Archive
Cyber Threat Intelligence
106 editions
June 2026
12 editions- 12 Jun ShinyHunters Exploits Oracle Zero-Day; EXILIADOS Targets Latin AmericaShinyHunters exploits unpatched Oracle flaw to extort universities. EXILIADOS #555 claims multiple breaches across Mexico and Argentina. Novo Nordisk confirms breach. Conti member pleads guilty.180 ev 53 crit
- 11 Jun ShinyHunters Exploits Oracle Zero-Day; Qilin, Elite Squad Dominate Daily EventsShinyHunters targets universities via CVE-2026-35273. Qilin and Elite Squad lead 218 tracked events. Critical data exposures hit France, Indonesia, US. New BitLocker bypass emerges.218 ev 89 crit
- 10 Jun CISA Mandates 3-Day Patching; Record Microsoft Patch Tuesday Hits 206 FlawsCISA orders agencies to patch critical vulns in 3 days. Microsoft ships record 206 fixes. Data breaches hit energy regulator, eToro, Dynatrace, and multiple Indonesian govt agencies. Active exploitati183 ev 92 crit
- 9 Jun Massive Breach Wave Hits Finance, Healthcare, Government Globally138 events tracked; 74 critical exposures. Major breaches alleged at Wise, Coinbase, Robinhood, Ochre Health, and multiple government agencies. Patch Tuesday record with 206 Microsoft vulns.138 ev 74 crit
- 8 Jun LauraAllen-Linked Data Sales Hit Coinbase, Nissan; Israel TargetedLauraAllen claims Coinbase, Nissan, and Crypto Forex Canada breaches. Israel faces 34 events. Check Point VPN flaw exploited. NSO Group contempt filing.192 ev 84 crit
- 7 Jun India, Vietnam, Mexico Hit in Wave of Data Breaches, Healthcare Targeted86 critical exposures today; India govt portals, Vietnam citizen DB, Mexico hospitals targeted. NoName057 leads DDoS. Healthcare, govt sectors under pressure.161 ev 86 crit
- 6 Jun Dumpdump-Linked Breaches Surge; Miasma Worm Hits 73 Microsoft Repos221 events tracked; Dumpdump and BABAYO EROR SYSTEM lead activity. Critical data exposures hit India, Indonesia, Mexico. Miasma worm targets Microsoft GitHub; ChatGPT Lockdown Mode released.221 ev 105 crit
- 5 Jun Dumpdump Dominates, UNC3753 Targets US Law Firms, PAN-OS ExploitedDumpdump leads 203 events; Qilin, Dark Storm active. UNC3753 vishing campaign targets US law firms. Critical PAN-OS bug exploited. DentaQuest breach hits 2.6M.203 ev 106 crit
- 4 Jun Aquahack Spree Hits 66 Targets; AI Agent Risks Dominate CTI AnalysisActor Aquahack claims 66 breaches across 20+ countries. AI agent supply chain and insider threats highlighted by Microsoft and DTEX. Cisco patches exploited SSRF in Unified CM.249 ev 152 crit
- 3 Jun Ukraine General Staff Leak Claim Caps Six-Bank Breach SpreeActor elazo2 claims six bank breaches across Chile and Bulgaria; Beregini alleges a Ukraine General Staff leak; HTTP/2 Bomb DoS downs major web servers.158 ev 73 crit
- 2 Jun Hacktivist DDoS Surge and a Red Hat Supply-Chain WormNoName057(16) led 15 DDoS claims as 51 alleged breaches hit the US, Italy and Indonesia, while a worm tainted 32 Red Hat npm packages.156 ev 51 crit
- 1 Jun Ukrainian Courts Breached Amid a Global Hacking Spreepol4rity breaches Ukraine's Supreme Court and other state bodies; Rupert hits 20 targets worldwide as critical Windows and Linux flaws are exploited.172 ev 65 crit
May 2026
18 editions- 31 May Skull1172 Hits Colombian Government Sites on Election DaySkull1172 claims breaches of a dozen-plus Colombian state bodies as the country votes, while Indonesian government sites are hit, among 137 daily events.137 ev 76 crit
- 30 May OpsShadowStrike Breaches US Universities as DDoS Hits ItalyOpsShadowStrike claims breaches at two Michigan universities and US banks; NoName057(16) floods Italian sites; PAN-OS bug CVE-2026-0257 actively exploited.138 ev 52 crit
- 29 May Rupert, Moelester Lead Breach Wave; Gogs RCE Zero-Day LandsRupert and Moelester drove nearly half of 64 alleged breach and leak claims, from Home Depot Canada to Argentine courts, as a Gogs RCE zero-day landed.128 ev 64 crit
