CyberNews

Cybersecurity News Dashboard

Category

Filter the feed by target type (multi-select)
Clear
Showing 11–20 of 105 articles
API BleepingComputer

Anthropic confirms Claude is down in major outage affecting multiple services

Claude is experiencing a major outage, with users reporting login problems and degraded performance across several Anthropic services. The incident began on August 16, 2026, at around 21:58 UTC, and is affecting Claude.ai, Claude Code, and Claude Cowork. According to Anthropic’s status page, the company first said it was investigating an issue preventing some users from authenticating to Claude.ai, Claude Code, and Claude Cowork. A few minutes later, Anthropic reported a broader service disruption involving degraded performance on Claude.ai and platform.claude.com. For users, the outage can result in problems signing in, Claude failing to load, requests not completing, or other errors when using the affected services. Anthropic’s status page currently classifies Claude.ai, Claude Code, and Claude Cowork as experiencing a major outage. Claude Console and the Claude API are currently listed as operational.

Aug 16, 2026, 10:28 PM Read more →
RANSOMWARE Security Affairs

Sophisticated Cyberattack Exposes Data of 678,000 French Taxpayers

France’s tax agency says hackers stole data on 678,000 taxpayers, including income and tax details, in a sophisticated cyberattack. A threat actor claimed to have breached France’s tax agency in late June. France’s tax administration confirmed that a cyberattack exposed personal data of 678,000 individuals and businesses, prompting an immediate criminal investigation. The cybercrime unit of the Paris Public Prosecutor’s Office has opened a probe and handed it to OFAC, France’s dedicated cybercrime fighting office. Tax officials described the attack as more sophisticated than anything they’d faced before. “The attack allowed hackers to extract data relating to 678,000 users of France’s tax system, including both private individuals and companies.” reports French media RFI. “Tax authorities said the incident was more complex than cyberattacks they had faced in the past, potentially renewing concerns over the security of government information systems following a series of recent breaches involving other public bodies.” The Directorate-General for Public Finances (DGFiP) stressed that the stolen data doesn’t grant access to taxpayers’ secure accounts on impots.gouv.fr. That’s a meaningful distinction, but income figures, tax rates, and family circumstances are exactly what an attacker needs to make a phishing email or phone call sound credible enough to extract a password or bank account number. “Officials said those affected would be contacted from early next week, with particular emphasis on alerting them to the potential risk of identity theft and fraudulent attempts to obtain further personal information.” continues RFI. French authorities did not disclose technical details about the cyberattack or its motivation. The breach follows recent attacks on systems linked to ANTS, the national secure documents agency, and INSEE, France’s statistics authority. Three government bodies hit in quick succession is a pattern, not a coincidence. For businesses, the exposed data was considered less sensitive, SIREN registration numbers, business addresses, and the address of the authorized representative. Public Accounts Minister David Amiel has asked the DGFiP to start notifying affected taxpayers from Monday and requested proposals on how to strengthen security procedures. Investigators still need to establish how the attackers got in, who they are, and whether the data has already been sold or used. Anyone contacted about this breach should treat follow-up requests for passwords or banking information as fraudulent regardless of how official they sound. Follow me on Twitter: @securityaffairs and Facebook and Mastodon Pierluigi Paganini (SecurityAffairs – hacking, France’s tax agency)

Aug 16, 2026, 08:55 AM Read more →
RANSOMWARE Security Affairs CVE-2026-58231 ↗

SAP Commerce Cloud CVE-2026-58231 Exploited in the Wild

Attackers are actively exploiting a maximum severity SAP Commerce Cloud vulnerability, tracked as CVE-2026-58231, just days after SAP released a patch. A critical SAP Commerce Cloud vulnerability, tracked as CVE-2026-58231 (CVSS score of 10.0), is under active exploitation just days after SAP released a patch. The flaw stems from insufficient authorization checks and input validation. “SAP Commerce Cloud allows an unauthenticated attacker to abuse a default authentication client and submit specially crafted input to certain functions lacking sufficient validation.” reads the advisory. “Successful exploitation could enable arbitrary code execution and compromise internal components, resulting in high impact on confidentiality, integrity, and availability of the application.” An unauthenticated attacker can abuse a default authentication client and send crafted input to vulnerable functions, potentially achieving arbitrary code execution and compromising internal components. Researchers at Defused Cyber observed exploitation attempts against honeypots only three days after the patch was released. The researchers pointed out that this vulnerability has no public PoC and had not been known to be exploited prior to their discovery. First exploitation attempts against CVE-2026-58231 (unauth RCE in SAP Commerce Cloud, CVSS 10.0) is now hitting our honeypots – 3 days after patch day. This vulnerability has no public PoC and is not known to be exploited. View the full payload https://t.co/GXFaqggV8a pic.twitter.com/zMJuo45Ahx — Defused (@DefusedCyber) August 14, 2026 The attackers behind the current exploitation remain unknown. However, previous critical SAP flaws have been exploited by China-linked APT groups, including UNC5221 and UNC5174, and ransomware gangs. Follow me on Twitter: @securityaffairs and Facebook and Mastodon Pierluigi Paganini (SecurityAffairs – hacking, SAP Commerce Cloud)

