// BREACH WATCH

BREACH & RANSOMWARE

Real-time breach and ransomware intelligence for third-party risk management.

Breaches Advisories Vulnerabilities RSS
0
Last 24h
4
Last 7 Days
4
Critical (7d)
All Critical High Medium Low
✕ Clear All
BREACH VERISQ BRIEF 🛡️
VERISQ BRIEFID Verification Firm IDScan.net Confirms Data Breach

IDScan.net Confirms Breach - But Leaves Victim Count and Point of Entry Unanswered A Louisiana identity verification company has confirmed a breach reportedly tied to the darkweb sale of more than 153 million U.S. and Canadian driver's licenses, but its notice does not say how many people were affected or how attackers got in.

🌐 idscan.net
Critical · Sep 12, 2026 · DataBreachToday
Read Full Intelligence Brief →
BREACH VERISQ BRIEF 💀
VERISQ BRIEFAttackers Exploit Critical Cisco FMC Flaw to deploy Qilin ransomware

Three threat groups are exploiting two Cisco FMC flaws to steal credentials, gain root access and deploy Qilin ransomware. Cisco Talos says three separate threat groups are exploiting two recently patched Secure Firewall Management Center (FMC) flaws. The main target is CVE-2026-20079, a critical authentication bypass that lets unauthenticated attackers remotely bypass security controls, run […]

Critical · Sep 11, 2026 · Security Affairs
Read Full Intelligence Brief →
BREACH VERISQ BRIEF 🔑
VERISQ BRIEFUK Council Attack Linked to Mass Exploitation of SonicWall Flaw

A critical SonicWall flaw was rapidly weaponized, with a UK Council attack linked to a campaign that exposed credentials and enabled Active Directory theft. On July 17, 2026, the Borough Council of King’s Lynn and West Norfolk announced it had detected a cyberattack affecting council services. Hunt.io has since published a detailed technical analysis linking […]

🌐 hunt.io
Critical · Sep 11, 2026 · Security Affairs
Read Full Intelligence Brief →
BREACH VERISQ BRIEF 🗄️
VERISQ BRIEFMassive Vietnam-Linked APIS Database Exposes Passport and Flight Data

An exposed Vietnam-linked APIS database contained 220.8 million passenger and crew records, including passport and flight data. Researchers found an exposed Advance Passenger Information System (APIS) database containing 220.8 million passenger and crew records from January 2017 to April 2026. The data includes sensitive details such as passport numbers, identities and flight information, potentially affecting […]

Critical · Sep 08, 2026 · Security Affairs
Read Full Intelligence Brief →
BREACH VERISQ BRIEF 🛡️
VERISQ BRIEF153M+ driver’s licenses for sale on new dark web platform

The FBI is investigating a possible breach of idscan.net linked to 153 million driver’s license scans for sale online.

🌐 idscan.net
Critical · Sep 02, 2026 · Malwarebytes Labs
Read Full Intelligence Brief →
BREACH VERISQ BRIEF 🏛️
VERISQ BRIEFFBI Probes Service Selling 153M+ Drivers Licenses

A new identity theft service launched on the dark web this week is selling digital scans of more than 153 million drivers licenses from people in the United States and Canada. Based on interviews with individuals whose licenses are available for purchase on this service, it appears to be siphoning images collected by a widely-used identity verification company based in Louisiana. KrebsOnSecurity also has learned that the New Orleans field office of the Federal Bureau of Investigation (FBI) today launched an official inquiry into the source of the images.

Critical · Sep 01, 2026 · Krebs on Security
Read Full Intelligence Brief →
BREACH VERISQ BRIEF 🏥
VERISQ BRIEFAttackers Access Aesto Health AWS Infrastructure, Exposing 9.5 Million Records

Aesto Health suffered a breach exposing personal and health data of more than 9.5 million people after attackers accessed its AWS infrastructure. Aesto Health, a U.S. healthcare technology company, disclosed a data breach that exposed personal and health information belonging to more than 9.5 million people. The company discovered the incident on December 18, 2025, […]

Critical · Sep 01, 2026 · Security Affairs
Read Full Intelligence Brief →
RANSOMWARE VERISQ BRIEF 💀
VERISQ BRIEFBerlin confirms data theft after Rhysida ransomware attack claims

Berlin's city administration has confirmed that cybercriminals are attempting to extort the city after the Rhysida ransomware gang listed it on their data leak site. [...]

