NIKSUN, Inc.

NIKSUN, Inc. Welcome to the official NIKSUN page, your source for regular company updates and conversation

Know the Unknown

Make security or network decisions based on actionable data and complete information

Learn more at www.niksun.com

Is Facebook not enough? Connect with us:

* twitter.com/NIKSUN
* linkedin.com/company/niksun

Springfield Public Schools in Massachusetts canceled classes today after a cyber-attack disrupted systems needed for ess...
09/08/2026

Springfield Public Schools in Massachusetts canceled classes today after a cyber-attack disrupted systems needed for essential school operations. Superintendent Dr. Sonia Dinnall said the scope and size of the breach remain under investigation, and all staff were instructed to stay off district systems until more is known. Students were also told not to use district-issued laptops while administrators develop backup plans for critical functions such as attendance reporting and system restoration.

The incident shows how quickly a cyber-attack can move from IT disruption to community-wide operational impact. For school districts, outages can affect attendance, communications, grading, transportation, payroll, food services, student devices, learning platforms, special education systems, and parent-facing portals. Canceling classes after a holiday weekend creates immediate challenges for families, staff, and students, while also raising concerns about whether student records, employee data, or district credentials may have been accessed.

Springfield-style incidents require immediate visibility into which systems are safe, which are compromised, and what can be brought back online without spreading the attack. A unified security, NPM, and infrastructure observability platform, like NIKSUN, can help district IT teams trace activity across identity systems, student devices, learning applications, file shares, endpoint telemetry, DNS, NetFlow/IPFIX, packet capture, SNMP-monitored infrastructure, and L2–L7 traffic. Instead of shutting down broadly because the scope is unknown, schools can rapidly determine where the threat started, whether it reached core systems, whether data moved, and which services can be safely restored. That level of visibility helps reduce downtime, protect student data, support faster incident response, and keep education moving even as cyberattacks increasingly target K-12 environments.

Read more:

Springfield Public Schools in Massachusetts canceled classes today after a cyber-attack disrupted systems needed for essential school operations. Superintendent Dr. Sonia Dinnall said the scope and size of the breach remain under investigation, and all staff were instructed to stay off district syst...

Carhartt has reportedly been linked to a ShinyHunters data leak affecting 12.9 million accounts, including customer, emp...
09/07/2026

Carhartt has reportedly been linked to a ShinyHunters data leak affecting 12.9 million accounts, including customer, employee, and corporate data. The apparel company has not confirmed the breach, but Have I Been Pwned listed exposed details including names, email addresses, phone numbers, and physical addresses. ShinyHunters claimed the compromised data included customer PII, employee information, customer metadata, royalty information, and internal corporate records after ransom negotiations allegedly failed.

The incident is concerning because Carhartt is a major U.S. retailer with nearly $1 billion in annual revenue, thousands of employees, and a large customer base across physical stores and digital channels. Even if some leaked records were synthetic or auto-generated, exposed real customer and employee data can fuel phishing, impersonation, loyalty fraud, credential stuffing, and targeted social engineering. The reported link to Carhartt’s Databricks cloud analytics platform also fits ShinyHunters’ broader pattern: instead of attacking only traditional networks, the group increasingly targets the cloud data platforms, SaaS applications, analytics environments, and business integrations where large companies centralize massive volumes of customer and operational data.

Carhartt-style breaches show why companies need consolidated visibility across SIEM, NDR, EDR, XDR, threat intelligence, cloud monitoring, SaaS security, data analytics platforms, and network forensics. When attackers move through Databricks, Salesforce, Snowflake, Oracle PeopleSoft, or other business systems, security teams need one evidence layer that connects identity activity, API calls, database queries, file exports, endpoint behavior, DNS, NetFlow/IPFIX, packet capture, and L2–L7 traffic. A unified view in a platform like NIKSUN helps teams determine whether ransom claims are real, which records were genuine versus synthetic, what data was accessed or exfiltrated, and which customers, employees, or partners are actually at risk. Instead of letting ShinyHunters control the narrative on a leak site, organizations can quickly prove breach scope, contain cloud access, rotate credentials, and protect customer trust.

Read more:

A dark web marketplace called Nexus is reportedly selling access to more than 153 million American and Canadian driver’s...
09/02/2026

A dark web marketplace called Nexus is reportedly selling access to more than 153 million American and Canadian driver’s license records, allegedly siphoned from IDScan.net, an identity verification platform used by businesses including Hertz, FedEx, Target, ma*****na dispensaries, and other organizations that perform in-person ID checks. The marketplace reportedly contains scans of more than 170 million people across North America, including driver’s licenses, ID cards, international travel cards, and medical cards. Investigative reporter Brian Krebs said the data includes front and back license images, along with infrared and ultraviolet scans used for document authentication.

