
OCC fines American Express Bank $350 million
The OCC fined American Express National Bank $350 million for BSA and AML failures after delays in reporting suspicious activity.
Oct 9, 2026 · 2 min
Up-to-date cyber intelligence coverage. Filter by category or browse the full archive.

The OCC fined American Express National Bank $350 million for BSA and AML failures after delays in reporting suspicious activity.
Oct 9, 2026 · 2 min

Vicksburg, Mississippi, temporarily shut down municipal systems after a ransomware attack. Emergency services stayed online.
Oct 6, 2026 · 2 min

The United States sanctioned 10 people and entities tied to a financial network linked to Tren de Aragua, accused of ATM hacks.
Oct 5, 2026 · 2 min

Wallstreet claimed an attack on Gibson Area Hospital in Illinois. FalconFeeds said 600 GB may have been exfiltrated.
Oct 4, 2026 · 3 min

S.3315 cleared the Senate unanimously and heads to the House. The bill adds rural hospital grants and security upgrades.
Oct 4, 2026 · 4 min

FBI, CISA and EPA flagged attacks on U.S. critical infrastructure, including water systems and tankers, plus exposed utility credentials.
Oct 3, 2026 · 3 min

Stevens Point says it stopped a ransomware attempt before data was stolen. Columbus is still in court over a 2024 data breach.
Oct 2, 2026 · 2 min

Sen. Kirsten Gillibrand reintroduced the Data Protection Act to create a federal privacy agency and regulate data
Oct 2, 2026 · 2 min

Cloudflare fixed a Containers isolation flaw that could expose residual data between customers. UpGuard also found thousands of exposed Supabase databases.
Oct 1, 2026 · 3 min

The Alturas, California hospital said an unauthorized actor accessed its systems and downloaded files. The number of affected people was not disclosed.
Sep 30, 2026 · 1 min

The guide urges tighter remote access controls, stronger contracts, and manual operations for critical infrastructure using third-party ICS integrators.
Sep 29, 2026 · 3 min

Emperador added OnTrac and Electrolux to its leak site, claiming $1 million and up to 75.1 MB of exfiltrated data.
Sep 28, 2026 · 2 min

The Senate advanced bipartisan telecom bills on voluntary certification and an NTIA working group to set cybersecurity best practices.
Sep 26, 2026 · 3 min

The OCC reorganized its cyber supervision program for national banks and federal savings associations without adding new requirements.
Sep 25, 2026 · 2 min

ECUCERT flagged three exploited CVEs in MikroTik RouterOS. Taiwan's NICS-TW and the Dutch DIVD also reported active attacks.
Sep 24, 2026 · 3 min

IBM found that one in five cyberattacks in Latin America over the past year was facilitated by AI.
Sep 23, 2026 · 3 min

Warner and Wyden reintroduced a bill to set mandatory health cyber standards, with audits, continuity plans and $1.3 billion.
Sep 23, 2026 · 2 min

Grafton City Hospital notified 1,215 people after a phishing-linked breach. Cedar County Memorial is still investigating a possible data exposure.
Sep 22, 2026 · 3 min

ZeroHour added new Qilin victims in Mexico, Chile, Argentina and Trinidad and Tobago. Panzer also listed Brazil’s K3G Solutions.
Sep 22, 2026 · 2 min

Treasury is pushing banks to file more SARs on cyberfraud and added a keyword to flag possible scam centers.
Sep 21, 2026 · 4 min

Congress moves on data privacy and incident reporting, while CISA’s CIRCIA rule remains pending and could affect cross-border operations.
Sep 21, 2026 · 4 min

CISA said ransomware is exploiting a critical VMware vCenter flaw, while reports point to victims and active campaigns in Latin America.
Sep 20, 2026 · 2 min

The House passed the Ratepayer Protection Act 417-3 as Congress moved on AI bills covering data centers, fraud, frontier models
Sep 19, 2026 · 4 min

Sutton and Fort Smith reported ransomware incidents tied to Global and Interlock. Both cities said the attacks were contained.
Sep 18, 2026 · 2 min

