Ransomware attack disables Canadian hospital's doors and HVAC. The incident underscores sometimes overlooked operational technology risks in healthcare environments.
https://www.databreachtoday.com/ransomware-attack-disables-canadian-hospitals-doors-hvac-a-32535
Mathew J. Schwartz
Cybersecurity journalist — I'm Executive Editor at Information Security Media Group, leading its DataBreachToday website as well as UK/Europe coverage of all things security, privacy, cybercrime, surveillance and more.
Seven Ukrainian civilians have asked a court in New York to order a US manufacturer to pay them more than $75 million, claiming the company has not done enough to prevent its technology from being used by Russia drone operators in perpetuating “a campaign of high-tech murder”.
https://www.pinsentmasons.com/out-law/news/ukrainians-sue-us-manufacturer-over-tech-russian-drone
@brianhonan@mastodon.social Oof — risks upon risks
The attack is coming from inside the meeting: Patch Zoom now to block vulnerabilities that a malicious meeting attendee could target to remotely exploit code on all other participants' systems. Old versions (update issued July 20) with E2EE enabled remain at risk. https://www.databreachtoday.com/zoom-flaws-facilitate-zero-click-remote-code-execution-a-32531
Rapid7 lays off 12% of staff as new CEO reshapes cyber firm
https://www.databreachtoday.com/rapid7-lays-off-12-staff-as-new-ceo-reshapes-cyber-firm-a-32526
Ransomware hackers, faced with declining willingness to accede to extortion, are resorting to ever more outlandish pressure tactics - including dispatching threat actors in disguise, to steal sensitive data in person. https://www.databreachtoday.com/flailing-ransomware-hackers-resorting-to-extreme-tactics-a-32375 #sneakernet
Leadership void: No single senior official is in charge of U.S. efforts to help secure commercial satellites and their land-based infrastructure against hackers, online spies and cyber attackers. https://www.databreachtoday.com/us-space-cybersecurity-no-one-in-charge-a-32342
Russian espionage hackers are targeting Zimbra Collaboration Suite with half-click attacks by exploiting a flaw (a patch is available) to execute a malicious script simply if a recipient reads the email in their webmail client.
https://www.databreachtoday.com/russian-espionage-hackers-hit-zimbra-half-click-attacks-a-32322
Eight Democratic U.S. Senators are demanding answers from the U.S. State Department about why the United States is requiring that government officials have direct access to the health data systems of dozens of foreign nations as a condition for U.S. global health funding.
https://www.databreachtoday.com/senators-probe-us-access-to-foreign-health-data-systems-a-32605
Weekly Breach Roundup
—Delta Air Lines passenger launched an evil twin attack
—LiteLLM attack exposed 430,000 pipelines
—Russian nation-state hackers targeted Ukrainian IT workers with fake job interviews
—Cisco warning over ClamAV flaws
—Ransomware extortionists hacked a healthcare sector victim's Facebook
—Yet more ClickFix attacks.
https://www.databreachtoday.com/breach-roundup-def-con-dolt-suspected-in-delta-wi-fi-hack-a-32554
More than three weeks after a wave of cyberattacks struck dozens of rural and small town water and wastewater utilities in at least 12 states, experts are still trying to figure out what exactly the attackers thought they were doing. https://www.databreachtoday.com/baffling-case-inept-iranian-strikes-on-water-utilities-a-32604
Amazon is redirecting engineering and computing resources from its Nova portfolio to a new frontier model, betting that specialization, customer-specific training and lower operating costs will matter more as leading AI systems approach comparable capability.
https://www.databreachtoday.com/amazon-custom-frontier-model-cut-costs-target-niches-a-32382
Once more, with ShieldBreak: Microsoft ecosystem faces fresh zero-day at the hands of the researcher who goes by "Nightmare Eclipse," with the flaw allowing a low-privileged attacker to gain system-level control by exploiting Microsoft Defender's privileged scanning capabilities (because antivirus) to execute malicious code.
https://www.databreachtoday.com/microsoft-faces-fresh-nightmare-eclipse-zero-day-a-32573
Extortion gang Fulcrumsec has leaked on its darkweb site a second large cache of data the group claims it stole in a June attack on Novo Nordisk. The latest data dump allegedly includes the Danish drug maker's "complete enterprise Hugging Face artificial intelligence and machine learning ecosystem." https://www.databreachtoday.com/extortion-gang-leaks-novo-nordisks-ai-ml-ecosystem-a-32553
Weekly Cryptohack Roundup
—Harmony and BTCPay hacked
—Violent crypto thefts surge
—U.S. CFTC files a $48 million fraud case
—NFT founder charged
—North Koreans used artificial intelligence for crypto exploits
—U.S. sanctions two Iranian exchanges
https://www.databreachtoday.com/cryptohack-roundup-harmony-btcpay-exploits-a-32543
Russia is targeting Ukraine using internet-connected cameras across Europe. The camera hacks facilitate the targeting of Ukrainian soldiers and materiel.
https://www.databreachtoday.com/russia-targeting-ukraine-using-internet-connected-cameras-a-32566 #cyberespionage
A prolific Russian-speaking extortion group known for supply-chain attacks claimed to have stolen data from more than 40 firms including heavyweight corporations such as oil giant Shell and manufacturer General Electric. https://www.databreachtoday.com/clop-claims-data-theft-from-more-than-40-companies-a-32581
U.S. federal prosecutors charged 17 Iranian nationals with a decade-long hacking campaign that stole more than 31 terabytes of research and intellectual property from hundreds of universities, companies and government agencies around the world.
https://www.databreachtoday.com/us-doj-charges-17-iranians-in-decade-long-hacking-campaign-a-32607
Uncle Sam seeks private hackers to surveil and disrupt foreign criminal networks that target Americans.
https://www.databreachtoday.com/uncle-sam-seeks-private-hackers-to-disrupt-criminal-networks-a-32549
Two weeks later: That's how long OpenAI said it'll pause frontier model training as it conducts a safety review
https://www.databreachtoday.com/openai-pauses-frontier-model-training-for-safety-review-a-32610
"The current lethality of the so-called drone kill zone has forced both sides to rely primarily on infiltration tactics using small groups or even individual soldiers when trying to take or reclaim territory, sometimes riding motorcycles, all-terrain vehicles, or horses."
https://arstechnica.com/gadgets/2026/08/ukrainian-drones-wipe-out-entire-us-tank-brigade-in-live-war-game/