The risk is enormous because scanned identity documents are far more dangerous than basic personal information. Driver’s licenses and government IDs can be used for identity theft, account opening fraud, age-verification bypass, synthetic identity schemes, SIM swaps, financial fraud, and impersonation across services that increasingly require document-based verification. This alleged breach also shows the danger of concentrating sensitive ID images in third-party verification platforms: one vendor collecting IDs for many businesses can become a single point of failure affecting retailers, logistics companies, rental services, cannabis dispensaries, and countless downstream customers.

For IDScan-style incidents, fragmented security tools are not enough. Organizations need a consolidated platform, such as NIKSUN, that unifies SIEM, NDR, EDR, XDR, threat intelligence, cloud monitoring, API security, data loss prevention, network forensics, packet capture, and compliance reporting into one security data lake. That unified view lets teams trace whether attackers abused credentials, exploited an exposed endpoint, accessed object storage, queried document databases, or exfiltrated bulk ID images through network traffic. Instead of discovering the breach from a dark web marketplace, defenders can detect abnormal document access, mass downloads, suspicious API calls, and outbound data movement in real time — proving what was accessed, which customers were affected, and how to contain the exposure before millions of identity documents are sold.

Read more: https://lnkd.in/p/gEc-EFyc

08/31/2026

A reported Steam data leak may have exposed roughly 12 TB of historical platform content, allegedly covering everything published on Steam between 2003 and 2013. According to a Valve-related content creator, the data was reportedly gathered through a publicly accessible endpoint rather than a traditional hack, with the cutoff tied to Valve’s transition to a different storage system in 2013. The dataset is said to include not only Valve games, but the broader Steam library from that period, including full games, beta builds, prototypes, and unreleased or early versions of titles.

The exposure is significant because software repositories, game builds, and development archives can contain far more than nostalgic content. Early builds may reveal source structure, unreleased assets, internal tools, developer workflows, test environments, licensing material, build pipelines, and historical security weaknesses. Even if the data came from an exposed endpoint rather than active intrusion, the outcome is the same: a massive platform archive became accessible without the visibility or controls needed to detect, classify, and restrict that exposure before 12 TB was reportedly collected.

This is exactly the kind of incident where a unified platform becomes the data foundation for AI and autonomous security agents. To keep up with escalating exposure risks, AI needs one correlated view across storage systems, public endpoints, repository access, API activity, identity logs, file downloads, DNS, NetFlow/IPFIX, packet capture, and L2–L7 traffic — not scattered clues discovered after archivists start publishing finds. With that context, agents can automatically identify exposed data stores, classify sensitive builds, detect abnormal bulk downloads, map which files were accessed, and recommend immediate containment. Instead of learning that a decade of platform content was accessible after the fact, organizations that leverage a platform like NIKSUN can have AI-driven visibility that continuously answers: what is exposed, who is pulling it, how much has moved, and what must be locked down now.

Read more: https://lnkd.in/p/gMWPVcA9

08/27/2026

Baylor Genetics disclosed a major healthcare data breach affecting more than 2.8 million people nationwide, after an unauthorized third party accessed parts of its network between June 11 and June 17. The company reported the incident to the U.S. Department of Health and Human Services as a hacking or IT incident involving a network server, and said some information may have been viewed or copied. Potentially exposed data includes names, dates of birth, addresses, Social Security numbers, diagnoses, medical conditions, laboratory results, medical testing information, and other sensitive genetic and health records.

The breach is especially serious because Baylor Genetics performs testing tied to deeply personal medical decisions, including pregnancy and family planning, hereditary cancer risk, rare diseases, whole-genome and whole-exome sequencing, carrier screening, prenatal testing, and oncology testing. The company began sending notification letters on August 14. Patients may not even recognize the Baylor Genetics name because testing may have been performed through third-party medical providers or other laboratories, yet the exposed information could reveal some of the most sensitive details about a person’s health, family risk, and genetic profile.

This is exactly why healthcare and life sciences organizations need a unified data foundation, like NIKSUN, for security AI and autonomous agents. Escalating attacks move too fast for teams to manually stitch together server logs, identity activity, EHR access, lab-system records, file activity, endpoint telemetry, DNS, NetFlow/IPFIX, packet capture, and L2–L7 traffic after the fact. A unified platform gives AI and agents the complete context they need to answer in seconds: who entered, how they moved, which systems were touched, what PHI or genetic data was viewed or copied, whether data left the network, and what needs to be contained now. Without that shared data layer, AI is guessing from fragments; with it, agents can accelerate root-cause analysis, trigger containment, prioritize patient notification, preserve HIPAA-ready evidence, and help defenders keep pace with attacks targeting the most sensitive medical data.

