Visualização normal

Hoje — 9 de Setembro de 2026Cybersecurity News
  • ✇Security Affairs
  • Massive Vietnam-Linked APIS Database Exposes Passport and Flight Data Pierluigi Paganini
    An exposed Vietnam-linked APIS database contained 220.8 million passenger and crew records, including passport and flight data. Researchers found an exposed Advance Passenger Information System (APIS) database containing 220.8 million passenger and crew records from January 2017 to April 2026. The data includes sensitive details such as passport numbers, identities and flight information, potentially affecting travelers of many nationalities who flew to, from or through Vietnam. Kinryū L
     

Massive Vietnam-Linked APIS Database Exposes Passport and Flight Data

8 de Setembro de 2026, 08:01

An exposed Vietnam-linked APIS database contained 220.8 million passenger and crew records, including passport and flight data.

Researchers found an exposed Advance Passenger Information System (APIS) database containing 220.8 million passenger and crew records from January 2017 to April 2026.

The data includes sensitive details such as passport numbers, identities and flight information, potentially affecting travelers of many nationalities who flew to, from or through Vietnam. Kinryū Labs discovered the Elasticsearch cluster, named “pax-info,” while searching for exposed databases.

It contained 29 indices and about 107 GB of data. The researchers linked the server to IP space assigned to Viettel in Hanoi, but could not confirm which Vietnamese organization operated it.

Researchers found an exposed APIS database linked to Vietnam that contained more than 220 million passenger and crew records from 2017 to 2026. The data included passport numbers, identities and flight details. The Elasticsearch database, discovered by Kinryū Labs, held about 107 GB of data across 29 indices. It was hosted on IP addresses assigned to Viettel in Hanoi, although researchers could not confirm which Vietnamese organization operated the system.

The exposed database contained names, dates of birth, sex, nationalities, passport or travel-document numbers, expiration dates and issuing countries, BleepingComputers reports.

It also included flight numbers and dates, airlines, departure and destination airports, transit airports, seat numbers, baggage references, and scheduled, estimated and actual flight times. The database covered many airlines across Asia-Pacific, Europe and the Middle East, so it could affect people from around the world who traveled to or through Vietnam between 2017 and 2026.

Kinryū Labs confirmed the data was real by matching records with its researchers’ own trips to Vietnam. The total also counts travel records, not unique people, so frequent travelers may appear multiple times.

While the researchers could not provide a complete breakdown by nationality, the data covered numerous international airlines across Asia-Pacific, Europe, and the Middle East. As a result, the exposed records could relate to people from virtually anywhere who visited or transited through Vietnam over the nine-year period.

Kinryū Labs verified that the information was legitimate by matching records in the database against its researchers’ own travel to Vietnam.

The figures represent travel records rather than unique individuals. Passengers and crew members who flew multiple times may therefore appear repeatedly in the database.

Kinryū Labs reached the exposed database by combining two security misconfigurations. Direct internet access returned a 401 error, but another cloud-based path exposed the cluster and accepted default credentials.

FOFA first detected the host in 2022 and identified it as a database in 2023, but researchers could not determine when the passenger data became accessible. The records cover more than nine years, but the actual exposure period remains unknown.

Kinryū Labs reported the issue to Vietnamese authorities, affected airlines and national CERTs on June 3. The database was secured by June 8, with Singapore Airlines helping coordinate the response.

Researchers found no evidence that the listed airlines operated the system or suffered a network breach. They also found no ransom notes or signs that attackers had altered the database.

However, without server logs, they could not determine whether anyone had copied or stolen the data before the system was secured.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, APIS)

  • ✇Security Affairs
  • Condé Nast Data of 32.8 Million Users Offered for Sale After WIRED Leak Pierluigi Paganini
    Condé Nast user data from 32.8 million accounts is reportedly for sale, raising risks of targeted phishing, fraud and scams. A database said to contain 32.8 million Condé Nast user records is being offered for $15,000 on a Russian-language cybercrime forum. Ransomnews reviewed a 5,000-record sample and concluded that it is consistent with genuine Condé Nast account data collected between September and late October 2025, including records that have not appeared publicly before. Ransomnews’ or
     

Condé Nast Data of 32.8 Million Users Offered for Sale After WIRED Leak

7 de Setembro de 2026, 16:40

Condé Nast user data from 32.8 million accounts is reportedly for sale, raising risks of targeted phishing, fraud and scams.

A database said to contain 32.8 million Condé Nast user records is being offered for $15,000 on a Russian-language cybercrime forum. Ransomnews reviewed a 5,000-record sample and concluded that it is consistent with genuine Condé Nast account data collected between September and late October 2025, including records that have not appeared publicly before. Ransomnews’ original report provides the underlying analysis.

The alleged dataset covers users across Condé Nast’s publishing portfolio, which includes Vogue, The New Yorker, GQ, Glamour, WIRED, Vanity Fair and other titles. Condé Nast has not publicly confirmed the breach or commented on the new sale listing.

The seller claims the database contains 32,815,767 unique email addresses. It also allegedly includes names, postal addresses, gender, dates of birth and phone numbers for portions of the population, but no passwords, password hashes, usernames or payment-card data.

“A database of 32,815,767 Condé Nast user records went on sale on a Russian-language hacker forum on 7 September 2026 for $15,000, offered as the full set behind December’s WIRED leak.” Ransomnews states. “Ransomnews tested the 5,000-row sample: it is genuine Condé Nast account data, captured in September and October 2025, and the 30.5 million non-WIRED records have not surfaced publicly before. Condé Nast has never commented on the breach.”

Ransomnews found that 31.6% of records allegedly include both first and last names, 22.3% include a postal address, 17.5% include gender, 12.6% include a date of birth and 2.9% include a phone number. The data is valuable because it can be filtered and combined with other information, not because every record contains every field.

The listing claims to include the full dataset behind the December 2025 leak involving WIRED, one of Condé Nast’s best-known publications. The seller says that a separate version excluding WIRED contains 30,455,594 records, which implies a WIRED subset of roughly 2.36 million records.

That figure closely matches the 2,366,576 WIRED records made public in December 2025. SecurityWeek previously reported that the actor behind that leak, using the name “Lovely,” claimed to have stolen more than 40 million Condé Nast records and threatened to release data linked to other publications.

Here’s a simpler and more natural version:

The numbers connect the new listing to the earlier WIRED breach, but they don’t prove that the seller is the original attacker. The seller could be the same person, a partner, or someone who got the data later.

The sample does not look like a recycled copy of the public WIRED leak. It contains names and street addresses at higher rates than the earlier WIRED dataset, has a different field structure and shows a demographic distribution that fits a broader collection of Condé Nast consumer titles, including publications with predominantly female readerships.

Ransomnews did not test the records against live Condé Nast accounts, which would have created further privacy risks. Instead, it used internal consistency checks to determine whether the sample behaved like a real long-running consumer database.

The 5,000-record sample closely matched the seller’s claims, with field-completion rates differing by only 1.2 percentage points. Among records with full names, 61.9% had an email address that matched the name or its initials. When names were randomly mixed between records, that figure fell to just 0.3%.

The data also passed basic time and location checks. None of the 227 records using Apple Relay, iCloud, Outlook, Me.com or Proton addresses appeared to predate those services. Also, 96.4% of U.S. ZIP codes matched the listed state, while 93.5% matched the listed city.

Messy data can be useful evidence. Fields such as “Select your state,” numeric dropdown values, inconsistent country labels, lower-case names and dates of birth set to 1 January are the kind of ordinary web-form errors that accumulate in a database built over decades. Fabricated data is usually cleaner. Real data is often embarrassingly human.

Account-creation dates in the sample run from February 1999 to 23 October 2025. Ransomnews notes that new-account entries thin sharply from September 2025 onward, which suggests the extraction took place over several weeks between September and late October.

That timing fits the earlier incident. The public WIRED leak contained records dated through September 2025, while the person calling themselves Lovely contacted DataBreaches.net in November and the WIRED material appeared online in December.

