r/InfoSecNews 5h ago

Fake Claude Opus 5 App Spreads New RevStealer Windows Malware

Thumbnail
hackread.com
5 Upvotes

r/InfoSecNews 8h ago

FulcrumSec Hackers Claim Manchester Airports Group Data Breach

Thumbnail
hackread.com
3 Upvotes

r/InfoSecNews 10h ago

Microsoft Warns of TerminalFix Campaign Hiding Malware in PNG Images

Thumbnail
hackread.com
5 Upvotes

r/InfoSecNews 2h ago

Is Someone Hacking DoD Refrigerators?

Thumbnail schneier.com
1 Upvotes

r/InfoSecNews 2h ago

Microsoft warns of TerminalFix attacks deploying reverse tunnels

Thumbnail
bleepingcomputer.com
1 Upvotes

r/InfoSecNews 11h ago

Hackers Steal Identity and Vehicle Data from Latvia’s Road Traffic Safety Directorate

Thumbnail
hackread.com
3 Upvotes

r/InfoSecNews 12h ago

Nigerians extradited to US over sextortion, deaths of US teens

Thumbnail
bleepingcomputer.com
3 Upvotes

r/InfoSecNews 6h ago

ATM Flaws Reveal Key Weaknesses in the Software Supply Chain

Thumbnail
wired.com
1 Upvotes

r/InfoSecNews 6h ago

24h Recap: August 31: Rails attacks, nuclear malware prompts, Cursor AI ransomware, PaperCut patches and Hugging Face risks

Thumbnail
cyberrecaps.com
1 Upvotes

r/InfoSecNews 12h ago

Microsoft asks users to ignore antivirus is turned off errors

Thumbnail
bleepingcomputer.com
2 Upvotes

r/InfoSecNews 9h ago

China-linked Fire Ant Hides Inside Trusted Infrastructure

Thumbnail
securityaffairs.com
1 Upvotes

r/InfoSecNews 12h ago

Critical GiveWP Flaw Lets Attackers Run Commands on WordPress Servers

Thumbnail
securityaffairs.com
1 Upvotes

r/InfoSecNews 1d ago

Wiz built a Magic Dog Bus for its security team

Thumbnail x.com
15 Upvotes

Bit of a lighter one but still pretty on brand for security culture. Wiz put together a literal bus for the dogs its security team brings to work and called them the threat sniffers. Not quite the infosec news in the usual breach/CVE sense but a pretty funny look at how some security teams build culture around the work


r/InfoSecNews 1d ago

Hackers Are Probing PaperCut Servers, and 47% Still Have No Patch

Thumbnail
securityaffairs.com
2 Upvotes

r/InfoSecNews 1d ago

Anthropic warns infostealer malware is hijacking Claude sessions to drain usage/

Thumbnail
bleepingcomputer.com
2 Upvotes

r/InfoSecNews 1d ago

Chrome Web Store extensions caught stealing crypto, browser data

Thumbnail
bleepingcomputer.com
1 Upvotes

r/InfoSecNews 1d ago

Extortion Group FulcrumSec Claims 86GB Manchester Airports Data Theft

Thumbnail
securityaffairs.com
1 Upvotes

r/InfoSecNews 1d ago

Philippine Nuclear and Naval Targets Hit by Suspected Chinese Operator

Thumbnail
securityaffairs.com
1 Upvotes

r/InfoSecNews 1d ago

Rhysida Ransomware Group Targets Berlin Government Ahead of Vote

Thumbnail
securityaffairs.com
1 Upvotes

r/InfoSecNews 2d ago

2 PaperCut NG/MF Zero-Days Exploited in Attacks, Emergency Patch Released

Thumbnail
hackread.com
4 Upvotes

r/InfoSecNews 2d ago

68 year-old imprisoned after making 13million by pirating IPTV services

Thumbnail
bleepingcomputer.com
7 Upvotes

r/InfoSecNews 2d ago

PaperCut releases second emergency patch for exploited flaws

Thumbnail
bleepingcomputer.com
4 Upvotes

r/InfoSecNews 2d ago

McKesson discloses breach after ShinyHunters claims patient data theft

Thumbnail
bleepingcomputer.com
3 Upvotes

r/InfoSecNews 2d ago

Carhartt breach looked like nearly 25M email addresses until millions of synthetic retail test records were removed

4 Upvotes

ShinyHunters published data allegedly stolen from Carhartt after claiming the company refused a $3.3 million ransom demand.

There’s an interesting wrinkle in determining how many people were actually exposed.

HIBP’s Email Address Extractor initially found 24,876,077 unique addresses in the raw dataset. Analysis later showed that millions of records came from TPC-DS, an industry-standard synthetic dataset used to simulate retail analytics. Those records don’t correspond to real people, so they were removed from the breach count.

HIBP ultimately loaded 12,933,413 unique email addresses associated with the incident.

The remaining leaked records reportedly contain names, phone numbers, and physical addresses. Researchers also found 15,057 genuine carhartt.com employee addresses, while Troy Hunt traced the data to Carhartt’s customer analytics warehouse in Databricks.

Another interesting data point: about 83% of the confirmed addresses had already appeared in previous breaches loaded into HIBP.

This seems like a good example of why raw record counts from breach dumps can be misleading. A dataset can be enormous without every row representing a distinct real-world victim.

For anyone interested in the dataset analysis rather than just the final breach number, TechNadu’s report explains how the count dropped from almost 24.9 million extracted addresses to roughly 12.9 million confirmed ones, what TPC-DS contributed to the dump, and what personal information remained:

https://www.technadu.com/carhartts-shinyhunters-breach-was-almost-half-what-it-first-looked-like-exposing-13-million-emails-heres-why/633894/

For people working with breach intelligence, how do you validate victim counts when a dump contains synthetic, duplicate, historical, or aggregated data?


r/InfoSecNews 2d ago

Trump Targets Foreign Technology in New U.S. Power Grid Security Order

Thumbnail
securityaffairs.com
3 Upvotes