Aug 15, 2026, 05:14 PM Read more →
RANSOMWARE BleepingComputer

Shell investigates 'potential incident' after Clop data theft claims

Oil giant Shell has confirmed it is investigating a potential security incident after the Clop ransomware gang claimed it stole 89GB of data. Shell is a British multinational energy conglomerate and one of the world's top three oil and gas companies, after Chevron and ExxonMobil. It has 85,000 employees in more than 70 countries and operates a massive network of tens of thousands of service and recharge stations that serve over 20 million customers daily. According to a recent post on Clop's dark web data leak site, the allegedly stolen files include engineering drawings, scans of facility testing reports, photos of the facilities, and project plans. "We are aware of a potential incident. We are working with our security teams and relevant experts to investigate," a Shell spokesperson told BleepingComputer when asked to confirm Clop's data theft claims.

Aug 14, 2026, 11:55 AM Read more →
IDENTITY The Hacker News

CTM360 Uncovers Over 3,000 Recruitment Phishing URLs Using Browser-in-the-Browser (BitB) Credential Traps

Cybersecurity researchers have uncovered a large-scale, global recruitment-themed phishing campaign that uses fake interview scheduling pages and Browser-in-the-Browser (BitB) windows to steal Google and Facebook credentials and, in more advanced cases, relay multi-factor authentication (MFA) prompts in real time. CTM360, which detailed the activity in a new report titled RecruitTrap, said it

