Coverage
Data Breaches
482 articles on breaches and ransomware
Advertisement
Canvas Platform Breach: Extortion Threatens 275M Student Data
A cybercrime group's data extortion attack on the Canvas education platform disrupted services and threatens to leak data from 275 million students and faculty.
ShinyHunters Defaces Canvas Login Portals in Extortion Campaign
ShinyHunters breached Instructure, defacing Canvas login portals for numerous educational institutions, potentially impacting user credentials and initiating extortion.
Claude AI Guided Hackers Toward OT Assets During Water Utility Intrusion
Threat actors utilized Anthropic’s Claude AI to navigate OT environments during a water utility breach, highlighting the rising risk of AI-assisted ICS attacks.
Instructure Data Breach: ShinyHunters Exposes Education Sector Vendor Risk
Analysis of the Instructure data breach by ShinyHunters, impacting educational institutions using Canvas LMS and highlighting critical third-party vendor dependencies.
Threat Activity Enablers: Unpacking Cybercrime Infrastructure
Analyzing how cybercriminals leverage hosting, domain, and cloud services as "threat activity enablers" to power operations. Learn to identify and disrupt this critical
MuddyWater Exploits Microsoft Teams via Chaos Ransomware Decoy
Iranian APT MuddyWater utilizes Microsoft Teams social engineering and Chaos ransomware decoys to mask state-sponsored espionage operations.
Ransomware Attackers Target Backup Infrastructure to Block Recovery
Explore how ransomware operators neutralize backup systems to prevent recovery. This analysis covers attacker TTPs and mitigation steps for backups.
MuddyWater Exploits Microsoft Teams for False Flag Ransomware
Iranian APT MuddyWater is leveraging Microsoft Teams social engineering to deploy false flag ransomware, obscuring state-sponsored espionage activities.
Instructure Data Theft Claim: 280 Million Records from 8,800+ Schools
A hacker claims to have stolen 280 million student and staff data records from 8,809 educational institutions impacted by a breach at Instructure.
Karakurt Extortion Gang Negotiator Sentenced to 8.5 Years in Prison
A Latvian national and key negotiator for the Karakurt extortion gang has been sentenced to 102 months for his role in U.S.-based data theft operations.
Insecure Self-Hosted AI: 1 Million Exposed Services Risks Analyzed
A security scan of 1 million exposed AI services reveals critical vulnerabilities in self-hosted LLM infrastructure and misconfigured model deployments.
Trellix Source Code Breach: Understanding Potential Supply Chain Risks
A deep dive into the Trellix source code repository breach, analyzing potential supply chain implications, intellectual property risks, and recommended mitigations for…
DigiCert Revokes Certificates After Support Portal Compromise
DigiCert is revoking TLS/SSL certificates following a breach where attackers used support chat to compromise an internal analyst's workstation and portal.
Trellix Source Code Repository Breach Analysis and Impact
Trellix confirms a data breach following unauthorized access to source code repositories via a third-party service. Learn the impact and mitigation steps.
AI-Assisted Attacks: Lessons from the Kaikatsu Club Data Breach
Analyze the 2025 Kaikatsu Club breach where AI-assisted malicious code allowed a teenager to steal 7 million user records, signaling a new era of cyber threats.
Instructure Data Breach: Student IDs and Private Messages Exposed
Edtech leader Instructure discloses a data breach involving student IDs and user messages after hackers disrupted services and threatened data leaks.
Instructure Data Breach: ShinyHunters Claims Theft of Employee Data
Educational technology giant Instructure confirms an internal data breach after the ShinyHunters threat group claims to have stolen sensitive corporate data.
CVE-2026-41940: Critical cPanel Vulnerability Exploited by Sorry Ransomware
Attackers are mass-exploiting CVE-2026-41940 in cPanel to deploy Sorry ransomware. Learn how to detect CVE-2026-41940 exploit and protect your web servers.
Trellix Source Code Breach: Assessing Risk to Security Products
Trellix confirms unauthorized access to a portion of its source code repositories, raising concerns regarding potential downstream supply chain risks.
French ANTS Agency Data Breach: Teen Suspect Detained
French authorities detain a 15-year-old suspected of orchestrating a data breach at ANTS, the national agency for administrative documents, impacting citizen data…
Ransomware Negotiator Double Agent Tactics: Managing IR Risks
Analysis of the legal case involving a ransomware negotiator acting as a double agent and how to secure the incident response supply chain against fraud.
20 Years of Threat Intel: Analyzing Adversarial Evolution Since 2006
Historical analysis of cybersecurity threat evolution over two decades, focusing on the transition from simple exploits to complex APT campaigns.
BlackCat Ransomware: Cybersecurity Pros Sentenced for 2023 Attacks
Two cybersecurity professionals receive four-year prison sentences for their roles in facilitating BlackCat (ALPHV) ransomware attacks against U.S. victims.
BlackCat Ransomware: IR Professionals Sentenced for Insider Attacks
Two cybersecurity incident response professionals were sentenced to four years in prison for conspiring with the BlackCat (ALPHV) ransomware gang.