Archive
Cyber Threat Intelligence
44 editions
June 2026
10 editions- 11 Jun Oracle Patch, OceanLotus Campaigns, OnyxC2 Stealer Hit HeadlinesOracle patches PeopleSoft zero-day amid ShinyHunters claims; OceanLotus targets Vietnam investors; OnyxC2 stealer emerges; CISA issues new patch directive.
- 9 Jun Qilin Exploits Check Point Zero-Day; AI Worm PoC EmergesCheck Point VPN zero-day fuels Qilin; AI weaponizes N-days in hours; Shai-Hulud hits 100+ packages; NSA and Coinbase claimed; 123 events.123 ev 59 crit
- 8 Jun Hacktivists Swarm Israel as Breach Claims Pile Up Worldwide189 incidents logged June 8, including 79 alleged breaches and leaks. Hacktivists swarmed Israel as actor LauraAllen claimed hits on Coinbase and Nissan.189 ev 79 crit
- 7 Jun Government, Banking Breach Claims Lead 158-Event Threat Day158 claimed incidents on June 7: 72 data breaches and 10 leaks, with NoName057(16) leading a DDoS and defacement wave on Italy, the US and the Gulf.158 ev 82 crit
- 6 Jun Dumpdump Leads 192-Event Day Hitting Telecom and Government192 events; Dumpdump claims Proximus, Wehkamp; ShinyHunters claims AT&T; BABAYO EROR SYSTEM targets 22 government sites; Cisco SD-WAN CVE exploited.192 ev 82 crit
- 5 Jun Dark Storm Team Hits 11 Israeli Government Portals; PAN-OS Auth Bypass CVE-2026-0257 Exploited | June 5 CTI Brief177 threat intelligence events on June 5: Dark Storm Team launches coordinated DDoS against Israeli government infrastructure; PAN-OS CVE-2026-0257 authentication bypass under active exploitation; Qilin ransomware hits 9 targets across 6 countries; DieNet disrupts Dutch public services.177 ev 80 crit
- 4 Jun Aquahack 63-Victim Blitz; Russian Banks, Belgium Gov HitActor Aquahack claims 63 breaches across 20+ countries including Belgian government identity registry and German payment platform Giropay; elazo2 sweeps 4184 ev 108 crit
- 3 Jun Ukraine General Staff Leak Claim Caps Six-Bank Breach SpreeActor elazo2 claims six bank breaches across Chile and Bulgaria; Beregini alleges a Ukraine General Staff leak; HTTP/2 Bomb DoS downs major web servers.158 ev 73 crit
- 2 Jun Hacktivist DDoS Surge and a Red Hat Supply-Chain WormNoName057(16) led 15 DDoS claims as 51 alleged breaches hit the US, Italy and Indonesia, while a worm tainted 32 Red Hat npm packages.156 ev 51 crit
- 1 Jun Ukrainian Courts Breached Amid a Global Hacking Spreepol4rity breaches Ukraine's Supreme Court and other state bodies; Rupert hits 20 targets worldwide as critical Windows and Linux flaws are exploited.172 ev 65 crit
May 2026
20 editions- 31 May Skull1172 Hits Colombian Government Sites on Election DaySkull1172 claims breaches of a dozen-plus Colombian state bodies as the country votes, while Indonesian government sites are hit, among 137 daily events.137 ev 76 crit
- 30 May OpsShadowStrike Breaches US Universities as DDoS Hits ItalyOpsShadowStrike claims breaches at two Michigan universities and US banks; NoName057(16) floods Italian sites; PAN-OS bug CVE-2026-0257 actively exploited.138 ev 52 crit
- 29 May Rupert, Moelester Lead Breach Wave; Gogs RCE Zero-Day LandsRupert and Moelester drove nearly half of 64 alleged breach and leak claims, from Home Depot Canada to Argentine courts, as a Gogs RCE zero-day landed.128 ev 64 crit
- 28 May Carnival 6M Breach Lands as FortiClient Exploit ReturnsCarnival confirmed 6M records exposed; threat actors revived a critical FortiClient EMS flaw; a Gitea bug exposed 30K deployments to container pulls.159 ev 53 crit
- 27 May Databasehooligan Dominates as AI Supply-Chain Attacks SurgeDatabasehooligan drove 36 of 148 tracked incidents in a global data-sale spree, while CrowdStrike disrupted GlassWorm and AI coding-agent attacks spread.148 ev 76 crit
