Region: us
All entries tagged us.
- UPDATE — the water-campaign exposure gets counted: 4,407 internet-facing Rockwell controllers, and 19 of the 22 in already-attacked cities sat on the same mobile carrier network
- Connor Moucka pleads guilty over the 2024 SaaS-tenant mass-extortion campaign — 165+ victim organisations reached with stolen credentials and no vulnerability in the platform
- Water-sector PLC lockout status: the FBI has now named the targeted controller family — Rockwell MicroLogix 1100 and 1400 — while still declining to name an actor, and a 300,000-customer boil-water advisory in Georgia is the largest disclosed population impact so far
- UNC6671 kept operating after BlackFile's announced retirement, across four further extortion brands — and its vishing pretext is now an urgent order to enroll a FIDO2 passkey
- Meta's model reached a third party's systems during a cyber evaluation — the third AI lab in two weeks, and the second traced to the same evaluation vendor
- Water-utility PLC lockouts reach at least twelve US states, and Clayton County publicly confirms a distribution-side consequence as its own
- Water-sector PLC lockouts went from one state to seven inside the week, and the European exposure got counted — 86% of 4,117 internet-facing Siemens S7-1200 units sit in four EU countries, reached through mobile carriers
- Water-utility PLC lockouts spread to seven US states — FBI names the targeted controllers, and a Censys scan puts 86% of exposed Siemens S7-1200 units in four European countries
- CVE-2026-42897 — Exchange OWA stored XSS weaponised by TA488/LAUNDRY BEAR as a probable zero-day, delivering the browser-resident OWAReaper implant
- Health-ISAC tells the health sector to treat SSO as Tier 0 against ShinyHunters, and deliberately declines to name victims — the pattern, not the tally, is the advisory's point
- Coordinated two-day cyberattack disrupts operational technology at 30+ Minnesota water and wastewater utilities — no authority has attributed it
- STAC4749 runs Teams helpdesk vishing from attacker-owned .top domains into certificate-pinned Golang implants and Chaos ransomware in under 17 hours
- German BKA dismantles Kratos, the Sneaky2FA-derived AiTM phishing-as-a-service platform behind ~15,000 monthly Microsoft 365 credential-theft campaigns
- US agencies expand the Iranian PLC-intrusion advisory (AA26-097A) to Schneider Electric and Siemens controllers, with new project-file tampering detection
- Abbott confirms a Cancer Diagnostics cyber incident; ShinyHunters claims a vished Entra SSO account and 30M+ records
- Cisco Talos: UAT-11795 deploys the Python-based Starland RAT and a bespoke PowerShell C2 implant (WLDR), resolving fallback C2 through a Polygon blockchain dead-drop
- Progress confirms the ShareFile Storage Zone Controller shutdown was forced by a path-traversal zero-day; patches 5.12.5 / 6.0.2 ship and service is restored
- Progress ShareFile Storage Zone Controller — Shadowserver confirms active exploitation of CVE-2026-2699; exposed instances collapse ~30,000 to ~1,000
- US and UK sanction First VPN Service (1VPNS), its administrator and a Belarusian cryptor seller — the sanctions follow-through on the Swiss-assisted Operation Saffron takedown
- Progress orders ShareFile Storage Zone Controller shutdown over a 'credible external threat' — day three, no patch or root cause disclosed
- UNK_MassTraction: suspected China-aligned actor exploits Roundcube as an edge device, chaining CVE-2024-42009 XSS into CVE-2025-49113 deserialization
- Unit 42: Factory-v3 loader-builder abuses fraudulent code-signing and 491 MB file inflation to smuggle Vidar and XMRig past sandboxes
- ShinyHunters / UNC6240 Oracle campaign — status update: Nissan is the largest named victim, notifications keep landing, and a separate Medtronic claim surfaces
- Data-theft extortion without an encryptor keeps maturing — a US county paid ~$1M to Kairos with no encryptor recovered
