The extortion group ShinyHunters says it exploited an unauthenticated file upload flaw in Grav CMS to compromise the Tor-based data leak site run by the Clop ransomware operation. The attackers uploaded a taunting message, later fully defaced the site with Pokémon-themed ASCII art, and claim to have exfiltrated source code, CMS plugins, system logs and other server files. BleepingComputer confirmed the defacement was live on Clop's infrastructure and that the uploaded file could be downloaded from the site.
bleepingcomputer.com
· 2026-09-19
A reverse-engineering report by developer ferstar found that ZCode, the coding agent built by Z.ai around its GLM models, silently packages a user's entire workspace—including .git history, LFS caches, reflogs and global configs—encrypts it, and uploads the archive to Aliyun OSS whenever a user is logged in. The researcher captured a 313MB encrypted archive from a 345MB commercial project spanning over 42,000 files, plus 564 logged failed upload attempts during investigation.
tokenstead.ai
· 2026-09-18
CrowdSec disclosed that a leak of its private source code repositories occurred in May 2026 and was reported to the company on September 16. The exposed material includes SaaS console code, AWS routines, connectors, and CI/CD tokens, but excludes CrowdSec's public Security Engine software. The company found no evidence of leaked credentials, customer data, or login information, and believes the Tanstack supply-chain compromise was the likely entry point.
crowdsec.net
· 2026-09-17
A 15.5 GB file containing over 7.3 million Chess.com user records surfaced for free on two data-leak forums, with no ransom attached. Analysis of the archive found genuine, recent Chess.com data including emails, usernames, ratings, and subscription status, but no passwords or payment details, pointing toward large-scale scraping rather than a server intrusion.
securityaffairs.com
· 2026-09-14
Security researchers found a flaw in Android's network stack that lets any app, without special permissions, send UDP packets through the device's Wi-Fi or cellular hardware that bypass VPN tunnels entirely. This occurs even when the 'Block all connections without VPN' setting is enabled, exposing a user's real IP address. The bug was reported through Google's Vulnerability Reward Program but closed without action, while GrapheneOS says it is working on a fix.
mullvad.net
· 2026-09-11
Shelly has released the Flood S Gen4, a Matter-certified water leak sensor priced under $30 that works natively with Apple Home, Google Home, Alexa, SmartThings, and Home Assistant. The device uses three large stainless steel contact pads instead of small metal pins, allowing it to detect water faster and even sense low-conductivity liquids like AC condensate.
9to5mac.com
· 2026-09-11
An anonymous researcher alerted the UK Biobank in April to sensitive participant data being sold on Alibaba's Xianyu marketplace, prompting officials to work with UK and Chinese authorities to remove the listing. The biobank then suspended researcher access for nearly five months while investigating the breach and rebuilding its data security infrastructure, with access set to resume this month.
nature.com
· 2026-09-08
A Bitcoin mining data center in El Reno, Oklahoma, owned by Athlon Blockchain LLC, has been condemned after leaking roughly 3 million gallons of water, prompting closures of schools, businesses, and city and county offices. The facility had reportedly continued construction and operations despite a 2023 city Stop Work Order tied to fire and safety code violations and expired permits.
tomshardware.com
· 2026-09-06
Berlin officials confirmed cybercriminals are attempting to extort the city after the Rhysida ransomware gang publicly listed it on their leak site last Friday, following an intrusion discovered in mid-August. The attackers claim to have stolen nearly 1.44 million files totaling 5.79TB, including government, legal, financial, HR, and health records, along with credentials belonging to senior officials and infrastructure security assessments. Mayor Kai Wergner said Berlin will not pay, and law enforcement including the State Criminal Police Office and federal security agencies are investigating.
bleepingcomputer.com
· 2026-08-31
Apple is adding an agentic AI feature to its Passwords app in iOS 27 that can automatically update weak or compromised passwords instead of requiring users to change them manually. The feature is part of a broader Apple Intelligence push and is currently in beta, with rollout timing uncertain between iOS 27.0 and a later 27.1 update.
9to5mac.com
· 2026-08-27