← All issues
cybersecurityCyberBubbledata-breach

3.6M Azure Records Stolen, Ransomware Hits Windows, and Who's Tracking You

🌐  World Intel
France: Tax Authority Breach Hits 678,000 People

An attacker broke into systems run by France's General Directorate of Public Finances and walked out with personal data on 678,000 individuals. The stolen records belong to ordinary taxpayers — not government officials. If you have any connection to French tax filings, watch for phishing emails pretending to be from French tax authorities.

↗ BleepingComputer
Global: Clop Ransomware Claims Hits on GE and Philips

The ransomware gang known as Clop says it breached both General Electric and Philips and stole data from both companies. GE and Philips have confirmed they are investigating the claims. Clop has a long history of targeting big industrial and healthcare firms, so these claims are being taken seriously.

↗ BleepingComputer
UK/Germany: Pokémon Center Breach via Third-Party Shipper

Pokémon Center is telling customers in the UK and Germany that their personal and order information was stolen — not from Pokémon Center itself, but from a logistics company called CEVA Logistics that handles shipping on its behalf. The company has cancelled some affected orders as a precaution. This is a good reminder that your data travels further than you might expect when you shop online.

↗ BleepingComputer
⚔️  Active Attacks
Ransomware Gangs Are Now Using a Known Windows Flaw — Actively

The US government's cybersecurity agency CISA has confirmed that ransomware groups are actively exploiting a high-severity flaw in the Windows Task Host — a core part of Windows that manages what programs can run at shutdown. The flaw was first flagged as being exploited back in April, but CISA's update today confirms that criminal ransomware gangs have now joined in. Any Windows system that hasn't applied recent security patches is at risk of being locked up and held for ransom.

🛡 What to do: Open Windows Update right now and install any pending updates. Don't postpone — this one is being actively weaponized by ransomware criminals today.
Mac Users: Hackers Exploit Screen Sharing to Secretly Mine Crypto

Hackers are exploiting a flaw in macOS's built-in Screen Sharing feature to secretly install a Monero miner on victims' Macs. The miner runs silently in the background, slowing your machine down and hiking your electricity bill — all while someone else profits. You wouldn't notice unless you were watching your system's resource usage carefully.

🛡 What to do: Go to System Settings → General → Sharing and turn off Screen Sharing if you don't use it. Then check for and install any pending macOS software updates.
🔓  New Vulnerabilities
CVE-2026-19478 GitLab (Community & Enterprise Edition) CRITICAL 9.4

A critical bug in GitLab — a popular platform that developers use to store and manage code — lets a complete stranger on the internet delete or modify public projects and wipe user data without ever logging in. GitLab rushed out an emergency patch five days ahead of its normal schedule, which tells you how serious this is. If your company runs its own self-hosted GitLab server, someone could erase your entire codebase right now unless you update.

Status: Patch available — update to GitLab 19.2.4, 19.1.6, 19.0.8, or 18.11.11 immediately. Cloud-hosted GitLab.com users are already protected and don't need to act.

CVE-2026-15748 Forminator Forms (WordPress Plugin) CRITICAL 9.8

Forminator Forms is a plugin used on over 600,000 WordPress websites to build contact forms. This flaw lets anyone — no account needed — upload a malicious file to a vulnerable site and then run that file to take complete control of the web server. Think of it like mailing a time bomb through a website's contact form. The catch: the site's form must include both a file upload field and a dropdown menu for the attack to work.

Status: Patch available — version 1.56.2, released July 31, 2026, fixes this. If you run a WordPress site with Forminator, update the plugin today.

CVE-2025-62593 Ray (AI/ML Computing Framework) CRITICAL 9.4

Ray is an open-source tool that many companies use to run large AI and machine learning workloads. A bug in Ray lets an attacker use a technique called a DNS rebinding attack to run any code they want on a Ray server — through a normal web browser like Firefox or Safari. CISA added it to its list of actively exploited flaws today, meaning real attackers are using it right now. The root cause is that Ray's developers chose not to require any login to access critical internal controls.

Status: Actively exploited. Check Ray's GitHub for the latest patched release and apply it immediately if your organization runs Ray.

🛠  New Tech
DecryptAds: A Free Tool That Shows Who's Really Tracking You Online

A new free service called DecryptAds (decryptads.com) lets you look up any website or app and instantly see which advertising companies and data brokers are collecting your information. It was built by security researcher Zach Edwards and two co-founders, who wanted to make the ad industry's largely hidden data-sharing web visible to everyone. A search for ESPN, for example, turns up 143 ad partners and 19 data broker domains — including four advertising firms based in Russia, China, or the UAE. The tool also flags adtech partners based in countries considered security risks, and can help track down the source of malicious ads. It's free, requires no account, and works for both websites and mobile apps.

💡  Deep Dive
3.6 Million Azure Records, One Bag of Stolen Passwords: The Hidden Cost of Reused Credentials

A hacker is claiming to have stolen employee databases from multiple Fortune 500 companies — and the method reportedly wasn't some Hollywood-style hack. They used compromised credentials: usernames and passwords that had already leaked elsewhere, tried against Microsoft Azure accounts until they worked. The claimed haul is 3.6 million records.

This is called credential stuffing, and it works because people reuse passwords. If your password for a shopping site you signed up for in 2019 is the same as your work email password, and that shopping site was ever breached, an attacker can try that same combination on your employer's systems. They don't need to be clever — they just need a list and a script. Microsoft's Azure platform is a prime target because so many large companies run their core operations on it.

The implications stretch far beyond the employees whose records were taken. Corporate databases often contain internal contact details, org charts, and system access information that makes follow-up attacks — like targeted spear-phishing — far easier and more convincing. One set of stolen records becomes the map for the next attack.

Microsoft has not confirmed the breach, and independent verification of the full claim is still ongoing. But the pattern is familiar enough to take seriously right now. The fix is simple in principle: use a different, strong password for every account, stored in a password manager, and turn on two-factor authentication wherever you can. If a company you work for uses Azure or any cloud platform, ask your IT team whether they have alerts in place for login attempts from unusual locations.

🛡️

Stay sharp. It's free.

Join thousands of readers who get daily cybersecurity news in plain English.

Subscribe Free →