Top Security Breaches 2026-07-28
Auto-generated 2026-07-28T09:00:35.881689+00:00 (UTC)
-
ShinyHunters data leaks fuel $2,000 sextortion email scam
Source: BleepingComputer | Published: 2026-07-25T14:16:26+00:00 | Score: 20.059
Threat actors are using email addresses exposed in data breaches leaked by the ShinyHunters extortion group to send sextortion emails demanding $2,000 in Bitcoin. […]
-
Cl0p Affiliates Target Internet-Exposed PTC Windchill and FlexPLM with Unauthenticated RCE
Source: The Hacker News | Published: 2026-07-25T10:14:03+00:00 | Score: 18.315
Threat actors linked to the Cl0p (aka Chubby Scorpius, FIN11, Graceful Spider, and Lace Tempest) ransomware campaign are exploiting flaws in internet-exposed PTC Windmill and FlexPLM deployments as part of a new data extortion campaign.
“Attackers chain a pre-authentication information disclosure in the FlexPLM WSDL endpoint with a server-side flaw in the Windchill login servlet, enabling
-
Chaos Ransomware Uses msaRAT to Route C2 Traffic Through Headless Chrome and Edge
Source: The Hacker News | Published: 2026-07-23T13:11:09+00:00 | Score: 15.592
The Chaos ransomware group ran its command-and-control through the victim’s own browser. Cisco Talos on Thursday detailed msaRAT, the Rust implant behind it, found on a compromised Windows machine ahead of the encryptor.
The implant never opens an outbound connection of its own. Its process talks to 127.0.0.1 and nothing else. It starts Chrome or Edge in headless mode and drives the browser
-
Ernst & Young data breach claimed by ShinyHunters extortion gang
Source: BleepingComputer | Published: 2026-07-27T15:12:27+00:00 | Score: 14.502
The ShinyHunters extortion gang has claimed responsibility for a recently disclosed Ernst & Young data breach, saying it obtained credentials for some of the company’s systems via a supply-chain attack. […]
-
About 900,000 Origin Energy customers affected by hack as company admits it was warned weeks before public told
Source: World news | The Guardian | Published: 2026-07-28T05:41:39+00:00 | Score: 13.766
Chief executive, Frank Calabria, apologises and advises customers to look out for suspicious activity amid heightened scam risk Origin Energy has admitted it was warned of the hack that accessed 900,000 current and former customers’ personal data three weeks before it first made the data breach public. Australia’s largest energy retailer said a “significant” proportion of the 900,000 had been former customers, with those affected to be notified in the coming days. Continue reading…
-
OnTrac notifies customers of data breach after network hack
Source: BleepingComputer | Published: 2026-07-24T19:55:01+00:00 | Score: 13.455
OnTrac parcel delivery company is informing that hackers breached its corporate network and may have accessed personal details belonging to its customers. […]
-
Coca-Cola confirms data theft in Fairlife ransomware attack
Source: BleepingComputer | Published: 2026-07-27T15:39:51+00:00 | Score: 13.407
The Coca-Cola Company has confirmed that hackers stole data from its dairy subsidiary, Fairlife, during a ransomware attack earlier this month. […]
-
Coca-Cola Confirms Data Breach After Fairlife Ransomware Attack
Source: SecurityWeek | Published: 2026-07-27T11:29:03+00:00 | Score: 13.351
The Anubis cybercrime group has taken credit for the attack and is threatening to leak data. The post Coca-Cola Confirms Data Breach After Fairlife Ransomware Attack appeared first on SecurityWeek .
End of report.
