Coverage
Data Breaches
470 articles on breaches and ransomware
Advertisement
Silver Fox Malware Campaign Impersonates Software Vendors
An active Silver Fox malware campaign uses fake software download sites to disable Windows Update and weaken Microsoft Defender defenses.
AI-Assisted Cyber Attacks Accelerate Enterprise Breaches
Unit 42 reveals how AI agents dramatically accelerate enterprise network breaches, compressing weeks of attack activity into hours for ransomware operations.
CVE-2026-84115: Cleo Harmony Auth Bypass Exploit Published
An exploit is published for CVE-2026-84115, an authentication bypass in Cleo Harmony allowing remote privilege escalation. Immediate patching to v5.8.1.11 is urged.
Philippines Nuclear Agency Breached via Unpatched ownCloud Flaws
Threat actors exploit unpatched ownCloud vulnerabilities to breach the Philippines nuclear agency, stealing sensitive databases and credentials.
Dark Web Service Nexus Sells 153M+ Driver Licenses
A new dark web service, Nexus, is selling over 153 million drivers' licenses from North America, likely sourced from an identity verification company.
Threat Actors Prefer Repeatable Playbooks Over Novel Exploits
Analysis of modern cyberattacks reveals threat actors increasingly favour scalable, repeatable playbooks over novel exploit development.
Rogue LLM Endpoints: Data Exposure & RCE Risk for AI Agents
Unverified LLM endpoints pose significant risks, enabling data leakage and potential remote code execution via compromised AI agent sessions.
Infostealers Target Anthropic Claude Users via Session Theft
Threat actors are employing various infostealers to compromise Anthropic Claude user accounts via session theft, posing significant risks.
Cronos Blockchain Halted After $6M Tectonic DeFi Exploit
A price manipulation attack on Tectonic’s TONIC token led to a $6M Ethereum theft from the Cronos blockchain, forcing an emergency network restart.
Nutex Health Suffers Data Breach, Sensitive Data Exfiltrated
Nutex Health experienced a data breach exposing patient, employee, and operational data. The company is assessing the full impact.
Mexico’s Cybersecurity Plan 2025-2030: Addressing Rising Threats
Mexico's National Cybersecurity Plan 2025-2030 aims to strengthen defenses against ransomware, state-sponsored espionage, and cybercrime.
State of AI-Enabled Malware: Real-World Impact and Defenses
Unit 42 reports AI-enabled malware is primarily proof-of-concept, with minimal operational activity. Existing defenses effectively detect current threats.
Cybersecurity Affordability Crisis: Impact on Small Businesses
Rising breach costs and defense spending strain budgets, leaving small businesses dangerously exposed and elevating supply chain risks.
CVE-2026-21962: Oracle WebLogic RCE Under Active Attack
CISA urges immediate patching for CVE-2026-21962, a critical Oracle WebLogic Server Proxy plugin vulnerability actively exploited in the wild.
SynkLoader Multitool Malware Employs Screen Hijacking
SynkLoader multitool malware leverages screen hijacking techniques and novel features for password theft, signaling potential ransomware threats.
ReliaQuest Thwarts ShinyHunters Social Engineering Attack on Okta SSO
ReliaQuest confirms a social engineering attack by ShinyHunters targeting an employee's Okta SSO, blocked from accessing applications or customer data.
AI-Powered PLC Attacks Target Critical Infrastructure
U.S. agencies warn that threat actors are using AI to target internet-exposed Siemens S7 Series PLCs in critical infrastructure sectors.
Encrypted Prompts Bypass AI Safety Guardrails in Grok and Gemini
Researchers discover cryptographic context injection, a novel technique bypassing AI safety filters in xAI Grok and Google Gemini using encryption.
SynkLoader Malware Steals Credentials in Microsoft Teams Phishing
New SynkLoader malware distributed via Microsoft Teams phishing campaigns uses a fake lock screen to steal Windows credentials, enabling corporate network access.
CISA Warns of Active Ray Exploit and Medusa Ransomware Campaign
SecurityWeek weekly briefing highlights active exploitation of Ray flaw by RondoDox botnet, Medusa ransomware, and Salt Typhoon breaches.
Hundreds of Leaked AWS Keys Expose Corporate Cloud Accounts
Research reveals over 9,000 publicly exposed Amazon Web Services access keys remain active, including hundreds of root and administrator credentials.
Sakura Internet Breach Exposes 1.36 Million Accounts
Japanese cloud provider Sakura Internet discloses a data breach exposing customer contract and membership data for up to 1.36 million accounts.
CISA Warns: Medusa Ransomware Breaches 500+ Critical Infra Orgs
CISA, FBI, and HHS alert on Medusa ransomware, which has impacted over 500 critical infrastructure organizations since June 2021, urging immediate network hardening.
Mitigating Large-Scale Credential Attacks and Password Spraying
Analysis of large-scale password spraying and credential theft campaigns targeting enterprise identity perimeters, edge devices, and cloud tenants.