AUTO-UPDATED EVERY 30 MIN

Significant Cyber Incidents

Major breaches, ransomware attacks, and nation-state operations affecting businesses worldwide. Sourced from Cyber Scoop, The Record, SecurityWeek, DataBreaches.net and more.

📡 43 incidents tracked·🕐 Last refresh: Sep 5, 2026, 11:46 p.m. PT
Government

French Police Arrest Suspected ZeroBytes Hacker Over Tax Data Theft

Waqas reports: French authorities have detained an 18-year-old man suspected of belonging to ZeroBytes, a hacking group that claimed responsibility for several attacks targeting French government services and companies. …

DataBreaches.netSep 5, 2026
Manufacturing

FalconFlank Zero-Day Hits CrowdStrike Falcon Sensor

CyberKendra reports: A security researcher known as Chaotic Eclipse has released FalconFlank, a proof-of-concept zero-day that escalates privileges on fully patched Windows machines running CrowdStrike Falcon. The resear…

DataBreaches.netSep 5, 2026
Enterprise

Elementor Pro WordPress Plugin Vulnerability Exploited to Hack Sites

Tracked as CVE-2026-32475 (CVSS score of 9.8), the bug described as an arbitrary file upload issue in the function that handles form submissions. The post Elementor Pro WordPress Plugin Vulnerability Exploited to Hack Si…

SecurityWeekSep 5, 2026
Education

European parliament members call for slowdown of Serbia’s EU entry over spyware use

The letter follows revelations about Serbian student activists being infected with Pegasus and NoviSpy, and coincides with other pressures on Belgrade. The post European parliament members call for slowdown of Serbia’s E…

Cyber ScoopSep 4, 2026
Manufacturing

In Other News: Microsoft’s Cloud Patches, Hacked Dropbox Accounts, Guardio’s $1.1B Valuation

Noteworthy stories that might have slipped under the radar: Microsoft rolled out patches for cloud services, hackers compromised 5,000 Dropbox accounts, and Guardio is now valued at $1.1 billion. The post In Other News: …

SecurityWeekSep 4, 2026
Enterprise

HPE Patches Critical RCE Vulnerabilities in AOS-CX

Nearly two dozen issues, tracked collectively as CVE-2026-73749 (CVSS score of 9.8), were addressed with the updates. The post HPE Patches Critical RCE Vulnerabilities in AOS-CX appeared first on SecurityWeek .…

SecurityWeekSep 4, 2026
Enterprise

OpenAI Pledges $1 Billion to Bring Frontier AI to Critical Infrastructure Defenders

The Daybreak initiative will provide subsidized AI cyber capabilities, training and technical assistance, though OpenAI has disclosed few details about costs and eligibility. The post OpenAI Pledges $1 Billion to Bring F…

SecurityWeekSep 4, 2026
Government

US, Britain to coordinate on scam center takedowns

The U.S. Department of Justice and the U.K.'s National Crime Agency and Crown Prosecutor signed a memorandum to cooperate on cases involving Southeast Asian scam operations.…

The RecordSep 4, 2026
Enterprise

UK account-hack losses surge as new reporting system exposes hidden cases

In its first annual assessment, published Friday, the City of London Police said victims reported losing £6.3 million ($8.5 million) to account hacks in the year ending March 31, up from £1.2 million ($1.6 million) a yea…

The RecordSep 4, 2026
Defence

Russian data centers face new security requirements amid Ukraine's drone threats

Russia's data centers are concentrated in areas increasingly exposed to Ukrainian drone attacks. The Kremlin wants them to stiffen their physical defenses.…

The RecordSep 4, 2026
Manufacturing

Sangoma Switchvox Vulnerabilities Exploited in the Wild

Tracked as CVE-2026-9586, the unauthenticated SQL injection flaw can be exploited remotely for arbitrary code execution. The post Sangoma Switchvox Vulnerabilities Exploited in the Wild appeared first on SecurityWeek .…

SecurityWeekSep 4, 2026
Government

Honeywell Aerospace Inc. Agrees to Pay Over $2M to Settle False Claims Act Allegations of Failing to Comply with Cybersecurity Requirements in a U.S. Department of Defense Contract

A DOJ press release on September 1: The Justice Department announced today that Honeywell Aerospace Inc. has agreed to pay $2,042,518 to resolve allegations that it is liable under the False Claims Act for failing to com…

