What's happening in security
Breaches, credential dumps, actively exploited bugs and AI incidents — pulled from 2,926 items across public feeds, Have I Been Pwned and CISA KEV.
Biggest this week
- Unauthenticated attackers are bypassing Cisco ISE’s management interface (CVE-2026-76460) — Help Net Security, 4h ago
- Google fixes actively exploited Android zero-day on Pixel devices — BleepingComputer, 1d ago
- Cisco warns customers of actively exploited zero-day in email gateways — CyberScoop, 1d ago
- Cisco patches actively exploited email gateway zero-day (CVE-2026-76461) — Help Net Security, 2d ago
- Active Exploitation Triggers Emergency Patch for Cisco ISE Zero-Day — SecurityWeek, 8h ago
-
Valve notifies Steam hardware customers of a data breach
Video game publisher and digital distribution giant Valve is notifying Steam hardware customers in Europe that hackers stole their data after hacking its shipping partner, CEVA Logistics. [...]
-
Alcon: 218,395 accounts breached
Data exposed: Email addresses, Names, Phone numbers, Physical addresses. In August 2026, the Alcon eye care company was named in a ShinyHunters "pay or leak" extortion campaign . The group subsequently published data allegedly sou…
-
Brinks Home: 732,162 accounts breached
Data exposed: Dates of birth, Email addresses, Names, Partial credit card data, Phone numbers, Physical addresses, Purchases. In July 2026, Brinks Home was targeted in a ShinyHunters "pay or leak" extortion campaign . The group su…
-
Unlimited Technology Systems breach impacts 3.8 million people
Healthcare software company Unlimited Technology Systems reported that more than 3.8 million people were impacted by a data breach incident that occurred in October 2025. [...]
-
In Other News: AI Slop Limits Apple Bounties, North Carolina Port Attacks, Hackers Target Wall Street
Noteworthy stories that might have slipped under the radar: ban on Chinese data center tech, QuickFox VPN supply chain attack, IEH Corporation mailbox breached via phishing. The post In Other News: AI Slop Limits Apple Bounties, N…
-
3.8 Million Impacted by Unlimited Technology Systems Data Breach
Hackers stole personal, medical, and health insurance information from a company’s data center. The post 3.8 Million Impacted by Unlimited Technology Systems Data Breach appeared first on SecurityWeek .
-
Exact Sciences: 10,869,543 accounts breached
Data exposed: Dates of birth, Email addresses, Genders, Names, Personal health data, Phone numbers, Physical addresses. In July 2026, Exact Sciences (now owned by Abbott Laboratories) was the target of a ShinyHunters "pay or leak"…
-
Meta AI model hacked a company during misconfigured cyber test
Meta has become the latest AI company to confirm that one of its models hacked a real organization during cybersecurity testing, as similar incidents continue to emerge following OpenAI'sOpenAI's initial disclosure that its agents…
-
Snowflake Hacker Pleads Guilty Over Breaches Affecting at Least 100 Million People
Connor Riley Moucka pleaded guilty in Seattle federal court on Wednesday to computer fraud, wire fraud, aggravated identity theft and a related conspiracy over the 2024 breaches of Snowflake customer accounts. The intrusions reach…
-
Inter-Con Security: 276,114 accounts breached
Data exposed: Email addresses, Employers, Job titles, Names, Phone numbers, Physical addresses. In June 2026, Inter-Con Security was targeted in a ShinyHunters “pay or leak” extortion campaign . The group subsequently published da…
-
A Security Pro Hacked North Korean Hackers. He Found They’d Breached Hundreds of Networks Worldwide
For nearly two years, researcher Vangelis Stykas has maintained access to North Korean hackers’ servers. His work shows they pulled off intrusions in a shocking number of systems across the globe.
-
Kali365 Weaponizes Microsoft Authentication Against US Companies: New Enterprise Risk
Kali365 is turning a legitimate Microsoft login into a gateway to corporate data. The phishing kit targets US organizations with attacker-controlled device codes that victims approve on Microsoft's real authentication page. Once a…
-
Angola's Largest Telco Breached Hours Before IPO
Unitel, Angola's dominant mobile operator, continues to recover from a cyberattack that caused outages the day of the government-owned telco's public offering.
