databreach (30)

31269809095?profile=RESIZE_400xGoogle’s artificial intelligence model Gemini has accessed protected systems belonging to three external companies during a cybersecurity evaluation.  The incident occurred after a configuration error exposed the autonomous agent to the live internet. Gemini was participating in a 'capture-the-flag' challenge to locate hidden data within a simulated target environment. Directed to investigate software belonging to a fictional business, the model encountered a scope failure when the fictional ent

31268896662?profile=RESIZE_400xThe escalating dispute between ShinyHunters and the Cl0p ransomware gang has taken another turn, with Cl0p apparently regaining the ability to publish on its compromised dark web site and posting a message asking ShinyHunters to make contact.

Hackread.com observed the latest change on 21 September 2026.  Cl0p’s onion address, previously taken over and repurposed by ShinyHunters, displayed a short message from the ransomware gang directed at ShinyHunters.

BookSecurity Audits - “Shiny Hunters, we'

31267256481?profile=RESIZE_400xA new social engineering campaign has been discovered in which attackers are using fake passkeys and IT support requests to gain access to Microsoft 365 accounts. Microsoft Threat Intelligence has tracked the activity since May 2026 and says several threat actors, including Storm-3121 and Storm-3032, use these initial-access methods.  The company links Storm-3121 activity to ShinyHunters and Falcon extortion, while Storm-3032 represents actors that split from BlackFile and now operate under the

31224322883?profile=RESIZE_400xCybersecurity researcher Jeremiah Fowler has identified a significant data exposure involving millions of private facial images.  In a collaborative investigation conducted with ExpressVPN, Fowler discovered a publicly accessible database containing approximately 9,042,977 images.   The collection, totaling 450.2GB of data, was found with no password protection or encryption, leaving it open to any internet user who stumbled upon the repository.[1]

The discovery highlights a worrying security la

31224322883?profile=RESIZE_400xCybersecurity researcher Jeremiah Fowler has identified a significant data exposure involving millions of private facial images.  In a collaborative investigation conducted with ExpressVPN, Fowler discovered a publicly accessible database containing approximately 9,042,977 images.   The collection, totaling 450.2GB of data, was found with no password protection or encryption, leaving it open to any internet user who stumbled upon the repository.[1]

The discovery highlights a worrying security la

31224322883?profile=RESIZE_400xCybersecurity researcher Jeremiah Fowler has identified a significant data exposure involving millions of private facial images.  In a collaborative investigation conducted with ExpressVPN, Fowler discovered a publicly accessible database containing approximately 9,042,977 images.   The collection, totaling 450.2GB of data, was found with no password protection or encryption, leaving it open to any internet user who stumbled upon the repository.[1]

The discovery highlights a worrying security la

31214613470?profile=RESIZE_180x180Contact details of Angelina Jolie, Robert De Niro and Martin Scorsese have been exposed in a data breach.  Jennifer Lawrence, Morgan Freeman, Michael Douglas, Rami Malek, Sharon Stone, and directors George Lucas and Danny Boyle are also said to have been involved in the alleged leak last month.  The stars’ phone numbers and email addresses were revealed after a Tribeca Film Festival database, simply named “contacts”, was accidentally made public online, with Jeremiah Fowler, a researcher for Bla

31214612658?profile=RESIZE_400xRansomware attacks have increased dramatically during the second quarter of 2026, with undisclosed incidents surging 40% year-on-year, according to BlackFog's latest State of Ransomware Report.  The cybersecurity firm documented 2,027 undisclosed attacks in Q2 2026, compared with 1,446 during the same period in 2025.  The report, which provides comprehensive analysis of both publicly disclosed and undisclosed ransomware attacks worldwide, also recorded 306 publicly disclosed attacks during the q

31198463869?profile=RESIZE_400xA hacker recently claimed to have exfiltrated tens of gigabytes of internal development data allegedly belonging to global professional services firm Accenture.  The incident became public when a threat actor on the PwnForums forum boasted of compromising the company and stealing 35 gigabytes of data.  According to the hacker, the stolen information includes Azure access keys, tokens, configuration files, RSA and SSH keys, and internal source code.  As proof of possession, the actor posted a scr

31185654276?profile=RESIZE_400xOrganizations invest heavily in cybersecurity tools, firewalls, and endpoint detection systems.  Yet many still encounter serious difficulties when an actual incident occurs. Incident response requires more than a plan on paper.  It demands swift and effective execution under pressure.  Most small and medium-sized enterprises hold only a basic notion of their actions in a crisis.  Someone would contact the IT team and systems would be examined.  In practice, a real incident arises amid uncertain

