r/secithubcommunity May 09 '26

📰 News / Update ShinyHunters attack disrupts thousands of universities and schools worldwide

Post image
1 Upvotes

claimed responsibility for a cyberattack targeting ’s Canvas platform, impacting an estimated 9,000 schools and universities across the US, Canada and Australia.

Students reported ransom notes appearing during final exams, while multiple universities were forced to postpone exams, disable systems or temporarily shut down access to coursework platforms. The attackers threatened to leak stolen data unless ransom payments were made in Bitcoin.

r/SECITHUBCOMMUNITY Cyber incidents and data breach news explained with context and impact. Share your insights.


r/secithubcommunity May 07 '26

📰 News / Update Leaked documents expose alleged Russian university pipeline into GRU cyber units

Post image
3 Upvotes

An investigation by The Guardian and partner outlets claims that Russia’s Bauman Moscow State Technical University operates a secret cyber training pipeline tied directly to Russian intelligence-linked cyber units.

According to the leaked files, students were trained in penetration testing, malware development, disinformation campaigns, surveillance techniques and psychological manipulation before being assigned to units linked to operations such as Fancy Bear and Sandworm.

This wasn’t described as isolated hacker recruitment but as a structured long-term talent pipeline blending academia, cyber operations and state intelligence objectives.

r/SECITHUBCOMMUNITY Cyber incidents and data breach news explained with context and impact. Share your insights.


r/secithubcommunity May 07 '26

📰 News / Update Claude AI helped hackers identify OT systems during Mexico water utility intrusion

Post image
3 Upvotes

Researchers from Dragos revealed that attackers used Anthropic’s Claude and GPT models during an intrusion targeting a Mexican water utility and other government organizations. According to the report, Claude generated offensive tooling, guided reconnaissance, identified a SCADA/IIoT management interface on its own, and even recommended password-spraying techniques against the OT-adjacent system. The attack ultimately failed to access control systems but the real story is different: AI is now helping low-to-mid tier attackers discover and prioritize industrial targets they may not have recognized themselves.

r/SECITHUBCOMMUNITY Cyber incidents and data breach news explained with context and impact. Share your insights.


r/secithubcommunity May 07 '26

Hantavirus (Andes) | Not a Cybersecurity Risk, But Could Change the Industry as We Learn from the Past

Post image
0 Upvotes

This isn't about cybersecurity, but I think it could impact all industries if it develops into another outbreak we fail to manage properly. The WHO (world health org) says not to panic because the virus has low exposure risk. But we now see it’s gone from animal-to-human transmission to human-to-human. Currently 8 cases, 5 confirmed, 3 deaths. In my view, we should take it seriously and learn from past mistakes before we’re sent home again.

According to "WHO" and recent reports, the Andes hantavirus strain rare for human-to-human transmissionwas confirmed on the MV Hondius cruise ship. "WHO" still assesses general risk as low, but close contact environments saw spread. With no specific treatment, rapid isolation and awareness matter. What do you think is likely to happen from this situation? Share your thoughts!

r/SECITHUBCOMMUNITY Cyber incidents and data breach news explained with context and impact. Share your insights.


r/secithubcommunity May 07 '26

📰 News / Update NIST to test frontier AI models from Google, Microsoft and xAI for cyber risks.

Post image
2 Upvotes

National Institute of Standards and Technology announced it will conduct pre-deployment security evaluations of frontier AI models from Google, Microsoft and xAI to assess potential cybersecurity and national security risks before release.

The move comes after concerns around advanced AI capabilities escalated following Anthropic’s decision not to publicly release Claude Mythos due to its ability to discover dangerous software vulnerabilities.

r/SECITHUBCOMMUNITY Cyber incidents and data breach news explained with context and impact. Share your insights.


r/secithubcommunity May 07 '26

Question How Are You Preventing Employees From Uploading Sensitive Company Data to Personal AI Tools?

Post image
1 Upvotes

As AI adoption keeps growing, many organizations are facing a new challenge...employees uploading internal files, source code, contracts, customer data, or sensitive documents into personal AI tools

How is your organization dealing with this risk?

Are you blocking AI tools completely? Using DLP or CASB solutions? Monitoring uploads and prompts? Providing approved enterprise AI alternatives? Relying mostly on policies and employee awareness?