Critical · Aug 31, 2026 · BleepingComputer
Read Full Intelligence Brief →
RANSOMWARE VERISQ BRIEF 🏛️
VERISQ BRIEFRhysida Ransomware Group Targets Berlin Government Ahead of Vote

Berlin ‘s government faces a Rhysida ransomware attack weeks before elections, with officials refusing to pay despite a claimed 5.79 TB data theft. Berlin’s state government confirmed this week it’s dealing with an extortion attempt following an August cyberattack on the city-state’s administrative network, and officials have already refused the requested ransom. The ransomware group […]

Critical · Aug 29, 2026 · Security Affairs
Read Full Intelligence Brief →
BREACH VERISQ BRIEF ☁️
VERISQ BRIEFPhilippine Nuclear and Naval Targets Hit by Suspected Chinese Operator

An alleged Chinese-speaking actor breached Philippine nuclear and naval targets by exploiting known flaws, stealing sensitive data. A suspected Chinese-speaking operator targeted a Philippine nuclear research body and a marine engineering company that supports the Philippine Navy, using well-known vulnerabilities in internet-facing ownCloud and WordPress systems. The activity was uncovered after Hunt.io found an exposed […]

🌐 hunt.io
Critical · Aug 29, 2026 · Security Affairs
Read Full Intelligence Brief →
BREACH VERISQ BRIEF 🏛️
VERISQ BRIEFUS takes down alleged Chinese hacking tools used against Federal Reserve, DOJ and Senate

The DOJ said it disrupted Chinese state-backed tools used to scan, infect and exploit IoT devices for attacks on federal agencies and multiple industries.

Critical · Aug 26, 2026 · The Record
Read Full Intelligence Brief →
BREACH VERISQ BRIEF 🛡️
VERISQ BRIEFHackers breached over 270 Zimbra servers in ongoing attacks

Threat actors have already compromised over 270 Zimbra instances in remote code execution attacks targeting a high-severity Zimbra Collaboration Suite (ZCS) vulnerability. [...]

Critical · Aug 25, 2026 · BleepingComputer
Read Full Intelligence Brief →
BREACH VERISQ BRIEF 🛡️
VERISQ BRIEFUK Power Plant Disabled for Four Days by Iran-Linked Hackers, Concurrent with US Water Attacks

Iran-linked hackers shut down a UK power plant for four days in the first confirmed attack of its kind, concurrent with water infrastructure attacks across 12 US states. Iran-linked hackers shut down a British power plant for four days in what The Telegraph describes as the most successful cyberattack of its kind against UK energy […]

Critical · Aug 23, 2026 · Security Affairs
Read Full Intelligence Brief →
RANSOMWARE VERISQ BRIEF 💀
VERISQ BRIEFCISA: Medusa ransomware hit over 500 critical infrastructure orgs

The FBI said Tuesday that the Medusa ransomware gang has breached more than 500 critical infrastructure organizations in the United States since June 2021. [...]

Critical · Aug 19, 2026 · BleepingComputer
Read Full Intelligence Brief →
RANSOMWARE VERISQ BRIEF 💀
VERISQ BRIEFChina-Linked Hackers Use N-able Flaw in Ransomware Attacks

Microsoft Says Storm-1175 Exploited CVE-2026-18577 After Its Disclosure Microsoft says China-linked Storm-1175 is exploiting N-able N-central authentication bypass CVE-2026-18577 to gain administrative RMM access, pivot into managed endpoints and rapidly deploy its new StormEncryptor ransomware.

Critical · Aug 11, 2026 · DataBreachToday
Read Full Intelligence Brief →
BREACH VERISQ BRIEF 🏥
VERISQ BRIEFUnlimited Technology Systems breach impacts 3.8 million people

Healthcare software company Unlimited Technology Systems reported that more than 3.8 million people were impacted by a data breach incident that occurred in October 2025. [...]

