Top Security Breaches 2026-08-25
Top Security Breaches 2026-08-25
Auto-generated 2026-08-25T09:00:43.102880+00:00 (UTC)
-
South Korean startup platform breach exposes key management failures
Source: BleepingComputer | Published: 2026-08-24T14:00:10+00:00 | Score: 17.689
A breach at South Korea’s government-backed startup platform exposed encrypted personal data after an encryption key was included in an API. Penta Security explains why encryption keys must be securely managed and kept separate from the data they protect. […]
-
⚡ Weekly Recap: AI-Powered PLC Attacks, GitLab Attacks, Stripe Key Leaks and More
Source: The Hacker News | Published: 2026-08-24T14:32:10+00:00 | Score: 16.269
A package gets installed. A login prompt opens. A box sits exposed to the internet. Nothing looks unusual yet.
That’s roughly the mood this week. Trusted tools turn hostile, old weak spots get fresh attention, AI makes exploit work cheaper, and researchers keep finding attacks that sound harder than they actually are.
Plenty to clean up. Here’s the short version.
⚡ Threat of the Week
U.S.
-
Hackers Compromised 14,500+ Dahua Devices Using Credential Attacks, Auth Bypasses, and P2P
Source: The Hacker News | Published: 2026-08-19T11:34:28+00:00 | Score: 14.372
Cybersecurity researchers at Hunt.io have disclosed details of a campaign that they say compromised more than 14,530 Dahua devices between June 17 and July 22, 2026, using credential attacks, two authentication-bypass flaws, and a peer-to-peer (P2P) relay technique.
The activity, codenamed Operation CameraSwarm, was reconstructed from a 407 MB exposed working directory containing 2,616 files
-
ReliaQuest confirms failed data-theft attack after ShinyHunters breach
Source: BleepingComputer | Published: 2026-08-24T15:17:16+00:00 | Score: 14.203
Cybersecurity company ReliaQuest has confirmed that one of its employees was targeted in a social engineering attack after hackers impersonated a member of the security team. […]
-
Ransom Busters Claims It Hacked Ransomware Servers, Asks Victims for Up to $60,000
Source: The Hacker News | Published: 2026-08-18T16:58:16+00:00 | Score: 13.6
A ransomware affiliate calling itself Ransom Busters has been spotted proactively sending emails to victim organizations and claims to delete stolen data from ransomware groups’ servers in exchange for a fee ranging from $20,000 to $60,000.
“In these messages, the third-party offers to help the victim recover from ransomware attack. This immediately stands out as anomalous,” GuidePoint Research
-
WordlistLoader Delivers Amatera via ClickFix, SynkLoader Phishes Windows Passwords
Source: The Hacker News | Published: 2026-08-24T12:35:36+00:00 | Score: 13.545
Cybersecurity researchers have flagged two new malware families called WordlistLoader and SynkLoader that’s used to deliver next-stage payloads and likely sell access to ransomware groups.
According to findings from Gen Digital, WordlistLoader is being used to deliver Amatera Stealer (aka ACR Stealer or AcridRain Stealer) via ClearFake campaigns, which employ the ClickFix (aka FakeCaptcha)
-
Hundreds of leaked AWS keys give full control over corporate accounts
Source: BleepingComputer | Published: 2026-08-21T15:55:15+00:00 | Score: 13.41
More than 9,300 Amazon Web Services (AWS) access keys publicly exposed between August 2022 and August 2026 are still active and valid. […]
-
Why “Shady AI” is Security’s Next Big Governance Problem
Source: The Hacker News | Published: 2026-08-20T11:45:00+00:00 | Score: 13.234
In March 2026, an internal AI agent at Meta triggered a “Sev 1” incident after sensitive company and user data was exposed to employees who weren’t authorized to access it.
The incident began when a Meta employee posted a technical question on an internal forum. An engineer used an approved AI agent to analyze it, but the agent posted its response publicly without approval. The employee
End of report.