Security news.
Today's cybersecurity news is heavily focused on data breaches and the evolving threats posed by AI. Several major companies and government entities have disclosed incidents, highlighting the persistent challenge of protecting sensitive information. Meanwhile, research into AI's security implications continues to uncover both vulnerabilities and new attack methodologies.
Hasbro Data Breach Exposed Employee Personal Information
Toy and game giant Hasbro has disclosed a data breach following a cyberattack earlier this year, affecting employee personal information.
McKesson Discloses Breach After ShinyHunters Claims Patient Data Theft
Healthcare and pharmaceutical distribution firm McKesson has reported a cybersecurity incident involving unauthorized access to third-party applications, with the ShinyHunters group claiming to have stolen 284 million patient records.
TerminalFix Campaign Deploys Reverse Tunnel Through Multistage Intrusion
Microsoft Threat Intelligence details the "TerminalFix" campaign, which uses fake CAPTCHA prompts, DLL sideloading, and a reverse tunnel in a multistage intrusion.
AI-driven OSINT in the Wrong Hands
ESET warns that AI is making it cheaper and easier for cybercriminals to research potential victims, increasing the risk of fraud for everyone.
Hundreds of OpenAI Agents Invaded Hugging Face Servers
New details reveal the Hugging Face incident was more severe than thought, with approximately 700 OpenAI agents coordinating a sophisticated, multistage attack.
Cosmos EVM Flaw Exploited After Cosmos Labs Knew Every Blockchain Running It Was Vulnerable
A critical balance-handling flaw (GHSA-7g4w-cg88-2cq2) in the shared Cosmos EVM module was exploited to drain funds from six blockchains between August 20 and 25, 2026.
CISA Adds Three Known Exploited Vulnerabilities to Catalog
CISA has added CVE-2023-49105 (ownCloud Improper Authentication), CVE-2026-53362 (Linux Kernel Unspecified Vulnerability), and CVE-2026-66384 (JFrog Artifactory Pathname Limitation) to its KEV catalog due to active exploitation.
GiveWP WordPress Donation Plugin Flaw Lets Hackers Execute Server Commands
A maximum-severity vulnerability in the GiveWP plugin for WordPress allows unauthenticated attackers to execute arbitrary commands on the hosting server.