New Orleans Sheriff’s Office Ransomware Attack

In September 2025, the Orleans Parish Sheriff’s Office in New Orleans fell victim to a ransomware attack. The hackers, known as the Qilin group, claimed responsibility and leaked more than 842 gigabytes of stolen data online. What Happened The attack disrupted several city services, including the online court docket system, which went offline for multiple […]

Read More

Uvalde CISD Ransomware Attack

On September 15, 2025, the Uvalde Consolidated Independent School District (CISD) in Texas was forced to cancel classes due to a ransomware attack. The attack disrupted multiple systems, raising concerns about security and safety across the district. What Happened The ransomware locked key infrastructure used daily by schools, including: Internal phone systems Security cameras Air […]

Read More

Jaguar Land Rover Cyber attack Halts UK Production (September 4, 2025)

Summary On September 4, 2025, Jaguar Land Rover (JLR) confirmed that a hacker known as “Rey” linked to the group Hellcat has claimed responsibility for a second cyberattack this year. The incident has halted vehicle production at key UK facilities like Solihull and Halewood, delayed thousands of deliveries, and raised serious concerns about vendor and […]

Read More

Massive TransUnion Breach Exposes Social Security Numbers of 4.4 Million Americans (September 5, 2025)

Summary A significant data breach at TransUnion, one of the three major U.S. credit reporting agencies, has compromised the personal information of approximately 4.4 million Americans, including Social Security numbers. Over 377,000 Texans were among those affected. The breach stemmed from a third-party application vulnerability, prompting TransUnion to offer two years of free credit monitoring […]

Read More

Salesloft Drift Supply-Chain Breach: How OAuth Tokens Let Hackers Into Salesforce (September 4, 2025)

Summary In August 2025, attackers stole OAuth tokens from Salesloft’s Drift chatbot integration and used them to access Salesforce data at hundreds of organizations. High-profile victims that disclosed impact include Zscaler, Palo Alto Networks, and Cloudflare. Exposed data varies by company, but often includes business contact info and support case details. The total blast radius […]

Read More

“Salt Typhoon”: Massive Cyber Operation Hits U.S., Targets Critical Infrastructure (September 5, 2025)

Summary On September 5, 2025, U.S. authorities revealed a massive cyber campaign dubbed “Salt Typhoon”, in which suspected Chinese hackers may have accessed sensitive American data and infiltrated power grid infrastructure. The FBI and DOJ are now spearheading a high-stakes response. The incident raises national security concerns, infrastructure risk, and potential implications for the average […]

Read More

Microsoft SharePoint Zero-Day Exploited in Widespread Hack Campaign

Incident window: July 19–21, 2025 Public alert issued: Late July 2025 What happened In one of the most significant enterprise security incidents in recent memory, a zero-day vulnerability in on-premises Microsoft SharePoint servers was actively exploited in a widespread cyber campaign. Between July 19 and July 21, over 8,000 servers globally were reportedly compromised by […]

Read More

Allianz Life Data Breach Exposes Info of Over 1.1 Million Customers

Incident date: July 16, 2025 Public notification: Mid‑August 2025 What happened Allianz Life Insurance Company of North America recently disclosed a major security breach originating from a third-party customer relationship management (CRM) vendor. On July 16, 2025, the CRM platform was compromised through a targeted social engineering attack. This breach exposed personal details belonging to […]

Read More

Surge in CEO Deepfake Scams—Artificially Created Voices and Faces Fuel Corporate Fraud

Timeline: Reported continuously from July 18 to July 31, 2025 What happened In the past two weeks, deepfake scams targeting corporate environments have surged dramatically. These attacks involve perpetrators creating highly realistic AI-generated video or audio impersonations of CEOs or senior executives. In several reported cases, employees in finance or HR were convinced to transfer […]

Read More

Cybersecurity Incident Report: Ransomware Attack Exploits Windows Zero-Day Vulnerability

Introduction On April 14, 2025, a significant cybersecurity incident involving a Windows zero-day vulnerability was disclosed, highlighting the persistent threat of ransomware attacks. This report examines the details of this incident, which exploited a flaw in the Windows Common Log File System (CLFS), enabling attackers to deploy ransomware and steal sensitive data. As cybersecurity threats […]

Read More