2026-09-15 11:45 UTC
Security Journalism
Security Week · Ionut Arghire · indexed 2026-09-15 11:50 UTC
Hackers exploited a vulnerability in a VPN product to steal the personal information of roughly 240,000 people. The post 240,000 Hit by Data Breach at Japan’s Digital Agency appeared first on SecurityWeek.
P0
2026-09-15 07:48 UTC
Other
Security Affairs · Pierluigi Paganini · indexed 2026-09-15 09:00 UTC
A Telegram Desktop flaw let bots inject JavaScript into exported chats, enabling data theft and page manipulation. Old HTML exports remain unsafe. A vulnerability in Telegram Desktop could have turned an ordinary chat export into a serious data leak. Security researchers Denis and Aleksander Rostilov of ExPatch found a stored cross-site scripting flaw in the […]
P0
2026-09-14 20:36 UTC
Security Journalism
BleepingComputer · Bill Toulas · indexed 2026-09-14 20:40 UTC
Japan's Digital Agency has discovered a data breach that may have exposed around 246,000 record rows containing personal information of government employees. [...]
P0
2026-09-14 16:15 UTC
Security Journalism
The Record · indexed 2026-09-14 16:15 UTC
The pro-Ukraine hacktivist group Hacking Cat has evolved from carrying out website defacements and data leaks to more sophisticated and destructive attacks on Russian targets, researchers said.
P0
2026-09-14 13:03 UTC
Security Journalism
Security Week · Ionut Arghire · indexed 2026-09-14 13:10 UTC
The company unintentionally disclosed users’ information to a third party impersonating a government agency. The post Personal, Financial Info Exposed in Revolut Data Breach appeared first on SecurityWeek.
P0
2026-09-14 12:22 UTC
Other
Check Point Research · urias@checkpoint.com · indexed 2026-09-14 12:30 UTC
For the latest discoveries in cyber research for the week of 14th Setpember, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES IDScan.net, a US identity verification provider, has disclosed a data breach after detecting unauthorized access on September 1. Exposed data included names and government identification numbers, while a criminal marketplace advertised a […] The post 14th September – Threat Intelligence Report appeared first on Check Point Research.
P0
2026-09-14 08:48 UTC
Security Journalism
BleepingComputer · Sergiu Gatlan · indexed 2026-09-14 08:55 UTC
Fintech company Revolut has disclosed a data breach after sharing data from an undisclosed number of customers with a threat actor impersonating a government agency. [...]
P0
2026-09-11 20:00 UTC
Security Journalism
The Record · indexed 2026-09-11 20:20 UTC
The Florida Department of Motor Vehicles confirmed a data breach claimed by the cybercrime group ShinyHunters, saying it originated with the theft of credentials stored on a police officer's personal device.
P0
2026-09-11 19:00 UTC
Security Journalism
BleepingComputer · Lawrence Abrams · indexed 2026-09-11 19:05 UTC
The Florida Department of Highway Safety and Motor Vehicles (FLHSMV) has confirmed that its DAVID driver database suffered a data breach, saying the attackers gained access using credentials belonging to a police department employee. [...]
P0
2026-09-10 18:55 UTC
Security Journalism
The Record · indexed 2026-09-10 19:00 UTC
A notice dated September 4 but not widely shared shows that IDScan acknowledged a data breach but did not specify how many people were affected.
P0
2026-09-10 11:20 UTC
Security Journalism
Security Week · Ionut Arghire · indexed 2026-09-10 11:35 UTC
In June 2026, hackers stole personal, health, and insurance information from AdaptHealth’s systems. The post 4.1 Million Impacted by AdaptHealth Data Breach appeared first on SecurityWeek.
P0
2026-09-09 15:31 UTC
Security Journalism
BleepingComputer · Bill Toulas · indexed 2026-09-09 15:35 UTC
Healthcare technology company Veradigm disclosed a data breach after a cybersecurity incident at one of its third-party vendors exposed patients' personal data. [...]
P15
2026-09-09 13:00 UTC
Vendor Research
Tenable Blog · Mark Beblow · indexed 2026-09-09 13:10 UTC
Open-source registries for AI agents are only effective when they include a rigorous, transparent security review process for community submissions. That’s why for its new CyberAgents Exchange registry, Tenable paired its exposure management expertise with OpenAI GPT Cyber models to create the CyberAgents Exchange AI Inspector.Key takeawaysThe Exchange Inspector combines Tenable’s exposure detection with OpenAI’s GPT Cyber models and with human oversight to rigorously vet submissions made to th…
P0
2026-09-08 14:00 UTC
Vendor Research
Google Threat Intelligence / Mandiant · Google Threat Intelligence Group · indexed 2026-09-08 13:45 UTC
Executive Summary Since the release of our May 2026 report detailing adversarial misuse of artificial intelligence (AI), Google Threat Intelligence Group (GTIG) has observed forward leaning adversaries transition from basic prompting to agentic AI workflows and AI-enabled automation. In these operations, human-in-the-loop latency is dramatically reduced, compressing the traditional window for defenders to respond. In Q2 2026, GTIG observed threat actors compromise a cloud resource, then plan, b…
P35
2026-09-08 13:00 UTC
Other
Check Point Research · stcpresearch · indexed 2026-09-08 13:10 UTC
Research by: Alexey Bukhteyev Key Takeaways Introduction Over the past several years, AI assistants have moved far beyond text generation. Modern systems can execute code, install additional dependencies, analyze user files, and access data through connected services. These capabilities significantly increase the practical value of LLMs, but they also change the security model: protecting user […] The post The Shared Clipboard Inside the Sandbox: Cross-Account Data Leakage in ChatGPT appeared f…
P0
2026-09-08 10:47 UTC
Security Journalism
Security Week · Ionut Arghire · indexed 2026-09-08 10:50 UTC
Hackers stole the information of students, teachers, staff, and parents/guardians from a self-hosted Metabase instance. The post Mathspace Data Breach Exposes Over 1 Million People appeared first on SecurityWeek.
