<?xml version='1.0' encoding='utf-8'?>
<rss version="2.0"><channel><title>Cybersecurity Tracker: Breaches</title><link>https://cybersecuritytracker.ai/breaches</link><description>Curated cybersecurity news and vulnerability intelligence.</description><lastBuildDate>Sun, 26 Jul 2026 22:32:50 GMT</lastBuildDate><item><title>Developing: AnMed reports phone and internet outage impacting all hospital locations; ERs remain open</title><link>https://databreaches.net/2026/07/26/developing-anmed-reports-phone-and-internet-outage-impacting-all-hospital-locations-ers-remain-open?pk_campaign=feed&amp;pk_kwd=developing-anmed-reports-phone-and-internet-outage-impacting-all-hospital-locations-ers-remain-open</link><guid isPermaLink="false">cst-3229</guid><description>AnMed Health System, which operates four hospitals in Upstate South Carolina and northeast Georgia, experienced a phone and internet outage affecting all locations. Emergency rooms remained operational during the incident despite the connectivity disruption.</description><pubDate>Sun, 26 Jul 2026 14:10:29 GMT</pubDate></item><item><title>A-list directors, actors and celebrities exposed in Tribeca film festival data leak</title><link>https://databreaches.net/2026/07/26/a-list-directors-actors-and-celebrities-exposed-in-tribeca-film-festival-data-leak?pk_campaign=feed&amp;pk_kwd=a-list-directors-actors-and-celebrities-exposed-in-tribeca-film-festival-data-leak</link><guid isPermaLink="false">cst-3230</guid><description>A security researcher discovered four publicly accessible, unencrypted databases connected to the Tribeca Film Festival, including a development database containing over 203,000 records. The databases lacked password protection and exposed sensitive information about festival-associated individuals.</description><pubDate>Sun, 26 Jul 2026 13:06:14 GMT</pubDate></item><item><title>Week in review: ServiceNow pre-auth RCE exploited in the wild, Hugging Face breached</title><link>https://helpnetsecurity.com/2026/07/26/week-in-review-servicenow-pre-auth-rce-exploited-in-the-wild-hugging-face-breached</link><guid isPermaLink="false">cst-3226</guid><description>A weekly news roundup covered multiple security topics, including active exploitation of a ServiceNow pre-authentication remote code execution vulnerability and a breach of Hugging Face. The piece also discussed how organizations increasingly run multiple AI platforms simultaneously across different vendors and departments.</description><pubDate>Sun, 26 Jul 2026 08:00:34 GMT</pubDate></item><item><title>US House Votes to Extend Cyber Sharing Law for 10 Years</title><link>https://databreaches.net/2026/07/25/us-house-votes-to-extend-cyber-sharing-law-for-10-years?pk_campaign=feed&amp;pk_kwd=us-house-votes-to-extend-cyber-sharing-law-for-10-years</link><guid isPermaLink="false">cst-3218</guid><description>The U.S. House of Representatives voted to extend a key cyberthreat sharing law for 10 years by including the reauthorization in the fiscal year 2027 national defense authorization act. The measure passed narrowly on a 216-212 vote Wednesday and was attached to the $1.15 trillion defense policy bill after the reauthorization had been stalled.</description><pubDate>Sat, 25 Jul 2026 14:25:16 GMT</pubDate></item><item><title>AU: Sydney nurse accused of downloading patients’ data in alleged ‘breach of trust’</title><link>https://databreaches.net/2026/07/25/au-sydney-nurse-accused-of-downloading-patients-data-in-alleged-breach-of-trust?pk_campaign=feed&amp;pk_kwd=au-sydney-nurse-accused-of-downloading-patients-data-in-alleged-breach-of-trust</link><guid isPermaLink="false">cst-3219</guid><description>A registered nurse in northern Sydney has been charged after allegedly downloading patient data without authorization. NSW Police launched an investigation following a report to the agency and subsequently searched a home in Frenchs Forest as part of the inquiry.