NIKSUN, Inc.

NIKSUN, Inc. Welcome to the official NIKSUN page, your source for regular company updates and conversation

Know the Unknown

Make security or network decisions based on actionable data and complete information

Learn more at www.niksun.com

Is Facebook not enough? Connect with us:

* twitter.com/NIKSUN
* linkedin.com/company/niksun

A dark web marketplace called Nexus is reportedly selling access to more than 153 million American and Canadian driver’s...
09/02/2026

A dark web marketplace called Nexus is reportedly selling access to more than 153 million American and Canadian driver’s license records, allegedly siphoned from IDScan.net, an identity verification platform used by businesses including Hertz, FedEx, Target, ma*****na dispensaries, and other organizations that perform in-person ID checks. The marketplace reportedly contains scans of more than 170 million people across North America, including driver’s licenses, ID cards, international travel cards, and medical cards. Investigative reporter Brian Krebs said the data includes front and back license images, along with infrared and ultraviolet scans used for document authentication.

The risk is enormous because scanned identity documents are far more dangerous than basic personal information. Driver’s licenses and government IDs can be used for identity theft, account opening fraud, age-verification bypass, synthetic identity schemes, SIM swaps, financial fraud, and impersonation across services that increasingly require document-based verification. This alleged breach also shows the danger of concentrating sensitive ID images in third-party verification platforms: one vendor collecting IDs for many businesses can become a single point of failure affecting retailers, logistics companies, rental services, cannabis dispensaries, and countless downstream customers.

For IDScan-style incidents, fragmented security tools are not enough. Organizations need a consolidated platform, such as NIKSUN, that unifies SIEM, NDR, EDR, XDR, threat intelligence, cloud monitoring, API security, data loss prevention, network forensics, packet capture, and compliance reporting into one security data lake. That unified view lets teams trace whether attackers abused credentials, exploited an exposed endpoint, accessed object storage, queried document databases, or exfiltrated bulk ID images through network traffic. Instead of discovering the breach from a dark web marketplace, defenders can detect abnormal document access, mass downloads, suspicious API calls, and outbound data movement in real time — proving what was accessed, which customers were affected, and how to contain the exposure before millions of identity documents are sold.

Read more: https://lnkd.in/p/gEc-EFyc

08/31/2026

A reported Steam data leak may have exposed roughly 12 TB of historical platform content, allegedly covering everything published on Steam between 2003 and 2013. According to a Valve-related content creator, the data was reportedly gathered through a publicly accessible endpoint rather than a traditional hack, with the cutoff tied to Valve’s transition to a different storage system in 2013. The dataset is said to include not only Valve games, but the broader Steam library from that period, including full games, beta builds, prototypes, and unreleased or early versions of titles.

The exposure is significant because software repositories, game builds, and development archives can contain far more than nostalgic content. Early builds may reveal source structure, unreleased assets, internal tools, developer workflows, test environments, licensing material, build pipelines, and historical security weaknesses. Even if the data came from an exposed endpoint rather than active intrusion, the outcome is the same: a massive platform archive became accessible without the visibility or controls needed to detect, classify, and restrict that exposure before 12 TB was reportedly collected.

This is exactly the kind of incident where a unified platform becomes the data foundation for AI and autonomous security agents. To keep up with escalating exposure risks, AI needs one correlated view across storage systems, public endpoints, repository access, API activity, identity logs, file downloads, DNS, NetFlow/IPFIX, packet capture, and L2–L7 traffic — not scattered clues discovered after archivists start publishing finds. With that context, agents can automatically identify exposed data stores, classify sensitive builds, detect abnormal bulk downloads, map which files were accessed, and recommend immediate containment. Instead of learning that a decade of platform content was accessible after the fact, organizations that leverage a platform like NIKSUN can have AI-driven visibility that continuously answers: what is exposed, who is pulling it, how much has moved, and what must be locked down now.

Read more: https://lnkd.in/p/gMWPVcA9

08/27/2026

Baylor Genetics disclosed a major healthcare data breach affecting more than 2.8 million people nationwide, after an unauthorized third party accessed parts of its network between June 11 and June 17. The company reported the incident to the U.S. Department of Health and Human Services as a hacking or IT incident involving a network server, and said some information may have been viewed or copied. Potentially exposed data includes names, dates of birth, addresses, Social Security numbers, diagnoses, medical conditions, laboratory results, medical testing information, and other sensitive genetic and health records.

The breach is especially serious because Baylor Genetics performs testing tied to deeply personal medical decisions, including pregnancy and family planning, hereditary cancer risk, rare diseases, whole-genome and whole-exome sequencing, carrier screening, prenatal testing, and oncology testing. The company began sending notification letters on August 14. Patients may not even recognize the Baylor Genetics name because testing may have been performed through third-party medical providers or other laboratories, yet the exposed information could reveal some of the most sensitive details about a person’s health, family risk, and genetic profile.