Critical · Aug 07, 2026 · BleepingComputer
Read Full Intelligence Brief →
BREACH VERISQ BRIEF 🏛️
VERISQ BRIEFSnowflake Hacker Pleads Guilty Over Breaches Affecting at Least 100 Million People

Connor Riley Moucka pleaded guilty in Seattle federal court on Wednesday to computer fraud, wire fraud, aggravated identity theft and a related conspiracy over the 2024 breaches of Snowflake customer accounts. The intrusions reached at least 165 organizations and exposed records belonging to at least 100 million people. Moucka, 26, of Kitchener, Ontario, personally took at least $495,000 from

Critical · Aug 06, 2026 · The Hacker News
Read Full Intelligence Brief →
BREACH VERISQ BRIEF 🛡️
VERISQ BRIEFBitcoin hardware wallet maker destroys some inventory after more than $88 million stolen

The company behind a popular hardware wallet for bitcoin owners was forced to destroy part of its inventory after thieves siphoned more than $88 million from customers through a firmware vulnerability.

Critical · Aug 03, 2026 · The Record
Read Full Intelligence Brief →
BREACH VERISQ BRIEF 🛡️
VERISQ BRIEF⚡ Weekly Recap: Rogue AI Models, $88M Bitcoin Theft, Water-System Attacks and Dangling DNS Hijacks

This week kept coming back to permission. A model crossed a boundary. A wallet trusted bad randomness. Webmail kept an intruder around. Public systems, package feeds, hotel networks, and login flows all gave away more than intended. Some of it was clever. Most of it was just access left lying around: old bugs, exposed gear, poisoned dependencies, weak defaults, and tooling that moved from

Critical · Aug 03, 2026 · The Hacker News
Read Full Intelligence Brief →
RANSOMWARE VERISQ BRIEF 💀
VERISQ BRIEFClop ransomware targets Windchill, FlexPLM in data theft attacks

The Clop ransomware gang (also tracked as Cl0p) is targeting Internet-exposed PTC Windchill and FlexPLM instances in a new data theft extortion campaign. [...]

Critical · Jul 24, 2026 · BleepingComputer
Read Full Intelligence Brief →
RANSOMWARE VERISQ BRIEF 💀
VERISQ BRIEFChaos Ransomware Uses msaRAT to Route C2 Traffic Through Headless Chrome and Edge

The Chaos ransomware group ran its command-and-control through the victim's own browser. Cisco Talos on Thursday detailed msaRAT, the Rust implant behind it, found on a compromised Windows machine ahead of the encryptor. The implant never opens an outbound connection of its own. Its process talks to 127.0.0.1 and nothing else. It starts Chrome or Edge in headless mode and drives the browser

Critical · Jul 23, 2026 · The Hacker News
Read Full Intelligence Brief →
BREACH VERISQ BRIEF 💣
VERISQ BRIEFSonicWall SMA zero-days were exploited weeks before disclosure

Two recently disclosed SonicWall SMA 1000 vulnerabilities – CVE-2026-15409 and CVE-2026-15410 – were exploited in zero-day attacks for weeks, allowing threat actors to install custom malware on vulnerable VPN appliances, Volexity researchers revealed. The intrusions began as early as June 22, 2026, well before the flaws became public. According to the researchers, the attackers’ goal was stealthy, long-term access: once inside, the intruders could reach stored or cached credentials, capture network traffic, and potentially intercept … More → The post SonicWall SMA zero-days were exploited weeks before disclosure appeared first on Help Net Security .

Critical · Jul 21, 2026 · Help Net Security
Read Full Intelligence Brief →
RANSOMWARE VERISQ BRIEF 💀
VERISQ BRIEFCritical Palo Alto VPN bug now exploited by Qilin ransomware gang

The Qilin ransomware gang is exploiting a critical PAN-OS GlobalProtect authentication bypass flaw to breach victims' networks, according to cybersecurity company Arctic Wolf. [...]

Critical · Jul 21, 2026 · BleepingComputer
Read Full Intelligence Brief →
BREACH VERISQ BRIEF 💣
VERISQ BRIEFSonicWall SMA1000 flaws exploited as zero-days to push custom malware

Two recently disclosed SonicWall SMA1000 vulnerabilities were exploited in zero-day attacks for weeks, allowing threat actors to install custom malware on vulnerable VPN appliances. [...]

