2026-09-23 05:30 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-23 06:40 UTC
The cyber extortion group known as ShinyHunters on Tuesday claimed it had breached the U.S. Federal Bureau of Investigation and stolen data belonging to current and former employees at the agency. "We have compromised the FBI. We hold very sensitive data on almost ALL FBI Agents and individuals who filed an application with the FBI for a job," the group said in a statement posted on their dark
P0
2026-09-21 23:13 UTC
Other
Check Point Research · urias@checkpoint.com · indexed 2026-09-21 23:20 UTC
For the latest discoveries in cyber research for the week of 21st September, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES Japan’s Digital Agency, which operates the Government Solution Service used by multiple ministries, has confirmed a data breach after attackers exploited a vulnerability in a VPN appliance. Approximately 246,000 records were exposed, […] The post 21st September – Threat Intelligence Report appeared first on Check Point Research.
P0
2026-09-21 21:18 UTC
Security Journalism
BleepingComputer · Bill Toulas · indexed 2026-09-21 21:20 UTC
Ecommerce platform BigCommerce has alerted multiple merchants to data breaches after attackers compromised credentials for third-party Ribon applications and used them to inject malicious scripts into online stores. [...]
P0
2026-09-21 15:00 UTC
Security Journalism
The Record · indexed 2026-09-21 15:30 UTC
Belgium’s national table tennis federation is investigating a cyberattack after a hacker claimed to have stolen data on tens of thousands of members.
P0
2026-09-21 10:55 UTC
Security Journalism
Security Week · Ionut Arghire · indexed 2026-09-21 11:00 UTC
The cybersecurity firm believes the data breach was the result of the May 2026 TanStack supply chain attack. The post CrowdSec Confirms Source Code Stolen in Supply Chain Attack appeared first on SecurityWeek.
P0
2026-09-19 13:48 UTC
Security Journalism
BleepingComputer · Lawrence Abrams · indexed 2026-09-19 14:00 UTC
The ShinyHunters extortion gang breached the Clop (aka Cl0p) ransomware operation's data leak site, defacing the Tor site and allegedly stealing server data and the private keys for its onion service. [...]
P15
2026-09-19 13:28 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-19 14:30 UTC
Identity visibility is a starting point for modern identity security, because stolen and misused credentials are among the most frequently reported initial access vectors in breach research, including Verizon's annual Data Breach Investigations Report. This article explains what identity visibility means in IAM, why cloud and multicloud environments complicate it, which capabilities matter in
P0
2026-09-18 17:10 UTC
Other
Security Affairs · Pierluigi Paganini · indexed 2026-09-18 17:20 UTC
A Gyazo breach exposed 23 million user records after attackers exploited a vulnerability in Helpfeel’s image upload server. Japanese software company Helpfeel is notifying Gyazo users about a data breach that compromised 23 million user records. Attackers gained unauthorized access by exploiting a vulnerability in the service’s image upload server. “We have confirmed that approximately […]
P0
2026-09-18 16:00 UTC
Security Journalism
BleepingComputer · Bill Toulas · indexed 2026-09-18 16:15 UTC
The Gyazo image-sharing platform has confirmed it suffered a data breach after hackers exploited a server vulnerability that allowed them to steal 23.6 million user records. [...]
P0
2026-09-18 11:38 UTC
Security Journalism
Security Week · Eduard Kovacs · indexed 2026-09-18 11:50 UTC
Gyazo maker Helpfeel said the attacker exploited a vulnerability in its image upload server to gain unauthorized access. The post 23 Million User Records Compromised in Gyazo Data Breach appeared first on SecurityWeek.
P0
2026-09-17 13:57 UTC
Security Journalism
Security Week · Ionut Arghire · indexed 2026-09-17 14:10 UTC
Revolut allegedly fed customer information to hackers impersonating an Italian government agency for five months. The post Revolut Data Breach: 5 Months, 680 High-Profile Accounts, $3M Ransom appeared first on SecurityWeek.
P0
2026-09-16 17:26 UTC
Security Journalism
BleepingComputer · Bill Toulas · indexed 2026-09-16 17:45 UTC
The Spanish Data Protection Agency (AEPD) was notified of an attack allegedly carried out with an AI agent powered by a known large language model (LLM). [...]
P0
2026-09-16 16:39 UTC
Security Journalism
Security Week · Kevin Townsend · indexed 2026-09-16 16:50 UTC
Spanish regulators say an AI agent chained together a successful login, vulnerability discovery, and access to personal data in a potential milestone for autonomous cyberattacks. The post First Agentic AI Data Breach Reported to Spanish Regulator appeared first on SecurityWeek.
P0
2026-09-16 13:09 UTC
Other
Security Affairs · Pierluigi Paganini · indexed 2026-09-16 14:15 UTC
A suspected compromise of an Italian government PEC account may have allowed threat actors to impersonate law enforcement and obtain sensitive data from hundreds of Revolut customers. The Revolut data exposure may be part of a much broader cyber incident involving compromised Italian government infrastructure. Revolut has confirmed that its systems were not breached. Instead, […]
P0
2026-09-16 10:47 UTC
Security Journalism
Security Week · Ionut Arghire · indexed 2026-09-16 11:00 UTC
In June 2026, hackers accessed files containing patients’ names, contact information, diagnosis details, and health insurance information. The post 280,000 Impacted by Premier Medical Group Data Breach appeared first on SecurityWeek.
