CYBER INTELLIGENCE REPORT

// 14 June 2026  ·  AUTOMATED THREAT DIGEST //
15Items
1Critical
0KEV
8DLS Victims
6Ransom Groups

CISA Known Exploited Vulnerabilities

No new CISA KEV catalogue additions in this collection window.

Ransomware Data-Leak Victims

11lapsus$

INGKA GROUP

Victim: INGKA GROUP | Group: lapsus$ | Website: ingka.com | Country: SE | Details: Full mapping of global e-commerce architecture and internal coworker platforms. Supply chain logistics, cloud infrastructure, and AI/MLOps repositories

SE
9shinyhunters

coe.int

Victim: coe.int | Group: shinyhunters | Website: coe.int | Country: FR | Details: Over 297 GB of Council of Europe HR and payroll data (429,000+ files) was compromised across the Secretariat, Directorate of Human Resources, Parliamentary As

FR
6krybit

www.mbt-energy.com

Victim: www.mbt-energy.com | Group: krybit | Website: www.mbt-energy.com | Country: DE | Details: Xiamen Mibet New Energy Co., Ltd. (Mibet Energy) is a Chinese high-tech enterprise specializing in the research, develop...

DE
5securotrop

Charisma Media

Victim: Charisma Media | Group: securotrop | Website: charismamedia.com | Country: US | Details: Status: AWAITING Size: 808 GB

US
5Black X

Daechang Solution

Victim: Daechang Solution | Group: Black X | Website: dsol.co.kr | Country: KR | Details: We possess all the core technical data of Daechang Solution. (Technical Research Institute, Valve Team, Cryogenic Team, Innovation Team, Sales Team, F

KR
5Triple X

Bni.co.id bank of indonesia free data.

Victim: Bni.co.id bank of indonesia free data. | Group: Triple X | Website: Bni.co.id | Country: ID | Details: BANK of indonesia bni.co.id Customer information from 2024 to 2026 All customer contracts, passports, and ID cards (few pic attac

ID
5Triple X

Law Offices US immigrationonline.com

Victim: Law Offices US immigrationonline.com | Group: Triple X | Website: immigrationonline.com | Country: US | Details: https://immigrationonline.com/ 1.5 terabytes of people's data in a immigrationonline law firm. Server overload and lack

US
5lapsus$

GITHUB INTERNAL

Victim: GITHUB INTERNAL | Group: lapsus$ | Website: github.com | Country: US | Details: Everything for the main platform is there. No ransom, we do not care about extorting Github. If no buyer is found, we leak for free.

US

Security News

8TheHackerNews

Critical Splunk Enterprise Flaw Lets Attackers Run Code Without Authentication

Splunk has released security updates to address a critical security flaw in Splunk Enterprise that could be exploited to conduct unauthenticated file operations and even remote code execution. The vulnerability, tracked as CVE-2026-20253, is rated 9.8 on the

CVE-2026-20253
4SecurityWeek

NPM 12 Will Change Script Execution Behavior to Prevent Supply Chain Attacks

By default, npm install will no longer execute scripts from dependencies, unless explicitly allowed. The post NPM 12 Will Change Script Execution Behavior to Prevent Supply Chain Attacks appeared first on SecurityWeek.

3BleepingComputer

Chinese hackers hijack auth flow, spy on isolated network for a decade

Chinese hackers took control of a target organization's authentication stack and maintained persistence for 10 years, with full visibility into the administrative activity. [...]

0BleepingComputer

Ex-school district employee jailed for hacks on former employer

A former  IT employee at an Iowa school district was sentenced to 21 months in prison after conducting a prolonged cyberattack against the former employer that disrupted classroom operations, deleted accounts, and caused tens of thousands of dollars in damages

0BleepingComputer

US Gov asks Anthropic to ban 'foreign national' access to Fable, Mythos

The US government has ordered Anthropic to block all foreign nationals from accessing Fable 5 and Mythos 5, forcing the company to suspend both models worldwide. Anthropic is complying but disputes the basis, calling the cited jailbreak narrow and the capabili

0TheHackerNews

U.S. Orders Anthropic to Suspend Fable 5 and Mythos 5 Access for Foreign Nationals

Anthropic said on Friday it will "abruptly disable" its most advanced artificial intelligence (AI) models, Claude Fable 5 and Mythos 5, for all users after the U.S. government ordered it to suspend access to the models for foreign nationals, whether inside or

0SecurityWeek

Anthropic Says It Has Taken Its Latest AI Models Offline to Comply With New Export Controls

Anthropic takes Fable 5 and Mythos 5 offline to comply with a directive from the Trump administration to prevent use by foreign nationals. The post Anthropic Says It Has Taken Its Latest AI Models Offline to Comply With New Export Controls appeared first on Se

Ransomware listings reflect unverified claims published on criminal data-leak sites. Organisations named should treat these as alleged compromises pending independent confirmation.