Accenture Breach, AssuranceAmerica Exposed, Mount Royal – Cyber News
Quick Answer
The top cybersecurity news this week includes Accenture's confirmed breach, AssuranceAmerica's customer data exposure, AI-driven ransomware, critical Microsoft Edge and U-Boot vulnerabilities, ShareFile security alerts, and growing threats to enterprise and email security.
It’s been a heavy week for breach disclosures and AI-powered attacks. IT giant Accenture confirmed a source-code theft, an insurance provider leaked millions of driver’s license numbers, and security researchers documented what they’re calling the first fully AI-agent-driven ransomware operation. Meanwhile, a wave of ransomware sentencings, a critical bootloader flaw, and a Progress Software emergency shutdown order rounded out a busy seven days.
Accenture confirms breach after hacker offers stolen data for sale!
A threat actor known as “888” posted on a cybercrime forum claiming to have breached the technology consulting company and stolen just over 35GB of source code in July 2026. The stolen data reportedly includes source code, RSA keys, SSH keys, Azure personal access tokens, Azure Storage access keys, and configuration files, with a screenshot showing what appeared to be a cloned Azure DevOps repository tied to an accenture.com hostname. Accenture confirmed the breach but hasn’t verified the full scope of what was taken.
AssuranceAmerica breach exposes millions of driver’s license numbers!
AssuranceAmerica, a provider of car and rental insurance across more than a dozen US states, discovered unauthorized access to its systems on March 17 and concluded that attackers stole names, contact information, and driver’s license numbers for almost 7 million customers. The attackers also took information about customers’ auto insurance policies, drivers, vehicles, and claims details. TechCrunch called it the largest known breach of driver’s license numbers so far in 2026.

Mount Royal University confirms breach as hackers claim 10TB stolen!
The Calgary-based university confirmed a data breach on June 17 affecting current and former students, after hackers claimed to have stolen and then deleted data from its file storage systems. The university says it’s still investigating and will provide updates once the probe wraps up.
Nextcloud misconfiguration leaks 367,000 files!
The self-hosted cloud provider left roughly 8GB of data” about 367,000 files” exposed due to a misconfiguration, including invoices, emails, names, and email addresses tied to clients like IONOS, STRATO, and a German school ministry.
KDDI breach grows to 12 million affected customers!
An update to last week’s story: Japanese telecom giant KDDI, whose email platform serves five other ISPs (STNet, JCom, Chubu Telecommunications, NIFTY, and BIGLOBE), now says roughly 12 million accounts and 7.6 million passwords were exposed in the breach” down slightly from earlier estimates of 14 million.
Two ransomware groups team up for an “unprecedented” campaign!
Threat intelligence researchers flagged a coordinated collaboration between two major ransomware operations, warning that the joint campaign represents a new level of organization and threat to enterprises.

Progress Software urges emergency shutdown of ShareFile servers!
Progress emailed ShareFile customers running Storage Zone Controllers, warning of a “credible external security threat” and telling them to shut servers down immediately. The order became public after a customer posted the email to Reddit’s r/sysadmin, and Progress’s status page listed affected customers as “not operational” while it investigates.
Malicious npm package targets crypto wallets via Injective Labs repo!
Unknown threat actors compromised the Injective Labs SDK project’s GitHub repository and used it to publish a malicious npm package designed to steal cryptocurrency wallet private keys and mnemonic seed phrases. The tainted package, released July 8, came with hidden telemetry functions that exfiltrated wallet data before being pulled from the registry.
Six flaws found in the U-Boot bootloader!
Researchers disclosed six vulnerabilities in the widely used U-Boot bootloader that could let attackers run malicious code during device boot, opening the door to stealthy firmware-level attacks that persist even after a reinstall.

“Ill Bloom” flaw drains over $5 million from crypto wallets!
Security firm Coinspect disclosed a vulnerability, nicknamed Ill Bloom, in how certain wallet software generated its recovery phrase the words controlling access to funds. Weak randomness in phrase generation let attackers work out the phrase and empty wallets, with one coordinated sweep confirmed on May 27.
Armenian national pleads guilty to Ryuk ransomware attacks!
A 34-year-old Armenian man pleaded guilty to hacking US companies and deploying Ryuk ransomware to encrypt their systems, as part of a broader wave of ransomware-related prosecutions this week.
Ransomware negotiator sentenced to nearly 6 years for aiding BlackCat!
A former negotiator was sentenced to 70 months in prison for conspiring with the now-defunct BlackCat (ALPHV) ransomware operators, working alongside two other security professionals to extort additional victims.
”Ghostcommit” attack hides prompt injection inside a PNG to steal repo secrets!
Researchers demonstrated a technique where a malicious image slipped past AI code-review tools CodeRabbit and Bugbot” which don’t open image files and tricked a coding agent into reading a repository’s .env file and writing the secrets into code as plain numbers.

Okta warns of voice-phishing scheme targeting Microsoft 365 passkeys!
A threat actor tracked as O-UNC-066 has been calling employees across food and beverage, tech, healthcare, automotive, construction, and aviation sectors, posing as security staff to convince them to register a new Entra passkey handing attackers persistent account access for data-extortion attacks.
China- and India-aligned hackers spied on Pakistani law enforcement for two years!
Researchers disclosed sustained cyber-espionage activity against multiple Pakistani law enforcement agencies running from February 2024 to April 2026, targeting servers hosting biometric records, criminal case files, and personnel data including one implant disguised as a routine portal update.
Microsoft Edge remote code execution flaw needs urgent patching!
Microsoft disclosed CVE-2026-57992, a high-severity RCE vulnerability in its Chromium-based Edge browser, warning that a specially crafted page could hand attackers control of an unpatched system.
Beyond patching software vulnerabilities, modern email security also requires layered protection. SPF, DKIM, and DMARC play a key role in defending domains against phishing, spoofing, and email impersonation.
General Manager
General Manager at DuoCircle. Product strategy and commercial lead across the email security portfolio.
Secure your email infrastructure
Protect, authenticate, and deliver. Contact our team to find the right solution.