breach

Amazon: AI-assisted Hacker Breached 600 FortiGate Firewalls in 5 Weeks

Russian-speaking hacker used AI to breach 600 Fortinet firewalls in 55 countries within five weeks, exploiting weak credentials and exposed interfaces without zero-day exploits. The attack involved automating access and reconnaissance tasks with AI-generated tools, leading to stolen configurations and credentials. Recommendations for FortiGate admins include disabling internet exposure of management interfaces and enabling MFA.

https://www.bleepingcomputer.com/news/security/amazon-ai-assisted-hacker-breached-600-fortigate-firewalls-in-5-weeks/

PayPal Data Breach Exposes SSNs and Business PII of Customers for Over Six Months

PayPal experienced a data breach due to a coding error in its Working Capital loan application, exposing customers' personal information, including Social Security numbers and business details, for about six months. The breach was identified on December 12, 2025, and reported to affected customers on February 10, 2026. No external intrusion was involved; it was an internal issue. PayPal has since rolled back the problematic code, terminated unauthorized access, initiated a full investigation, and is offering affected users two years of free credit monitoring.

https://cybersecuritynews.com/paypal-data-breach-expose-customer-data/

Chinese Hackers Exploiting Dell Zero-day Flaw Since Mid-2024

Chinese hackers have been exploiting a critical Dell security flaw, identified as CVE-2026-22769, in their RecoverPoint for Virtual Machines since mid-2024. The UNC6201 group uses hardcoded credentials for unauthorized access, deploying sophisticated malware like Grimbolt to infiltrate VMware networks. To mitigate these attacks, Dell advises affected customers to apply recommended remediations.

https://www.bleepingcomputer.com/news/security/chinese-hackers-exploiting-dell-zero-day-flaw-since-mid-2024/

Eurail Says Stolen Traveler Data Now up for Sale on Dark Web

Eurail's stolen customer data is for sale on the dark web after a breach revealed sensitive records, including names and bank details. The company is investigating the extent of the breach and has notified data protection authorities. Affected customers should be alert for phishing attempts and update their passwords.

https://www.bleepingcomputer.com/news/security/eurail-says-stolen-traveler-data-now-up-for-sale-on-dark-web/

2026 State of Enterprise Infostealer Identity Exposure

In 2025, enterprise identity exposure intensified, with enterprise identity logs increasing from 8% to 11% of all logs. Microsoft Entra ID credentials appeared in 79% of these logs, making them the most compromised. Over 18% of identity logs contained credentials for multiple providers, expanding the potential impact of a single breach.

https://flare.io/learn/resources/2026-enterprise-infostealer-identity-exposure/

Have I Been Pwned: SoundCloud Data Breach Impacts 29.8 Million Accounts

SoundCloud experienced a data breach affecting 29.8 million accounts, exposing email addresses and public profile information. The breach was confirmed on December 15, 2025, after users reported access issues. An investigation revealed no sensitive data was accessed, but the ShinyHunters group claimed responsibility and attempted extortion.

https://www.bleepingcomputer.com/news/security/have-i-been-pwned-soundcloud-data-breach-impacts-298-million-accounts/

Massive Credential Leak Exposes 149 Million Stolen Logins for Gmail, Facebook, Netflix and More

Massive leak of 149 million stolen logins (including for Gmail, Facebook, Netflix) poses significant customer trust risks, revealing cybersecurity failures. Exposed data includes sensitive credentials linked to major services. This incident highlights the need for improved security measures and customer education on malware risks, as credential theft becomes industrialized. Brands must prioritize trust and proactive responses to protect customer experience amidst rising cyber threats.

https://www.cxtoday.com/security-privacy-compliance/massive-credential-leak-exposes-149-million-stolen-logins-for-gmail-facebook-netflix-and-more/

BreachForums Hacking Forum Database Leaked, Exposing 324,000 Accounts

BreachForums hacking forum suffered a data breach, leaking 324,000 member accounts and internal data. The leak includes usernames, registration dates, and IP addresses, though many are local and not useful. The breach followed previous law enforcement actions against the forum, which has a history of being relaunched. The current admin acknowledged a temporary exposure of the database and advised members to use disposable emails for security.

https://www.bleepingcomputer.com/news/security/breachforums-hacking-forum-database-leaked-exposing-324-000-accounts/

An Instagram Data Breach Reportedly Exposed the Personal Info of 17.5 Million Users

Instagram data breach exposes info of 17.5M users, including usernames and emails, up for sale on dark web; risks include phishing and account takeovers. Malwarebytes ties breach to Instagram API from 2024. Users advised to enable two-factor authentication.

https://www.engadget.com/cybersecurity/an-instagram-data-breach-reportedly-exposed-the-personal-info-of-175-million-users-192105616.html

NordVPN Denies Breach Claims, Says Attackers Have “dummy data”

NordVPN denied breach claims, stating attackers accessed “dummy data” from a third-party testing platform, not sensitive information from its servers. A hacker alleged they stole databases with API keys through a brute-force attack, but NordVPN clarified the data was from a test environment unrelated to its actual systems. No real customer data was compromised, and the company had previously enhanced security following past breaches.

https://www.bleepingcomputer.com/news/security/nordvpn-denies-breach-claims-says-attackers-have-dummy-data/

Hackers Claim to Hack Resecurity, Firm Says It Was a Honeypot

Hackers claim to have breached cybersecurity firm Resecurity, stealing data. Resecurity argues it was a planned honeypot, containing only fake information to lure attackers. The group shared alleged screenshots of the breach, while Resecurity states the attackers accessed only synthetic datasets intended for monitoring. Resecurity has tracked the hackers' activity and reported findings to law enforcement.

https://www.bleepingcomputer.com/news/security/hackers-claim-resecurity-hack-firm-says-it-was-a-honeypot/

Trust Wallet Links $8.5 Million Crypto Theft to Shai-Hulud NPM Attack

Trust Wallet links $8.5M crypto theft to November's Shai-Hulud NPM attack, where an exploit of their Chrome extension enabled unauthorized access to over 2,500 wallets. Attackers used stolen GitHub secrets to inject malicious code into the browser extension's update. Trust Wallet has since revoked API access and started compensating affected users while repelling ongoing impersonation scams. The Shai-Hulud malware campaign compromised numerous npm packages, exposing 400,000 developer secrets.

https://www.bleepingcomputer.com/news/security/trust-wallet-links-85-million-crypto-theft-to-shai-hulud-npm-attack/

US, Australia Say ‘MongoBleed’ Bug Being Exploited

US and Australian cyber agencies confirmed hackers are exploiting the “MongoBleed” vulnerability in MongoDB systems, first revealed on December 25. CISA added it to their exploited vulnerabilities catalog, requiring federal agencies to patch by January 19. The bug affects many MongoDB versions, enabling unauthorized access to sensitive data. Experts warn about widespread exposure, estimating 42% of cloud environments have vulnerable instances, potentially impacting thousands globally.

https://therecord.media/us-australia-bug-exploitation

Scroll to Top