ZeroHour

Search: “US hospitals”

342 stories

BambooToken Malware Uses MQTT to Control Windows and Linux Systems

Lumen uncovers BambooToken, a stealthy multi-platform malware using MQTT C2 and Tendyron DLL sideloading to compromise Asian and South American organizations.

Lumen Black Lotus Labs disclosed BambooToken, a previously undocumented malware family active since at least February 2023 that controls Windows and (since December 2025) Linux hosts via the MQTT protocol for C2. The malware sideloads a rogue OnKeyToken_KEB.dll via Tendyron's OnKey PKI token software, gathers host details, and uses a WMI-based plugin to enumerate installed antivirus products and exfiltrate them to C2 domains proxied through Cloudflare. A dozen compromised entities were detected across Asia and South America, and DLL sideloading plus SoftEther VPN usage suggests a China nexus.

The Hacker News · 1d agoMalware in the wild 2 sources

Hackers claim millions of patient records stolen during data breach at healthcare giant McKesson

Hackers claim theft of millions of patient records from US healthcare distributor McKesson, which confirmed a hack and expects service degradation.

McKesson, which distributes medicines and medical devices to hospitals and healthcare practices across the US, said it was hacked. Threat actors claim millions of patient records were stolen in the breach. The company said it expects intermittent service degradation as it responds to the incident.

TechCrunch · Security · 16d agoData breach in the wild

IDScan Confirms Data Breach Following 153 Million Driver’s Licenses Leaked on the Dark Web

IDScan.net confirms a breach after a marketplace advertised over 153 million US and Canadian driver's licenses, possibly exfiltrated continuously for over a year.

The Louisiana identity-verification firm detected unauthorized access on or around September 1, 2026, after the 'Nexus' identity theft service on the Exploit forum began advertising 170M+ people's records, including 153M+ driver's licenses, 10M+ ID cards, 3M+ travel documents, and 579,000 medical cards. Canadian records exceed 1.1 million, and the trove includes commercial licenses, Common Access Cards, and dispensary IDs, with a record for US Defense Secretary Pete Hegseth reportedly included. Nexus operators claim continuous exfiltration for over a year, with the license count growing by nearly 400,000 in 24 hours, suggesting the intrusion may be active. The FBI's New Orleans field office has opened a formal inquiry, and IDScan.net is offering free credit monitoring.

Cyber Security News · 6d agoData breach in the wild 4 sources

Going with the Flow(s): Distinct Clusters Target Individuals of Interest to Russia

Suspected Russian clusters abuse OAuth and authentication flows to phish academia, defense, government, and think tank targets across Europe and the US.

Google Threat Intelligence Group (GTIG) is tracking three distinct suspected Russian cyber espionage clusters abusing legitimate authentication flows. Newly detailed clusters UNC7005 and UNC5976 conduct phishing, abuse OAuth flows, and/or deploy malware, alongside previously reported UNC6293 phishing operations. Targets include individuals in academia, aerospace and defense, governments, and think tanks across Europe, as well as academia and think tanks in the United States.

Google Threat Intelligence · 27d agoThreat actor in the wild