News

Cybersecurity News & Audit Summaries

Current events, industry audit reports, compliance watch updates, and technology alerts. By industry · National audits · Breach trackers · MFA directory · State collections: Texas · Florida · California · Illinois · New York · Pennsylvania — showing latest 30 of 790

Instant audit

Run a free scan at audit.emailmenow.com, then unlock the full technical report with remediation plan and compliance evidence for $99.

Run free audit
An isolated federal workstation unplugged from a network switch after a major-incident notice
Cybersecurity Alert
August 30, 2026 by EmailMeNow IT Consulting

ATF Confirms a Major Incident on a Standalone System — Qilin Claimed It, Without Samples

ATF confirmed a major incident on a standalone system holding investigation-target data. Qilin listed the bureau without samples; ATF has not attributed the actor. Audits (ideal 100%): atf.gov 66%, justice.gov 66%, login.gov 63%, eforms.atf.gov 43%. eForms MFA: password + PIN, no YubiKey.

NewsRansomwareATFDOJQilinMFAYubiKeyAuthenticator AppsCybersecurity
Read Update
Multi-source breach data week of August 30, 2026
Cybersecurity Alert
August 30, 2026 by EmailMeNow IT Consulting

Breach Data Week of August 30, 2026: Texas, HIBP, SEC & HHS Updates

Multi-source breach data week of August 30, 2026: Texas OAG, HHS OCR, SEC Form 8-K, HIBP, and state AG trackers. Texas YTD reports +8 (418 → 426). 7 companies/entities from source roundups.

CybersecurityData BreachTexasHave I Been PwnedHHS OCRSECForm 8-K
Read Update
Phone hovering over a restaurant tap-to-pay terminal beside a chargeback dispute letter
Cybersecurity Alert
August 30, 2026 by EmailMeNow IT Consulting

Montrose Restaurant Ate $5,000+ in Tap-to-Pay Chargebacks After Stolen Cards Hit Wallets

Leighton’s in Montrose absorbed 30–45 tap-to-pay chargebacks after stolen cards were loaded onto phones. Audits (ideal 100%): apple.com 69%, intezer.com 63%, toasttab.com 42%, leightonshtx.com 33%. Toast Web: Google Authenticator yes, YubiKey not documented.

NewsPhishingPaymentsSmall BusinessMFAYubiKeyAuthenticator AppsCybersecurity
Read Update
Darkened municipal workstations after a ransomware incident, with a printed notice on the desk
Cybersecurity Alert
August 30, 2026 by EmailMeNow IT Consulting

Norcross Confirmed Ransomware on August 1 — Residents Heard Weeks Later

City of Norcross confirmed ransomware on Aug 1, 2026; public notice came late August. Data exposure, actor, and ransom still undisclosed. Audits (ideal 100%): norcrossga.net 60%, gwinnettcounty.com 57%, civicplus.com 43%. CivicPlus: Google Authenticator yes, YubiKey not documented.

NewsRansomwareLocal GovernmentPhishingMFAYubiKeyAuthenticator AppsCybersecurity
Read Update
Hospital waiting-room table with a phone showing a fake Medicare Kit lure and a printed notice that no such program exists
Cybersecurity Alert
August 30, 2026 by EmailMeNow IT Consulting

Pennsylvania AG Warns MyChart Users About Fake “Medicare Kit” Phishing

AG Dave Sunday warned Aug 28 that a MyChart Medicare Kit does not exist. Officials describe impersonation, not a MyChart platform hack. Audits (ideal 100%): attorneygeneral.gov 78%, epic.com 69%, pennmedicine.org 58%, mychart.org 54%. Epic MFA: authenticator yes, YubiKey not named.

NewsPhishingMyChartHealthcarePennsylvaniaMFAYubiKeyAuthenticator AppsCybersecurity
Read Update
Laptop search results for a bank login with a suspicious lookalike URL ranked above the real site
Cybersecurity Alert
August 26, 2026 by EmailMeNow IT Consulting

Chameleon SEO Poisoning: Fake Bank Login Pages Rank in Google and Bing

Fortra FIRE reports a 40% Q2 2026 surge in Chameleon SEO poisoning — cloaked fake bank login pages that rank in Google and Bing but play dead to scanners. Audits (ideal 100%): texascapitalbank.com 85%, chase.com 79%, fortra.com 64%, bankofamerica.com 53% — 0/11 at 100%. Bank of America documents YubiKey; none advertise Google Authenticator.

