Data Security

Cybersecurity
24,650 Internet-Exposed Server BMCs Leak Password Hashes Before Login
Researchers found 24,650 internet-exposed BMCs that disclose IPMI password hashes before login, enabling offline hash cracking and full server takeover.
Cybersecurity
CubePilot Drone Controller Developer Hit by DNS Hijacking
Attackers seized CubePilot's domain DNS settings and obtained TLS certificates for all subdomains, potentially capturing credentials during the attack window.
Cybersecurity
Flying Eagle Android RAT Leaks on Telegram, 170 C2 Servers Active
Flying Eagle Android RAT source code is on Telegram; researchers traced matching panels to 170 servers targeting Chinese users via a fake government app.
Cybersecurity
Victims Sue Apple Over $1.8M Bitcoin Theft Via Fake Sparrow App
Three individuals sued Apple over a fake iOS Sparrow Wallet app that stole $1.8 million in Bitcoin by harvesting seed phrases. Apple was warned in ...
Cybersecurity
ShinyHunters Claims Ernst & Young Breach via Third-Party System
ShinyHunters posted Ernst & Young to its leak site, claiming a supply-chain attack on a third-party ticket system that exposed client tax and financial data.
Cybersecurity
Origin Energy Breach Exposes Data on 900,000 Australian Customers
Origin Energy disclosed a breach affecting 900,000 Australian customers, exposing names, bank account fragments, and addresses amid unconfirmed ransom claims.
Cybersecurity
DentaQuest Breach Affects 23.4 Million, PHI and SSNs Exposed
DentaQuest's breach notification confirms up to 23.4 million Medicaid dental enrollees potentially affected, with SSNs and dental PHI stolen in a network hack.
Cybersecurity
PEAR Ransomware Breach at MCBS Hits 1.26 Million Patients
PEAR ransomware group claimed 3 TB stolen from MCBS, a medical billing firm whose breach exposed 1.26 million patients at seven healthcare organizations.
Cybersecurity
ClickLock macOS Stealer Uses App-Kill Loop to Coerce Passwords
Group-IB documented ClickLock, a macOS stealer using a 210ms app-kill loop to coerce macOS passwords, hitting more than 100 victims across 33 countries.
Cybersecurity
Russian Threat Actor Uses Gemini CLI to Run Dental Clinic Botnet
Trend Micro documented Russian actor 'bandcampro' using Gemini CLI as a hacking assistant in a dental clinic botnet attack on an OpenDental patient database.