HeadFlash

Security

Sakura Internet breach may expose 1.36 million accounts

Japanese cloud provider Sakura Internet says hackers accessed its sales system, potentially compromising up to 1.36 million member accounts.

Listen

This edition was produced with artificial intelligence. Text and voice are generated automatically.

Sakura Internet breach may expose 1.36 million accounts

Japanese cloud and data center provider Sakura Internet disclosed that hackers accessed its sales management system, where customer contract and membership information is stored. The company said the incident may have impacted up to 1,360,563 member accounts, though the exact number remains to be determined as the investigation continues. The attack occurred on August 9 and was discovered during the investigation of a separate breach at the Sakura Rental Server service, which involved unauthorized logins to 583 accounts and installation of malware on Sakura’s systems.

Sakura Internet hack exposes data of up to 1.36 million accounts →

Ukraine’s asset agency hacked days before $165M IDS Ukraine deadline

Ukraine’s Asset Recovery and Management Agency (ARMA) confirmed on August 18, 2026, that its servers had been struck by unauthorized intrusion. The disclosure came days before the August 22 deadline for applications to a competition to award independent management of IDS Ukraine, a bottled water conglomerate linked to sanctioned Russian billionaire Mikhail Fridman. IDS Ukraine produces the Morshynska, Myrhorodska, Alaska, and Aqua Life water brands and reported UAH 7.4 billion (approximately $165 million) in revenue in 2025.

Russia’s GRU Hacked Ukraine’s Sanctioned-Asset Agency Days Before $165M Deadline →

Apple patches 29 flaws across iPhone, iPad, and Mac

Apple released iOS 26.6.1, iPadOS 26.6.1, and macOS Tahoe 26.6.2 on Monday, patching nearly 30 security vulnerabilities across iPhones, iPads, and Macs. The update is Apple’s third security release in three weeks, a pace the company attributes partly to AI tools uncovering bugs faster than its traditional software release cycle can absorb. Of the 29 CVEs documented on Apple’s security support page, 21 are WebKit-related, the browser engine powering Safari. Nine of the credited discoveries come from OpenAI Codex Security.

Apple Just Fixed 29 Security Flaws Across iPhone, iPad, and Mac, Including One That Could Expose Your Network Traffic to Attackers →

ClarityCheck exposed millions of face photos in unsecured database

ClarityCheck, a facial-identification service, left millions of face photos publicly exposed on the internet. Security researcher Jeremiah Fowler told Wired he discovered a publicly exposed database that was neither password-protected nor encrypted, containing approximately 9,042,977 image files totaling 450.2GB of data. The exposed records consisted primarily of facial images stored in folders labeled faces and profiles. In a limited sample, Fowler observed facial images of adults, teens, and children.

ClarityCheck people-finder left millions of face photos exposed, likely without their knowledge →

Medusa ransomware hit over 500 critical infrastructure orgs

The Cybersecurity and Infrastructure Security Agency (CISA) said Tuesday that the Medusa ransomware gang has breached more than 500 critical infrastructure organizations in the United States since June 2021. This was revealed in a joint advisory coordinated with the Department of Health and Human Services (HHS) and the Federal Bureau of Investigation (FBI). As of April 2026, Medusa actors have impacted more than 500 victims across multiple critical infrastructure sectors, including Healthcare and Public Health, Defense Industrial Base, Critical Manufacturing, Government Services and Facilities, Information Technology, and Financial Services.

CISA: Medusa ransomware hit over 500 critical infrastructure orgs →