ZeroHour

Search: “platforms”

16 stories in the last 7d

Non-Zero-Day VPN Flaw Left Japan ‘s Government Shared Network Platform Exposed: 246,000 Records at Risk

Japan's Digital Agency says attackers exploited a patchable VPN flaw to access a government shared platform, exposing records of ~246,000 employees across 23 ministries.

Japan's Digital Agency disclosed that attackers exploited a medium-severity, already-patchable vulnerability in a VPN device to access the Government Solution Service (GSS), potentially leaking personal data of roughly 246,000 government employees, officials, and contractors across 23 ministries. The intrusion was detected on June 25 and confirmed as VPN exploitation on July 9, with public disclosure 78 days after detection. Exposed data includes about 236,000 names, 231,000 email addresses, 94,000 phone numbers, and 1,000 physical addresses; no My Number, bank account, or pension numbers were included. The compromised maintenance staff account was suspended and the compromised hardware isolated, but the VPN product and flaw were not disclosed.

Security Affairs · 3d agoData breach 2 sources1

Hackers claim breach of Russian election systems days before parliamentary vote

Hacking group CikLeak claims it stole documents, server configurations and passwords from Russia's Central Election Commission and Vybory election platform contractors days before parliamentary voting.

An anonymous group calling itself CikLeak claims it breached systems of Russia's Central Election Commission and contractors developing the Vybory election platform, including Rostelecom, stealing internal documents, server configurations, passwords, and employee communications. The group gave the material to investigative outlet Important Stories, which says it authenticated the documents, though the depth of access to voting or counting systems remains unclear. CikLeak says its goal was transparency about manipulation opportunities, not disruption, and urged Russians to vote in person. The claim came days before the first State Duma election conducted on the Vybory 2.0 platform, amid rising attacks that CEC Chair Ella Pamfilova says are unprecedented in intensity.

The Record · 1d agoData breach in the wild

London property manager breach may have exposed bank details and lockbox codes

London property manager City Relay says attackers exploited a Metabase Cloud vulnerability twice, stealing landlord bank details, passwords, and lockbox codes.

City Relay, which manages thousands of London properties, told landlords that intruders accessed its third-party Metabase Cloud instance twice via an undisclosed vulnerability and extracted personal data, including names, addresses, phone numbers, bank account numbers, sort codes, IBANs, SWIFT references, account passwords, and key-storage locations with lockbox codes. The company reportedly learned of the intrusion on September 8, notified customers on September 14, and says it has rotated all exposed access and key-storage codes, with no evidence of data misuse or unauthorized property entries so far. Metabase disclosed a zero-day SQL injection flaw on August 6 that compromised fewer than 3% of its customers, with Framework and n8n as known victims, though it has not confirmed City Relay was part of that campaign.

The Register · Security · 1d agoData breach in the wild

Navigate360 may soon release a public notice about its horrific breach, but will any individuals be notified?

A hacktivist exfiltrated 8.3 million anonymous tips from Navigate360 school and community tip platforms; affected individuals remain unnotified after six months.

In April 2026, a hacktivist announced they had accessed and acquired 8.3 million tips submitted to supposedly anonymous tip lines and platforms used by schools, communities, Crime Stoppers organizations, law enforcement and the military. Six months later, no affected individuals have been notified, and DataBreaches has repeatedly reported Navigate360's lack of public transparency since April. A public notice may be released soon, but whether any individuals will be notified remains uncertain.

DataBreaches.net · 1d agoData breach

Japan’s Digital Agency Breach Exposes 240,000+ Users’ Personal Records to Hackers

Attackers exploited a patched VPN appliance flaw to breach Japan's Digital Agency shared government platform, exposing about 246,000 personal records.

Japan's Digital Agency disclosed on September 11 that attackers exploited a VPN appliance vulnerability to access the Government Solution Service (GSS), a shared IT platform across ministries, exposing roughly 246,000 personal records. The attacker was active since late May using a maintenance staffer's credentials, with suspicious activity detected June 25 and containment on July 9. Exposed data covers about 189,000 employees/public officials and 57,000 contractors; no My Number, bank, or pension data was included. The VPN flaw was medium severity with a patch already available, and the 78-day detection-to-disclosure gap has drawn scrutiny.

