Rhysida published nearly 1.4 million files stolen from Berlin after a €2 million ransom demand failed, exposing personal and sensitive government data.
Category: eSecurity Planet
IDScan Confirms Breach Tied to 153 Million Stolen Driver’s Licenses
IDScan confirmed unauthorized cloud access after researchers linked its infrastructure to a dark-web marketplace holding millions of identity records.
AI-Accelerated Attacks and Zero-Days Push Defenders Toward Machine Speed
Weekly summary of Cybersecurity Insider newsletters
McKesson Data Leak Includes 6.4M Email Addresses After $55.2M Extortion Demand
McKesson breach data includes 6.4 million unique email addresses after ShinyHunters allegedly demanded $55.2 million to keep the records private.
N0va Phishkit Targets North America and Europe Through Microsoft Logins
The N0va phishkit abuses Microsoft device-code authentication to obtain tokens even after users complete MFA.
Microsoft Defender’s ShieldBreak Fix May Already Have Another Bypass
A researcher says ShieldCrash bypasses Microsoft’s latest Defender fix, extending a patch-and-bypass chain involving RoguePlanet and ShieldBreak.
4 Spy Groups Used BlueMoon on Chrome, Windows in One Week
Four spy groups used BlueMoon to chain Chrome and Windows zero-days in one week, showing why fast patching and post-compromise hunting matter.
119,000 Fake Shops Are Mimicking Real Brands to Steal Card Details
Researchers uncovered more than 119,000 DoppelCart fake shopping domains impersonating thousands of brands and collecting shoppers’ payment information.
Hackers Are Hijacking Claude Accounts and Burning Through Paid Usage
Infostealer malware is hijacking authenticated Claude sessions, allowing attackers to consume paid AI usage without stealing users’ passwords.
AI-Orchestrated PaperCut Attack Compromises 440 Servers Across 48 Countries
Infostealer malware is hijacking authenticated Claude sessions, allowing attackers to consume paid AI usage without stealing users’ passwords.
32.8 Million Alleged Condé Nast Records Offered for $15,000
A seller is offering 32.8 million alleged Condé Nast user records for $15,000, potentially exposing subscriber details useful for targeted phishing.
NSA, FBI, CISA Warn of Industrial-Scale AI Model Distillation Attacks
US agencies say six China-based AI firms used large-scale distillation campaigns to extract capabilities from Claude, GPT, Gemini, and Grok models.
AI and Human Risk Reshape CISO Priorities in 2026
AI and human risk are reshaping CISO priorities as board expectations grow.
Passwd Review 2026: A Top Password Manager for Google Workspace
Passwd is a Google Workspace-focused password manager with strong usability, flexible pricing, passkey support, and private cloud deployment options.
Hackers Route Phishing Through Google to Steal Microsoft Credentials
KnowBe4 found hackers abusing trusted Google services to hide phishing pages that steal Microsoft credentials and enable persistent ScreenConnect remote…
ChatGPT Flaw Let Attackers Secretly Hijack a Victim’s AI Session
Check Point researchers found a ChatGPT flaw that let attackers run hidden tasks and retrieve connected Gmail data through a cross-account channel.
220 Million Travel Records Exposed Through Default Credentials
Researchers found 220.8 million passenger and crew records exposed through default credentials in a Vietnam-linked database containing sensitive travel…
Google Warns Hackers Are Turning AI Agents Into Attack Tools
Google warns that hackers are using AI agents to automate attack stages, harvest credentials, and accelerate cyberattacks with less human direction.
Microsoft’s September Patch Tuesday Fixes Nearly 1,000 Flaws, Including 2 Exploited Zero-Days
Microsoft’s September 2026 Patch Tuesday fixes nearly 1,000 vulnerabilities, including two Windows zero-days already exploited in attacks.
CVE-2026-75650 Adobe Commerce Zero-Day: Patch Isn’t Enough
Adobe patched the actively exploited CVE-2026-75650 Magento zero-day, but compromised stores still need malware hunting and broad credential rotation.