SecurityWeek’s earlier analysis said the attacker’s technical claims were consistent with insecure direct object reference, or IDOR, and broken access-control issues. In that kind of failure, an application lets one user view or alter another user’s data because it checks identifiers but fails to verify authorisation properly.

The seller’s account is new, has little visible reputation and offers escrow, according to Ransomnews. That profile fits a seller seeking a single buyer rather than public attention, especially when the dataset is priced at less than one-twentieth of a cent per record.

A public dump produces headlines. A private sale can produce a more focused problem: a buyer can use the data for phishing, lead generation, fraud, credential-stuffing preparation or correlation with other leaked datasets without ever publishing the full file.

The absence of passwords does not make the data harmless. A person who subscribed to Vogue, booked a gift subscription for GQ or registered for The New Yorker may receive a message that accurately uses their name, address and publication relationship. That is enough to make a fake renewal, refund or billing request look far more credible than ordinary spam.

Readers should treat unexpected messages about subscription renewals, billing problems, delivery issues, gifts or account verification with caution. Instead of using an email link, open the publisher’s website directly through a known address and check the account there.

A password reset is not the first priority based on this dataset alone, because no passwords or password hashes were found in the sample. However, anyone who reused the same email address across many services should be alert to follow-on phishing and should use a password manager and multi-factor authentication on important accounts.

Postal addresses were present in more than one-fifth of the claimed records. That means fraud may also arrive as physical mail, not only by email or SMS. A letter that references a real magazine title or subscription is not proof that it is genuine.

The more uncomfortable lesson is about breach economics. An attacker can release a small, recognisable subset to demonstrate that the data is real, then hold the larger collection back until a buyer appears. The public sees a leak. The criminal market sees inventory.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, data breach)

  • ✇Firewall Daily – The Cyber Express
  • Exposed Database Left 220Mn Airline Passenger, Crew Records Open to the Internet Mihir Bagwe
    A misconfigured Elasticsearch cluster exposed roughly 220.8 million airline passenger and crew records, including passport numbers and full itineraries, before it was secured in June, researchers at Kinryu Labs disclosed. The records spanned January 2017 through April 2026 and came from an Advance Passenger Information System deployment - the standardized data feed airlines transmit to border authorities before departure, covering traveler identity and flight details. Researchers linked the ser
     

Exposed Database Left 220Mn Airline Passenger, Crew Records Open to the Internet

8 de Setembro de 2026, 11:51

Airline, Data Leak,

A misconfigured Elasticsearch cluster exposed roughly 220.8 million airline passenger and crew records, including passport numbers and full itineraries, before it was secured in June, researchers at Kinryu Labs disclosed.

The records spanned January 2017 through April 2026 and came from an Advance Passenger Information System deployment - the standardized data feed airlines transmit to border authorities before departure, covering traveler identity and flight details. Researchers linked the server to IP address space assigned to Vietnamese telecommunications operator Viettel in Hanoi but said they could not confirm which organization operated it.

What was exposed

As per BleepingComputer, the data set combined identity documents with granular travel history. Exposed fields included names, dates of birth, sex and nationality; passport or travel document numbers, expiration dates and issuing countries; and flight numbers and dates, airline names, departure, destination and transit airports, seat numbers, baggage references, and scheduled, estimated and actual flight times.

That combination is unusually sensitive. Passport numbers are difficult to change and useful for identity fraud and account takeover at travel providers, while the itinerary fields - particularly transit airports and actual flight times - allow reconstruction of an individual's movements over nine years. Security researchers have long flagged APIS-style data as a surveillance risk precisely because it maps people to places at fixed times.

Also read: Why Airline Data Breaches Matter – And Why Qantas Could Have Been Worse

Two misconfigurations

According to Kinryu Labs, the cluster was protected inconsistently. Direct access over the internet returned an HTTP 401 authentication error, which would give a casual scanner the impression the system was locked down. An alternative cloud-based access path, however, reached the same cluster and accepted default credentials.

The exposure appears to have been long-lived. Internet scanning service FOFA detected the host in 2022 and identified it as a database in 2023. Kinryu Labs reported the issue on June 3, 2026, and the cluster was secured by June 8. Singapore Airlines assisted in coordinating the response, the researchers said. There is no indication any airline was itself breached or operated the server.

Researchers said they found no evidence the data was stolen, but noted that without server logs they could not determine whether anyone copied it during the years it was reachable — a distinction that matters more than it may appear, because notification obligations in several jurisdictions turn on whether unauthorized access can be ruled out.

Compliance exposure

Vietnam's Personal Data Protection Law, Law No. 91/2025/QH15, took effect Jan. 1, 2026 - before the exposure was reported and remediated. The statute requires notification within 72 hours of detecting a violation, rather than from the time it occurred, and expands notification duties to affected individuals in defined circumstances. Its penalty ceiling for general violations is 3 billion Vietnamese dong, with cross-border transfer breaches exposed to fines of up to 5% of prior-year revenue.

Because the records cover international flights, EU and UK residents are almost certainly represented, which brings GDPR and UK GDPR into scope for any controller established in or targeting those markets. Passport numbers and travel history fall squarely within personal data, and passenger data processing has drawn repeated scrutiny from European data protection authorities.

Ontem — 8 de Setembro de 2026Cybersecurity News
  • ✇Security | CIO
  • The EU AI Act just gave you a breach notification clock you didn’t know about
    Most security teams already have a breach clock memorized. GDPR gives you 72 hours. SEC rules give public companies four business days after determining an incident is material. Those numbers get built into incident response runbooks, tabletop exercises and escalation paths, because the clock starts the moment the team confirms something happened. Article 73 of the EU AI Act adds a third clock, and in my work advising enterprise clients on AI governance, I have yet to s
     

The EU AI Act just gave you a breach notification clock you didn’t know about

8 de Setembro de 2026, 07:00

Most security teams already have a breach clock memorized. GDPR gives you 72 hours. SEC rules give public companies four business days after determining an incident is material. Those numbers get built into incident response runbooks, tabletop exercises and escalation paths, because the clock starts the moment the team confirms something happened.

Article 73 of the EU AI Act adds a third clock, and in my work advising enterprise clients on AI governance, I have yet to see one with a runbook for it.

The obligation took effect on August 2, and it did so alone. The EU’s Digital Omnibus on AI, in force since late July, pushed the rest of the Act’s high-risk enforcement wave — classification, conformity assessment, technical documentation — back to December 2027. Article 73 was not part of that reprieve, though the extra time elsewhere is worth using to get ready. It requires providers of high-risk AI systems to report serious incidents to national market surveillance authorities within 15 days by default, 10 days if a death is involved and just 2 days for incidents the Act classifies as widespread or as a serious disruption to critical infrastructure. Coverage of Article 73 so far has treated it as a legal filing requirement, handled through the same channel as a data protection filing. That framing misses what the obligation is. It is an incident response deadline, and it runs on a different trigger than the breach clocks most security teams already know.

A client once asked me, almost as an aside, whether their customer-facing AI tool would trigger a reporting duty if it simply gave someone bad information rather than getting hacked. At the time, the honest answer was probably not, under any framework they were tracking. Article 73 changes that, and most organizations building or buying AI for the EU market have not caught up yet.

What counts as a trigger here is broader than most teams expect

GDPR’s 72-hour clock starts when you become aware of a personal data breach. That is a bounded question. Did data leave the environment? Was it accessed without authorization? Article 73 asks something harder. The European Commission’s draft guidance takes the position that an indirect causal link between an AI system and a downstream harm is enough to trigger the reporting duty. Their example is a loan denial that traces back to a flawed AI credit assessment. The AI system does not cause harm the moment it produces the assessment, only once a human acts on it and denies the loan. The fundamental rights category requires the infringement to interfere with Charter-protected rights at scale, which is why the Commission illustrates that threshold with patterns, a recruitment tool that discriminates systematically or a credit system that categorically rejects an entire neighborhood. Under the Commission’s reading, once a pattern like that exists, the clock starts when the provider becomes aware of it, not when the system generated the output.

