// BREACH WATCH

BREACH & RANSOMWARE

Real-time breach and ransomware intelligence for third-party risk management.

Breaches Advisories Vulnerabilities RSS
0
Last 24h
44
Last 7 Days
0
Critical (7d)
All Critical High Medium Low
✕ Clear All
BREACH VERISQ BRIEF 🔗
VERISQ BRIEFOpenAI Agents Linked to RubyGems Campaign That Gained RCE on RubyDoc Servers

The "major malicious attack" that targeted RubyGems in May 2026 was the work of a swarm of OpenAI agents, according to a new report published by researchers Spencer Kitts, Thomas Larsen, and Sydney Von Arx. On May 12, Maciej Mensfeld, senior product manager for software supply chain security at Mend.io, disclosed details of a coordinated cyber attack that targeted the package manager for the

🌐 mend.io
High · Sep 12, 2026 · The Hacker News
Read Full Intelligence Brief →
BREACH VERISQ BRIEF 🛡️
VERISQ BRIEFAI Agents Used in PaperCut Attacks on 395 Organizations

GreyNoise Says Attacker Used Hundreds of Agents in 48-Country Campaign A likely Russian-speaking attacker used hundreds of AI agents to exploit PaperCut systems, compromising at least 440 systems at 395 organizations in 48 countries. GreyNoise said the attacker used the agents to develop exploits, find targets and attack systems in parallel.

High · Sep 11, 2026 · DataBreachToday
Read Full Intelligence Brief →
BREACH VERISQ BRIEF ☁️
VERISQ BRIEFNovo Nordisk Data Breach Tied to Stolen GitHub Access Tokens

Cyber Extortion Group Continues to Target Exposed Cloud-Based Data Over Endpoints Cyber extortion group FulcrumSec continues to find hardcoded credentials in public-facing IT infrastructure and exploit them as part of what it's dubbed a "Hardcoded Horrorshow" that counts Ozempic maker Novo Nordisk among its victims. Here are defenses organizations need to put in place now.

High · Sep 11, 2026 · DataBreachToday
Read Full Intelligence Brief →
BREACH VERISQ BRIEF 🏦
VERISQ BRIEFHackers abused Claude to extract secrets from 1.8M Android apps

Anthropic says multiple threat groups, including the financially motivated and state-sponsored espionage groups linked to Russia and China, tried to abuse its Claude AI model for malicious purposes. [...]

High · Sep 11, 2026 · BleepingComputer
Read Full Intelligence Brief →
BREACH VERISQ BRIEF 🔑
VERISQ BRIEFFlorida says motor vehicle data breach tied to credentials stolen from officer’s personal device

The Florida Department of Motor Vehicles confirmed a data breach claimed by the cybercrime group ShinyHunters, saying it originated with the theft of credentials stored on a police officer's personal device.

High · Sep 11, 2026 · The Record
Read Full Intelligence Brief →
BREACH VERISQ BRIEF 🔑
VERISQ BRIEFFlorida confirms DMV database breached via stolen police account

The Florida Department of Highway Safety and Motor Vehicles (FLHSMV) has confirmed that its DAVID driver database suffered a data breach, saying the attackers gained access using credentials belonging to a police department employee. [...]

High · Sep 11, 2026 · BleepingComputer
Read Full Intelligence Brief →
BREACH VERISQ BRIEF 🎣
VERISQ BRIEFPasskey-themed phishing attacks lead to Microsoft 365 data theft

Microsoft says threat actors linked to ShinyHunters, Helix, and other extortion gangs are using passkey and single sign-on-themed social engineering attacks to compromise corporate Microsoft accounts and steal data from Microsoft 365 services. [...]

High · Sep 11, 2026 · BleepingComputer
Read Full Intelligence Brief →
BREACH VERISQ BRIEF 🎣
VERISQ BRIEFCrypto customers targeted by scammers after email marketing provider breach

A breach at email marketing company Brevo exposed Trezor, CoinTracking, and BitBox customers to phishing emails, but others may also be at risk.

High · Sep 11, 2026 · Malwarebytes Labs
Read Full Intelligence Brief →
RANSOMWARE VERISQ BRIEF 💀
VERISQ BRIEFUkrainian hacker gets four years in US prison over Conti ransomware attacks

A Ukrainian national was sentenced to four years in a U.S. prison for his role in the notorious Conti ransomware operation, which targeted more than 1,000 victims worldwide before shutting down in 2022.

