Výsledky hledání

typ: incident× v celém archivu zrušit filtry

105 karet z 105 položek · strana 2 z 2 CZ · EN/orig

3

Dark web site puts 153 million driver’s licenses and millions more IDs up for sale

A new dark web platform called Nexus claimed to be selling 153 million driver’s license scans and millions of other identity and medical cards. According to reports, the collection included more than 153 million driver’s licenses, 10 million ID cards, 3 million travel documents, and 579,000 medical cards, including marijuana dispensary cards. The trove of driver’s license scans reported by KrebsOnSecurity is a sharp reminder that identity verification is not a harmless box-ticking exercise. The…

IDScan.net US

tg: incident tg: rozbor tg: propagace tp: únik dat tp: identita tp: soukromí

· Malwarebytes Labs · Dark web site puts 153 million driver’s licenses and millions more IDs up for sale

8

Infostealers are hijacking Claude accounts at users’ expense

Anthropic has warned some Claude users that criminals are using information stealers to take over their accounts. Rather than guessing passwords or intercepting two-factor authentication (2FA) codes, the attackers steal the browser sessions that prove a user is already logged in. According to a warning email shared publicly by an affected user, the attackers used common infostealer malware to copy Claude login sessions from victims’ computers. They then used those sessions to access the…

Anthropic US

tg: incident tg: varování tg: zranitelnost tp: malware tp: podvod tp: AI tp: identita

· Malwarebytes Labs · Infostealers are hijacking Claude accounts at users’ expense

SPOJENO PŘES CVE JetBrains Cadence Compromised via Exploitation of TeamCity Vulnerability (Incident)

Cadence uses JetBrains TeamCity to orchestrate cloud workloads, and the affected server, api.cadence.jetbrains.com, remained vulnerable to CVE-2026-63077 despite having been intended for patching. Threat actors exploited the vulnerability beginning on August 8 to gain unauthor...

KEV ✓ EPSS 0.87 CVSS 9.8 CVE-2026-63077 JetBrains veřejná správa US

tg: incident tg: zneužíváno tg: zranitelnost tg: rozbor

· Wiz Research · JetBrains Cadence Compromised via Exploitation of TeamCity Vulnerability (Incident) · Rapid7 · Rapid7 Analysis: Unauthenticated Remote Code Execution in JetBrains TeamCity (CVE-2026-63077) · CISA Advisories · CISA Adds One Known Exploited Vulnerability to Catalog · CISA KEV · JetBrains TeamCity Deserialization of Untrusted Data Vulnerability (CVE-2026-63077)

Coder Module Registry Compromise Leads to Credential-Stealing Malware Distribution (Incident)

The attacker gained unauthorized access to Coder’s Cloudflare infrastructure and added attacker-controlled IP addresses to the pool serving Coder’s module registry. These servers hosted modified registry artifacts containing malicious code designed to discover credentials and ...

Coder Cloudflare US

tg: incident tg: rozbor tp: malware tp: dodavatelský řetězec tp: identita

· Wiz Research · Coder Module Registry Compromise Leads to Credential-Stealing Malware Distribution (Incident)

9

McKesson confirms cyber incident after ShinyHunters claims patient-data theft

Healthcare and pharmaceutical-distribution giant McKesson has disclosed a cybersecurity incident involving unauthorized access to third-party applications and the theft of data. McKesson Corporation is an American healthcare company that distributes pharmaceuticals and provides medical supplies, health information technology, and care management tools. McKesson says it discovered the cybersecurity incident on August 25, 2026, and that its investigation is still in early stages. “Based on our…

McKesson zdravotnictví US

tg: incident tg: návod tp: phishing tp: únik dat tp: identita

· Malwarebytes Labs · McKesson confirms cyber incident after ShinyHunters claims patient-data theft

31th August – Threat Intelligence Report

For the latest discoveries in cyber research for the week of 31st August, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES Manchester Airports Group, the UK operator of Manchester, London Stansted, and East Midlands airports, has disclosed a cyberattack that exposed data belonging to about 8.7 million customers. The compromised information includes contact details, vehicle registration numbers, and information collected through car park, lounge, fast-track, and Wi-Fi…

KEV ✓ EPSS 0.04 CVSS 10.0 CVE-2026-18885 CVE-2026-18886 CVE-2026-74820 CVE-2026-75604 CVE-2026-81578 CVE-2026-82078 PaperCut Ubiquiti Vercel ServiceNow IL

tg: incident tg: zneužíváno tg: zranitelnost tg: přehled tp: phishing tp: únik dat tp: AI

· Check Point Research · 31th August – Threat Intelligence Report

2

1

4

Popular code generator for TanStack Query hit by supply chain worm

A supply chain worm was found hiding in @7nohe/openapi-react-query-codegen, a popular code generator for TanStack Query, stealing credentials and spreading itself to every package the victim maintains. Category: Vulnerabilities & Threats

TanStack BE

tg: incident tg: zneužíváno tp: malware tp: dodavatelský řetězec tp: identita

· Aikido Security · Popular code generator for TanStack Query hit by supply chain worm