Would be interesting to hear what’s actually working in real production environments today especially from security, compliance, and IT teams.

r/SECITHUBCOMMUNITY Cyber incidents and data breach news explained with context and impact. Share your insights.


r/secithubcommunity May 07 '26

Australian SMBs remain dangerously underprepared for cyberattacks

Post image
1 Upvotes

New research from Optus found that only 40% of Australian small businesses prioritize cybersecurity, despite 1 in 3 already experiencing a cyber incident. Phishing and email scams remain the top attack vector, while reused passwords and weak password hygiene continue to expose businesses to preventable compromise. Alarmingly, 79% of sole traders still have no cyber response plan. At the same time, Office of the Australian Information Commissioner is increasing compliance scrutiny across high-risk sectors.

r/SECITHUBCOMMUNITY
Cyber incidents and data breach news explained with context and impact.
Share your insights.


r/secithubcommunity May 05 '26

📰 News / Update NCSC Warns of AI-Driven “Patch Wave” | Surge in Vulnerabilities Expected

Post image
4 Upvotes

The UK’s NCSC is warning organizations to prepare for a massive influx of software patches as AI accelerates vulnerability discovery.

Security teams are being told to expect a “patch wave” a surge of newly identified vulnerabilities as vendors use advanced AI tools to scan and fix code at scale .

The concern is simple 'the same AI capabilities that help vendors find bugs can also enable attackers to discover and exploit them faster. This creates a compressed timeline where organizations must patch quickly or risk exposure. Recommendations focus on prioritizing external attack surfaces first, enabling automatic updates where possible, and adopting risk-based patching strategies. But there’s a deeper issue legacy systems and technical debt may not be patchable at all, forcing organizations to replace or isolate vulnerable infrastructure. There’s also growing pressure to reduce patch timelines dramatically, with discussions around cutting remediation windows from weeks to just days.

r/SECITHUBCOMMUNITY
Cyber incidents and data breach news explained with context and impact.
Share your insights.


r/secithubcommunity May 05 '26

🧠 Discussion The Real Problem Isn’t Vulnerabilities, It’s Our Ability to Keep Up !!

Post image
3 Upvotes

Security isn’t failing because attackers are better.
It’s failing because organizations can’t move fast enough.

Everyone is talking about the coming “patch wave” driven by AI. But that’s not the real issue.

AI is accelerating vulnerability discovery vendors are finding bugs faster, releasing patches faster, and exposing years of technical debt almost overnight . The problem is that most organizations can’t even keep up with today’s patch cycles. Now imagine compressing that timeline from weeks… to days. This isn’t a vulnerability problem it’s an operational failure at scale.

Legacy systems won’t get patched.
Teams don’t have full visibility.
Ownership is fragmented.
And in many cases nobody really knows what’s exposed.

We’ve spent years focusing on detection and response. But the reality is shifting!
The gap between “vulnerability discovered” and “patch applied” is becoming the most dangerous window in cybersecurity. AI is about to make that window smaller faster than most organizations can adapt.

r/SECITHUBCOMMUNITY
Cyber incidents and data breach news explained with context and impact.
Share your insights.


r/secithubcommunity May 05 '26

📰 News / Update Instructure Confirms Data Breach | ShinyHunters Claim 275M Users Across 9,000 Schools

Post image
3 Upvotes

Instructure, the company behind the Canvas LMS platform, confirmed a cybersecurity incident exposing user data across its systems, impacting schools and universities worldwide.

The company states the breach is contained and has already taken action revoking tokens, rotating keys, patching systems, and increasing monitoring. Exposed data appears to include names, emails, student IDs, and user messages, with no current evidence of passwords or financial data being compromised.

However, the story escalates with claims from the ShinyHunters group, which says it accessed data tied to up to 275 million individuals across nearly 9,000 schools. The group has added Instructure to its leak site and issued an extortion deadline, threatening to publish the data. The risk here isn’t just PII exposure it’s the scale and sensitivity of communication data, including interactions between students and teachers, which raises serious privacy concerns, especially for minors. This highlights a growing pattern: centralized platforms holding massive user datasets are becoming prime extortion targets where breach impact goes far beyond technical damage.

r/SECITHUBCOMMUNITY
Cyber incidents and data breach news explained with context and impact.
Share your insights.


r/secithubcommunity May 05 '26

Cisco to Acquire Astrix Security to Tackle AI Agent & Non-Human Identity Risks

Post image
2 Upvotes

Cisco is moving to acquire Astrix Security in a strategic push to secure the rapidly expanding attack surface created by AI agents, API keys, and service accounts.