P0
2026-09-16 08:19 UTC
Other
Security Affairs · Pierluigi Paganini · indexed 2026-09-16 08:40 UTC
CenterPoint Energy confirmed a customer data breach after a hacker claimed to leak 7.49M records, including personal and billing information. CenterPoint Energy admitted on Monday that an intruder stole personal information belonging to some of its customers. The Houston-based utility, which supplies electricity and gas to about 7 million accounts across Texas, Indiana, Minnesota and […]
P0
2026-09-15 14:22 UTC
Security Journalism
The Record · indexed 2026-09-15 14:40 UTC
Houston-based CenterPoint Energy notified federal regulators about an incident that exposed some customer data on the dark web.
P0
2026-09-15 11:45 UTC
Security Journalism
Security Week · Ionut Arghire · indexed 2026-09-15 11:50 UTC
Hackers exploited a vulnerability in a VPN product to steal the personal information of roughly 240,000 people. The post 240,000 Hit by Data Breach at Japan’s Digital Agency appeared first on SecurityWeek.
P0
2026-09-15 07:48 UTC
Other
Security Affairs · Pierluigi Paganini · indexed 2026-09-15 09:00 UTC
A Telegram Desktop flaw let bots inject JavaScript into exported chats, enabling data theft and page manipulation. Old HTML exports remain unsafe. A vulnerability in Telegram Desktop could have turned an ordinary chat export into a serious data leak. Security researchers Denis and Aleksander Rostilov of ExPatch found a stored cross-site scripting flaw in the […]
P0
2026-09-14 20:36 UTC
Security Journalism
BleepingComputer · Bill Toulas · indexed 2026-09-14 20:40 UTC
Japan's Digital Agency has discovered a data breach that may have exposed around 246,000 record rows containing personal information of government employees. [...]
P0
2026-09-14 16:15 UTC
Security Journalism
The Record · indexed 2026-09-14 16:15 UTC
The pro-Ukraine hacktivist group Hacking Cat has evolved from carrying out website defacements and data leaks to more sophisticated and destructive attacks on Russian targets, researchers said.
P0
2026-09-14 13:03 UTC
Security Journalism
Security Week · Ionut Arghire · indexed 2026-09-14 13:10 UTC
The company unintentionally disclosed users’ information to a third party impersonating a government agency. The post Personal, Financial Info Exposed in Revolut Data Breach appeared first on SecurityWeek.
P0
2026-09-14 12:22 UTC
Other
Check Point Research · urias@checkpoint.com · indexed 2026-09-14 12:30 UTC
For the latest discoveries in cyber research for the week of 14th Setpember, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES IDScan.net, a US identity verification provider, has disclosed a data breach after detecting unauthorized access on September 1. Exposed data included names and government identification numbers, while a criminal marketplace advertised a […] The post 14th September – Threat Intelligence Report appeared first on Check Point Research.
P0
2026-09-14 08:48 UTC
Security Journalism
BleepingComputer · Sergiu Gatlan · indexed 2026-09-14 08:55 UTC
Fintech company Revolut has disclosed a data breach after sharing data from an undisclosed number of customers with a threat actor impersonating a government agency. [...]
P0
2026-09-11 20:00 UTC
Security Journalism
The Record · indexed 2026-09-11 20:20 UTC
The Florida Department of Motor Vehicles confirmed a data breach claimed by the cybercrime group ShinyHunters, saying it originated with the theft of credentials stored on a police officer's personal device.
P0
2026-09-11 19:00 UTC
Security Journalism
BleepingComputer · Lawrence Abrams · indexed 2026-09-11 19:05 UTC
The Florida Department of Highway Safety and Motor Vehicles (FLHSMV) has confirmed that its DAVID driver database suffered a data breach, saying the attackers gained access using credentials belonging to a police department employee. [...]
P0
2026-09-10 18:55 UTC
Security Journalism
The Record · indexed 2026-09-10 19:00 UTC
A notice dated September 4 but not widely shared shows that IDScan acknowledged a data breach but did not specify how many people were affected.
P0
2026-09-10 11:20 UTC
Security Journalism
Security Week · Ionut Arghire · indexed 2026-09-10 11:35 UTC
In June 2026, hackers stole personal, health, and insurance information from AdaptHealth’s systems. The post 4.1 Million Impacted by AdaptHealth Data Breach appeared first on SecurityWeek.
P0
2026-09-09 15:31 UTC
Security Journalism
BleepingComputer · Bill Toulas · indexed 2026-09-09 15:35 UTC
Healthcare technology company Veradigm disclosed a data breach after a cybersecurity incident at one of its third-party vendors exposed patients' personal data. [...]
P15
2026-09-09 13:00 UTC
Vendor Research
Tenable Blog · Mark Beblow · indexed 2026-09-09 13:10 UTC
Open-source registries for AI agents are only effective when they include a rigorous, transparent security review process for community submissions. That’s why for its new CyberAgents Exchange registry, Tenable paired its exposure management expertise with OpenAI GPT Cyber models to create the CyberAgents Exchange AI Inspector.Key takeawaysThe Exchange Inspector combines Tenable’s exposure detection with OpenAI’s GPT Cyber models and with human oversight to rigorously vet submissions made to th…
P0