惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

GbyAI
GbyAI
Google DeepMind News
Google DeepMind News
T
Tenable Blog
D
DataBreaches.Net
Google DeepMind News
Google DeepMind News
T
The Blog of Author Tim Ferriss
M
MIT News - Artificial intelligence
D
Docker
A
About on SuperTechFans
P
Privacy International News Feed
C
Cyber Attacks, Cyber Crime and Cyber Security
C
Cisco Blogs
Recent Announcements
Recent Announcements
博客园_首页
C
CXSECURITY Database RSS Feed - CXSecurity.com
有赞技术团队
有赞技术团队
L
Lohrmann on Cybersecurity
V
Visual Studio Blog
P
Privacy & Cybersecurity Law Blog
美团技术团队
CTFtime.org: upcoming CTF events
CTFtime.org: upcoming CTF events
N
News | PayPal Newsroom
Threat Intelligence Blog | Flashpoint
Threat Intelligence Blog | Flashpoint
Recent Commits to openclaw:main
Recent Commits to openclaw:main
Blog — PlanetScale
Blog — PlanetScale
N
Netflix TechBlog - Medium
Simon Willison's Weblog
Simon Willison's Weblog
WordPress大学
WordPress大学
E
Exploit-DB.com RSS Feed
MyScale Blog
MyScale Blog
H
Hacker News: Front Page
Latest news
Latest news
Vercel News
Vercel News
IT之家
IT之家
月光博客
月光博客
V
V2EX
P
Palo Alto Networks Blog
Application and Cybersecurity Blog
Application and Cybersecurity Blog
F
Fortinet All Blogs
aimingoo的专栏
aimingoo的专栏
S
Security Affairs
B
Blog RSS Feed
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
www.infosecurity-magazine.com
www.infosecurity-magazine.com
酷 壳 – CoolShell
酷 壳 – CoolShell
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
Know Your Adversary
Know Your Adversary
Cisco Talos Blog
Cisco Talos Blog
人人都是产品经理
人人都是产品经理
I
InfoQ

Cyber Security News

152 Chrome Extensions Hide Ad Tracking and Fake Google Search Traffic New Agentjacking Attack Hijacks Your AI Coding Agent to Run Code From Hackers Server BugHunter - Bug Bounty Toolkit Powered by Claude and Free AI Providers Splunk Enterprise Pre-Auth RCE Chain Exposes Database With Zero Authentication Anthropic Fable 5 and Mythos 5 Access Blocked to All Users Following Government Directive Fancy Bear Hackers Abuse EdgeRouters and Cloud Services to Launch Stealthy Cyberattacks Hackers Abuse Legitimate NinjaOne RMM Software to Bypass Traditional Malware Detection Malicious npm Campaign Steals SSH Keys, API Tokens, Cloud Credentials, and Wallet Secrets Hackers Use OnyxC2 Malware-as-a-Service to Steal Credentials From 210 Applications Facebook and Instagram Down Globally, Users Reporting Multiple Issues Google Sues Chinese Cybercrime Network for Using Gemini AI to Launch Cyberattacks 400+ Arch Linux AUR Packages Compromised in a Supply Chain Attack Deploying Infostealers Critical Vulnerability Chain in LangGraph Allows Attackers to Gain Full Server Control SHEETCREEP C# RAT Abuses Google Sheets API as C2 to Target Diplomatic Organizations Authorities Dismantle Cryptocurrency Laundering Services ‘AudiA6’ Used by Ransomware Gangs Hackers Use Free Spotify Premium Hacks on TikTok and Instagram to Spread Vidar Infostealer Solana FakeFix Campaign Uses 25 Malicious npm and PyPI Packages to Steal Developer Secrets Microsoft Outlook and Word Vulnerabilities Allow Attackers to Execute Malicious Code Palo Alto PAN-OS Vulnerability Allows Attackers to Execute Arbitrary Commands as Root User Google Patches 28 Chrome Vulnerabilities that Allow Attackers to Execute Malicious Code Microsoft Teams for Android Vulnerability Allows Attackers to Disclose Sensitive Data Oracle PeopleSoft 0-Day RCE Vulnerability Exploited in Attacks by ShinyHunters CISA Requires Federal Agencies to Patch Critical Vulnerabilities Within 3 Days OceanLotus APT Compromises FireAnt MetaKit in Supply-Chain Attack on Stock Investors GoFlateLoader Uses Massive PE Overlay to Deliver Lumma, Vidar, and StealC Infostealers Critical Langflow Vulnerability Exploited to Execute Malicious Code Hackers Abuse SniperDz PhaaS Ecosystem for Brand Impersonation and Browser Hijacking Researcher Hacked Google Using AI and Earned $500,000 Bug Bounty GitHub to Automate Disable npm Script Installs to Block Supply Chain Attacks Claude Mythos Turning N-Days Into N-Hours With Rapid Working Exploit Creation CISA Warns of Check Point Security Gateway Vulnerability Actively Exploited in Ransomware Attacks Hackers Use Weaponized DMG Files to Target macOS Users With Infostealer Malware Hackers Use BLUERABBIT Backdoor to Encrypt Files and Wipe Disks Across Windows Systems Hackers Abuse Residential Proxy Networks to Hide Malicious Activity and Evade Detection Cybercriminals Abuse Chinese-Language Guarantee Marketplaces to Trade Stolen Credentials Ivanti Command Injection Vulnerability Exploited in Attacks Following PoC Release PoC Exploit Released for Guest-to-Host Escape Linux Kernel Vulnerability Oracle Emergency Security Update to Fix Critical RCE Vulnerability GreatXML BitLocker Bypass 0-Day Exploited Via Windows Defender Offline Scan Hackers Abuse VMware-Signed Binary to Sideload NIGHTFORGE Loader in Espionage Attacks Multiple Splunk Enterprise Vulnerabilities Allow Attackers to Execute Malicious Script Hackers Abuse AWS CloudTrail and Google Cloud Logging to Evade Detection and Exfiltrate Logs China-Linked JDY Botnet Uses 1,500+ SOHO and IoT Devices for Rapid Vulnerability Exploitation CISA Warns of SolarWinds Serv-U Vulnerability Exploited in Attacks Top 5 Best Tools for Simulated DDoS Attacks in 2026 Critical Vulnerability in Hugging Face Transformers Enables Remote Code Execution Attacks OWASP CVE Lite CLI - New Tool to Scan for Vulnerabilities in Your Projects Anthropic's Claude Services Down — claude.ai, Claude Code, and Cowork Affected [Updated] Hackers Publish Malicious Python Package Mimicking Legitimate Parsimonious Parser Hackers are Increasingly Weaponizing Trusted Tools to Deploy Notorious Malware New Magecart Attack Turns Stripe into a Malware Command Server Hola Browser for Windows Delivery Pipeline Compromised to Deliver Cryptominer New Gafgyt Variant Targets Multiple Linux Architectures With Modular Propagation Microsoft 365 Service Degradation Bypassed Windows Driver Auto-Update Controls New SHub Stealer Variant Malware Targets Chrome, Firefox, Brave, Edge, Opera, and Crypto Wallets Malicious Browser Add-Ons Target ChatGPT, Claude, Copilot, Gemini, and DeepSeek Users
Maine Takes Data Breach Reporting Portal Offline After Fake VRChat and Discord Filings
Guru Baran · 2026-06-14 · via Cyber Security News

