Tag: leak
-
DeadLock Ransomware Uses Polygon Smart Contracts to Make Extortion Infra Harder to Disrupt
Tags: blockchain, communications, data, extortion, group, infrastructure, leak, microsoft, network, ransomware, service, threatThe ransomware group known as DeadLock has been observed using decentralized infrastructure to facilitate victim communications and data leak operations in a bid to improve operational resilience.”Its recovery ecosystem combines the Session messaging network with blockchain-backed services that store and deliver resources used throughout the extortion process,” the Microsoft Threat First seen on thehackernews.com Jump…
-
Exfiltration-Focused ExfilSquad Starts Leaking Stolen Data
Cities of Atlanta and Houston, and Frontier Airlines, Among New Group’s Victims. A fresh cybercrime group called ExfilSquad, which recently debuted with a data-leak site listing over a dozen victims, has begun leaking large quantities of stolen data. The group’s emergence comes as incident responders continue to see fewer victims paying exfiltration ransoms than ever…
-
9.2 Million Israeli Records Sold as a New Breach Are 20 Years Old
A seller claims to offer Israel’s 2026 population registry, but checks show the 9.2 million records are authentic data dating back to 2005. A vendor on a well-known leak forum claims to have breached Israel’s Population and Immigration Authority and is selling the entire national registry, 9.2 million records covering essentially the whole country. Ransomnews…
-
Cyberattack on Steam hardware shipper leaks names, addresses, and order data
Video game publisher Valve is alerting customers in Europe to a data breach at CEVA Logistics, its Steam hardware shipping partner. Reports from affected customers began … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/08/10/valve-data-breach-ceva-logistics-steam-hardware/
-
New CSS Bomb Attacks Let Hackers Steal Passwords and Tokens From Webmail Users
Security researcher Gareth Heyes has revealed techniques for webmail attacks that exploit HTML and CSS, the technologies used to format emails, to manipulate user interfaces, leak authentication data, and in some cases, capture passwords. Webmail services need to display HTML controlled by the sender without compromising the security of the mailbox application. To achieve this,…
-
New CSS Attacks Can Break Webmail Defenses to Steal Passwords and Tokens
New research shows content inside an email can escape its message boundary and interfere with the webmail interface.Across attack chains spanning Outlook, Gmail, Fastmail, Proton Mail, Yahoo Mail, and AOL Mail, the techniques can capture passwords, take over third-party accounts, leak tokens, hijack trusted UI actions, and manipulate AI tools that read email.PortSwigger researcher Gareth…
-
French rugby club Stade Français restores systems after cyberattack, probes data leak
The club said Thursday that it had already restored its IT environment from clean backups, allowing operations to continue normally. It added that its ticketing platform and online store were not affected and remain fully operational. First seen on therecord.media Jump to article: therecord.media/french-rugby-club-restores-systems-after-cyberattack
-
Exposed SISVISA Database Leaks 102,000 Brazilian Health Surveillance Records
An exposed SISVISA database leaked 102,215 Brazilian health records, exposing IDs, tax data, and regulatory documents without authentication. Researcher Jeremiah Fowler found a publicly accessible database that turned out to belong to SISVISA, Brazil’s Health Surveillance Information System, and alerted ExpressVPN, which later shared the findings with Hackread. The exposed instance held exactly 102,215 files,…
-
New TONTOU CPU attack bypasses Spectre v2 fixes, leaks Linux password hashes
Researchers found a way to bypass recent mitigations for Spectre v2 speculative execution side-channel attacks and developed an exploit to leak secrets from Linux machines. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/new-tontou-cpu-attack-bypasses-spectre-v2-fixes-leaks-linux-password-hashes/
-
iCloud Private Relay: WebKit legt echte IP trotz Schutz offen
iCloud Private Relay schützt nicht lückenlos: Drei WebKit-Leaks können echte IP-Adressen offenlegen und Apples Privatsphäre-Schutz umgehen. First seen on tarnkappe.info Jump to article: tarnkappe.info/artikel/it-sicherheit/icloud-private-relay-webkit-ip-leak-332158.html
-
Too many credential leaks, too little context? SOCRadar connects the dots
First seen on scworld.com Jump to article: www.scworld.com/news/too-many-credential-leaks-too-little-context-socradar-connects-the-dots
-
PSA: Apple’s Private Relay can leak your real IP address
A bug in how Apple implements its Private Relay feature, which in theory masks users’ IP addresses from the sites they visit, can reveal users’ real IP addresses. First seen on techcrunch.com Jump to article: techcrunch.com/2026/08/05/psa-apples-private-relay-can-leak-your-real-ip-address/
-
INC Ransomware Emerges as Dominant Actor Exploiting SonicWall SMA 1000 Flaws
The INC Ransomware operation has emerged as the “dominant threat actor” exploiting the recently disclosed security flaws in SonicWall Secure Mobile Access (SMA) 1000 series VPN appliances.In a report published over the weekend, Resecurity said it observed the INC Ransomware accelerating its activity since the beginning of August 2026, listing multiple victims on its data…
-
ExfilSquad hackers leak info of over 100,000 UK police officers, staff
A cyberattack on the U.K.’s Police National Legal Database (PNLD) has compromised contact data of more than 100,000 police officers and other criminal justice professionals. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/exfilsquad-hackers-leak-info-of-over-100-000-uk-police-officers-staff/
-
Alleged Żabka Breach Exposes Jira Data, Source Code, and API Keys
