Incident Response
EU cybersecurity system hampered by delays and weak information sharing
EvilTokens Phishing Service Uses AI and Device Code Attacks to Hijack Microsoft Accounts
Exploit Released for Unpatched Ubuntu Linux Flaw Enabling Host-Root Container Escape
Extradited Armenian National Sentenced Over Ryuk Ransomware Scheme
F5 patches BIG-IP APM zero-day flaw exploited in RCE attacks
F5 Patches Critical BIG-IP APM Zero-Day Exploited for Unauthenticated RCE on OAuth Servers
Fake Claude Max giveaway tricks users into handing over their Google account credentials
FBI agents' data breach
FBI data breach: Hackers claim personal details of thousands of agents were stolen, here is what happened
FBI Hacked, Employee Data Reportedly Exposed
FBI investigates claimed data breach of agent records by hacking group ShinyHunters
FBI investigating alleged ShinyHunters breach of its jobs site
Flock Camera Hacked, Security Leaders Discuss
Gabia Data Breach Exposes Personal Information of 2,998 Customers
Graphalgo Malware Hits Terraform and Go Packages in New Supply Chain Attack
Greece: Courier service reports customer data breach
Hacker claims massive FBI data breach
Hacker detained in Latvia for at least two cyberattacks
Hacker steals 600,000 credit cards while barely lifting a finger
Hackers Exploit Check Point 0-Day to Execute Arbitrary Scripts Without Authentication
Hackers start exploiting critical WordPress flaw for code execution
Hundreds of Leaked GitHub App Keys Still Authenticate
If You’ve Ever Applied For An FBI Job, Hackers May Have Your Address And Social Security Number
InfraTrust report warns network management systems under attack
Kaspersky Uncovers New Stealth Ransomware that Hijacks Corporate Devices without Encrypting Files
Latvia arrests suspected hacker for electronics repair company breach
Leaked GitHub key left US public health agency’s code exposed to poisoning
Los Angeles (LA) freeway sign hijacked to doxx political dissidents in latest Iran-linked hacking
Malicious AI agents steal 600K credit cards, infect 100+ sites with skimmers
MeDirect: Beware of phishing phone calls claiming your account is at risk
Microsoft and UK Police Dismantle AI-Powered ‘EvilTokens’ Phishing Service
Microsoft Disrupts AI-Powered EvilTokens Service Linked to 12,000 Hacked Inboxes
Microsoft disrupts EvilTokens phishing service that gave criminals access to 12,000 inboxes
Microsoft Takes Down AI Phishing Service EvilTokens
Microsoft Upgrades SharePoint Flaw From Spoofing to 8.8 RCE
Microsoft’s Takedown of EvilTokens Illustrates Broad Use of AI by Threat Actors
MikroTrick Chain Let Attackers Take Over MikroTik Routers Without a Password or SSH Key
Nearly two-thirds of tested websites fail every bot test
NetBSD 10.2 security fixes close a remote kernel bug in ipfilter
New cPanel Flaw Lets a Hosting Account Run Code as Root, Take Full Server Control
New RemControl Android banking malware targets users in Europe and Canada
New Zealand: Privacy Commissioner puts Manage My Health, Health NZ on notice after data breach
Open-Source AI Agents Breach 27 Companies, Steal 600,000 Credit Card Records
Placeholder domain used in developer documentation now serves ClickFix attacks
Quest Apartment customers urged to check passports and licences after major data breach
Quest Apartment Hotels customers urged to check passport and driver’s licence details after data breach
Ransomware Attacks Reach Record High for 2026
Ransomware group PAYLOAD weaponizes Microsoft Active Directory for disruption
Ryuk ransomware member sentenced to 24 months in prison
Ryuk ransomware operator gets 2-year sentence after extorting victims for $1.2 million
ShinyHunters Claim FBI Breach, Offer Sample of Alleged Stolen Data
