Ticker feed
A previously unknown hacking gang called ExfilSquad has stolen over 740,000 pieces of data from the UK Department for Education and the Police National Legal Database. The haul exposed names, email addresses, phone numbers and job titles belonging to government officials, senior school leaders, university staff, police officers — and members of the public, including parents.
Just over 600,000 lines came from the DfE's help-desk portal, with a smaller batch from its Turing scheme for students studying abroad. The gang claims a further 135,000 from the PNLD, including passwords used to access the site.
ExfilSquad is demanding payment from 14 alleged victims, threatening to publish everything if ignored. The DfE says it has seen no evidence ransomware was deployed and that the data is limited to customer service contact details. The PNLD says it held no confidential victim, witness or offender information. Both have reported the breach to the ICO.
One senior source briefed on the PNLD leak called the risk low — with a caveat worth acting on: if you reused your PNLD password on anything more sensitive, change it now.
Source: The Guardian
A previously unknown hacking gang called ExfilSquad has stolen over 740,000 pieces of data from the UK Department for Education and the Police National Legal Database. The haul exposed names, email addresses, phone numbers and job titles belonging to government officials, senior school leaders, university staff, police officers — and members of the public, including parents.
Just over 600,000 lines came from the DfE's help-desk portal, with a smaller batch from its Turing scheme for students studying abroad. The gang claims a further 135,000 from the PNLD, including passwords used to access the site.
ExfilSquad is demanding payment from 14 alleged victims, threatening to publish everything if ignored. The DfE says it has seen no evidence ransomware was deployed and that the data is limited to customer service contact details. The PNLD says it held no confidential victim, witness or offender information. Both have reported the breach to the ICO.
One senior source briefed on the PNLD leak called the risk low — with a caveat worth acting on: if you reused your PNLD password on anything more sensitive, change it now.
Source: The Guardian
More than 30 Minnesota community water systems were hit in a coordinated cyberattack on July 26–27, targeting operational technology (OT) systems across cities including Plymouth, Braham, South St. Paul, and Maple Plain. Automated control functions were disrupted, and Braham briefly took its water plant offline after attackers shut down its well and operating controls.
State and federal agencies are investigating, though no group has been officially blamed. Iran-linked threat actors remain suspects given recent US warnings about attacks on industrial control systems.
Plymouth said its problems were limited to equipment connected via cellular communications — and that lines up with a known blind spot. Denis Calderone, CTO of Suzu Labs, notes that water towers, lift stations and pump stations often reach SCADA systems over cellular modems, and those secondary links are "frequently overlooked during risk analysis."
Drinking water remains safe across all affected cities. But BreachLock CEO Seemant Sehgal's warning applies well beyond Minnesota: whatever common weakness the attackers found here almost certainly exists in water infrastructure elsewhere.
Updated 11 Aug 2026: The FBI has since confirmed the campaign targeted water systems in at least seven states, including Michigan and Georgia.
Source: SecurityWeek
More than 30 Minnesota community water systems were hit in a coordinated cyberattack on July 26–27, targeting operational technology (OT) systems across cities including Plymouth, Braham, South St. Paul, and Maple Plain. Automated control functions were disrupted, and Braham briefly took its water plant offline after attackers shut down its well and operating controls.
State and federal agencies are investigating, though no group has been officially blamed. Iran-linked threat actors remain suspects given recent US warnings about attacks on industrial control systems.
Plymouth said its problems were limited to equipment connected via cellular communications — and that lines up with a known blind spot. Denis Calderone, CTO of Suzu Labs, notes that water towers, lift stations and pump stations often reach SCADA systems over cellular modems, and those secondary links are "frequently overlooked during risk analysis."
Drinking water remains safe across all affected cities. But BreachLock CEO Seemant Sehgal's warning applies well beyond Minnesota: whatever common weakness the attackers found here almost certainly exists in water infrastructure elsewhere.
Updated 11 Aug 2026: The FBI has since confirmed the campaign targeted water systems in at least seven states, including Michigan and Georgia.
Source: SecurityWeek
A Russian state-backed hacking group called "Laundry Bear" has been quietly breaching Zimbra webmail servers since July 2025, targeting US government agencies, defense contractors, and Ukrainian government entities. A joint advisory from 15 countries revealed the group exploited CVE-2025-66376, a zero-day that only required victims to open or preview an email — no clicking required.
The haul was substantial: victims' last 90 days of email, addresses and passwords, the organization's email directory including its Global Address List, two-factor authentication tokens, and newly created application passcodes.