High · Sep 11, 2026 · The Record
Read Full Intelligence Brief →
BREACH VERISQ BRIEF ☁️
VERISQ BRIEFAI agents exploited PaperCut flaws to breach 395 organizations

A threat actor built a working exploit for PaperCut print management software, then handed the job of breaking into hundreds of organizations to AI agents that did most of the work on their own, according to GreyNoise. The result was at least 440 compromised PaperCut instances across 395 identified organizations in 48 countries. Attacker, believed to be Russian-speaking, first built a private lab environment with a vulnerable copy of PaperCut NG/MF and an Active Directory … More → The post AI agents exploited PaperCut flaws to breach 395 organizations appeared first on Help Net Security .

High · Sep 11, 2026 · Help Net Security
Read Full Intelligence Brief →
BREACH VERISQ BRIEF ☁️
VERISQ BRIEFIDScan confirms breach after 153 million driver’s licenses leak on dark web

Days after reports linked IDScan to a dark web database holding more than 153 million driver’s license scans, the identity verification company has confirmed hackers accessed customer data stored on its cloud platform. The Louisiana-based firm, which processes ID checks for car rental companies, retailers and cannabis dispensaries, posted a notice on its website September 4 acknowledging the incident. “On or around September 1, 2026, IDScan.net received information indicating that certain data may have been … More → The post IDScan confirms breach after 153 million driver’s licenses leak on dark web appeared first on Help Net Security .

🌐 idscan.net
High · Sep 11, 2026 · Help Net Security
Read Full Intelligence Brief →
BREACH VERISQ BRIEF 🎣
VERISQ BRIEFTrezor: 347,000 users targeted in phishing attacks after Brevo breach

Trezor has revealed that phishing attacks against its customers earlier this week targeted 347,000 email addresses and affected 2,500 users who clicked an embedded malicious link. [...]

High · Sep 11, 2026 · BleepingComputer
Read Full Intelligence Brief →
RANSOMWARE VERISQ BRIEF 💀
VERISQ BRIEFConti ransomware gang member sentenced to 4 years in prison

A Ukrainian national has been sentenced to four years in prison for his role in Conti ransomware attacks between 2021 and 2022. [...]

High · Sep 11, 2026 · BleepingComputer
Read Full Intelligence Brief →
BREACH VERISQ BRIEF 💣
VERISQ BRIEFBreach Roundup: ShinyHunters Claims Florida DMV Hack

Also, N-Able Patches Critical N-Central Zero-Day, Nightmare Eclipse Zero-Day This week: ShinyHunters claims Florida DMV breach, N-able patch, Bimbo Bakeries breach, French police arrest suspected ZeroBytes hackers, Patch Tuesday, a new Nightmare Eclipse zero-day, Grindr agrees to $35 million U.K. privacy settlement, SAP patch.

High · Sep 10, 2026 · DataBreachToday
Read Full Intelligence Brief →
BREACH VERISQ BRIEF 🛡️
VERISQ BRIEFSurfshark VPN says hackers breached internal testing, proxy servers

Surfshark disclosed that hackers accessed one of its internal test servers after a configuration error exposed it to the internet. [...]

High · Sep 10, 2026 · BleepingComputer
Read Full Intelligence Brief →
BREACH VERISQ BRIEF 🛡️
VERISQ BRIEFCISA’s ChatGPT Incident Exposes a Bigger AI Governance Problem

CISA’s ChatGPT incident exposes a growing AI governance gap as enterprises struggle to define who is accountable for actions taken by AI agents. The post CISA’s ChatGPT Incident Exposes a Bigger AI Governance Problem appeared first on TechRepublic .

High · Sep 10, 2026 · TechRepublic Security
Read Full Intelligence Brief →
BREACH VERISQ BRIEF 🛡️
VERISQ BRIEFIDScan confirms breach after hackers offer 153 million driver’s license scans for sale

A notice dated September 4 but not widely shared shows that IDScan acknowledged a data breach but did not specify how many people were affected.

High · Sep 10, 2026 · The Record
Read Full Intelligence Brief →
BREACH VERISQ BRIEF ☁️
VERISQ BRIEFAI-powered attack exploited PaperCut flaws to hack 395 organizations

A threat actor, likely Russian-speaking, used hundreds of AI agents to develop and launch a global exploitation campaign targeting vulnerable PaperCut NG/MF servers. [...]

High · Sep 10, 2026 · BleepingComputer
Read Full Intelligence Brief →
BREACH VERISQ BRIEF ☁️
VERISQ BRIEFIDScan confirms breach tied to 153 million stolen driver’s licenses

Identity verification company IDScan has confirmed that hackers accessed customer data stored in its cloud platform, days after reports linked the company to a massive database containing more than 153 million driver's license scans. [...]

