> TODAY'S SUMMARY (3 articles)
Raheim Hamilton, co-creator of the Empire Market dark web marketplace, has been sentenced to 40 years in prison for facilitating over $430 million in illegal trades, highlighting ongoing law enforcement efforts against cybercrime. Hamilton's guilty plea included the forfeiture of $100 million in Bitcoin and assets. Additionally, the FBI has arrested the founder of a Canadian cybersecurity firm, linked to the ShinyHunters hacking group, signaling a crackdown on organizations involved in ransomware negotiations. These developments underscore the increasing focus on dismantling criminal enterprises in the dark web and addressing ransomware threats.
|
// AI-powered summary generated at 08:00
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Microsoft Teams. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 9.8. The following CVEs are assigned: CVE-2025-53783.
This vulnerability allows local attackers to escalate privileges on affected installations of Microsoft Windows. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 8.8. The follow...
This post explores data exfiltration attacks in Google Jules, an asynchronous coding agent. This is the first of three posts that will highlight my research on Google Jules in May 2025. All information provided was also shared with Google at that time.
This first post will focus on data exfiltration...
This vulnerability allows remote attackers to execute arbitrary code on affected installations of NVIDIA Transformers4Rec. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. Th...
Threat insights from Datadog Security Labs for Q2 2025.
Une tentative de piratage a visé les serveurs de l'Université de St. Thomas, entraînant une interruption des services en ligne, mais aucune donnée n'a été compromise selon l'université. Les équipes de sécurité enquêtent sur l'incident et travaillent à rétablir les services le plus rapidement possibl...
Orchid Island Golf and Beach Club suffered a data breach where an unauthorized third party gained access to their network and took certain data files from their server, potentially exposing personal information of employees and previous employees.
Presently sponsored by: 1Password Extended Access Management: Secure every sign-in for every app on every device.Spoiler: I have data from the story in the title of this post, it's mostly what I expected it to be, I've just added it to HIBP where I've called it "Data Troll", and I'm going to give ev...
Donelan's Supermarkets experienced a network security incident where an unauthorized third-party accessed their network environment, potentially exposing personal information of customers. The incident occurred on or about August 14, 2025, and was discovered on the same date. The company is providin...
Marquis Software Solutions experienced a data security incident where an unauthorized third party accessed their network and may have accessed and acquired certain files. The incident was limited to Marquis' environment, and the company has no evidence of the misuse of personal information. The comp...
In June 2025, headlines erupted over a "16 billion password" breach. In reality, the dataset was a compilation of publicly accessible stealer logs, mostly repurposed from older leaks, with only a small portion of genuinely new material. HIBP received 2.7B rows containing 109M unique email addresses,...
North Metro Harness Initiative, LLC dba Running Aces experienced a data security incident between July 27, 2025, and August 14, 2025, potentially impacting personal information of customers. A cyberattack against Running Aces was claimed by Qilin on September 8.
Michigan Sugar Company suffered a data breach on August 14, 2025, where an unauthorized third party gained access to certain systems in its network, potentially resulting in the unauthorized access and acquisition of personal information. An attack was claimed by Akira on September 5.
A critical RCE vulnerability in Erlang’s OTP SSH daemon has been identified that allows unauthenticated command execution
Centers Laboratory, une entreprise de diagnostic de santé basée dans le New Jersey, a informé le gouvernement américain d'une violation de données découverte il y a près d'un an. L'intrusion, qui a eu lieu entre le 9 et le 14 août 2025, a permis aux acteurs de la menace d'exfiltrer des informations...
AI-powered trading platforms have been observed exploiting deepfake technology to trick investors with fake endorsements
The personal data of almost 145,000 people who were registered in Manpower’s systems was compromised
Eleanor Fairford, Deputy Director of Incident Management at the NCSC, and Mihaela Jembei, Director of Regulatory Cyber at the Information Commissioner’s Office (ICO), reflect on why it’s so concerning when cyber attacks go unreported – and look at some of the misconceptions about how organisations r...
Mayor of St. Paul, Minnesota, Melvin Carter, confirmed that employee data was published online by the Interlock ransomware gang
Guidance for enterprise administrators who want to reduce the likelihood of being held to ransom by WannaCry (or other types of ransomware).