Search This Blog

Powered by Blogger.

Blog Archive

Labels

Footer About

Footer About

Labels

Showing posts with label Data Leak. Show all posts

Clop-Linked Web Shell Targets PTC Windchill Servers in Data Theft Attacks

 

A custom Java web shell, associated with the Clop ransomware group, was created to target the PTC Windchill and FlexPLM servers by decrypting their credentials, enumerating file repositories, and stealing data. Researchers at cybersecurity firm ReliaQuest discovered the web shell after analyzing the recent data-theft campaign that abused the critical remote code execution vulnerability, CVE-2026-12569, affecting PTC Windchill. 

According to the researchers, the attackers did not use a traditional web shell to gain persistent access to the targeted servers. Instead, they used a custom component that demonstrated an in-depth understanding of the target application’s internal API, database schema, keystore, and file-vault structure. ReliaQuest notes that the discovered resource is an application-specific variation of the Clop ransomware group’s known mass exploitation framework. The web shell was linked to the Clop ransomware group because of extortion e-mails sent by the threat actors using the e-mail addresses associated with the data-leakage web site operated by Clop. 

In addition, the researchers identified X-windchill-req headers used by the web shell, which were also used by the Clop ransomware group in the past, as well as similar tactics, techniques, and procedures (TTPs). Earlier this year, Clop ransomware group’s infrastructure was found to target enterprise business software solutions such as Accellion FTA, GoAnywhere MFT, SolarWinds Serv-U FTP, Cleo, and MOVEit Transfer. This campaign, which affected the MOVEit Transfer application, compromised more than 2,770 organizations worldwide. 

The web shell is implemented as JavaServer Pages (JSP), which directly imports the PTC Windchill-specific classes such as MethodContext, WTConnection, and WTKeyStoreUtil, giving the threat actors’ access to PTC Windchill’s native functions, including the database, encrypted credentials decryption, and locating files stored in the application’s vaults. The web shell’s command execution capability was established using the custom protocol that utilizes the HTTP X-windchill-req header. 

Overall, the custom component allowed the attackers to achieve multiple malicious objectives, including Windchill secrets and configuration data theft, file vault discovery and enumeration, directory listing, file retrieval and deletion, executing additional Java classes, and identifying the server’s operating system. Besides that, ReliaQuest reports that the web shell’s implementation contains the Windchill vault enumeration code that queries multiple Windchill database tables, namely ApplicationData, FVITEM, FVMOUNT, and MasteredOnReplicaItem. 

The PTC released a set of security updates to address CVE-2026-12569 on June 17. Additionally, the vulnerability was included in the CISA’s Known Exploited Vulnerabilities catalog earlier this week after the PTC reported active exploitation attempts in the wild. Ransom-ISAC confirmed that ransomware group Clop was behind the attacks by sending extortion emails to the employees of the targeted organizations. ReliaQuest recommends that all the JSP files found in the PTC Windchill directories should be investigated for any suspicious content and that the researchers should look for the X-windchill-req string. 

Moreover, the organizations that determined that their Windchill servers were compromised by the ransomware group should change the LDAP manager’s password and other user credentials because they are considered insecure and may have been leaked.

Chick-fil-A Warns Customers After Credential Stuffing Attack Compromises User Accounts

 

Chick-fil-A notifies customer about personal information exposure after data breach occurred due to credential stuffing attack Chick-fil-A company has announced that personal and account information about some of its customers may have been exposed due to a data breach. This breach occurred through the use of credential stuffing, which is not a vulnerability within the corporation’s website or mobile application.

As explained in the company note to customers, unauthorized access attempts came from bad actors using credentials stolen elsewhere. The company discovered unauthorized access attempts to customer accounts after noticing anomalous activity in the login database, and the phishing campaign occurred between June 17-19, 2026, targeting Chick-fil-A One loyalty program accounts. The corporation concluded its investigation on July 13 th and established that attackers had used compromised credentials to access the account information of some customers. 

The information available to bad actors and potentially at risk of being misused varies depending on the customer’s account. It may include names, contact information, mailing addresses, phone numbers, dates of birth, and Chick-fil-A One account information like ID or QR code and mobile payment credentials. Moreover, attackers may have gained access to reward balances, gift card balances, and the last four digits of payment cards. Although the corporation has not revealed the number of affected clients, the number exceeds several thousand. 

According to the documents filed with the state, 2,182 Texas residents and 39 Massachusetts residents were impacted by the breach. However, there are also other states affected, as notifications to state attorney generals in charge of consumer protection have also been filed, including the District of Columbia. After discovering the issue, the corporation remediated the security risks and notified the affected clients. 

Moreover, Chick-fil-A took measures to enhance account security for all customers, including allowing password reset, account logout, and removing payment methods in the application. Some customers also received bonus points on their accounts as compensation for the issues experienced. Chick-fil-A corporation acknowledges the concern caused by the data breach and assures clients that it takes customer account security seriously. Moreover, the company has recommended that customers change passwords to strong and unique words or phrases not used for other accounts. 

Credential stuffing works only when the same or similar passwords are used across different accounts, so changing them to unique ones decreases the chances of experiencing another breach. Chick-fil-A data breach demonstrates once more that it is crucial to make sure that each online account, including email, banking, and social media accounts, uses a unique and strong password. 

If one suspects that an account may have been compromised, it should be changed to a strong password immediately. Also, it is essential to use multi-factor authentication when available and to monitor account activity regularly for unauthorized transactions or unauthorized access attempts.

Estée Lauder Discloses HR Data Breach Linked to Oracle E-Business Suite Vulnerability

 

Estee Lauder announced that their Oracle E-Business Suite (EBS) system that manages human capital operations was targeted by cyber criminals who managed to steal personal data of some of the company’s employees. The company confirmed that some of the information on the intranet belonged to third parties who were not authorized to access it. 

According to the company’s statement, Estee Lauder learned about the breach following an internal investigation into the cybersecurity incident. Specifically, investigators discovered on June 19, 2026, that unauthorized users accessed the Oracle EBS system on or around August 9, 2025. The data exfiltrated by the hackers varied depending on the individual’s details but generally included names, addresses, and email, birth dates, social security numbers, passport numbers, bank information, medical data, and records of payroll and performance reviews. 

