The extortion group ShinyHunters says it exploited an unauthenticated file upload flaw in Grav CMS to compromise the Tor-based data leak site run by the Clop ransomware operation. The attackers uploaded a taunting message, later fully defaced the site with Pokémon-themed ASCII art, and claim to have exfiltrated source code, CMS plugins, system logs and other server files. BleepingComputer confirmed the defacement was live on Clop's infrastructure and that the uploaded file could be downloaded from the site.
bleepingcomputer.com
· 2026-09-19
A 15.5 GB file containing over 7.3 million Chess.com user records surfaced for free on two data-leak forums, with no ransom attached. Analysis of the archive found genuine, recent Chess.com data including emails, usernames, ratings, and subscription status, but no passwords or payment details, pointing toward large-scale scraping rather than a server intrusion.
securityaffairs.com
· 2026-09-14
An anonymous researcher alerted the UK Biobank in April to sensitive participant data being sold on Alibaba's Xianyu marketplace, prompting officials to work with UK and Chinese authorities to remove the listing. The biobank then suspended researcher access for nearly five months while investigating the breach and rebuilding its data security infrastructure, with access set to resume this month.
nature.com
· 2026-09-08
Berlin officials confirmed cybercriminals are attempting to extort the city after the Rhysida ransomware gang publicly listed it on their leak site last Friday, following an intrusion discovered in mid-August. The attackers claim to have stolen nearly 1.44 million files totaling 5.79TB, including government, legal, financial, HR, and health records, along with credentials belonging to senior officials and infrastructure security assessments. Mayor Kai Wergner said Berlin will not pay, and law enforcement including the State Criminal Police Office and federal security agencies are investigating.
bleepingcomputer.com
· 2026-08-31
Apple is adding an agentic AI feature to its Passwords app in iOS 27 that can automatically update weak or compromised passwords instead of requiring users to change them manually. The feature is part of a broader Apple Intelligence push and is currently in beta, with rollout timing uncertain between iOS 27.0 and a later 27.1 update.
9to5mac.com
· 2026-08-27