The Office of the Maine Attorney General has temporarily taken its public-facing data breach reporting database offline after discovering that an unknown entity submitted fabricated breach notifications targeting two major online platforms, VRChat and Discord, in what officials are calling a deliberate abuse of the state’s breach disclosure system.

On June 12, 2026, the Maine Attorney General’s office issued a formal statement confirming that the reported data breaches involving VRChat and Discord were hoaxes.

The false filings were submitted by an unidentified third party with no affiliation to either company. After direct conversations with VRChat, one of the two named organizations, officials confirmed the notifications were entirely fabricated. Both fraudulent entries have since been removed from the public database.

Breach Reporting Portal Offline

According to earlier reporting, one fake filing claimed that Discord suffered an “insider wrongdoing” incident that exposed the personal data of more than 10 million users, while a separate filing alleged VRChat leaked data on approximately 2.4 million users signed by an employee who does not exist. Neither company filed those reports.

Maine’s breach notification law is among the strictest in the United States a company must notify the AG’s office even if just one Maine resident is affected by a breach.

This low threshold has made Maine’s public portal a go-to reference for security researchers, journalists, and class-action attorneys seeking early breach disclosures.

Critically, the AG’s office has acknowledged that submissions flow directly from the online reporting form onto the public portal without independent verification. This open-access design, while intended to ensure transparency and timely public disclosure, created an exploitable gap that the unknown actor leveraged to plant false information on an authoritative government website.

The Maine AG’s office has taken the public-facing breach database offline while it reviews internal procedures to prevent future abuse, while still preserving public access to legitimate breach data.

In the interim, entities required to file breach reports can continue doing so through the office’s online reporting service, and those needing information from existing reports can contact the AG’s Consumer Protection Division directly.

This incident highlights a systemic vulnerability in self-reported, auto-published government compliance portals. Security professionals and journalists should treat all portal entries as unverified until confirmed directly by the affected company.

Real large-scale breaches typically generate corroborating coverage across multiple independent outlets, official company advisories, or legal filings a fake entry rarely produces all three simultaneously.

The identity of the individual or group behind the fraudulent submissions remains unknown, and no arrests have been reported as of the time of publication.

Follow us on Google NewsLinkedIn, and X to Get More Instant Updates.

Guru Baran

Guru Baranhttps://cybersecuritynews.com

Gurubaran KS is a cybersecurity analyst, and Journalist with a strong focus on emerging threats and digital defense strategies. He is the Co-Founder and Editor-in-Chief of Cyber Security News, where he leads editorial coverage on global cybersecurity developments.