DataBreaches.netSep 4, 2026
Government

G7 urges organizations to prepare for quantum cyber threats

In a joint advisory released Thursday, the G7 Cyber Security Working Group and the U.S. Cybersecurity and Infrastructure Security Agency, CISA, said organizations should begin moving to post-quantum cryptography now.…

The RecordSep 4, 2026
Enterprise

DaVita settles ransomware attack lawsuit for $15M

Chad Van Alstin reports an update on a ransomware attack previously reported on DataBreaches.net: Nationwide kidney dialysis chain DaVita has agreed to pay $15 million to settle a class action lawsuit stemming from a 202…

DataBreaches.netSep 4, 2026
Enterprise

12-Year-Old PostgreSQL Vulnerability Enables Database, Server Takeover

Dubbed PostGREShell, CVE-2026-6471 turns low-level replication access into code execution, permanent superuser privileges and a persistent database backdoor. The post 12-Year-Old PostgreSQL Vulnerability Enables Database…

SecurityWeekSep 4, 2026
Enterprise

Catch Raises $5 Million for AI Executive Assistant With Guardrails

Catch promises the capabilities of a trusted executive assistant, with built-in controls governing what data and systems it can access. The post Catch Raises $5 Million for AI Executive Assistant With Guardrails appeared…

SecurityWeekSep 4, 2026
Enterprise

VMware Workstation and Fusion Updates Patch Critical Vulnerability

The flaws could allow attackers with administrative access to a virtual machine to execute code on the host system. The post VMware Workstation and Fusion Updates Patch Critical Vulnerability appeared first on SecurityWe…

SecurityWeekSep 4, 2026
Enterprise

Google Patches 6th Chrome Zero-Day of 2026

Google’s Chrome 152 security update resolves 12 vulnerabilities, including a high-severity type confusion flaw in the V8 engine. The post Google Patches 6th Chrome Zero-Day of 2026 appeared first on SecurityWeek .…

SecurityWeekSep 4, 2026
Manufacturing

Ledger faces $500 million class action over data breaches

Pavlo Kot reports: ​Hardware crypto wallet maker Ledger is facing a class action seeking at least $500 million over a series of customer data breaches. The plaintiff claims the company failed to adequately protect custom…

DataBreaches.netSep 4, 2026
Enterprise

FBI probes suspected breach at IDScan.net after dark web service Nexus offered 153M+ US and Canadian driver’s license scans

Pierluigi Paganini reports: A dark web identity theft service called Nexus appeared on September 1, 2026, offering searchable access to more than 153 million scanned driver’s licenses belonging to people in the United St…

DataBreaches.netSep 4, 2026
Manufacturing

TR: Fine for famous kebab chain that allowed theft of 500 thousand customers’ data

The Turkish Data Protection Authority (KVKK) investigation into the data breach at the famous restaurant chain Baydöner, where the full names, phone numbers, emails, and city information of 505,337 customers were comprom…

DataBreaches.netSep 4, 2026
Enterprise

OpenAI Pledges $1bn to Bring its AI Cybersecurity Tools to Essential Services

OpenAI has committed to subsidizing access to Daybreak, helping defenders deploy its AI models in its existing cybersecurity infrastructure…

InfoSecuritySep 4, 2026
Enterprise

Why judgment is emerging as cybersecurity’s defining skill

AI is getting better at much of what security teams have long spent time on: analyzing information, identifying patterns, and providing technically sound recommendations quickly. As those capabilities become more routine…

Cyber ScoopSep 4, 2026
Enterprise

Nvidia Is Buying AI Platform Hugging Face for $13 Billion

The deal highlights Nvidia’s push to champion increasingly popular open-source AI models. The post Nvidia Is Buying AI Platform Hugging Face for $13 Billion appeared first on SecurityWeek .…

SecurityWeekSep 4, 2026
Government

G7 Urges Fast-Track on Quantum-Safe Cybersecurity Rules

The G7 has published a call to action, urging governments to launch national strategies dedicated to the post-quantum encryption transition…

InfoSecuritySep 4, 2026
Government

US offers $10 million for info on Iranian allegedly behind cyberattacks on critical infrastructure

Amir Yaryab is the leader of the IRGC's cyber unit and oversees hacker groups such as the CyberAv3ngers, the State Department said in posting a reward for information about him.…

The RecordSep 4, 2026
Healthcare

CNIL: Health data breach: €500,000 fine imposed on the Loire Private Hospital

On September 3, 2026, the CNIL issued a €500,000 fine against the Loire Private Hospital, for not having taken appropriate measures to ensure the security of the data of its patients and some of their relatives. During t…

DataBreaches.netSep 3, 2026
Enterprise

Attackers exploit zero-days in consistently besieged SonicWall product

SonicWall customers have confronted a barrage of attacks for years, including five actively exploited vulnerabilities in SMA 1000 appliances since late 2025. The post Attackers exploit zero-days in consistently besieged …

Cyber ScoopSep 3, 2026
Defence

Two “Nephrology Associates” suffered cyberattacks. Only one of them has disclosed it.

