Find notable cyber news and cases, enriched with sources, timelines, and signals.

Recent notable Happenings and Cases

Hide ▲
Last updated: 02:20 02/09/2026 UTC
Last updated: 22:05 01/09/2026 UTC

Latest updates

Browse →

U.S. and Canadian drivers-license scans for sale on Nexus

Data Leak

Updated: 02.09.2026 01:40 · First: 02.09.2026 01:40 · 📰 1 src / 1 articles · H score: 76

The Nexus dark web service is selling 153 million+ drivers-license scans from people in the United States and Canada, exposing highly sensitive identity documents to buyers and increasing fraud and impersonation risk. The listings also include other identity documents, suggesting a broader cache of personal and government-issued records. The scale and resale format make the exposure immediately valuable to criminals and dangerous to affected individuals.

FBI New Orleans official investigation into idscan.net breach

Law Enforcement

Updated: 02.09.2026 01:40 · First: 02.09.2026 01:40 · 📰 1 src / 1 articles · H score: 62

The FBI New Orleans field office opened an official investigation into an apparent breach involving idscan.net, putting law-enforcement scrutiny on the source of the stolen license images. The inquiry comes as a dark web service is selling large volumes of identity-document scans tied to people in the United States and Canada.

Faronics Deploy adds anti-abuse measures after confirmed abuse

Security Tool/Service

Updated: 01.09.2026 23:53 · First: 01.09.2026 23:53 · 📰 1 src / 1 articles · H score: 34

Faronics tightened Faronics Deploy with additional anti-abuse measures after confirming malicious use of the platform, reducing abuse activity across the service. The response matters because the platform’s remote-deployment features were being used to obtain unauthorized administrative control and stage further access on endpoints.

Faronics Deploy phishing campaign to install ScreenConnect

Campaign

Updated: 01.09.2026 23:53 · First: 01.09.2026 23:53 · 📰 1 src / 1 articles · H score: 34

A phishing campaign is abusing Faronics Deploy to enroll victim endpoints and install ConnectWise ScreenConnect, giving attackers remote administrative control and a separate remote-access channel. The activity ran from July 21 to August 20 and used invoice and tax-document lures that reached more than 457 endpoints. Faronics later confirmed the abuse and added anti-abuse measures.

Aesto Health patient data breach

Data Leak

Updated: 01.09.2026 22:28 · First: 01.09.2026 22:28 · 📰 1 src / 1 articles · H score: 73

Aesto Health disclosed a data breach affecting 9,540,683 individuals, creating a major identity-theft and medical-fraud risk from exposed patient records. The intrusion reached a limited portion of AWS infrastructure in December 2025 and was confirmed internally on May 26, 2026. The exposed data included names, dates of birth, medical information, financial account numbers, government IDs, and Social Security numbers.

Aesto LLC operating as Aesto Health hit by network compromise

Incident

Updated: 01.09.2026 22:28 · First: 01.09.2026 22:28 · 📰 1 src / 1 articles · H score: 68

Aesto Health disclosed a breach of a limited portion of its Amazon Web Services infrastructure, exposing protected health information tied to 9,540,683 people. The intrusion occurred in December 2025 and was later confirmed on May 26, 2026 after forensic review. The compromised records included names, dates of birth, medical information, financial account numbers, government IDs, and Social Security numbers. The event also created downstream privacy risk for 29 healthcare providers that relied on the service.

US Coast Guard establishes Maritime Cybersecurity Policy office

Public Sector Action

Updated: 01.09.2026 21:26 · First: 01.09.2026 21:26 · 📰 1 src / 1 articles · H score: 28

The US Coast Guard established the Office of Maritime Cybersecurity Policy (CG-MCP) to centralize cyber policy, compliance, and enforcement coordination for the Marine Transportation System. The new office gives maritime cybersecurity a dedicated government authority as ports, vessels, and critical infrastructure face rising operational technology risk. It also creates a single liaison point for industry and other agencies on maritime cyber matters.

Langflow code validator RCE flaw (CVE-2026-0768)

Vulnerability

Updated: 01.09.2026 15:07 · First: 01.09.2026 15:07 · 📰 2 src / 2 articles · H score: 81

Langflow is being hit by active exploitation of CVE-2026-0768, a critical RCE flaw in the code validator of its custom component editor that can let an attacker run code as root without authentication. The vulnerability affects all Langflow releases up to 1.4.2 and is already being used for reconnaissance and credential harvesting. The exploitation activity raises the risk for exposed Langflow deployments that have not been hardened or remediated.

