2026-09-08 14:00 UTC
Vendor Research
Google Threat Intelligence / Mandiant · Google Threat Intelligence Group · indexed 2026-09-08 13:45 UTC
Executive Summary Since the release of our May 2026 report detailing adversarial misuse of artificial intelligence (AI), Google Threat Intelligence Group (GTIG) has observed forward leaning adversaries transition from basic prompting to agentic AI workflows and AI-enabled automation. In these operations, human-in-the-loop latency is dramatically reduced, compressing the traditional window for defenders to respond. In Q2 2026, GTIG observed threat actors compromise a cloud resource, then plan, b…
P35
2026-09-08 13:00 UTC
Other
Check Point Research · stcpresearch · indexed 2026-09-08 13:10 UTC
Research by: Alexey Bukhteyev Key Takeaways Introduction Over the past several years, AI assistants have moved far beyond text generation. Modern systems can execute code, install additional dependencies, analyze user files, and access data through connected services. These capabilities significantly increase the practical value of LLMs, but they also change the security model: protecting user […] The post The Shared Clipboard Inside the Sandbox: Cross-Account Data Leakage in ChatGPT appeared f…
P0
2026-09-08 10:47 UTC
Security Journalism
Security Week · Ionut Arghire · indexed 2026-09-08 10:50 UTC
Hackers stole the information of students, teachers, staff, and parents/guardians from a self-hosted Metabase instance. The post Mathspace Data Breach Exposes Over 1 Million People appeared first on SecurityWeek.
P0
2026-09-07 13:05 UTC
Security Journalism
BleepingComputer · Sergiu Gatlan · indexed 2026-09-07 13:15 UTC
Online maths learning platform Mathspace disclosed over the weekend that attackers stole data from more than 1 million students, staff, and parents after breaching its Metabase internal reporting system. [...]
P0
2026-09-07 12:16 UTC
Security Journalism
BleepingComputer · Sergiu Gatlan · indexed 2026-09-07 12:35 UTC
Cryptocurrency hardware wallet maker Trezor says an August data breach at its shipping and logistics provider, ShipMonk, affects an additional 67,000 U.S. customers. [...]
P0
2026-09-07 11:50 UTC
Security Journalism
The Record · indexed 2026-09-07 12:05 UTC
Another trove of data from Berlin's government has appeared online, authorities said. Germany's information security agency separately warned about the Rhysida cybercrime group.
P0
2026-09-04 18:30 UTC
Other
Security Affairs · Pierluigi Paganini · indexed 2026-09-04 18:55 UTC
Manchester Airports Group (MAG) data allegedly leaked by FulcrumSec exposes emails and phone numbers of 8.8 million people. Manchester Airports Group, which operates Manchester, London Stansted and East Midlands airports, has confirmed a data breach involving customer information held in a third-party database. The company says airport operations, passenger safety and aviation security were not […]
P0
2026-09-04 16:56 UTC
Security Journalism
BleepingComputer · Bill Toulas · indexed 2026-09-04 17:00 UTC
Multiple lawsuits have been filed against identity verification company IDScan after hackers allegedly breached the service and offered to sell more than 153 million driver's licenses. [...]
P0
2026-09-01 19:28 UTC
Security Journalism
BleepingComputer · Bill Toulas · indexed 2026-09-01 19:30 UTC
Aesto LLC, operating as Aesto Health, disclosed that a data breach discovered recently affects more than 9.5 million individuals. [...]
P0
2026-09-01 15:12 UTC
Other
Security Affairs · Pierluigi Paganini · indexed 2026-09-01 15:40 UTC
Aesto Health suffered a breach exposing personal and health data of more than 9.5 million people after attackers accessed its AWS infrastructure. Aesto Health, a U.S. healthcare technology company, disclosed a data breach that exposed personal and health information belonging to more than 9.5 million people. The company discovered the incident on December 18, 2025, […]
P0
2026-09-01 14:28 UTC
Security Journalism
BleepingComputer · Sergiu Gatlan · indexed 2026-09-01 14:30 UTC
Healthtech company Novocure says the data of an undisclosed number of employees and more than 1,400 U.S. cancer patients has been exposed in a mid-August cyberattack. [...]
P0
2026-08-31 13:30 UTC
Security Journalism
BleepingComputer · Bill Toulas · indexed 2026-08-31 13:40 UTC
Berlin's city administration has confirmed that cybercriminals are attempting to extort the city after the Rhysida ransomware gang listed it on their data leak site. [...]
P15
2026-08-30 17:21 UTC
Other
Security Affairs · Pierluigi Paganini · indexed 2026-08-30 17:45 UTC
Extortion group FulcrumSec claims they stole 86GB of Manchester Airports Group data after finding API credentials exposed in client-side JavaScript. Manchester Airports Group (MAG) disclosed a data breach on August 27 affecting customers of Manchester, London Stansted, and East Midlands airports. Two days later, BleepingComputer reports the extortion group FulcrumSec claimed responsibility, saying it stole […]
P0
2026-08-28 20:14 UTC
Other
Security Affairs · Pierluigi Paganini · indexed 2026-08-28 21:15 UTC
Love Electric’s alleged data breach exposes sensitive driver data and highlights the identity risks created by third-party salary sacrifice providers. A seller on an English-language data-breach forum claimed on August 26 that they had obtained the driver database of Love Electric, a UK broker that runs electric-vehicle salary sacrifice schemes. The seller, operating under the […]
P0
2026-08-28 11:46 UTC
Security Journalism
BleepingComputer · Sergiu Gatlan · indexed 2026-08-28 12:00 UTC
Hasbro, one of the world's largest toy and game companies, has disclosed that attackers have accessed the personal and financial information of an undisclosed number of employees. [...]