</description><pubDate>Sat, 25 Jul 2026 14:24:50 GMT</pubDate></item><item><title>No Need to Hack When It’s Leaking: Click to Pray edition</title><link>https://databreaches.net/2026/07/25/no-need-to-hack-when-its-leaking-click-to-pray-edition?pk_campaign=feed&amp;pk_kwd=no-need-to-hack-when-its-leaking-click-to-pray-edition</link><guid isPermaLink="false">cst-3220</guid><description>The Click To Pray app, a prayer application endorsed by the Pope with hundreds of thousands of users, exposed users' names and email addresses through a data leak. An ethical hacker discovered the exposure, which had persisted for months or longer.</description><pubDate>Sat, 25 Jul 2026 14:24:35 GMT</pubDate></item><item><title>ShinyHunters data leaks fuel $2,000 sextortion email scam</title><link>https://bleepingcomputer.com/news/security/shinyhunters-data-leaks-fuel-2-000-sextortion-email-scam</link><guid isPermaLink="false">cst-3217</guid><description>Threat actors are leveraging email addresses from ShinyHunters data leaks to conduct sextortion campaigns demanding $2,000 in Bitcoin from recipients. The attackers are exploiting publicly available breach data to target victims with extortion threats.</description><pubDate>Sat, 25 Jul 2026 14:16:26 GMT</pubDate></item><item><title>Cl0p Affiliates Target Internet-Exposed PTC Windchill and FlexPLM with Unauthenticated RCE</title><link>https://thehackernews.com/2026/07/cl0p-affiliates-target-internet-exposed.html</link><guid isPermaLink="false">cst-3213</guid><description>Cl0p-affiliated threat actors are exploiting unauthenticated remote code execution (RCE) vulnerabilities in internet-exposed PTC Windchill and FlexPLM deployments. The attackers chain pre-authentication information disclosure in FlexPLM with server-side flaws in Windchill's login servlet to gain unauthorized access. This activity is part of an active data extortion campaign.</description><pubDate>Sat, 25 Jul 2026 10:14:03 GMT</pubDate></item><item><title>DevMan RaaS Portal Centralizes Payload Builds, Victim Management, and Affiliate Payouts</title><link>https://thehackernews.com/2026/07/devman-raas-portal-centralizes-payload.html</link><guid isPermaLink="false">cst-3214</guid><description>DevMan operators maintain a web portal that enables affiliates to build ransomware payloads, track earnings, and manage victim information. The Swiss cybersecurity firm PRODAFT tracks the operation under the threat actor name Funky Mantis and reports that the platform centralizes multiple ransomware-as-a-service functions in one location.</description><pubDate>Sat, 25 Jul 2026 09:53:41 GMT</pubDate></item><item><title>OpenAI confirms ChatGPT is down worldwide</title><link>https://bleepingcomputer.com/news/artificial-intelligence/openai-confirms-chatgpt-is-down-worldwide</link><guid isPermaLink="false">cst-3208</guid><description>OpenAI confirmed that ChatGPT experienced a worldwide outage affecting access to the artificial intelligence chatbot. The company did not provide details on the cause or expected resolution timeline in the initial report.</description><pubDate>Sat, 25 Jul 2026 09:31:09 GMT</pubDate></item><item><title>OnTrac notifies customers of data breach after network hack</title><link>https://bleepingcomputer.com/news/security/ontrac-notifies-customers-of-data-breach-after-network-hack</link><guid isPermaLink="false">cst-3195</guid><description>OnTrac, a parcel delivery company, disclosed that attackers breached its corporate network and potentially accessed customer personal information. The company is notifying affected customers of the incident.</description><pubDate>Fri, 24 Jul 2026 19:55:01 GMT</pubDate></item><item><title>Chick-fil-A data breach affects more than 13,000 customers</title><link>https://bleepingcomputer.com/news/security/chick-fil-a-data-breach-affects-more-than-13-000-customers</link><guid isPermaLink="false">cst-3178</guid><description>Chick-fil-A confirmed that attackers using credential stuffing tactics compromised more than 13,000 customer accounts on its website and mobile app during a three-day period in mid-June. The breach involved unauthorized access to customer data through reused or weak credentials rather than a direct compromise of the company's systems.