High · Sep 10, 2026 · BleepingComputer
Read Full Intelligence Brief →
BREACH VERISQ BRIEF 🎣
VERISQ BRIEFAttackers call employees’ personal phones to break into Microsoft 365 accounts

Attackers are calling or texting employees on their personal phones, posing as internal IT staff, in a social engineering campaign that tricks them into handing over access to corporate cloud accounts. Once inside, they pull files and email from Microsoft 365 apps, SharePoint, OneDrive, and inboxes, for weeks at a time, according to Microsoft Security Research. (Source: Microsoft) Researchers have been tracking the campaign since May 2026. Because the initial contact often happens on a … More → The post Attackers call employees’ personal phones to break into Microsoft 365 accounts appeared first on Help Net Security .

High · Sep 10, 2026 · Help Net Security
Read Full Intelligence Brief →
BREACH VERISQ BRIEF ☁️
VERISQ BRIEFPaperCut Attacker Uses Hundreds of AI Agents to Compromise 440+ Instances

A suspected Russian-speaking cyber actor has been attributed to the use of artificial intelligence (AI) to devise exploits targeting a recently disclosed pair of security flaws in PaperCut NG/MF and break into hundreds of instances. According to independent reports from Blackpoint Cyber and GreyNoise, the activity originates from "45.142.193[.]132," an IP address that has been linked to

High · Sep 10, 2026 · The Hacker News
Read Full Intelligence Brief →
BREACH VERISQ BRIEF 🛡️
VERISQ BRIEFA New Claude ‘s Sandbox Failure Shows How AI Can Rationalize Real-World Harm

Claude models compromised real systems during misconfigured security tests, exposing a worrying mix of flawed reasoning, harmful actions and weak safeguards. Anthropic just published one of the more uncomfortable self-assessments a major AI lab has released this year. The company’s alignment report documents four separate incidents in which Claude models broke into real third-party systems […]

High · Sep 10, 2026 · Security Affairs
Read Full Intelligence Brief →
BREACH VERISQ BRIEF 🛡️
VERISQ BRIEFAnthropic Discloses Fourth AI Hacking Incident Involving Claude Opus 4.6

Anthropic on Wednesday disclosed a fourth incident in which its artificial intelligence (AI) model broke into real third-party systems, marking the latest in a growing list of cases that have raised concerns about the security risks posed by autonomous AI agents. The AI company said the incident dates back to January 2026 and involved an early version of Claude Opus 4.6 that breached "

High · Sep 10, 2026 · The Hacker News
Read Full Intelligence Brief →
BREACH VERISQ BRIEF 🎣
VERISQ BRIEFTrezor warns users of email provider breach, phishing attacks

Trezor warned customers on Wednesday that threat actors who breached its third-party email provider are targeting them in phishing attacks. [...]

High · Sep 10, 2026 · BleepingComputer
Read Full Intelligence Brief →
BREACH VERISQ BRIEF 🏥
VERISQ BRIEFMcKesson - 6,404,340 breached accounts

In August 2026, healthcare and pharmaceutical company McKesson was targeted in a ShinyHunters "pay or leak" extortion campaign . The group subsequently published a substantial corpus of data they alleged was sourced from the company, which included 6.4M unique email addresses among other personal and corporate data attributes. The impacted data related to a range of individuals and roles, including marketing campaign recipients, patients, staff and healthcare provider contacts. In McKesson's disclosure notice , the company advised it had identified unauthorised access to "certain third-party applications and the exfiltration of certain data was associated with a subset of customers within our Oncology & Multispecialty and Medical-Surgical business units", but had "reasonable assurance of no ongoing unauthorized activity".

High · Sep 10, 2026 · HIBP Latest Breaches RSS
Read Full Intelligence Brief →
BREACH VERISQ BRIEF 🏥
VERISQ BRIEFAdaptHealth confirms 4.1 million people exposed in July cyberattack

Healthcare company AdaptHealth has confirmed that data of 4.1 million people was exposed in a cyberattack discovered in July that was attributed to the ShinyHunters threat group. [...]

High · Sep 09, 2026 · BleepingComputer
Read Full Intelligence Brief →
BREACH VERISQ BRIEF 🗄️
VERISQ BRIEFDriver’s License Data for Sale

A database of 153 million drivers licenses is for sale on the dark web. Brian Krebs has more detail .