NewsPhishingSEO PoisoningBanksMFAYubiKeyAuthenticator AppsGoogleBingCybersecurity
Read Update
Operations-room laptops showing a generic domain marked taken down, with a muted U.S. flag in the background
Cybersecurity Alert
August 26, 2026 by EmailMeNow IT Consulting

DOJ and FBI Seize QTFY Platforms Used Against NASA, the Fed, and the Senate

DOJ and FBI seized domains hard-coded into China-nexus QScan and QTRouter platforms used against NASA, the Federal Reserve, DOJ, and the U.S. Senate. Audits (ideal 100%): nih.gov 78%, energy.gov 73%, nsa.gov 55% — 0/11 at 100%. Login.gov documents YubiKey and authenticator apps.

NewsFBIDOJNASAMFAYubiKeyAuthenticator AppsCybersecurity
Read Update
Cinematic consumer-lender storefront at night with a cloud-warning overlay asking whether Heights Finance was breached
Cybersecurity Alert
August 24, 2026 by EmailMeNow IT Consulting

Was Heights Finance Breached? We Scanned Their Domain Security

Heights Finance confirmed a May 2026 third-party cloud incident. Texas OAG lists 734,828 Texans. Audits (ideal 100%): heightsfinance.com 60%. MyAccount login is cell-phone only — no YubiKey or Google Authenticator.

NewsData BreachFinancialMFAPhishingTexasSouth CarolinaCybersecurity
Read Update
Split cybersecurity cover of a cracked Windows shield labeled ShieldBreak and a phone photo icon labeled ImageIO
Cybersecurity Alert
August 24, 2026 by EmailMeNow IT Consulting

ShieldBreak and Apple ImageIO: We Scanned Microsoft and Apple Domain Security

Microsoft Defender ShieldBreak (CVE-2026-69414) is still unpatched. Apple fixed ImageIO CVE-2026-65346 in iOS 26.6.1. Audits (ideal 100%): microsoft.com 71%, apple.com 69%. Microsoft and Apple Accounts document YubiKey; Apple does not document Google Authenticator.

NewsMicrosoftAppleDefenderVulnerability DisclosureMFAPhishingCybersecurity
Read Update
Multi-source breach data week of August 23, 2026
Cybersecurity Alert
August 23, 2026 by EmailMeNow IT Consulting

Breach Data Week of August 23, 2026: Texas, HIBP, SEC & HHS Updates

Multi-source breach data week of August 23, 2026: Texas OAG, HHS OCR, SEC Form 8-K, HIBP, and state AG trackers. Texas YTD reports +14 (404 → 418). 18 companies/entities from source roundups.

CybersecurityData BreachTexasHave I Been PwnedHHS OCRSECForm 8-K
Read Update
CVE tickets flooding an AI research console beside a locked remote-access door still using a stolen password
Cybersecurity Alert
August 22, 2026 by EmailMeNow IT Consulting

Beazley Q2 2026: Agentic AI Flooded CVE Lists — Ransomware Still Starts With Stolen Passwords

Beazley Security’s Q2 2026 threat report: disclosed CVEs +36%, CISA KEV +10%, but 67% of ransomware still starts with stolen VPN/RDP passwords. Device-code phishing beats MFA. Audits (ideal 100%): hackerone.com 88%, nist.gov 84%, beazley.security 78% — none at 100%.

NewsArtificial IntelligenceRansomwareMFAPhishingBECCyber InsuranceCybersecurity
Read Update
Empty university lecture hall with dark monitors and a first-day-delayed sign
Cybersecurity Alert
August 22, 2026 by EmailMeNow IT Consulting

UTSA Delayed Fall Classes After “Attempted Unauthorized Activity” — Not a Confirmed Data Breach

UT San Antonio detected attempted unauthorized activity at the network edge, took systems offline, and delayed fall classes to Aug 24. No evidence of data theft. Audits (ideal 100%): utsa.edu 70%, passphrase.utsa.edu 34%. Duo recommends YubiKey; Google Authenticator not documented.

