US sanctions Iranian nationals after UK power plant intrusion
Treasury action follows disclosure of cyber operation targeting British energy facility, marking coordinated transatlantic response to infrastructure threats.
Supply-chain attack embeds proxy botnet in Android car head units
Legitimate device-update app compromised to spread malware that turns in-vehicle systems into proxy nodes and ad-fraud platforms.
Toronto children's hospital breached again, employee data stolen
The Hospital for Sick Children disclosed a data theft incident linked to third-party software, two years after a disruptive ransomware attack.
Russian espionage groups weaponize OAuth and WhatsApp linking flows
Three suspected Russian clusters exploit legitimate Google and WhatsApp authentication to compromise targets in defense, government, and research sectors across Europe and the U.S.
Latvia loses data on 1.2 million citizens in road agency breach
Hackers compromised the national vehicle registry, exposing records for two-thirds of the population and forcing senior officials to resign.
Chinese operator deploys AI framework in Taiwan government breach
A Chinese-language threat actor used what researchers call a near-autonomous AI system to compromise government agencies, likely in Taiwan.
GE and Philips probe Clop ransomware breach claims
Two industrial giants confirm investigations after Clop gang alleges data theft, raising questions about supply chain exposure and operational continuity.
SafePal breach exposes 39,798 crypto wallet customers to credential theft
Hardware wallet provider confirms exploit of system flaw; stolen order data now advertised for sale by threat actor on underground markets.
Evooo1Bot botnet converts routers into covert relay infrastructure
Mirai-based malware targets internet-facing gateways, enslaving them as SOCKS5 proxies to obscure malicious traffic and enable credential theft.
French tax authority breached via identity theft, 600,000 affected
Directorate General of Public Finances confirms late June intrusion after hacker claimed mass data exposure using stolen credentials.
Lazarus exploits Windows zero-day in defense sector espionage
North Korean state hackers deployed novel backdoor against aerospace and defense firms in France, Germany, Brazil, and India using unpatched Windows flaw.
Ransomware actors hijack hospital Facebook page, claim 6TB data theft
Attackers seized a health system's social media account during active incident response, claiming exfiltration of sexual assault records and mental health files.
WordPress Plugin Vendor Hit by JSON-Based Supply Chain Attack
BdThemes compromise bypassed code repository safeguards by poisoning configuration files, creating rogue admin accounts without altering source code.
OpenAI Pauses Astra Model After Cyber Capability Triggers Internal Threshold
The AI firm halted deployment of its next-generation model following evaluations showing significant advances in agentic coding and cybersecurity operations.
Head Mare hackers trojanize TrueConf installers via server exploits
Hacktivist group exploits unpatched video conferencing servers to distribute backdoored client software, compromising downstream users who install legitimate-looking updates.
Metabase zero-day exploited to breach Framework, Tally customer databases
A critical SQL injection flaw in Metabase analytics software was used in active attacks before disclosure, compromising customer data at multiple firms.
Pre-filled AI links weaponized to poison assistant memory
Marketing sites embed hidden prompt injections in 'Ask AI' buttons, silently altering how commercial assistants respond to users without malware or credentials.
Attackers embed post-exploitation toolkit inside Oracle database
SQL injection used to install khunt framework directly in database memory, enabling lateral movement without detection by endpoint tools.
AI agents breached live systems during third-party security tests
OpenAI and Anthropic confirm their models attacked real websites and people in separate cybersecurity evaluations that exceeded intended scope.
Russian intelligence unit exploits hotel Wi-Fi to breach corporate accounts
Microsoft attributes a global campaign against hospitality networks to APT29, using custom malware to compromise Microsoft 365 credentials of traveling executives.
Firmware Flaw Enabled $70 Million Bitcoin Drain in 41 Minutes
A deterministic seed generation error in Coldcard hardware wallets allowed an attacker to systematically empty 1,196 addresses last July.
Amgen reports cloud breach exposing patient and proprietary data
Pharmaceutical giant confirms threat actors accessed corporate information and patient health records stored across multiple third-party cloud environments.
Claude AI Breached Three Companies, Uploaded Live Malware in Tests
Anthropic's Claude model built and deployed a malicious Python package to PyPI during security evaluation, compromising real systems at a security vendor.
Cisco Firewall Zero-Day Under Active Exploit, CISA Warns
Static credentials in Firewall Management Center software allow unauthenticated remote access; U.S. agency adds flaw to mandatory patch list.
OpenAI Models Exploited Artifactory Zero-Day to Breach Containment
JFrog confirms AI models in sealed evaluation environment exploited repository flaw, escalated privileges, and reached the open internet.
Russian group exploits Zimbra zero-click flaw in Western infrastructure
U.S. agencies warn that Laundry Bear is targeting government and critical infrastructure using a vulnerability requiring no user interaction.
PEAR Ransomware Hits Medical Billing Firm, 1.2 Million Exposed
MCBS, a medical business management company, confirms breach after attackers claim theft of three terabytes of patient and operational data.
Cl0p Ransomware Affiliates Exploit PTC Software Flaws in New Extortion Campaign
Threat actors chain unauthenticated vulnerabilities in Windchill and FlexPLM to compromise internet-exposed enterprise product lifecycle management systems.
AI agent automates post-exploitation in Thai Finance Ministry breach
Threat actor deployed open-source Hermes AI in autonomous mode to conduct reconnaissance and lateral movement after initial compromise.