</description><pubDate>Fri, 24 Jul 2026 14:04:29 GMT</pubDate></item><item><title>Suspect arrested in investigation into sadistic “764” group</title><link>https://databreaches.net/2026/07/24/suspect-arrested-in-investigation-into-sadistic-764-group?pk_campaign=feed&amp;pk_kwd=suspect-arrested-in-investigation-into-sadistic-764-group</link><guid isPermaLink="false">cst-3187</guid><description>A suspect from North Holland was arrested on July 20 in connection with an online sadistic network called '764'. The individual allegedly coerced minors to engage in self-harm and create 'bloodsigns' bearing his username as evidence of compliance.</description><pubDate>Fri, 24 Jul 2026 13:47:04 GMT</pubDate></item><item><title>Vatican's Official Prayer App Leaks 700K+ Global Users' PII</title><link>https://darkreading.com/vulnerabilities-threats/vatican-official-prayer-app-leaks-700k-pii</link><guid isPermaLink="false">cst-3167</guid><description>Vatican's official prayer application contained a vulnerable API endpoint that exposed personal information for over 700,000 users worldwide. The exposed data included names, email addresses, location information, and site status that could be accessed without authentication through a standard web browser.</description><pubDate>Fri, 24 Jul 2026 13:00:00 GMT</pubDate></item><item><title>Crime Stoppers assured people their tips would be anonymous. Then more than 1 million tips leaked.</title><link>https://databreaches.net/2026/07/24/crime-stoppers-assured-people-their-tips-would-be-anonymous-then-more-than-1-million-tips-leaked?pk_campaign=feed&amp;pk_kwd=crime-stoppers-assured-people-their-tips-would-be-anonymous-then-more-than-1-million-tips-leaked</link><guid isPermaLink="false">cst-3188</guid><description>A breach of Navigate360's systems exposed more than one million tips submitted to Crime Stoppers and law enforcement programs that relied on the company's software for anonymous reporting. The incident undermines trust in anonymous tip submission channels that promised confidentiality to sources.</description><pubDate>Fri, 24 Jul 2026 12:49:59 GMT</pubDate></item><item><title>Origin silent on settlement as alleged fired employee breach detail emerges</title><link>https://databreaches.net/2026/07/24/origin-silent-on-settlement-as-alleged-fired-employee-breach-detail-emerges?pk_campaign=feed&amp;pk_kwd=origin-silent-on-settlement-as-alleged-fired-employee-breach-detail-emerges</link><guid isPermaLink="false">cst-3170</guid><description>Origin Energy has declined to publicly comment on a reported private settlement of a cyber extortion threat. The alleged breach involved unauthorized access through a former employee's credentials, creating concurrent disclosure obligations to regulators, the ASX, and insurers.</description><pubDate>Fri, 24 Jul 2026 12:08:15 GMT</pubDate></item><item><title>T-Mobile violated WA data breach notification law, judge rules</title><link>https://databreaches.net/2026/07/24/t-mobile-violated-wa-data-breach-notification-law-judge-rules?pk_campaign=feed&amp;pk_kwd=t-mobile-violated-wa-data-breach-notification-law-judge-rules</link><guid isPermaLink="false">cst-3171</guid><description>A King County Superior Court judge ruled that T-Mobile violated Washington state data breach notification law by failing to properly notify customers of a 2024 breach affecting 40 million people whose sensitive personal information was stolen and sold on the dark web. The Washington attorney general's office filed the civil lawsuit against T-Mobile in January 2025. The ruling establishes that T-Mobile's notification practices did not meet the state's legal requirements.</description><pubDate>Fri, 24 Jul 2026 12:08:06 GMT</pubDate></item><item><title>Furious KPMG boss expels senior partner over confidential documents in locker</title><link>https://databreaches.net/2026/07/24/furious-kpmg-boss-expels-senior-partner-over-confidential-documents-in-locker?pk_campaign=feed&amp;pk_kwd=furious-kpmg-boss-expels-senior-partner-over-confidential-documents-in-locker</link><guid isPermaLink="false">cst-3172</guid><description>KPMG's chief operating officer, Eileen Hoggett, was expelled after an investigation confirmed she and other senior partners illegally accessed sensitive Lendlease board documents and stored them in a work locker. The expulsion followed a whistleblower claim regarding the unauthorized possession of confidential materials.