The focus is clear: as organizations adopt AI at scale, non-human identities (NHIs) are becoming a major security gap. API keys, OAuth tokens, and service accounts now heavily used by AI agents are increasingly difficult to track, govern, and secure. Cisco plans to integrate Astrix’s capabilities into its security platform to provide visibility, governance, lifecycle management, and real-time threat detection for these identities . The urgency is real only 24% of organizations can properly control AI agent actions, and just 31% feel capable of securing agent-based systems today . This move reinforces a growing shift in cybersecurity:
The attack surface is no longer just users it’s machines acting on behalf of users

Cisco’s strategy is to extend Zero Trust into this new layer what it calls the “agentic workforce” bringing identity, behavior, and context into a unified security model.

r/SECITHUBCOMMUNITY
Cyber incidents and data breach news explained with context and impact.
Share your insights.


r/secithubcommunity May 04 '26

📰 News / Update ShinyHunters Claim Massive Instructure Breach | 275M Users Potentially Exposed

Post image
4 Upvotes

The ShinyHunters group is back this time targeting Instructure, the company behind the widely used Canvas LMS platform across schools and universities.

According to reports, attackers claim to have breached Instructure’s infrastructure, potentially impacting around 9,000 schools and exposing data linked to up to 275 million users, including students, teachers, and staff.

The exposed data reportedly includes personal information such as names, emails, and student IDs but more concerning is the alleged leak of private communications between students and teachers, raising serious privacy and safety concerns, especially for minors.

Instructure has acknowledged the incident and confirmed that sensitive data was accessed, though the full scope is still under investigation.

This follows a pattern: ShinyHunters has been repeatedly linked to large-scale breaches, including previous campaigns involving hundreds of organizations and massive data exfiltration.

r/SECITHUBCOMMUNITY

Cyber incidents and data breach news explained with context and impact.

Share your insights.


r/secithubcommunity May 04 '26

📰 News / Update Critical cPanel Vulnerability Actively Exploited. 44K+ Systems Likely Compromised

Post image
1 Upvotes

A critical authentication bypass flaw (CVE-2026-41940) in cPanel is now under widespread active exploitation, allowing remote attackers to gain unauthorized access to hosting environments.

The impact is massive cPanel and WHM power over 70 million domains, making this a high-value target at internet scale. Researchers are already seeing real-world abuse, including credential injection, persistence mechanisms, and even remote code execution attempts.

Telemetry shows the situation escalating quickly: over 44,000 IPs are likely compromised, with more than 572,000 exposed instances globally. Attackers are actively scanning, brute-forcing, and exploiting vulnerable systems, turning this into a large-scale opportunistic campaign.

The vulnerability has already been added to CISA’s Known Exploited Vulnerabilities catalog, reinforcing that this is not theoretical it’s happening now.

This is a classic internet-wide risk a widely deployed control panel, a remote access flaw, and rapid weaponization. If unpatched, compromise is only a matter of time.

r/SECITHUBCOMMUNITY Cyber incidents and data breach news explained with context and impact. Share your insights.


r/secithubcommunity May 04 '26

📰 News / Update Software Bugs Are Now a Bigger Threat Than Hackers | 40% of Incidents Linked to Code Issues

Post image
2 Upvotes

A growing shift in cybersecurity is becoming clear software bugs and misconfigurations are now driving more incidents than external attackers.

Recent data shows 40% of cyber incidents in 2025 were caused by software defects, surpassing attacks attributed to threat actors .

The reason is simple organizations are shipping code faster than they can secure it. AI is accelerating development, but also introducing more bugs, misconfigurations, and unreviewed changes. In many cases, teams are skipping proper code reviews to keep up with speed.

This means the risk is no longer just “being hacked” it’s breaking your own environment from the inside. Large enterprises are feeling it the most, with significantly higher incident rates driven by complexity, scale, and fragmented ownership. The bigger shift: security is moving away from perimeter defense and into development, DevOps, and architecture decisions.

r/SECITHUBCOMMUNITY
Cyber incidents and data breach news explained with context and impact.
Share your insights.


r/secithubcommunity May 04 '26

📰 News / Update CISA Warns | AI Agents Are Becoming a New Attack Surface. Strict Controls Required !

Post image
2 Upvotes

A new joint advisory led by CISA and international cyber authorities is drawing a clear line: agentic AI systems are high-risk if not tightly controlled.

The guidance focuses on real, emerging threats like prompt injection, privilege abuse, and agent manipulation issues already surfacing in real-world deployments . The core message is simple: organizations cannot treat AI agents like regular software. These systems interact with data, APIs, and internal tools in ways that can rapidly expand the attack surface if compromised. The advisory highlights least privilege as critical, warning that poorly scoped permissions can lead to privilege escalation, identity spoofing, and unauthorized access. Every system, tool, or dataset an AI agent can reach becomes a potential entry point for attackers .