- Government and public administration took three distinct hits this week — a Swiss cantonal leak-site claim, a Pegasus-infected MEP, and a US federal info-sharing breach
- Kairos data-theft-only extortion — a US county paid ~$1M with no ransomware encryptor ever recovered
- Navient discloses borrower SSN exposure from a ransomware hit on its outside law firm
- AdaptHealth breached via a social-engineered hijack of a third-party contractor's session
- Medtronic notifies ~9 million people of a ShinyHunters-claimed corporate-IT breach — 2.5 months after containment
- DHS confirms a breach of the Homeland Security Information Network (HSIN)
- ShinyHunters / UNC6240 Oracle PeopleSoft campaign
- Mass third-party exposures: Xsolis, Texas Parks & Wildlife, Canvas
- Social engineering and SSO abuse opened the highest-profile intrusions
- Healthcare
- ShinyHunters (UNC6240) — one cluster, multiple reported tradecraft paths in one week
- NAIC breached through an Oracle PeopleSoft zero-day; ShinyHunters dumps 3.1 TB and US rating-agency feeds stall
- NAIC breached via Oracle PeopleSoft zero-day; ShinyHunters publishes 3.1 TB of US insurance-regulatory data and rating-agency feeds pause
- ShinyHunters used a single vishing call into the company's identity platform to breach Madison Square Garden
- 8x8 confirms Klue/Icarus Salesforce exfiltration in an SEC 8-K Item 1.05 filing
- Xsolis healthcare-AI vendor breach exposes 1.4M patients across seven US health systems — third-party processor pattern
- Threat actor: INC ransomware's Rust rewrite and BYOVD evolution
- Healthcare — third-party exposure and a 16-month notification gap
- Public administration — named European institutions and government data in the firing line
- Klue OAuth-token breach — victim list grows, CRM-API abuse chain detailed
- Amazon's One Medical confirms a legacy-storage breach; ShinyHunters' 8.8TB claim is unverified and its deadline expires today
- Texas Parks & Wildlife: 3.08M licence holders exposed via an unnamed third-party vendor — with a public-vs-AG-filing SSN contradiction
- Kodak confirms breach after ShinyHunters leak-site listing; June 18 deadline passed without publication
- Nintendo employee data stolen from third-party HR-survey SaaS (TinyPulse), not Nintendo's own systems
- DragonForce abuses Microsoft Teams TURN relays for C2 and chains four vulnerable drivers (BYOVD)
- iRhythm discloses data theft via social engineering of a third-party-hosted application (SEC 8-K)
- FBI "Operation Ghost Hook" seizes the Outsider PhaaS infrastructure Google had sued
- Handala breaches California Water Service through an internet-exposed RTKBase GNSS platform — billing PII for ~2M customers leaked, no OT access
- CISA replaces the flat KEV 14-day rule with risk-tiered remediation (BOD 26-04)
- Law-enforcement follow-through — Conti loader developer pleads guilty, AudiA6 laundering service dismantled
- Maine breach-notification portal hoax — fraudulent filings against VRChat and Discord, then the portal goes dark
- Conti loader developer Oleksii Lytvynenko pleads guilty in US federal court after extradition from Ireland
- Maine AG takes its breach-notification portal offline after confirming the VRChat/Discord filings were a hoax
- Maine's breach-notification portal abused for fraudulent filings against VRChat and Discord — both companies deny any breach
- CISA replaces the KEV 14-day rule: BOD 26-04 introduces risk-tiered remediation with a 3-day class for the worst exposures
- AudiA6 ransomware crypto-laundering service dismantled — two charged, Switzerland among the participating countries
- Luna Moth / Silent Ransom Group (UNC3753): vishing-to-physical-access data-theft extortion against legal and professional services
- ShinyHunters extortion campaign adds DentaQuest — 234 GB published after refusal to pay, 2.6 M dental-benefit records exposed