ShinyHunters claims FBI data breach affecting employees and job applicants
ShinyHunters claims FBI Data Breach, allegedly exfiltrates sensitive Employee Information
ShinyHunters Claims FBI Breach, Says It Stole Data on Agents and Job Applicants
ShinyHunters Claims FBI Data Breach: Hacker Group Says It Stole Records of All Employees and Applicants
ShinyHunters Claims FBI Hack Via PeopleSoft Zero Day
ShinyHunters Claims It Hacked the FBI, Holds Data on Every Employee, FBI Confirms Probe
ShinyHunters claims major data breach at the FBI
ShinyHunters Hacker Group Claims It Hacked the FBI and Stole Data on Nearly Every Agent
Spokane Public Schools Faces Cybersecurity Incident
StreamRat Android Trojan Turns Fake Streaming Ads Into Full Phone Takeover
Suisun City, California, Resumes Public Access After Cyber Attack
Swedish regulator fines IT provider Miljödata over data breach affecting millions
This Windows Malware is Built to Let Up to Four AI Models Vote on Its Next Move
TVING Applies 'Zero Trust' After Massive Data Breach
Windows Botnet x47.c Offers AI API Draining, 18 Attack Methods
WordPress 7.1.2 fixes critical unauthenticated path traversal vulnerability (CVE-2026-87902)
📅 22nd September
7 to 7 Dental Data Breach Affects 3,526 Texans
A cheap fake base station can still track 5G subscribers
AI Agents Are Opening New Doors for Attackers Into SMBs
AI Agents Are Rewriting the Rules of Lateral Movement
AI Drives Surge in Bot and API Threats
AI Incident Response Readiness Lags Behind AI Adoption
AI is set to help cyber attackers much more than defenders, says UK official
Albany College of Pharmacy and Health Sciences Data Breach Settlement
Aprio Advisory Group Data Breach Exposes Financial and Medical Info
Attacker compromised nearly 1000 Zyxel switches since August (CVE-2026-7273)
AVL Growth Partners Data Breach Exposes W-2 Information
Bangladesh: Alleged ‘hacker’ arrested in Natore
Belgian Sports Federations Hit by Cyberattacks, Data Under Investigation
BigCommerce Data Breach Exposes Customer Details Through Third-Party Apps
BigCommerce Merchants Hit by Data Breach via Ribon App
BigCommerce merchants impacted by third-party app data breach
BigCommerce Ribon: Data Breach via Third-Party Application
Brief hijack makes Elsevier domains redirect to LAPSUS$ “Chapter II” page
BYD removes China and surveillance references from car privacy policy
Call-on-Doc Data Breach Exposes Sensitive PHI and PII
Canada’s privacy commissioner investigating massive driver’s licence data breach
Canadian regulator opens probe of IDScan for allegedly violating data privacy laws
Check Point warns of Management Server zero-day exploited in attacks
Check Point Warns of Management Server Zero-Day Exploited in Targeted Attacks
Chinese hackers exploit WordPress, Zyxel flaws to steal government data
Chinese hackers weaponize “the gap” by reverse engineering Chrome fixes before they reach users
Chinese-speaking hacker used AI agents to breach 100 companies, steal credit card data
CISA orders feds to patch Zyxel flaw exploited for data theft
CISOs Must Update Incident Response Playbooks for Multimodal Deepfakes, Gartner Warns
Clop Ransomware Gang’s Leak Site Hijacked by Rival ShinyHunters
CLOSEDQUORUM: The Malware That Lets AI Vote on Its Next Move
Columbia to settle June 2025 data breach lawsuit for $16.1 million
Critical Bifrost AI Gateway Flaw Lets Attackers Run Commands Without Credentials
‘Cyber criminal groups suffer from the same security weaknesses they routinely exploit’: ShinyHunters claims it hacked Clop ransomware rival
Cyber criminals hack into rival hackers’ site amid ongoing feud
D-Link warns of max severity zero-day bug in DIR-822A routers
Digital Operational Resilience Act (DORA) Year Two: Can Your SOC Actually See the Attack?