Here’s a plainer version of that pattern. A public benefits agency uses an AI system to match applicants against its records. A flaw in the matching logic occasionally conflates applicants, and over several weeks it happens to a run of different people, each flagged as already receiving the same benefit elsewhere and suspended. Nobody catches the pattern at the time, because each flag looks unremarkable on its own. Applicants don’t find out until their payments stop arriving, weeks after the first mismatch. The system never malfunctioned in any way security tooling would catch. It just produced bad matches until people started missing payments.

That is a different kind of determination than “Did we get breached?” It requires tracing a causal chain from a model output through a downstream decision to an actual harm, then judging how confident you are in that link before you are required to report it. Most incident response teams have a well-practiced instinct for confirming unauthorized access, but few have one for confirming that an AI system caused a harm that surfaced elsewhere in the business, days or weeks later. I have watched security leaders confidently answer, “Were we breached?” in minutes, then go quiet when asked, “Did our AI system cause this?” because nobody owns that second question yet.

Why this does not fit into an existing IR playbook

Most incident response programs are built around a single moment: detection. Something trips an alert, a SOC analyst confirms it and the clock starts. Article 73 incidents will not look like that at all. The AI system that produced the flawed output may show no signs of compromise. Nothing gets flagged by a SIEM. The first sign might come from a customer complaint, an internal audit finding or a pattern a compliance analyst notices months after the AI system made the decision.

That means the “becoming aware” clause in Article 73 is doing real work, and most organizations have not decided who is responsible for noticing. Is it the team monitoring the AI system’s technical performance, the business unit acting on its outputs, or whoever eventually hears the complaint? Under Article 73, the clock starts when any of them establishes, or suspects, the causal link, and 15 days is not a long runway if the first internal conversation about “is this our incident” does not happen until day six or seven. I have seen governance structures where a business unit head, a model risk team and security each assumed someone else owned this judgment call. In practice nobody did, and that gap is where a 15-day clock burns down to five.

Some security teams are already mapping agent governance to a maturity model, arguing that oversight must scale with autonomy, moving from agent identities that are barely inventoried toward ones that are bounded, monitored and revocable in real time. Article 73 raises the stakes on that model considerably. The less a human reviews an AI system’s output before it reaches a customer, the more likely a downstream harm surfaces without anyone watching for it in real time, which is exactly the blind spot Article 73 is designed to close.

What needs to change

A few additions belong in an existing incident response program before this becomes a live problem instead of a paper requirement.

First, a defined owner for the causal link determination. Data breach response usually has a clear owner: security confirms the technical facts, legal makes the materiality call. Article 73 needs an equivalent split: Someone technical enough to trace an AI system’s output to a downstream decision and someone with authority to make the reporting call once that link looks plausible rather than certain. In practice, I recommend naming this owner in the incident response plan, not leaving it to be sorted out during the first real incident, when the clock is already running.

Second, a lower bar for opening an investigation. If GDPR taught teams to investigate the moment unauthorized access is suspected, Article 73 requires investigating the moment a downstream harm is suspected to trace back to an AI system, when the system looks normal to security monitoring. That means feeding business unit complaints and customer escalations into the same triage process that currently only starts from technical alerts.

Third, a documented decision log for the indirect link judgment call. Given how broadly the Commission has defined what counts as reportable, organizations will make defensible calls not to report many ambiguous situations. Those decisions need to be documented with the reasoning behind them, the way a security team documents a false positive call, because a regulator revisiting that judgment months later will expect to see how it was made rather than take the outcome on faith.

Fourth, controls built into the AI system, not bolted on after the fact. A defined owner and a lower investigation bar help catch a problem once it surfaces, but neither reduces how often a flawed output reaches a customer first. Scoped credentials, tool allowlists and pre-action approval hooks cut down on how many incidents exist to report.

The AI Act’s high-risk obligations have absorbed most of the attention this year, because conformity assessments and technical documentation are heavy lifts with long lead times. Article 73 looks lighter by comparison, a reporting duty rather than a certification process. It is not lighter. It asks security and compliance teams to build a new kind of judgment into their incident response programs, on a clock as tight as anything GDPR or the SEC have required. Treat the deferral on the rest of the high-risk package as what it actually is, extra runway to build that judgment and name its owner, because the conformity paperwork still gives you months and Article 73 still gives you days.

Antes de ontemCybersecurity News
  • ✇Security Affairs
  • Berlin Ransomware Leak Exposes State Secrets Pierluigi Paganini
    Berlin refused a 30 Bitcoin ransom, leading hackers to leak 6TB of sensitive state administration and national defense data on the dark web. When a ransomware gang dumps nearly six terabytes of state administration files onto the dark web, ignoring them does not make the problem go away. The Rhysida ransomware group recently carried out this exact threat against Berlin after local authorities refused to pay a thirty Bitcoin ransom. At the end of August, Berlin’s state government confirmed
     

Berlin Ransomware Leak Exposes State Secrets

7 de Setembro de 2026, 04:19

Berlin refused a 30 Bitcoin ransom, leading hackers to leak 6TB of sensitive state administration and national defense data on the dark web.

When a ransomware gang dumps nearly six terabytes of state administration files onto the dark web, ignoring them does not make the problem go away. The Rhysida ransomware group recently carried out this exact threat against Berlin after local authorities refused to pay a thirty Bitcoin ransom.

At the end of August, Berlin’s state government confirmed it was dealing with an extortion attempt following an August cyberattack on the city-state’s administrative network, and officials have already refused the requested ransom. The ransomware group Rhysida claimed responsibility on its leak site August 28, posting an entry titled simply “Berlin, Germany” and claiming 5.79 terabytes of data across roughly 1.44 million files, with personal information on 12,076 individuals allegedly included.

Rhysida claimed it stole 5.79 TB of data, covering around 1.44 million files. The alleged dataset includes:

  • Personal data: 12,076 individuals, 16,389 email addresses, 11,963 phone numbers and 148 IBANs.
  • Sensitive records: more than 5,000 personnel files, more than 5,000 administrative-offence files, payroll data and leadership information.
  • Credentials: plaintext passwords and credentials for systems including GebäudAtlas, the ePayment PAYONE database and Z_ADMIN accounts.
  • Government and legal material: disciplinary proceedings, court cases, supervisory documents, NDA records and Bundesrat committee protocols.
  • Classified information: data related to classified-material handling and documents allegedly containing state secrets.
  • Critical infrastructure: vulnerability analyses concerning Berlin’s water supply.
  • Identity documents: passports and ID cards from personnel records.
  • Other material: contracts, financial documents, HR records, infrastructure files, health data, password stores and SQL/PST archives.

The group also claimed that the material could involve violations of GDPR, German classified-information rules, criminal law and KRITIS/BSIG requirements. These are Rhysida’s claims and have not been independently verified.

The scale of the breach is staggering. Investigators are now looking at roughly 1.4 million files containing personal details of civil servants, internal infrastructure records, and critical government data.

The fallout goes far beyond routine data theft. Investigative journalist Lars Winkelsdorf pointed out the gravity of the situation on social media.

Die absolute Vollkatastrophe ist eingetreten

Dieses Datenleck ist schlimmer als alle bisherigen Terroranschläge zusammen 1/xhttps://t.co/epU4mCYgew

— Lars Winkelsdorf (@winkelsdorf) September 4, 2026

“In addition to LKA documents related to investigations, the files also include plans concerning national defense—ranging from the federal government’s secret communication channels in the event of an apocalypse to defense-related companies and emergency plans developed by government agencies,” Winkelsdorf wrote.

Exposing crisis response plans and secret communication channels turns a financial shakedown into a national security headache.

Worse still, the leaked material includes files concerning chemical, biological, radiological, and nuclear threats.

“Among the published files is a folder titled “AG CBRN-Rahmenplanung.” CBRN stands for chemical, biological, radiological and nuclear threats,” notes the Euronews report

Having that kind of operational data floating around public forums gives hostile actors a blueprint for disaster.

