Data Breaches & Exposures

Study of 10,616 Leaked AWS Keys Finds 768 Still Holding Full Admin Rights

Researchers tested keys exposed publicly between August 2022 and August 2026 and found 9,308 still authenticating. Of 817 belonging to companies, 768 carried full administrative access, including 526 root keys and 130 on organisation management accounts. Hugging Face was the largest source.

breach-confirmed cloud-security aws credential-exposure
Surveillance, Spyware & Intelligence Agencies

Wyden and Casar Ask GAO to Audit Federal Law Enforcement Hacking Tools

The senator and representative wrote to the Government Accountability Office seeking a review of how the FBI, DEA, Homeland Security Investigations and the Secret Service deploy intrusion software against Americans. The request covers abuse potential, leak safeguards, and warrant disclosure practices.

government-hacking oversight spyware united-states
Data Breaches & Exposures

Apollo Global Management Breach Exposes Names, Birth Dates and Social Security Numbers

The asset manager told affected individuals that intruders reached certain cloud platforms between 6 and 10 July using social engineering. Stolen fields covered names, dates of birth, home addresses and Social Security numbers. Dozens of financial institutions were hit by the same voice-phishing crews.

breach-confirmed social-engineering financial-services vishing
Privacy Rights & Data Protection

TikTok and ByteDance Settle US Children's Privacy Litigation for 400 Million Dollars

The Justice Department secured one of the largest COPPA recoveries on record, resolving a 2024 suit over accounts created by under-13s and data collected in Kids Mode. TikTok pays 300 million dollars immediately and 100 million more once its earlier FTC order is vacated.

coppa children-privacy settlement tiktok
Software & Supply Chain Attacks

Poisoned arrayref Crate Puts Build-Time Malware in Three Quarters of Rust Environments

Malicious releases of arrayref, internment and append-only-vec reached crates.io with a typosquatted proc-macro1 dependency whose build script fetched and ran a remote binary. arrayref alone counts 245 million downloads. Maintainers pulled the packages after 86 minutes; Wiz mapped infrastructure overlap with DPRK campaigns.

supply-chain rust north-korea typosquatting
Privacy Rights & Data Protection

Hong Kong Privacy Commissioner Puts Canvas Breach Toll at 153,866 Students and Staff

The Office of the Privacy Commissioner for Personal Data published findings from its investigation into the ShinyHunters compromise of Instructure Canvas, counting at least 153,866 affected people across four local institutions. City University of Hong Kong accounted for 96 percent of that total.

hong-kong education data-protection regulator
Nation-State Attacks & Cyber Espionage

Transparent Tribe Backdoors PATCHCORD and SHEETCORD Hit Afghan Telecom Networks

Acronis documented a refreshed Pakistan-linked toolset aimed at Afghan government and telecommunications organisations and Indian critical infrastructure. PATCHCORD hijacked desktop shortcuts for persistence while the operators routed command traffic through Google Sheets and GitHub Gists to blend with ordinary business activity.

breach-confirmed apt36 pakistan espionage afghanistan
Nation-State Attacks & Cyber Espionage

Black Spark Intrusion at Russian Traffic Analysis Vendor Microolap

The Russian network traffic analysis developer acknowledged a security incident while disputing the attackers' account. The pro-Ukraine group said it spent over a month inside the network and reached the EtherSensor product, with claims extending to Russian Railways, Goznak and VTB Bank.

breach-confirmed russia ukraine hacktivism
Cybercrime, Fraud & Underground Markets

First Documented Android Head-Unit Malware Spreads Through DoFun Firmware Updates

Kaspersky traced infections to TWCore, a system application on DoFun automotive head units used for analytics and software updates, turning vehicles into ad-fraud and residential proxy nodes. Researchers attributed the campaign with high confidence to MoYu Group, previously linked to the BADBOX ecosystem.

android automotive badbox ad-fraud botnet
Data Breaches & Exposures

LockBit 5 Leak-Site Post Targets U.S. Bank With a 3 September Deadline

LockBit 5 listed the lender and set a payment deadline of 3 September. U.S. Bancorp traced the material to a potential incident at a contractor of a third party and found no evidence its own systems, networks or data repositories were reached.

breach-claimed lockbit financial-services fourth-party-risk
Privacy Rights & Data Protection

Roblox Signs a Court-Enforceable Undertaking With Australia's eSafety Commissioner

eSafety testing showed adults could send connection requests to young children without parental consent and that children's profiles stayed broadly visible. Roblox took three months to make child accounts private by default, block unsolicited adult contact, and appoint an independent auditor.

child-safety esafety age-verification australia
Data Breaches & Exposures

CareCloud Breach Total Rises Elevenfold to 3,756,469 Patients

The health technology vendor revised its March intrusion upward from about 345,000 to 3,756,469 individuals on the HHS breach portal. Attackers held access to an AWS environment behind one of six EHR estates, taking names, Social Security numbers and medical records.

breach-confirmed healthcare aws hipaa
Cybercrime, Fraud & Underground Markets

Operation CameraSwarm Compromised 14,530 Dahua Surveillance Devices

Researchers documented a campaign running from 17 June to 22 July that chained credential attacks, the CVE-2021-33044 and CVE-2021-33045 authentication bypasses, and a peer-to-peer relay reaching devices behind NAT. Compromises concentrated in Russia and Ukraine, with 1,923 cameras given a persistent account.

surveillance-cameras iot credential-stuffing dahua
Nation-State Attacks & Cyber Espionage

SilkParasite Cluster Deploys Seven RAT Families Against Central Asian Governments

Bitdefender tied a China-nexus intrusion set active since October 2025 to spear-phishing against ministries in Uzbekistan, Turkmenistan, Kyrgyzstan, Tajikistan and Kazakhstan. Five of the seven remote access tools were previously undocumented, with DLL sideloading and Google Drive command channels across roughly 65 infected systems.

breach-confirmed china espionage apt central-asia
Cybercrime, Fraud & Underground Markets

StopAndProtect Ran Malware Delivery and Command Traffic Through 2,000 Hacked WordPress Sites

Check Point Research mapped an operation abusing nearly 2,000 compromised WordPress sites for distribution, command and control, and stolen-file storage. ClickFix lures triggered PowerShell that loaded ransomware, an SMB and USB worm, a lock screen and a credential stealer, reaching over 6,000 unique IP addresses.

wordpress clickfix credential-theft ransomware