- 26 May Data Breach Wave Hits Government, Education as DDoS SurgesA 178-incident day: NoName057(16) drives DDoS while alleged breaches hit NASA, Santander, Ukraine's defense ministry and Indonesian government bodies.178 ev 65 crit
- 25 May Databasehooligan Breach Spree Meets Ghost CMS Mass ExploitDatabasehooligan claimed 27 breaches across Europe and the Americas as a Ghost CMS flaw (CVE-2026-26980) was exploited to hijack 700+ sites.170 ev 71 crit
- 24 May Scattered LAPSUS$ Hunters Posts Defence-Database Sale SweepScattered LAPSUS$ Hunters claims database sales targeting NATO RTA, UK Government, US Navy, NASA Glenn, Spain MoD and 17 more in a single spree.164 ev 86 crit
- 23 May Pro-Russian DDoS dominates; Lazarus hits Tashkent educationNoName057(16) led 14 listings, Lazarus leaked Westminster International University in Tashkent, and Drupal Core SQLi plus Laravel-Lang join CISA KEV.140 ev 58 crit
- 22 May Iranian APT Hits Defense as KimWolf DDoS Operator ArrestedUnit 42 maps Iranian APT Screening Serpens; FBI arrests Canadian KimWolf DDoS operator behind 1M+ devices; 60 breach claims include BMW AG and FSB.182 ev 67 crit
- 21 May LAPSUS GitHub, NoName Ukraine DDoS Lead 120-Event Forum DayLAPSUS-GROUP claims a GitHub data sale; The BlackH4t MD-Ghost names NATO; NoName057(16) hits Ukraine with 11 DDoS; 32 of 120 events are data-breach claims.120 ev 32 crit
- 20 May GitHub Breach, npm Supply Chain Attack, and Mass Data Leaks Dominate May 20GitHub confirms internal repo theft via VS Code extension; Microsoft disrupts Fox Tempest signing service; 53 critical data exposure events hit US, France, India.157 ev 53 crit
- 19 May Exchange Markets Targets Gulf Finance; Fox Tempest DisruptedExchange Markets claims breaches at Qatar, Kuwait financial entities. Microsoft disrupts Fox Tempest malware-signing service. Drupal warns of critical patch. JAX7 targets Indonesian govt data.137 ev 47 crit
- 18 May Data Leak Surge Targets Government, Telecom, and Healthcare Globally159 events tracked; 48 critical exposures. Qilin, NoName057(16) active. India, US, Indonesia top victims. Healthcare, telecom, government sectors hit. Supply chain threats escalate.159 ev 48 crit
- 17 May Kazu Actor Strikes Healthcare, Government; NGINX Zero-Day Exploited47 critical data exposures logged, with Kazu targeting health and government sectors globally. NGINX CVE-2026-42945 exploited in the wild. Grafana GitHub token breach disclosed.140 ev 47 crit
- 16 May Major Data Breaches Hit Governments, Telecoms, and Education Worldwide165 events tracked; 66 critical exposures. Qilin, LockBit active. Multiple government, telecom, and education breaches reported globally.165 ev 66 crit
- 15 May BlackFile Shutdown Masks Vishing Surge; Cisco Zero-Day Under Active AttackUNC6671's BlackFile brand goes dark amid ongoing vishing extortion campaigns. Cisco SD-WAN zero-day CVE-2026-20182 exploited in the wild. Major breaches hit Coinbase, Eli Lilly, and U.S. Department of175 ev 63 crit
- 14 May Ghostwriter Targets Ukraine, Foxconn Hit by Nitrogen RansomwareQilin, Pharaoh's Team drive 197 events; Foxconn confirms ransomware; Ghostwriter targets Ukraine; critical data exposures hit India, France, Chile.197 ev 56 crit
- 13 May AI-Driven Patch Tuesday Surge; Government, Finance Breaches DominateMicrosoft patches 138 flaws including zero-click Outlook bug; AI tools find 16 vulns. Breaches hit Egypt Education, Indonesia BNI, US govt agencies. UK reforms cybercrime law.128 ev 57 crit
- 12 May Canvas ransom, Shai-Hulud npm wave, NoName DDoS surgeInstructure pays ShinyHunters for 3.65TB Canvas data; Mini Shai-Hulud npm wave hits TanStack, Mistral AI, UiPath; 56 alleged breach/leak claims.157 ev 56 crit