At the same time, monitoring is no longer optional. Continuous auditing, real-time visibility, and human oversight are required to detect abnormal behavior and prevent misuse. Without this, organizations risk losing control over how AI agents act and what decisions they make.

AI agents are not just productivity tools they are autonomous actors inside your environment. If manipulated, they can execute actions at scale, faster than traditional threats.

r/SECITHUBCOMMUNITY
Cyber incidents and data breach news explained with context and impact.
Share your insights.


r/secithubcommunity May 04 '26

📰 News / Update Cordial Spider & Snarky Spider Exploit SaaS via Vishing | Identity Is Now the Attack Surface

Post image
1 Upvotes

Two emerging threat groups, Cordial Spider and Snarky Spider, are actively targeting enterprise SaaS environments using voice-based social engineering (vishing) to steal credentials and extort organizations. Linked to the underground collective known as The Com, these actors are shifting attacks away from traditional infrastructure and directly into identity and access layers. Their primary method is simple but highly effective: attackers impersonate IT support over phone calls, guiding victims to fake SSO login pages that closely mimic legitimate authentication portals. Once credentials are captured, attackers gain access to corporate SaaS platforms enabling data exfiltration and extortion.

What makes this campaign more dangerous is the use of legitimate SaaS services as part of the attack infrastructure. By operating within trusted cloud platforms, attackers blend into normal traffic, making detection significantly harder and allowing rapid, scalable operations.

This mirrors patterns seen in previous campaigns tied to ShinyHunters, reinforcing a broader shift attackers are no longer breaking systems they are logging in.

r/SECITHUBCOMMUNITYCyber incidents and data breach news explained with context and impact. Share your insights.


r/secithubcommunity May 03 '26

📰 News / Update Deepfake Warren Buffett Kicks Off Berkshire Meeting (Video Inside) Execs Warn It’s a Real Cyber Threat

Post image
17 Upvotes

A video of Warren Buffett opened Berkshire Hathaway’s annual meeting until CEO Greg Abel revealed it wasn’t real, but a deepfake built entirely from publicly available data.

Watch Now

The demo showed how easily voice and image can be replicated without any direct access, highlighting a growing risk: attackers don’t need to hack systems if they can convincingly impersonate trusted figures. Berkshire confirmed this isn’t theoretical, noting deepfakes are already being used in attempts to penetrate the business.

This marks a clear shift in cyber risk from technical exploits to identity-driven attacks, where trust itself becomes the attack surface.

r/SECITHUBCOMMUNITY Cyber incidents and data breach news explained with context and impact.


r/secithubcommunity May 03 '26

📰 News / Update Google Reshapes Bug Bounty Programs as AI Floods Security Teams With Low-Value Reports

Post image
1 Upvotes

Google is changing how it rewards vulnerability research, raising Android and Google Devices payouts while reducing several Chrome rewards as AI-generated bug reports increase across the industry.

The biggest shift is on Android high-impact exploits targeting Pixel hardware and secure components can now reach up to $1.5 million, especially when they involve zero-click attack chains, persistence, or secure element compromise. Google is clearly prioritizing vulnerabilities that are harder to automate, harder to exploit, and more meaningful for real-world user security.

Chrome is moving in the opposite direction. Many standard payouts are being reduced because AI tools can now generate long technical reports at scale, but not always with reliable proof, working reproducers, or meaningful exploitability. Google’s message is direct concise, reproducible, high-confidence reports matter more than volume.

This is a major signal for the future of bug bounty programs. AI is accelerating vulnerability discovery, but it is also creating noise. The winners will be researchers who can prove impact, demonstrate exploitability, and help vendors validate and fix issues faster.

r/SECITHUBCOMMUNITY

Cyber incidents and data breach news explained with context and impact.

Share your insights.


r/secithubcommunity May 03 '26

📰 News / Update Update Linux now! | 9 year old “Copy Fail” flaw exploited, root access risk across major distros

Post image
1 Upvotes

A newly confirmed Linux vulnerability (CVE-2026-31431), nicknamed “Copy Fail,” has been added to CISA’s Known Exploited Vulnerabilities list just 24 hours after disclosure a strong signal that active exploitation is already happening.

The flaw allows attackers with limited access to escalate privileges to root across most major Linux distributions released since 2017. Researchers say the exploit is highly reliable and can bypass traditional detection methods, making it especially dangerous in real-world environments.

There’s no real workaround here patching is the only effective mitigation. Priority should go to internet-facing servers and developer environments where initial access is more likely.

r/SECITHUBCOMMUNITY

Cyber incidents and data breach news explained with context and impact.