Since the breach involved PII, financial information, and employment data, there is a risk of identity theft and financial fraud for the affected employees. After detecting the anomaly, Estee Lauder contracted cybersecurity experts to conduct a forensic audit, report the pertinent information to the relevant law enforcement agencies, and take additional measures to secure the site. The company is offering 24 months of identity and restoration services through Kroll to all the affected parties free of charge, and the services will be available until October 31, 2026. All the affected employees should remain on the lookout for possible suspicious activities, including monitoring financial accounts, credit reports, and other relevant personal information. 

Even though Estee Lauder did not disclose the identity of the perpetrators, in the context of the discovered timeline, it is plausible to assume that the threat actors who targeted the company are part of the Cl0p extortion group. According to reports by Google and Mandiant, the hacking group utilized several Oracle EBS vulnerabilities, including the zero-day flaw with the reference number CVE-2025-61882, to initiate attacks against other companies. 

The vulnerability that was most likely used in the attack allowed malicious cyber actors to deploy arbitrary code via an unauthenticated HTTP request and affected all Oracle EBS versions from 12.2.3 to 12.2.14. Notably, Oracle released a security patch on October 4, 2025, after detecting that the vulnerability was being actively exploited. The latest breach serves as a reminder of the potential risks associated with the use of enterprise resource planning software that has the capability to store PII and other sensitive information about employees. 

It is strongly advised that organizations that use similar systems remain wary of the threats and make sure that all the relevant software has been updated with the latest security patches while also configuring the tools in a manner that minimizes the attack surface. In addition, enterprise systems should be constantly monitored for any suspicious activities that could indicate possible threats to data security.

Location Sharing: Convenience at the Cost of Safety

 

Location sharing has become a routine feature in messaging, navigation, and social apps, yet it carries security and privacy risks that many users underestimate. While convenient for coordinating meetups or ensuring family safety, careless configuration can expose sensitive patterns about your daily life to strangers, advertisers, and even attackers who compromise the platforms you trust. 

The most immediate danger is physical safety. Continuous location sharing reveals where you live, work, study, and spend leisure time, effectively mapping your routine for anyone with access. Stalkers, harassers, or opportunistic criminals can exploit this data to time thefts, orchestrate impersonation scams, or physically follow you. Real-time updates on platforms like Snapchat’s Snap Maps make it trivial to see when you are home or away, turning a social feature into a surveillance tool if permissions are too broad. 

Beyond individual bad actors, the apps themselves and their data ecosystems present another layer of risk. Many services collect and retain location histories, which can be sold to data brokers, advertisers, or accessed by third parties through data breaches. Incidents like the Gravy Analytics hack show how aggregated location data can leak at scale, exposing users who never intended their movements to be public. Even when companies claim strong security, breaches and insider misuse remain persistent threats in today’s threat landscape. 

Location data also fuels more sophisticated cyberattacks through social engineering and targeted fraud. Attackers can correlate your whereabouts with spending habits, social posts, and device usage to craft convincing phishing messages, fake support calls, or credential-reset scams. For example, seeing that you just visited a shopping mall or a specific campus building can help criminals personalize spam about credit-card fraud or IT alerts, increasing the chance you click a malicious link. Geotagged photos and live stories further amplify this risk by publicly broadcasting your precise coordinates. 

Mitigating these risks requires deliberate permission management and a mindset Of location sharing has become a routine feature in messaging, navigation, and social apps, yet it carries security and privacy risks that many users underestimate. While convenient for coordinating meetups or ensuring family safety, careless configuration can expose sensitive patterns about your daily life to strangers, advertisers, and even attackers who compromise the platforms you trust.

Ernst & Young Notifies Clients Following Third-Party Support Platform Data Breach

 

The company Ernst & Young (EY) has sent out notices to the affected clients about the data breach involving the third-party support ticket platform, which EY’s employees used, and therefore, potentially exposed documents with sensitive tax details to hackers. EY is one of the world’s largest accounting firms that is known to have faced a cybersecurity incident when the unauthorized party gained access to the third-party support ticket platform used by EY’s IT staff on March 28, 2026, and removed several documents from it, reported on April 23, 2026. 

A company statement noted, after reviewing the activity within its environment with the help of outside cybersecurity experts, that the threat actors accessed the EY environment between March 28, 2026, and April 12, 2026. As per the breach notification letter, the documents removed from the support platform could include personal information or financial information, as well as details provided to EY’s support teams during the process of submitting the tickets or in connection with the preparation of the clients’ tax returns. 

EY acknowledges that tax-related information may have been involved in the data security incident but chose not to identify what specific details were affected, as the breach notification letters also include placeholders for the affected customers’ personal information. The company also declined to indicate how many clients were affected by the breach or whether it was limited to the U.S., as there are other EY entities around the globe. EY announced that after detecting the issue, the company took measures to secure the affected systems by cutting down the unauthorized access, and notified the appropriate federal agencies. 

Furthermore, EY has found no evidence that the information from the breach had been deployed or that any particular individuals were the specific targets. Nevertheless, the firm offered its affected clients with credit monitoring and identity theft protection services for 24 months for free from Experian. The customers whose data was at risk were encouraged to sign up for the monitoring services by October 31, 2026. 

At the moment of the announcement, neither ransomware gangs nor data extortionists have claimed responsibility for the cyberattack, nor did any bad actors leak the data or sell it on the dark web. The attack involving the third-party support ticket platform yet again demonstrated the challenges organizations face regarding their ability to protect clients’ data and ensure that their vendors and partners do the same. 

Experts note that companies should invest in making sure their third-party vendors have reliable security practices in place, monitor their activity on a regular basis, and avoid storing any sensitive data on the platforms that can be accessed by numerous individuals, as in the case of EY’s tickets system, to mitigate the risks of supply chain breaches and data leakage incidents.

UK Biobank Data Breach Rekindles Debate Over Research Data Security

 

A recent case concerning the UK Biobank has once again brought up the topic of securing medical research databases, as well as the importance of keeping research data both accessible and private. Professor of Cancer Medicine at the University of Oxford David Kerr pointed out that while sharing scientific data is important, it is also essential to maintain the trust of the general public and ensure the privacy of those whose data is being used. 