- 28 May Carnival 6M Breach Lands as FortiClient Exploit ReturnsCarnival confirmed 6M records exposed; threat actors revived a critical FortiClient EMS flaw; a Gitea bug exposed 30K deployments to container pulls.159 ev 53 crit
- 27 May Databasehooligan Dominates as AI Supply-Chain Attacks SurgeDatabasehooligan drove 36 of 148 tracked incidents in a global data-sale spree, while CrowdStrike disrupted GlassWorm and AI coding-agent attacks spread.148 ev 76 crit
- 26 May Data Breach Wave Hits Government, Education as DDoS SurgesA 178-incident day: NoName057(16) drives DDoS while alleged breaches hit NASA, Santander, Ukraine's defense ministry and Indonesian government bodies.178 ev 65 crit
- 25 May Databasehooligan Breach Spree Meets Ghost CMS Mass ExploitDatabasehooligan claimed 27 breaches across Europe and the Americas as a Ghost CMS flaw (CVE-2026-26980) was exploited to hijack 700+ sites.170 ev 71 crit
- 24 May Scattered LAPSUS$ Hunters Posts Defence-Database Sale SweepScattered LAPSUS$ Hunters claims database sales targeting NATO RTA, UK Government, US Navy, NASA Glenn, Spain MoD and 17 more in a single spree.164 ev 86 crit
- 23 May Pro-Russian DDoS dominates; Lazarus hits Tashkent educationNoName057(16) led 14 listings, Lazarus leaked Westminster International University in Tashkent, and Drupal Core SQLi plus Laravel-Lang join CISA KEV.140 ev 58 crit
- 22 May Iranian APT Hits Defense as KimWolf DDoS Operator ArrestedUnit 42 maps Iranian APT Screening Serpens; FBI arrests Canadian KimWolf DDoS operator behind 1M+ devices; 60 breach claims include BMW AG and FSB.182 ev 67 crit
- 21 May LAPSUS GitHub, NoName Ukraine DDoS Lead 120-Event Forum DayLAPSUS-GROUP claims a GitHub data sale; The BlackH4t MD-Ghost names NATO; NoName057(16) hits Ukraine with 11 DDoS; 32 of 120 events are data-breach claims.120 ev 32 crit
- 20 May GitHub Breach, npm Supply Chain Attack, and Mass Data Leaks Dominate May 20GitHub confirms internal repo theft via VS Code extension; Microsoft disrupts Fox Tempest signing service; 53 critical data exposure events hit US, France, India.157 ev 53 crit
- 19 May Exchange Markets Targets Gulf Finance; Fox Tempest DisruptedExchange Markets claims breaches at Qatar, Kuwait financial entities. Microsoft disrupts Fox Tempest malware-signing service. Drupal warns of critical patch. JAX7 targets Indonesian govt data.137 ev 47 crit
- 18 May Data Leak Surge Targets Government, Telecom, and Healthcare Globally159 events tracked; 48 critical exposures. Qilin, NoName057(16) active. India, US, Indonesia top victims. Healthcare, telecom, government sectors hit. Supply chain threats escalate.159 ev 48 crit
- 17 May Kazu Actor Strikes Healthcare, Government; NGINX Zero-Day Exploited47 critical data exposures logged, with Kazu targeting health and government sectors globally. NGINX CVE-2026-42945 exploited in the wild. Grafana GitHub token breach disclosed.140 ev 47 crit
- 16 May Major Data Breaches Hit Governments, Telecoms, and Education Worldwide165 events tracked; 66 critical exposures. Qilin, LockBit active. Multiple government, telecom, and education breaches reported globally.165 ev 66 crit
- 15 May BlackFile Shutdown Masks Vishing Surge; Cisco Zero-Day Under Active AttackUNC6671's BlackFile brand goes dark amid ongoing vishing extortion campaigns. Cisco SD-WAN zero-day CVE-2026-20182 exploited in the wild. Major breaches hit Coinbase, Eli Lilly, and U.S. Department of175 ev 63 crit
- 14 May Ghostwriter Targets Ukraine, Foxconn Hit by Nitrogen RansomwareQilin, Pharaoh's Team drive 197 events; Foxconn confirms ransomware; Ghostwriter targets Ukraine; critical data exposures hit India, France, Chile.197 ev 56 crit