Megalodon: New CI/CD Malware Spreads Across GitHub, Infecting ~5,000+ Repositories

OX Security analysis confirms 3,500+ GitHub repositories infected with Megalodon, a new CI/CD credential-stealing malware spreading via fake automated commits. Numbers rising.

OX Security
Threat hunters find Google API keys still usable 23 minutes after deletion

Plenty of time for bad actors to grab data or hit you with a giant bill

theregister

YCC情報システム、ランサムウェアの被害 調査完了-外部専門機関が実質的な情報漏えいを裏付ける痕跡は確認されず
https://rocket-boys.co.jp/security-measures-lab/ycc-info-systems-ransomware-probe-completed/

#セキュリティ対策Lab #security #DataBreach #securitynews

YCC情報システム、ランサムウェアの被害 調査完了-外部専門機関が実質的な情報漏えいを裏付ける痕跡は確認されず

株式会社YCC情報システム(山形市、以下「YCC社」)は2026年5月20日、2026年4月2日に発生したラン

合同会社ロケットボーイズ
Windows93 / Myspace93 - 46,105 breached accounts - RedPacket Security

In January 2021, the parody site Windows93 suffered a data breach of the Myspace93 sub-site after a beta application was exploited to download server files.

RedPacket Security
Dragonica Lunaris - 126,293 breached accounts - RedPacket Security

In December 2025, the European Dragonica private server Dragonica Lunaris suffered a data breach. The incident exposed 126k email addresses, usernames, dates

RedPacket Security
Data of around 1,700 people potentially compromised in Canvas data breach, N.W.T. gov't says
Approximately 1,700 teachers, education staff, government employees, program participants and contractors are affected by a breach that may have compromised email addresses, enrollment information and training data.
https://www.cbc.ca/news/canada/north/canvas-breach-nwt-9.7208039?cmp=rss

Getting hacked isn't the problem. How you respond is.

Data breaches are inevitable but your response defines your organization's reputation. In this week's episode of @sharedsecurity we discuss the need to stop judging organizations for being attacked and why we need to start holding them accountable for what comes after.

Watch this episode on YouTube:
https://youtu.be/-pgPoMNAmkw

Listen and subscribe wherever you like to get your podcasts:
https://sharedsecurity.net/subscribe
https://sharedsecurity.net/2026/05/18/cybersecurity-lessons-from-the-canvas-data-breach/

#podcast #cybersecurity #databreach #canvas

Bei einem #Cyberangriff auf einen externen Dienstleister für Kliniken haben Kriminelle bundesweit Daten von Zehntausenden Patienten gestohlen. Auch das Universitätsklinikum des Saarlandes (UKS) ist betroffen.
https://www.sr.de/sr/home/nachrichten/panorama/cyberangriff_saar_uniklinik_patientendaten_betroffen_100.html
#Security #Datenschutz #DataBreach
Hacker erbeuten Patientendaten: Auch Uniklinik Homburg betroffen

Bei einem Cyberangriff auf einen externen Dienstleister sind Daten von 1266 Patientinnen und Patienten des Universitätsklinikums in Homburg gestohlen worden. Nicht nur das Uniklinikum ist betroffen.

SR.de

“Based on the results of the data review to date, the following types of data were compromised in the incident: names; medical information (medical record numbers, disability codes, diagnoses, medications, test results, images, treatment plans); health insurance information (plans/policies, insurance companies, member/group ID numbers, Medicaid-Medicare-government payor ID numbers), billing/claims information; biometric information (finerprints & palm prints); personal information (Social Security numbers, driver’s license numbers or other government-issued identification numbers, taxpayer identification numbers or IRS-issued identity protection numbers, precise geolocation data, credit or debit card numbers, financial account information or credentials, online account credentials).”

#dataBreach #infosec

“Up to 1.8 Million Individuals Affected by NYC Health + Hospitals Data Breach”

https://www.hipaajournal.com/nyc-health-hospitals-data-breach-march-26/

Up to 1.8 Million Individuals Affected by NYC Health + Hospitals Data Breach

The HIPAA Journal reported on a data breach affecting patients of NYC Health + Hospitals Corporation in late March (see below), after the New York NYC Health + Hospitals Corporation has recently announced a security incident that involved the theft of PII and PHI from its network. Hackers had access to certain systems from November 25, 2025, to February 11, 2026, and stole the data of approximately 1.8 million individuals.

The HIPAA Journal