UK Biobank is one of the biggest biomedical research databases in the world, established in the early 2000s. It consists of the medical information of half a million people aged between 40 and 69, who volunteered to participate in the program from 2006 to 2010. The database contains genetic, imaging, metabolic, and clinical data on each of the volunteers, making it extremely useful for research into cancer, heart disease, brain conditions, and many other illnesses. Scientists from various corners of the world can apply to use the anonymized data of the UK Biobank volunteers for research purposes. 

According to Professor Kerr, the data from the database has been used to facilitate over 18,000 scientific publications to date. The information contained in the database is anonymized, meaning that the names and other obvious personal identifiers of the donors are removed. However, their ages and sexes are still available for scientific use. The data is invaluable to scientific research, as it has been found to be instrumental in facilitating major medical breakthroughs. 

However, the controversy involving the UK Biobank occurred when three scientists who had accessed the data were accused of trying to sell a part of the database containing the information on thousands of anonymous donors through Alibaba, an international Chinese online marketplace. It is reported that both the UK and Chinese authorities managed to remove the data from the marketplace before any purchases had been made. 

As a result, the three scientists lost their access to the database, and an investigation is currently underway to determine the full extent of the breach and whether personal information has been compromised. UK Biobank has issued a formal apology, calling the security breach a serious matter and stating that they are currently reviewing their security measures. 

According to Professor Kerr, while the database contains a wealth of information that has led to unprecedented international collaboration and research opportunities, such data has to be protected at all times. He noted that with the growing importance of biomedical research, large-scale health data sets have become targets for similar breaches, which has raised multiple concerns for the general public. 

Therefore, both the UK Biobank and the wider scientific community must continue working on protecting medical data sets while allowing unrestricted international collaboration and research.

AssuranceAmerica Data Breach Exposes Personal Information of Nearly 7 Million Individuals

 

Auto insurance company AssuranceAmerica is notifying almost 6.99 million people of the possible exposure of their private information after experiencing a data breach. The company appeared on the state attorney generals earlier this month to reveal the cyberattack occurred on March 16th 2026. 

Almost 7 million clients’ personal information was copied after hackers infiltrated the system using company employees’ credentials before being discovered a day later; they are now alerting policyholders and advising them to remain wary of contacting financial institutions as imposters may be using the stolen information to impersonate them Company officials stated that the information acquired from the breach includes customer’s name, address, social security numbers, driver license numbers, tax ID numbers, insurance policies, and claims history. 

South Carolina, for instance, has over 611,000 customers affected by the data theft, making it the state with the most affected people. The security analysts note that the exposure of personal information such as social security and driver’s license numbers increases the risk of identity theft since the stolen data provides an avenue for thieves to open credit accounts in someone’s name, take out loans, submit fraudulent taxes, circumvent identification processes, and even more. 

Edelson Lechtzin LLP law firm, which is investigating the exposure case, reports that the collected data can offer a wide window for committing financial fraud crimes against the unsuspecting ones. Though the company responded promptly to the issue by taking down their systems after discovering the unusual activity in their network on March 17th, the day after the cyberattack, customers were not notified of what occurred until mid-June, nearly 3 months later. 

According to the insurer’s report, the review of the compromised data concluded on June 15th, days before the customers were informed of what happened, which prompted consumer advocates to criticize the sluggish response by AssuranceAmerica. Furthermore, even though the company asserts that it has reinforced its system and reminded workers of the importance of cybersecurity awareness, it has not stated whether the affected people will be offered free credit monitoring or other services to guarantee their safety. 

The current case comes at a time when there has been a series of data breaches involving the exposure of people’s identities, with hackers targeting government-issued credentials such as licenses and passports. The attacks have been recorded in various industries, including the hospitality, finance, government, and technology sectors, and put every citizen at risk as their personal information is stored in numerous places. 

For instance, the individuals in the states affected by the breach should remain extra cautious when dealing with financial services, whether online or not, and apply for a security alert for their credit reports to help detect unauthorized applications for credit. They can also turn to their respective state attorney’s office to get more significant help. 

The AssuranceAmerica incident is a sobering reminder that the most effortless way to protect oneself is by changing passwords after such an occurrence, especially since other measures such as social security or driver’s license numbers may take longer to replace if they get into the wrong hands.

Govt: Kudankulam Data Breach Did Not Impact Nuclear Security, No Immediate Review Planned

 

The Centre has attempted to reassure the public that the data breach incident involving electronic files of the Kudankulam Nuclear Power Plant (KKNPP) has no implication on the nation’s nuclear security or reactor operations. Union Minister of State for Atomic Energy Jitendra Singh stated that the breach did not affect any sensitive nuclear facility or infrastructure. 

Singh stated during an interaction with reporters on the sidelines of the press conference on July 16 that there was no need for an immediate security review since the breach did not concern nuclear activities or reactors. Nuclear Power Corporation of India Limited (NPCIL), which manages the Kudankulam plant, claimed that the data breach incident did not disclose any sensitive information about reactors. 

“In the given scenario, the data breach is related to the Engineering, Procurement and Construction (EPC) contract for the Common Services–Balance of Plant (BoP) package for Units 3 and 4 under Implementation Agreement 7 (IA-7),” the NPCIL stated. It added that the EPC contract is signed with Reliance Infrastructure via a public tender process in 2018 for Kudankulam NPP. “The balance of plant involves many elements such as auxiliary systems, services, and infrastructure like cooling towers, which are comparable to those in conventional thermal power stations,” NPCIL noted.

It added that the BoP does not contain any nuclear power plant equipment or components or safety and security features. “In this context, NPCIL is not contemplating any First Information Report (FIR) as the cyber-attack was on the data of Reliance Infrastructure,” an NPCIL spokesperson said. They added that the information shared with Reliance Infrastructure during the tendering procedure included indicative drawings and technical specifications on the common services balance of plant, typically provided to all bidders. “This information did not include any sensitive nuclear safety information,” the spokesperson added. 

NPCIL stated that Reliance Infrastructure develops engineering drawings using the technical specifications and drawings provided by NPCIL in coordination with original equipment manufacturers (OEMs) for the approval process. The breach of data came after Reuters reported that ransomware group World Leaks exfiltrated more than 19,000 files from servers hosting Kudankulam Nuclear Power Plant, covering the 2016 fiscal year through mid-2025. 