JFrog Artifactory actively exploited authentication bypass (CVE-2026-82329)

Vulnerability

Updated: 01.09.2026 20:53 · First: 01.09.2026 20:53 · 📰 1 src / 1 articles · H score: 56

CVE-2026-82329 is a critical authentication bypass in JFrog Artifactory that can let unauthenticated network attackers gain administrative privileges under default configuration. JFrog patched the flaw in Artifactory 7.161.20 on August 28, 2026, and the issue affects multiple self-managed release lines. The weakness sits in JFrog Access, where attackers can abuse credential-handling logic to mint admin-level access.

JFrog Artifactory CVE-2026-82329 exploitation wave

Exploitation Wave

Updated: 01.09.2026 20:53 · First: 01.09.2026 20:53 · 📰 1 src / 1 articles · H score: 56

Threat actors are conducting an active exploitation wave against JFrog Artifactory systems through CVE-2026-82329, turning an authentication bypass into administrative access. The abuse began days after public disclosure and is focused on internet-exposed instances. Attackers are already using the flaw to mint admin tokens and enumerate users, groups, credential sets and federated access topologies. The rapid post-patch weaponization raises the risk of downstream tampering in software supply chain environments.

Breeze Comet Brazil-based e-crime cluster with alias overlap and payment-fraud monetization

Threat Actor Meta

Updated: 01.09.2026 20:19 · First: 01.09.2026 20:19 · 📰 1 src / 1 articles · H score: 27

Researchers have profiled Breeze Comet as a Brazil-based e-crime group with overlapping aliases and a monetization model centered on fraudulent transfers. The cluster's activity links it to Brazilian financial services, retail, and e-commerce targets, widening exposure across payment and banking workflows. Its operating model combines payment-system abuse, banking-software manipulation, and access to internal transaction environments, raising direct financial-loss risk. Alias overlap across UNC5669, Plump Spider, and SHADOW-AETHER-064 strengthens cross-vendor attribution and ecosystem tracking.

Breeze Comet Brazilian payment-system fraud campaign

Campaign

Updated: 01.09.2026 20:19 · First: 01.09.2026 20:19 · 📰 1 src / 1 articles · H score: 32

Breeze Comet has been conducting a financial intrusion campaign against Brazilian financial services, retail, and e-commerce organizations since 2024, putting payment systems and banking software at risk. The operation uses password spraying, IT-support impersonation, AnyDesk and other RMM tools, and JBoss AS web shells to reach internal environments and manipulate transactions. It has already enabled fraudulent transfers and hundreds of fraudulent transactions, making the campaign a direct threat to banks, payment processors, retailers, exchanges, and fintech providers.

COBALTSPIN Rust routing malware and network tunneling activity

Malware Activity

Updated: 01.09.2026 20:19 · First: 01.09.2026 20:19 · 📰 1 src / 1 articles · H score: 24

COBALTSPIN is being used as a Rust-based routing malware and network tunneler to preserve covert access to financial API infrastructure. The malware is deployed during lateral movement after unauthorized RDP sessions and commands over SMB network file shares. It also sets up a reverse SOCKS5 proxy over WebSocket to move traffic between command infrastructure and internal targets. That behavior helps maintain reach through boundary firewalls and sustain post-compromise access.

Softaculous hit by network compromise

Incident

Updated: 01.09.2026 17:45 · First: 01.09.2026 17:45 · 📰 1 src / 1 articles · H score: 10

Softaculous confirmed that Virtualizor update traffic was diverted in a BGP hijacking attack, allowing a malicious update package to reach a small number of installations. The compromise affected the update path and client/billing portal during August 28-30, creating a supply-chain risk for hosting providers. The vendor says the affected set was a handful of servers, and administrators were told to check for unauthorized service installation and credential misuse. Routing has since been restored and a new Virtualizor 3.2.9.9 release was issued with added defenses.

Novocure employee and patient data exposure

Data Leak

Updated: 01.09.2026 17:28 · First: 01.09.2026 17:28 · 📰 1 src / 1 articles · H score: 71

Novocure exposed employee and patient data in a mid-August cyberattack, affecting more than 1,400 U.S. cancer patients and an undisclosed number of employees. The exposed records included ID numbers for the patients and job titles and phone numbers for employees. Novocure said medical treatment devices were not accessed and its systems remained functional, but the exposure still created privacy and notification obligations.

