
Court records breach, Breeze Comet hits Brazil, Aesto records breach
About this episode
U.S. and Canadian court records breached in Thomson Reuters incident
Cybercrime Breeze Comet causing problems in Brazil
Aesto record system hit by data breach
Get the full show notes here: https://cisoseries.com/cybersecurity-news-court-records-breach-breeze-comet-hits-brazil-aesto-records-breach/
Huge thanks to our episode sponsor, KnowBe4
Your employees have always been the target, but the threats they face are evolving. AI empowers cybercriminals to clone a coworker's voice, fake a video call with your CEO, or personalize a phishing email using details scraped from your own website.
KnowBe4's AI-native Security Awareness Training (SAT) fights back with 12 autonomous defense agents that allow you to deliver personalized, relevant, and engaging training that adapts as fast as the threats your people face every day. More than 70,000 organizations trust KnowBe4 worldwide. Find out why at KnowBe4.com.
Get every episode summarized
Each time Cybersecurity Headlines publishes, we email you a written briefing from the transcript — the topics, who appeared, and any specific claims, with the ad reads skipped.
Email me new episodesFree for 3 shows. No card needed.
Hosts & guests
Transcript ready
55 searchable segments. Every word is indexed and playable.
Full transcript
Cybersecurity Headlines — Court records breach, Breeze Comet hits Brazil, Aesto records breach. Machine-transcribed; use the interactive transcript above to jump the player to any line.
From the CISO series, it's Cybersecurity Headlines. These are the Cybersecurity Headlines for Friday, September 4th, 2026. I'm Steve Prentice. US and Canadian court records breached in Thompson Reuters incident. Media company Thompson Reuters has, quote, disclosed a Cybersecurity incident impacting its court management software which has resulted in a breach of sensitive case data across Canada and the US, end quote. This event happened on June 30th within its C-track product, that is capital C-Hyphen-track product, which is a digital case management system. An investigation revealed that those responsible access C-track files in Canada associated with three levels of Ontario courts. Some of these could potentially, quote, contain individuals' names and personal information. Certain confidential, redacted or sealed information may also have been impacted for certain affected courts, end quote.
This incident has also impacted appellate courts in the 11 US states and the US Virgin Islands. Cybercrime gang, Breeze Comet causing problems in Brazil. Formerly known as UNC 5669, the Breeze Comet gang targets financial institutions, including financial services, Fintech, retail, point of sale services and e-commerce companies, as well as government organizations and banks. According to research from Google Threat Intelligence Group and Mandeant, the group uses, quote, custom malware and creative infiltration tactics, end quote, to break into transaction systems and then initiate payments to itself. This direct approach differs from social engineering, ransomware and other roundabout methods, and the researchers warn that it could work in other countries. ASTO Record System hit by Data breach. The Birmingham, Alabama-based company whose name is spelled A-E-S-T-O-A-STO provides data migration and archiving services to medical facilities, upgrading their technology or switching electronic health record vendors, and also supports healthcare groups purchased by other companies.
Company representatives have now informed federal regulators that more than 9.5 million people had sensitive information leaked during a cyber attack last December, which affected at least 30 healthcare organizations. These numbers form an update to their initial announcement made in June in which they stated that the perpetrators broke into its Amazon web services infrastructure between December 2 and December 18. The data Stolen includes names, social security numbers, medical information, driver's license numbers, financial account numbers, health insurance data, and more. CISA eliminates some cyber security assessments for critical infrastructure. Six free assessments that the agency had been offering to critical infrastructure organizations are being scaled back largely due to the reduction in its workforce. With titles like Cyber-Rosilians Reviews and ransomware readiness assessments, these actions quote, invulge advisors meeting with infrastructure operators asking them questions and helping them use the agency's cyber security evaluation tool, CSET, to generate reports with recommended security improvements.
These were considered to be amongst the most important services that CISA offered to infrastructure operators across the country. Huge thanks to our sponsor, No Before. Your employees have always been the target, but the threats they face are evolving. AI empowers cyber criminals to clone a coworker's face. Fake a video call with your CEO or personalize a fishing email using details scraped from your own website. No Before's AI Native Security Awareness Training fights back with 12 autonomous defense agents that allow you to deliver personalized relevant and engaging training that adapts as fast as the threats your people face every day. More than 70,000 organizations trust No Before worldwide. Find out why at nobefore.com. That is KNOWBE, the number 4.com.
China Fire and Campaign Exploded Compromised Cisco Routers A report from researchers at Cybersecurity firm Signea, that is S-Y-G-N-I-A, describes this string of breaches as sophisticated and effective, and that quote, used an array of methods to compromise popular Cisco routers and use them as a jumping off point to monitor organizations, steal credentials and break into other organizations. Asaf Perlman, director of Incident Response at Signea said that the Fire and Campaign quote didn't just compromise systems, it compromised the trust layer those systems depend on. The routers, authentication servers, and management infrastructure that many organizations overlook as legacy technology became the attacker's vantage point for reach, visibility, and control, he said. This, the researchers added, shows the actors are no longer focused only on endpoints, servers or cloud workloads. They want to target the infrastructure that sits between environments, being routers, hypervisors, access appliances, linux, management hosts, and the systems that create trust, reachability, and visibility.
August, Microsoft Update resets some desktop settings. Microsoft has confirmed that desktop settings are getting lost or reset on some Windows devices after installing the August 2026 Preview update. Symptoms of this have been reported such as wallpapers switching to a black background. The issue impacts systems running Windows 1124H2 and Windows 1125H2 and it may affect wallpaper, desktop theme, and various other settings. Microsoft confirms that users will not be able to restore their custom settings on affected devices. US becomes target in multi-country RMM fishing campaign. This fishing campaign originally focused on Canada and used federal tax forms as lures, but it has now expanded to 46 countries, and almost half of the damage is occurring in the US.
The campaign, quote, uses fake documents to trick victims into installing legitimate remote, monitoring, and management software, that is RMM. Depending on the country being targeted, the attackers adapt using shipping and UPS communications, the Dobie PDFs, tax notices, US Social Security Administration themes, invoices, and other documents. The operation has used a versatile GitHub pages, Netlify, compromised websites, and other infrastructure for delivery of their payloads. Plex urges users to patch vulnerabilities immediately. Users of Plex PLEX are being urged to update their desktop clients and media servers immediately to patch flaws that have not yet been assigned CVIDs, even though the company has recently requested them. Products affected are Plex Media Server version 1.43.2 and earlier. Organizations running these affected versions are advised to secure their systems as soon as possible by updating Plex Media Server to version 1.43.3, which was released in May, and the Plex desktop client to version 1.15.0, which was released on August 13th.
These can be downloaded from the official downloads page or the server management page. If you have some thoughts on the news from today or about this show in general, please be sure to reach out to us at Feedback at CISOSeries.com. We would love to hear from you. I'm Steve Prentice, reporting for the CISOSeries. Cybersecurity headlines are available every weekday. Head to CISOSeries.com for the full stories behind the headlines.
More episodes
More from Cybersecurity Headlines

MikroTik routers hijacked, Russian data center threats, UK cybercrime losses sur...
Cybersecurity Headlines

The Department of Know: Astra launches, CISA cuts programs, McKesson breached
Cybersecurity Headlines

153M licenses for sale, Anthropic reverses course, Astra enters the red zone
Cybersecurity Headlines

Fable 5.1 released, USPS "untested" IT, Exchange hijack vulnerability
Cybersecurity Headlines