According to the report, the documents contain details on control, cooling, and ventilation systems, suppliers, inspections conducted by Indian and Russian personnel, meeting records, and insurance data. The breach was attributed to a server managed by data centre infrastructure provider Yotta, hosted by third-party Reliance Group, which was responsible for the EPC contract for the Kudankulam NPP, admitting that the attack resulted in a partial data breach. 

Tamil Nadu-based Kudankulam Nuclear Power Plant currently operates two 1,000 MW VVER reactors and is set to commission four more reactors under the Russian technical collaboration agreement. The project aims to make Kudankulam one of India’s largest nuclear power parks with a total capacity of 6,000 MW. The data breach incident does not appear to affect the nuclear security or safety of the nation, as the government and NPCIL continue to emphasize. 

The breach did, however, raise concerns about the safety of digital assets and data security in various contracts, including those of critical infrastructure like Kudankulam NPP.

Japan's Largest Taxi Service Goes Offline After Cyberattack


Nihon Kotsu, Japan’s largest taxi operator, said that its systems were impacted in a cyberattack, causing the company to close down some of its infrastructure.

The incident happened last week and impacted business operations such as the company’s taxi dispatch system, currently offline.

Nihon Kotsu has an annual revenue of around $1 billion.

The company has 18,228 employees and has 8,588 taxis and over 2000 chauffeur vehicles.

Nihon Kotsu said in a statement, “We have confirmed that our internal systems were subjected to unauthorized external access (malware infection)”. It further added that “immediately after detecting the unauthorized access, we implemented emergency measures, such as disconnecting systems to prevent further damage.”

The impact

The company has closed down systems to offline to stop the threat but it has widely caused disruption in services.

The incident has disrupted web booking, car hire, reservation management, few internal systems, and telephone dispatch service.

Nihon Kotsu advised people to use the ‘GO’ taxi app instead, or use a taxi stand for booking a Nihon Kotsu vehicle. It is a major operational damage for a company that has one of  Tokyo’s biggest fleets but the manual working is still operational. The hire car reservation system is offline.

In a different announcement, Nihon Kotsu said that the “labor taxi” service for pregnant women is shut down in a few areas.

Investigation

The firm has brought in external cybersecurity experts to assist in investigating if there has been a data leak. The internal network has been separated to limit further spread.

Currently, no data leak has been confirmed and Nihon Kotsu will provide updates via official channels. “We are currently conducting a detailed investigation with specialized agencies into whether and to what extent data has been leaked. At this time, no information leak has been confirmed. However, in the unlikely event that we discover any leak or potential leak of personal information of our customers or related parties, we will promptly make an official announcement and contact those affected individually, in accordance with the law,” Nihon Kotsu said.

What next

Customers of Nihon Kotsu are cautioned not to click on any links in suspicious communications purporting to be from the company and not to open anything they receive. 

Mount Royal University says hackers stole and deleted files following June cyberattack





Mount Royal University (MRU) has confirmed that threat actors stole data and deleted files after breaching the university's network in a cyberattack that continues to affect recovery efforts weeks after the incident.

In an update published on its website, the Calgary-based public university said the attack occurred on June 17 and that internal technical teams are working alongside external cybersecurity specialists to investigate the intrusion, determine its full scope, and restore affected systems.

The cyberattack disrupted a wide range of university services, including internet connectivity, online platforms, and several internal systems used across campus. Recovery efforts remain ongoing, with the university warning that restoring all affected services may take several weeks or, in some cases, months.

According to the university's investigation, attackers gained unauthorized access to data stored on the institution's "H drive," a file storage system used by students and employees. Investigators have confirmed that files stored within certain folders were accessed and exfiltrated before the attackers deleted the original copies, a move that has further complicated recovery operations.

"We regret to inform our community that our investigation has now shown that data within certain folders on the University's 'H drive' was accessed and taken by an unauthorized actor," the university said in its advisory.

MRU said the affected folders contained information relating to current and former students, current and former employees, as well as other individuals whose data was stored within the impacted environment. The university has not yet disclosed the exact categories of information exposed or the total number of people affected.

The investigation also found that attackers deleted data stored on a separate departmental file storage system known as the "J drive." While the university said there is currently no evidence that information from the J drive was accessed or copied before it was erased, officials cautioned that recovering the deleted data remains an ongoing process and acknowledged that a complete restoration may not be possible.

The university has reported the incident to the Alberta Information and Privacy Commissioner and notified law enforcement authorities. Officials added that determining the precise impact for each affected individual will take time because the deletion of files has made forensic analysis more complex. Individuals whose information is confirmed to have been affected will receive direct notifications as the investigation progresses.

Responsibility for the attack has been claimed by the cybercrime group CMD Organization, which has published samples of what it alleges is stolen university data, including passport scans and other sensitive documents.

The group is demanding a ransom of 30 Bitcoin, valued at approximately $1.9 million at current exchange rates, and has reportedly given the university six days to respond before releasing additional data. CMD Organization also appears to operate an auction-based extortion model, advertising exclusive access to stolen datasets for the highest bidder through both clear web and dark web leak sites. At the time of writing, the group lists approximately 30 organizations on its extortion portal.

Founded more than a century ago, Mount Royal University currently serves about 11,560 students, including roughly 12,500 undergraduate learners.

As recovery work continues, the university said it will provide additional updates as more information becomes available. MRU is also offering two years of credit monitoring and identity theft protection to current employees and individuals who have worked at the university within the past five years.

Council of Europe Data Breach Exposes Records of 10000 Employees After ShinyHunters Leak


 

Council of Europe is investigating a major data breach following the public release of approximately 297 GB of sensitive employee data by cybercriminal group ShinyHunters following the expiration of a ransom deadline. 

An archive has been leaked that contains information regarding more than 10,000 current and former employees, contractors, and job applicants dating from 15 years ago. As one of Europe's leading human rights organizations since 1949, the Council of Europe has been an official observer at the United Nations since 1949. It represents 46 member states and is a central force in promoting democracy, human rights, and the rule of law throughout Europe. 

Since the information it holds is sensitive, the breach of confidentiality is particularly significant. As reported by ShinyHunters, more than 429,000 files, including personnel data, were obtained from multiple Council departments, including human resources and administrative units. This was one of the largest breaches of personal data involving an intergovernmental organization in Europe. 