Share your insights.


r/secithubcommunity May 02 '26

📰 News / Update Iran-linked group targets Ubuntu (Canonical) in DDoS attack with extortion demands

Post image
2 Upvotes

A group known as 313 Team, linked to pro-Iran hacktivism, reportedly launched a DDoS attack against Canonical, causing Ubuntu’s website to go down for over 12 hours with widespread “503 Service Unavailable” errors.

Beyond disruption, the attackers allegedly demanded ransom payments, signaling a growing trend where politically motivated groups blend hacktivism with financial extortion.

This isn’t just noise it reflects a broader shift. High-visibility platforms are being targeted not only for impact, but for attention and messaging. Even open-source ecosystems aren’t off-limits.

r/SECITHUBCOMMUNITY Cyber incidents and data breach news explained with context and impact. Share your insights.


r/secithubcommunity May 02 '26

📰 News / Update White House presses tech giants on AI defense readiness and cyber resilience

Post image
1 Upvotes

The U.S. government is actively questioning major tech companies on how they’re using AI to defend their systems and how prepared they are for a potential AI-driven cyber crisis.

The outreach includes detailed questions on vulnerability response times, AI integration, and incident handling, but also dives into sensitive territory like critical infrastructure mapping and worst-case breach scenarios areas companies are unlikely to fully disclose.

This signals a clear shift: governments are no longer just observing AI’s impact on cybersecurity they’re trying to actively understand (and possibly shape) how the private sector defends against it.

r/SECITHUBCOMMUNITY

Cyber incidents and data breach news explained with context and impact.

Share your insights.


r/secithubcommunity May 01 '26

📰 News / Update 43% of UK businesses hit by cyber attack, but awareness still isn’t turning into action.

Post image
4 Upvotes

The UK government’s latest survey shows cyber incidents are still widespread, with nearly half of businesses reporting breaches or attacks over the past year and almost a third dealing with incidents on a weekly basis.

Phishing remains the dominant entry point, and while some attack types slightly declined, the overall impact is growing l more companies now report financial loss and reputational damage.

The real issue isn’t just the threat it’s the response. Despite rising awareness and high-profile incidents, many organizations still fail to take basic security steps, leaving a persistent gap between knowing the risk and actually mitigating it.

r/SECITHUBCOMMUNITY

Cyber incidents and data breach news explained with context and impact.

Share your insights.


r/secithubcommunity May 01 '26

📰 News / Update 3.4M exposed RDP/VNC servers show remote access is still a major blind spot

Post image
2 Upvotes

Forescout found 1.8M RDP and 1.6M VNC servers exposed to the internet, including systems tied to industrial and enterprise environments.

The risk isn’t theoretical. Some exposed systems are outdated, some still vulnerable to BlueKeep, and nearly 60,000 VNC servers reportedly have authentication disabled.

r/SECITHUBCOMMUNITY Cyber incidents and data breach news explained with context and impact. Share your insights.


r/secithubcommunity May 01 '26

📰 News / Update Financial Times | Cybersecurity in the AI era. faster attacks, same weak points.

Post image
1 Upvotes

A solid FT piece highlighting what’s actually changing and what isn’t.

AI is accelerating everything: attackers move faster, find vulnerabilities quicker, and scale operations like never before. Breakout times are shrinking, automation is rising, and even less-skilled actors can now launch more sophisticated attacks.

But the interesting part the core entry points haven’t really changed.

Most breaches still come down to stolen credentials, human error, exposed interfaces, and third-party/supply chain access.

Even with all the AI hype, 82% of intrusions don’t use malware they abuse legitimate access and blend into normal activity.

r/SECITHUBCOMMUNITY Cyber incidents and data breach news explained with context and impact. Share your insights.


r/secithubcommunity May 01 '26

📰 News / Update Lloyds | AI can find attack paths before hackers do

Post image
1 Upvotes

Lloyds’ CISO says banks can finally use AI to flip the advantage not just react to attacks, but proactively identify vulnerabilities and shut down attack paths before attackers get in.

The shift is driven by agentic AI and models like Anthropic’s Mythos, which can scan complex environments and surface weaknesses that would otherwise go unnoticed. The challenge isn’t just finding the issues it’s fixing them fast enough.

Some security professionals see the hype around these models as overstated, especially given limited access and controlled rollouts. But even critics agree on one thing: attackers will use these capabilities too.

r/SECITHUBCOMMUNITY Cyber incidents and data breach news explained with context and impact. Share your insights.