Cybersecurity — page 2
Comcast to Pay $117.5 Million to Settle 2023 Data Breach Lawsuit
The cable giant will compensate U.S. customers after allegations of delayed victim notification and failure to patch known vulnerabilities.
Texas Credit Union Confirms Data Breach Exposing Social Security Numbers
Travis County Credit Union notified regulators and members after March 2026 email account compromise; law firm opens investigation.
Bayada Home Health Care Breach Exposes Patient Data Via Third-Party Vendor
Law firms are investigating after a Doctor Alliance security incident compromised Social Security numbers and medical records for thousands of patients across 22 states.
Analog Devices Confirms Data Breach, Operations Unaffected
The semiconductor giant disclosed unauthorized system access detected in late June, while investigating a second security incident.
Microsoft and Wiz Deploy Multi-Model AI Agents to Hunt Zero-Days
Both companies report breakthrough detection rates on CyberGym benchmark while cutting costs by half through model orchestration.
Tengu Botnet Weaponizes Hardware Watchdog to Survive Removal Attempts
Nozomi Networks Labs uncovers a Mirai-derived malware strain that forces system reboots when defenders try to kill its process.
Drone Autopilot Developer CubePilot Hit by DNS Hijacking Attack
Attackers seized control of the company's domain and obtained valid TLS certificates to intercept credentials from UAV operators and defense partners.
24,650 Internet-Exposed Server Controllers Leak Password Hashes to Unauthenticated Attackers
A 20-year-old IPMI protocol flaw enables offline password cracking against BMCs that operate beneath OS-level security monitoring.
Microsoft Patches Certighost Flaw as PoC Exploit Goes Public
A high-severity AD CS vulnerability lets low-privileged users impersonate domain controllers and seize full network control.
Critical vBulletin RCE Flaw CVE-2026-61511 Has Public Exploit
A pre-authentication remote code execution vulnerability in vBulletin forum software now has a public proof-of-concept, putting thousands of installations at risk.
OpenWrt Patches Critical DHCPv6 Flaw Enabling Remote Root Access
A stack buffer overflow in the default odhcpd daemon lets unauthenticated attackers execute code with root privileges on vulnerable routers.
Bank of Baroda Confirms Employee Email Hack, Up to 1TB of Customer Data Leaked
India's second-largest public sector bank says core systems remain secure after threat actor posted account records, Aadhaar numbers on dark web.
ShinyHunters Claims EY Breach, Threatens Data Leak by July 31
The extortion group says it stole employee credentials and client tax documents via a third-party platform compromise affecting at least 1,366 US residents.
24,000+ Server Management Controllers Exposed via 20-Year-Old Flaw
A decades-old IPMI authentication weakness lets attackers harvest password hashes from internet-facing BMCs, with researchers cracking credentials on at least one-third of exposed systems.
Bank of Baroda Confirms Email Breach, 1TB Data Allegedly Leaked on Dark Web
India's second-largest public sector bank says core systems remain secure after employee account compromise triggered forensic probe and cyber insurance claim.
Arista Patches CVSS 10.0 Zero-Day in VeloCloud Orchestrator Under Active Attack
CISA adds actively exploited command injection flaw to KEV catalog as administrators race to patch on-premises SD-WAN management systems.
South Korea's PIPC to Rule on KT Corp Sanctions Over Femtocell Data Breach
Regulators will determine fines under PIPA's 3% revenue penalty structure after breach exposed 22,227 subscriber lines and enabled fraudulent micropayments.
Bank of Baroda Confirms Data Breach via Compromised Employee Email
India's state-run lender says core banking systems remain secure after customer documents appeared on dark web.
AnMed Shuts 79 Facilities After Malware Attack Knocks Out IT Systems
South Carolina's largest independent health system canceled elective procedures and closed most outpatient locations following a cybersecurity incident that began July 26, 2026.
Dysphoria Botnet Adopts Blockchain C2 After JackSkid Takedown
Security researchers trace 200,000 infected IoT devices using Ethereum and Solana name services to evade disruption.
Hackers Exploit Critical FastJson 1.x Zero-Day to Execute Code on US Servers
CVE-2026-16723 bypasses default security in Spring Boot fat JAR deployments. No patch exists for the unmaintained 1.x branch.