Information available indicates that payroll records, bank account information, medical information, tax information, social security information, salary histories, personnel files, and thousands of CVs were exposed. Due to the large size of the dataset, identity theft, financial fraud, and highly targeted phishing are significantly more likely to occur. It has been reported that the breach is related to CVE-2026-35273, a critical 9.8-severity zero-day vulnerability affecting Oracle PeopleSoft's Environment Management Hub (PSEMHUB). 

According to security researchers, the vulnerability allowed attackers to execute arbitrary code remotely without authentication. According to Google's Mandiant team, more than 100 organizations had actively exploited the vulnerability prior to Oracle's release of security guidance. Using the zero-day vulnerability in combination with older vulnerabilities, ShinyHunters obtained persistent access, migrated laterally through compromised environments, and exfiltrated data while posing as legitimate users. 

The exploit was conducted between May 27 and June 9, before mitigations were available. ShinyHunters has also altered its extortion strategy significantly following the Council of Europe declining to meet the ransom demand. In response to the Council's refusal to pay the ransom, ShinyHunters announced it would permanently distribute stolen datasets through multiple mirror sites and torrent networks, thereby reducing the likelihood of future takedown efforts.

In addition, the incident adds to the growing number of campaigns involving ShinyHunterS Researchers have recently linked the group to attacks targeting multiple organizations, while Google's threat intelligence team has linked the group's latest activity to widespread exploitation of the Oracle PeopleSoft zero-day vulnerability before mitigations were available. 

According to a brief statement issued by the Council of Europe, the organization was "investigating the matter and assessing the situation." Further comment was not provided. The organization has not yet announced a formal notification process or measures to protect individuals' identities. Zero-day exploitation and data extortion campaigns are becoming increasingly prevalent, with public disclosure increasingly taking precedence over traditional ransomware encryption. 

The threat of persistent leak strategies is increasing, which is why organizations are being urged to strengthen vulnerability management, accelerate patch deployment, and improve incident response to minimize both institutions and individuals' long-term risks.

Nissan Confirms Employee Data Breach Following Oracle PeopleSoft Zero-Day Cyberattack

 

Nissan has confirmed that it fell victim to a third-party cyberattack after being targeted as an Oracle PeopleSoft user, making it the latest company to suffer an attack due to a yet-revealed vulnerability. The breach is currently under investigation, with Nissan reporting that the attackers could have accessed the personal data of thousands of employees worldwide. 

Based on the breach notification sent to the California Department of Consumer Affairs, Nissan Americas uses Oracle PeopleSoft to perform essential employee management functions, including payroll, taxes, and record-keeping. The attack relied on a zero-day flaw, CVE-2026-35273, which was patched later, with the vulnerability already being actively exploited. There breached data is reported to affect current and former employees in the United States, Canada, Mexico, and Brazil. 

Notably, the data includes social security, banking, financial, and tax information. Nissan is currently investigating the scope of the damage, with the company yet to conclude its research. Researchers report that ShinyHunters extortion gang is behind the identified Oracle PeopleSoft-related attacks, with over 100 companies already reportedly identified as victims of the zero-day flaw. 

Although Nissan was not found on the ShinyHunters data leak site, reports suggest that the cybercriminals might still use the data for extortion. It remains unclear whether the breached data would be published or utilized in ransomware attacks by the threat actors. The vulnerability affecting Oracle PeopleSoft, which has been reported to affect thousands of enterprise users worldwide, continues to raise concerns. 

Since the affected software is designed for critical data, including employee management, the security flaw may have severe implications. Besides Nissan, several companies have been reported to fall victim to the vulnerability, with Everest Ransomware Group recently claiming to have stolen customer data from the car manufacturer. Cybercriminals seem to target major manufacturers, including those based in the United States and threatening to expose the data for extortion. 

Although only a handful of companies have officially confirmed to be victims of the Oracle PeopleSoft cyberattack, others are likely to suffer due to the scale of the problem. National Association of Insurance Commissioners recently confirmed being a victim of the attack, with the University of Nottingham also reportedly being among the affected institutions. 

The most significant damage, however, seems to be related to the education sector, with Illinois Central College and Moody Bible Institute being the only two confirmed victims at the time of the publication. According to cybersecurity analysts, the sector has suffered the largest fallout from the PeopleSoft attack, with several universities reportedly being targeted by the ShinyHunters extortion gang. 

Another PeopleSoft cyberattack serves as a reminder of the constant security challenges facing enterprise users relying on the application to protect sensitive employee data. With investigations into the breach underway, more companies may be identified as victims of the attack in the coming weeks.

Hackers Breached Kubota, Employee Data Compromised


Kubota North America Corporation revealed that threat actors compromised its network systems and accessed few resources for over a month in the beginning of 2026.

After an investigation of the breach, the organization discovered that between March and April, the hacker accessed files carrying personal data of employees.

About Kubota 

It is a Japanese industrial manufacturer famous for its construction and agricultural work. Kubota has plants in 120 counties and currently employs over 52,000 people. Kubota has an annual revenue of $20 billion.

The North American division consists of facilities that make utility vehicles, tractors, and mowers. 

About the data leak

“We discovered that files maintained by our human resources team were accessed as part of this incident. We carefully reviewed these files, and on June 16, 2026, we determined that one or more files may have contained personal information related to certain employees and their dependents,” Kubota reported on its site.

What may have been leaked?

As per the announcement posted on the Kubota USA portal, the following employee information may have been revealed:

  • Social security numbers (for dependents too)
  • Full employee names (for dependents too)
  • Dates of birth (for dependents too)
  • IDs of taxpayers
  • Bank account details of direct deposit
  • Corporate payment card details
  • Benefits enrollment data and limited claims information (for dependents too)
  • Driver’s license details or other government IDs

Attack tactic

The specific data that was exposed varies per person. Kubota also started sending personalised mails to inform the individuals about the exact impact on them.

The notification information consists step by step instructions for using Kroll identity protection to help the targets address the threats coming from the leak of their personal data. 

Kubota has specially advised people to look out for bank accounts and  healthcare related statements and promptly report any malicious activity to the concerned authorities.

Safety measures

Kubot has implemented robust security measures to avoid such incidents from happening in the future. 

No cybercrime gangs, data extortion gangs, or ransomware gangs have claimed responsibility for the Kubota breach.

Kubota did not report any operational or business disruptions due to the breach.