Refusing to pay ransoms is the right policy, but it rarely stops the bleeding once the network is compromised. Governments keep treating cybersecurity like an IT expense rather than an existential line of defense.

Until boards start treating network segmentation with the same seriousness as physical security, we will keep watching expensive countdown timers tick down to zero.

Berlin’s state government announced the launch of a crisis response after the threat actors published the stolen data.

“A ‌central ⁠crisis unit will oversee the review, verification and assessment of the leaked data and support efforts to inform affected citizens and ​businesses, said the ​city.” Reuters reports.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, Berlin)

How a hole in Lenovo’s login system let hackers walk into 5,000 Dropbox accounts

7 de Setembro de 2026, 07:30
If you ever linked your Dropbox account to a Lenovo ID - perhaps to make life easier when logging in via a Lenovo laptop - you might want to take heed. Read more in my article on the Hot for Security blog.
  • ✇Firewall Daily – The Cyber Express
  • Mathspace Breach Impacts More Than 1 Million Users in Australia, NZ Ashish Khaitan
    The Mathspace data breach has affected 1,079,819 people in Australia and New Zealand after unauthorized parties accessed an internal reporting system and downloaded user information. Mathspace confirmed the security incident on September 3, 2026, and said the affected records involve students, parents or guardians, teachers, and Mathspace staff.  The company said names, email addresses, and account details were exposed, but customer passwords, single sign-on (SSO) tokens, and other authentica
     

Mathspace Breach Impacts More Than 1 Million Users in Australia, NZ

7 de Setembro de 2026, 04:14

Mathspace data breach

The Mathspace data breach has affected 1,079,819 people in Australia and New Zealand after unauthorized parties accessed an internal reporting system and downloaded user information. Mathspace confirmed the security incident on September 3, 2026, and said the affected records involve students, parents or guardians, teachers, and Mathspace staff.  The company said names, email addresses, and account details were exposed, but customer passwords, single sign-on (SSO) tokens, and other authentication credentials were not. There is currently no evidence that the information has been published, sold, distributed, or otherwise misused. The attacker’s identity remains unknown. 

How the Mathspace Data Breach Happened? 

The security incident resulted from a vulnerability in Mathspace’s self-hosted Metabase installation, which was used for internal reporting. The flaw allowed attackers to obtain administrator access without a legitimate login.  Metabase issued a critical security advisory and patched versions on August 6. Mathspace said its vulnerability-notification process failed to identify and escalate that advisory. The company later updated its Metabase instance on August 29 after seeing a subsequent notice.  An investigation found unauthorized access dating to August 10, Australian Eastern Standard Time. Information was downloaded from Mathspace’s Australian reporting database on August 27. Historical log reviews confirmed the unauthorized access on September 3, before the update had been applied. Mathspace also acknowledged that it did not complete additional compromise checks recommended for potentially affected systems at the time of the update. 

What Information was Exposed? 

The exported data included user IDs, usernames, first and last names, email addresses, country, time zone, user type, email-verification status, last-active date, last-login date and joining date. Not every field appeared for every affected person.  Mathspace said the exposure went beyond names and email addresses. User IDs are internal identifiers, including those linked to student accounts. However, no academic records, learning activities, results, assessments, password hashes, authentication tokens, SSO credentials or API credentials were exposed.  The data did not contain records directly linking accounts to schools, although Mathspace said school affiliations could potentially be inferred where identifiable email domains were used. Former or inactive users may also be affected because retained information could remain in the reporting database. 

What Users Should Know After the Security Incident? 

Names, email addresses, and account details could make phishing or impersonation attempts more convincing. Users have been advised to independently verify unexpected messages, avoid unfamiliar links and attachments, and never provide passwords or verification codes in response to unsolicited communications.  Mathspace is not requiring password resets because customer authentication credentials were not exposed. However, anyone who reused a Mathspace password elsewhere should change those reused passwords to unique ones and monitor accounts for unusual activity. 

Response to the Mathspace Data Breach 

After confirming the breach on September 3, Mathspace took Metabase offline, revoked its API keys, disabled Metabase database-access accounts in its Australian and US Snowflake environments, and changed passwords for its Metabase Cloud SQL databases. The company also copied the application database and exported access logs for investigation. Metabase remains offline while recovery and compromise checks continue.  Mathspace began notifying school contacts on September 4 and started notifying affected individuals on September 6, earlier than the date previously communicated to schools.  On September 4, the security incident was reported to Australia’s Office of the Australian Information Commissioner, the Australian Signals Directorate’s Australian Cyber Security Centre, New Zealand’s Office of the Privacy Commissioner and National Cyber Security Centre, as well as Australian state and territory education departments. 

Natural Resources Wales Data Breach Exposes Sensitive Employee Diversity Data

Natural Resources Wales (NRW) has reported a personal data breach involving sensitive diversity-monitoring information from both former and current employees. The breach affected individuals whom NRW employed between April 2013 and March 2018. An internal investigation revealed that a spreadsheet containing employee data was accidentally published online, making the information accessible before the issue was […]

The post Natural Resources Wales Data Breach Exposes Sensitive Employee Diversity Data appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

  • ✇Security Affairs
  • SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 113 Pierluigi Paganini
    Security Affairs Malware newsletter includes a collection of the best articles and research on malware in the international landscape Malware Newsletter Hackers Steal Claude Login Sessions With Infostealer Malware to Hijack Accounts Fire Ant Evolves: From Hypervisors to Trusted Infrastructure       Gryxa: The AI-Built Toolkit That Watches How You Remove It ValleyRAT masquerading as adware   13 Malicious Packagist Themes Deliver iOS Spyware That Steals Crypto Wallet Seeds  
     

SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 113

6 de Setembro de 2026, 05:27

Security Affairs Malware newsletter includes a collection of the best articles and research on malware in the international landscape

Malware Newsletter

Hackers Steal Claude Login Sessions With Infostealer Malware to Hijack Accounts

Fire Ant Evolves: From Hypervisors to Trusted Infrastructure      

Gryxa: The AI-Built Toolkit That Watches How You Remove It

ValleyRAT masquerading as adware  

13 Malicious Packagist Themes Deliver iOS Spyware That Steals Crypto Wallet Seeds  

Mirage Kitten targeting aviation and FinTech sectors across the Middle East and Africa with a new malware set

Uncovering StreamRat: From Meta Ads to Full Device Takeover  

Counterfeit installers to system compromise: Tracking a deceptive software download campaign

Gaming the system: how a Chinese-speaking actor turned Brazilian government sites into an SEO weapon September 2, 2026

Mini Shai-Hulud’s Latest Wave: 280 New Places It Hunts for Your Secrets  

Pegasus Spyware Infection of Serbian Pro-Democracy Student Activist 

Chinese-Speaking Operator Uses AI Agents to Target Government and Education Systems Across Asia

DPRK APTs: Ted backdoor and curlRAT target South Korean media and automotive sectors

Anatomy of BraZetsu: How Cybercriminals Fuel the Underground Ecosystem

Peer Pressure: Inside the Sality Botnet Disruption Operation

Graph-Based Learning for Android Authorship Attribution: A Comparative Analysis of GNN Models

Stability and Hopf Criteria in a Malware Dissemination Model for Wireless Sensor Networks with Distributed Recovery Delays

PhantomCall: Evading ML Malware Detectors via Function Call Graph Perturbation

REPLICANT: Learning Policies for Evading and Hardening Malware Detectors

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, newsletter)

  • ✇Security Affairs
  • Security Affairs newsletter Round 593 by Pierluigi Paganini – INTERNATIONAL EDITION Pierluigi Paganini
    A new round of the weekly Security Affairs newsletter has arrived! Every week, the best security articles from Security Affairs are free in your email box. Enjoy a new round of the weekly SecurityAffairs newsletter, including international press. PaperCut Flaws Exploited in Attacks on U.S. and European SchoolsBroadcom Patches Critical VMware Workstation and Fusion VM-Escape VulnerabilitiesU.S. CISA adds Google Chromium V8 flaw to its Known Exploited Vulnerabilities catalogCrooks Behind Ma
     

Security Affairs newsletter Round 593 by Pierluigi Paganini – INTERNATIONAL EDITION

6 de Setembro de 2026, 04:56

A new round of the weekly Security Affairs newsletter has arrived! Every week, the best security articles from Security Affairs are free in your email box.