High · Sep 09, 2026 · Schneier on Security
Read Full Intelligence Brief →
BREACH VERISQ BRIEF 💣
VERISQ BRIEFThe Models That Found 10,000 Zero-Days Broke Into Three Companies Using Weak Passwords

The question of whether a Frontier AI model could find vulnerabilities that no human researcher had found was settled in April. Claude Mythos Preview identified thousands of previously unknown flaws across every major operating system and browser, including a 27-year-old denial-of-service condition in OpenBSD, and within a month Anthropic and its Project Glasswing partners had […]

High · Sep 09, 2026 · Qualys Blog
Read Full Intelligence Brief →
BREACH VERISQ BRIEF 🔑
VERISQ BRIEFInfostealer Logs Expose Replayable AI Tokens That Can Bypass MFA

Cybercriminals are hijacking artificial intelligence (AI) user accounts via information stealer logs to create "stolen keys" that grant illicit access to tools from model providers like Google, Anthropic, and others.  Information stealers like Lumma Stealer or Vidar are equipped to harvest a wide range of data from compromised systems. This can include credential, session tokens, and API

High · Sep 09, 2026 · The Hacker News
Read Full Intelligence Brief →
BREACH VERISQ BRIEF 🛡️
VERISQ BRIEFOpenAI Agents Took Over Wiki Site Before Hugging Face Attack

Researchers and OpenAI disagree on whether the earlier incident involving DseWiki was a “hack” that the company did not disclose.

High · Sep 08, 2026 · Dark Reading
Read Full Intelligence Brief →
BREACH VERISQ BRIEF 💀
VERISQ BRIEFHackers Drain $320 Million From Liquid Network, Then Return Most of It

Crypto exchange network Liquid Network lost $320 million overnight, then got most of it back after the hackers demanded a bug fix instead of a ransom Bitcoin’s Liquid Network, a sidechain built by Blockstream and used by dozens of exchanges to move funds faster and more privately than the main Bitcoin blockchain allows, got drained […]

High · Sep 08, 2026 · Security Affairs
Read Full Intelligence Brief →
BREACH VERISQ BRIEF 🛡️
VERISQ BRIEFHackers breach F5 BIG-IP APM devices to deploy Linux rootkit

A Linux rootkit targeting devices in F5 BIG-IP APM environments can intercept PHP file loading and inject a fileless web shell directly into memory, avoiding the need to write malicious code to disk. [...]

High · Sep 08, 2026 · BleepingComputer
Read Full Intelligence Brief →
BREACH VERISQ BRIEF 🗄️
VERISQ BRIEFShinyHunters hackers claim breach of Florida "DAVID" DMV database

The ShinyHunters extortion gang claims it breached an online platform for the Florida Department of Motor Vehicles database known as "DAVID" and stole over 200,000 records about drivers in the state. [...]

High · Sep 08, 2026 · BleepingComputer
Read Full Intelligence Brief →
BREACH VERISQ BRIEF 🏦
VERISQ BRIEFSlim Spider Steals Crypto Custody Secrets From Brazilian Financial Institution

A previously undocumented financially motivated threat actor has been linked to attacks targeting Brazilian financial institutions since at least March 2026. Cybersecurity company CrowdStrike is tracking the Brazil-based activity cluster under the name Slim Spider. "The adversary demonstrates deep operational knowledge of Brazilian financial infrastructure, including the instant payment

High · Sep 08, 2026 · The Hacker News
Read Full Intelligence Brief →
BREACH VERISQ BRIEF 🛡️
VERISQ BRIEFLiquid Hackers Return 3,400 Bitcoin Taken via Elements Bug, Still Holding $47M in BTC

Whoever took nearly 4,000 bitcoin from the Liquid Network on Sunday, September 6, returned 3,400 of it the next day, Bitcoin's public record shows. About 598.5 bitcoin has not come back. Liquid is a Bitcoin sidechain that holds real bitcoin to back a token called L-BTC. The network is still paused, so holders cannot turn that token back into bitcoin. The 3,400 bitcoin was sent to a&

High · Sep 08, 2026 · The Hacker News
Read Full Intelligence Brief →
BREACH VERISQ BRIEF ☁️
VERISQ BRIEFGrindr settles HIV status data-sharing lawsuit for $35 million

Grindr has settled a UK lawsuit alleging that it shared sensitive user data, including HIV status, with advertising companies.

High · Sep 08, 2026 · Malwarebytes Labs
Read Full Intelligence Brief →
BREACH VERISQ BRIEF 🏛️
VERISQ BRIEFCybercriminals Hack Brazilian Government Servers to Host Phishing Sites

A Chinese-language group is compromising government and education sites to create a reverse-proxy network with gambling-themed sites.