This is exactly why healthcare and life sciences organizations need a unified data foundation, like NIKSUN, for security AI and autonomous agents. Escalating attacks move too fast for teams to manually stitch together server logs, identity activity, EHR access, lab-system records, file activity, endpoint telemetry, DNS, NetFlow/IPFIX, packet capture, and L2–L7 traffic after the fact. A unified platform gives AI and agents the complete context they need to answer in seconds: who entered, how they moved, which systems were touched, what PHI or genetic data was viewed or copied, whether data left the network, and what needs to be contained now. Without that shared data layer, AI is guessing from fragments; with it, agents can accelerate root-cause analysis, trigger containment, prioritize patient notification, preserve HIPAA-ready evidence, and help defenders keep pace with attacks targeting the most sensitive medical data.

Read more: https://lnkd.in/p/gR7GD7yz

08/21/2026

Apollo Global Management has confirmed a data breach after hackers used a social engineering attack to access the private equity giant’s cloud environment between July 6 and July 10. According to a filing with California’s attorney general, the attackers stole names, dates of birth, contact information, home addresses, and Social Security numbers. Apollo, one of the world’s largest private equity firms with $938 billion in assets under management and roughly 5,000 employees, has not publicly confirmed who was affected or whether the hackers demanded or received a ransom.

The breach is especially concerning because it fits a broader campaign targeting financial services and private equity firms through cloud identity compromise. Groups tracked under names such as Falcon, Helix, Pink, and Redact have been calling employees while posing as IT help desks, tricking them into entering passwords and MFA codes into spoofed login portals. For firms like Apollo, that kind of access can expose not only employee data, but also sensitive deal workflows, portfolio company information, investor communications, financial models, legal documents, diligence materials, and cloud-hosted collaboration systems.

In an Apollo-style breach, the most urgent question is what the compromised identity actually touched during those four days. Unified visibility in a platform like NIKSUN lets investigators trace the attack from the social engineering event to cloud login, MFA abuse, SaaS access, file downloads, database queries, mailbox activity, API calls, and outbound network sessions. By correlating identity logs, cloud audit trails, endpoint telemetry, DNS, NetFlow/IPFIX, packet capture, DLP signals, and L2–L7 session analytics, security teams can determine in minutes which accounts were abused, what data was accessed, whether files were exfiltrated, and which systems require containment or credential rotation. That level of traceability is critical for private equity firms, where one cloud breach can create risk across employees, investors, portfolio companies, and confidential transactions.

Read more: https://lnkd.in/p/gfJPtnfD

08/18/2026

GitHub suffered a major global outage this week, disrupting software development for more than seven hours across the Microsoft-owned platform’s 225 million-user ecosystem. The incident began around 6:40 a.m. Pacific and affected nearly every major workflow: the GitHub website, pull requests, code review, merges, GitHub Actions, automated testing and deployment pipelines, and GitHub Copilot. GitHub finally declared the incident resolved several hours later at 2:15 p.m. after scattered login failures continued to affect Copilot and other services.

The outage is especially damaging because GitHub is now critical software supply-chain infrastructure. When GitHub goes down, engineering teams cannot reliably review code, merge changes, trigger CI/CD workflows, ship updates, or use Copilot-assisted development. While GitHub’s Enterprise SLA commits to 99.9% quarterly uptime, the availability story users have been discussing is far worse: developer-tracked reports cited observed uptime around 90.21%, and recent coverage claimed April availability fell below 85% during GitHub’s outage-heavy period. That gap between contractual SLA, status-page reporting, and real-world developer experience is exactly why uptime percentages alone do not capture business impact: a multi-hour disruption during the workday can freeze releases, delay security patches, break DevOps pipelines, and expose how heavily modern software delivery depends on a few centralized platforms.

For GitHub-scale outages, teams need more than a status page — they need unified visibility that traces failures across the full developer workflow in seconds or minutes. A unified NPM and infrastructure observability platform, like NIKSUN, can correlate developer login attempts, Git operations, pull request latency, webhook delivery, GitHub Actions runners, Copilot authentication, API errors, DNS, network paths, cloud infrastructure, SNMP-monitored systems, NetFlow/IPFIX, packet capture, and L2–L7 traffic analytics. That lets engineering and platform teams quickly determine whether the issue is in the network layer, authentication service, CI/CD infrastructure, API gateway, cloud capacity, database backend, Copilot dependency, or local enterprise connectivity. With AI root-cause analysis, SLA monitoring, digital experience monitoring, packet-level forensics, and automated remediation, organizations can reduce downtime, protect release velocity, and keep software delivery moving even when a critical SaaS platform stumbles.

