2026-10-02 19:01 UTC
Security Journalism
BleepingComputer · Lawrence Abrams · indexed 2026-10-02 19:15 UTC
Frontline Education is notifying school districts of a data breach after attackers exploited a vulnerability in third-party software to gain unauthorized access to its systems and steal employee information, including Social Security numbers. [...]
P0
2026-10-01 14:25 UTC
Security Journalism
BleepingComputer · Lawrence Abrams · indexed 2026-10-01 14:30 UTC
An international law enforcement operation dubbed "Operation KillSwitch" seized the KillSec ransomware gang's data leak site and servers, led to three arrests, and identified a 16-year-old as the group's alleged administrator. [...]
P15
2026-10-01 12:30 UTC
Security Journalism
The Record · indexed 2026-10-01 12:45 UTC
One of Poland’s major online invoicing platforms suffered a data breach that may have exposed information belonging to its users, their customers and business partners.
P0
2026-09-30 14:16 UTC
Vendor Research
Rapid7 · Rapid7 · indexed 2026-09-30 15:05 UTC
Higher education faces a difficult security equation. Universities hold large volumes of sensitive student, financial, health, and research data while supporting open networks, distributed users, legacy infrastructure, and increasingly complex cloud environments. Attackers have taken notice, and the pressure on security teams continues to grow.In Q2 2025, universities faced an average of 4,388 cyberattacks per organization per week, up 24% from the same period in 2024. Nine in ten universities …
P40
2026-09-29 17:00 UTC
Security Journalism
Security Week · Eduard Kovacs · indexed 2026-09-29 17:15 UTC
Branch Target Reuse (BTR) is a new Spectre v2 attack targeting JIT compilers in web browsers, language runtimes, and the operating system kernel The post New Spectre v2 Variant Exposes Intel, AMD, Arm CPUs to Data Leaks appeared first on SecurityWeek.
P0
2026-09-29 14:09 UTC
Other
Security Affairs · Pierluigi Paganini · indexed 2026-09-29 15:00 UTC
Pentagon personnel agency breach exposed data of 3 million people after attackers accessed a file-sharing server for about nine months. The U.S. Defense Manpower Data Center (DMDC), which maintains personnel records for the Department of Defense, is notifying people that their personal information was exposed in a data breach. According to the agency, unauthorized users […]
P0
2026-09-29 12:27 UTC
Security Journalism
The Record · indexed 2026-09-29 12:45 UTC
A spokesperson for the court system told Recorded Future News that the incident did not involve ransomware and the hackers have not issued ransom demands for the stolen data as of Monday.
P15
2026-09-29 12:25 UTC
Security Journalism
Security Week · Eduard Kovacs · indexed 2026-09-29 12:40 UTC
The data breach affects the Defense Manpower Data Center (DMDC), which maintains personnel records for the Department of Defense. The post Pentagon Personnel Agency Data Breach Impacts 3 Million People appeared first on SecurityWeek.
P0
2026-09-28 20:31 UTC
Security Journalism
BleepingComputer · Bill Toulas · indexed 2026-09-28 20:40 UTC
Japanese car-sharing service Times Car has confirmed that approximately 6.6 million user accounts were compromised in a cyberattack disclosed late last week. [...]
P0
2026-09-27 09:27 UTC
Other
Security Affairs · Pierluigi Paganini · indexed 2026-09-27 09:40 UTC
Kosovo national Ardit Kutleshi pleaded guilty to running Rydox, a cybercrime marketplace that sold stolen identities and credentials for years. Ardit Kutleshi, 28 years old and a citizen of Kosovo, pleaded guilty last week to building and running the cybercrime marketplace Rydox. The Rydox marketplace has been active since February 2016; it facilitated over 7,600 […]
P0
2026-09-25 20:57 UTC
Security Journalism
BleepingComputer · Lawrence Abrams · indexed 2026-09-25 21:00 UTC
The Clop ransomware gang has moved its data leak site to a new Tor address after confirming its previous server was compromised and defaced through an unpatched Grav CMS flaw that BleepingComputer has learned is an unauthenticated path traversal vulnerability. [...]
P15
2026-09-24 13:15 UTC
Security Journalism
The Record · indexed 2026-09-24 13:35 UTC
The healthcare firm Astrana warned regulators that hackers accessed confidential information by impersonating company personnel.
P0
2026-09-24 09:56 UTC
Security Journalism
Security Week · Ionut Arghire · indexed 2026-09-24 10:05 UTC
Hackers impersonated the company’s personnel and contacted its employees to gain access to Astrana Health’s servers. The post Astrana Health Data Breach Impacts Private, Confidential Information appeared first on SecurityWeek.
P0
2026-09-23 05:30 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-23 06:40 UTC
The cyber extortion group known as ShinyHunters on Tuesday claimed it had breached the U.S. Federal Bureau of Investigation and stolen data belonging to current and former employees at the agency. "We have compromised the FBI. We hold very sensitive data on almost ALL FBI Agents and individuals who filed an application with the FBI for a job," the group said in a statement posted on their dark
P0
2026-09-21 23:13 UTC
Other
Check Point Research · urias@checkpoint.com · indexed 2026-09-21 23:20 UTC
For the latest discoveries in cyber research for the week of 21st September, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES Japan’s Digital Agency, which operates the Government Solution Service used by multiple ministries, has confirmed a data breach after attackers exploited a vulnerability in a VPN appliance. Approximately 246,000 records were exposed, […] The post 21st September – Threat Intelligence Report appeared first on Check Point Research.
