MyCyber News
Your daily cybersecurity news feed in one view.Curated, concise, and connected.
Your daily cybersecurity news feed in one view.Curated, concise, and connected.
Last feed pull: Sep 24, 2026, 2:02 AM (UTC+3)
Topic · Breaches & Ransomware
Socket identified a Firefox extension that ships with no hardcoded malicious code and fetches a remote payload after installation to silently automate Google account takeover, targeting Portuguese- and Spanish-speaking users since September 11, 2026. Socket's Threat Research team identified a malicious Firefox extension posing as a utility for identity verification before opening protected PDF documents. The extension, pdf-para-texto@extensao. local , was published to the Firefox Add-ons store on September 3, 2026, and its malicious functionality was first introduced in version 1. 4 on September 11, 2026. The extension does not have a significant user base, and the expected impact is fairly low.
A new dedicated leak site by threat actors calling themselves “The Seven Deadly Sins” lists Canva Pty Ltd among the sites that haven’t paid them. DataBreaches obtained additional details on the incident and this new group. Attack on Canva A spokesperson for The Seven Deadly Sins (TSDS) informed DataBreaches that on August 28, TSDS attacked… Source https://databreaches.net/2026/09/23/canva-hacked-via-vendors-salesforce-instance-other-customers-affected-as-well/1post-1participantReadfulltopic
OnTrac is a major last-mile e-commerce delivery company formed by the 2021 merger of LaserShip and OnTrac. It positions itself as a direct alternative to FedEx and UPS, offering coast-to-coast coverage, 7-day-a-week operations, and competitive rates to reach over 75% of the U. S. population. We hold your full employee database, 197k records of employee PII: employeeNumber,xrefCode,firstName,middleName,lastName,loginId,employeeId,hireDate,originalHireDate,startDate,terminated,roles,legalEntity,legalEntityAddress,homePhone,mobilePhone,businessPhone,businessMobile,pager,personalFax,personalEmail,businessEmail,facebook,linkedin,addressPrimary1,addressPrimary2,addressMailing1,addressMailing2,userApproved,nativeAuth,culture We demand an amount of 1 million, otherwise your data WILL be publicly posted. Instructions will be emailed to you shortly.
ShinyHunters claims to have breached FBI systems. CLOSEDQUORUM malware delegates command-and-control decisions to commercial LLMs. An IT error erases 11 years of hospital maternity data. F5 patches a critical BIG-IP APM zero-day. Ransomware activity remains high. Microsoft disrupts the EvilTokens cybercrime platform. Researchers turn Claude Code’s normal workflow against itself. Pundits propose an AI Assurance Compact. A Ryuk ransomware gang member gets two years prison time. Our guest is Jen Sovada, General Manager of Public Sector at Claroty, on Project Watershed 250 and the challenges facing U. S. water utilities. Meta’s Muse mettles with messages. Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you’ll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn.
Nearly nine out of 10 federal civilian executive branch agencies failed to meet last summer’s deadline to implement cloud security directives from the Cybersecurity and Infrastructure Security Agency, a watchdog report published Wednesday found. The conclusions from those results, according to the inspector general for the Department of Homeland Security: agencies “may encounter elevated security exposures that undermine the national cloud security posture and increase the likelihood of preventable cyberattacks and related threat,” and “CISA lacks the authority necessary to require full and timely implementation of Binding Operational Directives,” or BODs. The latter is a question that has surfaced before about CISA directives, which the agency uses to pressure agencies into improving their cyber defenses.
Abtach Ltd. was renamed Intersys Ltd. —a Pakistani company engaged in fraud targeting the US. The company’s employees charged fees for services that did not actually exist. The company’s founder, Azneem Bilwani, was involved in the illicit trafficking of synthetic opioids and fentanyl analogues, which were supplied to the US market via the eWorldTrade marketplace. We encrypted all virtual machines and snapshots on their ESXi hypervisors and all files on employee computers, and exfiltrated 1. 5 TB of data from their infrastructure. We possess all their documents and bank records, which contain evidence of Azneem Bilwani’s illegal activities. Will be published soon... • Severity: HIGH • Size: 1.5 TB • Status: selling • $100,000
The potentially serious breach highlights the supply chain risks facing even the most sophisticated organizations.
Overview Imprivata Enterprise Access Management (EAM), an authentication and single sign-on platform for enterprise and clinical environments, contains a vulnerability in versions 26. 2. 6 and below. The product provides no supported mechanism to rotate its RSA key pair after deployment, meaning the same key pair is used indefinitely to generate the appliance's X. 509 certificate. Description CVE-2026-82356 Imprivata EAM uses an RSA key pair to generate the X. 509 certificate that identifies the appliance to the clinical workstations, Electronic Health Record (EHR) platforms, and shared-device workflows that rely on it for authentication. After reviewing the product documentation and engaging Imprivata support, it was confirmed that no supported mechanism exists to rotate this RSA key pair after deployment.
