No new CISA KEV catalogue additions in this collection window.
Victim: INGKA GROUP | Group: lapsus$ | Website: ingka.com | Country: SE | Details: Full mapping of global e-commerce architecture and internal coworker platforms. Supply chain logistics, cloud infrastructure, and AI/MLOps repositories
Victim: coe.int | Group: shinyhunters | Website: coe.int | Country: FR | Details: Over 297 GB of Council of Europe HR and payroll data (429,000+ files) was compromised across the Secretariat, Directorate of Human Resources, Parliamentary As
Victim: www.mbt-energy.com | Group: krybit | Website: www.mbt-energy.com | Country: DE | Details: Xiamen Mibet New Energy Co., Ltd. (Mibet Energy) is a Chinese high-tech enterprise specializing in the research, develop...
Victim: Charisma Media | Group: securotrop | Website: charismamedia.com | Country: US | Details: Status: AWAITING Size: 808 GB
Victim: Daechang Solution | Group: Black X | Website: dsol.co.kr | Country: KR | Details: We possess all the core technical data of Daechang Solution. (Technical Research Institute, Valve Team, Cryogenic Team, Innovation Team, Sales Team, F
Victim: Bni.co.id bank of indonesia free data. | Group: Triple X | Website: Bni.co.id | Country: ID | Details: BANK of indonesia bni.co.id Customer information from 2024 to 2026 All customer contracts, passports, and ID cards (few pic attac
Victim: Law Offices US immigrationonline.com | Group: Triple X | Website: immigrationonline.com | Country: US | Details: https://immigrationonline.com/ 1.5 terabytes of people's data in a immigrationonline law firm. Server overload and lack
Victim: GITHUB INTERNAL | Group: lapsus$ | Website: github.com | Country: US | Details: Everything for the main platform is there. No ransom, we do not care about extorting Github. If no buyer is found, we leak for free.
Splunk has released security updates to address a critical security flaw in Splunk Enterprise that could be exploited to conduct unauthenticated file operations and even remote code execution. The vulnerability, tracked as CVE-2026-20253, is rated 9.8 on the
By default, npm install will no longer execute scripts from dependencies, unless explicitly allowed. The post NPM 12 Will Change Script Execution Behavior to Prevent Supply Chain Attacks appeared first on SecurityWeek.
Chinese hackers took control of a target organization's authentication stack and maintained persistence for 10 years, with full visibility into the administrative activity. [...]
A former IT employee at an Iowa school district was sentenced to 21 months in prison after conducting a prolonged cyberattack against the former employer that disrupted classroom operations, deleted accounts, and caused tens of thousands of dollars in damages
The US government has ordered Anthropic to block all foreign nationals from accessing Fable 5 and Mythos 5, forcing the company to suspend both models worldwide. Anthropic is complying but disputes the basis, calling the cited jailbreak narrow and the capabili
Anthropic said on Friday it will "abruptly disable" its most advanced artificial intelligence (AI) models, Claude Fable 5 and Mythos 5, for all users after the U.S. government ordered it to suspend access to the models for foreign nationals, whether inside or
Anthropic takes Fable 5 and Mythos 5 offline to comply with a directive from the Trump administration to prevent use by foreign nationals. The post Anthropic Says It Has Taken Its Latest AI Models Offline to Comply With New Export Controls appeared first on Se