Critical · Jul 20, 2026 · BleepingComputer
Read Full Intelligence Brief →
BREACH VERISQ BRIEF 🛡️
VERISQ BRIEFGoldenEyeDog Subgroup Linked to DigiCert Breach and Code-Signing Certificate Theft

Cybersecurity researchers have attributed the April 2026 DigiCert security incident to a threat activity cluster dubbed CylindricalCanine. Expel, which shared technical details of the event, described the threat actor as a sub-group of GoldenEyeDog (aka APT-Q-27, Dragon Breath, and Miuuti Group), a Chinese cybercrime group known for its targeting of the gambling and gaming sectors using

Critical · Jul 17, 2026 · The Hacker News
Read Full Intelligence Brief →
RANSOMWARE VERISQ BRIEF 💀
VERISQ BRIEFFormer ransomware negotiator gets 4 years for BlackCat attacks

A former employee of cybersecurity incident response company DigitalMint was sentenced to 70 months in prison for targeting U.S. companies in BlackCat (ALPHV) ransomware attacks. [...]

Critical · Jul 10, 2026 · BleepingComputer
Read Full Intelligence Brief →
BREACH VERISQ BRIEF 🎓
VERISQ BRIEFChinese Cyberespionage Exploits University Roundcube Servers

Campaign Combines XSS and Deserialization to Steal Credentials and Deploy Malware Proofpoint identified a likely China-aligned espionage group exploiting chained Roundcube vulnerabilities to steal credentials and deploy persistent malware against U.S. and Canadian university departments conducting sensitive physics, engineering and national security research.

Critical · Jul 07, 2026 · DataBreachToday
Read Full Intelligence Brief →
BREACH VERISQ BRIEF 🏛️
VERISQ BRIEFHackers Breach Sensitive DHS Information-Sharing Network

Hackers Breach DHS Network Used to Coordinate Major Event Security Federal investigators are probing a breach of a sensitive DHS network that thousands of law enforcement and emergency officials use to coordinate security for major events, as a top senator warns the intrusion could carry national security consequences.

Critical · Jul 07, 2026 · DataBreachToday
Read Full Intelligence Brief →
RANSOMWARE VERISQ BRIEF 💀
VERISQ BRIEFAI Agent Pulls Off a Ransomware Attack Without Human Help

Researchers Say the Attack Combined AI Decision-Making With Known Software Flaws An autonomous AI agent has executed what researchers describe as the first agentic ransomware attack, exploiting vulnerabilities, stealing credentials and encrypting a production database without human intervention. Cloud security firm Sysdig attributed it to a threat actor it tracks as Jadepuffer.

Critical · Jul 06, 2026 · DataBreachToday
Read Full Intelligence Brief →
RANSOMWARE VERISQ BRIEF 💀
VERISQ BRIEFJADEPUFFER: First End-to-End AI-Driven Ransomware Operation

Sysdig reports an AI agent ran a full ransomware attack end-to-end, exploiting flaws, stealing creds, moving laterally, and encrypting data without humans. Sysdig’s Threat Research Team has documented what it assesses to be the first ransomware operation driven end-to-end by a large language model. The operator, which Sysdig calls JADEPUFFER, broke into a server, harvested […]

Critical · Jul 03, 2026 · Security Affairs
Read Full Intelligence Brief →
BREACH VERISQ BRIEF 🛡️
VERISQ BRIEFEuropean Parliament Member Investigating Spyware Was Hacked With Pegasus

A new report from the Citizen Lab has revealed that former Member of the European Parliament Stelios Kouloglou had his mobile device repeatedly hacked with the notorious Pegasus spyware while serving on a committee that was tasked with investigating the abuse of such commercial surveillance tools in the bloc. "Through forensic analysis of his device, we found that the attackers could have had

Critical · Jul 03, 2026 · The Hacker News
Read Full Intelligence Brief →
RANSOMWARE VERISQ BRIEF 💀
VERISQ BRIEFAI Agent Exploits Langflow RCE to Automate Database Ransomware Attack

Security firm Sysdig says it has found what it believes is the first ransomware attack run from start to finish by an AI agent. Its Threat Research Team calls the operator JADEPUFFER and says a large language model handled the whole job: breaking in, stealing credentials, moving deeper into the network, then encrypting and wiping a company's production database. Ransomware has always

Critical · Jul 02, 2026 · The Hacker News
Read Full Intelligence Brief →
BREACH VERISQ BRIEF 🛡️
VERISQ BRIEFCritical SimpleHelp flaw exploited to deploy new stealer malware

Hackers are exploiting a recently disclosed critical vulnerability (CVE-2026-48558) in SimpleHelp to deploy Djinn Stealer, a previously undocumented cross-platform information stealer targeting Windows, macOS, and Linux. [...]

