❌

Normal view

There are new articles available, click to refresh the page.
Yesterday — 25 September 2026Main stream

Stevens Point servers go offline, city officials not sure if caused by a cyberattack

By: Dissent
24 September 2026 at 13:30
Brandi Makuski reports: Stevens Point officials are investigating a possible cyberattack after several city computer servers went offline early Wednesday, disrupting municipal phone and email services and leaving employees unable to access some city systems. District 4 Councilwoman Andrea Olson said city IT employees notified staff and council members of a cyberattack in a 6:51...

Source

Wyoming courts investigate extent of personal data exposed in cybersecurity breach

By: Dissent
24 September 2026 at 12:35
Maggie Mullen reports: The Wyoming Judicial Branch says it’s awaiting more details regarding the scope of a cybersecurity breach of a third-party software company that may have included a decade’s worth of data from the state’s court system. West Publishing Corporation, which the Wyoming Supreme Court and Wyoming district courts previously used for case management,...

Source

Error on North Carolina jury duty website exposed people’s social security numbers, medical records, more

By: Dissent
24 September 2026 at 12:33
Kudos to WBTV for following up on an astute observer’s vulnerability report. David Hodges reports: North Carolina residents summoned for jury duty received notice through a letter in the mail but to request an exemption from jury duty in North Carolina, a person can go online and fill out a jury excuse form. Zach Duda...

Source

Before yesterdayMain stream

FBI Hack Exposed FBI’s Own Hacking Unit

By: Dissent
23 September 2026 at 19:52
Joseph Cox reports: The catastrophic hack of at least thousands of FBI officials’ personal data, including their addresses, phone numbers, and even their spouses, includes members of the FBI’s secretive hacking team, potentially revealing who exactly is in that unit, 404 Media has found. The findings further highlight how sensitive the stolen data is, and...

Source

Canva hacked via vendor’s Salesforce instance; Other customers affected as well

By: Dissent
23 September 2026 at 16:59
A new dedicated leak site by threat actors calling themselves “The Seven Deadly Sins” lists Canva Pty Ltd among the sites that haven’t paid them. DataBreaches obtained additional details on the incident and this new group. Attack on Canva A spokesperson for The Seven Deadly Sins (TSDS) informed DataBreaches that on August 28, TSDS attacked...

Source

Latvia arrests suspected hacker for electronics repair company breach

By: Dissent
23 September 2026 at 11:51
Daryna Antoniuk reports: Latvian police arrested a 23-year-old man suspected of hacking at least two companies, stealing personal information and attempting to extort money from the victims, authorities said Wednesday. The first attack was detected in February, while a second — using similar methods — was discovered in early September at TSC, an electronics repair...

Source

ShinyHunters escalates dispute with FBI; claims to have seized job applicants’ site and acquired data (1)

By: Dissent
22 September 2026 at 14:43
Joseph Cox reports: A high profile hacking group claims it has breached multiple FBI-related services and stolen data “on all FBI employees and applicants.” A representative of the group, called ShinyHunters, told 404 Media the data includes FBI agents’ names, home addresses, phone number, and information on their spouse. The data breach could be massively...

Source

Spokane Public Schools takes some systems offline after ‘network security incident’

By: Dissent
22 September 2026 at 09:05
Shannon Moudy reports: Some systems are offline Monday after Spokane Public Schools says it experienced an overnight ‘network security incident.’ In an email sent to families Monday, the district says the situation is being investigated. “Out of an abundance of caution, we have chosen to take several of our systems offline. As a result, families...

Source

After water attacks, Capitol Hill offers its own proposal for an AI-cyber test program

22 September 2026 at 17:14

A House Democrat tapped to lead his party’s efforts on artificial intelligence has introduced legislation that would establish a test program within the Cybersecurity and Infrastructure Security Agency to give critical infrastructure operators free access to frontier AI models to protect their systems.

Rep. Josh Gottheimer, D-N.J., introduced the AI Cyber Defense Act Monday, inspired by the series of cyberattacks on water facilities in recent months. “If we don’t get ahead of it, it can mean a disaster for our families,” he said at a news conference when he first announced the measure and others tackling water cybersecurity.