[AI generated] N/A I don't have reliable, verified information about a specific company operating at "goldstarfinancial. com." There are multiple businesses that have used similar "Gold Star Financial" naming conventions in different jurisdictions (this is a fairly generic name used by mortgage brokers, lending companies, and financial services firms in various countries), so I cannot confidently confirm which specific entity this domain refers to, its current operational status, ownership, or verified business details without risking inaccurate attribution. If you can provide additional context (such as the specific country, registration details, or services advertised on the site), I can help assess it more accurately.
Tomix – Indústria de Equipamentos Agrícolas e Industriais, Lda. is a Portuguese manufacturer of crop-protection equipment, best known for agricultural sprayers, atomizers, dusters and related machinery. Founded in 1924 near Torres Vedras by Francisco Xavier Damião, it grew into a market leader in Portugal for plant-treatment equipment, including rotomoulded tanks and high-pressure washers. Since 1997 Tomix has been majority-owned by JOPER – Indústria de Equipamentos Agrícolas, S. A. , and today it operates as part of the family-run JOPER Group alongside JOPER and Ribatejo. Together they supply complementary agricultural machinery for transport, soil tillage and crop treatment across Iberia and export markets https://tomix. com. pt/
Open-Source AI Agents Breach 27 Companies, Steal 600,000 Credit Card Records Hackread
A 35-year-old Armenian national was sentenced to two years in prison for his involvement in a series of Ryuk ransomware attacks while living in Ukraine and Russia in 2019 and 2020, the Justice Department said Tuesday. Karen Vardanyan was extradited from Ukraine to the United States last year and pleaded guilty to computer fraud and conspiracy to commit fraud and extortion in July. Vardanyan’s sentencing, which also calls for about $1. 2 million in restitution to victims, matches terms of a plea agreement he reached with prosecutors. Vardanyan and his co-conspirators’ victims include a Michigan-based company that paid a ransom of nearly $1.2 million in January 2020, a Watsonville, Oregon-based technology company that was attacked in December 2019 and a Texas-based school breached in February 2020, according to court records.
Vestfrostsolutions.com The company sells reliability and precision — back bar coolers for Red Bull, ...
Legis Legis is a well-known Latin American publisher that creates specialized legal and business information resources. Founded over 60 years ago, the company serves professionals across six countries including Colombia, Venezuela, Argentina, Mexico, Peru, and Chile. DATABASES (SQL)PST/OSTLEGAL DOCUMENTS:Tutela - constitutional actions with claimants' personal dataID card copies (cedulas) of shareholders and third partiesEnvironmental sanction proceedings against the company (AUTO 10852)Sanction dispute with the pension authority (UGPP)Signed cease & desist - trademark dispute (Xpandia case)Personal data transfer agreements (Colsubsidio, Universidad Externado)Litigation log of all company lawsuitsContract matrix, payment agreements, reorganization documentsFINANCE & OWNERSHIP:Shareholder and ultimate-beneficial-owner register with ID copiesOwnership structure: ~99.
Asyad Group is Oman’s global integrated logistics provider, ranked 4th on Forbes’ “10 Biggest Logistics Companies in MENA” list.
An Armenian national and member of the Ryuk ransomware gang was sentenced to two years in federal prison for his role in launching attacks.
Revenue: 4K Users Trump Mobile is an American mobile virtual network operator (MVNO) that uses a licensed brand from the Trump Organization and was launched by Donald Trump Jr. and Eric Trump. THEY GOT FKED LOL. ONLY 4K USERS? LOL Includes eSIM QR codes and user PII.
The ShinyHunters cybercriminal organization on Tuesday replaced agency images on the FBIjobs.gov site with a photo of a Pokemon that has become the group’s defacto mascot.
ShinyHunters claims FBI breach via PeopleSoft zero-day, steals staff data; FBI investigating, no confirmation yet. The popular cybercrime group ShinyHunters is claiming that it breached the U. S. Federal Bureau of Investigation (FBI) and stole sensitive information belonging to FBI employees and job applicants. The group says the operation was not financially motivated and was instead carried out in response to an FBI warning published earlier this year. The claim surfaced on September 22 and quickly drew attention after ShinyHunters said it had obtained data on a large number of current and former FBI personnel. The group reportedly offered a sample of around 5,000 records as evidence and claimed that the stolen information could include names, addresses, phone numbers, Social Security numbers, assignments and, in some cases, family details.
Network Solutions has launched Dark Web Monitoring, a new security capability that alerts small businesses when information associated with their domain appears in known breach data and provides steps they can take to reduce risk. Stolen credentials and other information exposed in data breaches can circulate across dark web marketplaces, forums and other sources. For a small business, that exposure can lead to account takeovers, compromised email, impersonation and unauthorized access to sensitive business or … More → The post Network Solutions Dark Web Monitoring alerts small businesses to domain-linked data exposure appeared first on Help Net Security .
Latvian police arrested a 23-year-old man suspected of hacking at least two companies, stealing personal information and attempting to extort money from the victims.