Enjoy a new round of the weekly SecurityAffairs newsletter, including international press.

PaperCut Flaws Exploited in Attacks on U.S. and European Schools
Broadcom Patches Critical VMware Workstation and Fusion VM-Escape Vulnerabilities
U.S. CISA adds Google Chromium V8 flaw to its Known Exploited Vulnerabilities catalog
Crooks Behind Manchester Airports Group Hack Leaked Data of 8.8 Million People
PostgreSQL Hit by 12-Year-Old Vulnerability Allowing Server Takeover
Chinese Hackers Use AI Agents in Multi-Country Cyber Campaign
Google fixes the sixth actively exploited Chrome zero-day of 2026
Dark Web Service Nexus Sells 153M+ Driver’s Licenses
2,000 Leaked Documents Reveal How Russia Turns Engineering Students Into GRU Cyber Operators
OpenAI Astra Brings Autonomous Zero-Day Exploitation to AI
SonicWall Patches Two New Actively Exploited Zero-Days in SMA 1000 VPNs
$536 and 8 Hours: AI Learns to Attack a Different PLC
Iran-linked APT Mirage Kitten Uses Fake Job Tests to Spread Malware
Hackers Target Langflow in CVE-2026-0768 Attacks
Attackers Access Aesto Health AWS Infrastructure, Exposing 9.5 Million Records
Chaotic Eclipse Releases GenDigital Avast Antivirus ZeroDay PrettyPrague
Five Venezuelan Nationals Plead Guilty in Kansas ATM Jackpotting Attempt
North Korea-linked IT Workers Are Getting Hired Inside Western Companies
Chaotic Eclipse Releases Kaspersky Zero-Day HardBreacher
U.S. CISA adds PaperCut NG/MF flaws to its Known Exploited Vulnerabilities catalog
ValleyRAT: When Legitimate Software Becomes a Malware Delivery Tool
China-linked Fire Ant Hides Inside Trusted Infrastructure
Infostealers Are Hijacking Claude Sessions and Draining Subscriptions
Critical GiveWP Flaw Lets Attackers Run Commands on WordPress Servers
Extortion Group FulcrumSec Claims 86GB Manchester Airports Group Data Theft
Hackers Are Probing PaperCut Servers, and 47% Still Have No Patch

International Press – Newsletter

Cybercrime

FulcrumSec claims Manchester Airports hack, theft of 86 GB of data

Aurora ransomware targets ESXi, abuses Cursor Agent for exploitation  

FBI investigation leads to five Venezuelan nationals pleading guilty to attempting to jackpot Kansas ATMs  

FBI Probes Service Selling 153M+ Drivers Licenses

Two Nigerian Nationals Extradited from Nigeria to the United States to Face Sextortion Charges in North Carolina and Mississippi  

The Town 2025 ticketing data sold as a Ticketmaster breach 

Gaming the system: how a Chinese-speaking actor turned Brazilian government sites into an SEO weapon September 2, 2026  

Manchester Airports Group Data on 8.8 Million People Leaked After Ransom Refusal   

Attackers Exploit PaperCut Flaws to Steal Credentials From Schools and Universities

ASCII smuggling crosses over from AI prompt injection to phishing evasion

Malware

Hackers Steal Claude Login Sessions With Infostealer Malware to Hijack Accounts

Gryxa: The AI-Built Toolkit That Watches How You Remove It

ValleyRAT masquerading as adware  

13 Malicious Packagist Themes Deliver iOS Spyware That Steals Crypto Wallet Seeds  

Mini Shai-Hulud’s Latest Wave: 280 New Places It Hunts for Your Secrets  

Hacking

Eclypsium flags 1,051 CVEs in infrastructure advisories 

Unauthenticated PHP Object Injection to Remote Code Execution on GiveWP  

Kaspersky zero-day exploit HardBreacher 

PrettyPrague: GenDigital Avast Antivirus ZeroDay Elevation of Privileges Vulnerability  

Same Target, Different Playbooks: Two Attackers, Two Different Paths to Pwning the AI Stack 

Can AI Create PLC Attacks? Yes, But It’s Not That Easy Yet  

Attackers Exploit Two SonicWall SMA 1000 Zero-Days That May Form an Attack Chain

FalconFlank is a 0day privilege escalation that abuses the office malicious macros remediation in Crowdstrike Falcon 

Cloud Sync Root RegistrationShieldBreak: Hunting Windows Defender Remediation Abuse and Cloud Files Hijacking  

Google Releases Chrome Update to Patch Actively Exploited V8 Zero-Day

When Sorting Leads To Confusion  

Intelligence and Information Warfare  

Pegasus Spyware Infection of Serbian Pro-Democracy Student Activist

Fire Ant Evolves: From Hypervisors to Trusted Infrastructure

Insights into Suspected DPRK Workers: Red Flags to Look Out For   

Mirage Kitten targeting aviation and FinTech sectors across the Middle East and Africa with a new malware set  

Leaked Russian Cyber-Operations Training Materials  

Threat Intelligence Report: University Leak Exposes Russia’s Military Cyber Training Pipeline  

Chinese-Speaking Operator Uses AI Agents to Target Government and Education Systems Across Asia

How the Russians Got Inside My Phone

DPRK APTs: Ted backdoor and curlRAT target South Korean media and automotive sectors    

Cybersecurity

Judge says Pentagon’s measures against Anthropic were ‘illegal and baseless’  

How AI could make it harder for governments to use hacking tools  

Own a gun? Go to church? Do yoga? AI can find out in seconds        

Path to Astra: critical capabilities and frontier safeguards  

PostGREShell: The database powering much of the internet had an open door for 12 years 

Fighting AI with AI: The US’s New Cyber Rules of Engagement 

ATM Flaws Reveal Key Weaknesses in the Software Supply Chain 

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, newsletter)

  • ✇Security Affairs
  • Crooks Behind Manchester Airports Group Hack Leaked Data of 8.8 Million People Pierluigi Paganini
    Manchester Airports Group (MAG) data allegedly leaked by FulcrumSec exposes emails and phone numbers of 8.8 million people. Manchester Airports Group, which operates Manchester, London Stansted and East Midlands airports, has confirmed a data breach involving customer information held in a third-party database. The company says airport operations, passenger safety and aviation security were not affected, but the incident has exposed data that can make fraud far more convincing. The data
     

Crooks Behind Manchester Airports Group Hack Leaked Data of 8.8 Million People

4 de Setembro de 2026, 15:30

Manchester Airports Group (MAG) data allegedly leaked by FulcrumSec exposes emails and phone numbers of 8.8 million people.

Manchester Airports Group, which operates Manchester, London Stansted and East Midlands airports, has confirmed a data breach involving customer information held in a third-party database. The company says airport operations, passenger safety and aviation security were not affected, but the incident has exposed data that can make fraud far more convincing.

The data related to parking, lounge and Fast Track bookings, as well as airport Wi-Fi sign-ups. MAG said attackers took email addresses, phone numbers, vehicle registration details and postcodes, while payment-card data was not accessed.

The group disclosed the incident on 27 August and said it had contained the risk, engaged specialist advisers and notified relevant authorities.

The extortion group FulcrumSec claimed responsibility for the intrusion and leaked the data after MAG had refused its ransom demand.