-
Iran Cyberattacks Against Minnesota Water Systems
Attribution is preliminary , and so far it seems no real damage. And it seems like this is a campaign that has targeted at least seven states . And, because this is where the US is right now, Trump doesn t believe it s Iran and th…
-
SplitVPN: 865,336 accounts breached
Data exposed: Device information, Email addresses, Geographic locations, IP addresses, Partial credit card data. In July 2026, the Russian VPN service SplitVPN (previously known as NotVPN) suffered a data breach . The incident exp…
-
Adform compromised to serve crypto stealer via supply chain attack
Adform are an advertising company used by around 14k companies, owning around a 30% share of the demand-side category. They operate by offering a Javascript embed for websites, via this URL: hxxps://s2.adform.net/banners/scripts/s…
-
We now have a better understanding how OpenAI hacked into Hugging Face
10 days passed from OpenAI models exploiting JFrog Artifactory 0-day to release of a patch.
-
Houston City College: 831,642 accounts breached
Data exposed: Academic records, Citizenship statuses, Dates of birth, Email addresses, Genders, Names, Phone numbers, Physical addresses. In June 2026, Houston City College was the target of a ShinyHunters "pay or leak" extortion …
-
27th July – Threat Intelligence Report
For the latest discoveries in cyber research for the week of 27th July, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES Nichirei, a Japan-based frozen-food supplier and logistics company, has experienced…
-
Smashing Security podcast #477: How 14 orders of chicken McNuggets helped nail a suspected Russian hacker
A Russian intelligence-linked hacker is arrested in Thailand while enjoying a beach holiday - and the trail of evidence that nailed him to the Russian government includes 14 separate orders of chicken McNuggets. Meanwhile, AI musi…
-
Suno: 55,282,226 accounts breached
Data exposed: Email addresses, Names, Partial credit card data, Phone numbers, Physical addresses, Purchases. In November 2025, AI music generation tool Suno suffered a data breach that later came to light in July the following ye…
-
20th July – Threat Intelligence Report
For the latest discoveries in cyber research for the week of 20th July, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES Ernst Young, a global accounting and professional services company, has disclosed a…
-
Paidwork: 23,272,765 accounts breached
Data exposed: Bank account numbers, Dates of birth, Device information, Education levels, Email addresses, Financial transactions, Genders, IP addresses, Names, Passwords, Personal interests, Phone numbers, Physical addresses, Pro…
-
North Korea Is Hiring
The recruiter was real, the company was real, and the code they asked him to run was a hacked poker game that helps fund a nuclear program.
-
Fluke: 821,100 accounts breached
Data exposed: Email addresses, Employers, Job titles, Names, Physical addresses, Support tickets. In July 2026, electronic test and measurement equipment company Fluke was targeted in a ShinyHunters "pay or leak" extortion campaig…
-
Goose Creek: 6,574,121 accounts breached
Data exposed: Email addresses, Names, Phone numbers, Physical addresses, Purchases. In June 2026, a party claiming to have access to data from Goose Creek Candle Company sent emails to a number of the company's customers , claimin…
-
Lessons Learned from CISA’s Recent GitHub Leak
The Cybersecurity and Infrastructure Security Agency (CISA) has issued a postmortem on a data leak in which a contractor published dozens of internal CISA credentials -- including AWS Govcloud keys -- in a public GitHub repository…
-
13th July – Threat Intelligence Report
For the latest discoveries in cyber research for the week of 13th July, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES U.S. auto insurer AssuranceAmerica has disclosed a data breach affecting approximat…
-
Glendale Community College: 793,925 accounts breached
Data exposed: Academic records, Dates of birth, Email addresses, Genders, Government issued IDs, Names, Phone numbers, Physical addresses. In June 2026, Glendale Community College was the target of a ShinyHunters "pay or leak" ext…
-
Moody Bible Institute: 2,303,416 accounts breached
Data exposed: Dates of birth, Email addresses, Genders, Marital statuses, Names, Phone numbers, Physical addresses. In June 2026, Moody Bible Institute was targeted by a ShinyHunters "pay or leak" extortion campaign . Over 2.3M un…
-
22nd June – Threat Intelligence Report
For the latest discoveries in cyber research for the week of 22nd June, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES Texas Parks and Wildlife Department has been affected by a third-party data breach …
-
Sysco: 2,691,852 accounts breached
Data exposed: Customer feedback, Email addresses, Employers, Job titles, Names, Phone numbers, Physical addresses, Usernames. In June 2026, the food distribution company Sysco was targeted by a ShinyHunters "pay or leak" extortion…
-
American Tower: 216,601 accounts breached
Data exposed: Email addresses, Job titles, Names, Phone numbers, Physical addresses. In June 2026, telecommunications tower infrastructure company American Tower was the target of a ShinyHunters "pay or leak" extortion campaign . …
-
What’s the Average Cost of a Data Breach in 2025? | Huntress
Learn what the average cost of a data breach is and how factors like industry and location impact it. Plus, learn how to protect yourself from costly breaches.