Doctor's Choice Data Breach Impacts 14,333 Texans
Education sector faces higher email-driven ransomware and account takeover risks
EU Cyber Resilience Act (CRA): What Manufacturers Selling Digital Products in the EU Need to Know About Vulnerability and Incident Reporting
EU Cybersecurity Response Hampered by Critical Information Gaps
EU Fines Google 403 Million Euros For Location Data Breach
EvilTokens PhaaS disrupted after compromising 12,000 Microsoft accounts
FBI Investigating ShinyHunters Claims of Employee Data Theft
Gemini AI Autonomously Hacked 3 Companies, Google Confirms
Google Faces €403 Million GDPR Fine Over Location Tracking
Google fined $463 million over EU data breach
Google’s location tracking comes with a €403 Million fine
Hacker group ShinyHunters claims massive breach of FBI employee data
Hackers are using AI agents to breach companies in just hours, Anthropic says
Hackers breach two Colorado water utility companies
Hacking group ShinyHunters claims it breached the FBI, stole agents’ and applicants’ data
Hacking the hackers: ShinyHunters breaches Clop ransomware site
How Much Does a Data Breach Cost in 2026? Global Average Hits Record $4.99 Million as AI Attacks Reach $6 Million
How to Spot and Report Phishing Attacks
India: Gang with China links busted in Rs 1.95-crore whale phishing fraud
India: Pune Police Bust Five-Member Gang With China Links in ₹1.95 Crore Whale Phishing Fraud
India’s Department of Telecommunications (DoT) Warns Citizens Over SIM Fraud and IMEI Tampering
Iranian hacker in IRGC-linked cyber case to be extradited to US
Kaspersky Uncovers ‘Payload,’ a Stealth Ransomware Targeting Corporate Devices
Kaspersky uncovers stealthy ‘Payload’ ransomware campaign targeting corporate networks
Lakes Region Visiting Nurse Association (LRVNA) Data Breach Exposes Sensitive Personal Information
Malicious npm Package indexed-btree Hid Its Loader in Runtime Code Before Removal
Malicious npm Package Poses as Twilio Bug-Bounty Probe, Can Exfiltrate Credentials
Meta’s Muse AI Agent Has a Zero-Day That Lets Malware Hijack Its Microphone
Meta’s Muse AI assistant can be hijacked through a simple attack
Microsoft and Coinbase probe leads to arrest of crooks behind ‘EvilTokens’, a DIY phishing network powered by AI
Microsoft and Coinbase Take Down EvilTokens, an AI Phishing Service
Microsoft Disrupts EvilTokens Device Code Phishing Service
Microsoft Takes Down EvilTokens AI Phishing Service
Microsoft Takes Down EvilTokens Device-Code Phishing Service Tied to 12,000 Inbox Compromises
Microsoft’s EvilTokens takedown sheds light on state of AI-powered cybercrime
Millennium Partners Data Breach Exposes Social Security Numbers
MovieReaper Malware Uses The Odyssey Torrents to Infect Users Worldwide
Namibia: Ransomware group targets defence ministry
Nepal: Stock Market reopens after ransomware attack disrupts trading
Nepal: Stock Market Trading Halted Due to Cyber Attack on Data Center
Nepal Stock Exchange (NEPSE) ‘technical glitch’ was a ransomware attack. What happened?