Zimbra patched the flaw in version 10.1.13 in November 2025, but the campaign ran undetected for months, and CISA only added it to its Known Exploited Vulnerabilities catalog in March 2026. Proofpoint, which tracks the group as TA488, has seen no activity since February — after researchers at Seqrite went public and the group tore down its own infrastructure.
Organizations still running unpatched Zimbra remain at risk. Update, review authentication logs, and revoke any unauthorized application passcodes — especially ones named "ZimbraWeb."
Source: Dark Reading
A Russian state-backed hacking group called "Laundry Bear" has been quietly breaching Zimbra webmail servers since July 2025, targeting US government agencies, defense contractors, and Ukrainian government entities. A joint advisory from 15 countries revealed the group exploited CVE-2025-66376, a zero-day that only required victims to open or preview an email — no clicking required.
The haul was substantial: victims' last 90 days of email, addresses and passwords, the organization's email directory including its Global Address List, two-factor authentication tokens, and newly created application passcodes.
Zimbra patched the flaw in version 10.1.13 in November 2025, but the campaign ran undetected for months, and CISA only added it to its Known Exploited Vulnerabilities catalog in March 2026. Proofpoint, which tracks the group as TA488, has seen no activity since February — after researchers at Seqrite went public and the group tore down its own infrastructure.
Organizations still running unpatched Zimbra remain at risk. Update, review authentication logs, and revoke any unauthorized application passcodes — especially ones named "ZimbraWeb."
Source: Dark Reading
Security researcher Justin O'Leary found serious "confused deputy" flaws in both Microsoft Azure and Google Cloud Platform — disclosing the Azure bug on 12 May and the GCP one on 18 June — and neither company properly acknowledged them.
The Azure bug lets an attacker escalate from Backup Contributor, with zero Kubernetes permissions, to full cluster-admin access via the AKS backup service. O'Leary rates it CVSS 9.9. The GCP flaw sits in Config Connector, the open source Kubernetes add-on for managing GCP resources, and lets someone with basic namespace access silently crown themselves GCP Organization Owner — with the attack hidden from audit logs, since it looks like service account activity.
Microsoft appears to have quietly patched its flaw without disclosure or a CVE. Google's bug bounty panel told O'Leary the report "didn't qualify," arguing customers are responsible for their own permission settings, though it said it might fix the issue anyway. Anyone running Config Connector should review who holds namespace access in the meantime.
O'Leary details both at Black Hat USA 2026, in a talk called "Trust No Deputy: Breaking Azure and GCP Through Managed Identity Chains."
Source: Dark Reading
Security researcher Justin O'Leary found serious "confused deputy" flaws in both Microsoft Azure and Google Cloud Platform — disclosing the Azure bug on 12 May and the GCP one on 18 June — and neither company properly acknowledged them.
The Azure bug lets an attacker escalate from Backup Contributor, with zero Kubernetes permissions, to full cluster-admin access via the AKS backup service. O'Leary rates it CVSS 9.9. The GCP flaw sits in Config Connector, the open source Kubernetes add-on for managing GCP resources, and lets someone with basic namespace access silently crown themselves GCP Organization Owner — with the attack hidden from audit logs, since it looks like service account activity.
Microsoft appears to have quietly patched its flaw without disclosure or a CVE. Google's bug bounty panel told O'Leary the report "didn't qualify," arguing customers are responsible for their own permission settings, though it said it might fix the issue anyway. Anyone running Config Connector should review who holds namespace access in the meantime.
O'Leary details both at Black Hat USA 2026, in a talk called "Trust No Deputy: Breaking Azure and GCP Through Managed Identity Chains."
Source: Dark Reading
Coca-Cola has confirmed a data breach tied to a ransomware attack on its dairy subsidiary Fairlife. The company initially disclosed the intrusion on July 16, suspending production at four U.S. Fairlife facilities. Most production has since resumed, and Fairlife product availability remains largely unaffected thanks to existing inventory.
The Anubis ransomware group claimed responsibility on July 20, alleging it stole 1 TB of confidential data — a figure Coca-Cola has not confirmed. The company acknowledges data was taken but hasn't said what, and says the incident won't materially affect its financial condition or results of operations.
Anubis has been active since December 2024, runs a double-extortion model, and unusually also carries a wiper mode for permanently destroying files. It has threatened to publish the stolen Fairlife data if no ransom is paid.
Source: SecurityWeek
Coca-Cola has confirmed a data breach tied to a ransomware attack on its dairy subsidiary Fairlife. The company initially disclosed the intrusion on July 16, suspending production at four U.S. Fairlife facilities. Most production has since resumed, and Fairlife product availability remains largely unaffected thanks to existing inventory.