Read more: https://lnkd.in/p/gR7GD7yz

08/21/2026

Apollo Global Management has confirmed a data breach after hackers used a social engineering attack to access the private equity giant’s cloud environment between July 6 and July 10. According to a filing with California’s attorney general, the attackers stole names, dates of birth, contact information, home addresses, and Social Security numbers. Apollo, one of the world’s largest private equity firms with $938 billion in assets under management and roughly 5,000 employees, has not publicly confirmed who was affected or whether the hackers demanded or received a ransom.

The breach is especially concerning because it fits a broader campaign targeting financial services and private equity firms through cloud identity compromise. Groups tracked under names such as Falcon, Helix, Pink, and Redact have been calling employees while posing as IT help desks, tricking them into entering passwords and MFA codes into spoofed login portals. For firms like Apollo, that kind of access can expose not only employee data, but also sensitive deal workflows, portfolio company information, investor communications, financial models, legal documents, diligence materials, and cloud-hosted collaboration systems.

In an Apollo-style breach, the most urgent question is what the compromised identity actually touched during those four days. Unified visibility in a platform like NIKSUN lets investigators trace the attack from the social engineering event to cloud login, MFA abuse, SaaS access, file downloads, database queries, mailbox activity, API calls, and outbound network sessions. By correlating identity logs, cloud audit trails, endpoint telemetry, DNS, NetFlow/IPFIX, packet capture, DLP signals, and L2–L7 session analytics, security teams can determine in minutes which accounts were abused, what data was accessed, whether files were exfiltrated, and which systems require containment or credential rotation. That level of traceability is critical for private equity firms, where one cloud breach can create risk across employees, investors, portfolio companies, and confidential transactions.

Read more: https://lnkd.in/p/gfJPtnfD

08/18/2026

GitHub suffered a major global outage this week, disrupting software development for more than seven hours across the Microsoft-owned platform’s 225 million-user ecosystem. The incident began around 6:40 a.m. Pacific and affected nearly every major workflow: the GitHub website, pull requests, code review, merges, GitHub Actions, automated testing and deployment pipelines, and GitHub Copilot. GitHub finally declared the incident resolved several hours later at 2:15 p.m. after scattered login failures continued to affect Copilot and other services.

The outage is especially damaging because GitHub is now critical software supply-chain infrastructure. When GitHub goes down, engineering teams cannot reliably review code, merge changes, trigger CI/CD workflows, ship updates, or use Copilot-assisted development. While GitHub’s Enterprise SLA commits to 99.9% quarterly uptime, the availability story users have been discussing is far worse: developer-tracked reports cited observed uptime around 90.21%, and recent coverage claimed April availability fell below 85% during GitHub’s outage-heavy period. That gap between contractual SLA, status-page reporting, and real-world developer experience is exactly why uptime percentages alone do not capture business impact: a multi-hour disruption during the workday can freeze releases, delay security patches, break DevOps pipelines, and expose how heavily modern software delivery depends on a few centralized platforms.

For GitHub-scale outages, teams need more than a status page — they need unified visibility that traces failures across the full developer workflow in seconds or minutes. A unified NPM and infrastructure observability platform, like NIKSUN, can correlate developer login attempts, Git operations, pull request latency, webhook delivery, GitHub Actions runners, Copilot authentication, API errors, DNS, network paths, cloud infrastructure, SNMP-monitored systems, NetFlow/IPFIX, packet capture, and L2–L7 traffic analytics. That lets engineering and platform teams quickly determine whether the issue is in the network layer, authentication service, CI/CD infrastructure, API gateway, cloud capacity, database backend, Copilot dependency, or local enterprise connectivity. With AI root-cause analysis, SLA monitoring, digital experience monitoring, packet-level forensics, and automated remediation, organizations can reduce downtime, protect release velocity, and keep software delivery moving even when a critical SaaS platform stumbles.

Read more: https://lnkd.in/p/gRpwfQks

08/06/2026

Spotify experienced a possible service disruption this week, with Downdetector recording thousands of user reports of issues. Most complaints centered on the website, though disruptions to a platform of Spotify's scale typically ripple across mobile apps, connected devices, in-car integrations, and third-party services that rely on Spotify's APIs. When consumer streaming outages happen, they surface a broader operational truth: modern digital services depend on a stack complex enough that a single component failure can affect hundreds of thousands of users before the provider's own dashboards catch up.

Streaming platforms run on layered infrastructure — content delivery networks, authentication and account services, recommendation and personalization engines, audio delivery, payment processing, and the regional cloud capacity underneath. A degradation in any single layer manifests very differently: playback stalls on mobile, login times out on web, playlists fail to sync across devices, or podcast downloads halt entirely. For dependent businesses — advertisers, podcast networks, connected-device makers, and enterprises using Spotify APIs — the immediate question is whether the fault sits with the provider, transit, or their own integration. Without unified visibility, that question takes hours to answer while user complaints accumulate.