Cyber Security News · 2d agoData breach in the wild 2 sources

Beyond the Perimeter: Building Resilience Against Cloud and SaaS Supply-Chain Attacks

ShinyHunters exploited an Oracle PeopleSoft zero-day to steal data and extort roughly 100 organizations, including the Council of Europe, for up to $2.3M.

Between May and early June 2026, the ShinyHunters group exploited a critical zero-day in Oracle PeopleSoft across about 100 organizations and 300 instances worldwide, per reports cited by The Register. Stolen records included employee and student personal data, payroll, tax, financial and health information, plus immigration and passport documents. AgentCypher.ai estimates extortion demands of $400,000 to $2.3 million per victim, typically in Bitcoin; the Council of Europe refused to pay. The article uses the incident to argue for Zero Trust, supply-chain risk management, rapid patching, encrypted distributed backups and defined recovery-time objectives.

Cyber Security News · 6d agoData breach in the wild2

America's Driver's License Breach Is a National Security Disaster

Dark web service Nexus sells 153 million US/Canadian driver's licenses linked to a breach of identity verifier IDScan.

Krebs on Security revealed a dark web service, Nexus, selling access to 153 million driver's licenses and 3 million travel documents from US and Canadian citizens, roughly 63 percent of all US licenses. Circumstantial evidence links the data to identity verification firm IDScan, which confirmed it is investigating a breach, and the FBI is probing the incident. Licenses belonging to senior US officials, including Pete Hegseth, an FBI assistant director, and Krebs's own contacts were verified as genuine. The exfiltration appears ongoing, with the database growing by nearly 400,000 licenses in a single day, and the data carries significant national security value for foreign intelligence services.

Hacker News · security · 2d agoData breachHN 26↑ · 4 comments3· 1 read

23 Million User Records Compromised in Gyazo Data Breach

Hacker exploited a Gyazo upload-server flaw, exposing 23.6 million user records and 490 million image metadata records.

Helpfeel disclosed that a hacker exploited a vulnerability in Gyazo's image upload server on September 11, executing malicious commands before being removed the next day. The attacker accessed a database with roughly 23.62 million user records, including names, email addresses, password hashes, user and device IDs, X integration tokens, profile data, usage statistics, and billing information. Additionally, about 490 million image metadata records were accessed, potentially allowing reconstruction of URLs to users' uploaded images, and a list of private images was also compromised. Payment card data was not affected.

SecurityWeek · 2h agoData breach in the wild 3 sources

Brevo Supply Chain Attack Injects Malware Into 100,000 Websites

Attackers breached Brevo, hijacked a Cloudflare API key, and injected ClickFix malware scripts served to visitors of 100,000+ websites including Trezor.

Brevo was hacked on September 10, 2026, via a vulnerability in its SAML SSO handling, exposing 138 accounts including crypto storage provider Trezor; attackers phished from six accounts and exported contacts from 43. On September 14 they used a compromised long-lived Cloudflare API key to deploy a worker that injected malicious scripts into brevo.com, sibforms.com, and three JavaScript files embedded in customer websites. The scripts showed fake 'Cloudflare, verify you are human' pages using the ClickFix technique and tried to install a malicious WordPress plugin for logged-in admins. Sansec estimates more than 100,000 websites were affected during roughly four hours; the API key was first misused in late August 2026.

SecurityWeek · 4h agoData breach in the wild 5 sources1

Spain reports first data breach involving autonomous AI agent

Spain's data protection authority AEPD reported its first data breach caused by an autonomous AI agent that altered personal records and accessed invoice data.

Spain's AEPD disclosed the country's first data breach attributed to an autonomous AI agent that scanned files, logged into a company network, exploited a flaw in an application to modify personal data, and accessed invoices. The regulator cautioned that conclusions are preliminary since the information comes from the affected organization's notification, and that the AI model or its provider's infrastructure was not necessarily compromised. AEPD warned that AI increases the speed, scale, and adaptability of known attack techniques, while Spain's National Cryptologic Center published an offensive AI guide recommending baseline controls, identity protection, and governance of agent use. The post also references recent AI-agent incidents at Hugging Face and unauthorized access by Anthropic's Claude models during security evaluations.

Help Net Security · 1d agoData breach in the wild1

CenterPoint Energy Data Breach – Hackers Stolen Customer’s Personal Data

CenterPoint Energy confirmed via SEC 8-K filing that an unauthorized third party stole customer personal data from an internet-facing system.