The Anubis ransomware group claimed responsibility on July 20, alleging it stole 1 TB of confidential data — a figure Coca-Cola has not confirmed. The company acknowledges data was taken but hasn't said what, and says the incident won't materially affect its financial condition or results of operations.
Anubis has been active since December 2024, runs a double-extortion model, and unusually also carries a wiper mode for permanently destroying files. It has threatened to publish the stolen Fairlife data if no ransom is paid.
Source: SecurityWeek
CISA added six actively exploited Microsoft zero-days to its Known Exploited Vulnerabilities Catalog on 10 February 2026: CVE-2026-21510 (Windows Shell), CVE-2026-21513 (MSHTML), CVE-2026-21514 (Office Word), CVE-2026-21519 (Desktop Window Manager), CVE-2026-21525 (Remote Access Connection Manager) and CVE-2026-21533 (Remote Desktop Services).
Between them they cover privilege escalation, security feature bypasses and denial of service. Microsoft shipped fixes in its February 2026 Patch Tuesday, so anyone current on updates is covered — the risk sits with organisations that deferred that cycle.
Federal remediation deadlines have since changed. CISA replaced Binding Operational Directive 22-01 with BOD 26-04 on 10 June 2026, swapping flat timelines for a tiered model running from three days to 60 days depending on risk.
Nation-state groups, including China's Salt Typhoon, are among those exploiting similar flaws. All organisations should confirm the February patches are applied and audit exposure across Office, RDS and remote access tools.
Source: Cybersecurity News
CISA added six actively exploited Microsoft zero-days to its Known Exploited Vulnerabilities Catalog on 10 February 2026: CVE-2026-21510 (Windows Shell), CVE-2026-21513 (MSHTML), CVE-2026-21514 (Office Word), CVE-2026-21519 (Desktop Window Manager), CVE-2026-21525 (Remote Access Connection Manager) and CVE-2026-21533 (Remote Desktop Services).
Between them they cover privilege escalation, security feature bypasses and denial of service. Microsoft shipped fixes in its February 2026 Patch Tuesday, so anyone current on updates is covered — the risk sits with organisations that deferred that cycle.
Federal remediation deadlines have since changed. CISA replaced Binding Operational Directive 22-01 with BOD 26-04 on 10 June 2026, swapping flat timelines for a tiered model running from three days to 60 days depending on risk.
Nation-state groups, including China's Salt Typhoon, are among those exploiting similar flaws. All organisations should confirm the February patches are applied and audit exposure across Office, RDS and remote access tools.
Source: Cybersecurity News
A supply chain attack hit Jscrambler's popular NPM package on July 11, after a threat actor used a compromised publishing credential to push malicious versions containing hidden malware. Jscrambler versions 8.16, 8.17, 8.18 and 8.20 were affected — 8.19 was not — along with jscrambler-webpack-plugin 8.6.2, gulp-jscrambler 8.6.2, grunt-jscrambler 8.5.2 and jscrambler-metro-plugin 9.0.2. The tainted versions were downloaded 1,479 times before being deprecated.
The malware, written in Rust, steals credentials, crypto wallet seed phrases, browser data and cloud API keys — and reaches further than most, pulling in AI coding assistant and MCP configurations, OS keyrings, messaging apps and Steam sessions. It exfiltrates everything over TLS and tries stolen credentials against cloud APIs.
Jscrambler has deprecated the malicious versions and released clean version 8.22. If you installed any affected version, remove it immediately, scan for malware, and rotate all secrets and API keys.
Source: SecurityWeek
A supply chain attack hit Jscrambler's popular NPM package on July 11, after a threat actor used a compromised publishing credential to push malicious versions containing hidden malware. Jscrambler versions 8.16, 8.17, 8.18 and 8.20 were affected — 8.19 was not — along with jscrambler-webpack-plugin 8.6.2, gulp-jscrambler 8.6.2, grunt-jscrambler 8.5.2 and jscrambler-metro-plugin 9.0.2. The tainted versions were downloaded 1,479 times before being deprecated.
The malware, written in Rust, steals credentials, crypto wallet seed phrases, browser data and cloud API keys — and reaches further than most, pulling in AI coding assistant and MCP configurations, OS keyrings, messaging apps and Steam sessions. It exfiltrates everything over TLS and tries stolen credentials against cloud APIs.
Jscrambler has deprecated the malicious versions and released clean version 8.22. If you installed any affected version, remove it immediately, scan for malware, and rotate all secrets and API keys.
Source: SecurityWeek
A misconfigured Python HTTP server in Budapest with directory listing enabled handed researchers a full look inside three active phishing campaigns. The exposed server at 185.163.204.7 contained credential logs, phishing configs, RMM installers, combolists, and even the operator's own Telegram session files.
