Police dismantle KillSec ransomware operation, arrest suspected 16-year-old leader
A Eurojust-coordinated operation led to three arrests, eight searches and the seizure of KillSec's leak site, five servers and 110 TB of stolen data.
A Eurojust-coordinated operation led to three arrests, eight searches and the seizure of KillSec's leak site, five servers and 110 TB of stolen data.
KVKK says an unauthorized party used automated requests against unauthenticated URLs to download application documents, including passport details and criminal records, of 7,591 people.
KVKK says unauthorized access to a server in a data processor's systems exposed contact details, login credentials and order data of about 133,031 Deve Yükü customers and members.
KVKK says an unauthorized party used unlawfully obtained credentials to access office supplies retailer Ofix's Elasticsearch service, exposing names and emails of 183,873 customers.
KVKK says unauthorized access to a data processor's server exposed names, phone numbers, emails and MD5-hashed login credentials of about 323,052 Bambi customers.
Turkey's data protection authority KVKK says a security incident at the e-commerce provider of Efece Ayakkabıcılık exposed names, contact details and hashed passwords of 353,811 people.
Attackers took over Microsoft's @Microsoft account on X, which has more than 13 million followers, and used it to push a fake Clippy-branded cryptocurrency token.
Symantec says the China-nexus group behind Warlock breached a water utility, a telecom provider, a regional government body and a university through SharePoint flaws.
Fortinet disclosed an actively exploited FortiMail flaw rated 9.8 that lets unauthenticated attackers write arbitrary files; CISA added it to KEV with an October 4 deadline.
The Defense Manpower Data Center says attackers abused a file-sharing system flaw to access records, including Social Security numbers, of roughly 3 million people between October 2025 and July 2026.
Cisco warned that attackers are exploiting a critical authentication bypass in Catalyst SD-WAN Manager that grants admin access; CISA ordered federal agencies to patch by 3 October.
Turkey's data protection authority KVKK published a breach notice for brokerage Papara Menkul Değerler, whose customer data was accessed after a data processor's Okta SSO platform was compromised.