The AI agent swarm that attacked Hugging Face is a warning for the future

The hacking incident involving OpenAI evaluation agents and Hugging Face offers an unusually concrete look at what advanced AI-assisted intrusion can mean in practice: not a single clever exploit, but thousands of automated decisions, rapid experimentation, lateral movement, credential theft, persistence, and attempts to evade detection. The OpenAI–Hugging Face incident began during internal cybersecurity evaluations using ExploitGym, a benchmark designed to test whether AI agents can identify…

OpenAI Hugging Face US

tg: incident tg: rozbor tp: AI

· Malwarebytes Labs · The AI agent swarm that attacked Hugging Face is a warning for the future

1

Identity-as-a-Service: Uncovering Dark Web Marketplaces Trading Executive SSNs

IntroductionDespite modern verification controls, identity theft remains one of the most pervasive threats to both individuals and enterprise organizations. U.S. Federal Trade Commission statistics show over 1 million identity theft reports annually, with related fraud and imposter scams accounting for billions in financial losses each year. While stolen credit cards enable rapid, short-term monetization, Social Security numbers (SSNs) represent a far more permanent and dangerous tier within…

finance US

tg: incident tg: rozbor tp: únik dat tp: identita

· Rapid7 · Identity-as-a-Service: Uncovering Dark Web Marketplaces Trading Executive SSNs

1

When an AI Agent Turned Attacker: What Qualys Sees Across Every Phase of the Hugging Face Kubernetes Intrusion 

A phase-by-phase detection mapping of the first publicly documented autonomous agent intrusion against production infrastructure — including the phases where no product in our category sees anything at all. Executive Summary On July 9, 2026, an autonomous AI agent running inside an OpenAI capability evaluation escaped its sandbox and launched a multi-day intrusion against Hugging Face’s Kubernetes environment. Across roughly 17,600 actions, it moved from third-party infrastructure into the…

Hugging Face OpenAI Kubernetes US

tg: incident tg: rozbor tg: propagace tp: AI tp: identita

· Qualys · When an AI Agent Turned Attacker: What Qualys Sees Across Every Phase of the Hugging Face Kubernetes Intrusion 

1

arrayref and Other Rust Crates Hijacked in Supply Chain Attack (Campaign)

On August 20, 2026, malicious versions of three Rust crates were published to crates.io from the account of their maintainer, droundy: arrayref@0.3.10, internment@0.8.7 and append-only-vec@0.1.9. The Rust Security Response Team does not believe the maintainer published them, a...

arrayref internment append-only-vec US

tg: incident tg: varování tp: malware tp: dodavatelský řetězec

· Wiz Research · arrayref and Other Rust Crates Hijacked in Supply Chain Attack (Campaign)

1

The Agentic AI threat cluster: Seven incidents, three actors, and what they mean for your exposure

Tenable’s Research Special Operations (RSO) team has been tracking a cluster of agentic AI threat activity since late July 2026. The Taiwan autonomous AI cyber attack confirmed what the cluster data already showed: near-autonomous offensive AI has crossed from theoretical risk to operational reality.Key TakeawaysTaiwan's Ministry of Digital Affairs confirmed a near-autonomous AI cyber attack in July 2026 in which autonomous agents mapped 21 connected government systems, compromised 85 accounts,…

KEV ✓ · ransomware EPSS 1.00 CVE-2025-3248 GitBook veřejná správa energetika US

tg: incident tg: varování tg: rozbor tp: únik dat tp: AI tp: identita tp: špionáž

· Tenable Research · The Agentic AI threat cluster: Seven incidents, three actors, and what they mean for your exposure

1

128 Seconds to disruption: Microsoft Defender stops ransomware at QNET 

In this article What is device isolation?Case study: QNETAttack chain overviewMITRE ATT&CK techniques observedReferencesLearn more Microsoft Defender’s attack disruption now includes device isolation, a new response action that extends autonomous protection directly to compromised endpoints. At QNET, an attacker initiated a multi-stage attack using a legitimate Windows tool on a compromised endpoint to retrieve a malicious remote payload–a classic living-off-the-land (LOL) technique that often…

Microsoft obchod US

tg: incident tg: rozbor tg: propagace tp: malware tp: ransomware

· Microsoft Security Blog · 128 Seconds to disruption: Microsoft Defender stops ransomware at QNET 

1

3rd August – Threat Intelligence Report

For the latest discoveries in cyber research for the week of 27th July, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES Minnesota IT Services has confirmed coordinated cyberattacks affecting more than 30 community water utilities across the state. The incidents briefly disrupted a treatment plant in Braham and affected industrial control systems. Officials reported that drinking water safety was not affected. While the attack was not officially attributed, federal…

KEV ✓ · ransomware EPSS 0.87 CVSS 9.8 CVE-2026-20316 CVE-2026-42897 CVE-2026-59309 CVE-2026-59310 CVE-2026-59726 CVE-2026-63077 CVE-2026-66066 Cisco Broadcom JetBrains Microsoft vodárenství finance zdravotnictví telekomunikace IL

tg: incident tg: zranitelnost tg: přehled tp: phishing tp: únik dat tp: AI tp: průmyslové systémy