Aug 14, 2026, 10:57 AM Read more →
RANSOMWARE Security Affairs

Chess.com Leak Exposes 7.3 Million Users – Evidence Points to Scraping

7.3 million Chess.com profiles leaked online: the data is genuine, but evidence points to large-scale scraping, not a server breach. Free is a strange price for stolen data, and that’s exactly what makes this listing worth a second look. A 15.5 GB file containing over 7.3 million chess.com user records showed up on two data-leak forums this week, no cost, no ransom demand, just handed out. Ransomnews’s technical analysis confirms the data is real and recent. What it isn’t, on the evidence, is a hack. “The archive is a single 744 MB 7-Zip file that expands to a 15.5 GB tab-separated table: one header row and 7,337,395 records, each with 38 fields. The schema is chess.com-specific throughout. Alongside the obvious identifiers, email, partial email, username, user ID, UUID, first and last name, country, location and locale, it carries platform state: chess title, points, skill level, premium status and label, verification and activation flags, best rating and rating type, official rating, member-since and last-login timestamps.” reads the report published by Ransomnew. “Two fields at the end are the interesting ones. Every record has gam_audiences and audiences_member_of populated, Google Ad Manager audience segments, with values like coach-nudge experiment groups, trial eligibility, lapsed-user cohorts and rating-band targeting. Those are marketing-stack fields, not profile data. They do not appear in chess.com’s public API.” The file carries email addresses, usernames, real names, countries, chess ratings, subscription tiers, and something odder: internal Google Ad Manager audience tags, the kind of marketing segmentation data that never shows up in chess.com’s public API. Roughly three-quarters of records include an email address. There are no passwords, no password hashes, and no payment data anywhere in the file, which matters a lot for how seriously affected users need to react. Proving this data is genuine didn’t require touching chess.com’s servers at all. Every account UUID in the file is a version-1 identifier, the kind that embeds the exact timestamp it was generated, and researchers decoded that hidden timestamp across 200,000 sample records to compare it against each account’s registration date. The match rate came back at 100%, which isn’t something anyone could fake without possessing actual chess.com-issued identifiers down to the millisecond. Three separate details point toward scraping rather than an actual system breach. The data wasn’t captured in one moment, it was stamped across nine consecutive days in daily batches, the pattern of a scheduled collection job rather than a single database dump. About 7.4% of user records appear twice, the same accounts revisited on different days, something that simply doesn’t happen inside a genuine database export. This has happened to chess.com before, and the company was blunt about it at the time. Back in 2023, a similar leak of 828,000 records surfaced with a nearly identical field structure, and chess.com stated plainly, “In November 2023 a threat actor published 828,000 chess.com records with a near-identical field set. Chess.com’s response then was unambiguous: as it told Hackread, “This was NOT a data breach.” continues the report. “Our infrastructure, member accounts, and data such as passwords are secure.” The data had been pulled by abusing the platform’s find-friends feature, feeding in externally sourced email addresses to resolve them against accounts. A second scrape affecting roughly 476,000 users followed. This 2026 file is the same technique at roughly nine times the scale.” That earlier incident came from abusing the platform’s find-friends feature to resolve external email lists against real accounts; this new file looks like the same technique running at roughly nine times the scale. One detail doesn’t fit a purely public-facing scrape, though. Advertising-audience segment data isn’t something chess.com’s open API exposes, and it appears on every single row in this file, which suggests whoever built this had access to an authenticated or internal-facing endpoint rather than just the public developer tools. That’s the specific question chess.com is best positioned to answer, and it’s the one that actually matters for understanding how this happened. The account distributing the file, going by V0idix, isn’t monetizing anything here. The same handle has posted dozens of free database dumps across other unrelated companies, building reputation through volume rather than through sales, which fits a collector who harvests and republishes data rather than someone selling access to a fresh intrusion. None of this means chess.com users should shrug it off just because passwords weren’t exposed. A verified email sitting next to a real name, country, skill rating, and subscription tier is more than enough raw material for a convincing phishing message about a membership renewal or a fair-play dispute. The right response isn’t panicking about a hacked account, it’s treating unexpected chess.com emails with more suspicion than usual and checking whether that same email address has turned up anywhere else, since reused credentials remain the far more dangerous exposure than anything sitting in this particular file. Follow me on Twitter: @securityaffairs and Facebook and Mastodon Pierluigi Paganini (SecurityAffairs – hacking, Chess.com)

Aug 14, 2026, 08:24 AM Read more →
RANSOMWARE Security Affairs

US Authorizes Private Cyber Firms to Hack Transnational Criminal Networks

Trump authorizes vetted US cybersecurity firms to conduct government-approved cyber operations against transnational criminal networks. President Trump signed a national security memorandum on August 13 establishing a formal program that allows vetted private US cybersecurity companies to conduct offensive cyber operations against transnational criminal organizations under government direction and oversight. The program, managed by the National Coordination Center, covers both intelligence collection, described as Cyber Surveillance Operations, and active disruption of criminal infrastructure, described as Cyber Effects Operations. It’s the formal implementation of what the White House’s Cyber Strategy for America promised in March: unleashing the private sector as an offensive cyber instrument. “The American private sector is the most innovative and technologically advanced in the world, and its scale, speed, and capacity secure a critical offensive cyber advantage for the United States. Yet, American businesses’ innovative capabilities have historically been underutilized in efforts to identify and disrupt criminal networks operating in cyberspace. Thus, it is the policy of the United States to use all instruments of national power, including the innovative capabilities of the private sector, to combat cybercrime.” states the memorandum. “By partnering with vetted United States companies subject to the direction and oversight of the Federal Government, we will enhance our ability to counter TCO threats and combat transnational cybercrime, fraud, and other predatory schemes against American citizens.” The program targets what the memo defines as Cyber-Enabled Transnational Criminal Organizations, any foreign group conducting cyber-enabled crime against US interests, explicitly excluding entities that are institutional parts of foreign governments or wholly operated under foreign government direction. That carve-out matters: this program is aimed at criminal networks, not nation-state adversaries. The line between the two is often blurry in practice, but the memo establishes the presumption that a group is not government-directed unless clear intelligence says otherwise. ““Cyber Effects Operation” means activity conducted in or through the interdependent network of information technology infrastructure that includes the Internet, telecommunications networks, computers, information systems, industrial control systems, networks, and embedded processors and controllers that results in the manipulation, disruption, denial, degradation, or destruction of information systems, networks, physical or virtual infrastructure controlled by information systems, or information resident thereon.” continues the memorandum. Program executive directors from the Department of Justice and the Department of Homeland Security must co-approve every operation in writing before any action is taken. Operations that could produce those Critical Outcomes require additional authorization beyond the program executive directors, an explicit acknowledgment that some cyber actions cross into territory governed by the laws of armed conflict. Companies wanting to participate must clear rigorous vetting, demonstrate technical capability, submit to annual evaluations, and maintain a bond or escrow of at least $1 million that is forfeited if they violate their contract terms. The operational procedures are to be finalized within 60 days, and the Justice Department will review any operation that touches a US person or raises domestic constitutional questions. The legal question hovering over the whole program is whether the CFAA exemption for lawfully authorized government investigative activities extends to private companies acting under government contracts, a question no US court has yet answered. Jenner & Block lawyers noted the exemption likely applies when companies operate under direct government direction, but wouldn’t cover independent offensive operations without that oversight. That’s precisely why the memo makes government control explicit at every step: every operation needs written approval before action, every unintended contact with a US person or system must trigger an immediate stop and notification, and the Justice Department stays in the loop throughout. Follow me on Twitter: @securityaffairs and Facebook and Mastodon Pierluigi Paganini (SecurityAffairs – hacking, Transnational Criminal Networks)

