Arizona’s court system said attackers gained access after an employee clicked a malicious link in a phishing email and copied sensitive backup files involving protective orders and foster care cases. The court later said attackers copied more than 150,000 Foster Care Review Board recommendation reports covering current and past children’s-care cases dating back to 2010.
Why it matters
The reports can include children’s information, names of involved parties, case materials, findings, and recommendations; the court said they do not contain addresses or telephone numbers.
Known limitation: This item is supported by one source record and has not been independently corroborated here.
Security Daily
Identity · Arstechnica Security
What happened
Microsoft warned that attackers were exploiting critical CVE-2026-73570 in Zimbra Collaboration Suite to seek email backups and authentication credentials from vulnerable organizations. The vulnerability allows unauthenticated attackers to remotely issue operating-system commands.
Why it matters
Shadowserver reported that scans found 274 separate compromised Zimbra instances.
Known limitation: This item is supported by one source record and has not been independently corroborated here.
Security Daily
AI & Agents · Cyberscoop
What happened
Proofpoint attributed phishing campaigns to TA419, a China-aligned cyber espionage group, targeting U.S. AI policy experts and seeking access to cloud accounts at think tanks, universities, and law firms. The campaigns impersonated prominent officials, economists, and an Anthropic employee, using invitations about AI policy committees, export controls, supply chains, or military use of Claude models to start conversations.
Why it matters
Proofpoint characterized the operation as adversary-in-the-middle phishing: victims could interact with genuine Microsoft infrastructure, enter passwords, complete multifactor authentication, and pass access checks while session information was captured.
Known limitation: This item is supported by one source record and has not been independently corroborated here.
Evidence is visible. Uncertainty stays visible too.
Baitaphish separates source records from interpretations, labels AI-assisted enrichment, and avoids turning ingestion volume into unsupported claims about threats, prevalence, or risk.