Significant Cyber Incidents
Major breaches, ransomware attacks, and nation-state operations affecting businesses worldwide. Sourced from Cyber Scoop, The Record, SecurityWeek, DataBreaches.net and more.
Delaware Consumer Privacy and Data-Breach Law Updates
Joseph J. Lazzarotti of JacksonLewis writes: On September 2, 2026, Delaware’s Governor signed House Bill (HB) 380 and HB 381. HB 380 amends the Delaware Personal Data Privacy Act (DPDPA), which was enacted in 2023 and be…
AT&T store worker gets 16 months inside for SIM-swap side hustle
Connor Jones reports: A former AT&T retail worker who used his system access to hijack customers’ phone numbers for cybercriminals has been sentenced to 16 months in federal prison. Kenneth Carter, 44, carried …
HHS Releases Updated Security Risk Assessment Tool
From HHS OCR: The U.S. Department of Health and Human Services Office for Civil Rights (OCR) and the Office of the National Coordinator for Health IT (ONC) are pleased to announce the release of version 3.7 of the Securi…
Anthropic CEO Dario Amodei Says AI Industry Needs to Give Safety Measures Time to Catch Up
Dario Amodei warned that within six to 12 months AI could be capable of leading a swarm of agents that could take over the entire internet. The post Anthropic CEO Dario Amodei Says AI Industry Needs to Give Safety Measur…
Not just Korea: Google leaked identifying info for sex crime victims across the world
Shin Da-eun and Park Kang-su report: Korea was not the only country where victims who sent Google removal requests about illegally obtained sexual images ended up having their private information posted online, the Hanky…
NYS DFS Issues New Cybersecurity Guidance on Risk Assessments for Financial Services Entities
New York State Department of Financial Services (DFS): September 10, 2026 New York State Department of Financial Services (DFS) Acting Superintendent Kaitlin Asrow today issued new cybersecurity guidance outlining the De…
BlueMoon Exploit Kit Chains Recent Chrome, Windows Zero-Days
Multiple espionage-motivated threat actors have adopted BlueMoon in opportunistic, rushed deployments. The post BlueMoon Exploit Kit Chains Recent Chrome, Windows Zero-Days appeared first on SecurityWeek .…
Users in Houthi-Held Yemen Tried to Develop Advanced Weapons With AI, Anthropic Says
Anthropic said the users did not succeed in “fielding an operational device” but did carry out a failed test of a guided rocket. The post Users in Houthi-Held Yemen Tried to Develop Advanced Weapons With AI, Anthropic Sa…
Researchers say OpenAI agents were behind May hacking campaign targeting RubyGems
OpenAI confirmed their agents were behind a campaign in May that researchers say flooded the popular online code repository with malicious software packages. The post Researchers say OpenAI agents were behind May hacking…
Cyberattack causes a flight delay? Airlines won’t owe you a hotel or meal
A Department of Transportation rule published last week says that airlines complying with cybersecurity regulations will have reduced customer obligations in the event of an attack. The post Cyberattack causes a flight d…
Florida says motor vehicle data breach tied to credentials stolen from officer’s personal device
The Florida Department of Motor Vehicles confirmed a data breach claimed by the cybercrime group ShinyHunters, saying it originated with the theft of credentials stored on a police officer's personal device.…
TX: Two Lamesa ISD employees arrested over security breach
Urijah Jaushlin reports: Two Lamesa ISD employees were arrested in connection with a law enforcement investigation involving allegations of a breach of computer security, according to a press release by the Lamesa Indepe…
GitLab’s critical flaw is already drawing internet-wide probes
One flaw allows an unauthenticated attacker to read files from the server. GitLab urged operators of self-managed installations to upgrade immediately. The post GitLab’s critical flaw is already drawing internet-wi…
Microsoft sees some new wrinkles in invoice-scam emails
Researchers analyzed a flood of fraudulent business emails and found that the threat actors had doubled-up on tactics to make them appear legitimate, including help from AI.…
Phishing Research Challenges Conventional Security Awareness Testing
Analysis of 2.47 million simulated attacks shows why organizations should measure credential leaks and reporting, not just clicks. The post Phishing Research Challenges Conventional Security Awareness Testing appeared fi…
GitLab Vulnerability Exploited One Day After Disclosure
The critical-severity path traversal flaw allows unauthenticated attackers to read arbitrary files from the GitLab server. The post GitLab Vulnerability Exploited One Day After Disclosure appeared first on SecurityWeek .…
Ukrainian National Sentenced to Four Years in Prison for Wire Fraud Conspiracy in Connection with Conti Ransomware
There’s an update to a previously reported case. From the Department of Justice, this press release: Oleksii Oleksiyovych Lytvynenko, 44, a Ukrainian national, was sentenced today to four years in prison for conspi…
Personal Info Possibly Compromised at Japan’s Digital Agency
JiJi Press reports: Japan’s Digital Agency said Friday that about 246,000 sets of personal information, including the names and email addresses of government employees, may have been compromised through the unautho…
In Other News: InjectEave Attack, SIM Swapper Sentenced, Glasswing Findings Review
Noteworthy stories that might have slipped under the radar: Invisible Unicode slips past phishing filters, US puts $10 million bounty on Iranian cyber official, military ties of Chinese hacking group QTFY. The post In Ot…
Hackers Favor US Eastern Business Hours in M365 Phishing Campaign
