Data breaches
A Somerset NHS worker accessed up to 200 patient records without permission between August 2017 and October 2023, sharing screenshots of medical information with their partner. The breach at Musgrove Park Hospital included sensitive data — demographic details, A&E visits, and appointment records — and even led to a patient being contacted using a phone number taken from hospital files.
The worker resigned before facing disciplinary action and received only a police caution, with officers concluding the actions weren't malicious. Victims are furious. "She violated families, vulnerable people," one told the BBC. Privacy campaigners are now calling for automatic NHS App notifications whenever patient records are viewed.
Source: BBC News
A Somerset NHS worker accessed up to 200 patient records without permission between August 2017 and October 2023, sharing screenshots of medical information with their partner. The breach at Musgrove Park Hospital included sensitive data — demographic details, A&E visits, and appointment records — and even led to a patient being contacted using a phone number taken from hospital files.
The worker resigned before facing disciplinary action and received only a police caution, with officers concluding the actions weren't malicious. Victims are furious. "She violated families, vulnerable people," one told the BBC. Privacy campaigners are now calling for automatic NHS App notifications whenever patient records are viewed.
Source: BBC News
The Cl0p ransomware gang has publicly named more than 40 organizations it claims to have breached through a vulnerability in PTC's Windchill and FlexPLM platforms. The flaw, CVE-2026-12569, allows unauthenticated remote code execution and was added to CISA's KEV catalog in June after active exploitation began.
High-profile alleged victims include Shell, Philips, Fiserv, Zebra Technologies, Ingersoll Rand, and Apple lens supplier Largan Precision. GE was listed but has been removed from C10p's website— possibly signaling ransom negotiations. Stolen data ranges from 1 GB to several terabytes per organization, covering databases, engineering blueprints, and corporate documents. None of the named companies have confirmed a significant breach.
Source: SecurityWeek
The Cl0p ransomware gang has publicly named more than 40 organizations it claims to have breached through a vulnerability in PTC's Windchill and FlexPLM platforms. The flaw, CVE-2026-12569, allows unauthenticated remote code execution and was added to CISA's KEV catalog in June after active exploitation began.
High-profile alleged victims include Shell, Philips, Fiserv, Zebra Technologies, Ingersoll Rand, and Apple lens supplier Largan Precision. GE was listed but has been removed from C10p's website— possibly signaling ransom negotiations. Stolen data ranges from 1 GB to several terabytes per organization, covering databases, engineering blueprints, and corporate documents. None of the named companies have confirmed a significant breach.
Source: SecurityWeek
A supply chain attack that exposed more than 2,000 organizations traces back to a compromised Trivy build — not LiteLLM, as initially reported. SOCRadar identified 2,188 organizations with attributable records and found 95% had their data collected before March 24, when the two poisoned LiteLLM releases appeared on PyPI for just 40 minutes.
The real damage started March 19, when TeamPCP force-pushed malicious commits to 76 of 77 trivy-action version tags, using access it had kept after an incomplete credential rotation — Aqua Security's own systems were never breached. Their Shai-Hulud worm harvested credentials, tokens, and API keys, then used stolen developer secrets to spread itself across accessible packages.
It all falls under CVE-2026-33634 — 8.8 high on CVSS v3.1, 9.4 critical on v4.0 — covering Trivy v0.69.4, trivy-action 0.0.1 through 0.34.2, setup-trivy 0.2.0 through 0.2.6, LiteLLM 1.82.7 to 1.82.8, and telnyx-python 4.87.1 to 4.87.2. CISA added it to KEV on March 26, with an April 9 deadline.
Six CI/CD platforms were hit — GitHub Actions, GitLab CI, Jenkins, Bitbucket, CircleCI, and Buildkite — with Germany, Brazil, and France most affected. Stolen data is already up for sale on Telegram.
Source: SecurityWeek
A supply chain attack that exposed more than 2,000 organizations traces back to a compromised Trivy build — not LiteLLM, as initially reported. SOCRadar identified 2,188 organizations with attributable records and found 95% had their data collected before March 24, when the two poisoned LiteLLM releases appeared on PyPI for just 40 minutes.
The real damage started March 19, when TeamPCP force-pushed malicious commits to 76 of 77 trivy-action version tags, using access it had kept after an incomplete credential rotation — Aqua Security's own systems were never breached. Their Shai-Hulud worm harvested credentials, tokens, and API keys, then used stolen developer secrets to spread itself across accessible packages.
It all falls under CVE-2026-33634 — 8.8 high on CVSS v3.1, 9.4 critical on v4.0 — covering Trivy v0.69.4, trivy-action 0.0.1 through 0.34.2, setup-trivy 0.2.0 through 0.2.6, LiteLLM 1.82.7 to 1.82.8, and telnyx-python 4.87.1 to 4.87.2. CISA added it to KEV on March 26, with an April 9 deadline.