Nepal’s stock market has a bigger problem than a ransomware attack: Everything you need to know
Network Segmentation Failures Are Expanding the Corporate Attack Surface
New ClosedQuorum Windows malware uses AI for attack decisions
New CVSS 10.0 VeloCloud Orchestrator Flaw Actively Exploited in Certificate-Based Setups
New Linux Kernel Flaw Gives ARM64 KVM Guests Read-Write Access to Host Memory
New TASK#STOMP Windows Backdoor Enables Continuous Document Theft
New Windows Defender zero-day blocks Microsoft antivirus updates
Nightmare Eclipse Drops New Microsoft Defender Exploit After Revealing Identity
North Korean Attackers Hit 30,000 Devices and Steal $10.7 million
One Hidden Meta Muse Setting Could Let Attackers Turn the AI Assistant Into a Backdoor
Over 30,000 Veterans' Medical Results, Personal Information Exposed by Cyber Data Breach
PAYLOAD ransomware hijacks Windows Group Policy in encryption-less attacks
Potential data breach may affect nearly 2 million people in Czech Republic
Princeton investigates potential cybersecurity incident
Quest breach included thousands of credit card CVVs
Quest Hotels data breach: Almost 2 million impacted, almost 50k credit cards compromised
Ransomware Gangs Are Skipping Encryption to Just Steal and Leak Your Data
Ransomware Without Encryption: PAYLOAD Weaponizes Windows Group Policy
RatHat Android Malware Uses AI to Target Banking Credentials in Real Time
Researcher Drops BigDiskBuster Zero-Day PoC That Blocks Microsoft Defender Updates
Researchers uncover malware that uses AI to choose its next move
Rogue external MFA providers can steal passwords during logins
Scammers use genuine Google sign-ins to sell costly, unverified AI subscriptions
ServiceTitan Data Breach Affects 4,851 Individuals: PHI Exposed
SharePoint Flaw Initially Listed as Spoofing by Microsoft Enables Authenticated RCE
ShinyHunters breaches Clop ransomware site and demands payment
ShinyHunters claims FBI breach via Oracle PeopleSoft zero-day
ShinyHunters claims FBI hack, data theft in PeopleSoft zero-day breach
ShinyHunters claims FBI systems hack, sensitive data "on almost ALL FBI agents"
ShinyHunters hackers say they breached Federal Bureau of Investigation, no immediate FBI comment
ShinyHunters hacks Clop and threatens to extort the ransomware gang
ShinyHunters Hacks FBI Jobs Portal, Claims It Stole Agents’ Data
SideCopy Broadens India Targeting to Academia With ReverseRAT Spear-Phishing
South Korea's Kakao Games Data Breach Victims Rise to 243 as 103 More Confirmed
Stolen passwords are exposing America’s water providers to hackers
Suede Data Breach Exposes Social Security Numbers
Sweden fines Miljödata $183,000 over breach affecting 2.2 million
Tessco Data Breach Exposes Sensitive Personal Information of Minors
The latest deepfake numbers give CISOs plenty to worry about
The next intellectual property thief may sound like your CEO
The Philippines: Land Transportation Franchising and Regulatory Board (LTFRB) flags data breach
Two arrested in UK after Microsoft takedown of ‘Eviltokens’ AI-chatbot for cybercriminals
UK cops arrest 2 EvilTokens suspects, Microsoft seizes 50 phishing kit websites
Ukrainian Hackers Just Stole Heaps of Classified Data from the Russian Navy
United Underwriters Insurance Data Breach Exposes PII
Unmasking EvilTokens: Getting to the root of device code phishing
Veterans Affairs (VA) criticizes Baylor Genetics for delayed notification after data breach
Warning Issued Over Fake 'Seoul Citizen Safety Insurance' Phishing Sites...Beware of Personal Info Requests
West Virginia hospital faces class-action lawsuit over data breach
When the Phishing Page Exists Only Inside the Browser
Why Ransomware Gangs Are Launching Cyber Attacks on Each Other
Why Security Needs to Stay Alert in the ShinyHunters, Clop Feud
WordPress Comment2Shell Flaw Can Turn Anonymous Comment XSS Into RCE via Admin Session
WordPress Issues Patch for Critical Flaw That Can Enable Code Execution on Some Servers
Zyxel and Veeam Flaws Under Active Exploitation With Command and SYSTEM Access
📅 21st September
A Background Check Is Only as Reliable as the Identity Behind It
AI agents on Amazon Web Services (AWS) can access and leak secrets, researchers warn
