From SecurityWeek · 40 stories
Coca-Cola's Fairlife Hits U.S. Production Halt Due to Anubis Ransomware Attack
A ransomware attack by the Anubis group has forced Coca-Cola's Fairlife to suspend U.S. production. Hackers claim they extracted 1 TB of data, threatening to release it unless a ransom is paid. The incident raises concerns about cybersecurity in the food and beverage sector.
Hacker Reveals AI Music Generator Suno Breached, Exposing Data Practices
A hacker breached AI music generator Suno, revealing it had scraped millions of songs from platforms like YouTube and Deezer for its training datasets. Exposed user data from over 55 million accounts highlights serious privacy and copyright violation concerns. This incident raises questions about the legality of Suno's dataset usage amidst ongoing lawsuits.
Critical KVM/x86 Vulnerability Allows VM Escape to Host on Intel and AMD
Januscape, a 16-year-old use-after-free vulnerability (CVE-2026-53359) in Linux's KVM hypervisor, allows guest VMs to execute arbitrary code on host systems, compromising host security in multi-tenant environments. Discovered by Hyunwoo Kim, this first-known architecture-independent exploit has been demonstrated in Google's kvmCTF. Cloud providers like Google Cloud and AWS may be particularly vulnerable, posing risks of data breaches.
19-Year-Old Extradited to U.S. for Role in Scattered Spider Hacks
Peter Stokes, a dual U.S. and Estonian citizen, was extradited from Finland to the U.S. to face charges related to hacking activities with Scattered Spider. Notable incidents include a 2025 cyberattack on a luxury jewelry retailer demanding an $8 million cryptocurrency ransom. The extradition underscores efforts to combat global cybercrime.
Chrome 150 Update Addresses 27 Vulnerabilities, Enhances Security
Google released Chrome 150, patching 27 security vulnerabilities, including two critical use-after-free flaws in Ozone and Views. This update is part of a broader effort to improve browser security, with most flaws discovered internally by Google. Regular updates are essential due to frequent exploitation of memory safety vulnerabilities in browsers like Chrome.
US Proposes AI Incident Alert System to China Ahead of Trump-Xi Talks
The U.S. proposed a notification mechanism for AI incidents with national security implications during discussions with China. This initiative aims to increase transparency between the two leading AI powers and sets a precedent for international cooperation on AI risks.
Critical RCE Flaw in Forminator WordPress Plugin Affects 600,000+ Sites
A critical security vulnerability (CVE-2026-15748) in the Forminator Forms WordPress plugin allows unauthenticated attackers to upload malicious PHP files, leading to remote code execution and site compromise. The flaw, rated 9.8 on CVSS, affects over 600,000 active installations and requires specific form configurations for exploitation, but has been patched in version 1.56.2.
Zero Trust Creator Affirms Model's Effectiveness Against AI-Assisted Attacks in New Book
John Kindervag, creator of the Zero Trust model, released a new book asserting that Zero Trust principles remain effective against AI-assisted cyber threats. The book, co-authored with various experts, concludes that AI threats are fundamentally similar to past threats, only faster and more sophisticated, and Zero Trust can mitigate them if correctly implemented.
Microsoft and Partners Dismantle EvilTokens AI Cybercrime Platform, Two Arrested
Microsoft, in collaboration with partners including Health-ISAC, Cloudflare, and OpenAI, has taken down EvilTokens, an AI-powered cybercrime platform. The platform, which offered AI tools for account compromise and financial fraud, led to the arrest of two men, aged 32 and 38, in the UK by the Metropolitan Police Service.
Microsoft sets new Patch Tuesday record with over 650 security fixes for Windows
Microsoft released over 650 security fixes for Windows in its September Patch Tuesday, setting a new record. This increase in patched vulnerabilities is attributed to new AI models, like Anthropic's Mythos and OpenAI's cybersecurity model, which are discovering software flaws at a rapid pace.