</description><pubDate>Fri, 24 Jul 2026 12:07:56 GMT</pubDate></item><item><title>Millions of California-bought cars can be hijacked via Bluetooth</title><link>https://databreaches.net/2026/07/24/millions-of-california-bought-cars-can-be-hijacked-via-bluetooth?pk_campaign=feed&amp;pk_kwd=millions-of-california-bought-cars-can-be-hijacked-via-bluetooth</link><guid isPermaLink="false">cst-3174</guid><description>Researchers at UC San Diego identified Bluetooth vulnerabilities affecting at least 2.2 million vehicles equipped with dealer-installed KARR and SWDS security systems. The flaws allow nearby attackers to unlock doors or disable vehicle ignition through wireless attacks. The full research details are forthcoming.</description><pubDate>Fri, 24 Jul 2026 12:06:56 GMT</pubDate></item><item><title>Man gets six years for hacking 750 women's Snapchat accounts</title><link>https://bleepingcomputer.com/news/security/man-gets-six-years-for-hacking-750-womens-snapchat-accounts</link><guid isPermaLink="false">cst-3159</guid><description>An Illinois man received a 76-month prison sentence and three years of supervised release for hacking over 750 women's Snapchat accounts to obtain their nude photos. The case illustrates criminal liability for unauthorized account access and theft of intimate images.</description><pubDate>Fri, 24 Jul 2026 11:17:19 GMT</pubDate></item><item><title>Clop ransomware targets Windchill, FlexPLM in data theft attacks</title><link>https://bleepingcomputer.com/news/security/clop-ransomware-targets-windchill-flexplm-in-data-theft-attacks</link><guid isPermaLink="false">cst-3151</guid><description>The Clop ransomware group is conducting data theft extortion attacks against publicly accessible instances of PTC Windchill and FlexPLM product lifecycle management platforms. These attacks represent an expansion of the group's targeting beyond previously observed patterns.</description><pubDate>Fri, 24 Jul 2026 07:36:39 GMT</pubDate></item><item><title>Ransomware gangs go after EMEA healthcare’s supply chain</title><link>https://helpnetsecurity.com/2026/07/24/emea-healthcare-ransomware-activity</link><guid isPermaLink="false">cst-3148</guid><description>A Flare researcher analyzed ransomware leak-site activity targeting healthcare organizations across the EMEA region from 2024 to 2026 and found that ransomware groups are systematically attacking the entire healthcare supply chain, not just hospitals. The attacks extend beyond hospitals and clinics to include telemedicine providers, diagnostic laboratories, pharmacies, and other ecosystem participants. While hospital breaches receive media attention, attacks on peripheral healthcare entities often remain unreported despite comparable damage.</description><pubDate>Fri, 24 Jul 2026 05:30:33 GMT</pubDate></item><item><title>Ransomware in 2026: More groups, more victims, no slowdown</title><link>https://helpnetsecurity.com/2026/07/24/ransomware-attack-trends-2026-report</link><guid isPermaLink="false">cst-3150</guid><description>Black Kite's 2026 Ransomware Report finds a fragmented ransomware landscape with 61 new groups entering the market between April 2025 and March 2026, averaging more than one new group per week. Unlike previous years defined by dominant actors or major incidents, 2026 shows multiple ransomware playbooks scaling simultaneously with no signs of slowdown.</description><pubDate>Fri, 24 Jul 2026 04:30:22 GMT</pubDate></item><item><title>Ransomware is the Scoreboard</title><link>https://recordedfuture.com/blog/ransomware-is-the-scoreboard</link><guid isPermaLink="false">cst-3190</guid><description>Recorded Future documented 13,000 ransomware victims over two years, with groups like Interlock and RansomHub continuing successful attacks despite existing defensive technologies such as attack path management tools. The article argues that defenders struggle because they focus on compliance checklists and vulnerability lists rather than modeling their environment as an interconnected graph of assets, configurations, and credentials that attackers actually traverse, and proposes that AI agents continuously recomputing attack paths at adversarial speed could improve defense.