The Treasury asked banks to improve suspicious activity reports tied to cyber scams and added a SAR keyword after losses near $13 billion.
Sep 18, 2026 · 3 min

CIRCIA could take effect in late 2026 or early 2027, while Congress weighs bills that would require AI reporting
Sep 17, 2026 · 3 min

A former IT administrator said a foreign ransomware attack hit Eudora and the Douglas County sheriff’s office. The attribution is unconfirmed.
Sep 16, 2026 · 2 min

The U.S. Treasury asked banks and fintechs to step up cyberfraud reporting, citing losses of nearly $13 billion since 2023.
Sep 16, 2026 · 4 min

Anthropic said it blocked Claude from surveillance, fraud and weapons uses, while Unit 42 reported commercial AI attacks in Latin America.
Sep 15, 2026 · 3 min

Congress faces CISA deadlines and new bills on cyber threat sharing, federal surveillance and health data.
Sep 15, 2026 · 3 min

Nutex Health told the SEC a third party posted data allegedly taken from its network and said it found no material business or reporting impact.
Sep 13, 2026 · 2 min

CISA added seven vulnerabilities to the KEV, including active exploitation in SonicWall SMA 1000, Kestra OSS, LiteLLM and Sangoma Switchvox.
Sep 12, 2026 · 3 min

The OCC said public comments are due 60 days after Federal Register publication. The proposal moves ahead with the Fed
Sep 12, 2026 · 4 min

The OCC keeps a 36-hour reporting rule for banks and foreign branches in the U.S., as CIRCIA and NYDFS add pressure.
Sep 11, 2026 · 4 min

Congress is weighing bills on AI chatbots, autonomous agents, maritime cybersecurity and health care resilience, with compliance implications.
Sep 11, 2026 · 2 min

Security Arsenal detected 11 new INCRANSOM victims in five days, with cases in the U.S.
Sep 10, 2026 · 4 min

The House is moving on child privacy, smart meter data, and AI agent security through three federal bills.
Sep 9, 2026 · 3 min

Dallas Fed says generative AI and AI agents belong inside existing bank risk frameworks.
Sep 9, 2026 · 4 min

DaVita, Cornerstone Behavioral Healthcare and Alta Orthopaedics reported breaches tied to ransomware. Nutex Health was also claimed.
Sep 8, 2026 · 3 min

HIPRA and new House bills on smart meters, data brokers, water and platform liability move forward in Congress.
Sep 8, 2026 · 3 min

CISA added CVE-2026-81578, CVE-2026-82078, and CVE-2026-82329 to KEV after active exploitation in PaperCut
Sep 6, 2026 · 2 min

U.S. proposed a special measure on Banque Misr UAE and clarified SAR, cybersecurity and bank board expectations.
Sep 6, 2026 · 2 min

KRYBIT added 14 victims in 24 hours across 9 countries and more than 8 sectors, while CYFIRMA added Colombia and Chile as targets.
Sep 4, 2026 · 4 min

The House passed the NDO Fairness Act and extended CISA 2015 through Dec. 11. Health, network security and minors bills also moved.
Sep 4, 2026 · 3 min

Greenberg Traurig appeared in multiple leak posts, but there is no official verification of a breach or of who was behind it.
Sep 4, 2026 · 2 min

The U.S. Treasury formed a public-private group to prepare finance for post-quantum cryptography, without immediate new rules.
Sep 3, 2026 · 3 min

The Justice Department said several named agencies were targets, not confirmed victims, in a campaign attributed to QTFY.
Sep 3, 2026 · 3 min

KRYBIT, LOCKBIT5, and INC Ransom added new victims, with most activity centered on the United States and fresh listings in 48 and 24 hours.
Sep 2, 2026 · 3 min

Microsoft found real intrusions in LiteLLM, RAGFlow and Kestra used to steal AI keys, access containers and mine crypto.
Aug 31, 2026 · 3 min

The OCC and FDIC raised the bar for unsafe or unsound findings and standardized the MRA threshold.
Aug 31, 2026 · 3 min