Six CI/CD platforms were hit — GitHub Actions, GitLab CI, Jenkins, Bitbucket, CircleCI, and Buildkite — with Germany, Brazil, and France most affected. Stolen data is already up for sale on Telegram.
Source: SecurityWeek
Supporters of Yorkshire's Brain Tumour Charity were emailed on 12 August: an unauthorised third party had reached Beacon CRM, the database the Leeds charity uses, and exported all of it — names, addresses, donation records and health information. Beacon detected the intrusion on 29 July and warned customers on 4 August.
This isn't a YBTC problem. Beacon told every customer to assume all data stored in the platform has been downloaded. Sheffield Hospitals Charity was caught in the same incident. Beacon put the affected organizations at more than 1 000; later reporting puts it nearer 1 500 — close to its whole customer base. How many individuals, nobody knows.
The likely way in was an AWS access key exposed in publicly accessible JavaScript on Beacon's own site, embedded there by automated build tooling. Beacon says it has fixed the vulnerability, rotated its keys, forced password resets and added monitoring, and that no unauthorized access remains.
YBTC chief executive David Grant-Roberts says there's no evidence the data has been published, disclosed or otherwise misused, and asks supporters to be wary of unexpected emails, calls or texts mentioning YBTC, Beacon or donations. Affected charities have their own duty: report to the ICO within 72 hours, and the Charity Commission published guidance on 7 August.
Source: BBC News
Supporters of Yorkshire's Brain Tumour Charity were emailed on 12 August: an unauthorised third party had reached Beacon CRM, the database the Leeds charity uses, and exported all of it — names, addresses, donation records and health information. Beacon detected the intrusion on 29 July and warned customers on 4 August.
This isn't a YBTC problem. Beacon told every customer to assume all data stored in the platform has been downloaded. Sheffield Hospitals Charity was caught in the same incident. Beacon put the affected organizations at more than 1 000; later reporting puts it nearer 1 500 — close to its whole customer base. How many individuals, nobody knows.
The likely way in was an AWS access key exposed in publicly accessible JavaScript on Beacon's own site, embedded there by automated build tooling. Beacon says it has fixed the vulnerability, rotated its keys, forced password resets and added monitoring, and that no unauthorized access remains.
YBTC chief executive David Grant-Roberts says there's no evidence the data has been published, disclosed or otherwise misused, and asks supporters to be wary of unexpected emails, calls or texts mentioning YBTC, Beacon or donations. Affected charities have their own duty: report to the ICO within 72 hours, and the Charity Commission published guidance on 7 August.
Source: BBC News
A data breach in New York City's affordable housing lottery program exposed personal information for about 38,000 applicants, including names, incomes, phone numbers, and in some cases Social Security numbers. The breach occurred between May and July when applications became publicly searchable online due to a "system misconfiguration" by Reside New York, a company that reviews applications for the city.
City Council Housing Committee Chair Pierina Sanchez demanded answers after CBS News New York uncovered the breach. Reside CEO Martin Joseph blamed a third-party company called LogicFold for the mistake and says the portal was fixed immediately after being notified.
No identity theft or fraud has been reported so far. The city assures applicants that Housing Connect remains safe, and affected individuals are being offered credit monitoring services.
Source: CBS News New York
A data breach in New York City's affordable housing lottery program exposed personal information for about 38,000 applicants, including names, incomes, phone numbers, and in some cases Social Security numbers. The breach occurred between May and July when applications became publicly searchable online due to a "system misconfiguration" by Reside New York, a company that reviews applications for the city.
City Council Housing Committee Chair Pierina Sanchez demanded answers after CBS News New York uncovered the breach. Reside CEO Martin Joseph blamed a third-party company called LogicFold for the mistake and says the portal was fixed immediately after being notified.
No identity theft or fraud has been reported so far. The city assures applicants that Housing Connect remains safe, and affected individuals are being offered credit monitoring services.
Source: CBS News New York
Texas Attorney General Ken Paxton filed a lawsuit against California-based PowerSchool after hackers breached the company's systems in December 2024, exposing personal information of over 880,000 Texas students and teachers. The stolen data included Social Security numbers, medical records, disability information, and even bus stop locations.
A hacker used a subcontractor's account to transfer massive amounts of unencrypted data to a foreign server. PowerSchool, which serves over 90 of America's 100 largest school districts including Dallas ISD, allegedly failed to implement basic security measures like multi-factor authentication despite advertising "state-of-the-art" protection.
Paxton seeks fines and stronger security requirements, warning that children's credit could be compromised for years.
Source: CBS News Texas
Texas Attorney General Ken Paxton filed a lawsuit against California-based PowerSchool after hackers breached the company's systems in December 2024, exposing personal information of over 880,000 Texas students and teachers. The stolen data included Social Security numbers, medical records, disability information, and even bus stop locations.
A hacker used a subcontractor's account to transfer massive amounts of unencrypted data to a foreign server. PowerSchool, which serves over 90 of America's 100 largest school districts including Dallas ISD, allegedly failed to implement basic security measures like multi-factor authentication despite advertising "state-of-the-art" protection.