Three distinct threat actors were identified: codemado, an Egyptian operator whose Microsoft 365 AiTM campaign ran from January to May 2026; mail-argenta, a Nigerian operator undone by his own reused password, hardcoded in a public GitHub repo and later found in infostealer logs; and saroula01, whose Device Code Flow campaign quietly accumulated 218 victims across 12 countries over a year — 94% of them corporate accounts.
All three built their MFA-bypassing infrastructure from customised Evilginx forks pulled straight off public GitHub repositories, with minimal modification. The barrier to running these attacks is effectively zero.
Source: Lexfo Security Blog
A misconfigured Python HTTP server in Budapest with directory listing enabled handed researchers a full look inside three active phishing campaigns. The exposed server at 185.163.204.7 contained credential logs, phishing configs, RMM installers, combolists, and even the operator's own Telegram session files.
Three distinct threat actors were identified: codemado, an Egyptian operator whose Microsoft 365 AiTM campaign ran from January to May 2026; mail-argenta, a Nigerian operator undone by his own reused password, hardcoded in a public GitHub repo and later found in infostealer logs; and saroula01, whose Device Code Flow campaign quietly accumulated 218 victims across 12 countries over a year — 94% of them corporate accounts.
All three built their MFA-bypassing infrastructure from customised Evilginx forks pulled straight off public GitHub repositories, with minimal modification. The barrier to running these attacks is effectively zero.
Source: Lexfo Security Blog
Security firm Socket has uncovered "Operation Muck and Load" — a campaign using 222 GitHub repositories across 190 accounts to distribute Windows malware. Active since January 24, 2026, the threat actor published over 1,200 package versions, 700 of which are malicious.
The attack disguises a Go module as a legitimate DNS scanning tool, impersonating the real open source project dnsub. Hidden PowerShell code then pulls encrypted payloads from dead-drop platforms including Pastebin, YouTube, Instagram, Telegram, and Google Docs — making it harder to shut down.
Final payloads include AsyncRAT, Quasar RAT, Vidar infostealer, and XMRig cryptominers. Anyone who has pulled a DNS or subdomain scanning module from GitHub should check what they actually installed — go.mod and go.sum are the place to start.
Source: SecurityWeek
Security firm Socket has uncovered "Operation Muck and Load" — a campaign using 222 GitHub repositories across 190 accounts to distribute Windows malware. Active since January 24, 2026, the threat actor published over 1,200 package versions, 700 of which are malicious.
The attack disguises a Go module as a legitimate DNS scanning tool, impersonating the real open source project dnsub. Hidden PowerShell code then pulls encrypted payloads from dead-drop platforms including Pastebin, YouTube, Instagram, Telegram, and Google Docs — making it harder to shut down.
Final payloads include AsyncRAT, Quasar RAT, Vidar infostealer, and XMRig cryptominers. Anyone who has pulled a DNS or subdomain scanning module from GitHub should check what they actually installed — go.mod and go.sum are the place to start.
Source: SecurityWeek
Accenture has confirmed a security incident after a hacker posted on PwnForums claiming to have stolen 35 gigabytes of internal data — including Azure access keys, tokens, SSH and RSA keys, configuration files, and source code. The threat actor posted a screenshot of a private Azure DevOps repository on an accenture.com domain as proof, and listed the data for sale.
Accenture called it "this isolated matter," said it had "remediated its source," and reported no impact to operations or service delivery. It did not confirm what was taken, whether personal or client data was involved, or how the attacker got in.
Ross Filipek, CISO at Corsica Technologies, warns the stolen data could serve as "a playbook for future attacks" — exposing code vulnerabilities, credentials and infrastructure detail. Consulting firms make attractive targets precisely because of how deep their access runs into client systems.
Source: SecurityWeek
Accenture has confirmed a security incident after a hacker posted on PwnForums claiming to have stolen 35 gigabytes of internal data — including Azure access keys, tokens, SSH and RSA keys, configuration files, and source code. The threat actor posted a screenshot of a private Azure DevOps repository on an accenture.com domain as proof, and listed the data for sale.
Accenture called it "this isolated matter," said it had "remediated its source," and reported no impact to operations or service delivery. It did not confirm what was taken, whether personal or client data was involved, or how the attacker got in.
Ross Filipek, CISO at Corsica Technologies, warns the stolen data could serve as "a playbook for future attacks" — exposing code vulnerabilities, credentials and infrastructure detail. Consulting firms make attractive targets precisely because of how deep their access runs into client systems.
Source: SecurityWeek