View Ridge Security
Back to Cyber HoseActive Exploits & Incidents

Canadian hacker pleads guilty to theft from 165 Snowflake customers

๐Ÿ’ฅ BREACHES & INCIDENTS

  • Canadian hacker pleads guilty to theft from 165 Snowflake customers Connor Moucka pleaded guilty to stealing data from at least 165 Snowflake customers.
    • Snowflake customers including AT&T, Ticketmaster, Santander, and Advance Auto Parts were affected.
    • More than 100 million people had data exposed, including financial, payroll, identity, and call-history records.
    • Moucka and co-conspirators accessed Snowflake accounts without MFA using credentials stolen by infostealer malware.
    • Custom software helped identify valuable data before terabytes were stolen for extortion and sale online. ๐Ÿ“Ž Coverage: bleepingcomputer.com ยท ๐Ÿ‘ via BleepingComputer, CyberScoop

๐Ÿ•ต๏ธ RESEARCH & DEEP DIVES

  • AI Helps Global Crime Syndicates Scale Fraud Global crime syndicates are scaling fraud with AI-generated voices, video, and personas.
    • Global organized-crime syndicates are conducting AI-enabled fraud campaigns.
    • Voice cloning and real-time deepfake video overlays make scams more convincing.
    • LLM-driven persona management and automated translation help syndicates operate at scale. ๐Ÿ“Ž Coverage: darkreading.com ยท ๐Ÿ‘ via Dark Reading

๐Ÿ”“ CVEs & KEV

  • CVE-2026-17556 โ€” CVSS 8.8 โ€” Path traversal in GitHub Enterprise Server allowed unauthenticated deletion o...
  • CVE-2026-71309 โ€” CVSS 8.6 โ€” rclone: Incomplete path validation allows backend root escape in serve restic...
  • CVE-2026-70617 โ€” CVSS 8.6 โ€” Spacebar Server Missing Authorization via Group DM Recipient EndpointSpacebar...
  • CVE-2026-66298 โ€” CVSS 8.6 โ€” JS-view sandboxed output can synthesize keyboard events to trigger unconfirme...
  • CVE-2026-34966 โ€” CVSS 8.3 โ€” Gitea prior to 1.27.0 SSRF via Migration URI Fetch BypassGitea prior to 1.27....
  • CVE-2026-71312 โ€” CVSS 8.0 โ€” rclone: PowerShell Smart-Quote Filename Injection Enables SFTP Server-Side Co...
  • CVE-2026-55524 โ€” CVSS 7.5 โ€” PraisonAI: SSRF in web_crawl tool via redirect-following and DNS rebinding (v...
  • CVE-2026-18411 โ€” CVSS 7.2 โ€” Use of hard-coded cryptographic key in Acrisure KARR BT and DR-100The KARR Se...
  • CVE-2026-66881 โ€” CVSS 7.0 โ€” Path traversal in imported file_entries name allows arbitrary file write via ...
  • CVE-2026-66885 โ€” CVSS 6.8 โ€” Livebook Teams identity callback lacks state binding, allowing login CSRFCros...
  • CVE-2026-15996 โ€” CVSS 6.6 โ€” Denial of service vulnerability in GitHub Enterprise Server allowed unauthent...
  • CVE-2026-71311 โ€” CVSS 6.4 โ€” rclone: FTP Command Arguments Permit CRLF Injection When Custom Encoding Pres...

Need help assessing your exposure?

Start with the free Posture Self-Check to see where you stand against the current threat landscape.

Free Posture Self-Check