BT
Privacy ToolboxJournalProjectsResumeBookmarks
Feed
Privacy Toolbox
Journal
Projects
Resume
Bookmarks
Intel
Threat Actors
Privacy Threats
Dashboard
CVEs
Tags
Intel
Threat ActorsPrivacy ThreatsDashboardCVEsTags

Intel

  • Feed
  • Threat Actors
  • Privacy Threats
  • Dashboard
  • Privacy Toolbox
  • CVEs

Personal

  • Journal
  • Projects

Resources

  • Subscribe
  • Bookmarks
  • Developers
  • Tags
Cybersecurity News & Analysis
github
defconxt
•
© 2026
•
blacktemple.net

Data Breaches & Incidents

RSS
highData Breaches & Incidents

Weekly Security Roundup: Banking Trojan Targets Brazil, Iranian Hackers Hit Healthcare Giants, HR Under Attack

Iranian-linked Handala group claims attacks on medical device maker Stryker and payment processor Verifone, while new PixRevolution banking trojan uses live operators to steal Brazil's PIX transfers in real-time. Meanwhile, Russian-speaking attackers deploy BlackSanta malware through fake job applications targeting HR departments.

Mar 12, 2026Hackread
malwarebanking-trojaniranian-threat-actors
highData Breaches & Incidents

Whistleblower Alleges Former DOGE Member Took Social Security Data to New Position

A whistleblower has alleged that a former Department of Government Efficiency (DOGE) member improperly took Social Security Administration data when leaving for a new position. The incident highlights insider threat risks in government data handling.

Mar 12, 2026Hacker News (filtered)
data-breachinsider-threatsocial-security
highData Breaches & Incidents

Data Breach Roundup: ShinyHunters Targets 400 Firms, MyFitnessPal Compromised, Lazarus Group Deploys Deepfakes

ShinyHunters claims to have stolen data from 400 firms via Salesforce portals and is threatening public disclosure unless ransom demands are met. Separately, MyFitnessPal's new owner Cal AI faces breach claims affecting 3 million users' health data, while North Korea's Lazarus Group deployed deepfake technology in a sophisticated LinkedIn-based social engineering attack targeting a security CEO.

Mar 11, 2026Hackread
data-breachshinyhunterssalesforce
🇰🇵Lazarus🏴ShinyHunters
🇺🇸LinkedIn
highData Breaches & Incidents

DOGE Employee Allegedly Exfiltrated Social Security Data via USB Drive

A DOGE employee allegedly stole Social Security data and copied it to a thumb drive, according to reports. The incident underscores persistent insider threat vulnerabilities in government data handling.

Mar 11, 2026Hacker News (filtered)
data-exfiltrationinsider-threatusb-security
highData Breaches & Incidents

Iran's MuddyWater Targets US Firms, macOS Stealer Campaign, and HIBP Surge

Iran's MuddyWater hackers deployed new Dindoor backdoor against US companies while cybercriminals used fake CleanMyMac sites to distribute macOS stealer malware. Meanwhile, Have I Been Pwned processed five major breaches in two days, highlighting an acceleration in data compromise incidents.

Mar 10, 2026Hackread, Troy Hunt
muddywateraptmacos
🇮🇷MuddyWater
highData Breaches & Incidents

2,600+ TLS Certificates Compromised by Private Key Exposure on GitHub and DockerHub

A collaborative investigation by Google and GitGuardian discovered that private keys for more than 2,600 valid TLS certificates were exposed on GitHub and DockerHub. The compromised certificates belong to Fortune 500 companies and government agencies, creating significant risks for cryptographic security and potential impersonation attacks.

Mar 7, 2026Hackread
tls-certificatesprivate-keysgithub-leaks
🇺🇸Google
highData Breaches & Incidents

Data Breach Roundup: APT36 AI Campaign, PleaseFix 1Password Exploit, and LeakBase Seizure

Pakistani threat actor APT36 is actively targeting Indian government networks using AI-generated malware and trusted cloud services. Meanwhile, researchers discovered PleaseFix vulnerabilities in Perplexity's Comet browser that allow attackers to steal 1Password credentials through zero-click calendar invites.

Mar 6, 2026Hackread
apt36ai-malwarepassword-manager
🇺🇸Google
highData Breaches & Incidents

Security Roundup: Certificate Abuse, Phishing Evolution, and Enterprise Defense Gaps

Attackers are leveraging stolen certificates to distribute malware through fake Zoom/Teams updates, while new phishing tactics exploit encrypted flows and QR codes to bypass enterprise defenses. Startups face unique confidentiality challenges during fundraising and hiring processes.

Mar 5, 2026Hackread
phishingmalwarecertificates
mediumData Breaches & Incidents

Weekly Security Roundup: Vehicle Tracking Privacy Flaws, Telegram Cybercrime Surge, and Major CSAM Network Disrupted

Researchers demonstrate how unencrypted tire pressure sensors can track vehicles without consent, while cybercriminals increasingly use Telegram for selling access and malware. Meanwhile, Europol's Project Compass resulted in 30 arrests targeting a network exploiting minors.

Mar 4, 2026Hackread
privacyvehicle-securitytelegram
🇦🇪Telegram🇺🇸Google
mediumData Breaches & Incidents

Iranian Prayer App BadeSaba Compromised to Broadcast Anti-Government Messages

Hackers breached BadeSaba, a widely-used Iranian prayer and calendar application, using the platform to distribute anti-government messages and calls for military defection. The incident highlights the vulnerability of mobile applications as vectors for politically motivated attacks.

Mar 3, 2026Hackread
iranmobile-apphacktivism
mediumData Breaches & Incidents

Weekly Security Roundup: Teramind Phishing Campaign Targets Remote Workers

Cybercriminals are leveraging fake video conferencing pages to trick users into installing Teramind monitoring software on Windows systems. The campaign exploits trust in legitimate platforms like Zoom and Google Meet to deploy potentially unwanted monitoring tools.

Mar 2, 2026Hackread
phishingteramindmonitoring-software
🇺🇸Google
highData Breaches & Incidents

Weekly Roundup: Pakistani Media Hijacked, Gaming RAT Campaign, and European DDoS Surge

Pakistani media giants Geo News and ARY News suffered coordinated satellite feed hijacking for anti-military messaging, while Microsoft warns of RAT distribution through fake Roblox tools. European organizations face escalating DDoS threats according to Link11's 2026 report.

Mar 2, 2026Hackread, Troy Hunt
media-hijackingddos-attacksgaming-malware
Prev12Next