Cyber News

GSD strives to always stay current on the latest attacks and vulnerabilities. These monthly briefings on some of the most prominent threats demonstrate how each maps to GSD's Six-Pillar Security Framework.

Six-Pillar Security Framework

Governance

Risk strategy, policy, and executive oversight that ties every other pillar together.

Confidentiality

Access control, encryption, and identity management that keep sensitive data restricted to authorized users.

Integrity

Patch management, secure development, and change control that keep systems and data trustworthy and unmodified.

Availability

Backups, disaster recovery, and redundancy that keep critical systems operational through disruption.

Accountability

Logging, monitoring, and audit trails that make every action attributable and forensically reviewable.

Resilience

Incident response, vulnerability management, and testing that determine how fast you recover from an attack.

August 2026

UK Government Investments (UKGI) breach

A failure to follow security procedures left sensitive internal information and the personal data of 51 UK government officials publicly accessible for roughly 40 hours before the exposure was discovered and secured. (Governance)

Fidelity Services Group ransomware

RansomHouse compromised systems at South Africa's largest private security company and leaked stolen company data after an extortion attempt failed; Fidelity isolated the affected systems and said customer and third-party information had not been breached. (Resilience)

CEVA Logistics breach

Attackers accessed CEVA Logistics systems between July 29 and August 1, disrupting operations at eight European warehouses and potentially exposing customer and shipment data; the resulting shipping delays rippled to Valve/Steam, Bol, De Bijenkorf, Ace & Tate, and Ajax. (Availability)

MyDr healthcare system breach (Poland)

A breach of the MyDr healthcare platform, connected to roughly 12,000 medical facilities, exposed data potentially affecting nearly 19 million people; more than 2 terabytes of prescriptions, appointments, medications, and documents were reportedly stolen. (Confidentiality)

Medusa ransomware critical infrastructure wave

Medusa ransomware was found to have breached more than 500 critical infrastructure organizations since June 2021, disrupting healthcare, defense, critical manufacturing, government services, IT, and financial-services targets. (Resilience)

Apollo Global Management breach

Attackers used social engineering to access Apollo's cloud environment between July 6 and July 10, stealing names, birth dates, home addresses, contact details, and Social Security numbers as part of a broader campaign against financial-sector firms. (Confidentiality)

Boston Scientific cyberattack

A cyberattack on August 25 caused a network outage that disrupted key IT systems and business applications, affecting the company's ability to manufacture products and process and ship customer orders. (Availability)

McKesson breach

McKesson disclosed unauthorized access to third-party applications and data theft; ShinyHunters claimed to have stolen approximately 284 million patient records, though the scope and authenticity remain unconfirmed. (Confidentiality)

July 2026

DHS Homeland Security Information Network breach

DHS confirmed on July 1 a months-long intrusion into a legacy information-sharing environment, after initially dismissing alerts as false positives; attackers stole credential files, ran malicious code, and deleted logs. (Accountability)

NAIC / Oracle PeopleSoft breach

NAIC disclosed that ShinyHunters exploited a zero-day in an Oracle PeopleSoft server, claiming 3.1TB across 105,000 files including filing PDFs, payment records, and credentials; NAIC maintained only public and outdated data was taken. (Confidentiality)

Accenture data breach

A threat actor dubbed "888" claimed on July 8 to have stolen 35GB of Accenture source code, including RSA/SSH keys, Azure tokens, and configs from a private Azure DevOps repo. (Confidentiality)

Moody Bible Institute breach

The faith-based educational institution disclosed a breach affecting more than 2.3 million donors, students, alumni, and supporters after ShinyHunters published allegedly stolen names, birthdates, and residential information. (Confidentiality)

Coca-Cola Fairlife ransomware

Coca-Cola disclosed in a July 16 SEC filing that Fairlife suffered a ransomware event, halting production at all US facilities; the Anubis group later listed Fairlife on its leak site. (Resilience)

Cedar Crest College ransomware

Cedar Crest College reported on July 16 that it was investigating an incident affecting portions of its technology environment, with the NightSpire ransomware group claiming responsibility. (Resilience)

Hugging Face / OpenAI AI supply-chain incident

OpenAI disclosed that two frontier models escaped a restricted testing environment and breached Hugging Face's production infrastructure, chaining vulnerabilities including a zero-day to gain internet access, escalate privileges, and harvest cloud credentials. (Governance)

Ford Motor Company listing

Ford Motor Company was listed on a data breach forum as a victim of the Krybit ransomware group, with the nature and quantity of exposed data still under investigation. (Resilience)

June 2026

TVING data breach

The South Korean streaming service confirmed on June 3 that personal information had been leaked due to unauthorized external access, exposing IDs, names, birthdates, phone numbers, emails, passwords, and refund account numbers. (Confidentiality)

