
Cybersecurity Today Major US Bank Data Linked Through Breach At SitusAMC
Nov 26, 2025
A major security breach at Ascensus has US banks on alert, with the ALFV ransomware gang claiming a staggering three terabytes of stolen data. Broadcom is under attack from CLOP via vulnerabilities in Oracle’s system. In a twist, malicious Blender 3D files are now delivering stealthy SteelC malware. The JavaScript ecosystem isn't safe either, as Shai-Hulud compromises 500 NPM packages. Additionally, a deceptive phishing campaign is targeting Microsoft users with look-alike domains.
AI Snips
Chapters
Transcript
Episode notes
Major Vendor Data-Theft Creates Uncertainty
- Ascensus confirmed a data-theft incident where attackers stole three terabytes but did not encrypt systems.
- Jim Love said banks and investigators are still assessing what was taken and who may be affected.
High-Profile ERP Flaws Fuel Public Shaming
- CLOP added Broadcom to its leak site amid an Oracle E-Business Suite zero-day campaign.
- Jim Love noted Oracle issued a patch and many organizations likely applied it already.
3D Models Becoming Silent Malware Carriers
- Blender model files with auto-run Python scripts are delivering SteelC info-stealer to creators.
- Jim Love warned that enabled auto-run plus shared model repositories makes creative workflows a supply-chain risk.