High · Sep 08, 2026 · Dark Reading
Read Full Intelligence Brief →
BREACH VERISQ BRIEF 🎣
VERISQ BRIEFTrezor customers hit with phishing calls and letters after shipping-partner breach

Roughly 67,000 more customers of SatoshiLabs, the maker of hardware crypto-wallet Trezor, are at heightened risk of phishing attacks after their names, email addresses, phone numbers, and shipping addresses were exposed. “The leaked information could be used for scam emails, fraudulent calls or letters, and could potentially expose affected individuals to physical security risks,” the Czech-based company confirmed in an update on the August 2026 data breach at ShipMonk, the firm that ships Trezor wallets … More → The post Trezor customers hit with phishing calls and letters after shipping-partner breach appeared first on Help Net Security .

High · Sep 08, 2026 · Help Net Security
Read Full Intelligence Brief →
BREACH VERISQ BRIEF ☁️
VERISQ BRIEFGrindr to Pay £26 Million to Settle U.K. Claims Over HIV Status Data Sharing

Online dating app Grindr has opted to pay £26 million ($35.1 million) to settle a lawsuit in the U.K. over allegations that it shared users' personal information, including their HIV status, with third-parties. Grindr, which is the largest LGBTQ+ dating app, was sued in April 2024, accusing it of violating U.K. privacy laws by sharing sensitive data for commercial purposes such as advertising.

High · Sep 08, 2026 · The Hacker News
Read Full Intelligence Brief →
BREACH VERISQ BRIEF 💀
VERISQ BRIEFCondé Nast Data of 32.8 Million Users Offered for Sale After WIRED Leak

Condé Nast user data from 32.8 million accounts is reportedly for sale, raising risks of targeted phishing, fraud and scams. A database said to contain 32.8 million Condé Nast user records is being offered for $15,000 on a Russian-language cybercrime forum. Ransomnews reviewed a 5,000-record sample and concluded that it is consistent with genuine Condé […]

High · Sep 07, 2026 · Security Affairs
Read Full Intelligence Brief →
BREACH VERISQ BRIEF 🛡️
VERISQ BRIEFHow a hole in Lenovo’s login system let hackers walk into 5,000 Dropbox accounts

If you ever linked your Dropbox account to a Lenovo ID - perhaps to make life easier when logging in via a Lenovo laptop - you might want to take heed. Read more in my article on the Hot for Security blog.

High · Sep 07, 2026 · Graham Cluley
Read Full Intelligence Brief →
BREACH VERISQ BRIEF 🛡️
VERISQ BRIEFA week in security (August 31 – September 6)

Last week on Malwarebytes Labs: Stay safe!

High · Sep 07, 2026 · Malwarebytes Labs
Read Full Intelligence Brief →
BREACH VERISQ BRIEF ☁️
VERISQ BRIEFAttackers Breached JetBrains Cadence via Unpatched TeamCity, Extracting AWS Credentials

JetBrains is urging Cadence users to revoke and rotate all credentials following a security incident last month in which unidentified threat actors exploited a recently disclosed critical vulnerability in TeamCity to breach its own environment. "Cadence users should immediately revoke or rotate all credentials and secrets that may have been used to run their Cadence executions," JetBrains said.

High · Sep 05, 2026 · The Hacker News
Read Full Intelligence Brief →
BREACH VERISQ BRIEF 📧
VERISQ BRIEFTrezor Says ShipMonk Breach Exposed 67,000 U.S. Customers' Data It Said Was Deleted

Hardware wallet manufacturer Trezor on Friday disclosed that another 67,000 customers from the U.S. have been impacted in a breach at its shipping provider ShipMonk. The exposed information includes customer names, email addresses, phone numbers, shipping addresses, and order numbers between November 2019 and August 2021. The breach does not affect the security of the company's hardware wallets

High · Sep 05, 2026 · The Hacker News
Read Full Intelligence Brief →
BREACH VERISQ BRIEF 🔑
VERISQ BRIEFCrooks Behind Manchester Airports Group Hack Leaked Data of 8.8 Million People

Manchester Airports Group (MAG) data allegedly leaked by FulcrumSec exposes emails and phone numbers of 8.8 million people. Manchester Airports Group, which operates Manchester, London Stansted and East Midlands airports, has confirmed a data breach involving customer information held in a third-party database. The company says airport operations, passenger safety and aviation security were not […]

High · Sep 04, 2026 · Security Affairs
Read Full Intelligence Brief →
BREACH VERISQ BRIEF ☁️
VERISQ BRIEFIDScan sued over alleged data breach affecting 153 million drivers

Multiple lawsuits have been filed against identity verification company IDScan after hackers allegedly breached the service and offered to sell more than 153 million driver's licenses. [...]

High · Sep 04, 2026 · BleepingComputer
Read Full Intelligence Brief →