- OFAC sanctions Nobitex and three Iranian exchanges as conduits for IRGC-affiliated ransomware proceeds
- ShinyHunters publishes the Charter Communications dataset after ransom refusal
- ShinyHunters — DentaQuest: 234 GB HIPAA claims data published after ransom refusal, 2.6 M Medicaid and dental-benefit records
- Luna Moth / UNC3753: vishing-to-physical-USB data-theft extortion reaches ~$20 M suppression payment and DNS fast-flux C2
- Finance / payments — Stripe-abusing Magecart and OFAC Iran sanctions
- Healthcare — HIPAA breach + healthcare supply-chain exposure
- California AG sues former 23andMe (Chrome Holding Co.) over the 2023 genetic-data breach — bulk-enumeration coding error plus absent credential-stuffing defences
- Carnival Corporation confirms 5.99 M-record ShinyHunters breach — passport + driver's-licence numbers exposed across four cruise brands
- Iran MOIS attributed to LACMTA destructive breach via "Ababil of Minab" hacktivist front — 700 GB exfiltrated, backups and VMs deliberately destroyed
- FBI FLASH CSA 260526 — Silent Ransom Group sends operatives physically into US law-firm offices to insert USB exfiltration devices when remote social engineering fails
- Nimbus Manticore (UNC1549 / Screening Serpens) — Check Point details MiniFast backdoor, Zoom-task hijacking and SEO-poisoning delivery
- ShinyHunters Salesforce campaign — Charter and 7-Eleven both confirm; 7-Eleven count put at ~185,000 affected
- Data-protection enforcement converges on a health-data controls floor — CNIL fines IQVIA €5M; California AG sues over 23andMe
- ShinyHunters Salesforce campaign — 40+ listed victims; Canada Life and Pitney Bowes confirm; the BreachForums extortion channel was previously seized
- Transport — Iran-MOIS destructive breach against LACMTA with deliberate backup and VM destruction
- ShinyHunters lists Charter Communications (Spectrum) — telco victim in the Salesforce-credential campaign
- Kimwolf / "Dort" DDoS-for-hire operator arrested — 30+ Tbps IoT botnet, U.S. DoD-range targeting, AISURU variant
- West Pharmaceutical Services — 8-K/A confirms full operational restoration, data investigation ongoing
- B1ack's Stash carding marketplace publicly releases 4.6M card records — SOCRadar attributes collection to e-skimming and phishing; not confirmed by issuing banks
- Microsoft DCU disrupts Fox Tempest malware-signing-as-a-service feeding Rhysida, INC, Qilin and Akira ransomware operations
- 7-Eleven confirms ShinyHunters breach of 600,000+ Salesforce franchise-application records — same campaign as Instructure, Vimeo, Wynn Resorts, Vercel, Medtronic
- CISA contractor (Nightwing) exposed AWS GovCloud admin keys and internal credentials in public GitHub repo for ~6 months
- BKA arrests Dream Market lead administrator "Speedstepper" in Germany — cryptocurrency-to-physical-gold OPSEC failure after seven years at large
- Instructure Canvas — US House Homeland Security Committee opens formal investigation; Instructure paid ransom
- Foxconn confirms Nitrogen ransomware crippled North-American manufacturing sites; 8 TB / 11M files claimed
- West Pharmaceutical Services files SEC Form 8-K Item 1.05 — data exfiltrated, systems encrypted, global operations partially restarted
- CISA Emergency Directive ED-26-03 — Cisco Catalyst SD-WAN
- Canvas / Instructure — ShinyHunters / WorldLeaks ransom-paid, US House investigation
- West Pharmaceutical Services — SEC Form 8-K Item 1.05
- BWH Hotels — 181-day unauthorised access to guest-reservation web application
- Foxconn — Nitrogen ransomware confirmed against North-American manufacturing sites
- Hospitality
- Manufacturing
- Canvas / Instructure extortion — ransom paid, US House investigation, second-intrusion vulnerability re-exploited
- MuddyWater (Iran / MOIS) Chaos ransomware false-flag + Teams BEC
- ShinyHunters / WorldLeaks — week-long cross-incident operator activity touching Inditex, Vimeo, ADT, and Instructure / Canvas