Welcome back, security sleuths.
This week's edition packs loads of action. And lots of heartache.
We've got luxury cars held hostage by hackers, tech giants actually fighting back against cybercriminals, and a sobering reminder that even your data protectors aren't safe from being breached themselves.
Plus, there's a hidden surprise tucked away in this issue for eagle-eyed readers who make it to the end.
But first, the urgent stuff: Google just patched an actively exploited zero-day vulnerability in Chrome (CVE-2025-10585). If you haven't updated your browser in the last 48 hours, do it now. Seriously, close this email and update Chrome before you forget. The attackers are already using this one in the wild.
Now, let's dive into the chaos.
TransUnion, one of the three major credit bureaus that millions rely on to monitor their financial identity, suffered a massive data breach affecting over 4.4 million customers. The attack exploited vulnerabilities in third-party platforms, including Salesforce integrations, to access sensitive personal information, including Social Security numbers, birth dates, and personal data used in credit monitoring. (However, not the credit reports themselves.)
Key Insights:
The incident highlights a troubling pattern in cybersecurity: supply chain attacks are becoming the weapon of choice for sophisticated hackers. Rather than attacking well-defended primary targets directly, criminals are exploiting weaker links in the technology ecosystem, particularly cloud platforms and third-party integrations that companies like TransUnion depend on. These attacks are more complex to detect and can spread across multiple organizations before anyone notices.
Why This Matters For You:
For the millions who signed up for credit monitoring after previous data breaches, this creates a cruel irony. The very service designed to protect your identity from cybercriminals became another source of exposure. It's a stark reminder that in our interconnected digital economy, your personal data is only as secure as the weakest link in the chain. That chain keeps getting longer every year.
Read More on CNET.
PS: I trusted TransUnion to protect my data after a previous breach. Only to become one of their 4.4 million victims myself. Read on for the whole story.
Microsoft and Cloudflare joined forces this week to dismantle RaccoonO365, a massive "phishing-as-a-service" operation. The takedown, which included a court-ordered seizure of 338 websites, has deactivated a criminal enterprise that was helping even low-skilled hackers steal login credentials from thousands of organizations worldwide. RaccoonO365 had been operating like a twisted startup, offering subscription-based phishing kits for as little as $355 a month. Its service has generated at least $100,000 in revenue while targeting everyone from small businesses to primary healthcare providers.
Key Insights:
The takedown represents a rare and critical example of major tech companies working together proactively rather than just reacting to attacks after the damage is done. Microsoft used its threat intelligence network to identify the operation, while Cloudflare leveraged its position as a primary internet infrastructure provider to cut off the criminals' access to key services. The coordinated effort disabled over 300 malicious domains and disrupted a network that was processing thousands of stolen credentials daily.
Why This Matters For You:
This collaborative approach could signal a new era in cybersecurity defense, where the most prominent players in tech stop treating cybercrime as someone else's problem. Instead of just teaching people to spot fake emails, the industry is finally going after the factories that mass-produce them. Microsoft's investigation, which came about by an operational security lapse that exposed a cryptocurrency wallet, led them to identify the alleged leader as Joshua Ogundipe, a Nigerian national. They have since issued a criminal referral for him to international law enforcement.
Read More on Microsoft.
Jaguar Land Rover's UK manufacturing operations have been frozen for nearly three weeks after a devastating cyberattack. The luxury automaker's production lines have ground to a halt as a result of the sophisticated hack, forcing JLR to shut down multiple factories across the globe. A group known as "Scattered Lapsus$ Hunters" claimed credit and left thousands of workers unable to build vehicles, causing significant inventory shortages for dealers.
Key Insights:
This prolonged shutdown highlights how modern car manufacturing depends entirely on interconnected digital systems that control everything from robotic assembly lines to inventory management. This attack has effectively grounded one of Britain's most iconic automotive brands for a month, with JLR extending the production pause until at least September 24, and some industry insiders warning the disruption could continue into late October or even November. The ripple effects are already spreading to dealerships, suppliers, and the thousands of workers whose livelihoods depend on continuous production.
Why This Matters For You:
For car buyers, this incident signals a troubling new reality where hackers from around the world might prevent you from purchasing a new car. The automotive industry's rush toward connected, software-driven vehicles has created new vulnerabilities that can literally stop production lines in their tracks. But what about the WORKERS who might lose their jobs? While JLR continues to pay its own employees, the ripple effects are already devastating for thousands of employees in its extensive supply chain. Many of these workers are facing furloughs, reduced hours, or temporary layoffs as a direct result of the cyberattack.
Read More on Entrepreneur.
In the world of cybersecurity, we talk a lot about the importance of protecting your data. The irony is, I'm a cybersecurity writer who doesn't even own a credit card. I don't believe in them. So, when the National Public Data breach compromised my Social Security number, I did the "responsible" thing: I signed up for an account with TransUnion to get their identity protection services and to freeze my credit. You know. To protect my data from being stolen.
The punchline, of course, is that TransUnion then proceeded to get breached. The company I entrusted with my most sensitive information, which was supposed to safeguard my identity, became yet another source of my data being compromised. It's a cruel joke. Isn't it? The solution to one data breach became the cause of another.
This breach isn't just a personal story. It's a scathing indictment of the entire data security industry. Cybersecurity experts and gurus tell us to "trust" these companies with our most sensitive information, often after our data has already been stolen from somewhere else. But who protects us from the protectors? In a system where data is a commodity and breaches are an inevitability, the only thing we can truly be sure of is that our personal information is for sale. Again.
PS: And this wasn't even my worst breach experience. They didn't just steal my Social Security number that time. They stole my DNA. That story is for another time.
Please read my two newsletters:
# 1 - Pithy Cyborg - AI news in a no-fluff format. Timely insights into how AI is changing the world around us. Plus, a fun and battle-tested AI prompt in each issue.
# 2 - Pithy Security - Useful cybersecurity news without fear-mongering. Simple security that lets you spot scams and stay safe without needing to become an expert.
PS: Do you have questions? Reply to this email!
Thanks for reading. More cutting-edge cybersecurity insights coming soon.
You're receiving this because you subscribed at PithySecurity.Substack.com. You can unsubscribe at any time using the link below. This newsletter reflects my personal opinions, not professional or legal advice. I may earn commissions from recommended tools. Thanks for your support!

Comments
Nothing yet. Say the first thing.
Sign in to join the conversation.