Novocure hit by network compromise

Incident

Updated: 01.09.2026 17:28 · First: 01.09.2026 17:28 · 📰 1 src / 1 articles · H score: 62

Novocure confirmed a mid-August cyberattack that involved unauthorized access to its systems and exposed patient and employee information. More than 1,400 U.S. cancer patients had ID numbers accessed, and fewer than 50 western U.S. patients also had identifying and provider contact details exposed. The company said medical treatment devices were not accessed and its systems remained fully functional, but notification reviews are still underway.

Nimbus Manticore LinkedIn recruiter-persona cyber espionage campaign

Campaign

Updated: 01.09.2026 16:08 · First: 01.09.2026 16:08 · 📰 1 src / 1 articles · H score: 35

Nimbus Manticore has expanded a LinkedIn recruiter-persona campaign that uses trojanized coding challenge archives to deliver malware to technical targets. The operation is aimed at critical sectors across the Middle East and Africa and is built for cyber espionage, not one-off theft. Its cross-platform payloads, including NodeRabbit and PollCat, increase risk for Windows, Linux, and macOS developer systems.

NodeRabbit and PollCat cross-platform RAT activity

Malware Activity

Updated: 01.09.2026 16:08 · First: 01.09.2026 16:08 · 📰 1 src / 1 articles · H score: 22

The discovery of NodeRabbit and PollCat adds two previously undocumented cross-platform RATs to Nimbus Manticore's toolset, widening risk across Windows, Linux, and macOS. The malware is delivered through LinkedIn and job-search spear phishing that uses trojanized coding challenge archives, with NodeRabbit first seen in Afghanistan and later on systems in Egypt and Ethiopia. The implants use Azure-hosted C2 and OS-specific persistence while enabling host enumeration, shell execution, and file access.

White House launches Project Watershed 250 Texas pilot

Public Sector Action

Updated: 01.09.2026 15:45 · First: 01.09.2026 15:45 · 📰 1 src / 1 articles · H score: 23

The White House launched Project Watershed 250, a six-month pilot in Texas that gives water and wastewater utilities cybersecurity support at no cost. The program targets critical infrastructure that has faced rising cyber pressure and is meant to strengthen defenses for providers that often lack resources. It also creates a model for possible expansion to other states and rural communities.

Microsoft security patch release for CVE-2026-62911

Security Patch Release

Updated: 01.09.2026 15:38 · First: 01.09.2026 15:38 · 📰 1 src / 1 articles · H score: 32

Microsoft patched CVE-2026-62911 in Exchange Server 2016, Exchange Server 2019, and Exchange Server Subscription Edition (SE) during the August 2026 Patch Tuesday. The update closes a high-severity authentication bypass that could let an attacker take over user mailboxes and access email content and attachments. The release is urgent because exploit code is already reported online and exposed servers remain unpatched.

Microsoft Exchange Server 2016/2019/SE authentication bypass (CVE-2026-62911)

Vulnerability

Updated: 01.09.2026 15:38 · First: 01.09.2026 15:38 · 📰 1 src / 1 articles · H score: 29

An authentication bypass in Microsoft Exchange Server 2016/2019/SE leaves about 21,899 exposed servers at risk of mailbox takeover. The flaw is tracked as CVE-2026-62911, and Microsoft patched it in the August 2026 Patch Tuesday. Exploit code is already reported online, increasing urgency for operators that have not yet installed the update.

Claude-assisted porting of a WAGO 750-852 RCE exploit to WAGO 750-831

Technical Analysis

Updated: 01.09.2026 15:37 · First: 01.09.2026 15:37 · 📰 1 src / 1 articles · H score: 14

Forescout’s Vedere Labs showed that Anthropic’s Claude could adapt a working RCE exploit from WAGO 750-852 to the related WAGO 750-831, increasing concern that adjacent OT targets can be escalated with AI-assisted experimentation. The exercise moved beyond simple proof of vulnerability and into controlled payload development, highlighting how PLC exploit porting can become faster once the initial analysis barrier is crossed. A later attempt to extend the work into a command-and-control implant went further and bricked the PLC, underscoring the operational risk of aggressive payload iteration. The effort also consumed hundreds of dollars and more than eight hours, showing that the workflow was slow but still practical enough to watch closely.