</description><pubDate>Fri, 24 Jul 2026 00:00:00 GMT</pubDate></item><item><title>Microsoft 365 outage affects Teams, SharePoint and other services</title><link>https://bleepingcomputer.com/news/microsoft/microsoft-365-outage-affects-teams-sharepoint-and-other-services</link><guid isPermaLink="false">cst-3100</guid><description>Microsoft experienced a widespread outage affecting Teams, SharePoint, and other Microsoft 365 services, with impact concentrated in North America. The disruption impacted collaboration and productivity tools relied upon by thousands of organizations.</description><pubDate>Thu, 23 Jul 2026 15:34:43 GMT</pubDate></item><item><title>Chick-fil-A Accounts Get Fried in Credential Stuffing Attack</title><link>https://securityweek.com/chick-fil-a-accounts-get-fried-in-credential-stuffing-attack</link><guid isPermaLink="false">cst-3109</guid><description>Threat actors used credentials from previous breaches to gain unauthorized access to Chick-fil-A One customer accounts through credential stuffing. The attack relied on reused passwords rather than exploiting a vulnerability in the restaurant chain's systems.</description><pubDate>Thu, 23 Jul 2026 14:55:19 GMT</pubDate></item><item><title>Major Australian energy supplier confirms customer data compromised</title><link>https://therecord.media/australia-origin-energy-data-breach</link><guid isPermaLink="false">cst-3113</guid><description>Origin Energy, a major Australian energy supplier, confirmed that customer data was compromised in a recent breach and is investigating the scope of the incident to determine how many Australians were affected.</description><pubDate>Thu, 23 Jul 2026 13:20:00 GMT</pubDate></item><item><title>Chaos ransomware's msaRAT: Living off the browser to build a covert C2 channel</title><link>https://blog.talosintelligence.com/chaos-msarat-living-off-the-browser-to-build-covert-c2-channel</link><guid isPermaLink="false">cst-3081</guid><description>Cisco Talos discovered msaRAT, a Rust-based remote access trojan attributed to the Chaos ransomware group that establishes command-and-control communications exclusively through Chrome DevTools Protocol rather than direct network connections. The malware is delivered via a malicious MSI installer disguised as a Windows update and leverages the browser, Cloudflare Workers, and Twilio TURN relays to create a covert WebRTC DataChannel for C2 communications. Chaos is a ransomware-as-a-service group active since February 2025 that uses phishing, vishing, and legitimate tools for post-compromise activities before deploying encryption.</description><pubDate>Thu, 23 Jul 2026 10:00:38 GMT</pubDate></item><item><title>Microsoft working to fix Exchange Online mailbox quarantine issue</title><link>https://bleepingcomputer.com/news/microsoft/microsoft-working-to-fix-exchange-online-mailbox-quarantine-issue</link><guid isPermaLink="false">cst-3069</guid><description>Microsoft is addressing an issue with Exchange Online that has been incorrectly quarantining customer mailboxes since Sunday. The company is working to resolve the problem and restore normal service for affected users.</description><pubDate>Thu, 23 Jul 2026 09:20:10 GMT</pubDate></item><item><title>Ransomware Attack Puts a Chill On Japanese Frozen-Food Chain</title><link>https://darkreading.com/cyberattacks-data-breaches/ransomware-attack-japanese-frozen-food-chain</link><guid isPermaLink="false">cst-3055</guid><description>A cyberattack on a Japanese food and logistics company disrupted frozen food distribution to thousands of clients, including major restaurant chains such as Kentucky Fried Chicken. The incident affected supply chains across multiple food service operators dependent on the firm's distribution network.</description><pubDate>Thu, 23 Jul 2026 01:00:00 GMT</pubDate></item><item><title>ID: Kootenai County notifies residents of data breach</title><link>https://databreaches.net/2026/07/22/id-kootenai-county-notifies-residents-of-data-breach?pk_campaign=feed&amp;pk_kwd=id-kootenai-county-notifies-residents-of-data-breach</link><guid isPermaLink="false">cst-3057</guid><description>Kootenai County is notifying residents of a ransomware attack discovered on March 30, 2026, that compromised personal information on its computer network. The county took immediate action to secure and restore its systems following the detection.