Daily cybersecurity intelligence digest from CyberNetSec.io - September 6, 2026
📊 8 threat intelligence reports covering vulnerabilities, exploits, threat actors, and security advisories.
1. Trezor Data Breach Exposes 80k Users via ShipMonk
A supply chain attack on Trezor's logistics partner, ShipMonk, has exposed the personal data of approximately 80,689 U.S. customers. The breach stemmed from the exploitation of a critical zero-day vulnerability (CVE-2026-72898) in the Metabase analytics platform used by ShipMonk. The compromised data includes names, addresses, and contact information, placing affected users at high risk of targeted phishing and physical threats. The attack is attributed to the ShinyHunters extortion group.
2. Rhysida Leaks 5.8TB of Berlin Government Data
The Rhysida ransomware group has published 5.8 terabytes of data allegedly stolen from the Berlin state government after officials refused to pay a 30 bitcoin ransom. The massive data dump includes highly sensitive information, such as details on critical infrastructure, the Federal Chancellery, personnel files, and contracts. A crisis task force has been established to analyze the 1.44 million leaked files and assess the security risks, which comes just weeks before a state election.
3. Baylor Genetics Breach Exposes Data of 2.8M
Houston-based Baylor Genetics is notifying 2,810,878 patients and staff of a major data breach. The incident, which occurred in June 2026, involved an unauthorized party gaining access to its IT systems and stealing a vast amount of sensitive personal and medical information. Exposed data includes lab results, Social Security numbers, and financial details, placing millions at risk of identity theft and fraud. The company is offering identity protection services to those affected.
4. Winona County Paid Ransom, Then Attacked Again
Officials in Winona County, Minnesota, confirmed they paid a $128,539 ransom following a ransomware attack in January 2026 to restore services and protect resident data. Despite the payment, the county was targeted by a second, unrelated ransomware attack just three months later in April. The incident highlights the persistent threat ransomware poses to local governments and raises questions about the effectiveness of paying ransoms, as attackers often fail to delete stolen data or provide working decryptors.
5. HumanEdge Staffing Firm Discloses Data Breach
The New York-based staffing and recruitment firm HumanEdge, Inc. has disclosed a data breach that exposed sensitive personal information, including full names and Social Security numbers. The incident, which was first detected in March 2026, was found to have compromised files containing PII of employees, job applicants, and clients. The company began notifying affected individuals in September and is now facing an investigation by a national class-action law firm.
6. See's Candies Hit by Qilin Ransomware Attack
The confectionery company See's Candies, Inc. was the victim of a ransomware attack in April 2026, attributed to the Qilin ransomware group. The attack involved both file encryption and data exfiltration, with stolen files later posted on the dark web. The compromised data, which may include customer and employee PII, has led to multiple class-action law firms launching investigations into the company's data security practices. The four-month delay between the attack and public disclosure is a key point of scrutiny.
7. ASCII Smuggling Phishing Evades Email Filters
Microsoft has detailed a high-volume phishing campaign that sent up to 2.37 million emails on peak days by using an evasion technique called 'ASCII smuggling.' Attackers inserted invisible Unicode characters from the Tags block (U+E0000–U+E007F) into financial keywords like 'funding' and 'loan.' This split the words at a code level, allowing the emails to bypass security filters that rely on exact keyword matching, while the text appeared normal to the human eye. The campaign was linked to a broader SBA loan-themed phishing operation.
8. FBI Warns of MFA-Bypassing OAuth Phishing
The FBI's Internet Crime Complaint Center (IC3) has issued a public service announcement about a sophisticated 'OAuth consent phishing' campaign targeting high-profile individuals since late 2025. Attackers use social engineering to trick victims into granting a malicious application permissions to their cloud accounts (e.g., Google, Microsoft). This provides the attacker with persistent access that bypasses both passwords and multi-factor authentication (MFA), as access is token-based. Changing the account password does not revoke this access.
📌 Subscribe to daily updates at CyberNetSec.io
All reports include detailed analysis, IOCs, mitigation strategies, and references.
Top comments (0)