KnowBe4 researchers observed a new phishing campaign leveraging Microsoft 365’s Direct Send to send malicious emails…
Trezor Says 347,000 Users Received Phishing Emails After Brevo Hack
Hackers compromised the Brevo marketing platform and used that access to send phishing emails to users of Trezor, BitBox, and CoinTracking. The post Trezor Says 347,000 Users Received Phishing Emails After Brevo Hack app…
Anthropic caught Russia-linked spies using Claude in hacking operations
Anthropic detected and disrupted a Russia-linked cyber-espionage group that used its AI tool Claude in a hacking campaign targeting more than 20 government, intelligence, diplomatic and defense organizations.…
Ukrainian hacker gets four years in US prison over Conti ransomware attacks
A Ukrainian national was sentenced to four years in a U.S. prison for his role in the notorious Conti ransomware operation, which targeted more than 1,000 victims worldwide before shutting down in 2022.…
Ukrainian Conti Ransomware Developer Sentenced to 4 Years in US Prison
Oleksii Oleksiyovych Lytvynenko has been sentenced to 4 years in prison after he was arrested in Ireland in 2023. The post Ukrainian Conti Ransomware Developer Sentenced to 4 Years in US Prison appeared first on Security…
Check Point Patches Critical VPN Vulnerabilities
Tracked as CVE-2026-85102 and CVE-2026-85103, the flaws could be exploited for remote code execution. The post Check Point Patches Critical VPN Vulnerabilities appeared first on SecurityWeek .…
Kiteworks Acquires Bonfy.AI to Fill the AI Gap in Data Governance
Financials have not been disclosed, but the estimated cost is in the tens of millions of dollars. The post Kiteworks Acquires Bonfy.AI to Fill the AI Gap in Data Governance appeared first on SecurityWeek .…
Most Organizations Skip Permissions Reviews Before Deploying AI Tools
A new Syskit study has shown that only 43% of organizations with AI agents deployed in Microsoft 365 environments completed a permission review before doing so…
Treasury urges banks to file cyber scam reports, noting nearly $13 billion in losses since 2023
As the cyber scam industry expands globally, the U.S. government wants banks to share more information about what's happening to their customers.…
Conti ransomware crew member sentenced to four years in prison
Oleksii Lytvynenko joined the notorious group in 2021 and was directly involved in attacks on at least 12 companies. The post Conti ransomware crew member sentenced to four years in prison appeared first on CyberScoop .…
Hawley probes OpenAI over Hugging Face breach
The Republican lawmaker called OpenAI’s leadership decisions “reckless,” and used recent warnings about the existential risk of AI to bolster his inquiry. The post Hawley probes OpenAI over Hugging Face breach appeared f…
AI lets small actors run state-level hacking campaigns, Anthropic report finds
The report details a Russian-aligned espionage campaign against more than 20 organizations, an exploit foundry run by Chinese undergraduates and ShinyHunters-affiliated breaches, among other disrupted operations. The pos…
CISA Updates Insider Threat Guide With New Mitigation Advice
CISA has updated its insider threat guide with new advice on remote work, AI and risk detection…
Governments ‘buying time’ in race between innovation, security, national cyber director says
Sean Cairncross also said AI has shown long-standing issues in cyber rather than creating new ones. The post Governments ‘buying time’ in race between innovation, security, national cyber director says appeared first on …
FTC Withdraws Obsolete Policy Statement
From the Federal Trade Commission: The Federal Trade Commission rescinded the 2021 Policy Statement on Breaches by Health Apps and Other Connected Devices. This controversial policy statement purported to apply the FTC’s…
Korea raises data breach fines to 10% of revenue
Korea JoongAng Daily reports: Korea’s privacy regulator is sharply raising the cost of data breaches, aiming to push companies to treat data protection as a preventive investment rather than a routine cost of doing…
MantaxOtax Android Malware Combines Ransomware With Spyware
MantaxOtax Android malware combines ransomware with extensive spyware capabilities…
FBI Publishes First-Ever Cyber Strategy, With Focus on Disrupting Threat Actors
The new document appears to be part of a broader shift by the US government towards the proactive disruption of cyber threat actors…
Anthropic Reveals Yet Another Cybersecurity Incident
Anthropic has found a fourth case of its model accessing third-party systems without authorization…
OFAC Sanctions Chinese Scam Platform Xinbi Guarantee
The US Treasury has placed sanctions on notorious Chinese cybercrime marketplace Xinbi Guarantee…
Chinese espionage groups swarm to exploit triple-link chain of zero-days
Multiple China-aligned threat groups exploited the defects quickly to target various organizations. Proofpoint said the activity is ongoing and expects it to widen. The post Chinese espionage groups swarm to exploit trip…
FTC rescinds policy statement requiring health apps to notify customers after a breach
The policy, passed under the Biden administration, forced health apps to disclose when users’ personal health records were exposed in a breach or shared without authorization. The post FTC rescinds policy statement requi…
Lawmakers call on Commerce to sanction hackers-for-hire
The groups have allegedly targeted American citizens and companies, including the wife of GOP Senate candidate Mike Rogers, a former representative running in a Michigan swing race. The post Lawmakers call on Commerce to…
Researchers Build WeChat Zero-Click Worm Hijacking Phones via Calls
The hacking tool, built using a combination of AI models, is effective against Android and iOS devices…