“Today we are releasing the Manchester Airports Group dataset: every customer, event, configuration that serves Manchester Airport, London Stansted and East Midlands Airport. Half a terabyte, and every byte of it is pure PII. However, we have decided to withhold the most dangerous part of the breach : the nearly 200,000 passengers whose entire upcoming travel schedules were exposed by MAG’s negligence, which, when linked with their full PII and vehicle information, creates an ideal opportunity for burglars, stalkers, and worse.” FulcrumSec wrote on its data leak site. “Unfortunately for them, MAG made zero effort to protect all their data they’d been collecting. The way we gained access was so simple it is tragi-comical: Iterable admin keys in the frontend JavaScript of each of its three airports’ websites: manchesterairport.co.uk, stanstedairport.com, and eastmidlandsairport.com. Each site had its own key hardcoded into it that provided access to millions of passengers who had passed through that airport. That means for this breach to have occurred at the scale it did, MAG had to make a catastrophic security mistake not once, not twice, but THREE times.”

FulcrumSec claims it accessed MAG’s systems using administrator keys exposed in the JavaScript of its three airport websites. MAG hasn’t confirmed this, and SecurityWeek hasn’t independently verified it, so the claim remains unproven. Still, the case highlights a basic security rule: keep secrets off client-side code, rotate them regularly, limit access and scan code, repositories, logs and configurations for accidental exposure.

The group then published roughly 550 GB of uncompressed data it says came from the airport operator’s systems.

“These exposed keys gave us access to the following:

  • 8,672,291 customer profiles with email, name, mobile, home town, postal region, and the residential IP address the account last connected from
  • 1,169,302,811 events, of which 1,160,120,195 are email-channel events: 611,629,550 sends, 463,286,223 opens, 36,878,965 clicks, plus every subscribe, unsubscribe, bounce and complaint
  • 2,482,763 purchases — every booking every customer of its parking, lounge, and fast-track products has ever made. An analysed subset of 1,154,675 transactions, from 877,754 identified purchasers, totals £83,413,317.89
  • 461,433 SMS messages rendered with a passenger’s booking date, car park and vehicle registration spelled out in plain text
  • 108,077 unique UK vehicle registration plates tied to the owner’s email, mobile, airport, car park and dated booking
  • The complete platform configuration: every campaign, every journey, every list, every segment and every template, all as live JSON” FulcrumSec added.

The announcement claims that a leaked MAG database exposes 190,849 future bookings, including 142,755 linked to vehicle registrations, potentially revealing when homes will be empty.

It also claims the data includes thousands of government, judicial, military, police, NHS and defence-industry employees, creating significant security risks. The attackers say they removed the most sensitive travel details before publishing, while accusing MAG of downplaying the breach.

Databreach notification service Have I Been Pwned processed the available dataset and added the incident to its breach database. The service reports that approximately 8.8 million email addresses and phone numbers were compromised, alongside names, IP addresses, browser user-agent details, geographic information, purchases and vehicle registration plates.

That is not just a list of email addresses. It is a working fraud kit: a criminal can link a person to an airport, a booking type, a car, a location and a contact number. They don’t need to guess much after that.

What affected people should do

Anyone who has used MAG’s parking, lounge, Fast Track or airport Wi-Fi services should assume that phishing attempts may become more tailored. They should be cautious with messages claiming to concern a booking, refund, parking penalty, account problem or payment request.

Users should change passwords if they reused one associated with these services elsewhere, especially on email accounts. They should also enable multi-factor authentication, review account-recovery methods and avoid clicking links in unexpected messages.

A legitimate organisation will not ask for a password, a banking PIN or a one-time authentication code by email, SMS or phone. If a message refers to a booking, open the relevant airport or provider site manually rather than following the link it contains.

The Have I Been Pwned breach entry allows users to check whether their email address appears in the published dataset.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, Manchester Airports Group)

  • ✇Cybersecurity News
  • Trezor Data Breach at ShipMonk Grows to 80,000 Customers Do Son
    The Trezor data breach at shipping partner ShipMonk exposed about 80,000 customers' order data. Wallets are safe, but phishing risk is high. Related Posts: Massive IDScan Data Breach Reported Independent Investigation Reveals 1,200 OpenAI Agents Breached Isolation in Hugging Face Attack JetBrains Cadence Server Compromised The post Trezor Data Breach at ShipMonk Grows to 80,000 Customers appeared first on Daily CyberSecurity.
     
  • ✇Security Affairs
  • Dark Web Service Nexus Sells 153M+ Driver’s Licenses Pierluigi Paganini
    FBI probes suspected breach at IDScan.net after dark web service Nexus offered 153M+ US and Canadian driver’s license scans. A dark web identity theft service called Nexus appeared on September 1, 2026, offering searchable access to more than 153 million scanned driver’s licenses belonging to people in the United States and Canada. The FBI’s New Orleans field office opened a formal investigation the same day. Brian Krebs at KrebsOnSecurity, who broke the story, traced the source to idsca
     

Dark Web Service Nexus Sells 153M+ Driver’s Licenses

4 de Setembro de 2026, 04:02

FBI probes suspected breach at IDScan.net after dark web service Nexus offered 153M+ US and Canadian driver’s license scans.

A dark web identity theft service called Nexus appeared on September 1, 2026, offering searchable access to more than 153 million scanned driver’s licenses belonging to people in the United States and Canada.

The FBI’s New Orleans field office opened a formal investigation the same day. Brian Krebs at KrebsOnSecurity, who broke the story, traced the source to idscan.net, a New Orleans-based identity verification company whose clients include Hertz, Target, FedEx, Motorola Solutions, Caesars Entertainment, and the financial services firm Jack Henry.

“On Monday, Aug. 31, a source alerted KrebsOnSecurity to a service advertised by a new user on the Russian cybercrime forum Exploit, offering access to digital scans of identity documents on more than 170 million people in North America. The source brought it to my attention because the proprietor of this identity theft service offered my Virginia drivers license as a free sample in their initial sales thread on Exploit.” wrote Krebs. “The service, dubbed Nexus, claims to have more than 153 million drivers licenses for people in the United States and Canada, as well as more than 10 million identification cards; more than three million travel documents and/or international IDs; and at least 579,000 medical cards.”

The record total was also increasing by roughly 400,000 per day at the time of publication, which the operators attributed to ongoing active exfiltration from a live breach they claim has been running for over a year.

Krebs found his own driver’s license in the database after a source alerted him to the service. The operators had posted his Virginia license as a free sample on the Russian cybercrime forum Exploit. Each record contains six images of the license, showing the front and back in visible, infrared, and ultraviolet light, with a timestamp. Krebs’ timestamp matched a June 2025 flight and car rental.

He then checked nine friends and relatives, and everyone who found their license confirmed traveling or renting a car around the same date. His license and his mother’s, who rented a Hertz car with him that day, had timestamps just seconds apart.

Security researcher Zach Edwards, whose license also appeared in Nexus, narrowed the source further. His timestamp matched a trip to Las Vegas for DEF CON in August. He hadn’t rented a car, but he had shown his license at a marijuana dispensary: Planet13, a multi-state chain. In 2022, idscan.net published a press release announcing an exclusive identity verification partnership with Planet13’s dispensaries nationally. The company now serves more than 1,000 marijuana dispensaries in 19 states, and its own documentation confirms that its technology scans IDs with both infrared and ultraviolet light, precisely the format of the images appearing in Nexus.

Idscan.net performs more than 21 million verifications per month at more than 20,000 locations globally. Its client list spans car rentals, retailers, hotels, financial services, and dispensaries, which explains both the volume and the geographic spread of the records. The dataset also includes marijuana dispensary cards and records marked with the notation “CAC,” which may refer to Common Access Cards, the government-issued credentials used to enter federal buildings and secure facilities. If confirmed, that would significantly expand the security implications beyond consumer identity theft.

The database reportedly contained the driver’s licenses of U.S. Defense Secretary Pete Hegseth and the FBI’s assistant director, but not FBI Director Kash Patel’s.

Idscan.net said Krebs’ findings would help its internal investigation but gave no further details. The company later said it was working with law enforcement and forensic experts. Soon after the story became public, the Nexus service went offline.

Identity verification systems that require driver’s licenses are spreading sensitive data across an expanding network of third-party vendors, and oversight mechanisms haven’t kept pace. Every bar, hotel, car rental counter, dispensary, and age-verification system that scans an ID is creating a copy of that image in a system whose security posture the cardholder has no way to assess.