</description><pubDate>Thu, 23 Jul 2026 00:45:56 GMT</pubDate></item><item><title>TN: Data breach delays start of Sumner County school year</title><link>https://databreaches.net/2026/07/22/tn-data-breach-delays-start-of-sumner-county-school-year?pk_campaign=feed&amp;pk_kwd=tn-data-breach-delays-start-of-sumner-county-school-year</link><guid isPermaLink="false">cst-3058</guid><description>Sumner County Schools in Tennessee discovered a data breach in its computer network and postponed the start of the school year to resolve the incident before students return. The breach was identified earlier in the week, prompting district officials to revise the calendar.</description><pubDate>Thu, 23 Jul 2026 00:25:52 GMT</pubDate></item><item><title>Instructure Incident Driving 58 Percent of Breach Notices in 2026</title><link>https://databreaches.net/2026/07/22/instructure-incident-driving-58-percent-of-breach-notices-in-2026?pk_campaign=feed&amp;pk_kwd=instructure-incident-driving-58-percent-of-breach-notices-in-2026</link><guid isPermaLink="false">cst-3059</guid><description>A single Instructure incident generated 471 million breach notices in the first half of 2026, accounting for 58 percent of all breach notifications despite 1,029 total compromises being reported during that period. The Identity Theft Resource Center documented this concentration of impact from one major breach event among organizations handling large datasets.</description><pubDate>Wed, 22 Jul 2026 23:12:10 GMT</pubDate></item><item><title>Swiss train maker Stadler refuses Everest $12 million ransomware demand</title><link>https://therecord.media/stadler-refuses-everest-ransom-demand</link><guid isPermaLink="false">cst-3075</guid><description>Stadler Rail, a Swiss train manufacturer, declined to pay a $12.3 million ransom demand from cybercriminals who obtained technical data through a compromised supplier's file-sharing platform.</description><pubDate>Wed, 22 Jul 2026 23:00:00 GMT</pubDate></item><item><title>Upbound says hack caused $13 million in fraudulent Acima leases</title><link>https://bleepingcomputer.com/news/security/upbound-says-hack-caused-13-million-in-fraudulent-acima-leases</link><guid isPermaLink="false">cst-3047</guid><description>Threat actors who compromised Upbound Group's systems used stolen data to fraudulently originate approximately $13 million in Acima leases. The breach highlighted the exposure of customer information and the downstream financial impact when stolen credentials are weaponized for unauthorized transactions.</description><pubDate>Wed, 22 Jul 2026 21:43:39 GMT</pubDate></item><item><title>South Korea discloses data breach impacting diplomats worldwide</title><link>https://bleepingcomputer.com/news/security/south-korea-discloses-data-breach-impacting-diplomats-worldwide</link><guid isPermaLink="false">cst-3048</guid><description>South Korea's National Diplomatic Academy suffered a ten-month breach of its online education system, exposing personal information of current and former Ministry of Foreign Affairs employees and diplomats stationed abroad. The incident remained undetected for an extended period before disclosure.</description><pubDate>Wed, 22 Jul 2026 20:06:54 GMT</pubDate></item><item><title>Swiss rail giant Stadler rejects $12.3M ransom demand after cyberattack</title><link>https://bleepingcomputer.com/news/security/swiss-rail-giant-stadler-rejects-123m-ransom-demand-after-cyberattack</link><guid isPermaLink="false">cst-3032</guid><description>Swiss rail manufacturer Stadler Rail was targeted by the Everest ransomware group, which demanded $12.3 million following a breach of a shared data exchange platform with a supplier. Stadler has rejected the ransom demand. The incident affected the company's IT systems and exposed sensitive business information.