Houston-based utility CenterPoint Energy disclosed a breach in a Form 8-K filed September 14, 2026, after an online post claimed to offer a dataset of customer information. The company confirmed an unauthorized party accessed personal information for a portion of its customer base via an internet-facing system, but has not disclosed how many individuals were affected or what data types were exposed. Investigation with external forensic experts is ongoing, law enforcement and regulators have been notified, and electric and gas delivery operations remain unaffected. CenterPoint does not expect a material financial impact but warned the scope could grow as the review continues.

Cyber Security News · 1d agoData breach 5 sources

Electric and gas utility CenterPoint Energy warns of data breach after dark web post

CenterPoint Energy confirmed hackers stole customer personal data from an external-facing system after a dark web post claimed 7.5 million records.

Texas utility CenterPoint Energy filed an SEC 8-K disclosing that a dark web post claimed to sell data stolen from the company, and an investigation confirmed personal information was taken from an external-facing system. The criminal post claims about 7.5 million records including customer names, account information, last four Social Security digits and billing data. Electric and gas service was not impacted; the company serves 7 million customers across Indiana, Minnesota, Ohio and Texas, and previously disclosed a 2023 breach via a file-sharing platform.

The Record · 2d agoData breach

Revolut gave customer IDs and financial data to a government impostor

Revolut handed customer IDs, selfies, and financial records to criminals using a legitimate government agency email domain.

Revolut acknowledged disclosing sensitive customer records after accepting fraudulent information requests sent from an email address on a legitimate government agency domain, describing it as an external impersonation scam rather than a system intrusion. The London-based fintech, which serves more than 80 million customers globally, says customer funds were not affected and only a 'very limited' number of customers were impacted. Disclosed data includes identity and contact information, copies of passports and driver's licenses, verification selfies, account statements, and transaction histories. Revolut blocked the sending address and notified the relevant agency, law enforcement, data protection authorities, and financial regulators.

Malwarebytes Labs · 4d agoData breach

Revolut Data Breach Exposes Customers’ Passport Copies and Full Transaction Histories to Hackers

Revolut leaked KYC documents and full transaction histories after a fraudulent, domain-authenticated email request impersonating a government agency.

Revolut disclosed that an attacker using an unauthorized email account on a legitimate government domain, with valid domain-authentication credentials, tricked the fintech into releasing customer data. The exposed data includes passport and driver's license copies, identity-verification selfies, full names, dates of birth, addresses, IBANs, and complete transaction histories including Bitcoin activity. Revolut says core systems, accounts, and funds were not compromised, and it blocked the email source and notified authorities. On-chain investigator ZachXBT and others indicated the operation targeted high-net-worth users facing elevated phishing, SIM-swap, and extortion risk.

Cyber Security News · 5d agoData breach3· 1 read

Revolut Exposed KYC Data After Fraudulent Government Email Passed Security Checks

Revolut handed over KYC documents, selfies, and Bitcoin transaction histories to attackers after a fraudulent email from a genuine government domain passed authentication checks.

Revolut confirmed on September 12, 2026 that it disclosed sensitive customer KYC data to an unauthorized third party after a fraudulent information request was sent from an email account operating inside a real government agency's domain, carrying valid domain authentication credentials. The exposed data included identity documents (passports, driver's licenses), verification selfies, birth dates, contact details, IBANs, account statements, and full transaction histories including Bitcoin. Revolut discovered the fraud only after independently verifying with the agency, blocked the sender, and notified law enforcement and financial regulators, but did not disclose the number of affected customers or the agency involved. Researcher ZachXBT assessed the operation was targeted at high-net-worth users, useful for fraud, impersonation, or extortion.

Security Affairs · 5d agoData breach

Crypto customers targeted by scammers after email marketing provider breach

Attackers exploited a Brevo SAML SSO flaw to access 138 accounts and phish crypto customers of Trezor, CoinTracking, and BitBox.

An attacker exploited a flaw in Brevo's SAML SSO handling to access 138 customer accounts on September 10; six accounts were used to send phishing emails and contacts were exported from 43 accounts. Crypto firms Trezor, CoinTracking, and BitBox confirmed customers received phishing emails, with Trezor warning roughly 347,000 newsletter subscribers. The Trezor-themed email cited a fabricated STM32 microcontroller entropy bug and urged recipients to enter wallet backups through a malicious link. Exported contact lists could fuel future targeted phishing attacks.

Malwarebytes Labs · 6d agoData breach in the wild