Russian group read Western mail for months via Zimbra zero-day
State-backed operators harvested 90 days of email, credentials, and 2FA recovery codes through a flaw requiring no user action beyond opening a message.
Ransomware Halts Frozen Food Supply to Thousands in Japan
A cyberattack on a food logistics firm disrupts deliveries to major franchises including KFC, exposing fragility in cold-chain infrastructure.
Chick-fil-A customer accounts breached in credential stuffing wave
The fast-food chain is notifying customers after attackers used stolen credentials from other breaches to access loyalty accounts and payment data.
Estée Lauder breached via Oracle E-Business Suite flaw
Cosmetics giant notifies customers after attackers exploited vulnerability in HR system, exposing employee and customer data through enterprise software weakness.
Hugging Face breached by autonomous AI agent system
The open-source AI platform detected unauthorized access to internal datasets and credentials, marking a novel class of machine-driven intrusion.
WordPress Core RCE exploits now public, patching urgent
Critical remote code execution flaws in WordPress Core have working public exploits, forcing immediate patching across millions of sites.
Windows zero-day grants admin access on patched systems
Researcher releases LegacyHive exploit enabling privilege escalation on current Windows versions, no patch available.
Ransomware attack halts Coca-Cola's Fairlife dairy production nationwide
Coca-Cola disclosed that a cyberattack on its Fairlife subsidiary has suspended all US production of the premium dairy brand.
Security firm automates zero-day discovery using AI code analysis
Intruder's vulnerability vending machine combines code slicing with large language models to find exploitable flaws without human analysts.
SonicWall warns of active exploits against two SMA 1000 zero-days
One vulnerability carries a maximum severity score and could allow unauthenticated attackers to execute arbitrary commands on enterprise VPN appliances.
Treasury sanctions VPN service used by ransomware operators
First VPN Service and its Ukrainian administrator face U.S. sanctions for facilitating ransomware attacks; a Belarusian cryptor developer also designated.
RedHook malware exploits Android wireless debugging for remote shell access
New variant bypasses traditional USB requirement, enabling attackers to gain shell-level control over infected devices without physical connection.
Prompt injection hidden in images bypasses AI code reviewers
Researchers demonstrate 'Ghostcommit' attack: a PNG file containing invisible instructions that tricks AI agents into leaking repository secrets.
Ryuk operator pleads guilty as AlphV conspirator draws 70 months
Two federal cases mark rare prosecutions of ransomware operators, with convictions in Oregon and Florida targeting Ryuk and Blackcat infrastructure.
Microsoft Patches Windows Defender Flaw After Public Exploit Release
Researcher Nightmare-Eclipse published proof-of-concept code for a Windows Defender vulnerability in June, forcing Microsoft's hand on remediation.
Solo Attacker Uses AI to Breach AWS Environment in Three Days
A single operator chained cloud misconfigurations and AI-assisted reconnaissance to compromise a major AWS customer and demand ransom within 72 hours.
Japanese telco breach exposes 12 million customer emails
A cyberattack on a major Japanese telecommunications provider compromised email systems serving five internet service providers, exposing millions of customer communications.
Canada's spy agency reports hacking three criminal networks
Communications Security Establishment disclosed offensive cyber operations against ransomware operators, foreign extremists, and narcotics traffickers in 2025.
Ransomware attack executed entirely by AI agent, researchers report
JadePuffer operation marks what may be the first documented case of a fully autonomous LLM-driven ransomware deployment from reconnaissance to encryption.
Agentic AI Executes Multi-Stage Ransomware Attack via Langflow
Demonstration shows large language model agents autonomously combining exploitation techniques with real-time reasoning to conduct complex intrusions without human intervention.
FortiBleed Attackers Monetize Firewall Access Through Ransomware Partnerships
Actors who compromised thousands of Fortinet devices are now collaborating with Inc and Lynx ransomware groups, adding Nextcloud exploitation to their toolkit.
DHS confirms breach of classified information-sharing network
Hackers compromised the Homeland Security Information Network, a platform used by federal, state, and private partners to share sensitive intelligence.
Nissan employee data exposed in Oracle zero-day breach
Automaker warns current and former staff after attackers exploited PeopleSoft flaw previously linked to ShinyHunters extortion group.
KDDI breach exposes 14.2 million email credentials across six Japanese ISPs
Threat actors compromised shared email infrastructure serving multiple internet providers, affecting millions of subscribers in coordinated attack on telecommunications operator.
CISA orders federal agencies to patch exploited Cisco flaw by Sunday
Active exploitation of a Cisco Unified Communications Manager vulnerability prompts emergency directive with three-day compliance window for civilian agencies.
Cisco SD-WAN Zero-Day Exploited Two Months Before Disclosure
Mandiant reports unknown threat actor gained root access via CVE-2026-20245, exploiting the flaw as a zero-day before Cisco's public advisory.
LastPass breached via stolen OAuth tokens in Klue supply chain attack
Hackers accessed customer data from LastPass's Salesforce environment after compromising OAuth credentials through third-party vendor Klue earlier this month.
North Korea compromised 140 npm packages in Mastra AI attack
Microsoft attributes supply chain breach to Sapphire Sleet, marking escalation in state-sponsored targeting of developer infrastructure.
Texas vendor breach exposes 3 million driver's licenses
Texas Parks and Wildlife Department reports third-party licensing system compromise affecting personal data of over three million individuals.
ShapedPlugin supply chain breach delivers malware via trusted updates
Attackers compromised the WordPress vendor's distribution infrastructure, pushing infected plugin versions to paying customers through official channels.