> IT-Sentinel.com

// Cybersecurity & IT News Aggregator - Real-time Threat Intelligence Feed

NEWS CVE
← messages.back_to_articles

> InfoSec News Nuggets – 10/07/2026

[SOURCE] AboutDFIR [AUTHOR: Mary] [DATE: 07/10/2026 10:48] [LANGUAGE: EN]
ASOS confirms data breach after “HACKED” in-app notifications UK fashion retailer ASOS confirmed a data breach on Tuesday after attackers abused a third-party customer communications platform to push an unauthorized “ASOS HACKED” alert to mobile app users around 5:00 a.m. ET, claiming they had fully compromised the company’s Snowflake instance and threatening to leak data unless ASOS engaged with them. The message pointed recipients to a Telegram channel run by a group calling itself “Xuanye,” which later claimed it had stolen customer information but offered no proof or victim count. ASOS says names and contact details may have been exposed but does not believe payment card data or passwords were affected, has not confirmed the Snowflake claim, and is now showing an in-app notice telling customers to ignore the rogue alert and its link.   FBI Drops Accenture Contractor After Sensitive Data Breach The FBI removed an Accenture contractor on Monday after concluding that a missed security patch led to the ShinyHunters breach that exposed sensitive personal details of thousands of bureau employees. FBI cyber division chief Brett Leatherman said the incident stemmed from a security failure on a third-party-managed platform after a contractor failed to apply a patch issued specifically to secure it, and sources identified the platform as the Oracle PeopleSoft system behind the FBI’s jobs site. Oracle had released a fix in June for the PeopleSoft flaw that ShinyHunters was already exploiting, and the group later claimed it used that same bug to steal 2 to 3 TB of data, including counterintelligence roles, home addresses of human intelligence operatives, and medical and psychiatric records, a level of exposure former officials describe as a major blow to the bureau’s operational security.   Data breach at Denmark’s population register exposes 8.8 million people Denmark’s Central Population Register (CPR) has suffered a breach exposing the names, addresses, and 10-digit CPR numbers of about 8.8 million people, roughly 80% of the register, including current residents, deceased individuals, and citizens living abroad. Attackers misused a private Danish company’s lawful lookup access during September, staying within the data fields private companies are permitted to retrieve, and the activity was discovered on October 2 before being reported to the Danish Data Protection Agency two days later. The company’s access has been cut off, police are investigating with no suspect named, the minister responsible has ordered a full security review of the CPR system, and citizens are being warned to expect fraud attempts from callers or emailers who already know their personal details.   Personal Information for Over 1 Million People Stolen in a Cyberattack on Arizona’s Court System A cyberattack on Arizona’s court system, believed to have begun when an employee clicked a malicious link in an email, resulted in the theft of personal information for 1.3 million people with unpaid court fees, fines, and restitution payments for traffic and criminal violations going back as far as 30 years. The attackers also took records of nearly 30,000 active and inactive orders of protection and 150,000 reports dating to 2010 from a foster care review board, before court technology staff shut down the intrusion on a backup server about two hours after spotting it on September 24. The Arizona Supreme Court says it has notified those affected, has no evidence the data has been used or shared, and reports that no records were altered and no juror, witness, or employee information was taken.   100+ Compromised Websites Use Fake Cloudflare Checks to Deliver LunexStealer Ukraine’s CERT-UA has identified more than 100 compromised websites injected with malicious JavaScript that shows Windows visitors arriving from search engines a fake Cloudflare verification page, using the ClickFix technique to trick them into running a command that installs an MSI package delivering the LunexStealer (aka Psychedelic Stealer) information stealer. The campaign, attributed to a cluster tracked as UAC-0277, uses EtherHiding to pull its configuration from Polygon or Ethereum smart contracts, and some variants abuse a vulnerable AMD driver to blind security tools or rely on DLL sideloading. LunexStealer drops a malicious browser extension called LUNARAXE that poses as a Microsoft Office Word editor to steal cookies, history, and credentials and give operators remote control of the browser, and CERT-UA recommends blocking the Windows Run dialog for regular users, restricting MSI installs, enabling Microsoft’s vulnerable driver blocklist, and allowlisting browser extensions. The post InfoSec News Nuggets – 10/07/2026 appeared first on AboutDFIR - The Definitive Compendium Project.
[messages.read_original_source] →