Gottheimer holds a couple of posts relevant to the legislation: He’s one of three co-chairs of the House Democratic Commission on Artificial Intelligence, and the top Democrat on the House Intelligence Committee’s cyber subcommittee. He also has bipartisan support for the bill, with co-sponsors Reps. Don Bacon, R-Neb., Zach Nunn, R-Iowa, Hillary Scholten, D-Mich., and Greg Landsman, D-Ohio.

The bill directs the Department of Homeland Security, through CISA, to create a program “through which owners and operators of critical infrastructure that participate in the Program are able to securely utilize artificial intelligence procured through the Secretary and technical assistance provided by the Secretary to protect against, detect, test for, and remediate vulnerabilities in the cybersecurity of such critical infrastructure.”

AI-tinged, water-focused cybersecurity pilot programs are all the rage lately. The introduction of Gottheimer’s legislation is adjacent to, but different from, a test program that the Office of the National Cyber Director recently announced in Texas.

One criticism of that program is that private sector companies offered their cyber and AI services through it on a purely voluntary basis, with no significant budget to bolster the pilot. Gottheimer’s bill would authorize $100 million for the pilot program from 2027 to 2031 before it ends, although appropriators would have to follow through on providing the actual dollars. The Trump administration has significantly cut CISA funding in its second term.

“Right now federal funding for critical infrastructure has an uncertain future and many of our local communities just don’t have the resources they need to pay for AI tokens to do the patching they need,” Gottheimer said when he introduced the bill. “It’s expensive to bring the AI in to analyze your system and find those vulnerabilities.”

Critical infrastructure owners and operators could apply for the pilot program, which the bill directs to give priority to nonprofit, publicly owned, rural and small-sized organizations.

“The same technology that can help a small town’s IT guy find and patch a gap in cybersecurity can also help a hostile government find a hundred more it hasn’t even discovered yet,” Gottheimer said when he announced the bill. “AI didn’t create this threat, but it’s accelerated it, and our defenses have to keep up.”

The post After water attacks, Capitol Hill offers its own proposal for an AI-cyber test program appeared first on CyberScoop.

Another worry for water systems: infostealer exposure

22 September 2026 at 06:00

Nearly two of every 10 U.S. water and wastewater organizations have identity data actively exposed from infostealers harvesting their credentials, according to research published Tuesday.

The study from identity risk firm SpyCloud follows months of reports about a wave of cyberattacks hitting targets in the sector, which U.S. government officials suspect are tied to Iran.

The company built a database of 66,845 Environmental Protection Agency-registered systems, examined internet domains and ultimately analyzed 10,000 organizations, finding that 1,787 showed active infostealer exposure.

In one case, a single infected device at a smart meter technology provider that SpyCloud didn’t name contained saved logins linked to roughly 167 different U.S. utility metering tenants — meaning that one exposure opened the door to many more. 

That “cascading supply chain exposure” was one of the biggest findings of the report that SpyCloud shared exclusively with CyberScoop, said Jason Lancaster, chief investigations officer at the cyber firm, along with the quantitative approach” to measure exposure overall.

“We talk about it a lot,” Lancaster said of the exponential risk that one exposure can present. “There’s examples here and there, but that was a standout example of, here’s a tangible thing that is an exposure right now.”

Generally, “Infostealer exposure means the attacker isn’t guessing anymore, they’ve got legitimate points of entry,” Lancaster said. “In the investigations I’ve worked, that log data usually contains stolen session cookies, credentials, and autofill info pulled straight off the infected device. That’s enough to walk right past [multifactor authentication] by hijacking an already-authenticated session, log into corporate email or VPNs without raising a single alert, and sit there quietly for weeks while they map out the network.”

Still, the study had limitations. It doesn’t address what apparently led to the cyberattacks that unfolded in Minnesota and elsewhere this summer: internet-exposed programmable logic controllers.

It’s “important to note that our research did not focus on OT devices which run the most critical processes within these utilities, and any exposure we cite herein should not be interpreted as exposure of specific OT devices,” the report said. It did, however, find that 258 of the 1,787 organizations with active infostealer exposure carried credentials to operational technology or remote-access systems.