</description><pubDate>Wed, 22 Jul 2026 16:59:17 GMT</pubDate></item><item><title>Real world incident response: Microsoft and AXA XL strengthen cyber resilience</title><link>https://microsoft.com/en-us/security/blog/2026/07/22/real-world-incident-response-microsoft-and-axa-xl-strengthen-cyber-resilience</link><guid isPermaLink="false">cst-3041</guid><description>Microsoft and AXA XL have established a partnership to integrate Microsoft Defender Experts Cybersecurity Incident Response services into AXA XL's cyber insurance offerings for policyholders. The collaboration aims to coordinate technical response, business decisions, and insurance coverage in parallel during incidents rather than sequentially, reducing response delays and risk. The model emphasizes pre-crisis alignment among security, executive, legal, and insurance teams to streamline decision-making when incidents occur.</description><pubDate>Wed, 22 Jul 2026 16:00:00 GMT</pubDate></item><item><title>Ransomware Does Not Pause While You Figure Out Who Is in Charge</title><link>https://halcyon.ai/blog/ransomware-response-authority-who-is-in-charge</link><guid isPermaLink="false">cst-3031</guid><description>Organizations face simultaneous decision-making pressures when ransomware incidents occur outside business hours, requiring clear cross-functional authority structures to respond effectively. The article outlines the need for defined ownership across multiple response tracks to avoid delays and coordination failures during critical incidents.</description><pubDate>Wed, 22 Jul 2026 15:45:20 GMT</pubDate></item><item><title>Japanese food logistics giant recovers as extortion group claims cyberattack</title><link>https://therecord.media/nichirei-japan-food-logistics-cyberattack-recovery</link><guid isPermaLink="false">cst-3020</guid><description>Nichirei Logistics Group, a major Japanese food distribution company, has restored warehouse operations and frozen food shipments following a disruption. A cybercriminal group claimed responsibility for causing the incident through a cyberattack.</description><pubDate>Wed, 22 Jul 2026 15:40:00 GMT</pubDate></item><item><title>How enterprise GenAI can amplify ransomware risk — and how to contain it</title><link>https://bleepingcomputer.com/news/security/how-enterprise-genai-can-amplify-ransomware-risk-and-how-to-contain-it</link><guid isPermaLink="false">cst-3011</guid><description>Enterprise generative AI systems can amplify ransomware risk when AI assistants inherit excessive permissions or operate with compromised identities. Organizations can mitigate this exposure through identity controls, governance frameworks, and least-privilege access models that balance security with AI adoption.</description><pubDate>Wed, 22 Jul 2026 15:30:00 GMT</pubDate></item><item><title>If you pay a hacker’s ransom, chances are that they’ll come back for more</title><link>https://techcrunch.com/2026/07/22/if-you-pay-a-hackers-ransom-chances-are-that-theyll-come-back-for-more</link><guid isPermaLink="false">cst-3028</guid><description>Security researchers observe that paying ransoms to attackers creates perverse incentives, as threat actors have no genuine reason to cease targeting an organization once payment is made. The dynamic mirrors traditional extortion, where capitulation signals vulnerability rather than resolution.</description><pubDate>Wed, 22 Jul 2026 15:29:41 GMT</pubDate></item><item><title>Suno, Paidwork Data Breaches Affect Tens of Millions of Accounts</title><link>https://securityweek.com/suno-paidwork-data-breaches-affect-tens-of-millions-of-accounts</link><guid isPermaLink="false">cst-3015</guid><description>Data breaches at Suno and Paidwork exposed personally identifiable information and financial data from tens of millions of accounts. Attackers leaked names, email addresses, phone numbers, passwords, and financial information from both platforms.</description><pubDate>Wed, 22 Jul 2026 15:02:11 GMT</pubDate></item><item><title>Greedy ransomware crews return for seconds after victims cough up first extortion payments</title><link>https://databreaches.net/2026/07/22/greedy-ransomware-crews-return-for-seconds-after-victims-cough-up-first-extortion-payments?pk_campaign=feed&amp;pk_kwd=greedy-ransomware-crews-return-for-seconds-after-victims-cough-up-first-extortion-payments</link><guid isPermaLink="false">cst-3027</guid><description>A Proofpoint survey of UK organizations found that 58 percent of those hit by ransomware paid the initial extortion demand. Among organizations that paid, 22 percent were targeted again by the same or different threat actors seeking additional payments.