Australian authorities have charged two alleged TeamPCP members after software supply chain attacks exposed over 500,000 credentials and at least 300GB of data.
Manchester Airports Group data breach affected 8.7 million customers at three UK airports, exposing mainly emails, phone numbers, postcodes and vehicle details.
More than 100 U.S. water systems faced cyberattacks in July, with exposed PLCs and cellular modems giving hackers access to some utility controls and operations, CISA has now revealed.
Forescout disclosed 15 TP-Link flaws at Black Hat USA 2026 that could expose Omada credentials and VPN keys, allow internal access and affect VIGI camera feeds.
At Black Hat USA 2026, Novee found GitHub workflow flaws in Claude Code, Gemini CLI and Codex that enabled RCE, credential theft and agent control in pipelines.
Kaspersky links OctLurk and SilkLurk to cyberespionage attacks stealing passwords, emails and files from government systems in six countries since January 2025.
Galaxy Research linked a suspected Bitcoin theft of 1,367.05 BTC to weak COLDCARD seeds. Coinkite says updates cannot repair seeds already generated on devices.
Bitsight found Fuyao software on H96 Android TV boxes, letting operators fake ad clicks and route proxy traffic through their owners' home internet connections.
Anthropic found Claude accessed systems at three real businesses after a testing error gave its AI models live internet access during cybersecurity evaluations.
A backdoored ARVE WordPress Plugin release could grant attackers administrator access with one token, but WordPress.org blocked automatic distribution to WordPress sites.
Cybersecurity researchers at Wiz found CosmosEscape in Azure's Gremlin API, exposing a master key that could access any Cosmos DB account. Microsoft fixed it, with no customer impact found.
LeakNet claims it stole 11TB of NYC Health + Hospitals data containing sensitive medical, financial and biometric records linked to more than 12 million people.
Ruflo fixed a CVSS 10.0 flaw that exposed its MCP bridge without any authentication, putting AI provider keys, stored chats and persistent agent memory at risk.
Researchers found 24,650 public BMC interfaces leaking IPMI password hashes, exposing servers to offline password cracking through a decades-old protocol flaw.
EY confirmed the theft of client tax documents from its third-party support platform. ShinyHunters claims responsibility and is threatening to publish the data.
Fake helpdesk callers use Microsoft Teams and Quick Assist to access employee computers, where attackers install new GoGRPC backdoor in suspected ransomware operations
Certighost allowed a low-privilege domain user obtain a valid Domain Controller certificate through AD CS. Microsoft patched the issue in the July security updates.
Compromised hotel Wi-Fi gateways redirect business travelers to fake Microsoft 365 login pages allowing attackers to steal credentials and authorization tokens.
Google Search indexed public Claude AI chat links, letting people find shared conversations through the site query before those listings disappeared soon after.