Latest Threat Feed

EY DATA BREACH EXPOSES GOLDMAN SACHS AND MAN GROUP CLIENT INFORMATION

The EY data breach has exposed sensitive information belonging to clients of Goldman Sachs, Man Group and real estate developer Tishman Speyer. According to the Financial Times, compromised records included names, addresses, email addresses, tax identifiers and financial information. Goldman Sachs and Man Group said their own internal systems were unaffected. EY attributed the incident […]

EY DATA BREACH EXPOSES GOLDMAN SACHS AND MAN GROUP CLIENT INFORMATION Read More »

Latest Threat Feed

ASOS CONFIRMS CYBER INCIDENT AFTER ATTACKERS HIJACK CUSTOMER NOTIFICATION PLATFORM

ASOS confirmed on October 6, 2026, that unauthorized activity affected third-party platforms used to communicate with customers, enabling an unidentified party to send an unauthorized notification through the retailer’s official channels. The UK-based online fashion retailer said basic personal information, including customer names and contact details, may have been accessed. ASOS does not currently believe

ASOS CONFIRMS CYBER INCIDENT AFTER ATTACKERS HIJACK CUSTOMER NOTIFICATION PLATFORM Read More »

Latest Threat Feed

WARLOCK RANSOMWARE HITS WATER AND TELECOM OPERATORS THROUGH SHAREPOINT FLAWS

NEW ATTACKS TARGET CRITICAL INFRASTRUCTURE October 2, 2026 — The operators of Warlock ransomware have compromised at least four organizations during a two-month campaign targeting Portuguese- and Spanish-speaking countries, according to new research from Symantec’s Threat Hunter Team. The identified victims include a water utility, telecommunications provider, regional government body and university across Europe, Africa

WARLOCK RANSOMWARE HITS WATER AND TELECOM OPERATORS THROUGH SHAREPOINT FLAWS Read More »

Latest Threat Feed

MI5 WARNS CHINESE-LINKED INSTITUTE USED UK RESEARCH TO ADVANCE ESPIONAGE

FIRST PUBLIC ESPIONAGE ALERT TARGETS ACADEMIC PARTNERSHIPS MI5 issued an unusual public warning on September 30, 2026, alleging that a Chinese research organization covertly funded British academic work to strengthen China’s technical espionage capabilities. The UK intelligence agency said more than 100 UK-linked academics contributed to projects financed through the China General Technology Research Institute,

MI5 WARNS CHINESE-LINKED INSTITUTE USED UK RESEARCH TO ADVANCE ESPIONAGE Read More »

Latest Threat Feed

TIMES CAR BREACH EXPOSES 6.6 MILLION ACCOUNTS, INCLUDING 1.6 MILLION IDENTITY DOCUMENTS

COMPANY CONFIRMS LARGE-SCALE DATA THEFT Times Mobility has confirmed that an attacker stole personal information associated with approximately 6.6 million current, former and prospective Times Car accounts. In a September 29, 2026 update, the Japanese car-sharing operator disclosed that roughly 1.6 million affected accounts included copies of identity documents. The exposed files may contain driver’s-license

TIMES CAR BREACH EXPOSES 6.6 MILLION ACCOUNTS, INCLUDING 1.6 MILLION IDENTITY DOCUMENTS Read More »

Latest Threat Feed

CISA FLAGS RANSOMWARE USE OF CRITICAL JETBRAINS TEAMCITY VULNERABILITY

A critical vulnerability in JetBrains TeamCity On-Premises is now known to be used in ransomware campaigns, according to an update to CISA’s Known Exploited Vulnerabilities catalog. The flaw, tracked as CVE-2026-63077, gives organizations running unpatched TeamCity servers an urgent reason to update and investigate possible intrusion. An attacker who can reach a vulnerable TeamCity server

CISA FLAGS RANSOMWARE USE OF CRITICAL JETBRAINS TEAMCITY VULNERABILITY Read More »

Latest Threat Feed

SALESBLEED FLAWS LET SALESFORCE AI AGENTS LEAK CRM DATA AND SEND PHISHING MESSAGES

Security researchers have disclosed three vulnerabilities in Salesforce Agentforce that could have allowed attackers to steal sensitive CRM data and distribute phishing messages through trusted enterprise AI agents. Collectively named SalesBleed, the flaws were discovered by Zenity Labs. Researchers found that an attacker could place malicious instructions inside a Salesforce Web-to-Lead submission. When an employee

SALESBLEED FLAWS LET SALESFORCE AI AGENTS LEAK CRM DATA AND SEND PHISHING MESSAGES Read More »

Latest Threat Feed

ASTRANA HEALTH DATA BREACH EXPOSES CONFIDENTIAL INFORMATION AFTER SOCIAL ENGINEERING ATTACK

Astrana Health has disclosed a material cybersecurity incident involving unauthorized access to private and confidential information stored on company servers. According to a September 23 filing with the U.S. Securities and Exchange Commission, attackers impersonated Astrana Health personnel and spoofed the company’s main telephone number while contacting employees. The social engineering campaign was designed to

ASTRANA HEALTH DATA BREACH EXPOSES CONFIDENTIAL INFORMATION AFTER SOCIAL ENGINEERING ATTACK Read More »

Latest Threat Feed

SOLARWINDS PATCHES CRITICAL UNAUTHENTICATED RCE FLAWS IN OBSERVABILITY PLATFORM

SolarWinds has released an urgent security update addressing two remote code execution vulnerabilities in its Observability Self-Hosted platform. The flaws could allow unauthenticated attackers to execute malicious code on affected systems under specific configurations. The vulnerabilities are tracked as CVE-2026-28324 and CVE-2026-28325. SolarWinds fixed both issues in Observability Self-Hosted version 2026.2.3, released on September 22,

SOLARWINDS PATCHES CRITICAL UNAUTHENTICATED RCE FLAWS IN OBSERVABILITY PLATFORM Read More »

Latest Threat Feed