By security practitioners, for security practitioners novacoast federal | Apex Program | novacoast | about innovate
By security practitioners, for security practitioners

Top 10 Cybersecurity News (August 24, 2026): Hacker Sells Azure Data From McDonald’s, 77 Firefox Extensions Linked To Wallet Theft, and More

WEEKLY TOP TEN: August 24, 2026, 16:00 GMT

  1. Hacker Sells Azure Data From McDonald’s And Others

    A threat actor known as TheHatman began advertising employee databases allegedly stolen from Microsoft Azure tenants belonging to several Fortune 500 companies, using compromised credentials to access the environments. The seller claims 3.64 million total records, with the largest single dump containing 1.7 million employee records from McDonald’s Corporation. Other named organizations include Gap Inc., Vodafone, Tata Consultancy Services, HCL Technologies, InterContinental Hotels Group, and Kyndryl. Gap Inc. said its investigation found the advertised data non-sensitive and several years old. The other companies had not confirmed the claims at time of publication.
  2. CISA Flags Four Actively Exploited Vendor Flaws

    CISA added four vulnerabilities to its Known Exploited Vulnerabilities catalog based on confirmed in-the-wild exploitation: a Microsoft Internet Key Exchange service extensions double-free flaw, a Microsoft SharePoint weak authentication bug, a Broadcom VMware vCenter path traversal vulnerability, and an Apple macOS improper authentication flaw. Federal civilian agencies must remediate under Binding Operational Directive 26-04. The SharePoint and vCenter flaws in particular carry high exploitation likelihood given active proof-of-concept availability, and organizations running any of the affected products should prioritize patching over routine maintenance cycles.
  3. 77 Firefox Extensions Linked To Wallet Theft

    Socket’s threat research team identified 77 Firefox browser extensions engaged in crypto wallet and credential theft, expanding on prior research into malicious extension ecosystems. The extensions impersonate legitimate utilities while harvesting wallet seed phrases, session tokens, and login credentials from users who install them believing they provide genuine functionality. The findings highlight ongoing risk in browser extension marketplaces, where malicious add-ons can pass initial review and accumulate installs before detection. Organizations should audit approved browser extension lists and restrict installation privileges on managed endpoints.
  4. French Tax Authority Breach Hits 680,000 People

    France’s Directorate General of Public Finances disclosed that hackers accessed its systems in June and July using compromised credentials belonging to an employee and a third party, exposing tax and property data for roughly 678,000 individuals and businesses. Reference tax income figures, withholding tax rates, company identifiers, and cadastral data on real estate were compromised. The intrusion was only confirmed publicly after a threat actor boasted about the access on a hacking forum. The agency reported the breach to France’s data protection regulator and plans to notify affected individuals directly.
  5. SafePal Discloses Breach Of 39,798 Customer Orders

    Crypto hardware wallet maker SafePal disclosed that an authorization flaw in a plugin used for order tracking exposed information for approximately 39,798 customers who placed orders between March 2025 and April 2026. Exposed data includes names, email addresses, shipping addresses, phone numbers, and purchase details, but not seed phrases, private keys, or wallet credentials. A threat actor began advertising the same dataset on a cybercrime forum the same day SafePal disclosed the incident. The company notified affected customers individually and warned of elevated phishing risk tied to the exposed order data.
  6. Microsoft Links 30 Domains To MacSync Stealer

    Microsoft Defender Experts correlated more than 30 rotating domains to MacSync Stealer, a macOS-focused information stealer, by tracking recurring endpoint and network behavior rather than relying on domain names. The malware spreads through ClickFix-style social engineering that tricks victims into pasting commands into Terminal, then collects Keychain material, browser data, SSH keys, AWS credentials, and Kubernetes configuration files. Microsoft confirmed active data exfiltration in addition to command-and-control beaconing. The findings give defenders behavior-based detection opportunities that remain effective even as the underlying domain infrastructure changes rapidly.
  7. Australian Hotel Chain Breach Traced To Third Party

    An Australian hotel chain notified guests that a vulnerability at a third-party database operator led to unauthorized access to a database system holding personal information. The company said it identified the unauthorized access on Monday, August 17, and immediately took steps to contain the incident, tracing the root cause to the third-party service provider rather than its own infrastructure. The notification did not specify the exact volume of records affected or the identity of the compromised vendor, but confirmed guest personal information was exposed.
  8. CISA Warns Of Active Threat To Siemens S7 PLCs

    CISA, joined by the NSA, FBI, Department of Energy, and EPA, issued advisory AA26-231A warning of active threat activity against internet-exposed Siemens S7 Series programmable logic controllers used at water treatment plants, power facilities, and chemical and manufacturing sites nationwide. The advisory confirms threat actors are using Censys and ZoomEye to locate exposed S7 devices on port 102, then using AI tools to generate functional exploit code against them. Agencies are directed to take internet-exposed S7 controllers offline immediately and follow seven listed hardening actions.
  9. Post-DEF CON Phishing Uses Google Doc Lure

    A Huntress researcher was targeted after Black Hat and DEF CON by a threat actor who used X direct messages and a fake security conference planning pretext to build trust before attempting to deliver malware via a Google Doc using Apps Script. The lure impersonated a shared conversation badge suggesting it came from Apple Support, and the campaign targeted both macOS and Windows users with platform-specific payloads. The researcher recognized the attempt and continued engaging to document the threat actor’s tactics rather than falling for the deployment attempt.
  10. StopAndProtect Network Hijacks 2,000 WordPress Sites

    Check Point Research uncovered a cybercrime operation dubbed StopAndProtect that has compromised nearly 2,000 WordPress sites, turning them into a distributed criminal network used for malware delivery, data theft, surveillance, and ransomware staging. The campaign exploits common WordPress vulnerabilities and weak credentials to gain persistent access, then repurposes the compromised sites as infrastructure supporting multiple downstream criminal operations rather than a single payload. Site operators are urged to audit plugin inventories, rotate administrative credentials, and check for unfamiliar admin accounts or scheduled tasks introduced without authorization.

Our Threat Operations and Intelligence team compiles a daily digest of the most recent online cybersecurity risks. The previous 10 stories were determined to be most significant during the course of the week, ranked by highest risk, and using multiple sources when available.

Previous Post

Top 10 Cybersecurity News (August 17, 2026): Jewelbug APT Runs Espionage and Crypto Fraud in Parallel, Iran-Linked Hackers Hit New Jersey, Alabama Water Utilities, and More

Innovate uses cookies to give you the best online experience. If you continue to use this site, you agree to the use of cookies. Please see our privacy policy for details.