Revolut confirms customer data breach via fraudulent government agency requests
Revolut disclosed that an unauthorized third party obtained sensitive customer data by submitting fraudulent requests from a legitimate government agency email domain. The exposed information includes identity details, contact information, and potentially verification selfies, account statements, and transaction histories for a limited number of customers. This incident highlights vulnerabilities in data access protocols, even when dealing with seemingly legitimate government communications.
Trezor Discloses ShipMonk Breach Exposed Data of 67,000 U.S. Customers
Hardware wallet manufacturer Trezor announced that 67,000 U.S. customers had their personal data exposed due to a breach at its shipping provider, ShipMonk. This incident is significant because it adds to previously disclosed exposures and highlights the risks associated with third-party data handling, even after assurances of data deletion.
PaperCut warns of active exploitation of zero-day vulnerability in NG and MF software
PaperCut issued an urgent security advisory regarding a zero-day vulnerability in all versions of its PaperCut NG and PaperCut MF print management software, which is actively being exploited in attacks. The company released emergency patches and advised organizations to restrict access to web interfaces of Internet-exposed servers, as this vulnerability poses a significant risk to affected systems.
Craneware Reports Data Breach Affecting US Hospitals and Pharmacies
Craneware, a UK-based software provider for over 2,000 US hospitals, reported a data breach involving employee and customer information. The breach resulted in the theft of significant data, impacting hospitals' billing and patient management services. The incident has been contained, with investigations ongoing.
Two Berlin State Ministries Disconnected from Government Network Following Security Breach
Two Berlin state ministries, responsible for urban development and mobility, have been isolated from the city government's IT network due to a security breach. This incident has disrupted internal communications and some public services, highlighting vulnerabilities in government IT infrastructure.
Hackers deliver malicious Virtualizor update via BGP hijacking
Hackers used BGP hijacking to redirect traffic for Virtualizor's update infrastructure, delivering malicious updates to a small number of installations. Softaculous, the vendor, released a new Virtualizor version and advised users to check for a malicious service and reset credentials.
Sality P2P Botnet Dismantled After 23 Years of Operation
The Sality peer-to-peer (P2P) botnet, active since 2003, has been disrupted through an international law enforcement effort involving the U.S. Department of Justice, Europol, Eurojust, and private partners like CrowdStrike and the Shadowserver Foundation. The operation, which took place on August 31, 2026, included a P2P sinkhole and domain seizures, effectively neutralizing a long-standing threat that infected over 15,000 devices and distributed various malware, including the EggJagger clipjacking tool.
Boston Scientific reports cyberattack disrupting global operations and order processing
Medical technology company Boston Scientific experienced a cyberattack on August 25 that disrupted its IT systems, causing a network outage and affecting its ability to process and ship customer orders globally. The incident impacts a major medical device manufacturer, potentially affecting the supply chain for critical medical equipment worldwide.
ATF confirms "major incident" after Qilin ransomware group claims breach
The U.S. Bureau of Alcohol, Tobacco, Firearms and Explosives (ATF) confirmed a "major incident" involving a breach of one of its standalone systems, following claims by the Qilin ransomware group. The agency stated that its main enterprise network, eForms system, and other ATF systems were not affected, and operations remain uninterrupted.
Grok AI Vulnerable to Data Exfiltration via Encrypted Malicious Instructions
Researchers discovered a new prompt injection attack against Grok that uses encrypted malicious instructions to bypass guardrails and exfiltrate user data. This method exploits the LLM's inability to distinguish between trusted user input and harmful content, allowing it to steal chat data and personal information.
Ransom Cartel Creator Sentenced to 16 Years for Ransomware-as-a-Service Operation
Maksim Silnikau, the 40-year-old Belarusian creator and administrator of the Ransom Cartel ransomware-as-a-service operation, was sentenced to 16 years in prison in Virginia. Silnikau developed the ransomware and recruited affiliates to attack at least 18 companies globally between 2021 and 2023, providing them with tools and infrastructure for intrusions and ransom negotiations.
