Unbiased headlines. Facts, not spin.
Every story is an unbiased news briefing written from 110+ sources across the spectrum — sources linked so you can verify it yourself.
SSA Data Breach Lawsuit Drags On as VMware Flaw Fuels Ransomware and Third-Party Vendors Keep Losing Americans' Data

The SSA breach
More than a year after Department of Government Efficiency staffers moved through the Social Security Administration, litigation over what happened to the agency's data is still working through federal courts, according to TechCrunch.
The central allegation, made by a federal whistleblower, is that DOGE personnel uploaded a live copy of the Social Security database, containing Social Security numbers and personal information tied to most living Americans, to an unsecured third-party server. That claim is unproven. No court has ruled on it, and the Social Security Administration itself has said in court filings that it does not know what was actually stored on the server, per TechCrunch.
The agency's filings do confirm one thing: DOGE signed an agreement with an outside political advocacy group, described as an effort to find evidence of voter fraud. President Trump has repeatedly claimed such fraud exists. TechCrunch notes he has done so without presenting evidence. That distinction matters, because the fear articulated by critics that the database could be misused to target Americans is a fear about intent, not a documented outcome.
Two senior House Democrats investigating the matter called the exposure something that "could very well be the largest data breach in our nation's history," according to TechCrunch. That is their characterization, made in the context of an ongoing investigation, not a finding by a court or an independent auditor. It is a serious allegation from officials with subpoena power and access to internal records, but it remains an allegation until the litigation and investigation produce documented findings.
The fair question conservatives and civil libertarians alike should be asking is the same one: why does the agency still not know, more than a year later, what left its network and where it went? Whether the fault lies with DOGE's rushed access, the SSA's own recordkeeping, or both, the uncertainty itself is the story. Government sloppiness with the most sensitive database in the country deserves scrutiny regardless of which administration or initiative caused it.
Europe's grid and water attacks
Separately, a string of attacks on European energy and water infrastructure has been attributed, at least in part, to Russia, according to TechCrunch. Poland's energy grid was hit with destructive malware late last year. A Swedish thermal plant and a Norwegian dam were also targeted, with the dam incident reportedly causing a large uncontrolled water release. Earlier this year, Russian-linked hackers went after Polish water treatment plants.
These are not financially motivated ransomware jobs. They are attacks on civilian infrastructure with the potential for physical, real-world harm, and they fit a broader pattern of nation-state actors probing power grids and water systems rather than just stealing data.
VMware's vCenter flaw goes from APT tool to ransomware weapon
On the ransomware front, the Cybersecurity and Infrastructure Security Agency has confirmed that gangs are now exploiting a critical VMware vCenter vulnerability, tracked as CVE-2026-59310, according to Bleeping Computer. Broadcom patched the flaw on July 29 and, in a supplemental FAQ, told customers to treat it as an emergency.
The timeline moved fast. Roughly two weeks after the patch, incident response firm QUIRSO found more than 361 IP addresses across 47 countries compromised by a suspected advanced persistent threat actor using the flaw to install a reverse SSH tool for persistent access. Days later CISA added the vulnerability to its Known Exploited Vulnerabilities catalog and gave federal agencies three days to secure their systems. Over the weekend, CISA updated the listing again to flag ransomware gangs as active exploiters, per Bleeping Computer.
Shadowserver currently tracks more than 450 VMware vCenter servers still exposed online, with no public data on how many have been patched, Bleeping Computer reported. CISA has now tagged 26 VMware vulnerabilities as exploited in the wild over the past five years, nine of them by ransomware operators specifically, because compromised vCenter or ESXi servers hand attackers a foothold into an organization's entire virtual infrastructure.
The vendor problem, in numbers
A monthly breach report from PKWare on August 2026 incidents adds a data point that cuts across the sector: four of the five largest breaches that month sat on infrastructure the breached organization did not directly operate.
McKesson and Baxter International both reported unauthorized access through third-party applications. Heights Finance pointed to a third-party cloud platform. Unlimited Technology Systems was breached inside a commercial data center, a case that took nine months from detection to notification and produced the month's largest confirmed exposure, 3,803,750 individuals. Baylor Genetics, the lone company breached on its own network, confirmed 2,810,878 affected individuals, roughly nine times the subtotal early state-filing coverage had carried, according to PKWare.
PKWare also flagged a gap between claimed and confirmed numbers. Incidents tied to extortion groups produced the biggest headlines, including a claim of more than 25 million Salesforce records tied to a campaign that hit Alcon, but the group in that case ultimately published only 218,395 verified email addresses.
What comes next
The SSA litigation remains unresolved, and neither the whistleblower's claim nor the scope of any misuse has been confirmed by a court. CISA's three-day patch deadline for federal vCenter systems has passed, but Shadowserver's count of exposed servers suggests many organizations, public and private, still have not closed the door ransomware gangs are now actively using.
Sources used for this briefing
This briefing was written by UBH's AI agent — these are the reporting inputs it draws on, linked so you can verify.