Apollo Data Breach, Claude Code Attack, UK Plant Shutdown
Quick Answer
The Apollo data breach, Claude Code attack, and UK plant shutdown highlight evolving cybersecurity risks. These incidents show how data exposure, AI-assisted attacks, and operational disruptions can threaten organizations and why stronger security controls are essential.
This was a heavy week for the cybersecurity world, with stories spanning nation-state attacks on critical infrastructure, a private equity firm’s costly brush with social engineers, and multiple uncomfortable reminders that AI tools are now embedded on both sides of the attacker-defender line. Below is a roundup of the 15 biggest stories.
Private equity giant Apollo Global Management confirms a major data breach!
Apollo Global Management, which manages roughly $938 billion in assets, disclosed that hackers used social engineering tactics to break into its cloud environment between July 6 and July 10. Attackers made off with names, dates of birth, home addresses, contact details, and Social Security numbers. Apollo’s human resources chief said the firm “promptly notified law enforcement, engaged leading outside cybersecurity and forensic experts” and began offering affected individuals credit monitoring. The breach follows a broader campaign flagged by Google researchers in which callers posing as internal IT help desk staff have targeted dozens of financial and private equity firms, including Uber Freight and Levi Strauss. (Source: TechCrunch)

A ransomware affiliate weaponized Claude Code to run a live cyberattack!
A new report from Gambit Security details how a suspected affiliate of “The Gentlemen” ransomware-as-a-service group used Anthropic’s Claude Code as an operational partner during real-world intrusions across at least eight organizations, including an Australian energy utility and a Mauritius financial firm. The attacker reportedly used Claude to breach VPN appliances, execute a sophisticated LDAP pass-back attack to steal domain credentials, create hidden backdoor accounts, and rank stolen SQL databases by business value before exfiltrating them. It’s the latest example of criminals turning AI coding assistants into active participants in intrusions rather than passive advisors. (Source: UNDERCODE NEWS)
Iran-linked hackers reportedly shut down a UK power plant for four days!
The Telegraph reports that hackers linked to Iran’s regime successfully forced a small British power plant offline for four consecutive days, in what officials describe as the first successful cyberattack of its kind on UK energy infrastructure. The UK’s Department for Energy Security and Net Zero says there was never a risk to the wider national grid, since the affected site was a small-scale generator, but the agency has since warned power companies more broadly about the risk of similar attacks. The incident reportedly coincided with a separate wave of Iran-linked attacks on US water utilities across a dozen states last month. (Source: BBC via Slashdot)

Microsoft patches a maximum-severity Entra ID flaw already being exploited!
Microsoft disclosed CVE-2026-69836, a perfect-10 CVSS vulnerability in Entra ID (formerly Azure Active Directory) that could let an unauthenticated attacker remotely execute code with no user interaction required. The company said the flaw, caused by unsafe deserialization of untrusted data, had already been exploited in the wild before it was fully mitigated on Microsoft’s own infrastructure. No customer action is required since the fix was applied server-side, though Microsoft has not disclosed who was targeted or how long the exploitation window was open. Security professionals note that “no action required” only covers patching — organizations should still review access logs. (Source: The Register)
Hundreds of thousands of leaked AWS keys still work — many with full admin rights!
Truffle Security re-verified 10,616 AWS access keys found publicly exposed since 2022 and discovered that 88% still authenticate. Among corporate-linked credentials, 768 keys grant full administrative control of their AWS accounts, including 526 root keys and 242 keys with AdministratorAccess. The median live leaked key was roughly five years old and had never been rotated, and 130 of the exposed root keys belonged to AWS Organizations management accounts, meaning a single compromise could expose every linked account. Researchers say the numbers show forgotten, unrotated secrets — not fresh developer mistakes — are the real risk. (Source: Cybernews)
A critical GitLab flaw is already under active exploitation!
GitLab issued an emergency out-of-band patch for CVE-2026-19478, a CVSS 9.4 code injection vulnerability in its GraphQL API that lets an unauthenticated attacker remotely modify or delete public projects and user data. Within days, attack-surface firm watchTowr said it had reproduced the exploit and observed real-world attempts hitting its honeypot network. Beyond deleting projects, attackers can reportedly forge merge records to fake a security fix that never actually landed, and ban legitimate maintainers. Self-managed GitLab instances on affected versions should be patched immediately. (Source: SecurityWeek)