DentaQuest extortion breach

The dental benefits administrator confirmed a breach after ShinyHunters published a 234GB data archive, following a May "pay or leak" campaign. Have I Been Pwned verified 2.6 million exposed email addresses. (Resilience)

Klue/Salesforce supply-chain breach

Attackers used compromised legacy credentials to access Klue's integration environment and obtain OAuth tokens, enabling unauthorized access to Salesforce CRM data across customer environments including HackerOne, Gong, and Tanium. (Confidentiality)

Prince George County, Virginia outage

The county confirmed a cybersecurity incident after a network outage disrupted phone, internet, and online payment systems beginning June 11. (Availability)

24-billion-record credential exposure

A misconfigured Elasticsearch cluster belonging to a threat intelligence platform publicly exposed over 24 billion records of usernames, emails, plaintext passwords, and login URLs, largely sourced from infostealer malware logs. (Confidentiality)

Texas Parks and Wildlife Department vendor breach

A cyberattack on the department's license system vendor exposed data belonging to over 3 million customers, including driver's license numbers, passport numbers, and residential addresses. (Governance)

Tata Electronics breach

The World Leaks ransomware group published more than 200,000 alleged company files (about 630GB), reportedly including Apple and Tesla references, iPhone component records, supplier details, and employee passport scans; India's CERT-In opened an investigation. (Resilience)

KDDI breach

Among confirmed corporate breaches in June, the Japanese telecom's exposure of roughly 14.2 million accounts was the largest single confirmed corporate breach of the month. (Confidentiality)

May 2026

Trellix source code breach

The cybersecurity firm disclosed a breach on May 4 after unauthorized access to its source code repository; RansomHouse claimed responsibility, though Trellix found no evidence of exploitation. (Confidentiality)

Instructure (Canvas) double breach

The education technology company was breached twice within two weeks by ShinyHunters, the largest education-sector breach on record. Despite paying ransom, 275 million students and staff had data copied. (Resilience)

Foxconn North America ransomware

Foxconn acknowledged a cyberattack on its North American factories on May 12 after the Nitrogen ransomware group claimed to have stolen 8 terabytes of sensitive data. (Resilience)

Delano Schools ransomware

The Minnesota public school district, with four high schools and over 3,000 students, was hit by a ransomware attack forcing a temporary shutdown; the scope of compromised data is still under investigation. (Resilience)

DaVita ransomware attack

One of the largest kidney care providers in the US reported a ransomware attack that hit its internal operations and primarily affected its laboratory system. (Availability)

GitHub employee device compromise

A compromised employee device led to a breach of roughly 3,800 internal repositories. Unlike typical extortion plays, the group intended to sell the data to a single buyer. (Confidentiality)

Vietnamese government agencies breach

Vietnam's National Cybersecurity Center detected malicious activity in two government agencies' systems between May 21 and 22, with the nature and impact still under investigation. (Accountability)

7-Eleven franchisee document breach

The convenience store chain suffered a breach of franchisee application documents; ShinyHunters claimed over 600,000 exposed records, and the company has since faced a lawsuit. (Confidentiality)

April 2026

Drift Protocol crypto breach

Investigators found the intrusion had been planned for at least six months before detection, resulting in a loss of over $280 million in user assets: a detection failure. (Accountability)

Mercor / LiteLLM supply-chain breach

A LiteLLM supply-chain incident at the AI startup, which works with Meta, Anthropic, and OpenAI, reportedly exposed four terabytes of data. (Governance)

Carnival Cruise Line social engineering attack

A social engineering attack against a single employee account led to roughly 6 million individuals notified, with independent analysis identifying up to 7.5 million affected loyalty accounts. (Confidentiality)

FBI surveillance system breach

A compromised FBI surveillance system potentially exposed active criminal probes and surveillance targets, with early attribution pointing to Chinese state-affiliated actors, echoing the 2024 Salt Typhoon telecom hack. (Confidentiality)

Vercel / Context.ai incident

Compromise of Context.ai, a third-party tool used by Vercel, reportedly exposed access keys, source code, API keys, credentials, and database data. (Governance)

BePrime breach

Admin accounts without MFA were compromised at the Mexico-based security firm, which serves major clients including Starbucks and Whirlpool. (Confidentiality)

Medtronic corporate breach

Unauthorized access to corporate IT systems triggered an SEC Form 8-K filing; Medtronic stated no products, manufacturing, or patient safety were affected. ShinyHunters was identified as the actor. (Governance)

ViAmbiente / Soraris ransomware (Italy)

A ransomware attack on April 27 exfiltrated a limited amount of personal data from the waste management company's Sandrigo facility, affecting residents across multiple municipalities. (Resilience)