Coverage
Data Breaches
470 articles on breaches and ransomware
Advertisement
AI Overwhelms Patching: Rapid7 Warns of Exposure Crisis
Rapid7 analysis reveals an AI-driven surge in vulnerabilities is overwhelming traditional patching, requiring a shift to exposure management.
LLM Persistent Memory and Contextual Integrity Risks
Analysis of new research on LLM contextual integrity, persistent memory risks, and how frontier models leak sensitive user data over time.
Ransom Busters Ransomware Affiliate Poses as Recovery Firm
A ransomware affiliate masquerades as an incident recovery service to intercept victims, divert negotiations, and manipulate ransom payments.
Microsoft Removes WMIC Tool in Windows 11 to Curb Living-off-the-Land Tactics
Microsoft removes the legacy WMIC tool from Windows 11 builds to disrupt living-off-the-land techniques used by ransomware and malware.
Threat Actor Claims 3.6 Million Azure Account Records Stolen
A threat actor named TheHatman is selling 3.6 million employee records allegedly stolen from major corporate Azure tenants using compromised credentials.
DGFiP Data Breach Exposes 680,000 Individuals' Tax Data
France's DGFiP disclosed a data breach exposing tax income, withholding rates, and cadastral data for 680,000 individuals via compromised credentials.
SafePal Data Breach Exposes 39,798 Customer Order Details
SafePal confirms a data breach impacting 39,798 customers, exposing names, emails, and shipping info. Stolen data is for sale, increasing phishing risks.
Clop Ransomware Exploits CVE-2026-12569 in PTC Products
Shell investigates potential data theft by Clop gang after exploitation of critical CVE-2026-12569 in PTC Windchill and FlexPLM instances.
Beacon CRM Data Breach Exposes Over 1,000 Charity Databases
Beacon CRM data breach exposed personal details of supporters across 1,000+ charities due to a compromised AWS access key.
Scottish Government Data Breach at Prosecutor's Office via Third Party
The Scottish Crown Office and Procurator Fiscal Service (COPFS) suffered a data breach linked to a third-party supplier, risking sensitive personal data.
RingCentral Data Breach Exposes 1.6M Users to ShinyHunters
RingCentral data breach impacts 1.6 million users after a sophisticated social engineering attack by ShinyHunters. Names, emails, addresses, and phone numbers exposed.
Hackers Arrested Over €30M Bank Fraud via Service Provider Flaw
Brazilian and German authorities arrested cybercriminals for €30M bank fraud exploiting a service provider flaw, impacting Commerzbank customers.
ShinyHunters Breaches ShipMonk: 14,000 Trezor Customers' Data Exposed
ShinyHunters group breached shipping provider ShipMonk, exposing personal data of 14,000 Trezor customers via a Metabase SQL injection vulnerability.
Data Analyst Sentenced to Prison for Extorting Brightly Software
A former data analyst contractor was sentenced to two years in prison for orchestrating a $2.5 million cryptocurrency extortion scheme against Brightly.
Picus Blue Report 2026: Enterprise Edge Defenses vs Post-Compromise
Analysis of the Picus Labs Blue Report 2026 reveals strong enterprise perimeter defenses, but severe blind spots for internal reconnaissance and credential theft.
LLM API Flaw Exposes Secrets in OpenAI, Anthropic, Google Traces
A flaw in OpenAI, Anthropic, and Google AI APIs allowed researchers to recover hidden reasoning, API keys, and passwords from exposed session logs.
City-Forum Data Theft Targets Salesforce and ServiceNow Portals
City-Forum data theft attacks target misconfigured Salesforce and ServiceNow portals, exploiting overly permissive guest access rules.
Ransomware Attack Hits Colombian Justice Ministry
A ransomware attack targets the Colombian Justice Ministry days before a presidential transition, highlighting regional risks.
Gunra Ransomware Exploits Fortinet Flaws and Bypasses MFA
Gunra ransomware targets critical infrastructure using leaked Conti code, old Fortinet vulnerabilities, and MFA bypass techniques.
Deadlock Ransomware Uses Blockchain for C2 Resilience
Deadlock ransomware uses Polygon blockchain smart contracts and Session to resist infrastructure takedown and evade law enforcement.
Geopolitical AI Supply Chain Threats and Cyber Espionage
Examine how state-sponsored threat groups and criminal syndicates target the global AI supply chain, from rare earth minerals to silicon chips.
Wesco Confirms Cloud CRM Incident After ExfilSquad Data Leak
Wesco confirms a cloud CRM security incident as ExfilSquad claims theft of 2.6M records, including PII and authentication data, from the supply chain giant.
Hackers Breach Polish CHP Plant via Private APN and Teltonika Router
Attackers breached a Polish combined heat and power plant via a private APN, shutting down a steam turbine and water treatment system.
SonicWall SMA1000 Exploited: Ransomware Targets CVE-2026-15409/15410
CISA confirms ransomware exploitation of SonicWall SMA1000 flaws CVE-2026-15409 and CVE-2026-15410, urging immediate patching.