Paxton seeks fines and stronger security requirements, warning that children's credit could be compromised for years.
Source: CBS News Texas
AT&T will pay $177 million to settle lawsuits over two massive data breaches that exposed personal information of nearly 181 million customers. The 2019 breach affected 73 million people, exposing Social Security numbers and birth dates. The 2024 breach compromised phone records of 109 million customers through cloud provider Snowflake.
Customers affected by the 2019 breach can claim up to $5,000 with documented losses, while 2024 breach victims can receive up to $2,500. Those without proof of losses will receive smaller payments from the settlement pools. People hit by both breaches can file separate claims.
The deadline to file claims is November 18, 2025. Payments should begin early next year once the settlement receives final court approval.
Source: CNET
AT&T will pay $177 million to settle lawsuits over two massive data breaches that exposed personal information of nearly 181 million customers. The 2019 breach affected 73 million people, exposing Social Security numbers and birth dates. The 2024 breach compromised phone records of 109 million customers through cloud provider Snowflake.
Customers affected by the 2019 breach can claim up to $5,000 with documented losses, while 2024 breach victims can receive up to $2,500. Those without proof of losses will receive smaller payments from the settlement pools. People hit by both breaches can file separate claims.
The deadline to file claims is November 18, 2025. Payments should begin early next year once the settlement receives final court approval.
Source: CNET
Credit bureau TransUnion suffered a major data breach on July 28 that exposed sensitive information of 4.4 million customers. The breach compromised names, Social Security numbers, and birthdates through unauthorized access to a third-party application storing customer data.
State filings reveal conflicting details about what information was accessed, but the most serious filing from Texas confirms Social Security numbers were exposed. Since the breach occurred months ago, experts warn the stolen data may already be circulating on the dark web.
TransUnion is offering affected customers 24 months of free credit monitoring and notifying those impacted. Consumer rights firm Wolf Haldenstein advises people to watch for unusual credit report activity and consider freezing their credit.
Source: CNET
Credit bureau TransUnion suffered a major data breach on July 28 that exposed sensitive information of 4.4 million customers. The breach compromised names, Social Security numbers, and birthdates through unauthorized access to a third-party application storing customer data.
State filings reveal conflicting details about what information was accessed, but the most serious filing from Texas confirms Social Security numbers were exposed. Since the breach occurred months ago, experts warn the stolen data may already be circulating on the dark web.
TransUnion is offering affected customers 24 months of free credit monitoring and notifying those impacted. Consumer rights firm Wolf Haldenstein advises people to watch for unusual credit report activity and consider freezing their credit.
Source: CNET
AT&T has reached a massive $177 million settlement for two major data breaches that exposed millions of customers' personal information. The 2019 breach affected 73 million people, exposing Social Security numbers and birth dates. A separate 2024 hack accessed phone records of 109 million customers through cloud provider Snowflake.
Customers can now file claims through November 18, 2025. Those who can prove documented losses may receive up to $5,000 for the 2019 breach and $2,500 for the 2024 incident. People affected by both breaches can claim compensation from each settlement. Even without proof of loss, eligible customers will receive cash payments based on which breach affected them.
Source: CNET
AT&T has reached a massive $177 million settlement for two major data breaches that exposed millions of customers' personal information. The 2019 breach affected 73 million people, exposing Social Security numbers and birth dates. A separate 2024 hack accessed phone records of 109 million customers through cloud provider Snowflake.
Customers can now file claims through November 18, 2025. Those who can prove documented losses may receive up to $5,000 for the 2019 breach and $2,500 for the 2024 incident. People affected by both breaches can claim compensation from each settlement. Even without proof of loss, eligible customers will receive cash payments based on which breach affected them.
Source: CNET
Healthcare Services Group, a major provider of housekeeping and food services to healthcare facilities, suffered a significant data breach affecting 624,000 individuals. The Pennsylvania-based company discovered unauthorized access to its systems containing sensitive personal information including names, Social Security numbers, and medical data.
The breach occurred earlier this year, though the company has not disclosed specific details about how attackers gained access or the exact timeline of the incident. Healthcare Services Group has notified affected individuals and is providing credit monitoring services.
This breach adds to the growing list of healthcare-related cyberattacks in 2025, highlighting ongoing vulnerabilities in the sector's digital infrastructure.
Source: Security Week
Healthcare Services Group, a major provider of housekeeping and food services to healthcare facilities, suffered a significant data breach affecting 624,000 individuals. The Pennsylvania-based company discovered unauthorized access to its systems containing sensitive personal information including names, Social Security numbers, and medical data.
The breach occurred earlier this year, though the company has not disclosed specific details about how attackers gained access or the exact timeline of the incident. Healthcare Services Group has notified affected individuals and is providing credit monitoring services.
This breach adds to the growing list of healthcare-related cyberattacks in 2025, highlighting ongoing vulnerabilities in the sector's digital infrastructure.
Source: Security Week