Skip to main content
news

DentaQuest Data Breach, CEVA Customer Exposure, Levi Strauss Attack – Cybersecurity News [August 10, 2026]

Brad Slavin
Brad Slavin General Manager

Quick Answer

What are the biggest cybersecurity threats this week? Major breaches at DentaQuest and CEVA Logistics, active exploitation of Cisco and VMware flaws, macOS attacks, ransomware, spyware, and AI security risks highlight the growing need for stronger cybersecurity and email protection.

cybersecurity update

It was a heavy week for healthcare and logistics data, with DentaQuest and CEVA Logistics both confirming massive breaches, while a Canadian hacker pleaded guilty to the record-breaking Snowflake campaign. Attackers also kept up the pressure on infrastructure, actively exploiting flaws in Cisco firewalls, Apple’s macOS, and VMware vCenter. Meanwhile, AI’s dual-use nature took center stage at Black Hat and DEF CON, with researchers exposing critical flaws in AI coding agents even as AI helped build a Zoom zero-click exploit in under 24 hours.

DentaQuest breach exposes millions of dental patients’ data

A cyberattack on DentaQuest exposed sensitive information belonging to at least 15 million people, with some estimates placing the total above 23 million. Potentially affected data includes Social Security numbers, government health IDs, treatment details, and billing information, and the ShinyHunters group reportedly claimed responsibility. Affected patients should watch for medical identity fraud and unexpected insurance activity. esecurityplanetesecurityplanet

Hosted Email Server 5644

CEVA Logistics customers exposed across Europe

A cyberattack exposed CEVA Logistics customer information across Europe, including names, addresses, contact information, and order data. Security researchers warn the stolen records are ideal material for convincing delivery-related phishing and smishing scams, since scammers can reference real order details. Stolen customer data can fuel highly targeted phishing attacks, making robust email security and authentication increasingly important. esecurityplanet

Levi Strauss hit by social engineering attack

Attackers compromised three Levi Strauss employee computers and exposed corporate data through a social engineering breach. The denim giant says it contained the intrusion without customer or operational impact, though the full scope is still under investigation. esecurityplanet

Trezor discloses breach tied to shipping partner

Hardware wallet maker Trezor disclosed a breach affecting nearly 14,000 customers after its shipping and logistics provider, ShipMonk, was hacked. Attackers accessed customer names, shipping addresses, emails, and phone numbers for orders placed between May and August, impacting buyers across the US, UK, Sweden, Colombia, Brazil, Italy, and Portugal. Privacy Guides

Framework notifies “all customers” of a data breach

Computer maker Framework told its entire customer base that hackers accessed names, email addresses, phone numbers, and physical addresses in a recent breach another entry in a growing string of attacks against hardware and electronics companies this year. Privacy Guides

Wesco investigates cybersecurity incident

Global supply chain and distribution company Wesco confirmed it’s investigating a cybersecurity incident, adding to a notable spike in attacks against logistics and supply-chain firms this month. Privacy Guides

Cisco firewalls actively exploited in the wild

Attackers are actively exploiting a Remote Access SSL VPN vulnerability affecting Cisco ASA and FTD devices, allowing unauthenticated attackers to remotely restart vulnerable devices and trigger denial-of-service conditions. Cisco has released patches, and there’s no workaround, so organizations need to update immediately and watch for unexplained device restarts. esecurityplanetesecurityplanet

Apple patches macOS zero-day already being exploited for crypto mining

A recently patched macOS flaw a critical authentication issue in the Screen Sharing component (CVSS 9.8) is already being exploited in the wild to deploy cryptocurrency miners, according to a warning from the Netherlands’ national cyber security centre. Apple fixed it via an emergency update earlier this month covering macOS Tahoe, Sequoia, and Sonoma. The Hacker News

Spf Record 7604

New technique lets attackers hijack Chrome and Edge sessions

Researchers detailed a post-exploitation technique that enables the Chrome DevTools Protocol inside a running Chrome or Edge process on Windows, letting an attacker who already has code execution steal cookies, saved data, and authenticated browser sessions without exploiting a new browser vulnerability. The Hacker News

China-linked group swaps ransomware strains

Storm-1175, a China-linked threat actor, has transitioned from using Medusa ransomware to a new C++ strain called StormEncryptor, likely gaining initial access by exploiting a flaw in N-able N-central. Substack

VMware vCenter flaw exploited across dozens of countries

Threat actors are actively exploiting a critical directory traversal vulnerability in VMware vCenter that allows remote code execution, with one advanced persistent threat actor reportedly targeting over 360 IP addresses across 47 countries using a reverse shell framework to maintain persistence. Substack

Spf Record Generator 7061

Apple warns iPhone users of mercenary spyware targeting

Apple sent a new batch of high-confidence threat notifications on August 13 to iPhone users targeted by sophisticated mercenary spyware, the kind of alert typically reserved for high-profile individuals like journalists and politicians. Apple is urging recipients to enable Lockdown Mode and verify alerts only through account.apple.com, since scammers have been known to spoof these warnings too. Substack

ClickFix malware campaign now specifically targets Macs

More than 250 malicious domains are using browser fingerprinting to identify Mac visitors and serve them fake “fix it” prompts that trick them into running commands that install Atomic Stealer or MacSync malware while showing harmless content to researchers and scanners.eSecurity Planet

Ransomware gangs increasingly target managers and executives

A Zscaler report found that 62% of identified ransomware victims held manager-level roles or higher, and 75% worked in critical business functions like finance, sales, and operations a sign that attackers are deliberately going after employees with broad access and decision-making power, not just IT admins. eSecurity Planet

Spf Validator 7800

Suspected Wi-Fi attack disrupts Delta flight full of DEF CON hackers

A Delta flight carrying attendees leaving the DEF CON security conference experienced a roughly 30-minute Wi-Fi outage, suspected to be caused by a rogue access point or deauthentication attack. Delta says aircraft systems and passenger safety were unaffected, and the incident remains under investigation a fittingly ironic story for hacker-conference season.eSecurity Planet

Royal Navy drone cameras caught phoning home to China

A UK defense security assessment detected unexpected network traffic from Royal Navy drone cameras to a Chinese IP address. Investigators found no evidence of an actual compromise, but officials disconnected the devices’ internet access as a precaution reviving concerns about supply-chain risk in connected hardware. eSecurity Planet

Brad Slavin
Brad Slavin

General Manager

General Manager at DuoCircle. Product strategy and commercial lead across the email security portfolio.

Secure your email infrastructure

Protect, authenticate, and deliver. Contact our team to find the right solution.