McKesson discloses breach after ShinyHunters claims patient data theft post, augustus 28, 2026september 4, 2026 Healthcare and pharmaceutical distribution giant McKesson has disclosed a cybersecurity incident involving unauthorized access to third-party applications and data theft, with the ShinyHunters extortion group claiming it stole 284 million patient data records. McKesson is a major U.S. healthcare company and pharmaceutical distributor that provides medicines, medical supplies, technology, and… Continue Reading
Carhartt data breach exposes information of 12.9 million accounts post, augustus 27, 2026augustus 28, 2026 The ShinyHunters extortion group has published sensitive data from nearly 13 million accounts stolen from clothing retailer giant Carhartt earlier this month, according to data breach notification service Have I Been Pwned. Founded in 1889, Carhartt is an American apparel company with workwear and streetwear manufacturing facilities in Kentucky and… Continue Reading
FBI Disrupts China-Linked QTFY Infrastructure Used to Steal Data From U.S. Organizations post, augustus 26, 2026september 4, 2026 The U.S. Department of Justice (DoJ) on Wednesday announced the disruption of two hacking platforms named QScan and QTRouter operated by Chinese threat actors to target critical infrastructure and other sensitive networks in the country. The activity has been attributed to a Chinese state-sponsored group known as QTFY, employed by Nanjing Xinjiuwei… Continue Reading
Actively Exploited Oracle WebLogic Vulnerability Exposes Critical Enterprise Data post, augustus 25, 2026augustus 26, 2026 A maximum-severity vulnerability affecting Oracle HTTP Server and the Oracle WebLogic Server Proxy Plug-in is being actively exploited, prompting an urgent warning from the US Cybersecurity and Infrastructure Security Agency and a compressed remediation deadline for federal agencies. The vulnerability, tracked as CVE-2026-21962, carries a CVSS severity score of 10.0,… Continue Reading
Massive DDoS attack disrupts Norway’s government digital services post, augustus 25, 2026augustus 26, 2026 A large distributed denial-of-service (DDoS) attack has disrupted Norway’s shared government digital infrastructure since Monday, affecting services used by the public sector. The attack started at 03.38 CEST on Monday and has targeted the infrastructure supporting services operated by the Norwegian Digitalization Agency, Digitaliseringsdirektoratet (Digdir), and its operations provider, Vivicta…. Continue Reading
Iraanse hackers legden Britse energiecentrale 4 dagen plat post, augustus 23, 2026augustus 24, 2026 Iraanse hackers hebben vorige maand een energiecentrale in het Verenigd Koninkrijk vier dagen platgelegd met een cyberaanval. Dat meldt de Britse krant The Telegraph. Volgens de krant is het de eerste keer dat hackers die gelinkt worden aan het Iraanse regime een energiefaciliteit in het VK wisten te raken. Om welke energiecentrale… Continue Reading
Microsoft Confirms Maximum-Severity Entra ID Vulnerability Exploited In Attacks post, augustus 21, 2026augustus 24, 2026 Microsoft has disclosed a maximum-severity security vulnerability in Microsoft Entra ID that was exploited in real-world attacks before the company completed a cloud-side fix, raising significant questions about the exposure of one of the most consequential identity platforms used by businesses, governments, and public-sector organizations worldwide. The vulnerability, tracked as… Continue Reading
US Agencies Warn of Active AI-Assisted Campaign Targeting Siemens S7 Industrial Controllers post, augustus 21, 2026augustus 24, 2026 US cybersecurity and intelligence agencies have issued an urgent warning about an active threat campaign targeting Siemens S7 programmable logic controllers used in manufacturing plants, energy facilities, water systems and other critical infrastructure. The joint advisory was issued by the US National Security Agency, Cybersecurity and Infrastructure Security Agency (CISA),… Continue Reading
US Agencies Update Medusa Ransomware Warning As Victim Count Surpasses 500 post, augustus 20, 2026augustus 24, 2026 U.S. Cybersecurity and Infrastructure Security Agency CISA and law-enforcement have issued an expanded warning about the Medusa ransomware operation after federal investigations identified more than 500 affected organisations across critical infrastructure and other industries. The updated joint advisory, published on August 18 by the Cybersecurity and Infrastructure Security Agency, the… Continue Reading
AI Agent Introduced A Flaw in Snowflake’s Code—Then Another AI Agent Exploited It post, augustus 18, 2026augustus 24, 2026 An artificial intelligence-generated security fix introduced a vulnerability into one of Snowflake’s public GitHub repositories, before a separate autonomous AI security agent found the defect, exploited it and extracted credentials providing access to parts of the company’s internal Jira environment. The incident did not result from an uncontrolled attack or… Continue Reading