SafePal data breach exposes order information for 39,798 customers
Cryptocurrency hardware wallet provider SafePal reported a data breach affecting approximately 39,798 customers, exposing names, email addresses, shipping addresses, phone numbers, and purchase information. A threat actor is now claiming to sell this stolen data on a cybercrime forum. This breach could lead to targeted phishing and social engineering attacks against affected customers.
New 'ShieldBreak' Zero-Day Exploit Bypasses Microsoft Defender Patch, Grants SYSTEM Privileges
Security researcher Nightmare Eclipse released "ShieldBreak," a new zero-day exploit for Microsoft Defender that bypasses a previous patch for the RoguePlanet vulnerability (CVE-2026-50656). This exploit allows SYSTEM privileges on fully updated Windows 10, Windows 11, and Windows Server systems, highlighting an incomplete patch for a privilege escalation flaw.
Mozilla Replaces GPG Signing Key for Firefox and Thunderbird After Accidental Exposure
Mozilla has replaced the GPG signing subkey used for Firefox and Thunderbird Linux tarballs, RPM packages, and checksum files. The previous key was inadvertently committed in an unencrypted copy to a private GitHub repository. This change primarily affects users who manually verify GPG signatures or use Firefox RPM packages on older Linux distributions, who will need to import the new key and the old key's revocation.
UNC6671 Extortion Group Rebrands and Continues Vishing Attacks on Financial Firms
The UNC6671 extortion group has rebranded its operations under new names including Redact, Pink, Helix, and Falcon, despite an alleged retirement of its previous BlackFile brand. The group continues to use voice phishing (vishing) to target enterprise employees, particularly in financial services, private equity, and professional services, leading to data theft from cloud environments like Microsoft 365 and Okta.
Apple Implements Bug Report Caps Due to Surge in AI-Generated Submissions
Apple has introduced a cap on open security reports and a 30-day cool-off period for submissions to its bug bounty program, effective June. This change was made in response to a significant increase in AI-assisted reports, many of which were not genuine vulnerabilities, leading to review teams being overwhelmed. The new policy impacted Italian cybersecurity company Bynario, which used GPT-5.5 to find a critical macOS bug (CVE-2026-43760) but was initially unable to report it due to reaching the submission limit.
Over 24,000 Internet-Exposed Servers Leak BMC Password Hashes via Decades-Old Flaw
More than 24,000 internet-exposed servers are leaking authentication password hashes due to CVE-2013-4786, a 20-year-old vulnerability in the Intelligent Platform Management Interface (IPMI) v2.0 specification. This flaw allows remote attackers to obtain password hashes before login and conduct offline password guessing attacks, potentially leading to full control over physical servers and broader management plane compromise.
Hackers hijack hotel Wi-Fi DNS to steal Microsoft 365 accounts
Hackers are redirecting users to fake Microsoft 365 login pages by changing DNS settings on Wi-Fi devices in hotels and conference centers. This campaign, ongoing since June, affects organizations across various sectors by potentially compromising sensitive business information.
Origin Energy Confirms Customer Data Breach Affecting Personal and Partial Banking Details
Origin Energy confirmed a data breach affecting its 4.8 million customer accounts, compromising personal details and partial banking information. This incident exposes customers to potential identity theft and phishing, highlighting ongoing cybersecurity risks for critical service providers.
Symlink Vulnerability in AI Coding Assistants Poses Security Threat
Researchers discovered that a vulnerability in six AI coding assistants allows malicious repositories to execute code on developers' machines. By exploiting symbolic link (symlink) flaws, attackers could bypass user consent and access sensitive files, raising significant security concerns.
Adobe Acrobat Integration in WhatsApp Web Exposes User Data Through Chrome Extension Vulnerability
Adobe Acrobat tools are now available within WhatsApp Web and Windows app, allowing users to handle PDFs easily. However, a critical vulnerability in the Adobe Acrobat Chrome extension, affecting 329 million users, could enable unauthorized access to WhatsApp Web chats. The flaw has been patched, ensuring data security moving forward.