Sometimes, first impressions are wrong. And in the case of “Nephrology Associates,” DataBreaches mistakenly thought one victim was attacked by two different groups. But no, there are actually two unrelated en…

DataBreaches.netSep 3, 2026
Education

The New School Safety Perimeter: Where Cybersecurity Meets Physical Security

Kumar Sokka reports: At many institutions, the student ID number exposed in a data breach is the same number that unlocks dorm doors, sits behind classroom badge readers, controls laboratory access, and authenticates int…

DataBreaches.netSep 3, 2026
Government

The G7 tells industry to hurry up and prep for post-quantum encryption

The nations warn that governments and industry can no longer treat quantum codebreaking as a distant or theoretical possibility. The post The G7 tells industry to hurry up and prep for post-quantum encryption appeared fi…

Cyber ScoopSep 3, 2026
Education

Pegasus Zero-Click Exploit Infects Serbian Student Activist's iPhone

Pegasus infected a Serbian student activist's iPhone through an iMessage zero-click exploit…

InfoSecuritySep 3, 2026
Enterprise

Outsider Phishing Kit Survives Takedown With 700 New Pages

Outsider phishing kit generated 700 new pages after a Google-led disruption…

InfoSecuritySep 3, 2026
Enterprise

CREST Onboards First Cohort for AI-Enabled Pentesting Accreditation

CREST’s new AI-enabled penetration testing accreditation welcomes its first 10 providers…

InfoSecuritySep 3, 2026
Manufacturing

US and Canadian Court Records Breached Following Thomson Reuters Incident

Thomson Reuters has disclosed a cyber incident affecting its C-Track court management software, potentially exposing court records in Canada and the US…

InfoSecuritySep 3, 2026
Enterprise

FBI Probes Possible Breach of 153 Million Driver’s Licenses

The FBI is investigating how scans of over 153 million driver’s licenses are being sold on the dark web…

InfoSecuritySep 3, 2026
Manufacturing

International Operation Disrupts Sality P2P Botnet

US-led action sinkholes machines caught up in Sality botnet…

InfoSecuritySep 3, 2026
Government

Jail time for Maine child in 764 marks turning point in federal law enforcement

Researcher tracking 764 said the first-of-its-kind case has a wider impact that will cause ripples across the landscape of violent extremist crime. The post Jail time for Maine child in 764 marks turning point in federal…

Cyber ScoopSep 2, 2026
Government

FCC proposes public scorecard to rate telecoms on anti-robocall efforts

The agency also booted 14 phone service providers from U.S. networks for violating existing robocalling regulations. The post FCC proposes public scorecard to rate telecoms on anti-robocall efforts appeared first on Cybe…

Cyber ScoopSep 2, 2026
Manufacturing

Dogged Russia-based botnet dismantled after 23-year run

Sality’s peer-to-peer infrastructure allowed it to evade system-wide disruption efforts for an exceptionally long period. Authorities and cybersecurity experts finally brought it down. The post Dogged Russia-based botnet…

Cyber ScoopSep 2, 2026
Critical Infrastructure

Pegasus, NoviSpy variant spyware found on devices of Serbian activists

It’s the first Pegasus infection of 2026 that Citizen Lab is forensically confirming, and the SHARE Foundation said it’s the biggest wave of spyware surveillance in Serbia yet. The post Pegasus, NoviSpy variant spyware f…

Cyber ScoopSep 2, 2026
Defence

Wyden seeks upgraded NSA security guidance on commercial VPN use

it’s the latest in a sequence of letters to feds from Sen. Ron Wyden, D-Ore., on commercial VPNs. The post Wyden seeks upgraded NSA security guidance on commercial VPN use appeared first on CyberScoop .…

Cyber ScoopSep 2, 2026
Defence

FBI raises alarm over deceptive phishing campaign targeting prominent people

The ongoing social engineering threat, which dates back to late 2025, tricks victims into granting threat actors long-term access to their accounts. The post FBI raises alarm over deceptive phishing campaign targeting pr…

Cyber ScoopSep 1, 2026