Extortion group ShinyHunters is not afraid to make enemies. Now it claims to have breached the FBI. After reportedly taking over ransomware group Clop’s leak site , ShinyHunters says it attacked the FBI to punish the agency for spreading what it calls false information about the group. In a very long post on its leak site, the group outlines its grievances: “ PSA – READ THIS NOW Dear Assistant Director Brett Leatherman of the FBI Cyber Division & Director Kash Patel of the FBI, During Quarter Two of this year the Federal Bureau of Investigation (FBI) made substantial false allegations regarding our organisation in a FLASH report. We have been severely offended. We were very disappointed to see an agency of your standing would resort to such circulation of disinformation in an attempt to “disrupt” our operations, an effort that ultimately proved unsuccessful.
A total of 1073 firms fell victim to ransomware attacks globally in August, with the industrial sector the most affected, according to new NCC data
N/A
Lapsus$ is a hacking and extortion group first known for breaching Okta, Microsoft, Nvidia, Samsung, and Uber in 2021 and 2022 using social engineering rather than malware, and it has since reemerged as part of a larger collective called Scattered Lapsus$ Hunters. Unlike ransomware gangs that rely on encryption, Lapsus$ built its reputation on stealing source code and internal data, then threatening to leak it publicly unless the victim paid or complied with its demands. This tactic made it one of the most disruptive threat actors of the past few years despite reportedly being run largely by teenagers. That threat hasn’t gone away; it’s evolved.
agrofruto. pe—We are a Peruvian company in the Agroindustrial sector, dedicated to the expo Deadline: 2026-09-30 09:45:00. 000000
Facilities Services Stolen data: 200 GB.
Government Administration Stolen data: 3 GB.
Optometrists Stolen data: 7 GB.
Government Administration Stolen data: 2 GB.
MINISTÉRIO DA FAZENDA SECRETARIA DA RECEITA FEDERAL DO BRASIL The archives contain several thousand documents with personnel and customer data, as well as all user date on gov. br with passwords. [Sector: Finance]
What Happened • On 25 August 2026, Manchester Airports Group (MAG), the operator of Manchester Airport, London Stansted Airport, and East Midlands Airport, reported they recently suffered data breach. • Personal information belonging to approximately 8.7 million customers was reportedly accessed. The majority of affected records involve email addresses collected via in-airport Wi-Fi sign ups, alongside customer data from car parking, airport lounge, and Fast Track security bookings. • According to BBC reports, the cybercriminals behind the attack issued a ransom demand to MAG. MAG said it had to temporarily suspended access to its online "Manage My Booking" service but importantly said that passenger safety, aviation security, and flight operations remained uncompromised and operated normally.
Attackers spoofed LastPass on GitHub, used a Microsoft-signed driver to disable 145 security products, then deployed an infostealer. Someone impersonated LastPass on GitHub, got users to download a fake authenticator, and ended up killing 145 different antivirus and EDR products using a driver that Microsoft itself had signed. That last part is the one worth sitting with. LastPass’s Threat Intelligence, Mitigation, and Escalation team spotted the fake GitHub organization on August 13, 2026. It appeared high in search results for “LastPass Authenticator download” and used real LastPass logos and branding to look legitimate. The download page also displayed fake trust badges, including “VirusTotal Approved.” The badges were meaningless and were simply there to make users feel safe enough to download the file.
An Armenian man was sentenced to 24 months in prison and 3 years of supervised release for hacking U. S. companies and encrypting their systems in Ryuk ransomware attacks. [... ]
Strengthen your readiness against Silent Ransom Group. As SRG increasingly uses IT impersonation and legitimate remote-access tools to target law firms, firms should review how they verify support interactions, protect sensitive client data and detect suspicious activity. The post When IT Support Is the Attack: How Law Firms Can Defend Against Silent Ransom Group appeared first on Sygnia . Incident Response vs. Crisis Management: Key Differences
Organization with 137 emails extracted. Domain: aokkef. fr
The cyber extortion group known as ShinyHunters on Tuesday claimed it had breached the U. S. Federal Bureau of Investigation and stolen data belonging to current and former employees at the agency. "We have compromised the FBI. We hold very sensitive data on almost ALL FBI Agents and individuals who filed an application with the FBI for a job," the group said in a statement posted on their dark
The FBI is investigating an attack on its own systems after ShinyHunters claimed responsibility for the incident, putting the prolific cybercrime group in the most direct conflict yet with agents responsible for investigating data extortion attacks. The Monday breach, first reported by 404 Media , allowed ShinyHunters to temporarily deface the FBI jobs site. The group claimed it stole “very sensitive data on almost all FBI agents and individuals who filed an application with the FBI for a job,” in a lengthy post on its data-leak site. “The FBI is aware of claims regarding unauthorized activity affecting FBIjobs.gov and is currently investigating,” a spokesperson for the agency said in a statement. An alert on the FBI jobs site notes that apply. fbijobs. gov and the Special Agent Application Portal are currently unavailable.
Sweden's data privacy regulator, IMY, has imposed a $183,000 (SEK 1. 8 million) fine on IT systems provider Miljödata for inadequate security measures leading to a breach in August 2025 affecting 2. 2 million people. [... ]
The ShinyHunters extortion gang claims it breached FBI systems using a new Oracle PeopleSoft zero-day vulnerability, gaining access to internal services and stealing sensitive data on employees and job applicants. [... ]