Critical · Jun 29, 2026 · BleepingComputer
Read Full Intelligence Brief →
BREACH VERISQ BRIEF 🏛️
VERISQ BRIEFA Hack Too Far? Report Ties Russia to Jaguar Land Rover Hit

How Should the British Government Respond to the $2.5B Economic Disruption? Suggestions that the Kremlin orchestrated the disruptive hack attack against British automotive giant Jaguar Land Rover raise the question of how the British government might respond. For businesses, Moscow's advancing use of "gray zone" tactics is a reminder that they're in the line of fire.

Critical · Jun 27, 2026 · DataBreachToday
Read Full Intelligence Brief →
BREACH VERISQ BRIEF 🔑
VERISQ BRIEF24B Records Exposed in Massive Leak of Emails, Passwords, and Login Data

Cybernews researchers found an exposed database with 24 billion credential records, raising fresh risks from password reuse and credential stuffing. The post 24B Records Exposed in Massive Leak of Emails, Passwords, and Login Data appeared first on TechRepublic .

Critical · Jun 18, 2026 · TechRepublic Security
Read Full Intelligence Brief →
BREACH VERISQ BRIEF 🔑
VERISQ BRIEFFortiBleed Exposes Admin Passwords for 75,000 Fortinet Firewalls

FortiBleed: Admin Passwords for 75,000 Fortinet Firewalls Are Out in the Wild. Half the Internet-Facing Fortinets on the Planet. Security researcher Bob Diachenko found a server sitting open on the internet containing what appeared to be valid Fortinet VPN credentials, including usernames, email addresses, and plaintext passwords for tens of thousands of organizations. He posted […]

Critical · Jun 18, 2026 · Security Affairs
Read Full Intelligence Brief →
BREACH VERISQ BRIEF 🔑
VERISQ BRIEF 24 billion stolen records exposed online. Here’s what to do

Researchers found an exposed collection of 24 billion stolen records, including usernames, passwords, and other sensitive account data.

Critical · Jun 17, 2026 · Malwarebytes Labs
Read Full Intelligence Brief →
RANSOMWARE VERISQ BRIEF 💀
VERISQ BRIEFUkrainian Extradited from Ireland Pleads Guilty Over Role in Conti Ransomware Scheme

Ukrainian national Oleksii Lytvynenko pleaded guilty in the U.S. for his role in Conti ransomware attacks targeting victims worldwide. Oleksii Oleksiyovych Lytvynenko (44), a Ukrainian national extradited from Ireland to the U.S., has pleaded guilty to conspiracy to commit wire fraud for his involvement in the Conti ransomware operation. Prosecutors said he helped conduct attacks […]

Critical · Jun 14, 2026 · Security Affairs
Read Full Intelligence Brief →
BREACH VERISQ BRIEF 💣
VERISQ BRIEFShinyHunters Uses Oracle Zero-Day to Rampage Higher Ed

A major bug in Oracle's ERP software disproportionately affected American universities, and hackers have capitalized by stealing gobs of data.

Critical · Jun 12, 2026 · Dark Reading
Read Full Intelligence Brief →
BREACH VERISQ BRIEF 🛡️
VERISQ BRIEFSouth Korea hits Coupang with record $409 million fine over data breach

The penalty is the largest ever issued by the commission for a personal data breach, surpassing the record 134.8 billion won ($88.8 million) fine levied against SK Telecom earlier this year.