Some of the report’s conclusions were about the limitations of the data itself.

“Exposure concentrated in larger operators and in the vendor supply chain; small utilities were largely underrepresented,” SpyCloud said. “That’s a pattern in the data, not a claim that every water system nationwide carries this risk — and it measures identity exposure, not confirmed intrusion.”

It’s the first study of its kind that SpyCloud has done for a specific industry, so the company doesn’t have comparisons to other industries, Lancaster said. SpyCloud has begun a responsible disclosure process for those affected within its report, he said, beginning with a briefing for the Cybersecurity and Infrastructure Security Agency.

“It’s important to remember, infostealer logs aren’t the end of an incident — they are often the beginning,” Lancaster said. “Access brokers sell these logs specifically because ransomware crews and other fraudsters want exactly this kind of entry point. So, the real question isn’t whether the exposure is dangerous. It’s how much time you have before someone weaponizes that stolen data against you.”

The post Another worry for water systems: infostealer exposure appeared first on CyberScoop.

Dems seek top-to-bottom assessment of CISA workforce

21 September 2026 at 12:05

A group of leading House Democrats introduced legislation Monday requiring the Cybersecurity and Infrastructure Security Agency to conduct an assessment of its workforce to determine whether it’s up to the task after the exit of around 1,000 employees during President Donald Trump’s second term.

The concept of a force structure assessment is more common in military branches, including one that Congress previously ordered for Cyber Command. The CISA Force Structure Assessment Act would order the agency to carry out a review of whether the agency still has the necessary personnel, training and certifications after budget cuts and other Trump-era departures.

“America’s cyber defenses are only as strong as the people behind them,” Rep. James Walkinshaw, the Virginia Democrat serving as lead sponsor of the bill, said in a news release. “As cyber threats grow more sophisticated and technologies like artificial intelligence and quantum computing reshape the threat landscape, Congress needs a clear accounting of whether CISA has the workforce, skills, and resources required to keep Americans safe and enable mission delivery. This legislation will identify critical gaps and give Congress concrete information to address them.”

Also sponsoring the bill are the top Democrat on the House Homeland Security Committee, Bennie Thompson of Mississippi, and the top Democrat on its cybersecurity subcommittee, Delia Ramirez, D-Ill.

Additional elements of the force structure assessmewould include a review of the security of federal IT systems and support for state and local governments; the risks posed by AI, quantum computing and other cutting edge technologies; CISA’s threat-hunting and incident response capabilities; support for critical infrastructure and operating technology, including CISA’s role as a sector risk management agency for a number of industry sectors; the operation of the Joint Cyber Defense Collaborative; and international cooperation.

Some lawmakers and other observers have worried those areas have been greatly impacted by staffing cuts, ultimately hurting CISA’s ability to carry out its core functions.

Ramirez dinged GOP lawmakers for “a lack of interest in safeguarding our nation’s cybersecurity and our residents’ civil rights and privacy” in going along with the CISA cuts and other developments at the Department of Homeland Security.

Lawmakers on both sides of the aisle have voiced concern about the scope of cuts at CISA, but Republicans have approved some of them while pushing back on others. CISA itself is currently seeking to hire hundreds of new personnel, even as its latest budget blueprint calls for yet more funding reductions.

“With Iran targeting our critical infrastructure and frontier AI models creating new cyber risks, we must ensure we have a cybersecurity workforce to counter these growing threats,” Thompson said. “After Trump has spent the past two years targeting and slashing CISA’s workforce, we need the agency to assess if it has [the] right personnel in place to fulfill its mission.”

National Cyber Director Sean Cairncross has discussed White House plans to develop a cybersecurity academy meant to consolidate and enhance existing federal cyber training and education programs, with the aim of addressing cyber workforce shortages. His office has reportedly drafted an executive order that would establish that academy.

The post Dems seek top-to-bottom assessment of CISA workforce appeared first on CyberScoop.