On ensuring employee safety, Kubota said, “We take the privacy and confidentiality of our employees’ information very seriously. To help prevent something like this from happening again, we have taken and will continue to take steps to further enhance our existing security measures.” 

Hackers Steal Encrypted Password Vaults in Dashlane Attack

 

Dashlane’s June 2026 breach is a reminder that even password managers can become targets when attackers focus on account access rather than the encrypted vault itself. In this case, hackers used brute-force attacks against Dashlane’s two-factor authentication flow, gained access to a small number of customer accounts, and downloaded encrypted password vaults. 

According to Dashlane’s disclosure, the attackers targeted the device-registration process, which lets a new phone or computer be added to an account after verification. Dashlane said the campaign affected about 20 customer accounts and resulted in at least a dozen encrypted vaults being copied, while the company’s own infrastructure was not compromised. 

The good news is that the stolen vaults are still encrypted and cannot be opened without each user’s master password. Dashlane’s zero-knowledge design means it does not store master passwords in plaintext, so the immediate risk depends heavily on how strong and unique the user’s master password is. That said, the incident still matters because an encrypted vault can be dangerous if the master password is weak, reused, or already exposed elsewhere. Security researchers also noted the broader lesson: once attackers have a copy of the vault, they can attempt offline cracking without triggering more defenses on the service side. 

For users, the safest response is to change the master password to a long, unique passphrase, review recently registered devices, and reset any sensitive accounts stored in the vault, starting with email, banking, and identity services. It is also wise to use phishing-resistant 2FA such as a hardware security key where possible, and watch for suspicious password-reset emails for the next few weeks.

MyPillow Private Data Leaked Online After Mike Lindell Denies Hack

 

Mike Lindell, CEO of MyPillow, insists his company was never hacked, but a ransomware group leaked nearly 12,000 internal files online just two days after his public denial. The Play ransomware gang published a 9.8-gigabyte data cache containing sensitive financial, payroll, and personal information from the pillow manufacturer, directly contradicting Lindell’s claim that MyPillow was “the most secure company” in the country. 

The attack began when Play announced on its dark web blog last week that it had stolen data from MyPillow, threatening to publish everything on Friday if ransom demands were not met. In a Wednesday telephone interview with Straight Arrow News, Lindell said he never received any ransom demand and asserted no data was taken, calling the allegations “another hit job by outside sources because I’m running for governor”. He is currently seeking the Republican nomination for Minnesota governor. 

Straight Arrow’s initial analysis of the leaked data revealed nearly 1,000 vendor invoices, including payments to high-profile figures like Trump Media & Technology Group (owner of Truth Social), conspiracy theorist Alex Jones, and Lara Trump. Documents show MyPillow paid Lara Trump $2,156.33 for advertising services in December 2023 and wired $4,023.16 to Jones’ Free Speech Systems the same month for running a company promo. Bank statements, audit files, wire transfers from 2026, and American Express statements for Lindell’s businesses including FrankSpeech (now LindellTV) are also present. 

The data breach exposes severely sensitive personal information, including payroll records with employees’ full names and phone numbers, plus tax forms like 1099s and W-9s containing names, addresses, and Social Security numbers. A folder titled “Aviation” contains private jet expenses and flight logs from 2018 to 2024. The files span from before 2011 through 2026, covering over a decade of internal company operations. 

Lindell claimed his company stores no sensitive data internally and relies on external third parties, but the leaked cache proves otherwise. When Straight Arrow shared photos of the data with Lindell via text, he did not immediately respond. This incident follows MyPillow’s 2019 Magecart credit card hack, raising serious questions about the company’s cybersecurity posture as Lindell campaigns for governor.

Trump Mobile Data Leak Exposes Customer Information as Questions Grow Around T1 Smartphone

 

Following confirmation by Trump Mobile, fresh attention has turned toward the company over a breach affecting its T1 smartphone users. Sensitive data - such as contact numbers, residential locations, emails, and additional private records - appeared publicly online, sources indicate. This exposure casts doubt on how securely the firm manages user information. Questions emerge about safeguards meant to protect personal details. 

A statement from a Trump Mobile representative confirmed none of the leaked data involved monetary records. Yet word emerged solely once people found their private info appearing on web platforms. Skeptics wonder about the delay in alerting impacted clients despite clear dangers tied to such leaks. Despite awareness, updates reached users well after exposure occurred. Blame for the event points toward an outside tech partner handling parts of Trump Mobile's systems. 

Though confirmation came from Trump Mobile about information being exposed, the specific vendor stayed unnamed in public updates. Details about customer notifications remain unclear, with no official word on outreach efforts so far. Later arriving than first planned, the phone now joins past problems tied to the Trump Mobile T1 handset. Though initially set for an August 2025 release, several setbacks pushed delivery further into delay. 

At first, ads insisted production would happen within U.S. borders - this messaging changed over time, replaced by phrases like "crafted around American ideals." Despite its appeal, the T1 phone faces scrutiny due to visual and sourcing concerns. A golden exterior carries a symbolic banner on the rear - yet close inspection reveals just eleven bars where thirteen should appear. Some watchers point out discrepancies resembling those seen in national imagery. Doubt emerges too around innovation claims, given speculation it may simply repurpose another model already on the market. 

Some industry analyses point to similarities between the T1 and earlier Android phones, many made outside domestic markets. Because of these links, questions about its cost have grown - priced above five hundred dollars, it stands out next to far cheaper counterparts. Though not identical, enough resemblance exists to spark discussion among buyers and critics alike. Worries have grown since details of the leak came to light, touching both users and analysts. 

Though Trump Mobile insists nothing related to money was exposed, risks tied to trust and safety surface when private details are found unprotected on the web. With reviews still underway, clarity could become a priority - especially around how the event unfolded and what happens behind the scenes with user records.

MyPillow Hit by Ransomware Attack as Cyber Threats Intensify


 

MyPillow, a Minnesota-based bedding manufacturer founded by Mike Lindell, has been targeted by a ransomware group. This adds the company to a growing list of organizations that are currently under cyber extortion threats. As a result of the unauthorized access to a broad range of sensitive corporate and personal records, identified as Play, the threat actor claims that payroll data, financial information, tax information, identification information, and internal business files have been exfiltrated. 

