Gyazo, a screenshot-sharing service owned by Helpfeel, confirmed a data breach exposing 23.62 million user records and 490 million image metadata records after attackers exploited a server vulnerability. The breach occurred on or before September 18 and compromised user emails, usernames, and hashed passwords.
Australian energy retailer Origin Energy confirmed an unauthorized party accessed and leaked sensitive customer data including personally identifiable information. The breach exposed approximately 2 million customer records.
About 900,000 current and former customers of Australia's largest energy retailer had their data accessed in a cyberattack. CEO Frank Calabria apologized after the company was warned of the security threat weeks before disclosing it publicly.
Analog Devices announced that an unauthorized party gained access to its systems last month and exfiltrated certain files during the breach. The company stated that its operations remain unaffected despite the security incident.
Healthcare billing company Medical Computer Business Services (MCBS) disclosed a 2025 network breach affecting the sensitive information of 1.26 million people, with the compromise occurring around September 26, 2025. The breach exposed patient data handled by the major medical billing processor.
LACMA has disclosed a # databreach that exposed customer and employee information. The breach may have exposed names, dates of birth, Social Security numbers, ID numbers, financial details, health insurance, and medical information.
DentaQuest disclosed a data breach affecting more than 23 million individuals, exposing personal and dental health information. The breach was reported across multiple news sources on the same date.
This cluster aggregates unrelated security news: DCSync attacks, Operation STANDOFF malware, a Houston City College breach of 831,642 records, FFmpeg vulnerabilities, and PortSwigger's Burp AI tool announcement. No single narrative unifies these disparate incidents.
AfD Has the Wurst Response to Berlin Data Breach https://www.
CenterPoint Energy confirms data breach affecting 7 million customers' PII. Utility discovered incident after dark web post claimed stolen data for sale.
The SEC filing was made yesterday: https://www. htm Security Week: Texas Utility CenterPoint Energy Confirms Breach After Hacker Leaks Data https://www.
Extortion and ransomware group LeakNet claims to have stolen 11TB of data from NYC Health + Hospitals, affecting over 12 million patients; only 1.8 million victims have been officially confirmed so far. The breach involves sensitive healthcare records and represents one of the largest health system breaches reported.
23 Million User Records Compromised in Gyazo Data Breach https://www.
Spain's data protection authority documented the first known data breach involving an AI agent, which used a large language model to access a system, modify personal data, and steal invoices. The report was published on September 15, 2026.
Hackers breached OnTrac's corporate network and accessed customer personal details including names, addresses, and contact information. The parcel delivery company is investigating the incident.
Multiple unrelated cybersecurity threats were reported this week including malware campaigns impersonating Windows apps, hidden iOS tracking data streams, Iranian state-sponsored industrial system interference, and an API vulnerability in the Vatican's mobile app. Additional coverage addressed AI security concerns and emerging shadow AI agent threats.
Hasbro, the toy and entertainment giant behind Monopoly, Transformers, Nerf, Play-Doh, Peppa Pig, D&D, and Magic: The Gathering, disclosed a data breach on August 28, 2026 affecting employee personal and financial information. The company implemented remediation measures following discovery of the incident.
Online mathematics learning platform Mathspace disclosed on 7 September 2026 that unauthorized parties exploited an unpatched Metabase vulnerability to access personal data belonging to 1.08 million students, parents, guardians, and staff across Australia and New Zealand. The breach exposed account information through an internal reporting system.
Cluster contains two unrelated social media posts: one critical comment about Microsoft's official .NET skills documentation, and a link to IBM's 2026 data breach report. No single story.
Healthcare and pharmaceutical distribution giant McKesson on 2026-08-28 disclosed a cybersecurity incident involving unauthorized access and data theft, with the ShinyHunters extortion group claiming on 2026-08-30 to have exfiltrated 284 million healthcare records via vishing attacks on third-party applications. The breach represented one of the largest healthcare data exposures.
Citrix urges admins to patch new NetScaler flaws as soon as possible https://www.
7M Customers Should Do https://www.
Former Oregon State QB reportedly named starter at Northwestern https://www.
Three unrelated Mastodon posts linking to OregonLive articles: data breach settlement compensation, accessibility challenges in Alabama cities, and family estrangement trends.
The ShinyHunters extortion group published sensitive data stolen from 12.9 million Carhartt customer accounts on August 27, 2026, following an attack on August 13. The group claims to have stolen over 50GB of documents; Carhartt had not confirmed the breach as of report date.
Healthcare technology company Veradigm disclosed on September 8–9, 2026, that attackers stolen credentials from a third-party vendor to access its customer service API, exposing patient personal data including Social Security numbers. The Gentlemen ransomware gang claimed responsibility for the attack.
Three cybersecurity stories (Europol targeting teen hackers, AI email tricks, malicious npm packages targeting Alibaba developers) appear alongside unrelated Hackaday maker articles (pinball wall art, video glasses viewfinder, GNOME Shell tiling extension).
A wave of critical security vulnerabilities were disclosed and patched in July 2026: Node.js fixed 11 flaws (server crashes, filesystem bypass), GitLab 13 flaws (data leaks, pipeline tampering), Home Assistant FFmpeg plugin (file theft, root execution), and Cisco Secure Firewall (0-day actively exploited). A Brinks Home data breach was also claimed by ShinyHunters group.
Japanese car-sharing service Times Car confirmed on September 28-29 that approximately 6.6 million user accounts were compromised in a cyberattack. Stolen data includes names, addresses, dates of birth, phone numbers, emails, driver's license images, and identity verification photos, though passwords were hashed and payment card data remained protected.
Resource Center of Dallas Reports Data Breach Affecting 12,490 Individuals The Resource Center of Dallas reported a data breach affecting 12,490 individuals after attackers accessed its network in February 2026.