Significant Cyber Incidents
Major breaches, ransomware attacks, and nation-state operations affecting businesses worldwide. Sourced from Cyber Scoop, The Record, SecurityWeek, DataBreaches.net and more.
New Zealand to pursue social media ban for children under 16
The legislation would mandate that high-risk social media platforms such as Instagram, TikTok, Snapchat and Facebook take “reasonable steps” to ensure users are over age 16 by using tools like facial age estimation, digi…
Ascent Skilled Nursing Facilities Assure Breach Victims of “Credible Evidence” Stolen Data Was Deleted
A DataBreaches.net Commentary On July 31, Asheville Beaverdam NC Opco LLC d/b/a Bear Mountain Health and Rehabilitation, Asheville Victoria NC Opco LLC d/b/a Elevate Health & Rehabilitation, and Asheville US Seventy …
Treasury sanctions alleged Iranian hackers as part of ‘economic D-Day’
It’s a follow-up to an indictment the Justice Department unsealed last week against people affiliated with the Mabna Institute. The post Treasury sanctions alleged Iranian hackers as part of ‘economic D-Day’ appeared fir…
Bipartisan Senate bill aims to prepare energy sector for Q-Day
Under the bill, FERC would consider cyber threats from quantum computers and post-quantum cryptography in its reliability standards for the energy sector. The post Bipartisan Senate bill aims to prepare energy sector for…
Indian man who fled US arrested on charges he helped scammers siphon $7.5 million from the elderly
A Jersey City resident is facing charges for his alleged role as a money mule for overseas cyberscammers who stole millions from elderly New Yorkers.…
“Cognizable damage” required for data breach claims, MA appeals court says in a first
Christopher R. Deubert of Constangy, Brooks, Smith & Prophete, LLP writes: Helpful guidance for businesses, and for Massachusetts state courts. In 2021, the U.S. Supreme Court held in TransUnion, LLC v. Ramirez that …
ReliaQuest Confirms ShinyHunters Hack, but Says Impact Was Limited
A ReliaQuest employee fell victim to a phishing attack and the hackers gained access to a dashboard. The post ReliaQuest Confirms ShinyHunters Hack, but Says Impact Was Limited appeared first on SecurityWeek .…
New Guidance Helps Businesses Verify Quantum-Safe Hardware Claims
TCG has released new guidance to help proving that trusted platform modules genuinely meet essential quantum-safe requirements…
NIST Warns of Unique Security Risks in Multi-Cloud Environments
NIST has set out 23 novel challenges that arise in multi-cloud environments and has encouraged the cyber community to find solutions…
Fake Codex Download Uses Google Sites to Deliver macOS Malware
Fake Codex pages used Google Sites, sponsored search and ClickFix to target Mac users…
Hired for One Job, Judged on Another: The CISO’s Real Problem
The skills that get a CISO hired are rarely the skills they are judged on later. Most security leaders are stuck in that gap. Closing it is the real job. The post Hired for One Job, Judged on Another: The CISO’s Real Pro…
Doubloon Dredger Abuses Notion to Harvest Authentication Tokens
Doubloon Dredger abused Notion and malicious PDFs to harvest Microsoft authentication tokens…
Uber Fined Nearly $1 Billion by Dutch Regulators Over Automated Suspensions of Driver Accounts
Dutch Data Protection Authority said it is imposing a fine of 825 million euros because Uber violated the EU’s General Data Protection Regulation. The post Uber Fined Nearly $1 Billion by Dutch Regulators Over Automated …
Personal Information Exposed in Apollo Global Data Breach
Eduard Kovacs reports: Private equity giant Apollo Global Management has disclosed a data breach that exposed sensitive personal information. According to a data breach notice sent to affected individuals, a social engin…
Hackers infecting Android car systems to build proxy botnet
A new strain of malware is being used to infect Android-based car systems, turning the devices into part of a botnet.…
91 Vulnerabilities Patched in Spring Application Framework
More than 200 vulnerabilities have been patched to date this year, compared to only 16 in 2025 and 22 in 2024. The post 91 Vulnerabilities Patched in Spring Application Framework appeared first on SecurityWeek .…
ShinyHunters provided no real proof they hacked ReliaQuest– because they didn’t get anywhere: ReliaQuest
Yesterday, DataBreaches reported that ShinyHunters had added ReliaQuest to its dedicated leak site, but without any substantive proof — only a few screenshots showing access to a user account on reliaquest.okta[.]com/end…
Venezuelan Gets Record Federal Prison Term for ATM Jackpotting
Juan Manuel Gouveia-Aguilera has been sentenced to 8 years in prison for his role in an ATM jackpotting scheme that caused millions in losses. The post Venezuelan Gets Record Federal Prison Term for ATM Jackpotting appea…
Personal Information Exposed in Apollo Global Data Breach
The private equity firm appears to have been targeted as part of a campaign focusing on major financial companies. The post Personal Information Exposed in Apollo Global Data Breach appeared first on SecurityWeek .…
Rethinking Application Security for the AI Era
As AI dramatically shortens the time from vulnerability disclosure to exploitation, enterprises must look beyond patching to reduce application risk. The post Rethinking Application Security for the AI Era appeared first…
Iran-Linked Hackers Shut Down UK Power Plant for Four Days
The attack caused real-world operational disruption and raised concerns about the resilience of Britain’s distributed energy infrastructure and the potential for repeatable attacks. The post Iran-Linked Hackers Shut Down…
TikTok Reaches $400 Million Settlement With US Justice Department Over Children’s Privacy
