SpaceX, in partnership with Nvidia, has designed a space-optimized Vera Rubin NVL72 system for launch to orbit in Q4 next year, with significant scale in 2028
🛡️ Nissan Confirms Data Breach Following Oracle PeopleSoft 0-Day Attacks
Source: https://t.co/4ioGNSk0NB
Nissan Americas has officially confirmed a data breach affecting current and former employees across four countries after threat actors exploited a critical zero-day vulnerability in Oracle PeopleSoft software, a campaign attributed to the ShinyHunters extortion group.
The attack stems from CVE-2026-35273, a CVSS 9.8-rated unauthenticated Server-Side Request Forgery (SSRF)-to-Remote Code Execution (RCE) vulnerability residing in the Updates Environment Management (PSEMHUB) component of Oracle PeopleSoft PeopleTools versions 8.61 and 8.62.
#cybersecuritynews #databreach
🚨 Cybersecurity firm Trellix confirms a breach.
Attackers accessed part of its source code repository; no exploitation or release impact found. Investigation ongoing with forensic experts and law enforcement.
Details ➜ https://t.co/CZZUWCGbNG
🚨 Two US cybersecurity professionals have been sentenced for moonlighting as ALPHV BlackCat ransomware affiliates.
Ryan Goldberg, 40, of Georgia, and Kevin Martin, 36, of Texas, deployed BlackCat ransomware against multiple US victims between April and December 2023. They paid the operators a 20% cut for access to the platform, hit medical and engineering firms, leaked patient data to pressure payment, and split a $1.2 million Bitcoin ransom three ways with co-conspirator Angelo Martino.
Martino had a second job. He worked as a ransomware negotiator for victims, and used that role to leak confidential victim information to the attackers to push ransom prices up.
When Goldberg tried to flee abroad, the FBI tracked him through 10 countries before he was caught.
Both men were sentenced yesterday. Martino is sentenced July 9.
Better understand agentic AI systems and mitigate the cybersecurity risks using a new guide we authored with @ASDGovAu and others. View the joint report. #Cybersecurity#AgenticAI
https://t.co/3nOvJwMYdS
NEW: A Cursor AI coding agent deleted a startup's entire production database in 9 seconds. The agent, powered by Claude, was working on a staging task, found a broadly scoped API token, and executed a volume delete without confirmation. It later confessed in detail, admitting it guessed and violated safety rules.
PocketOS, which powers car rental businesses, lost months of bookings data.
In short, the AI agent rouge.
🚨‼️ BREAKING: The Crunchyroll breach data, leaked via an Indian outsourcing partner, has been sold.
1.2 million of 2 million customer records were purchased by a single buyer.
We've obtained the 1.2 million emails from Mr. Raccoon and will be sharing them with HaveIBeenPwned.
🚨‼️ BREAKING: Adobe has been breached by threat actor Mr. Raccoon, leaking 13 million support tickets with personal data, 15,000 employee records, all HackerOne submissions, internal documents and more.
Mr. Raccoon gained access through an Indian BPO, first deploying a remote access tool on an employee, then phishing their manager.
Mr. Raccoon told us: "They allowed you to export all tickets in one request from an agent."
🚨 PayPal Data Breach Exposes SSNs & Business PII of Customers for Over Six Months
Source: https://t.co/Wbw7okmMab
PayPal has issued a formal data breach notification disclosing that a coding error in its PayPal Working Capital (PPWC) loan application exposed the personally identifiable information (PII) of an undisclosed number of customers for approximately six months, from July 1, 2025, to December 13, 2025.
The company detected the unauthorized exposure on December 12, 2025, and formally notified affected customers via written disclosure dated February 10, 2026, from its San Jose, California headquarters.
The breach resulted not from an external intrusion campaign but from an internal software defect, a code change within the PPWC loan application interface that inadvertently permitted unauthorized third parties to access customer PII.
#cybersecuritynews #databreach
For over 20 years, criminals operated proxy services known as 5Socks and Anyproxy that were built entirely on hacked end-of-life home and business routers. The operators made $46 million selling access to anyone who wanted to hide their identity online, and the router owners never knew their devices had been compromised. In 2025, the #FBI and international partners dismantled the botnet and indicted four foreign nationals.
If your router no longer receives security updates, it is not just outdated – it may already be working for someone else. Old technology is not just inefficient, it is dangerous, and attackers actively scan for and exploit outdated, unpatched systems. Learn more about protecting yourself at https://t.co/eo0d5soexR.
Our 2025 Year in Review is live! See how CISA protected communities, fostered innovation, and defended federal networks. 30,000+ incidents triaged, 2+ million priority calls connected, & 1.71B connections blocked. Read more: https://t.co/kgnlLzgyrc