NewsEducationTexasSan AntonioOutageMFAPhishingCybersecurity
Read Update
Laptop inbox showing a suspicious new-login email from a lookalike social-support address
Cybersecurity Alert
August 17, 2026 by EmailMeNow IT Consulting

FBI: Lookalike Support Emails and Stolen MFA Codes Unlock Social Accounts

FBI PSA 2026-08-10: phishing lookalike domains and fake support texts steal MFA codes to take over social accounts. Audits (ideal 100%): ic3.gov 87%, instagram.com 80%, google.com 55%. Instagram MFA Pass; Facebook Strong.

NewsPhishingMFAFBIInstagramPasskeysYubiKeyAuthenticator AppsCybersecurity
Read Update
Person on a phone call with an Android install-unknown-app prompt on screen
Cybersecurity Alert
August 17, 2026 by EmailMeNow IT Consulting

WindRelay: A 13-Minute Bank Call Sideloads Android Malware and Relays Your Card

Group-IB: SpyNote RAT plus WindRelay NFC relay in a live bank-impersonation call. Sideload is the install. Audits (ideal 100%): chase.com 79%, malwarebytes.com 71%, bankofamerica.com 53%. YubiKey does not stop a RATted phone.

NewsSocial EngineeringAndroidBanking FraudMFAYubiKeyAuthenticator AppsCybersecurity
Read Update
Multi-source breach data week of August 16, 2026
Cybersecurity Alert
August 16, 2026 by EmailMeNow IT Consulting

Breach Data Week of August 16, 2026: Texas, HIBP, SEC & HHS Updates

Multi-source breach data week of August 16, 2026: Texas OAG, HHS OCR, SEC Form 8-K, HIBP, and state AG trackers. Texas YTD reports +22 (382 → 404). 21 companies/entities from source roundups.

CybersecurityData BreachTexasHave I Been PwnedHHS OCRSECForm 8-K
Read Update
Hospital nurses station with paper charts while computer monitors sit dark during a network downtime
Cybersecurity Alert
August 15, 2026 by EmailMeNow IT Consulting

JPS Health Network Took Systems Offline After “Suspicious Activity” — EHR Back, MyChart Still Down

Fort Worth’s JPS Health Network isolated systems Aug 3 after suspicious activity. EHR returned Aug 15; MyChart stayed down. Audits (ideal 100%): jpshealthnet.org 33% (Identity 0%); jpshealth.org 58%. MyChart MFA: SMS/email OTP, passkeys on login, no documented YubiKey.

NewsHealthcareTexasFort WorthOutageMFAMyChartCybersecurity
Read Update
Airplane cabin at night with a rogue Wi-Fi hotspot and a fake login on a passenger laptop
Cybersecurity Alert
August 14, 2026 by EmailMeNow IT Consulting

Delta Flight 591: Rogue In-Flight Wi-Fi After DEF CON — Phishing, Not a Plane Hack

Delta Flight 591 (LAS–ATL, Aug 10) carried a rogue “Delta WiFi Fast” network after DEF CON 34. Delta says aircraft systems were not hacked. Domain audits (ideal 100%): defcon.org 79%; viasat.com 77%; delta.com 70%; google.com 52% — none at 100%. SkyMiles MFA: SMS/email OTP, no YubiKey or Google Authenticator.

NewsAirlinesWi-FiPhishingMFATravel SecurityCybersecurity
Read Update
Multi-source breach data week of August 9, 2026
Cybersecurity Alert
August 9, 2026 by EmailMeNow IT Consulting

Breach Data Week of August 9, 2026: Texas, HIBP, SEC & HHS Updates

Multi-source breach data week of August 9, 2026: Texas OAG, HHS OCR, SEC Form 8-K, HIBP, and state AG trackers. Texas YTD reports +12 (370 → 382). 10 companies/entities from source roundups.

CybersecurityData BreachTexasHave I Been PwnedHHS OCRSECForm 8-K
Read Update