31185653453?profile=RESIZE_400xNYC Health + Hospitals (NYCHHC), the healthcare system of New York City and the largest municipal healthcare network in the United States, has confirmed it suffered a cyberattack that resulted in the loss of highly sensitive data on 1.8 million people.  Among the stolen data are fingerprints and palm prints, which can never be changed, making this breach even more disruptive.  This is the latest in a growing number of major data breaches added to the healthcare data breach tracker maintained by

31148712298?profile=RESIZE_400xA recent analysis report by Surfshark found that, among global data breaches, South Africa ranks 42nd in Q1 2026.  Globally, 210.3 million accounts were breached, with the US ranking first at 29% of all breaches from January through March.  France takes second place, followed by India, Brazil, and the UK.[1]  Surfshark is a consumer-focused cybersecurity and privacy product suite.

Since 2004, South Africa has been the second-most breached country in Africa, with 45.7 million compromised user acc

31126688092?profile=RESIZE_400xHackers are claiming to have stolen a trove of data belonging to Lockheed Martin, the world’s largest defense contractor and an American aerospace company.  They are now selling it on the dark web.

The situation began on March 26, 2026, when a Telegram account linked to a dark web marketplace known as Threat Market, which posts in both Russian and English, claimed it had been approached by a group described as “APT IRAN.”  According to the post, the group requested infrastructure support to sell

31125805877?profile=RESIZE_400xGoogle has warned that ransomware gangs are reinventing their business models as traditional encryption-based attacks become less profitable and data-theft extortion surges.   According to new analysis, better cybersecurity controls, improved backup strategies, and stronger recovery capabilities mean more victims can restore their systems without paying, directly eroding criminal revenue. However, threat actors are not retreating; they are adapting their methods to make operations harder to disr

31105892100?profile=RESIZE_400xThe Federal Bureau of Investigation (FBI) has officially confirmed that a limited number of its servers have been compromised in a cybersecurity incident.  The breach affected surveillance systems used by the FBI for lawful foreign intelligence interception operations, with investigators suspecting state-backed Chinese hackers based on suspicious activity patterns.  The security breach occurred during the second week of February 2026 and was detected on 17 February 2026.  The incident has raised

31101311893?profile=RESIZE_400xAs the healthcare sector continues to grapple with the professionalization of cybercrime, the University of Mississippi Medical Center (UMMC) has become the latest high-profile target in a sprawling ransomware attack.  This incident is a reminder of the "identity-first" battlefield and the catastrophic impact of machine-speed exfiltration on clinical operations.  The attack, first disclosed on 19 February 2026, has severely disrupted the state's only academic medical center. UMMC leadership, inc

13770058857?profile=RESIZE_400xSouth Africa has seen its increases in social upheaval and other political struggles.  Cyber-attacks are an additional concern for South Africans to worry about.  South Africa has experienced 110 cybercrime incidents involving extortion, ransomware, and state hacking in the past five years, according to Orange Cyberdefense’s inaugural Security Navigator Africa report.  This is the highest number in Africa and more than double that of Egypt, which ranked second with 46 incidents between 2020 and

13715453285?profile=RESIZE_400xCredit rating company TransUnion has suffered a data breach, which has impacted the personal information of nearly 4.5 million Americans.  The firm revealed that unauthorized access was gained to a third-party application serving its US consumer support operations in a notification letter to impacted customers.  The information was limited to specific data elements and did not include credit reports or core credit information.

TransUnion has not publicly provided any more details on the nature o

13715435097?profile=RESIZE_400xA new sneaky type of malware, known as Raven Stealer, has been identified by the Lat61 Threat Intelligence Team at Point Wild.  The research team, led by Onkar R. Sonawane, has found that this seemingly simple program is surprisingly adept at remaining undetected while stealing your personal information.  The research, shared with Hackread.com, reveals that the malware is primarily spread through underground forums and often bundled with pirated software.

Built using the programming languages De

13712659476?profile=RESIZE_400xA joint study by Cybersecurity at MIT Sloan (CAMS) and Safe Security has examined 2,800 ransomware incidents and found that a staggering 80.83%, or more than 2,272 attacks, were driven by artificial intelligence. This statistic is not theoretical; it's based on comprehensive, real-world data collected during 2023–2024.

The Rethinking the Cybersecurity Arms Race working paper paints a vivid picture of how AI is transforming attack methods. Adversaries are no longer relying on manual orchestration