Read more: https://lnkd.in/p/gRpwfQks

08/06/2026

Spotify experienced a possible service disruption this week, with Downdetector recording thousands of user reports of issues. Most complaints centered on the website, though disruptions to a platform of Spotify's scale typically ripple across mobile apps, connected devices, in-car integrations, and third-party services that rely on Spotify's APIs. When consumer streaming outages happen, they surface a broader operational truth: modern digital services depend on a stack complex enough that a single component failure can affect hundreds of thousands of users before the provider's own dashboards catch up.

Streaming platforms run on layered infrastructure — content delivery networks, authentication and account services, recommendation and personalization engines, audio delivery, payment processing, and the regional cloud capacity underneath. A degradation in any single layer manifests very differently: playback stalls on mobile, login times out on web, playlists fail to sync across devices, or podcast downloads halt entirely. For dependent businesses — advertisers, podcast networks, connected-device makers, and enterprises using Spotify APIs — the immediate question is whether the fault sits with the provider, transit, or their own integration. Without unified visibility, that question takes hours to answer while user complaints accumulate.

Consumer platform reliability increasingly determines brand trust and revenue continuity, making end-to-end observability a strategic requirement rather than a technical nice-to-have. Effective service assurance depends on transactions that mirror real user flows, packet-level analysis of client-to-cloud traffic, flow and SNMP data for infrastructure context, and application logs correlated with AI-driven anomaly detection. Platforms like NIKSUN that unify packets, flows, SNMP, logs, events, and synthetic transactions into a single observability fabric give operators and dependent enterprises the cross-domain visibility needed to localize root cause in minutes rather than hours, and to communicate accurately with users before social media defines the narrative.

Read more: https://lnkd.in/p/g2ZTq_pD

07/31/2026

Hawthorn Medical Associates, a Dartmouth-based practice now affiliated with Brown University Health, has disclosed a data breach affecting more than 290,000 Massachusetts residents — the second-largest breach in the state this year. According to state filings and notices dated July 16, unauthorized access to a "historic file server" occurred between December 15–16, 2025, but affected individuals were not notified for seven months. Exposed data may include SSNs, medical information, health insurance, bills, bank and credit card details, and HR records. Recipients include non-patients and even a former patient who died 11 years ago.

The case highlights two persistent problems in healthcare cybersecurity: excessive retention of historical patient data on under-monitored systems, and the multi-month gap between compromise and notification. Unfortunately, a seven month delay in notification is not unusual as most organizations lack the forensic tools to determine the who, what, where, when, and how of a breach quickly. Without full-fidelity evidence retained and indexed from the moment of intrusion, investigators must reconstruct scope after the fact, which is why the phrase, "we couldn't determine exactly what information was exposed," appears so often in breach notices. Affected individuals live with lifetime fraud risk while the provider works out what happened.

Closing that gap is where a next-generation SOC model matters. Tomorrow's SOCs must run AI-driven investigative workflows continuously against a single retained record — packets, flows, logs, identity events, endpoint telemetry — so when an alert surfaces, questions about what was accessed, by whom, and how much left the network can be answered immediately, rather than in months. Platforms like NIKSUN, with a unified data lake and forensic-grade retention that agentic analytics can query directly, give healthcare providers the ability to detect and prevent intrusions before they unfold.

Read more:

Medical Computer Business Services (MCBS), a medical billing firm, has disclosed a 2025 data breach affecting over 1 mil...
07/30/2026

Medical Computer Business Services (MCBS), a medical billing firm, has disclosed a 2025 data breach affecting over 1 million patients, per HHS filings. The intrusion occurred over four days in September 2025 but was only acknowledged recently, almost a year later. A ransomware group called PEAR has taken credit, and a 3.3 TB trove of stolen data is now openly downloadable from the dark web. Exposed data includes names, addresses, dates of birth, health plan policy numbers, and detailed medical histories. Affected providers include C&C MD PC, Nuclear Medicine and Pathology Associates, and Radiation Oncology Associates, among others.

The case illustrates the vendor-driven exposure that now dominates healthcare breach headlines. A single billing intermediary becomes a concentration point for the most sensitive PHI, and one intrusion cascades into notification obligations for every covered entity it serves. The nine-month gap between compromise and disclosure is also representative: without deep forensic visibility into those four days in September, investigators had to reconstruct scope after the fact while attackers had already staged and exfiltrated 3.3 TB. By disclosure, the data was already public.