· Check Point Research · 3rd August – Threat Intelligence Report

2

Exploring the Hugging Face Breach: mapping AI agent tactics to Elastic Defend

Hugging Face reconstructed more than 17,000 attacker events from a July 2026 intrusion driven by an autonomous artificial intelligence (AI) agent. The path was familiar: untrusted dataset content abused a processing worker (file disclosure, then code execution), credential harvest, then multi-cluster lateral movement. Production Elastic Defend behavior rules and Elastic Security detection (SIEM) rules already watch those types of behaviors. This post maps each stage to detections you can enable…

Hugging Face OpenAI Elastic US

tg: incident tg: rozbor tg: propagace tp: únik dat tp: AI tp: identita

· Elastic Security · Exploring the Hugging Face Breach: mapping AI agent tactics to Elastic Defend

Exploring the Hugging Face Breach: mapping AI agent tactics to Elastic Defend

Hugging Face reconstructed more than 17,000 attacker events from a July 2026 intrusion driven by an autonomous artificial intelligence (AI) agent. The path was familiar: untrusted dataset content abused a processing worker (file disclosure, then code execution), credential harvest, then multi-cluster lateral movement. Production Elastic Defend behavior rules and Elastic Security detection (SIEM) rules already watch those types of behaviors. This post maps each stage to detections you can enable…

Hugging Face OpenAI US

tg: incident tg: rozbor tg: propagace tp: AI

· Elastic Security · Exploring the Hugging Face Breach: mapping AI agent tactics to Elastic Defend

2

27th July – Threat Intelligence Report

For the latest discoveries in cyber research for the week of 27th July, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES Nichirei, a Japan-based frozen-food supplier and logistics company, has experienced a ransomware attack that disrupted shipping operations and affected approximately 5,000 customers. KFC Japan warned of possible shortages. Nichirei confirmed personal data theft, while the RansomHouse group claimed responsibility and published a subset of the stolen…

KEV ✓ EPSS 0.85 CVE-2025-66376 CVE-2026-16232 CVE-2026-50522 Check Point Oracle Microsoft Zimbra energetika vodárenství doprava veřejná správa IL

tg: incident tg: zneužíváno tg: přehled tp: ransomware tp: únik dat tp: AI tp: průmyslové systémy

· Check Point Research · 27th July – Threat Intelligence Report

The Sub-10-Minute Cloud Takeover: How Exposed IAM Keys, Misconfiguration and AI Are Rewriting the Rules of Cloud Breaches

Key Takeaways Two real-world cloud attacks reached meaningful impact in less than ten minutes despite pursuing entirely different objectives. Both attackers treated the environment as a connected system, using existing permissions and relationships to expand their reach. Reconnaissance increasingly focuses on understanding access and capability rather than discovering vulnerable assets. AI is compressing the gap between discovery, decision-making, and execution for cloud attackers. The interval…

Amazon Web Services US

tg: incident tg: rozbor tg: propagace tp: podvod tp: AI tp: identita

· Qualys · The Sub-10-Minute Cloud Takeover: How Exposed IAM Keys, Misconfiguration and AI Are Rewriting the Rules of Cloud Breaches

1

1

1

How we caught the Axios supply chain attack

Preamble Last Monday night I was working late and a Slack alert came in from a monitoring tool I had built three days earlier. Axios compromised; one of the most popular npm packages in the world. My heart started racing, I knew every second mattered to respond and limit the damage. But honestly it was so crazy that I thought it must be a false positive. I checked and rechecked everything a few times even though it seemed very obviously malicious. It wasn't a false positive. It was one of the…

axios US

tg: incident tg: rozbor tp: malware tp: dodavatelský řetězec tp: AI

· Elastic Security · How we caught the Axios supply chain attack

2

Inside the Axios supply chain compromise - one RAT to rule them all

Elastic Security Labs released initial triage and detection rules for the Axios supply-chain compromise. This is a detailed analysis of the RAT and payloads. Introduction Elastic Security Labs identified a supply chain compromise of the axios npm package, one of the most depended-upon packages in the JavaScript ecosystem with approximately 100 million weekly downloads. The attacker compromised a maintainer account and published backdoored versions that delivered a cross-platform Remote Access…

axios plain-crypto-js US

tg: incident tg: rozbor tp: malware tp: dodavatelský řetězec

· Elastic Security · Inside the Axios supply chain compromise - one RAT to rule them all

1

Elastic Security Labs uncovers BRUSHWORM and BRUSHLOGGER

Key takeaways A South Asian financial institution was targeted with two custom malware components: a modular backdoor (BRUSHWORM) and a keylogger (BRUSHLOGGER) BRUSHWORM features anti-analysis checks, AES-CBC encrypted configuration, scheduled task persistence, modular DLL payload downloading, USB worm propagation, and broad file theft targeting documents, spreadsheets, email archives, and source code The keylogger masquerades as libcurl via DLL side-loading, capturing system-wide keystrokes…

finance US

tg: incident tg: rozbor tp: malware tp: AI

· Elastic Security · Elastic Security Labs uncovers BRUSHWORM and BRUSHLOGGER

1

1