The idscan.net incident, if confirmed at the reported scale, would be among the largest exposures of government-issued identity document images ever recorded.

Krebs reports that Nexus shut down after his article, while the FBI opened an investigation after learning that stolen IDs may include licenses belonging to FBI agents.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, Nexus)

  • ✇Security Affairs
  • 412,000 The Town 2025 Ticket Buyers’ Data Hits the Dark Web Pierluigi Paganini
    412,000 The Town 2025 festival buyer records are being sold for $10,000, with Brazil’s data openly marketed for bank fraud, loans and SIM registration. A seller on a Russian-language data-trading forum listed what they’re calling a Ticketmaster database on September 2, claiming over 412,000 Latin American purchase records with a heavy concentration of Brazilian data. Ransomnews’s analysis confirms the sample is genuine ticket-buyer data from The Town 2025, the São Paulo music festival, thoug
     

412,000 The Town 2025 Ticket Buyers’ Data Hits the Dark Web

3 de Setembro de 2026, 10:17

412,000 The Town 2025 festival buyer records are being sold for $10,000, with Brazil’s data openly marketed for bank fraud, loans and SIM registration.

A seller on a Russian-language data-trading forum listed what they’re calling a Ticketmaster database on September 2, claiming over 412,000 Latin American purchase records with a heavy concentration of Brazilian data. Ransomnews’s analysis confirms the sample is genuine ticket-buyer data from The Town 2025, the São Paulo music festival, though who actually lost the data and how remains unconfirmed.

“The listing is headed “SELLING NEW TICKETMASTER DATABASE” and describes a global ticketing platform, Latin America region, with an internal ticketing database as the source and a breach date of 28 August 2026. It advertises 412,192 rows across 34 columns.” reported Ransomnews. “The country breakdown is dominated by Brazil at 251,557 records, or 61%, with Argentina at 219, Chile 155, Colombia 144, Peru 123 and Paraguay 72, plus nine more countries not itemised.”

The seller is asking $10,000 for the full database, or $80 for every 1,000 records, with escrow available. The 251,557 Brazilian records make up about 61% of the database, meaning the seller is effectively asking around four cents per person.

The data includes names, email addresses, CPF numbers, phone numbers, neighborhoods, ticket types, and payment details. Together, these details provide a detailed profile that could be used for identity theft and fraud.

“The seller’s own notes are the part that should concern Brazilian readers most. Alongside the sales copy, the listing states that the CPF numbers work “for Brazilian bank fraud, loan apps and SIM registration”.” continues the report.”That is not our characterisation of the risk. It is the seller describing the intended use of the file.”

Ransomnews ran the kind of checks that usually expose fake listings within minutes, and this one kept passing. Purchase IDs across the sample rise in strict chronological order, exactly what an auto-incrementing database key produces and something close to statistically impossible to fake by chance. Every CPF number in the sample passes Brazil’s official check-digit validation, phone area codes correctly match the state listed on each row rather than defaulting to a single city, and neighborhood names map precisely onto their stated cities, the kind of granular accuracy a random data generator simply doesn’t produce.

The ticket prices provide another strong sign that the database is genuine. Full-price tickets cost exactly 975 reais, while discounted tickets cost 487.50 reais, matching Brazil’s legal student discount. The database also lists Pix and Elo as payment methods, both widely used in Brazil.

Even the incomplete records look realistic. Complimentary tickets issued by the festival’s back office contain no name or CPF, only the ticket type and date. These kinds of inconsistencies are common in real databases but would be unusual in fabricated data.

However, there is an important detail that challenges the claim of a direct Ticketmaster breach. Every record in the sample has exactly the same processing timestamp: October 1, 2025 at 23:05:41, about two weeks after the festival ended.

A live database dump would normally contain different timestamps. The identical timestamp instead suggests that the data may have been exported in a single batch after the event and then shared with a promoter, sponsor, payment provider, or another partner. Ransomnews therefore warns that blaming Ticketmaster directly would go beyond what the available evidence currently shows.

That distinction matters more than it might seem, because it points at an industry-wide blind spot rather than one company’s failure. Brazilian ticketing requires CPF collection to enforce discount eligibility rules, which means live-events companies routinely end up holding a national identity number, a verified phone, and a home neighborhood for hundreds of thousands of people, data with the sensitivity of a bank record sitting inside an industry with nothing like a bank’s security requirements. The moment that data gets exported into a spreadsheet to reconcile ticket sales with a partner, which happens constantly and rarely makes headlines, it becomes dramatically easier to lose.

“If you bought tickets to The Town 2025, treat your CPF as exposed.” concludes the report. “A CPF cannot be reissued the way a password can, and the seller is explicitly marketing these numbers for credit and telecoms fraud.”

If you bought tickets to The Town 2025, the practical response here isn’t panic, it’s specific vigilance. A CPF can’t be reissued the way a password gets reset, so treat it as permanently exposed and check your credit record through Brazil’s Central Bank registry or services like Serasa for accounts you didn’t open. Watch closely for SIM swap attempts given the seller’s explicit mention of telecom fraud, and be skeptical of any inbound call or message referencing your actual festival purchase, since whoever holds this file knows exactly which days you attended and how you paid, more than enough detail to make a scam call sound completely legitimate.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, The Town 2025)

  • ✇Cyber Security News
  • Trezor Confirms ShipMonk Data Breach Exposed 67,000 Additional US Customers Guru Baran
    Hardware wallet maker Trezor has confirmed that a data breach at logistics partner ShipMonk is substantially larger than first reported, after older U.S. order records that should have been deleted remained in the leaked dataset. On September 4, 2026, Trezor said it was told two days earlier that the incident also included order data from a prior ShipMonk partnership between November 2019 and August 2021, fully exposing about 67,000 additional U.S. customers. Trezor first disclosed the inc
     

Trezor Confirms ShipMonk Data Breach Exposed 67,000 Additional US Customers

4 de Setembro de 2026, 08:37

Hardware wallet maker Trezor has confirmed that a data breach at logistics partner ShipMonk is substantially larger than first reported, after older U.S. order records that should have been deleted remained in the leaked dataset.

On September 4, 2026, Trezor said it was told two days earlier that the incident also included order data from a prior ShipMonk partnership between November 2019 and August 2021, fully exposing about 67,000 additional U.S. customers.

Trezor first disclosed the incident on August 13 after ShipMonk reported unauthorized access on August 10. That notice covered 11,742 customers whose names, emails, phone numbers and shipping addresses were fully exposed, plus 1,947 with partial exposure of name, city and email, totaling about 13,689 people.

Those records were linked to orders in the United States, United Kingdom, Sweden, Colombia, Brazil, Italy and Portugal between May 10 and August 8, 2026. An August 14 update already admitted that some partial-exposure records included older orders.

ShipMonk told customers that attackers exploited a vulnerability in the analytics platform Metabase. Metabase notified the logistics firm on August 6 that an unauthorized party used a software flaw to reach account and customer data. Later reporting tied the campaign to a critical SQL injection zero-day that yielded administrator access on compromised instances. Trezor’s own systems were not breached, its devices remain secure, and wallet backups were not leaked. Parcel contents were not exposed.

The latest update undercuts the retention argument Trezor used to bound the first disclosure. The company requires fulfillment partners to delete or anonymize order data 90 days after delivery. Trezor said it repeatedly requested and received written assurance that ShipMonk had deleted the older records, yet the data was still in ShipMonk’s systems.

The newly acknowledged U.S. files include name, email, phone number, shipping address, and order number, bringing the overall impact above 80,000 customers.

That combination of home addresses, phone numbers and hardware-wallet purchase history is useful for phishing and, Trezor now warns, physical security risk.

Scammers can impersonate Trezor, banks, or exchanges by email, call, or letter and push victims to enter a recovery seed. Affected customers have been emailed from help@trezor.io; anyone who did not receive that message is not in the leaked set.

Recipients should treat urgent requests for personal data as hostile, verify claims only through official Trezor channels, and never type a wallet backup into a website or share it with anyone.