Closing that gap is where an AI-native and agentic SOC model matters. Traditional detection depends on analysts pivoting across disconnected tools to piece together what happened; an agentic approach turns the same investigative logic into AI-driven workflows that continuously mine full-fidelity evidence against a single retained record. When an alert lands, the questions that used to take weeks — what was accessed, by whom, and how much left the network — can be answered quickly because the evidence was already indexed and correlated. Platforms like NIKSUN — with a unified data lake that agentic analytics can query directly — give healthcare vendors the ability to discover and block the attack before it perpetrates.

Read more:

American Airlines grounded all flights nationwide last evening after a systemwide IT outage prompted a Federal Aviation ...
07/29/2026

American Airlines grounded all flights nationwide last evening after a systemwide IT outage prompted a Federal Aviation Administration advisory and a ground stop. The airline confirmed the disruption on social media, calling it a "technology issue" that impacted connectivity for some of its systems. The scale of the impact — every American flight in the country halted while engineers worked the problem — illustrates how deeply operational continuity now depends on internal IT and network systems performing as expected.

The airline case is a clean illustration of a broader shift: IT infrastructure is no longer a support function sitting adjacent to the business — it is the substrate the business runs on. Airline operations depend on real-time interaction between crew scheduling, weight and balance systems, dispatch, weather, reservations, gate assignment, and communications infrastructure. A degradation or connectivity failure in any single system can cascade into a ground stop within minutes, because the aircraft cannot legally or safely operate without those signals. In every case, an "IT outage" is now indistinguishable from an operational outage.

Reducing mean time to detect and mean time to restore under these conditions requires unified visibility, such as that provided by NIKSUN, across every layer of the stack — network, application, identity, and infrastructure — with the ability to localize a fault before it becomes a business-halting event. Effective controls include synthetic transactions that mirror real operational workflows, packet-level analysis to distinguish network issues from application failures, flow and SNMP data for infrastructure context, and application logs tied to the specific systems the business depends on — all correlated with AI-driven anomaly detection. Platforms like NIKSUN that consolidate packets, flows, SNMP, logs, events, and synthetic transactions into a single observability fabric give operators the cross-domain context needed to catch degradation early, localize root cause in minutes, and keep IT problems from becoming operational ones.

Read more:

T-Mobile experienced a widespread service disruption this week, with Downdetector reports climbing to more than 220,000 ...
07/28/2026

T-Mobile experienced a widespread service disruption this week, with Downdetector reports climbing to more than 220,000 within an hour. Most complaints centered on mobile signal and 5G home internet. T-Mobile initially made no public comment before eventually stating that teams were "actively working the reports of technical challenges" and treating restoration as their highest priority. The scale and speed of the escalation — hundreds of thousands of user reports in under an hour — illustrates how quickly a carrier-level incident becomes a public event, and how much the vendor communication gap costs when customers, dependent businesses, and municipal services lose connectivity simultaneously.

Modern carrier networks are complex: radio access, core routing, authentication and subscriber databases, transport backhaul, IMS and voice cores, and 5G control-plane services all interact, and a fault at any layer can degrade service in different ways for different customer segments. Distinguishing a radio issue from a core network problem from a subscriber-database slowdown requires correlating packet, signaling, flow, SNMP, and telemetry data in real time against a unified topology view. When those signals live in separate tools, the NOC spends critical minutes assembling the picture manually while user-facing impact expands — as reflected in the difference between "9,000 reports" and "220,000 reports" across a single hour.

Reducing mean time to detect and mean time to restore requires unified visibility across every layer of the carrier stack. Effective controls include synthetic transactions mirroring subscriber flows, packet-level capture and decode across signaling protocols, flow and SNMP data for infrastructure context, and AI-driven anomaly detection tied to a unified topology. Platforms like NIKSUN that consolidate all data into a single observability fabric give carriers the cross-domain context needed to localize root cause in minutes rather than hours, quantify customer impact in real time, & communicate accurately to subscribers before user reports dominate social media.

Read more:

T-Mobile experienced a widespread service disruption this week, with Downdetector reports climbing to more than 220,000 within an hour. Most complaints centered on mobile signal and 5G home internet. T-Mobile initially made no public comment before eventually stating that teams were "actively workin...

Address

457 North Harrison Street
Princeton, NJ
08540

Opening Hours

Monday 8am - 5pm
Tuesday 8am - 5pm
Wednesday 8am - 5pm
Thursday 8am - 5pm
Friday 8am - 5pm

Telephone

(609) 936-9999

Alerts

Be the first to know and let us send you an email when NIKSUN, Inc. posts news and promotions. Your email address will not be used for any other purpose, and you can unsubscribe at any time.

Contact The Business

Send a message to NIKSUN, Inc.:

Shortcuts

Share