Critical

Canadian Man Pleads Guilty in Snowflake Extortions

Krebs on Security
Actively Exploited

Overview

Connor Riley Moucka, a 26-year-old from Kitchener, Ontario, has pleaded guilty to serious charges related to hacking and extorting over 165 organizations using Snowflake, a cloud data storage provider. His actions also included stealing call and text history records for more than 100 million AT&T customers. This case highlights the significant risks associated with cloud services and the potential for large-scale data breaches. The guilty plea marks a pivotal moment in addressing cybercrime, as it demonstrates the legal consequences of such actions. Organizations that rely on cloud storage must remain vigilant about their security measures to protect sensitive data from similar attacks.

Key Takeaways

  • Active Exploitation: This vulnerability is being actively exploited by attackers. Immediate action is recommended.
  • Affected Systems: Snowflake, AT&T
  • Action Required: Organizations should enhance security protocols, including regular audits and user access reviews, to prevent unauthorized access to data.
  • Timeline: Ongoing since 2024

Original Article Summary

A 26-year-old Canadian man once described as one of the most consequential cybercrime threat actors of 2024 has pleaded guilty to computer fraud and conspiracy to hack and extort more than 165 organizations that used the cloud data storage provider Snowflake. Connor Riley Moucka, of Kitchener, Ontario, also admitted to stealing call and text history records of more than 100 million AT&T customers.

Impact

Snowflake, AT&T

Exploitation Status

This vulnerability is confirmed to be actively exploited by attackers in real-world attacks. Organizations should prioritize patching or implementing workarounds immediately.

Timeline

Ongoing since 2024

Remediation

Organizations should enhance security protocols, including regular audits and user access reviews, to prevent unauthorized access to data.

Additional Information

This threat intelligence is aggregated from trusted cybersecurity sources. For the most up-to-date information, technical details, and official vendor guidance, please refer to the original article linked below.

Related Topics: This incident relates to Data Breach.

Related Coverage

Researcher Claims Control of ChatGPT Secure Sandbox

darkreading

At Black Hat USA 2026, a researcher showcased a proof-of-concept attack that allowed remote control over ChatGPT's secure sandbox environment. This demonstration raised concerns about the potential for unauthorized manipulation of AI systems, particularly in isolated environments that are designed to be secure. The attack chain exhibited how an attacker could gain command-and-control access during a live session, which could have serious implications for users relying on AI for various applications. As AI technologies become increasingly integrated into business and personal use, ensuring their security against such vulnerabilities is crucial. The findings indicate a need for AI developers to strengthen sandbox environments to prevent similar exploits in the future.

Aug 6, 2026

Hedge fund cyberattacks tied to BlackFile-linked UNC6671 extortion group

BleepingComputer

A series of cyberattacks has recently targeted hedge funds, private equity firms, and other financial institutions, with investigators linking these incidents to a group known as UNC6671. This group is reportedly connected to the BlackFile threat actors, who are known for their extortion tactics. The attacks have raised concerns among financial organizations, as they not only risk sensitive data breaches but also threaten the financial stability of the affected companies. As attackers become more sophisticated in their methods, firms in the finance sector are being urged to bolster their cybersecurity measures and remain vigilant against potential threats. Understanding the tactics used by these groups is crucial for organizations to protect themselves from future incidents.

Aug 6, 2026

New Zapscape KVM Flaw Could Let Privileged L1 Guest Code Escape to Linux Hosts

The Hacker News

A newly discovered vulnerability in the Zapscape Linux kernel, tracked as CVE-2026-64561, poses a significant risk to systems using KVM (Kernel-based Virtual Machine) technology. This flaw allows attackers with kernel privileges in an L1 guest virtual machine to potentially escape the isolation that KVM provides, enabling them to execute arbitrary code on the host system. The issue primarily arises when nested virtualization is deployed with untrusted guests, which increases the likelihood of exploitation. As companies and organizations increasingly rely on virtualized environments, this vulnerability underscores the need for vigilance in managing and securing these systems to prevent unauthorized access and potential breaches.

Aug 6, 2026

TeamPCP Traced Back to 2020 Cryptojacking Operation

Infosecurity Magazine

Oligo Security has traced TeamPCP back to a cryptojacking operation that has been active since 2020. This group has been linked to the ShadowRay 2.0 malware, which is designed to hijack computing resources for cryptocurrency mining without the owner's consent. The researchers' findings indicate that the infrastructure used by TeamPCP has been operating for several years, raising concerns about the long-term impact on affected systems. Users and organizations need to be vigilant, as cryptojacking can lead to degraded system performance and increased energy costs. Understanding the history and tactics of such groups is crucial for improving defenses against these types of cyber threats.

Aug 6, 2026

How AI Exposed a Browser Security Gap that Enterprises Cannot Ignore

BleepingComputer

A recent analysis by Skyhigh Security reveals that artificial intelligence has brought attention to existing security vulnerabilities in web browsers, rather than creating new ones. As organizations increasingly rely on browsers for data management and AI interactions, these vulnerabilities pose significant risks. Browsers are now seen as essential points for controlling data flow, which means any weaknesses can lead to data leaks or breaches. Companies need to reassess their browser security measures to protect sensitive information, especially as remote work continues to be prevalent. This situation underscores the importance of proactive security practices in the face of evolving technology.

Aug 6, 2026

Zero-Click AI Browser Hacking: Claude and ChatGPT Atlas Hijacked via Emails, X Posts

SecurityWeek

Researchers at Zenity have identified a serious vulnerability affecting AI browser applications, specifically Anthropic's Claude and OpenAI's ChatGPT Atlas. This issue allows attackers to hijack these platforms through seemingly harmless emails and posts on social media, particularly X (formerly Twitter). Despite reporting their findings to the companies involved in late 2025 and early 2026, the vulnerabilities remain unpatched, putting users at risk. This situation raises concerns about the security of AI tools that many people rely on for various tasks. Users of these applications should be cautious and stay informed about potential exploits until a fix is implemented.

Aug 6, 2026