AI Agent Runs Espionage Attack on Thailand Finance Ministry
Threat actors deployed the Hermes AI agent in autonomous YOLO mode to automate post-exploitation, leaving behind a custom implant and extensive logs.
Origin Energy Data Breach Exposes 900,000 Customer Records
Australia's largest integrated energy company confirms cybersecurity incident as shares fall on ASX.
Cloud Giants Reject Researcher's Confused Deputy Flaws Despite Privilege Escalation Risks
Microsoft and Google declined to officially recognize vulnerabilities that allowed attackers to become cluster-admin and Organization Owner while remaining invisible in audit logs.
Arista Patches Critical VeloCloud Zero-Day Under Active Exploitation
A perfect-10 severity command injection flaw in on-premises VeloCloud Orchestrator deployments is being weaponized against unpatched systems, prompting emergency CISA catalog listing.
Chick-fil-A Loyalty Accounts Breached in Credential Stuffing Attack
Second such incident in three years exposes names, payment data, and stored credit balances.
Ransomware Gang Claims DRDO Breach; Defence Agency Denies Data Theft
A group calling itself Babuk Locker 2.0 announced a massive data leak in March 2025, though cybersecurity experts question the group's legitimacy and DRDO officials reject the allegations.
Apple Sued Over $1.8M Bitcoin Theft From Fake Sparrow Wallet App
Three plaintiffs argue Apple's App Store security promises created false sense of trust that scammers exploited.
DentaQuest Breach Exposes Up to 23.4M Records After Ransom Talks Fail
The ShinyHunters group leaked 234GB of sensitive health data including children's Social Security numbers after negotiations with the dental benefits administrator collapsed.
EY Investigates Data Breach After Third-Party Platform Compromise
The Big Four firm detected unauthorized access to an IT support system that exposed client tax and financial documents.
Coca-Cola Confirms Data Theft in Fairlife Ransomware Attack
The beverage giant suspended U.S. dairy production for days before acknowledging exfiltration in the July 2026 incident.
Bank of Baroda Confirms Email Compromise After Hacker Claims 1TB Data Leak
India's second-largest public sector bank says core systems remain secure while forensic investigation underway.
23andMe Pays $18 Million to Settle Multistate Probe Into 2023 Data Breach
A coalition of state attorneys general penalized the genetic testing firm for failing to protect sensitive user information.
SourTrade Malvertising Campaign Builds Malware Inside Victim's Browser
A sophisticated operation targeting crypto investors uses browser APIs to assemble executables in memory, evading signature-based detection.
Scammers Weaponize ShinyHunters Breach Data in $2,000 Sextortion Campaign
A commodity email scam is exploiting leaked credentials from the notorious extortion group, though ShinyHunters denies any involvement.
CTM360 Uncovers 'InsureTrap' Campaign Hijacking Insurance Accounts in Real Time
A new phishing kit relays stolen credentials and OTPs instantly, bypassing multi-factor authentication before victims realize their sessions are compromised.
GitHub Dependabot Gets 3-Day Cooldown to Block Malicious Updates
New default delay creates detection window for supply chain attacks while keeping security patches immediate.
ServiceNow RCE Exploited in Wild as OpenAI Agent Breaches Hugging Face
Two July 2026 incidents mark a turning point: active exploitation of a critical enterprise flaw and the first autonomous AI agent attack on major infrastructure.
SourTrade Malvertising Campaign Builds Unique Malware Inside Victim Browsers
A sophisticated operation weaponizes the browser as a malware assembly line, defeating hash-based detection by creating bespoke executables for each target.
Researcher Releases GitLab RCE Exploit After Silent Patch Leaves Servers Exposed
A proof-of-concept for a critical remote code execution flaw went public six weeks after GitLab quietly fixed it without a security advisory or CVE assignment.
23andMe Pays $18M to 42 States Over 2023 Genetic Data Breach
Multistate settlement finalizes during bankruptcy proceedings after hackers accessed 6.9 million users' DNA profiles.
OpenAI Confirms Global ChatGPT Outage Affecting Millions Worldwide
A nearly two-hour disruption knocked out ChatGPT, Codex, and APIs across multiple continents on July 25, 2026.
Critical Fastjson 1.x Flaw Under Active Attack With No Patch Available
CVE-2026-16723 enables unauthenticated remote code execution against Spring Boot applications using the end-of-life library branch.