The Breach News

Hospitals Threatened by BeyondTrust Ransomware Attacks

Fraud Management & Cybercrime, Identity & Access Management, Ransomware Critical Vulnerability Could Provide Attackers Access to Clinical Networks Marianne Kolbasuk McGee (HealthInfoSec) • February 20, 2026 The Department of Health and Human Services along with industry officials are advising healthcare organizations to patch a critical flaw in BeyondTrust’s remote support…

Read MoreHospitals Threatened by BeyondTrust Ransomware Attacks

LeakWatch 2026: Weekly Overview of Security Incidents, Data Breaches, and IT Events for Calendar Week 8

In calendar week 08 of 2026, the cybersecurity landscape in Germany faced significant challenges, marked by a convergence of critical data breaches and disruptions primarily affecting healthcare and telecommunications. This week, spanning from February 16 to February 22, highlighted a range of vulnerabilities and incidents that underscore ongoing risks related…

Read MoreLeakWatch 2026: Weekly Overview of Security Incidents, Data Breaches, and IT Events for Calendar Week 8

Fortinet and Zoho Encourage Customers to Address Enterprise Software Vulnerabilities with Patching

Fortinet has identified a critical vulnerability impacting its FortiADC application delivery controller that has the potential for arbitrary code execution. This flaw, categorized as CVE-2022-39947 with a CVSS score of 8.6, affects several FortiADC versions, including 7.0.0 to 7.0.2, 6.2.0 to 6.2.3, and several earlier versions down to 5.4.0. According…

Read MoreFortinet and Zoho Encourage Customers to Address Enterprise Software Vulnerabilities with Patching

Metadata Reveals Authors Behind ICE’s ‘Mega’ Detention Center Plans

A PDF document distributed by officials from the Department of Homeland Security (DHS) to New Hampshire Governor Kelly Ayotte’s office has inadvertently revealed sensitive information regarding individuals involved in its creation. This document details a plan to establish large-scale detention and processing centers known as “mega” detention facilities across the…

Read MoreMetadata Reveals Authors Behind ICE’s ‘Mega’ Detention Center Plans

Hackers Leak Personal Information of EDL Members, Group Calls for Caution

A notable security breach has raised alarms within the English Defence League (EDL), after an anti-Islamist group disclosed sensitive member information online. The breach was perpetrated by hackers identifying themselves as members of the Mujahideen Hacking Unit, who gained unauthorized access to one of the organization’s websites. A significant amount…

Read MoreHackers Leak Personal Information of EDL Members, Group Calls for Caution

Android Malware Exploits Google Gemini During Runtime

Cybercrime, Endpoint Security, Fraud Management & Cybercrime Experts Reveal PromptSpy Leverages AI for Enhanced Device Persistence Pooja Tikekar (@PoojaTikekar) • February 20, 2026 Image: Shutterstock Recent investigations have unearthed a novel strain of Android malware known as PromptSpy, which harnesses Google’s Gemini generative artificial intelligence model to automate its persistence…

Read MoreAndroid Malware Exploits Google Gemini During Runtime

Flagstar Customers Move Forward in $31.5M Data Breach Settlement

Preliminary Settlement Reached in Flagstar Bank Data Breach Lawsuits On February 20, 2026, a federal judge in Michigan granted preliminary approval for a significant settlement involving Flagstar Bank that totals $31.5 million. This settlement aims to address consolidated class-action claims stemming from two major data breaches that compromised the personal…

Read MoreFlagstar Customers Move Forward in $31.5M Data Breach Settlement

Critical Security Vulnerability Discovered in “jsonwebtoken” Library Utilized by Over 22,000 Projects

High-Severity Flaw in jsonwebtoken Library Poses Remote Code Execution Risk A significant security vulnerability has been discovered in the widely used open-source jsonwebtoken (JWT) library, which could allow attackers to execute arbitrary code on servers processing maliciously crafted JSON web token requests. This issue has been tracked as CVE-2022-23529 and…

Read MoreCritical Security Vulnerability Discovered in “jsonwebtoken” Library Utilized by Over 22,000 Projects