P0
2026-09-21 21:18 UTC
Security Journalism
BleepingComputer · Bill Toulas · indexed 2026-09-21 21:20 UTC
Ecommerce platform BigCommerce has alerted multiple merchants to data breaches after attackers compromised credentials for third-party Ribon applications and used them to inject malicious scripts into online stores. [...]
P0
2026-09-21 15:00 UTC
Security Journalism
The Record · indexed 2026-09-21 15:30 UTC
Belgium’s national table tennis federation is investigating a cyberattack after a hacker claimed to have stolen data on tens of thousands of members.
P0
2026-09-21 10:55 UTC
Security Journalism
Security Week · Ionut Arghire · indexed 2026-09-21 11:00 UTC
The cybersecurity firm believes the data breach was the result of the May 2026 TanStack supply chain attack. The post CrowdSec Confirms Source Code Stolen in Supply Chain Attack appeared first on SecurityWeek.
P0
2026-09-19 13:48 UTC
Security Journalism
BleepingComputer · Lawrence Abrams · indexed 2026-09-19 14:00 UTC
The ShinyHunters extortion gang breached the Clop (aka Cl0p) ransomware operation's data leak site, defacing the Tor site and allegedly stealing server data and the private keys for its onion service. [...]
P15
2026-09-19 13:28 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-19 14:30 UTC
Identity visibility is a starting point for modern identity security, because stolen and misused credentials are among the most frequently reported initial access vectors in breach research, including Verizon's annual Data Breach Investigations Report. This article explains what identity visibility means in IAM, why cloud and multicloud environments complicate it, which capabilities matter in
P0
2026-09-18 17:10 UTC
Other
Security Affairs · Pierluigi Paganini · indexed 2026-09-18 17:20 UTC
A Gyazo breach exposed 23 million user records after attackers exploited a vulnerability in Helpfeel’s image upload server. Japanese software company Helpfeel is notifying Gyazo users about a data breach that compromised 23 million user records. Attackers gained unauthorized access by exploiting a vulnerability in the service’s image upload server. “We have confirmed that approximately […]
P0
2026-09-18 16:00 UTC
Security Journalism
BleepingComputer · Bill Toulas · indexed 2026-09-18 16:15 UTC
The Gyazo image-sharing platform has confirmed it suffered a data breach after hackers exploited a server vulnerability that allowed them to steal 23.6 million user records. [...]
P0
2026-09-18 11:38 UTC
Security Journalism
Security Week · Eduard Kovacs · indexed 2026-09-18 11:50 UTC
Gyazo maker Helpfeel said the attacker exploited a vulnerability in its image upload server to gain unauthorized access. The post 23 Million User Records Compromised in Gyazo Data Breach appeared first on SecurityWeek.
P0
2026-09-17 13:57 UTC
Security Journalism
Security Week · Ionut Arghire · indexed 2026-09-17 14:10 UTC
Revolut allegedly fed customer information to hackers impersonating an Italian government agency for five months. The post Revolut Data Breach: 5 Months, 680 High-Profile Accounts, $3M Ransom appeared first on SecurityWeek.
P0
2026-09-16 17:26 UTC
Security Journalism
BleepingComputer · Bill Toulas · indexed 2026-09-16 17:45 UTC
The Spanish Data Protection Agency (AEPD) was notified of an attack allegedly carried out with an AI agent powered by a known large language model (LLM). [...]
P0
2026-09-16 16:39 UTC
Security Journalism
Security Week · Kevin Townsend · indexed 2026-09-16 16:50 UTC
Spanish regulators say an AI agent chained together a successful login, vulnerability discovery, and access to personal data in a potential milestone for autonomous cyberattacks. The post First Agentic AI Data Breach Reported to Spanish Regulator appeared first on SecurityWeek.
P0
2026-09-16 13:09 UTC
Other
Security Affairs · Pierluigi Paganini · indexed 2026-09-16 14:15 UTC
A suspected compromise of an Italian government PEC account may have allowed threat actors to impersonate law enforcement and obtain sensitive data from hundreds of Revolut customers. The Revolut data exposure may be part of a much broader cyber incident involving compromised Italian government infrastructure. Revolut has confirmed that its systems were not breached. Instead, […]
P0
2026-09-16 10:47 UTC
Security Journalism
Security Week · Ionut Arghire · indexed 2026-09-16 11:00 UTC
In June 2026, hackers accessed files containing patients’ names, contact information, diagnosis details, and health insurance information. The post 280,000 Impacted by Premier Medical Group Data Breach appeared first on SecurityWeek.
P0
2026-09-16 08:19 UTC
Other
Security Affairs · Pierluigi Paganini · indexed 2026-09-16 08:40 UTC
CenterPoint Energy confirmed a customer data breach after a hacker claimed to leak 7.49M records, including personal and billing information. CenterPoint Energy admitted on Monday that an intruder stole personal information belonging to some of its customers. The Houston-based utility, which supplies electricity and gas to about 7 million accounts across Texas, Indiana, Minnesota and […]
P0
2026-09-15 14:22 UTC
Security Journalism
The Record · indexed 2026-09-15 14:40 UTC
Houston-based CenterPoint Energy notified federal regulators about an incident that exposed some customer data on the dark web.
P0