Aug 14, 2026, 07:14 AM Read more →
IDENTITY The Hacker News

IAM Compliance Requirements and Best Practices

IAM compliance is the practice of demonstrating that identity and access controls are not only documented but actually enforced across users, applications, infrastructure, and non-human identities. This guide explains what IAM compliance requires, which regulations matter, and how organizations move from periodic access reviews toward continuous, evidence-backed verification that auditors can

Aug 14, 2026, 05:19 PM Read more →
RANSOMWARE BleepingComputer

Akira hackers disable EDR with Safe Mode, steal data but fail to encrypt

An Akira ransomware affiliate disabled the endpoint detection and response (EDR) solution on a compromised system by restarting the machine into Safe Mode with Networking. The attack occurred on August 4 after the hacker obtained initial access through an exposed SonicWall VPN device without multi-factor authentication (MFA). Managed detection and response (MDR) services company Huntress says that roughly two hours after a successful VPN login, the attacker connected to the domain controller via RDP, enumerated Active Directory users and computers, and then moved to an application server. They used WinRAR to archive mapped file shares and the s5cmd command-line tool to upload the stolen data to an attacker-controlled S3 bucket, before installing AnyDesk for remote access. At that stage, the attacker used AnyDesk to force the compromised host to boot into Safe Mode with Networking and disable both the Huntress agent and Microsoft Defender’s real-time protection.

Aug 13, 2026, 08:47 PM Read more →
IDENTITY Security Affairs CVE-2026-71362 ↗

Adobe Commerce CVE-2026-71362 Comes Under Attack Shortly After Public Disclosure

Hackers began targeting a critical Adobe Commerce flaw that could let unauthenticated attackers hijack customer accounts and access private data. Hackers began targeting CVE-2026-71362 (CVSS score of 9.1), a critical Adobe Commerce flaw, shortly after its public disclosure. The vulnerability allows unauthenticated attackers to switch customer sessions, hijack accounts and access private data. Cybersecurity firm Sansec blocked the first exploitation attempts after Adobe published its advisory. The flaw affects Commerce, Commerce B2B and Magento Open Source versions through the July 2026 patches. Adobe released an isolated fix and urged users to patch. “Adobe has released APSB26-92 as isolated patch files. The update fixes seven vulnerabilities, including an unauthenticated customer account takeover with a CVSS score of 9.1. Sansec Shield already blocks exploitation attempts.” reads the advisory published by Sansec. “Sansec reviewed the patch and confirmed that the vulnerability lets attackers switch a customer session to another customer account. This gives them access to the victim’s account and private customer data.” Sansec pointed out that an attacker can exploit the flaw without existing account, administrator privileges, or user interaction. Adobe fixed how Magento handles customer identity in account sessions. The remaining flaws include stored cross-site scripting and authorization issues. Follow me on Twitter: @securityaffairs and Facebook and Mastodon Pierluigi Paganini (SecurityAffairs – hacking, Adobe)

Aug 13, 2026, 05:48 PM Read more →