A proposed class-action settlement could pay Central Maine Healthcare hospital patients affected by a data breach up to $5,000 per person, with claims processes and eligibility details outlined if the deal is approved.
Apollo Global Management said hackers gained unauthorized access to information on its cloud platforms from July 6–10, exposing names, birth dates, home addresses and Social Security numbers; the breach is attributed to a social engineering incident, law enforcement was notified, and there is no evidence yet that personal data was publicly posted or used for fraud.
A threat actor named TheHatman is selling massive Azure/Entra tenant dumps containing employee records from multiple major companies, including McDonald’s (~1.7M) and Vodafone (~425k), exfiltrated via compromised credentials. The data fields cover names, corporate emails, phone numbers, addresses, job titles, departments, and privileged accounts, enabling targeted BEC and privilege escalation. While the exact intrusion vector isn’t confirmed, researchers link the leaks to Infostealer infections and credential abuse rather than a Azure zero-day. Defenders should monitor for credential exposure, enforce MFA, and review third-party access to Azure directories to mitigate risk.}
AnMed Health’s Facebook page was taken down after hackers posted nearly 100 ransom messages, claiming to have exfiltrated six terabytes of sensitive patient data and threatening further harm unless paid. The incident appears to be part of a broader cyberattack that began July 26; AnMed has since set up a patient helpline and recovery site while authorities investigate.
Valve has informed European Steam hardware buyers that their personal data may have been exposed in a cyberattack on CEVA Logistics, which handles Steam Deck, Steam Machine, and Steam Controller deliveries. The breach occurred July 29–August 1 and was reported August 7; affected data include names, street addresses, postal codes, cities, countries, phone numbers, email addresses tied to Steam accounts, and the type and price of the ordered hardware, while payment data, passwords, and Steam Guard codes were not affected. CEVA said the intrusion affected part of its European operation and several warehouses, with Valve notifying data protection authorities. Customers are warned to expect phishing attempts referencing orders, and Steam Support will never request passwords. The exact number of affected customers has not been disclosed.
Valve says a data breach at its European shipping partner CEVA Logistics may have exposed the personal information of customers who ordered Steam hardware in Europe, including names, addresses, phone numbers, and email addresses, with the breach occurring July 29–August 1 and delivery-related data kept for up to 90 days. The company warns of fake messages claiming to be from Steam, Valve, or a courier; CEVA does not have payment data or passwords, and Valve will not contact users via email, Steam chat, or Discord—use help.steampowered.com for official assistance.
Metabase warns of a high-severity zero-day (CVSS 10) that has been exploited in the wild to gain unauthenticated admin access by injecting arbitrary SQL into the Metabase database. The flaw affects self-hosted Metabase versions from 1.58.x up to 1.63.x (fixed in 1.63.5); Metabase Cloud was updated. A temporary workaround is to block the /api/session/reset_password endpoint. After patching, admins should revoke all sessions, review and rotate API keys and credentials, verify administrator accounts, and inspect logs for unauthorized activity. IoCs include a POST /api/session/reset_password (400) followed by a GET /api/user/current (200). Affected customer Framework reported exposure of names, login IPs, addresses, phone numbers, and emails, though no payment data was compromised. Metabase did not detail the attacker activity but referenced a past vulnerability CVE-2023-38646.
A parliamentary Defence Committee report says the MoD's management of the Afghan Relocations and Assistance Policy (ARAP) was a 'foreseeable' systemic failure, driven by inappropriate tools (Excel), weak operating procedures, insufficient training and an overreliance on secrecy that undermined accountability. The breach exposed personal data of more than 18,500 ARAP applicants, stemming from a spreadsheet shared with a trusted third party, and has prompted reforms as ARAP closes in 2025, with ongoing scrutiny of UK Special Forces involvement and governance of the scheme.
A cybersecurity researcher says Angelina Jolie and Robert De Niro were at the center of a Tribeca Film Festival data leak exposing celebrities’ phone numbers, emails and device data; the festival removed the database and is investigating the exposure.
Chick-fil-A says a June security incident may have exposed limited personal data from Chick-fil-A One loyalty accounts, including names, email addresses, membership numbers, mobile payment numbers, the last four digits of cards and the amount of loyalty credit; attackers used third-party credentials to access the site and app June 17–19, prompting password resets, balance restoration, and customer notifications across several states, with an apology from the company.
Chick-fil-A says unauthorized parties accessed Chick-fil-A One accounts during a June 17–19 cyberattack, potentially exposing names, email addresses, loyalty numbers, the last four digits of card numbers, and Chick-fil-A credits for customers in 10 states and Washington, D.C. Texas later reported 2,182 affected residents. The company reset passwords, forced logouts, removed stored payment methods, and restored balances while urging customers to monitor credit reports and account activity for signs of identity theft.
Chick-fil-A says a limited number of Chick-fil-A One loyalty accounts were accessed in an automated attack on June 17–19, potentially exposing names, email addresses, birthdays, phone numbers, addresses, and the last four digits of stored payment cards. The company forced logouts, removed saved payment methods, reset passwords, restored balances, and offered a reward to impacted customers. Massachusetts reported 39 affected residents and Texas 2,182; Georgia impact is unclear. The breach underscores varying state disclosure rules and the need for vigilance against identity theft, with the company providing guidance for affected residents.
Chick-fil-A disclosed a data breach after a June credential-stuffing attack on its Chick-fil-A One site/app that may have exposed customer data, including names, emails, membership numbers, mobile pay numbers, QR codes, Chick-fil-A credit, and the last four digits of card numbers, with possible birth dates, phone numbers, and addresses; affected accounts were logged out, payment methods removed, balances restored, and customers were urged to change passwords, with notices issued to residents in multiple states (including Texas and Massachusetts).
Hugging Face disclosed that attackers used an autonomous AI agent to breach its production infrastructure, stealing internal datasets and cloud credentials after exploiting a malicious dataset to trigger two code-execution vulnerabilities; the company evicted the attacker, rebuilt affected nodes, rotated credentials, and deployed enhanced detection while informing law enforcement and engaging external forensics. There is no current evidence of tampering with public models or Spaces, though the incident highlights evolving AI-driven attack risks. Users are advised to rotate access tokens and review account activity; Hugging Face also stresses having a vetted self-hosted model ready to use during incidents to avoid guardrail lockout and contain attacker data.
Security roundup flags widening privacy and security concerns: Stardust period-tracker data sharing is exposed in a Mozilla audit (Euki is the privacy-friendly exception), Russia’s FSB is sanctioned for a near–blackout attack on Poland’s grid, a Russian hacker’s ties to Kaspersky surface in a Reuters report, DHS’s HSIN breach was initially treated as a false positive before confirmation, and Suno’s AI music training scraped millions of songs with customer data exposed—illustrating how AI, surveillance, and state-linked cyber operations intersect with everyday tech.