Five Venezuelans plead guilty in U.S. ATM jackpotting case

Law Enforcement

Updated: 01.09.2026 12:15 · First: 01.09.2026 12:15 · 📰 1 src / 1 articles · H score: 29

Five Venezuelan nationals pleaded guilty in a U.S. ATM jackpotting case, resolving a cybercrime prosecution tied to attempted malware-driven cash theft from ATMs. One defendant has already received a nine-month prison sentence, while the others remain pending sentencing. The case also follows December 2025 arrests after failed malware installation attempts in Kansas.

METR agent orchestration dashboard fail-open authentication security flaw

Vulnerability

Updated: 01.09.2026 12:05 · First: 01.09.2026 12:05 · 📰 1 src / 1 articles · H score: 32

A fail-open authentication vulnerability in METR’s agent orchestration dashboard exposed the system to the public internet for several days, creating unauthorized-access risk. The dashboard was meant to sit behind Google authentication, but the flaw silently disabled that control. METR said no sensitive information is believed to have been accessed, but the exposure left a public-facing management surface reachable by outsiders.

METR hit by network compromise

Incident

Updated: 01.09.2026 12:05 · First: 01.09.2026 12:05 · 📰 2 src / 2 articles · H score: 31

METR disclosed a March 2026 incident in which attackers stole an API key for public-model inference and consumed a substantial amount of credits, creating unauthorized usage and potential cost exposure. The compromise involved a publicly accessible EC2 instance whose authentication failed open, exposing the orchestration dashboard for days. METR said no sensitive information is believed to have been accessed, but the stolen credentials enabled three weeks of abuse that could have generated about $600,000 in charges.

GuardBreaker VBS prompt injection trips LLM safety mechanisms in UAC-0099 malware

Technical Analysis

Updated: 01.09.2026 11:26 · First: 01.09.2026 11:26 · 📰 1 src / 1 articles · H score: 23

GuardBreaker is a prompt-injection technique that uses a VBS comment to trigger LLM safety refusals, disrupting malware triage and scanner workflows. The method was observed in UAC-0099 tooling and is aimed at preventing AI-assisted analysis from reaching the rest of the script. That raises the risk of false refusals, truncated parsing, and missed payload discovery in automated review pipelines.

UAC-0099 malicious VBS script delivering MATCHBOIL

Malware Activity

Updated: 01.09.2026 11:26 · First: 01.09.2026 11:26 · 📰 1 src / 1 articles · H score: 20

A UAC-0099 malicious VBS script now extends the malware chain by downloading and installing MATCHBOIL, a loader used to stage additional payloads against a target in Ukraine. The script also embeds a prompt-like comment meant to disrupt AI-assisted analysis and interfere with automated triage. The activity shows how a loader delivery path can be paired with analysis-evasion content inside the same payload.

McKesson customer data exfiltration via third-party applications

Data Leak

Updated: 01.09.2026 11:25 · First: 01.09.2026 11:25 · 📰 1 src / 1 articles · H score: 81

McKesson confirmed unauthorized access to third-party applications and exfiltration of data tied to a subset of customers, raising the risk of exposure across its oncology and medical-surgical business lines. The affected data was linked to Oncology & Multispecialty and Medical-Surgical customers, and the investigation was first disclosed on August 28 before being confirmed the next day. A threat actor calling itself ShinyHunters claimed responsibility on a leak site, while outside reports suggested as many as 284 million records and a $55m ransom demand. McKesson said there was no ongoing unauthorized activity in its corporate network and that customer service remained unaffected.

PaperCut customer confirmed compromise incidents

Incident

Updated: 27.08.2026 19:31 · First: 27.08.2026 19:31 · 📰 2 src / 4 articles · H score: 41

PaperCut NG and PaperCut MF are under active zero-day exploitation, with confirmed customer incidents affecting all versions of the print management software. PaperCut released emergency patches for v25 and v26 and urged operators of Internet-exposed Application Servers to restrict access to trusted IP addresses immediately. The company shared indicators of compromise tied to suspicious activity from pc-app.exe and server.log files that are missing, truncated, or deleted. The investigation is ongoing, and PaperCut has not identified the flaw, the attackers, or any post-compromise actions.

Tectonic cryptocurrency lending platform hit by cyberattack

Incident

Updated: 31.08.2026 23:47 · First: 31.08.2026 23:47 · 📰 1 src / 1 articles · H score: 54

The Tectonic lending platform on Cronos suffered a price-manipulation exploit that let an attacker borrow $74 million in assets and caused major losses. Cronos halted and then restored the chain after the incident, keeping the platform under investigation and increasing concern about DeFi collateral manipulation.