24 Billion Credentials: Scale That Numbs, Threat That Doesn't
Cybernews uncovered an unsecured Elasticsearch cluster holding 24 billion plaintext credential records across 8.3 terabytes, complete with usernames,...

Created by CuratorMaster
Cybersecurity news, data breaches, ransomware attacks, hacking incidents, privacy concerns, online security tips, tech security updates
Explore the latest content tracked by Cybersecurity Hacking News
Cybernews uncovered an unsecured Elasticsearch cluster holding 24 billion plaintext credential records across 8.3 terabytes, complete with usernames,...
ShinyHunters turns single intrusions into domino effects through vishing, stolen SSO tokens, and supply-chain OAuth abuse.
Attackers now weaponize decades-old flaws faster than scanners detect them, making vulnerability management answer the wrong questions.
FulcrumSec's leak of Novo Nordisk's proprietary AI models alongside 1.3TB of data reveals how hackers now target trained models as high-value IP in drug development. This escalates risks beyond traditional clinical data theft.
AI impersonation attacks target credentials and actions, not just perception. Detection-based training can't keep pace as AI improves faster than...
A Cloud Security Alliance report shows 80% of organizations missing the 24-hour patch window experience security incidents tied to known...
Microsoft paired AI analysis with RICO to treat StealC and Amadey as one conspiracy, linking their shared infrastructure and suing five defendants.
-...
Palo Alto Networks, IBM, and Red Hat are integrating virtual patching with Project Lightwell to deliver same-day network protections before official...
International authorities seized €41 million in crypto and disrupted 326 servers plus 142 domains tied to Amadey, StealC, and SocGholish.
Scammers are impersonating trusted entities like tax authorities, software vendors, and email providers to exploit urgency and trust.
AI-powered attacks now reach data exfiltration in under 72 minutes, down from nearly five hours the prior year.
Modern malware shows striking diversity in families and tactics, all leveraging MaaS models and evasion techniques.
The FortiBleed operation has harvested more than 110 million credentials since February 2026 by targeting exposed FortiGate appliances through...
Germany leads Europe as the top ransomware target, with attacks often tracing back to Russia and growing nearly twice as fast as in France. This...
Attackers are exploiting CVE-2026-20230 in Cisco Unified CM weeks after the June 3 patch, with Defused detecting the first activity from a single...
ShadowPad's modular backdoor architecture allows remote plugin deployment for customized attacks, evolving from its 2015 origins as a PlugX...
Fraud begins quietly with data gathering, not fake invoices.