Today’s digest leans incident-heavy: a university forced offline days before classes start, a crypto wallet vendor tripped up by a third-party plugin, and another vishing-driven cloud breach claimed by ShinyHunters. Here’s what’s new since yesterday’s digest.
Incident watch: A cyberattack forces UT San Antonio to delay the start of its fall semester for 42,000 students
The University of Texas at San Antonio pushed back the start of its fall semester by three days — from Wednesday, August 19 to Monday, August 24 — after a cyberattack hit its academic network over the weekend. University Technology Solutions says the intrusion attempt was caught “at the edge of our network, before it reached core systems,” and worked with outside incident response specialists to contain it. The disruption still knocked out phone lines, password resets, and network access campus-wide, forcing the university to extend the student payment deadline and adjust course waitlist procedures. So far, investigators have found no evidence that university data was taken. UTSA is one of the largest universities in Texas, serving more than 42,000 students. Help Net Security · KSAT
Catching an intrusion “at the edge” instead of in core systems is the outcome every network segmentation plan is built for, and it’s worth noting that even a contained attack still cost UTSA three days of downtime and a semester delay. If your organization runs a back-to-school or seasonal ramp-up period, this is a reasonable prompt to confirm your edge detection actually covers the systems your busiest week depends on — password resets and payment processing rarely get the same monitoring attention as core databases.
Incident watch: A third-party order-tracking plugin exposes personal data for nearly 40,000 SafePal crypto customers
Crypto wallet maker SafePal disclosed on August 16 that an authorization flaw in a third-party order-tracking plugin on its e-commerce site let one customer view another customer’s order information. The exposure affected 39,798 customers who placed orders between March 2, 2025, and April 11, 2026, and included names, email addresses, shipping addresses, phone numbers, and purchase details. SafePal says wallet software and hardware were not involved — no seed phrases, private keys, or wallet passwords were exposed, and there’s no evidence of unauthorized wallet access. The company has fixed the plugin, engaged a third-party security firm for an audit, cut data retention to 90 days, and taken down more than 30 phishing sites already built around the leaked order data. Help Net Security · Security Affairs
The wallet itself being unaffected is the good news; the bad news is that shipping addresses and order history are exactly what a convincing “your hardware wallet shipment needs verification” phishing call needs. If you run e-commerce integrations for a hardware or financial product, treat any plugin that can cross-reference one customer’s data against another’s as a high-severity authorization surface, not a low-priority third-party dependency.
Breach watch: Questel confirms a Microsoft 365 breach after a vishing attack; ShinyHunters claims 21 million records
French IP management firm Questel confirmed on August 13 that attackers gained unauthorized access to part of its Microsoft 365 environment — specifically a Sales SharePoint site — following a voice phishing (vishing) attempt against staff. The ShinyHunters extortion group listed Questel on its leak site on August 1 and claims to have stolen more than 21 million records containing some personal data, plus 147GB of internal corporate files. Questel has not confirmed that figure and says its forensic review is ongoing, but stresses that none of its production tools, IP platforms, or SaaS products were accessed, and it has found no evidence attackers retain access. Cyberinsider · BreachNews
This is the same playbook ShinyHunters has run against Abbott, RingCentral, and a string of other targets this year: a phone call to a help desk or employee, a compromised SSO or M365 session, and a claim of mass data theft that outpaces what the victim can confirm. The consistent lesson across all of them is the same — if your help desk can reset credentials or approve an MFA change over the phone, that process is your actual attack surface, regardless of how strong the underlying identity provider is.
Final thought
None of today’s three stories involved a novel exploit — a caught intrusion attempt, a third-party plugin’s authorization bug, and another vishing-driven cloud compromise. That’s the pattern worth sitting with: the highest-volume attack paths right now aren’t zero-days, they’re the operational seams around identity verification and third-party integrations that don’t get the same scrutiny as your own code. If you want help mapping which of your vendor integrations or help-desk processes carry that kind of exposure, see our how-to guides or book a discovery call.