DEV Community

NetSecOpsIO
NetSecOpsIO

Posted on Originally published at cyber.netsecops.io

Daily Cybersecurity Intelligence - September 6, 2026

Daily cybersecurity intelligence digest from CyberNetSec.io - September 6, 2026


📊 8 threat intelligence reports covering vulnerabilities, exploits, threat actors, and security advisories.


1. Trezor Data Breach Exposes 80k Users via ShipMonk

A supply chain attack on Trezor's logistics partner, ShipMonk, has exposed the personal data of approximately 80,689 U.S. customers. The breach stemmed from the exploitation of a critical zero-day vulnerability (CVE-2026-72898) in the Metabase analytics platform used by ShipMonk. The compromised data includes names, addresses, and contact information, placing affected users at high risk of targeted phishing and physical threats. The attack is attributed to the ShinyHunters extortion group.

📖 Read full report →


2. Rhysida Leaks 5.8TB of Berlin Government Data

The Rhysida ransomware group has published 5.8 terabytes of data allegedly stolen from the Berlin state government after officials refused to pay a 30 bitcoin ransom. The massive data dump includes highly sensitive information, such as details on critical infrastructure, the Federal Chancellery, personnel files, and contracts. A crisis task force has been established to analyze the 1.44 million leaked files and assess the security risks, which comes just weeks before a state election.

📖 Read full report →


3. Baylor Genetics Breach Exposes Data of 2.8M

Houston-based Baylor Genetics is notifying 2,810,878 patients and staff of a major data breach. The incident, which occurred in June 2026, involved an unauthorized party gaining access to its IT systems and stealing a vast amount of sensitive personal and medical information. Exposed data includes lab results, Social Security numbers, and financial details, placing millions at risk of identity theft and fraud. The company is offering identity protection services to those affected.

📖 Read full report →


4. Winona County Paid Ransom, Then Attacked Again

Officials in Winona County, Minnesota, confirmed they paid a $128,539 ransom following a ransomware attack in January 2026 to restore services and protect resident data. Despite the payment, the county was targeted by a second, unrelated ransomware attack just three months later in April. The incident highlights the persistent threat ransomware poses to local governments and raises questions about the effectiveness of paying ransoms, as attackers often fail to delete stolen data or provide working decryptors.

📖 Read full report →


5. HumanEdge Staffing Firm Discloses Data Breach

The New York-based staffing and recruitment firm HumanEdge, Inc. has disclosed a data breach that exposed sensitive personal information, including full names and Social Security numbers. The incident, which was first detected in March 2026, was found to have compromised files containing PII of employees, job applicants, and clients. The company began notifying affected individuals in September and is now facing an investigation by a national class-action law firm.

📖 Read full report →


6. See's Candies Hit by Qilin Ransomware Attack

The confectionery company See's Candies, Inc. was the victim of a ransomware attack in April 2026, attributed to the Qilin ransomware group. The attack involved both file encryption and data exfiltration, with stolen files later posted on the dark web. The compromised data, which may include customer and employee PII, has led to multiple class-action law firms launching investigations into the company's data security practices. The four-month delay between the attack and public disclosure is a key point of scrutiny.

📖 Read full report →


7. ASCII Smuggling Phishing Evades Email Filters

Microsoft has detailed a high-volume phishing campaign that sent up to 2.37 million emails on peak days by using an evasion technique called 'ASCII smuggling.' Attackers inserted invisible Unicode characters from the Tags block (U+E0000–U+E007F) into financial keywords like 'funding' and 'loan.' This split the words at a code level, allowing the emails to bypass security filters that rely on exact keyword matching, while the text appeared normal to the human eye. The campaign was linked to a broader SBA loan-themed phishing operation.

📖 Read full report →


8. FBI Warns of MFA-Bypassing OAuth Phishing

The FBI's Internet Crime Complaint Center (IC3) has issued a public service announcement about a sophisticated 'OAuth consent phishing' campaign targeting high-profile individuals since late 2025. Attackers use social engineering to trick victims into granting a malicious application permissions to their cloud accounts (e.g., Google, Microsoft). This provides the attacker with persistent access that bypasses both passwords and multi-factor authentication (MFA), as access is token-based. Changing the account password does not revoke this access.

📖 Read full report →


📌 Subscribe to daily updates at CyberNetSec.io

All reports include detailed analysis, IOCs, mitigation strategies, and references.

Top comments (0)