Alleged Å»abka data leak offered for Euro5,000 includes Jira data, GitLab repos, and secrets; researchers verified much of the sample. A brand-new forum account showed up on August 2, posted once, and asked five grand for what it claims is a full data dump from Å»abka Polska. Å»abka Polska is Poland’s largest convenience store operator…
-
CRPx0 Ransomware Claims Hyundai Turkey Breach, Steals 1.5GB of Assessment Data
The double-extortion ransomware group CRPx0 has listed Hyundai’s Turkish operations on its dark web leak site, claiming to have exfiltrated 1.5 GB of sensitive personnel and recruitment data from the automaker’s assessment systems. According to CyberWatch, first flagged on its data-leak portal, the target is described as a >>Korean automotive manufacturer (Turkish operations)<< with the…
-
The Cyber Express Weekly Roundup: AI Fraud, Data Leaks, Malware Campaigns, and Critical Infrastructure Threats
Tags: ai, cyber, cyberattack, data, exploit, finance, fraud, government, infrastructure, intelligence, leak, malicious, malware, software, threatThis weekly roundup highlights the growing complexity of digital threats affecting governments, businesses, developers, and consumers. From artificial intelligence being misused for financial fraud to large-scale customer data exposures, malicious software targeting developer ecosystems, and cyberattacks against critical infrastructure, recent incidents demonstrate how attackers are exploiting both emerging technologies and existing security weaknesses. First seen…
-
ShinyHunters Claims Ernst Young (EY) Data Breach, Threatens July 31 Leak
EY confirmed the theft of client tax documents from its third-party support platform. ShinyHunters claims responsibility and is threatening to publish the data. First seen on hackread.com Jump to article: hackread.com/shinyhunters-ernst-young-ey-data-breach-threat-leak/
-
Tanaka Dominates Data Leak Landscape With 25 Leak Posts
Ransomware often dominates cybersecurity headlines, but stolen data has become an equally valuable commodity in the cybercrime economy. In the first half of 2026, one threat actor stood out in the data leak ecosystem: Tanaka, a prolific data leak broker responsible for more publicized leak activity than any other actor tracked by Cyble. First seen…
-
Over 24,000 exposed server BMCs leak password hash via decades-old flaw
More than 24,000 internet-exposed servers are leaking authentication password hashes due to a 20-year-old vulnerability in their Baseboard Management Controller (BMC) interface. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/over-24-000-exposed-server-bmcs-leak-password-hash-via-decades-old-flaw/
-
Fake ShinyHunters Emails Give Victims 48 Hours to Pay $2,000 Bitcoin Ransom
Fake ShinyHunters-themed sextortion emails are abusing data from recent ShinyHunters leaks to threaten victims with the release of fabricated “webcam recordings” unless a 2,000 dollar Bitcoin ransom is paid within 48 hours. Despite the technical-sounding claims, there is no evidence of actual device compromise, malware deployment, or recorded content behind these messages. The emails impersonate…
-
ShinyHunters Claims EY Data Breach, Threatens to Leak Stolen Client Tax Data
ShinyHunters has claimed responsibility for the data breach at Ernst & Young (EY) and is threatening to publish allegedly stolen client tax information unless the professional services firm engages in negotiations before July 31, 2026. The extortion group posted about EY on its dark web leak site, describing the deadline as a “final warning” and…
-
Pope’s prayer app leaks 700,000 user emails
First seen on scworld.com Jump to article: www.scworld.com/brief/popes-prayer-app-leaks-700000-user-emails
-
Vatican’s ‘Click to Pray’ app leaks personal data of hundreds of thousands
First seen on scworld.com Jump to article: www.scworld.com/brief/vaticans-click-to-pray-app-leaks-personal-data-of-hundreds-of-thousands
-
Australian energy provider Origin Energy disclosed a data breach impacting customer data
Origin Energy confirmed a data breach after a hacker claimed to have stolen data from 2 million customers and threatened to leak it. Origin Energy disclosed a cyberattack that exposed customer data after a hacker claimed to have stolen records belonging to 2 million customers and threatened to publish them. An alleged hacker calling themselves…
-
ShinyHunters data leaks fuel $2,000 sextortion email scam
Threat actors are using email addresses exposed in data breaches leaked by the ShinyHunters extortion group to send sextortion emails demanding $2,000 in Bitcoin. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/shinyhunters-data-leaks-fuel-2-000-sextortion-email-scam/
-
Vatican’s Official Prayer App Leaks 700K+ Global Users’ PII
A porous API endpoint exposes, names, email addresses, location, and site status, all of which can be easily gleaned by anyone with a browser. First seen on darkreading.com Jump to article: www.darkreading.com/vulnerabilities-threats/vatican-official-prayer-app-leaks-700k-pii
-
EU Financial Institutions Leak Data Through Cookie Trackers
European banks inadvertently transmitted customer data to ad platforms via tracking pixels, raising serious compliance, security, and privacy concerns. First seen on darkreading.com Jump to article: www.darkreading.com/data-privacy/eu-financial-institutions-cookie-trackers
-
Anubis ransomware claims Coca-Cola Fairlife attack, threatens data leak
The Anubis ransomware gang has claimed responsibility for the cyberattack on Coca-Cola’s Fairlife dairy subsidiary, threatening to publish allegedly stolen corporate data unless the company pays a ransom. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/anubis-ransomware-claims-coca-cola-fairlife-attack-threatens-data-leak/
-
India says allegedly leaked nuclear plant files pose no safety risk
Documents that the World Leaks cybercrime group claimed to leak from the Kudankulam Nuclear Power Plant do not contain information pertaining to safety or security, Indian officials said. First seen on therecord.media Jump to article: therecord.media/india-nuclear-plant-kudankulam-world-leaks-documents