TikTok will pay $300 million immediately and another $100 million after an order vacates an earlier consent decree against its predecessor company, Musical.ly. The post TikTok Reaches $400 Million Settlement With US Just…
Wake-Up Call for CNI After Iranian Attack Shuts Down UK Power Plant
Experts argue Iranian cyber-attack on UK power plant lays bare frailty of critical national infrastructure…
Researchers Uncover Thousands of Leaked AWS Keys
Truffle Security says it found over 9000 publicly accessible and active AWS key pairs…
Anthropic Expands Mythos 5 Access to More Defenders, Unveils $35M Open Source Fund
Claude Security, currently in public beta for Claude Enterprise customers, now runs codebase scans on Mythos 5. The post Anthropic Expands Mythos 5 Access to More Defenders, Unveils $35M Open Source Fund appeared first o…
Postal Service moves to finalize mail ballot regs before SCOTUS ruling
The rules have already been rejected by multiple state courts, but the Trump administration said it’s preparing in case of a favorable Supreme Court decision. The post Postal Service moves to finalize mail ballot regs be…
Connecticut says data from 41,000 Medicaid members exposed in portal breach; the second portal incident this year
WSFB reports: State officials say a data breach involving the Connecticut Medicaid program’s provider portal exposed payment and claims information tied to roughly 41,000 HUSKY Health members. The Connecticut Department …
Lawmakers call for investigation into impact of CISA staffing cuts
Lawmakers say little is known about how recent cuts have impacted CISA and how the knowledge that was lost has been replaced.…
Apollo discloses data breach from ongoing wave of attacks hitting financial sector
The private equity firm said attackers broke into some of its cloud platforms during a five-day period in early July, compromising sensitive personal data. The post Apollo discloses data breach from ongoing wave of attac…
Troutman Pepper Locke Silent as Threat Actors Leak Client Data, Tens of Thousands of SSNs
In April, Silent Ransom Group’s (SRG)* leak site listed 38 law firms that had not paid them and whose data was leaked. By June 29, there were 48 law firms. Now there are 64, and, in somewhat surprising claims, SRG …
U.S. Bank says breach claims related to fourth-party incident
The bank said there is no evidence that its own systems, networks or data repositories were compromised.…
Lawmakers seek watchdog review of federal hacking of Americans
Sen. Ron Wyden and Rep. Greg Casar want a GAO probe on the government’s use of spyware and other sophisticated hacking tools and authorities. The post Lawmakers seek watchdog review of federal hacking of Americans appear…
Scammers Pose as NYPD Officers in “Well-Done” Video-Call Impersonation Scam
The phone rang, and when “Eddie” (not his real name) picked up, the caller identified herself as being from American Express. Even though Eddie didn’t have any American Express account, he wasn’t …
North Korean Hackers Tied to Rust Supply Chain Attack
Cybersecurity researchers have linked a malicious backdoor in compromised Rust packages to previous North Korean supply chain attacks…
AI, Data Breaches, and an Old Lesson from the Law of Bailment
So I didn’t know what the doctrine of bailment is. If you don’t either, you may want to read this post by Jake L. Ramsey of Offit Kurman. It starts by noting the presentation at BlackHat by two OpenAI enginee…
New Agent Tesla Malware Variant Boosts Evasion Capabilities
An Agent Tesla v4 malware campaign used novel emoji-based code obfuscation to evade detection, KnowBe4 has revealed…
Early 764 member sentenced to 77 years, longest prison term to date for a nihilistic violent extremist
Kyle Spitze led an offshoot of the violent extremist collective and victimized dozens of girls, coercing them to degrade themselves under threats of doxing and swatting. The post Early 764 member sentenced to 77 years, l…
Retail theft bill spurs ‘very large and very dangerous’ surveillance fears
The Combating Organized Retail Crime Act has won a big House vote and could be on the fast track in the Senate — and supporters say it could help fight cybercrime. The post Retail theft bill spurs ‘very large and very da…
The push to designate AI as the next critical infrastructure sector
The designation would unlock a range of federal services, tools and resources for an industry that policymakers view as increasingly tied to national and economic security. The post The push to designate AI as the next c…
Largest Applebee’s franchisee says hackers stole sensitive data
Amar Ćemanović reports: Apple American Group LLC, a major Applebee’s franchise operator in the United States, has disclosed a data breach incident. The event has reportedly exposed sensitive personal information, includi…
AI-fueled attacks pose ‘active threat’ to water, other sectors, U.S. agencies warn
The agencies said the hackers are taking aim at Siemens S7 Series programmable logic controllers in what could be a first. The post AI-fueled attacks pose ‘active threat’ to water, other sectors, U.S. agencies warn appea…
A California county wants to hire Tina Peters to help run its elections
After her prison sentence for felony election-related crimes was commuted, Peters is poised to once again administer critical election duties. The post A California county wants to hire Tina Peters to help run its electi…
Prison for data analyst who tried to extort $2.5 million from his employer
There’s an update to a previously reported case of a disgruntled former employee who tried to extort his employer, Brightly Software. Graham Cluley reports: When Cameron Curry discovered that his contract as a data…