The claims have attracted attention due to the sensitive nature of the alleged exposed data, even though Lindell has denied the allegations and described them as politically motivated. As a result of this incident, the risks associated with modern ransomware campaigns are evolving, resulting from increased data theft and public exposure, which often accompany or replace traditional file encryption methods. 

MyPillow has become increasingly aware that its network has been compromised and its company data has been stolen as further details emerge from the alleged intrusion. It was reported that CEO Mike Lindell dismissed the claims when they first emerged in May 2025, however, the threat actors later released approximately 9.8 gigabytes of data via a dark-web leak portal, a tactic commonly used to pressure organizations unwilling to negotiate ransom. 

There are 11,456 files reported in the dataset dating from 2011 through 2026, indicating that historical records of the company have been preserved alongside more recent information about the company. This exposure indicates that the attackers obtained sensitive operational data, including payroll records and financial transactions, indicating the potential depth of the compromise, as well as raising further concerns about how long unauthorised access will remain within the company's network. 

Play's dark-web leak portal revealed the allegations of MyPillow, listing the company among its claimed victims and setting a deadline for public release of purportedly stolen information if ransom negotiations failed. The allegations gained further visibility when MyPillow appeared there. Ransomware operations are evolving in a broader sense, with attackers increasingly stealing data and threatening to publish it, as opposed to relying solely on file encryption to threaten victims.

In the ransomware ecosystem, data-centric extortion tactics are becoming increasingly popular. Modern threat groups increasingly prioritize stealing sensitive information over system encryption as a means of disrupting business operations. By leveraging the threat of public disclosure, they are exerting pressure on victims by leveraging the theft of sensitive information. By adopting this approach, organisations become more vulnerable to reputational damage, regulatory scrutiny, legal liabilities, and heightened concerns about employee and customer privacy as a result of an incident. 

The lack of verification can lead to unverified claims of data compromise quickly escalating to a broader business risk, prompting questions about the security posture of the organization and the integrity of data that has been entrusted to it from stakeholders, partners, insurers, and regulators. In addition to the nature of the alleged cyber intrusion, the incident has gained heightened public attention as a result of the company's and its leadership's high profile. 

During Mike Lindell's tenure, MyPillow has grown beyond its flagship bedding products to include mattresses, linens, bath products, nutritional supplements, coffee, and snacks. Since Lindell is a political activist and continues to promote disputed claims regarding the 2020 U.S. presidential election, MyPillow's public profile extends beyond retail. These claims have resulted in multiple legal challenges, making any major development involving the company likely to be of interest to individuals outside the cybersecurity community as well. 

The consequences of such an unverified claim of data compromise are that it quickly escalates into a broader business risk, causing stakeholders, partners, insurers, and regulators to inquire about the organization's security posture and the integrity of data entrusted to it. Due to the nature of the alleged cyber intrusion as well as the profile of the company and its management, the incident has heightened public attention. 

Since Mike Lindell has become President of MyPillow, it has expanded its product line beyond its bedding offerings to encompass mattresses, linens, bath products, nutritional supplements, coffee, and snack items. Due to Lindell's political activism and ongoing promotion of disputed claims surrounding the 2020 United States presidential election, MyPillow's public profile has extended beyond retail. 

A number of legal challenges have been brought against the company for these claims, making any major development involving the company likely to draw attention from outside the cybersecurity community as well. 

According to Lindell, political controversy has negatively impacted MyPillow's business, indicating that independent assessments have estimated an estimated $400 million in losses to the company and brand. Additionally, Lindell indicated that he plans to seek compensation through President Donald Trump's recently instituted $1.8 billion Anti-Weaponization Fund, an initiative that has become the subject of political debate and controversy. 

Since several years, MyPillow has had financial difficulties, particularly after major retailers, including Walmart, Kohl's, J.C. Penney, Wayfair, and Bed Bath & Beyond, removed its products from their shelves as a result of the events surrounding January 6. While Lindell has maintained that these decisions were politically motivated, several retailers have indicated that declining consumer demand played a significant role in these decisions. Due to this, the ransomware claims are coming at a time when the company is already confronting legal disputes, reputational pressure, and broader political controversy. 

The ten candidates who seek the Republican nomination to run for Minnesota’s gubernatorial office include Lindell, who will face Senator Amy Klobuchar as the Democratic frontrunner after Governor Tim Walz has decided not to seek another term. 

Based on the information reportedly exposed through the leak, it appears as though access has been gained to some of the company's most important financial and personnel records. It is believed that the breach resulted in the theft of Social Security numbers, tax documentation including W-9 and 1099 forms, payroll records containing employee contact information, bank statements, wire transfer documentation, American Express account statements, vendor billing records, advertising expenditure reports, internal audit documents, budgeting materials from the corporation, and even aviation-related expense logs associated with private aircraft operations. 

From a data security and compliance perspective, the breadth of the dataset indicates that the attackers may have accessed systems that contained both administrative and operational information, thus increasing the severity of the incident. 

From a data security and compliance perspective, MyPillow has not disclosed how many people were potentially affected, whether external incident-resolution specialists were consulted, or whether identity theft protection services were offered to the affected. It remains unclear, therefore, how the breach was disclosed, how notifications were carried out, and how the company is conducting remediation efforts.

In addition to the immediate allegations, this incident illustrates an important aspect of cybercrime: access to sensitive information has become just as valuable to threat actors as access to systems. In this case, it is likely that the outcome will be determined not only by what was accessed, but also by what was disclosed.

Millions of Devices at Risk: New Trojan Monitors Smartphones

 

A menacing new Trojan has emerged that puts millions of smartphone devices worldwide at risk, according to recent cybersecurity reports. This sophisticated malware specifically targets Android devices and has already infected thousands of users across 143 countries. The Trojan's ability to monitor smartphones in real-time represents a significant evolution in mobile cyberthreats, with security researchers warning that the actual infection count could be far higher than currently detected.

The malware spreads primarily through seemingly legitimate websites that trick users into downloading malicious applications. Once installed, the Trojan grants hackers complete remote control over compromised devices, enabling live monitoring of user activities. Security firm Zimperium zLabs identified similar dangerous Trojans like Arsink, which impersonates popular brands including WhatsApp and TikTok to evade detection. The infected devices can have their audio recorded, text messages read, and even be wiped completely by attackers. 

