View Ridge Security
Back to Cyber HoseActive Exploits & Incidents

CareCloud Data Breach Exposes Personal, Financial, and Medical Data

๐Ÿšจ ACTIVE EXPLOITATION

  • CareCloud Data Breach Exposes Personal, Financial, and Medical Data of 350,000+ Hackers stole personal, financial, and medical data from CareCloud's AWS environment.

    • Applies to CareCloud Health division's electronic health record environment
    • Over 350,000 individuals impacted with stolen names, addresses, SSNs, DOBs, IDs, financial and medical info
    • Hackers accessed CareCloud's AWS environment between March 10 and March 16, 2026
    • Data exfiltration confirmed after investigation concluded on June 24, 2026 ๐Ÿ“Ž Coverage: securityweek.com ยท ๐Ÿ‘ via SecurityWeek
  • ExfilSquad hacks UK Department for Education, steals 600,000 records Hackers from ExfilSquad breached the UK Department for Education and stole data.

    • Targets: UK Department for Education and UK Police National Legal Database
    • Data stolen: 600,000 records including names, emails, and phone numbers
    • Attack vector: Breach of two web portals, including the agency's help desk portal
    • Threat actor: ExfilSquad claims responsibility and is attempting extortion
    • Additional claims: ExfilSquad also claims breaches of UK Police database and Microsoft ๐Ÿ“Ž Coverage: news.risky.biz ยท ๐Ÿ‘ via @campuscodi@mastodon.social
  • No detailed public reports on OpenAI-Hugging Face rogue AI incident CVE-2026-59726 and CVE-2026-66803
    No substantive information is available on the OpenAI-Hugging Face rogue AI incident or related CVEs.

    • Applies to OpenAI and Hugging Face AI platforms
    • Vulnerabilities identified as CVE-2026-59726 and CVE-2026-66803
    • No public technical details or attack vectors disclosed
    • No confirmed exploitation or impact reports found ๐Ÿ“Ž Coverage: mastodon.social ยท ๐Ÿ‘ via @campuscodi@mastodon.social

๐Ÿ”“ CVEs & KEV

  • Other: 21 CVEs (worst 9.8)

๐Ÿ•ต๏ธ RESEARCH & DEEP DIVES

  • Astaroth Malware Uses WhatsApp Web to Spread Banking Trojan in Brazil Astaroth malware spreads via victims' WhatsApp Web sessions by sending malicious ZIP files to contacts.

    • Targets Brazilian WhatsApp users by exploiting active WhatsApp Web sessions
    • Sends convincing Portuguese messages with malicious ZIP attachments to contacts
    • Uses WebDriver to automate hidden browser sessions and WPPConnectWA-JS library for messaging
    • Filters contacts to exclude groups, unsaved numbers, and non-Brazilian contacts
    • Evolved from email phishing to automated WhatsApp propagation for faster infection chains ๐Ÿ“Ž Coverage: cybersecuritynews.com ยท ๐Ÿ‘ via Cyber Security News
  • OctLurk and SilkLurk Backdoors Target Central Asian Government Networks Custom backdoors OctLurk and SilkLurk have compromised Central Asian government computers.

    • Targets government networks in Afghanistan, Kazakhstan, Kyrgyzstan, Tajikistan, Uzbekistan, and Syria
    • Backdoors enable keylogging, browser password theft, email exfiltration, and remote command execution
    • OctLurk uses victim-specific loaders and in-memory plugins for stealth and broad control
    • SilkLurk hides behind legitimate Windows programs and injects payloads into memory
    • Attackers use stolen admin credentials, scheduled tasks, malicious services, and PlugX RAT for persistence and lateral movement ๐Ÿ“Ž Coverage: cybersecuritynews.com ยท ๐Ÿ“„ Original: cybersecuritynews.com ยท ๐Ÿ‘ via Cyber Security News
  • Gentlemen Ransomware Kills Nearly 180 Security Processes Before Encryption Gentlemen ransomware disables nearly 180 security processes before encrypting files.

    • Targets businesses using antivirus, endpoint detection, backup agents, and monitoring software
    • Uses kernel-level driver anticheatG13.sys to terminate security-related processes and manipulate system memory
    • Driver supports process termination, network traffic control, command-line rewriting, and driver load inspection
    • Attackers gain deep system access to disable defenses before deploying ransomware encryption ๐Ÿ“Ž Coverage: cybersecuritynews.com ยท ๐Ÿ‘ via Cyber Security News

๐Ÿ“‹ ADVISORIES

  • CISA Warns Water Utilities of Cyberattacks on Internet-Exposed PLCs CISA warns water utilities of rising cyberattacks targeting internet-exposed PLCs.

    • Applies to water and wastewater utilities using programmable logic controllers (PLCs)
    • PLCs controlling water treatment, pumping, chemical dosing, and wastewater management are vulnerable
    • Attackers alter PLC passwords and IP addresses to disrupt operations and lock out operators
    • PLCs exposed via direct internet connections or vendor-installed cellular modems are targeted
    • Rockwell Automation MicroLogix 1400 PLCs specifically mentioned for password recovery guidance ๐Ÿ“Ž Coverage: cybersecuritynews.com ยท ๐Ÿ‘ via Cyber Security News
  • PHP fixes three vulnerabilities causing SQL injection, memory corruption, and crashes PHP patched three high-severity flaws affecting ext-pgsql, ext-bcmath, and ext-phar extensions.

    • Affects PHP optional extensions: ext-pgsql, ext-bcmath, and ext-phar
    • SQL injection via php_pgsql_convert() in PostgreSQL extension with standard_conforming_strings enabled
    • Out-of-bounds memory write in bccomp() due to incorrect buffer handling in BCMath extension
    • Denial-of-service crash from infinite recursion in phar_get_link_source() following circular symbolic links in Phar archives
    • Fixed in PHP versions 8.2.33, 8.3.33, 8.4.24, and 8.5.9 ๐Ÿ“Ž Coverage: cybersecuritynews.com ยท ๐Ÿ‘ via Cyber Security News

Need help assessing your exposure?

Start with the free Posture Self-Check to see where you stand against the current threat landscape.

Free Posture Self-Check