Ransomware attack on Kansas county will affect some services

By: Dissent
18 September 2026 at 16:43
Joseph McCarty reports: A Kansas county’s government says it has been hit by a ransomware attack. Ellis County discovered the attack on parts of its information technology systems Thursday morning. Officials said they “immediately took steps to contain the disruption” by isolating the affected systems and enlisting the help of cybersecurity experts. The county said...

Source

The U.S. military leaked more than 93,000 tips via insecure P3 Global Intel. Has anyone been notified?

By: Dissent
18 September 2026 at 15:56
As part of DataBreaches.net’s ongoing investigation into the Navigate360 breach, this report covers approximately 94,000 unclassified but sensitive tips submitted through P3 Global Intel apps and websites used by the military. What has Homeland Security done in response to the breach?  When the Navigate360 breach first broke, DDoSecrets.org called it “BlueLeaks 2.0” because of the...

Source

Raon data leak: Insider leak of 1,894 cases went undetected for 4 years

By: Dissent
18 September 2026 at 08:45
Choi Won-woo reports: Internal data amounting to 1,894 cases from the Korean-type heavy ion accelerator ‘Raon,’ built with a state budget of 1.5 trillion Korean won [USD $1,080,038,017.50 at today’s rates] was confirmed to have been leaked externally. The estimated time of the leak is 2022, and the Institute for Basic Science (IBS) Heavy Ion...

Source

Navigate360 may soon release a public notice about its horrific breach, but will any individuals be notified?

By: Dissent
17 September 2026 at 08:07
Six months ago, a hacktivist announced that they had accessed and acquired 8.3 million tips submitted on supposedly anonymous tip lines and platforms used by schools, communities, Crime Stoppers organizations, law enforcement, and the military. Six months later, individuals affected by the breach STILL haven’t been notified.  Since April, DataBreaches has reported Navigate360’s lack of public transparency about the...

Source

Gyazo Breach Exposes 23.62 Million User Records and 490 Million Image Metadata Records

By: Dissent
17 September 2026 at 07:40
Swati Khandelwal reports: A security breach at Gyazo, Helpfeel’s image-sharing service, exposed about 23.62 million user records, including email addresses and password hashes, the Kyoto-based company said in a notice published Wednesday. It also exposed about 490 million image metadata records, mostly for images from January 2019 or earlier, including the IDs that make up...

Source

Student photos, bank details stolen by hackers after St James Anglican School in Perth hit by cyber attack

By: Dissent
15 September 2026 at 07:48
Emma Kirk reports: A school in Perth’s north has been targeted in a cyber attack, with hackers stealing students and families’ personal information. St James Anglican School, in Perth’s north, identified a cyber breach involving unauthorised access into its computer systems. Parents were advised the school immediately contained the cyber security incident and secured its...

Source

Possible cyber incident disrupts Monroe schools in Wisconsin

By: Dissent
14 September 2026 at 13:44
Joseph Topping reports an incident at the School District of Monroe in Wisconsin has resulted in the district pulling the plug on internet connections: Students powered down computers, school phone service failed and a scheduled ACT session was canceled after a possible network security issue disrupted the School District of Monroe in Wisconsin. Classes continued...

Source

Silent Ransom Group Hacked Greenberg Traurig; Who notifies the 126k Affected? (1)

By: Dissent
14 September 2026 at 09:03
Silent Ransom Group added Greenberg Traurig to its list of prominent law firms it attacked and leaked. DataBreaches.net has exclusive details on the incident. On August 21, when DataBreaches reported on a data breach affecting Troutman Pepper Locke, the firm was one of 64 law firm listings on Silent Ransom Group’s (SRG’s) leak site. As...

Source

AT&T store worker gets 16 months inside for SIM-swap side hustle

By: Dissent
13 September 2026 at 10:50
Connor Jones reports: A former AT&T retail worker who used his system access to hijack customers’ phone numbers for cybercriminals has been sentenced to 16 months in federal prison. Kenneth Carter, 44, carried out the SIM swaps at a store in Portland, Oregon, , allowing the criminals to intercept authentication codes and raid victims’ bank accounts....

Source

❌
❌