This Trojan's most alarming capability is its live monitoring feature combined with coordinated attack systems. Beyond stealing credentials, the malware transmits live screen content to remote servers, creating a continuous visual feed that allows attackers to observe activity and intercept authentication steps in real time. Encrypted communication channels connect infected devices to centralized command systems that coordinate attacks and distribute updated instructions, managing thousands of compromised devices simultaneously. The infection has created a massive footprint, with Egypt reporting around 13,000 compromised phones, Indonesia approximately 7,000, and Iraq and Yemen each with 3,000 infections. 

The Trojan harvests an extensive range of sensitive data including SMS messages, call logs, contacts, device location, and Google account information. It can steal user accounts in messengers and social networks, stealthily send messages on behalf of victims, monitor browser activities, replace links, swap numbers during calls, and intercept SMS messages. Previous similar malware campaigns have already stolen at least $270,000 worth of cryptocurrency, suggesting the financial damage from this new Trojan could be substantial. 

Experts recommend several critical protection measures to safeguard against this threat. Users should only download applications from official app stores like Google Play, avoid clicking links from suspicious websites, and keep their Android operating system updated with the latest security patches. Google has warned that over 40% of Android devices remain vulnerable because they run outdated versions without security support. If your smartphone brand no longer provides security updates, experts strongly recommend considering a new device to protect your personal data.

9-Year-Old Linux bug Found by Researchers, Could Leak Data


Experts have revealed details of a bug in the Linux kernel that stayed unnoticed for nine years. The flaw is tracked as CVE-2026-46333 (CVSS score: 5.5). 

Improper bug management 

The incident is improper privilege management that could have allowed threat actors to reveal sensitive data as unprivileged local users and launch arbitrary commands on default installs such as Ubuntu, Debian, and Fedora. Its alias is aka ssh-keysign-pwn.

Vulnerability existed since 2016

Cybersecurity firm Qualys found the flaw. Since November 2016, the problem has been present in mainstream Linux (v4.10-rc1). 

Distribution updates and upstream patches are already accessible. There are publicly available working exploits, thus administrators should install vendor kernel upgrades right away, Qualys said.

Privilege compromise tactic

TRU discovered a small window in which a privileged process that is dropping its credentials can still be accessed through ptrace-family operations, despite the fact that its dumpable flag should have blocked that path, during ongoing study into Linux kernel privilege boundaries.  

Qualys also added that an attacker can obtain open file descriptors and authenticated inter-process channels from a dying privileged process and utilize them under their own uid by combining this window with the pidfd_getfd() syscall (introduced in v5.6-rc1, January 2020)

What is successful exploit?

Successful bug exploit can allow a local threat actor to reveal /etc/shadow and ho'st private keys under /etc/ssh/*_key, and deploy arbitrary commands as root via four distinct hacks attacking ssh-keysign, accounts-daemon, chage, and pkexec.

PoC exploit

The bug reveal is a proof-of-concept (PoC) exploit for the bug. It was released recently, and soon after, a public kernel surfaced. CVE-2026-46333 is the latest security bug revealed in Linux after Dirty Frag, Fragnesia, and Copy Fail in recent months.

How to stay safe

Experts have advised to use the latest kernel update released by Linux distributions. If users are unable to do it immediately, temporary patchwork includes raising "kernel.yama.ptrace_scope" to 2.
Qualys added, "On hosts that have allowed untrusted local users during the exposure window, treat SSH host keys and locally cached credentials as potentially disclosed. Rotate host keys and review any administrative material that lived in the memory of set-uid processes,” Qualys said.

Incident impact

The incident happened after the release of a PoC for a local privilege exploit known as PinTheft that lets local hackers get access to root privileges on Arch Linux systems. The hack requires the Reliable Datagram Sockets (RDS) module to be deployed on the victim system, readable SUID-root-binary, io_ring enabling, and x86_64 support for the given payload.

Data Leak: Instructure, Canvas Allegedly Hacked, ShinyHunters Claim Responsibility


Instructure, a cloud-based LMS Canvas company was hit by a massive data attack. Ransomware gang ShinyHunters claimed responsibility for the attack, saying that it had stolen data related to 280 million students, teachers, and school staff.

100s of GBs data leaked

The data breach accounts for hundreds of gigabytes, possibly leaking Canvas users’ email ids, private messages, and names. 

Instructure revealed in May that it was hit by a data breach. The Canvas incidents of 8,809 universities, educational platforms, schools were impacted by the attack. ShinyHunters said that the numbers range between tens of thousands to several millions per institution.

It is concerning that a lot of K-12 students’ data has been leaked. If your child has been affected by the data breach, Malware Bytes can help in what to do next and how to stay safe.

Canvas compromised

Various students who tried using Canvas after the cyberattack received the message from ShinyHunters blackmailing to leak the data if Instructure did not contact the hackers by May 12. Canvas was shut down offline for various students following the incident, but it is now available for most users. 

GTA 6, Studio Rockstar were blackmailed too

ShinyHunters has been killing it this year, with only high profile targets in its track records. The group asked for a ransom from GTA 6 (a video game) Studio Rockstar in April. But in reality, it was a hoax demand as the hackers did not have anything important/worthy to leak. 

Nvidea Geforce allegedly hacked

But recently, the group allegedly claimed responsibility for the Nvidea’s GeForce Now breach, claiming to have “pulled their entire database straight from the backend."

Shiny hunters all over the place

In the Canvas incident, ShinyHunters allegedly stole user records through exposrting features inside the platform. This consists of DAP queries, APIs, and provisioning reports, according to Bleeping Computers. “The unauthorized actor carried out this activity by exploiting an issue related to our Free-For-Teacher accounts,” Instructure said. 

It also added that it “revoked privileged credentials and access tokens, deployed platform-wide protections, rotated certain internal keys, restricted token creation pathways, and added monitoring across our platforms." 

The impact

Instructure also “engaged a third-party forensic firm and notified law enforcement. Beyond the immediate response, we're hardening administrative access, token management, permissions, monitoring, and related workflows. The investigation may inform further improvements.”

However, it might be too little, too late—parents are unlikely to overlook the possibility of disclosing their children's information. The much bigger problem, though, is the disastrous harm ShinyHunters has caused to Canvas's operations and reputation, as malware historian vx-underground stated on X.