P0
2026-08-27 13:51 UTC
Vendor Research
Rapid7 · Alexandra Blia · indexed 2026-08-27 14:25 UTC
IntroductionDespite modern verification controls, identity theft remains one of the most pervasive threats to both individuals and enterprise organizations. U.S. Federal Trade Commission statistics show over 1 million identity theft reports annually, with related fraud and imposter scams accounting for billions in financial losses each year. While stolen credit cards enable rapid, short-term monetization, Social Security numbers (SSNs) represent a far more permanent and dangerous tier within th…
P0
2026-08-27 11:10 UTC
Security Journalism
BleepingComputer · Sergiu Gatlan · indexed 2026-08-27 11:15 UTC
The ShinyHunters extortion group has published sensitive data from nearly 13 million accounts stolen from clothing retailer giant Carhartt earlier this month, according to data breach notification service Have I Been Pwned. [...]
P0
2026-08-26 09:00 UTC
Vendor Research
Tenable Cyber Exposure Alerts · Research Special Operations · indexed 2026-08-26 13:15 UTC
A joint Tenable-SentinelOne analysis of 93 CVE-actor attribution pairs reveals that both state-sponsored actors and cybercriminals independently converge on the same edge infrastructure. Special thanks to SentinelOne® Incident Readiness & Response for their contributions to this publication.It is the shared attack surface where state-sponsored threat actors and financially motivated criminal groups independently converge — not the province of a single adversary category, and not exclusively a n…
P45
2026-08-25 21:58 UTC
Security Journalism
BleepingComputer · Bill Toulas · indexed 2026-08-25 22:10 UTC
The Los Angeles County Museum of Art (LACMA) has announced that a breach last year exposed customer and employee information. [...]
P0
2026-08-25 14:44 UTC
Security Journalism
BleepingComputer · Bill Toulas · indexed 2026-08-25 14:45 UTC
Healthcare and services provider Nutex is investigating a data breach incident where an unauthorized third party exfiltrated information from company servers. [...]
P0
2026-08-21 10:10 UTC
Security Journalism
BleepingComputer · Ax Sharma · indexed 2026-08-21 10:25 UTC
Toronto's Hospital for Sick Children (SickKids) says a cybersecurity incident exposed the personal information of some current and former employees and job applicants, stemming from a flaw in third-party software. Clinical systems and patient records were not affected. (264) [...]
P0
2026-08-19 20:59 UTC
Security Journalism
BleepingComputer · Lawrence Abrams · indexed 2026-08-19 22:15 UTC
A suspected ransomware affiliate is posing as a ransomware recovery service called "Ransom Busters," contacting the victims before the attacks become public and claiming to be able to provide decryption keys and delete stolen data for a fee. [...]
P15
2026-08-19 20:59 UTC
Security Journalism
BleepingComputer · Lawrence Abrams · indexed 2026-08-19 21:10 UTC
A suspected ransomware affiliate is posing as a ransomware recovery service called "Ransom Busters," contacting the victims before the attacks become public and claiming to be able to provide decryption keys and delete stolen data for a fee. [...]
P15
2026-08-19 20:07 UTC
Security Journalism
BleepingComputer · Bill Toulas · indexed 2026-08-19 20:15 UTC
U.S. healthcare IT company CareCloud disclosed that the data breach incident it suffered earlier this year has impacted more than 3.7 million individuals. [...]
P0
2026-08-18 16:58 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-18 18:35 UTC
A ransomware affiliate calling itself Ransom Busters has been spotted proactively sending emails to victim organizations and claims to delete stolen data from ransomware groups' servers in exchange for a fee ranging from $20,000 to $60,000. "In these messages, the third-party offers to help the victim recover from ransomware attack. This immediately stands out as anomalous," GuidePoint Research
P15
2026-08-17 19:12 UTC
Security Journalism
BleepingComputer · Lawrence Abrams · indexed 2026-08-17 19:15 UTC
Pokémon Center is notifying customers in the United Kingdom and Germany that it suffered a third-party data breach after hackers stole customer personal and order information from third-party logistics provider CEVA Logistics. [...]
P0
2026-08-17 17:54 UTC
Other
Security Affairs · Pierluigi Paganini · indexed 2026-08-17 18:35 UTC
SafePal says a breach exposed personal data of 39,798 customers, but not wallet credentials, private keys, seed phrases, or payment information. SafePal disclosed a data breach affecting about 39,798 customers after hackers exploited a vulnerability in its order-tracking plugin. The flaw exposed information linked to orders placed between March 2, 2025, and April 11, 2026, […]
P0
2026-08-17 17:00 UTC
Security Journalism
The Record · indexed 2026-08-17 17:10 UTC
The crypto hardware wallet company SafePal confirmed a data breach on Sunday, telling users that nearly 40,000 customers had information stolen during a recent security incident.
P0
2026-08-17 10:09 UTC
Security Journalism
BleepingComputer · Sergiu Gatlan · indexed 2026-08-17 10:20 UTC
The French Ministry of the Economy and Finance has disclosed a data breach after an attacker accessed the General Directorate of Public Finances (DGFiP) systems and stole data belonging to 678,000 individuals. [...]
P0
2026-08-16 23:47 UTC
Security Journalism
BleepingComputer · Lawrence Abrams · indexed 2026-08-16 23:55 UTC
Cryptocurrency hardware wallet provider SafePal is warning of a data breach affecting about 39,798 customers after a flaw was exploited to steal customer order information, and a threat actor is now claiming to be selling the stolen data. [...]
P0