P0
2026-09-07 13:05 UTC
Security Journalism
BleepingComputer · Sergiu Gatlan · indexed 2026-09-07 13:15 UTC
Online maths learning platform Mathspace disclosed over the weekend that attackers stole data from more than 1 million students, staff, and parents after breaching its Metabase internal reporting system. [...]
P0
2026-09-07 12:16 UTC
Security Journalism
BleepingComputer · Sergiu Gatlan · indexed 2026-09-07 12:35 UTC
Cryptocurrency hardware wallet maker Trezor says an August data breach at its shipping and logistics provider, ShipMonk, affects an additional 67,000 U.S. customers. [...]
P0
2026-09-07 11:50 UTC
Security Journalism
The Record · indexed 2026-09-07 12:05 UTC
Another trove of data from Berlin's government has appeared online, authorities said. Germany's information security agency separately warned about the Rhysida cybercrime group.
P0
2026-09-04 18:30 UTC
Other
Security Affairs · Pierluigi Paganini · indexed 2026-09-04 18:55 UTC
Manchester Airports Group (MAG) data allegedly leaked by FulcrumSec exposes emails and phone numbers of 8.8 million people. Manchester Airports Group, which operates Manchester, London Stansted and East Midlands airports, has confirmed a data breach involving customer information held in a third-party database. The company says airport operations, passenger safety and aviation security were not […]
P0
2026-09-04 16:56 UTC
Security Journalism
BleepingComputer · Bill Toulas · indexed 2026-09-04 17:00 UTC
Multiple lawsuits have been filed against identity verification company IDScan after hackers allegedly breached the service and offered to sell more than 153 million driver's licenses. [...]
P0
2026-09-01 19:28 UTC
Security Journalism
BleepingComputer · Bill Toulas · indexed 2026-09-01 19:30 UTC
Aesto LLC, operating as Aesto Health, disclosed that a data breach discovered recently affects more than 9.5 million individuals. [...]
P0
2026-09-01 15:12 UTC
Other
Security Affairs · Pierluigi Paganini · indexed 2026-09-01 15:40 UTC
Aesto Health suffered a breach exposing personal and health data of more than 9.5 million people after attackers accessed its AWS infrastructure. Aesto Health, a U.S. healthcare technology company, disclosed a data breach that exposed personal and health information belonging to more than 9.5 million people. The company discovered the incident on December 18, 2025, […]
P0
2026-09-01 14:28 UTC
Security Journalism
BleepingComputer · Sergiu Gatlan · indexed 2026-09-01 14:30 UTC
Healthtech company Novocure says the data of an undisclosed number of employees and more than 1,400 U.S. cancer patients has been exposed in a mid-August cyberattack. [...]
P0
2026-08-31 13:30 UTC
Security Journalism
BleepingComputer · Bill Toulas · indexed 2026-08-31 13:40 UTC
Berlin's city administration has confirmed that cybercriminals are attempting to extort the city after the Rhysida ransomware gang listed it on their data leak site. [...]
P15
2026-08-30 17:21 UTC
Other
Security Affairs · Pierluigi Paganini · indexed 2026-08-30 17:45 UTC
Extortion group FulcrumSec claims they stole 86GB of Manchester Airports Group data after finding API credentials exposed in client-side JavaScript. Manchester Airports Group (MAG) disclosed a data breach on August 27 affecting customers of Manchester, London Stansted, and East Midlands airports. Two days later, BleepingComputer reports the extortion group FulcrumSec claimed responsibility, saying it stole […]
P0
2026-08-28 20:14 UTC
Other
Security Affairs · Pierluigi Paganini · indexed 2026-08-28 21:15 UTC
Love Electric’s alleged data breach exposes sensitive driver data and highlights the identity risks created by third-party salary sacrifice providers. A seller on an English-language data-breach forum claimed on August 26 that they had obtained the driver database of Love Electric, a UK broker that runs electric-vehicle salary sacrifice schemes. The seller, operating under the […]
P0
2026-08-28 11:46 UTC
Security Journalism
BleepingComputer · Sergiu Gatlan · indexed 2026-08-28 12:00 UTC
Hasbro, one of the world's largest toy and game companies, has disclosed that attackers have accessed the personal and financial information of an undisclosed number of employees. [...]
P0
2026-08-27 13:51 UTC
Vendor Research
Rapid7 · Alexandra Blia · indexed 2026-08-27 14:25 UTC
IntroductionDespite modern verification controls, identity theft remains one of the most pervasive threats to both individuals and enterprise organizations. U.S. Federal Trade Commission statistics show over 1 million identity theft reports annually, with related fraud and imposter scams accounting for billions in financial losses each year. While stolen credit cards enable rapid, short-term monetization, Social Security numbers (SSNs) represent a far more permanent and dangerous tier within th…
P0
2026-08-27 11:10 UTC
Security Journalism
BleepingComputer · Sergiu Gatlan · indexed 2026-08-27 11:15 UTC
The ShinyHunters extortion group has published sensitive data from nearly 13 million accounts stolen from clothing retailer giant Carhartt earlier this month, according to data breach notification service Have I Been Pwned. [...]
P0