Researcher Releases Windows Zero-Day Exploit 'LegacyHive' Post-Patch Tuesday
Security researcher Chaotic Eclipse released a zero-day exploit for Windows shortly after Microsoft's Patch Tuesday. The exploit, called LegacyHive, targets the Windows User Profile Service and allows privilege escalation on all supported Windows versions. This revelation underscores ongoing security challenges and may necessitate urgent updates from Microsoft.
US Charges Russians for Operating 'Bulletproof' Hosting Services Linked to $62M in Cybercrime Losses
U.S. prosecutors have unsealed charges against three Russian nationals linked to bulletproof hosting providers Media Land and ML.Cloud. The Russians allegedly supported ransomware attacks through these services, causing over $62 million in damages. A $10 million reward is offered for information leading to their arrests.
Microsoft Patches Windows Defender 'RoguePlanet' Vulnerability CVE-2026-50656
Microsoft has patched the 'RoguePlanet' vulnerability (CVE-2026-50656) affecting Windows Defender on Windows 10 and 11, which allowed SYSTEM privileges escalation. The vulnerability was disclosed by researcher Nightmare Eclipse, and a month later Microsoft released the patch in Malware Protection Engine update version 1.1.26060.3008. The flaw's potential use in privilege escalation makes its resolution important for system security.
Google and FBI Disrupt NetNut Proxy Network of 2 Million Devices
Google, the FBI, Lumen, and others disrupted the NetNut residential proxy network involving over 2 million devices used for malicious activities. The operation disabled command-and-control features, protecting home devices from being exploited. This action significantly reduces cybercriminals' ability to mask their activities using residential IPs.
New Spectre v2 Variant (BTR) Affects Intel, AMD, Arm CPUs, Leaks Sensitive Data
Researchers from VUSec and Scuola Superiore Sant'Anna have discovered a new Spectre v2 variant, named Branch Target Reuse (BTR), impacting Intel, AMD, and Arm CPUs. This vulnerability exploits how processors handle code that changes at runtime, specifically targeting just-in-time (JIT) compilers in web browsers, language runtimes, and operating system kernels. BTR can lead to sensitive data leaks, such as root password hashes from Intel Linux systems, and fixes for CVE-2026-64507 and CVE-2026-64508 have been merged into the Linux kernel.
Former US Soldier Sentenced to 70 Months for Extorting Tech and Telecom Firms
A former U.S. Army soldier received a 70-month prison sentence for hacking and extorting at least 10 U.S. technology and telecommunications companies. He and accomplices stole login credentials, extorted companies for over $1 million, and sold stolen data, impacting sensitive customer records and leading to SIM-swapping fraud.
ShinyHunters Breaches Clop Ransomware Leak Site, Claims Data and Private Key Theft
The ShinyHunters extortion group breached the Clop ransomware operation's data leak site, defacing it and claiming to have stolen server data and the private keys for its onion service. This incident highlights the ongoing conflict between different cybercriminal groups and could impact Clop's future operations if the claims of private key theft are verified.
Rydox Cybercriminal Marketplace Operator Pleads Guilty After Brother's Deportation
Ardit Kutleshi, an operator of the Rydox cybercriminal marketplace, pleaded guilty to aggravated identity theft and money laundering charges. This development follows the deportation of his brother, who was also involved in running the illicit platform that facilitated the sale of stolen personal information and fraud tools.
Ryuk Ransomware Member Sentenced to 24 Months in Prison for Hacking US Companies
Karen Serobovich Vardanyan, a member of the Ryuk ransomware group, received a 24-month prison sentence for hacking US companies and deploying ransomware. Vardanyan specialized in gaining initial access to corporate networks, contributing to attacks that extorted over $15 million in Bitcoin from victims.