Consumer platform reliability increasingly determines brand trust and revenue continuity, making end-to-end observability a strategic requirement rather than a technical nice-to-have. Effective service assurance depends on transactions that mirror real user flows, packet-level analysis of client-to-cloud traffic, flow and SNMP data for infrastructure context, and application logs correlated with AI-driven anomaly detection. Platforms like NIKSUN that unify packets, flows, SNMP, logs, events, and synthetic transactions into a single observability fabric give operators and dependent enterprises the cross-domain visibility needed to localize root cause in minutes rather than hours, and to communicate accurately with users before social media defines the narrative.

Read more: https://lnkd.in/p/g2ZTq_pD

07/31/2026

Hawthorn Medical Associates, a Dartmouth-based practice now affiliated with Brown University Health, has disclosed a data breach affecting more than 290,000 Massachusetts residents — the second-largest breach in the state this year. According to state filings and notices dated July 16, unauthorized access to a "historic file server" occurred between December 15–16, 2025, but affected individuals were not notified for seven months. Exposed data may include SSNs, medical information, health insurance, bills, bank and credit card details, and HR records. Recipients include non-patients and even a former patient who died 11 years ago.

The case highlights two persistent problems in healthcare cybersecurity: excessive retention of historical patient data on under-monitored systems, and the multi-month gap between compromise and notification. Unfortunately, a seven month delay in notification is not unusual as most organizations lack the forensic tools to determine the who, what, where, when, and how of a breach quickly. Without full-fidelity evidence retained and indexed from the moment of intrusion, investigators must reconstruct scope after the fact, which is why the phrase, "we couldn't determine exactly what information was exposed," appears so often in breach notices. Affected individuals live with lifetime fraud risk while the provider works out what happened.

Closing that gap is where a next-generation SOC model matters. Tomorrow's SOCs must run AI-driven investigative workflows continuously against a single retained record — packets, flows, logs, identity events, endpoint telemetry — so when an alert surfaces, questions about what was accessed, by whom, and how much left the network can be answered immediately, rather than in months. Platforms like NIKSUN, with a unified data lake and forensic-grade retention that agentic analytics can query directly, give healthcare providers the ability to detect and prevent intrusions before they unfold.

Read more:

Medical Computer Business Services (MCBS), a medical billing firm, has disclosed a 2025 data breach affecting over 1 mil...
07/30/2026

Medical Computer Business Services (MCBS), a medical billing firm, has disclosed a 2025 data breach affecting over 1 million patients, per HHS filings. The intrusion occurred over four days in September 2025 but was only acknowledged recently, almost a year later. A ransomware group called PEAR has taken credit, and a 3.3 TB trove of stolen data is now openly downloadable from the dark web. Exposed data includes names, addresses, dates of birth, health plan policy numbers, and detailed medical histories. Affected providers include C&C MD PC, Nuclear Medicine and Pathology Associates, and Radiation Oncology Associates, among others.

The case illustrates the vendor-driven exposure that now dominates healthcare breach headlines. A single billing intermediary becomes a concentration point for the most sensitive PHI, and one intrusion cascades into notification obligations for every covered entity it serves. The nine-month gap between compromise and disclosure is also representative: without deep forensic visibility into those four days in September, investigators had to reconstruct scope after the fact while attackers had already staged and exfiltrated 3.3 TB. By disclosure, the data was already public.

Closing that gap is where an AI-native and agentic SOC model matters. Traditional detection depends on analysts pivoting across disconnected tools to piece together what happened; an agentic approach turns the same investigative logic into AI-driven workflows that continuously mine full-fidelity evidence against a single retained record. When an alert lands, the questions that used to take weeks — what was accessed, by whom, and how much left the network — can be answered quickly because the evidence was already indexed and correlated. Platforms like NIKSUN — with a unified data lake that agentic analytics can query directly — give healthcare vendors the ability to discover and block the attack before it perpetrates.

Read more:

Address

457 North Harrison Street
Princeton, NJ
08540

Opening Hours

Monday 8am - 5pm
Tuesday 8am - 5pm
Wednesday 8am - 5pm
Thursday 8am - 5pm
Friday 8am - 5pm

Telephone

(609) 936-9999

Alerts

Be the first to know and let us send you an email when NIKSUN, Inc. posts news and promotions. Your email address will not be used for any other purpose, and you can unsubscribe at any time.

Contact The Business

Send a message to NIKSUN, Inc.:

Shortcuts

Share