AI compliance issues hit 2 in 5 large companies, and legacy workflows are a big factor
Allergy Centers Data Breach Compromises Social Security Numbers
Ambry Genetics Pays $700K HIPAA Fine in Phishing Breach
Analysts Link Fetch.ai, NuNet, and SingularityNET Attacks to Single Hacker
Anatomy of a Ransomware Recovery: Hour by Hour
Attackers Abuse npm Trusted Publishing in GHAPPIER Campaign
Australian not-for-profit Thorndale Foundation investigating Qilin breach claims
Australians love these cars. Experts have 'real security concerns'
Belgian table tennis, gymnastics federations hit by cyberattacks
BigCommerce alerts merchants of data breach linked to Ribon apps
Boustead Singapore Reveals Cybersecurity Incident at Overseas Unit
Canadian investigation launched into data breach that exposed millions of IDs
CenterPoint Energy confirms data breach exposure for Indiana customers following alleged 7.5 million record leak
ChatMinerva breached, intruder accessed databases with users' chats
China-Linked FamousSparrow Deploys SparroWocky Backdoor in Latin America
China-nexus actor steals thousands of documents in monthslong exploitation campaign
CISA alerts of active exploitation of three Linux kernel flaws
CISA, FBI and Partners Detail Gunra Ransomware Tactics
ClickFix Attacks Spread ChainScript RAT via Fake Spotify and Teams Installers
ClickFix Lures Deploy ChainScript RAT Using Polygon to Rotate C2 Infrastructure
Clop Ransomware Responds to ShinyHunters Amid Eight-Figure Demands
Contagious Interview Campaign Compromises 30,000 Devices, Steals $10.71 Million in Crypto
CrowdSec Confirms Source Code Stolen in Supply Chain Attack
Cyber Attack to Cost Springfield Schools Time on Winter Break
Cyberattack hits University of Munich, potentially exposing student financial data
Cybercrime civil war brewing? ShinyHunters reportedly hacks Cl0p ransomware gang and threatens further damage
Cybercriminal Claims Moneyboxx Finance Breach, Posts Alleged Source Code on PwnForums
Data Breach at Translation Vendor Affects UnitedHealthcare Plan Members
Data Protection Commission fines Google 403 million euros for location data breach
Employees sue global agribusiness following criminal data breach
EU data regulator fines Google more than $460 million for location data violations
EU fines Google 403 million euros for location data breach
EU fines Google €403 million over location data breach
EU hits Google with €403 million fine over location data breach
EU slaps Google with USD 463 million fine over location data breach
Experts Alarmed Over Gyazo’s Breach of 490 Million Metadata Records
Fake LastPass Authenticator Installer Abuses Microsoft-Signed Driver to Kill Antivirus and EDR
French Crypto Holders Flooded With Fake Support Calls After Tax Data Breach
Gone Phishing? Cybercriminals Are Getting Savvier
Google Fined €403 Million Over GDPR Violations Tied to Location Data
Google fined €403 million over location data privacy violations
Google Gemini demonstrates ability to Cyber Attack Companies after OpenAI Cyber Incident
Google Hit with €403 million GDPR Fine Over Location Data Practices
Google hit with €403 million GDPR fine over location tracking
Google says Gemini breached three companies during security test
Google Wants Android Apps to Look Beyond the Security Patch Date
Greystar Data Breach Exposes Personal and Financial Data
Group Policy hijacked: PAYLOAD ransomware weaponizes Active Directory GPO
Hacked? Qantas investigating WhatsApp phishing reports
Hacker group claims to have hijacked rival gang's website
Hacker Group Exposes Major Vulnerabilities in Flock Automated License Plate Readers
Hacker-on-Hacker Crime: ShinyHunters Is Trying to Extort CLOP Ransomware Group
Hackers exploit Gyazo server flaw to steal 23.6 million user records
Hackers gain brief control over LNG vessel safety systems near Gibraltar
Intent injection attacks are a new worry for AI-native 6G networks
Ireland fines Google €403 million on behalf of EU for location data breach
Jade Sleet Linked to Indian IT Provider Breach With FLATROOF and ROOFDECK Backdoors
Leggett & Platt Data Breach Impacts Adults and Minor Dependents: Personal Information Exposed
LeMaitre Vascular Data Breach Exposes Social Security Numbers
