Skip to content
Security matters
Security matters
  • APTs
  • Tijdlijn
  • Kill chain
  • Uitgelicht
  • Privacy
Security matters

McKesson discloses breach after ShinyHunters claims patient data theft

post, augustus 28, 2026september 4, 2026

Healthcare and pharmaceutical distribution giant McKesson has disclosed a cybersecurity incident involving unauthorized access to third-party applications and data theft, with the ShinyHunters extortion group claiming it stole 284 million patient data records. McKesson is a major U.S. healthcare company and pharmaceutical distributor that provides medicines, medical supplies, technology, and…

Continue Reading

Carhartt data breach exposes information of 12.9 million accounts

post, augustus 27, 2026augustus 28, 2026

The ShinyHunters extortion group has published sensitive data from nearly 13 million accounts stolen from clothing retailer giant Carhartt earlier this month, according to data breach notification service Have I Been Pwned. Founded in 1889, Carhartt is an American apparel company with workwear and streetwear manufacturing facilities in Kentucky and…

Continue Reading

FBI Disrupts China-Linked QTFY Infrastructure Used to Steal Data From U.S. Organizations

post, augustus 26, 2026september 4, 2026

The U.S. Department of Justice (DoJ) on Wednesday announced the disruption of two hacking platforms named QScan and QTRouter operated by Chinese threat actors to target critical infrastructure and other sensitive networks in the country. The activity has been attributed to a Chinese state-sponsored group known as QTFY, employed by Nanjing Xinjiuwei…

Continue Reading

Actively Exploited Oracle WebLogic Vulnerability Exposes Critical Enterprise Data

post, augustus 25, 2026augustus 26, 2026

A maximum-severity vulnerability affecting Oracle HTTP Server and the Oracle WebLogic Server Proxy Plug-in is being actively exploited, prompting an urgent warning from the US Cybersecurity and Infrastructure Security Agency and a compressed remediation deadline for federal agencies. The vulnerability, tracked as CVE-2026-21962, carries a CVSS severity score of 10.0,…

Continue Reading

Massive DDoS attack disrupts Norway’s government digital services

post, augustus 25, 2026augustus 26, 2026

A large distributed denial-of-service (DDoS) attack has disrupted Norway’s shared government digital infrastructure since Monday, affecting services used by the public sector. The attack started at 03.38 CEST on Monday and has targeted  the infrastructure supporting services operated by the Norwegian Digitalization Agency, Digitaliseringsdirektoratet (Digdir), and its operations provider, Vivicta….

Continue Reading

Iraanse hackers legden Britse energiecentrale 4 dagen plat

post, augustus 23, 2026augustus 24, 2026

Iraanse hackers hebben vorige maand een energiecentrale in het Verenigd Koninkrijk vier dagen platgelegd met een cyberaanval. Dat meldt de Britse krant The Telegraph. Volgens de krant is het de eerste keer dat hackers die gelinkt worden aan het Iraanse regime een energiefaciliteit in het VK wisten te raken. Om welke energiecentrale…

Continue Reading

Microsoft Confirms Maximum-Severity Entra ID Vulnerability Exploited In Attacks

post, augustus 21, 2026augustus 24, 2026

Microsoft has disclosed a maximum-severity security vulnerability in Microsoft Entra ID that was exploited in real-world attacks before the company completed a cloud-side fix, raising significant questions about the exposure of one of the most consequential identity platforms used by businesses, governments, and public-sector organizations worldwide. The vulnerability, tracked as…

Continue Reading

US Agencies Warn of Active AI-Assisted Campaign Targeting Siemens S7 Industrial Controllers

post, augustus 21, 2026augustus 24, 2026

US cybersecurity and intelligence agencies have issued an urgent warning about an active threat campaign targeting Siemens S7 programmable logic controllers used in manufacturing plants, energy facilities, water systems and other critical infrastructure. The joint advisory was issued by the US National Security Agency, Cybersecurity and Infrastructure Security Agency (CISA),…

Continue Reading

US Agencies Update Medusa Ransomware Warning As Victim Count Surpasses 500

post, augustus 20, 2026augustus 24, 2026

U.S. Cybersecurity and Infrastructure Security Agency CISA and law-enforcement have issued an expanded warning about the Medusa ransomware operation after federal investigations identified more than 500 affected organisations across critical infrastructure and other industries. The updated joint advisory, published on August 18 by the Cybersecurity and Infrastructure Security Agency, the…

Continue Reading

AI Agent Introduced A Flaw in Snowflake’s Code—Then Another AI Agent Exploited It

post, augustus 18, 2026augustus 24, 2026

An artificial intelligence-generated security fix introduced a vulnerability into one of Snowflake’s public GitHub repositories, before a separate autonomous AI security agent found the defect, exploited it and extracted credentials providing access to parts of the company’s internal Jira environment. The incident did not result from an uncontrolled attack or…

Continue Reading
  • Previous
  • 1
  • …
  • 3
  • 4
  • 5
  • …
  • 47
  • Next

2020 2023 2024 2025 2026 China Iran North Korea Russia ShinyHunters

©2026 Security matters | WordPress Theme by SuperbThemes