Critical · Jun 12, 2026 · The Record
Read Full Intelligence Brief →
BREACH VERISQ BRIEF 💣
VERISQ BRIEFOracle PeopleSoft RCE Flaw Used as Zero-Day in Ongoing ShinyHunters Campaign

ShinyHunters exploited a critical Oracle PeopleSoft zero-day to breach over 100 organizations, mostly universities, before a patch was available. Mandiant and Google’s Threat Intelligence Group published an analysis of an active ShinyHunters campaign on June 11, one day after Oracle finally issued an advisory for the vulnerability being exploited. The gap matters: the activity ran […]

Critical · Jun 12, 2026 · Security Affairs
Read Full Intelligence Brief →
BREACH VERISQ BRIEF ☁️
VERISQ BRIEFCalifornia AG sues 23andMe over 2023 breach exposing health data

California Attorney General Rob Bonta filed a lawsuit against 23andMe, now Chrome Holding Co., over the company's failure to protect sensitive customer genetic and personal information. [...]

Critical · May 29, 2026 · BleepingComputer
Read Full Intelligence Brief →
RANSOMWARE VERISQ BRIEF 💀
VERISQ BRIEFThe Gentlemen ransomware: Dissecting a self-propagating Go encryptor

Microsoft Threat Intelligence presents a comprehensive analysis of The Gentlemen, a Go-based ransomware deployed by affiliates of Storm-2697 that combines per-file ephemeral key encryption with an aggressive self-propagation module to deploy itself across an entire network using series of simultaneous lateral movement techniques per target. The post The Gentlemen ransomware: Dissecting a self-propagating Go encryptor appeared first on Microsoft Security Blog .

Critical · May 28, 2026 · Microsoft Security Blog
Read Full Intelligence Brief →
BREACH VERISQ BRIEF 🛡️
VERISQ BRIEFThe LA Metro Attack Wasn’t Hacktivism. It Was a State Operation With a Costume On.

Iran’s “hacktivist” group Ababil of Minab, which hit LA Metro and wiped terabytes of data, is forensically linked to Iran’s intelligence service MOIS. In late March, a group calling itself Ababil of Minab posted videos and screenshots online claiming it had broken into the Los Angeles County Metropolitan Transportation Authority, wiped hundreds of terabytes of […]

Critical · May 27, 2026 · Security Affairs
Read Full Intelligence Brief →
RANSOMWARE VERISQ BRIEF 🏦
VERISQ BRIEFWeekly Update 505

Well, that didn't last long! Recording this on Saturday morning my time, I observed ShinyHunters having gone quiet since the massive haul that would have been the Instructure ransom. It was two weeks almost to the hour since I'd first heard rumour of payment being made,

Critical · May 24, 2026 · Troy Hunt Blog
Read Full Intelligence Brief →
BREACH VERISQ BRIEF 🏛️
VERISQ BRIEFCISA Security Leak

Crazy story : Until this past weekend, a contractor for the Cybersecurity & Infrastructure Security Agency (CISA) maintained a public GitHub repository that exposed credentials to several highly privileged AWS GovCloud accounts and a large number of internal CISA systems. Security experts said the public archive included files detailing how CISA builds, tests and deploys software internally, and that it represents one of the most egregious government data leaks in recent history. News article .

Critical · May 22, 2026 · Schneier on Security
Read Full Intelligence Brief →
BREACH VERISQ BRIEF 🔗
VERISQ BRIEFGitHub, Grafana Labs breaches traced back to TanStack supply chain compromise

GitHub CISO Alexis Wales has named the malicious VS Code extension behind the breach they suffered at the hands of the threat group TeamPCP: Nx Console, a popular developer tool with 2.2 million installs. A malicious version of the otherwise benign extension was used to steal secrets and developer credentials, which were then used to move through CI/CD pipelines and exfiltrate around 3,800 of GitHub’s private code repositories. One missed token, many victims The company … More → The post GitHub, Grafana Labs breaches traced back to TanStack supply chain compromise appeared first on Help Net Security .

Critical · May 21, 2026 · Help Net Security
Read Full Intelligence Brief →
BREACH VERISQ BRIEF 💣
VERISQ BRIEFHuawei zero-day attack behind last year’s crash of Luxembourg's entire telecoms network

There is no evidence that the incident has recurred, but the flaw remains unexplained and has not been publicly acknowledged by the company.

Critical · May 19, 2026 · The Record
Read Full Intelligence Brief →