-
Madison Square Garden Sports: 9,796,738 accounts breached
Data exposed: Customer service records, Email addresses, Names, Phone numbers, Physical addresses. In June 2026, the sports and entertainment company Madison Square Garden Sports was the target of a ShinyHunters "pay or leak" exto…
-
JCPenney: 368,418 accounts breached
Data exposed: Dates of birth, Email addresses, Government issued IDs, Job titles, Names, Phone numbers, Physical addresses, Usernames. In June 2026, retailer JCPenney and associated brands were targeted in a ShinyHunters "pay or l…
-
Ralph Lauren: 139,903 accounts breached
Data exposed: Age groups, Email addresses, Genders, Names, Phone numbers. In June 2026, fashion retailer Ralph Lauren was targeted in a ShinyHunters "pay or leak" extortion campaign . The group subsequently published hundreds of g…
-
Operation Endgame 4.0: 4,348,526 accounts breached
Data exposed: Email addresses, Passwords. On 18 June 2026, the latest phase of Operation Endgame targeted the SocGholish malware operation , a prolific malware distribution network used to compromise systems and facilitate further…
-
CFGI: 248,235 accounts breached
Data exposed: Email addresses, Employers, Job titles, Names, Phone numbers, Physical addresses. In March 2026, the financial consulting and advisory firm CFGI was the target of a ShinyHunters "pay-or-leak" extortion campaign . The…
-
The Devil, Eight Million Emails, and a Whole Lot of Milk | Phishing Stager Exposed
A compromised terminal server became a phishing stager. A fake Boots survey aimed at 8.9 million inboxes, with the payload on a hacked Bolivian government site.
-
15th June – Threat Intelligence Report
For the latest discoveries in cyber research for the week of 15th June, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES The University of Nottingham, a UK research university, has suffered a data breach …
-
Berkadia: 305,216 accounts breached
Data exposed: Email addresses, Employers, Names, Phone numbers, Physical addresses. In March 2026, the commercial real estate finance company Berkadia was the target of a ShinyHunters "pay or leak" extortion campaign . The group s…
-
Infinite Campus: 137,123 accounts breached
Data exposed: Email addresses, Employers, Job titles, Names, Phone numbers, Physical addresses, Support tickets, Usernames. In March 2026, the student information system Infinite Campus was targeted in a ShinyHunters "pay or leak"…
-
University of Nottingham: 454,635 accounts breached
Data exposed: Academic records, Citizenship statuses, Dates of birth, Disabilities, Email addresses, Ethnicities, Genders, IP addresses, Names, Passport numbers, Phone numbers, Physical addresses, Purchases, Salutations, Usernames…
-
Baker Distributing: 102,935 accounts breached
Data exposed: Email addresses, Names, Phone numbers, Physical addresses, Support tickets. In May 2026, the HVAC/R wholesale distributor Baker Distributing Company was added to the ShinyHunters data extortion group's "pay or leak" …
-
BCD Travel: 396,313 accounts breached
Data exposed: Email addresses, Employers, Job titles, Names, Phone numbers, Physical addresses, Support tickets. In May 2026, the corporate travel management company BCD Travel was claimed as a victim of the ShinyHunters "pay or l…
-
DentaQuest: 2,553,599 accounts breached
Data exposed: Dates of birth, Email addresses, Genders, Government issued IDs, Health insurance information, Names, Phone numbers, Physical addresses. In May 2026, the dental benefits administrator DentaQuest was the target of a S…
-
1,000 Data Breaches Later, the Disclosure Lag is Worse Than Ever
Today, I loaded the 1,000th data breach into Have I Been Pwned . Reflecting on that milestone number, I pondered how to mark the occasion in writing, and what immediately came to mind was a very simple question: why is it still ne…
-
Edmunds: 177,860 accounts breached
Data exposed: Device information, Email addresses, IP addresses, Passwords, Phone numbers, Usernames. In January 2026, the automotive research and car-shopping platform Edmunds was listed by the ShinyHunters hacking group as havin…
-
Atlas Menu: 63,926 accounts breached
Data exposed: Email addresses, IP addresses, Passwords, Support tickets, Usernames. In May 2026, the GTA V and CS2 cheat service Atlas Menu suffered a data breach. An attacker claimed to have gained access to all Atlas systems and…
Last fetch 12m ago · 1 new · 2 source error(s)