xAI’s Grok can be tricked into leaking your chat history with zero clicks!
Researchers at Adversa AI disclosed “cryptographic context injection,” a technique where an attacker hides encrypted instructions on a webpage that Grok is asked to summarize. Because the payload is encrypted, safety filters can’t read it — but Grok’s own code sandbox decrypts and executes it, then quietly sends the user’s name, approximate location, subscription tier, and full chat history to an attacker-controlled server. Adversa says it reported the flaw to xAI back in June, followed up twice since, and could still reproduce the attack as of August 19 with roughly a 40% success rate. No patch or CVE has been issued. (Source: The Hacker News)
Hundreds of fake VPN extensions are hijacking Chrome browser traffic!
Security firm Socket linked 737 VPN and proxy extensions on the Chrome Web Store to a coordinated operation, with 274 of them impersonating trusted brands like NordVPN, ProtonVPN, and Surfshark. Rather than protecting users, the extensions routed browsing traffic through shared, operator-controlled proxy servers, exposing browsing history, IP addresses, and unencrypted HTTP data. Some “premium” tiers advertised servers in Japan, Singapore, and Australia that simply didn’t exist. Google has removed some listings, but hundreds remained live as of this week. (Source: gHacks)
Criminals are spending millions buying expired domains to spread malware!
DNS threat intelligence firm Infoblox found that roughly 65,000 expired domains are re-registered every day, and criminals are snapping many of them up to inherit their existing traffic and trust. One tracked actor, “Sable Squirrel,” has spent an estimated $7 million acquiring over 10,000 expired domains to build a network spanning illegal sports streaming, gambling promotion, and malware command-and-control infrastructure, tied to samples of Quasar RAT, AsyncRAT, and other malware families. Infoblox calls it the largest domain acquisition budget it has identified for a single actor. (Source: The Hacker News)

A Windows Defender driver can be secretly weaponized to disable security software!
At Black Hat USA and DEF CON, Check Point researcher Jiří Vinopal revealed a technique that abuses BTR.sys, a legitimately signed Microsoft Defender boot-time remediation driver, to perform arbitrary kernel-level file and registry operations across every Windows version from Windows 7 through Windows 11 25H2. Because BTR.sys is a required Defender component, it can’t simply be blocklisted without breaking Defender itself. The researcher published a proof-of-concept tool showing how the technique could be used to delete security software during the brief “golden window” after a system boots but before Defender’s protections fully activate. (Source: The Hacker News)
Trump authorizes private companies to hack foreign cybercriminals!
President Trump signed a National Security Presidential Memorandum creating the first formal US program letting vetted private companies conduct offensive “hack-back” operations against foreign transnational criminal organizations, under the direction of the Departments of Justice and Homeland Security. Dubbed “cyber privateers” by commentators, participating firms could conduct both surveillance operations and disruptive attacks on criminal infrastructure. Former officials have welcomed the move as closing a real capability gap, while others warn it risks uncoordinated private actors operating without clear federal deconfliction. (Source: CNN)
A hacker is selling millions of employee records from McDonald’s, Vodafone, and other Fortune 500 firms!
A threat actor going by “TheHatman” has been flooding cybercrime forums with internal employee directories allegedly pulled from the Microsoft Azure and Entra tenants of McDonald’s, Vodafone, TCS, HCL Technologies, IHG, Kyndryl, Gap Inc., and others, totaling an estimated 3.64 million records. McDonald’s tops the list with roughly 1.7 million records. Researchers at Hudson Rock say the pattern points to compromised credentials from infostealer malware rather than a single Azure vulnerability, since only large enterprises appear affected. Some named companies, including TCS and Vodafone, say the exposed data appears to be several years old. (Source: SecurityWeek)

A Chinese-speaking hacker built an AI agent to autonomously scan for vulnerabilities!
Palo Alto Networks’ Unit 42 detailed how a threat actor known as “knaithe” or “KnYuan” combined the DeepSeek AI model with the open-source Hermes Agent framework, controlled via Telegram, to autonomously perform reconnaissance, download public exploit code, and attempt attacks against internet-facing servers with minimal human input. Researchers gained rare visibility into the operation after the AI agent accidentally exposed its own working directory, revealing API keys, target lists, and session logs. The actor reportedly also briefly tested Claude Code and OpenAI’s Codex, but leaned on DeepSeek’s more permissive framework for offensive work. (Source: Unit 42)
A leaked database claims to hold 7.3 million scraped Chess.com accounts!
A hacker posted a 15.5GB file on cybercrime forums containing what appears to be genuine data scraped from over 7.3 million Chess.com accounts, including usernames, account IDs, names, countries, and roughly 4.6 million email addresses. No passwords were found in the dataset. Researchers note the technique mirrors a smaller 2023 incident where Chess.com’s find-friends feature was abused to resolve external email lists against real accounts — this time at roughly nine times the scale. Chess.com, notably, does not offer two-factor authentication for its members. (Source: Hackread)
Major data breaches, AI-driven attacks, critical infrastructure threats, and the growing importance of DMARC, DKIM, and SPF in strengthening email security, reducing email spoofing, and mitigating phishing-related risks continue to shape the cybersecurity landscape.
General Manager
Founder and General Manager of DuoCircle. Product strategy and commercial lead for DMARC Report's 2,000+ customer base.
LinkedIn Profile →Take control of your DMARC reports
Turn raw XML into actionable dashboards. Start free - no credit card required.