Lessons must be learnt from cyber attack on Revolut, experts warn
Lincoln Investment Data Breach Compromises SSNs and Medical Records
LinkedIn wins court order blocking mass scraping of user data
Maltese accounts may be affected by Revolut data breach
Maltese Accounts Reportedly Among 680 Impacted By Revolut Data Breach
Massachusetts fines TradeZero for data breach, compromising personal information of thousands
MedImpact Data Breach Exposes Personal Information
Mexico probes possible Aeromexico customer data breach
Nepal: Glitches on stock trading platform risk investments of 8 million investors
Nepal: Ransomware attack on Data Hub forces stock market to halt trading
Nepal: Ransomware attack shuts stock market as investors raise security concerns
Nepal stock market halted after ransomware attack disrupts 72 brokers
New Exvicy ClickFix Framework Built on Rival ErrTraffic's Code
New York healthcare provider suffers data breach affecting over 280,000
North Korea’s job interview scam runs both ways
North Korean WaterPlum Hackers Infected 30,000 Devices Through Fake Job Interviews
PAYLOAD Ransomware Hijacks Active Directory GPO to Disrupt Entire Windows Domain Without Encryption
PAYLOAD Ransomware Hijacks Active Directory Group Policy for Encryptionless Extortion
Qantas investigates WhatsApp phishing reports targeting customers
Raising the alarm: Brigham Young University (BYU) researchers find AI is an effective tool in phishing scams
Revolut Customers Targeted with New Wave of Phishing Attacks
Rosch Visionary Systems Data Breach Exposes PHI
Royal College of Veterinary Surgeons (RCVS) apologises after month-long Find a Vet data breach
Royal National Lifeboat Institution (RNLI) warns supporters of possible data breach as it faces far-right targeting
Russia reports thousands of cyberattacks on election infrastructure during vote
Rust developers targeted by hackers with fake job calls and malicious commands
Scammers impersonate cops, use arrest threats to extort victims
‘Scary how open’: BYD Shark 6 remotely hacked during cyber safety test
Securing AI Agents Requires More Than a One-Time Risk Assessment
Severe Bluetooth flaw allows hackers to take over DJI drones in mid-air
ShinyHunters allegedly launches Cyber Attack on Clop Ransomware Group leading to Data Theft
ShinyHunters Claim Hack of Rival Ransomware Gang Clop
ShinyHunters cybercrime gang takes over Cl0p ransomware site, demands extortion payment
ShinyHunters defaces Clop ransomware data leak site, claims data theft
ShinyHunters Extortion Syndicate Hijacks Cl0p Ransomware Dark Web Infrastructure
ShinyHunters Hacks Cl0p’s Dark Web Leak Site in Ransomware Gang Feud
Some Maltese accounts caught up in Revolut data breach, hacker says
South African organisations are taking longer to recover from ransomware attacks
Spanish privacy regulator probes AI agent-driven cyber attack
Taiwan Fines Coupang $47,000 Over Data Breach Hitting 200,000 Users
Taiwan fines Coupang over data breach impacting 200,000 users
TASK#STOMP PowerShell Backdoor Steals Documents, Wi-Fi Passwords, and Clipboard Data
TD Bank Data Breach Exposes Personal and Financial Information
Texas Regional Asthma, Allergy & Immunology Center (TRAAC) Data Breach Impacts 5,040 Patients: Medical Info Exposed
The Philippines: Data breach hits Land Transportation Franchising and Regulatory Board (LTFRB) online system
The Philippines: National Privacy Commission (NPC) reports Land Transportation Franchising and Regulatory Board (LTFRB) online system data breach
The recovery costs of a ransomware attack in South Africa is over $1 million
The ‘significant’ threat of a major cyber attack on Greater Manchester
The TASK#STOMP Windows backdoor takes Wi-Fi passwords, screenshots, and business files
Tishman Speyer Data Breach Compromises Social Security Numbers
WaterPlum Hackers Steal $10.7 Million in Crypto From IT Workers
What To Do After a Healthcare Data Breach: Tips for Nurses
Why Spam Filters Struggle as AI Rewrites Phishing Emails
Why was Nepal’s stock market shut on Monday
WordPress Click2Shell flaw lets hackers execute PHP on the server
Welcome to DBD. On March 8th 2026, DBD celebrated it's sixth anniversary and