ZeroHour

Search: “Windows 11”

12 stories

Week in review: Records allegedly stolen from Azure tenants, Medusa ransomware hits 500+ orgs

Week in review: Medusa ransomware hit 500+ orgs per CISA, millions of Azure tenant records allegedly stolen, SafePal and French tax authority breaches disclosed.

Help Net Security's weekly roundup covers the FBI, CISA, and HHS joint advisory update reporting Medusa ransomware has breached more than 500 organizations since June 2021, and threat actor TheHatman's claim of millions of employee records stolen from Azure tenants of Fortune 500 firms including McDonald's, Vodafone, Kyndryl, and Tata Consultancy Services, per Hudson Rock. It also covers the SafePal breach affecting 39,798 customers, France's DGFiP breach exposing data on 678,000 individuals, and UT San delaying its fall semester after a cyberattack. Security items include critical unauthenticated GitLab flaw CVE-2026-19478, an actively exploited patched macOS Screen Sharing flaw deploying a cryptominer, US charges against 17 Mabna Institute Iranian hackers over 31TB of stolen academic data, and Google Mandiant's AI agents finding 100+ high-severity vulnerabilities.

Help Net Security · 26d agoData breach in the wildCVE-2026-19478

Three intrusions at UK criminal records office went undetected for two years

UK ICO reprimands ACRO criminal records office after three undetected intrusions over two years exposed thousands of records, including domestic violence victims.

The UK Information Commissioner's Office reprimanded ACRO Criminal Records Office after three intrusions between July 2021 and June 2023 exploited a Kentico customer portal unpatched since September 2019 and ignored Trend Micro antivirus alerts, including four quarantined Mimikatz detections. An attacker maintained persistent access for roughly seven months and staged data of nearly 11,000 people for exfiltration, though ACRO could not confirm exfiltration due to insufficient logging. ACRO notified more than 84,000 people on a precautionary basis; the Medusa ransomware group claimed the incident, and network segmentation kept attackers out of the Police National Computer.

The Record · Aug 12, 2026Data breach in the wild

Hackers reveal how Flock cameras really track cars and people

Hackers tore down a Flock Safety camera, dumped its storage, recovered an encryption key, and revealed its software detects people as well as vehicles.

Hackers from a collective calling itself stegan0gram removed a Flock Safety camera from service, made a near-complete copy of its storage, and recovered an encryption key stored on the device that unlocked thousands of vehicle-detection videos, sharing the files with 404 Media, WIRED, and Distributed Denial of Secrets. Analysis of about 21 days of logs shows more than a million images, roughly 28 photos per passing vehicle, and Flock-built apps that detect people, bicycles, and even bumper stickers, while plate inference happens on Flock's servers. Flock had previously downplayed early-2025 root-access research by Jon Gaines, and records from Alpharetta, Georgia were searchable by over 2,000 agencies via Flock's national network.

Ars Technica · Securityupdated · 19h agofirst · 1d agoData breach in the wild 6 sources

Brevo supply-chain attack injected ClickFix scripts on customer sites

Attackers used a stolen Cloudflare API key to inject ClickFix malware-delivery scripts into Brevo sites and customer-embedded scripts for five hours.

Brevo confirmed attackers stole a long-lived Cloudflare API key with full account permissions that had been hardcoded in source code, and used it to create a malicious Cloudflare Worker that rewrote content at the CDN edge for roughly 5.5 hours on September 14 (16:07-20:30 UTC), affecting brevo.com, sendinblue.com, sibforms.com, and customer-embedded Brevo scripts; Sansec estimated up to 100,000 websites may have been exposed. Visitors saw fake Cloudflare verification pages with ClickFix instructions to run a Windows command, and the injected code uploaded a persistent WordPress backdoor plugin named 'Web Media Optimizer' to sites where logged-in admins browsed. The backdoor hides from the plugin list, persists in the must-use plugins directory, contacts attacker servers, and contains a hardcoded key to forge WordPress administrator sessions. Brevo said app.brevo.com, its API, email delivery, and customer data were unaffected; a separate September 10 SSO incident led to Trezor phishing hitting 347,000 addresses with at least 2,500 accounts compromised.

BleepingComputerupdated · 4h agofirst · 20h agoData breach in the wild 5 sources

SafePal breach affects 39,798 customers, data allegedly for sale

SafePal disclosed a breach exposing order data of 39,798 customers via an order-tracking plug-in flaw; the data appears for sale online.

Cryptocurrency wallet maker SafePal exposed names, phone numbers, addresses and purchase details for 39,798 orders placed between March 2, 2025 and April 11, 2026, due to an authorization flaw in an order-tracking plug-in. Seed phrases, private keys, wallet passwords, payment cards and government IDs were not exposed, and no wallet or fund compromise was found. A threat actor is selling data on a cybercrime forum citing the same order window and count, and SafePal has taken down more than 30 phishing sites and notified customers on August 16.

Help Net Security · Aug 17, 2026Data breach in the wild

SafePal Hardware Wallet Maker Says Flaw Exposed Data of Nearly 40,000 Customers

SafePal disclosed an order-tracking plug-in authorization flaw exposing names, emails, addresses and purchase details of 39,798 hardware wallet customers; no wallet credentials affected.

Hardware wallet maker SafePal disclosed that an authorization flaw in an order-tracking plug-in exposed names, email addresses, shipping addresses, phone numbers and purchase details of approximately 39,798 customers. No seed phrases, private keys, wallet credentials or financial information were exposed, and SafePal found no evidence of wallet or fund compromise. A separate configuration error left a data-cleanup process broken between September 2025 and April 2026, extending the affected order window back to March 2025. A threat actor has advertised a matching dataset on a cybercrime forum, and the company has fixed the flaw, cut data retention to 90 days, purged affected records, engaged third-party validators and taken down over 30 phishing sites.

The Hacker News · Aug 18, 2026Data breach in the wild