River Bank obtained assurances from the attackers that the stolen data in the June attack was deleted

2026-08-03T14:51:37Z196573a2bfd88654bed88c308252d31a472292a66b77a9d8bbd65c5b8617f41f
CVE-2026-48449CVE-2026-66066API keysAPT29Active StorageAdobe Campaign ClassicCVEDNS hijackingICSMicrosoft 365 token theftMidnight BlizzardOT securityRuby on RailsSCADA/PLCStorm-2945arbitrary file readdata breachextortionfinancial datahealthcarehotel Wi-Filaw enforcementmalwareransomwareremote code executionsecrets exposuresource code exposure

What happened

Security Affairs feed covering recent breaches, ransomware activity, critical software vulnerabilities, malware campaigns, Russian state-linked phishing, and attacks against operational technology. Notable items include critical unauthenticated file-read/RCE vulnerabilities in Ruby on Rails Active Storage (CVE-2026-66066) and Adobe Campaign Classic (CVE-2026-48449), alleged exposure of Żabka source code and API keys, a CareCloud breach affecting approximately 345,000 individuals, and attacks targeting internet-exposed PLCs at Minnesota water utilities.

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
securityaffairs
Record identifier
196573a2bfd88654bed88c308252d31a472292a66b77a9d8bbd65c5b8617f41f
Enrichment time
2026-08-03T14:51:37Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.