Cybersecurity Today

Major US Bank Data Linked Through Breach At SitusAMC

Nov 26, 2025
A major security breach at Ascensus has US banks on alert, with the ALFV ransomware gang claiming a staggering three terabytes of stolen data. Broadcom is under attack from CLOP via vulnerabilities in Oracle’s system. In a twist, malicious Blender 3D files are now delivering stealthy SteelC malware. The JavaScript ecosystem isn't safe either, as Shai-Hulud compromises 500 NPM packages. Additionally, a deceptive phishing campaign is targeting Microsoft users with look-alike domains.
Ask episode
AI Snips
Chapters
Transcript
Episode notes
INSIGHT

Major Vendor Data-Theft Creates Uncertainty

  • Ascensus confirmed a data-theft incident where attackers stole three terabytes but did not encrypt systems.
  • Jim Love said banks and investigators are still assessing what was taken and who may be affected.
INSIGHT

High-Profile ERP Flaws Fuel Public Shaming

  • CLOP added Broadcom to its leak site amid an Oracle E-Business Suite zero-day campaign.
  • Jim Love noted Oracle issued a patch and many organizations likely applied it already.
INSIGHT

3D Models Becoming Silent Malware Carriers

  • Blender model files with auto-run Python scripts are delivering SteelC info-stealer to creators.
  • Jim Love warned that enabled auto-run plus shared model repositories makes creative workflows a supply-chain risk.
Get the Snipd Podcast app to discover more snips from this episode
Get the app