Trezor said this is the first incident since its 2013 founding to expose customer phone numbers and shipping addresses, and it is preparing an Anonymous Delivery option with locker pickup and automatic deletion of shipping identifiers.

Learn 7 Metric-Gated AI SOC Deployment Phases – Download Free AI SOC Deployment Playbook 2026.

The post Trezor Confirms ShipMonk Data Breach Exposed 67,000 Additional US Customers appeared first on Cyber Security News.

The Cyber Express Weekly Roundup: Claude Session Hijacking, PaperCut Exploits, and Enterprise Cyberattacks

4 de Setembro de 2026, 08:48

Weekly Roundup September 2026

This weekly roundup highlights a range of cybersecurity developments affecting artificial intelligence platforms, enterprise software, healthcare organizations, social media accounts, and internet-facing infrastructure.  From stolen Claude sessions and bypassed PaperCut security fixes to an attempted attack targeting hundreds of thousands of X users, recent incidents demonstrate how attackers continue to exploit both software vulnerabilities and active user sessions.  The latest developments also show that organizations face growing risks across AI services, on-premises systems, enterprise edge devices, and account recovery infrastructure. Security teams are being urged to respond quickly as attackers increasingly target exposed systems and authentication mechanisms. 

The Cyber Express Weekly Roundup 

Anthropic Warns of Claude Session Hijacking 

Anthropic has warned that common infostealer malware is being used to steal active Claude sessions, potentially allowing attackers to bypass passwords and two-factor authentication. The campaign involves malware such as Vidar, LummaC2, RedLine, and Atomic Stealer, which is often distributed through pirated software and illicit downloads. Attackers may also consume victims’ paid AI usage. Read more… 

PaperCut Releases Second Emergency Patch After First Fix Is Bypassed 

PaperCut has released a second emergency patch for two actively exploited vulnerabilities affecting its NG and MF print management servers. Researchers discovered ways to bypass the initial security fix, potentially allowing attackers to chain the flaws and achieve pre-authentication remote code execution on exposed systems. Read more… 

Boston Scientific Cyberattack Limited to Certain On-Premises Systems 

Boston Scientific says its ongoing cybersecurity incident is limited to certain on-premises systems, with no impact identified on its cloud-based applications. The company has also reported no confirmed data breach or evidence of unauthorized activity since August 25, as its investigation into the incident continues. Read more… 

DOJ Investigates Attempted Cyberattack on Hundreds of Thousands of X Users 

The U.S. Department of Justice is investigating a large-scale cyberattack targeting hundreds of thousands of X accounts through the platform’s password-recovery system. Attorney General Todd Blanche said X detected and disrupted the campaign before the targeted accounts could be captured, preventing the attempted account takeover operation from succeeding. Read more… 

Two Citrix NetScaler Flaws Put Enterprise Edge Devices at Risk 

Two vulnerabilities in Citrix NetScaler ADC and Gateway have prompted an urgent patching warning from Australia’s cybersecurity agency. CVE-2026-19489, a memory overflow flaw, and CVE-2026-19490, an authentication bypass, can affect systems with specific configurations involving SIP ALG, SAML, or VPN gateway functionality. Read more… 

Weekly Cybersecurity Takeaway 

This week’s developments demonstrate that cybersecurity threats are increasingly targeting authentication systems, active user sessions, exposed enterprise infrastructure, and critical business applications. AI platforms, print management servers, healthcare environments, social media accounts, and network edge devices all remain potential targets for attackers.  Organizations should prioritize rapid security patching, protection of active sessions, strong authentication controls, careful monitoring of exposed infrastructure, and timely investigation of suspicious activity. Security teams should also review systems that rely on password-recovery mechanisms and identify enterprise devices operating with vulnerable configurations.  As businesses continue to rely on cloud services, AI platforms, remote access technologies, and internet-facing enterprise systems, attackers are finding new opportunities to exploit trusted sessions and security weaknesses. Organizations must maintain continuous monitoring and rapid response capabilities to reduce the impact of increasingly targeted cyberattacks. 

ShipMonk Data Breach Exposes Personal Data of 67,000 Additional Trezor Customers

Trezor has revealed that a data breach involving its fulfillment provider, ShipMonk, exposed personal and order information of approximately 67,000 additional US customers. This significantly broadens the scope of an incident initially reported in August. The newly identified data pertains to Trezor orders processed during a prior partnership with ShipMonk, which lasted from November 2019 […]

The post ShipMonk Data Breach Exposes Personal Data of 67,000 Additional Trezor Customers appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

  • ✇Security Affairs
  • Attackers Access Aesto Health AWS Infrastructure, Exposing 9.5 Million Records Pierluigi Paganini
    Aesto Health suffered a breach exposing personal and health data of more than 9.5 million people after attackers accessed its AWS infrastructure. Aesto Health, a U.S. healthcare technology company, disclosed a data breach that exposed personal and health information belonging to more than 9.5 million people. The company discovered the incident on December 18, 2025, after attackers gained access to part of its Amazon Web Services infrastructure. Aesto Health is a U.S. healthcare technolog
     

Attackers Access Aesto Health AWS Infrastructure, Exposing 9.5 Million Records

1 de Setembro de 2026, 12:12

Aesto Health suffered a breach exposing personal and health data of more than 9.5 million people after attackers accessed its AWS infrastructure.

Aesto Health, a U.S. healthcare technology company, disclosed a data breach that exposed personal and health information belonging to more than 9.5 million people. The company discovered the incident on December 18, 2025, after attackers gained access to part of its Amazon Web Services infrastructure.

Aesto Health is a U.S. healthcare technology company based in Birmingham, Alabama. It helps healthcare providers manage and protect electronic health records and other legacy medical data. Its services include secure data migration, electronic health record (EHR) exchanges and long-term data archiving. Aesto works with medical practices and healthcare organizations that need to move, store or access patient information securely.

“On or about December 18, 2025, Aesto experienced a network security incident that impacted a limited portion of our Amazon Web Services infrastructure.” reads the Notice of Data Security Incident. “After an extensive forensic investigation and manual document review, on May 26, 2026, we confirmed that between on or about December 2, 2025, and December 18, 2025, certain protected health information belonging to patients of various Covered Entity clients stored within Aesto’s network may have been accessed and/or acquired by an unauthorized actor.”

The company launched an investigation into the incident with external leading cybersecurity experts.

The network security incident affected part of its Amazon Web Services infrastructure between December 2 and 18, 2025. On May 26, 2026, Aesto confirmed that an unauthorized actor may have accessed or acquired protected health information stored in its network. Exposed data may include names, birth dates, medical and insurance information, driver’s license and government ID numbers, financial account details, taxpayer IDs and, for a limited number of people, Social Security numbers.

Aesto says it found no evidence of identity theft or financial fraud linked to the breach. Starting June 26, 2026, it notified affected healthcare clients whose patients’ data may have been accessed.

The company announced it has already implemented measures to strengthen security and set up a dedicated helpline for questions.

The healthcare firm also notified the US Department of Health and Human Services (HHS), reporting that the incident impacted 9540683 individuals.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, Aesto Health)

  • ✇Cybersecurity News
  • JetBrains Cadence Server Compromised Do Son
    An unpatched JetBrains Cadence server exposed cloud infrastructure, AWS credentials, and critical developer secrets. Discover the details of this severe breach. Related Posts: Meta Settles Child Privacy Lawsuit Rapidly Mercor Data Breach Targets AI Supply Chain Exposed Git Repositories Leak Critical Cloud Secrets The post JetBrains Cadence Server Compromised appeared first on Daily CyberSecurity.
     

JetBrains Cadence Server Compromised

Por:Do Son
30 de Agosto de 2026, 23:50

An unpatched JetBrains Cadence server exposed cloud infrastructure, AWS credentials, and critical developer secrets. Discover the details of this severe breach.

Related Posts:

The post JetBrains Cadence Server Compromised appeared first on Daily CyberSecurity.

❌
❌