</description><pubDate>Wed, 22 Jul 2026 14:34:35 GMT</pubDate></item><item><title>Chick-fil-A discloses data breach after credential stuffing attacks</title><link>https://bleepingcomputer.com/news/security/chick-fil-a-discloses-data-breach-after-credential-stuffing-attacks</link><guid isPermaLink="false">cst-2975</guid><description>Chick-fil-A disclosed a data breach affecting customer accounts compromised through credential stuffing attacks. The restaurant chain is notifying affected customers as part of its response to the incident.</description><pubDate>Wed, 22 Jul 2026 06:40:29 GMT</pubDate></item><item><title>Milford, New Hampshire Confirms Unauthorized Activity, Withholds Details of Suspected Cyberattack</title><link>https://databreaches.net/2026/07/21/milford-new-hampshire-confirms-unauthorized-activity-withholds-details-of-suspected-cyberattack?pk_campaign=feed&amp;pk_kwd=milford-new-hampshire-confirms-unauthorized-activity-withholds-details-of-suspected-cyberattack</link><guid isPermaLink="false">cst-2974</guid><description>Milford, New Hampshire confirmed unauthorized activity affecting town systems beginning July 15 but has not disclosed specific details about the suspected cyberattack. The town issued alerts to residents about the incident, though the full scope and nature of the compromise remain unclear.</description><pubDate>Wed, 22 Jul 2026 00:01:07 GMT</pubDate></item><item><title>Human-in-the-Loop vs Human-on-the-Loop: What's the Difference?</title><link>https://reliaquest.com/blog/human-in-the-loop-vs-human-on-the-loop</link><guid isPermaLink="false">cst-3203</guid><description>The article contrasts human-in-the-loop and human-on-the-loop oversight models for AI-driven security operations centers (SOCs). Human-in-the-loop, which requires analyst approval for every AI action, creates bottlenecks at scale when SOCs handle thousands of daily alerts. Human-on-the-loop, where AI acts autonomously while humans monitor and can intervene, offers better efficiency for mid-risk, reversible decisions while reserving human pre-approval for irreversible, high-consequence actions like system isolation.</description><pubDate>Wed, 22 Jul 2026 00:00:00 GMT</pubDate></item><item><title>Police dismantle Kratos phishing platform, arrest developer</title><link>https://bleepingcomputer.com/news/security/police-dismantle-kratos-phishing-platform-arrest-developer</link><guid isPermaLink="false">cst-2969</guid><description>German and US authorities dismantled the Kratos phishing-as-a-service platform and arrested its developer in Indonesia. The operation targeted the infrastructure supporting a platform that enabled phishing campaigns globally. Law enforcement cooperation disrupted a significant threat delivery mechanism.</description><pubDate>Tue, 21 Jul 2026 23:07:33 GMT</pubDate></item><item><title>Ransomware Is Accelerating, But It's Not Because of AI</title><link>https://darkreading.com/cyberattacks-data-breaches/ransomware-is-accelerating-not-ai</link><guid isPermaLink="false">cst-2964</guid><description>Researchers attribute the acceleration of ransomware attacks to ecosystem fragmentation, new threat actors entering the market, and expanding targeting of organizations with weaker defenses, rather than artificial intelligence-driven acceleration.</description><pubDate>Tue, 21 Jul 2026 21:48:05 GMT</pubDate></item><item><title>Cyberattack against Maine telecom disrupted municipal internet service in 23 towns</title><link>https://databreaches.net/2026/07/21/cyberattack-against-maine-telecom-disrupted-municipal-internet-service-in-23-towns?pk_campaign=feed&amp;pk_kwd=cyberattack-against-maine-telecom-disrupted-municipal-internet-service-in-23-towns</link><guid isPermaLink="false">cst-2967</guid><description>A cyberattack against a Maine telecommunications company on Sunday disrupted internet service across 23 towns in the midcoastal region. At least one municipal government, including the town of Damariscotta, experienced service loss as a result of the incident.</description><pubDate>Tue, 21 Jul 2026 19:07:18 GMT</pubDate></item></channel></rss>