Skip to main content

Current cyber intelligence

Cybersecurity News: Latest Incidents & Threat Intelligence

Shadow Tier brings verified public reporting into one current view. Start with the latest incidents below, or compare the companies, sectors, attack patterns, impacts and countries connected to them.

109

Reports in 90 days

in the current rolling intelligence window

9

Active topics

represented in the same 90-day window

48

High priority

high or critical reports in 90 days

Latest reporting

Latest cybersecurity incidents

Showing 3754 of 109 reports published in the last 90 days.

Dystar logoRansomware
High

DyStar Group Hit by Settra Ransomware Attack, 1.3 TB of Internal Data Exfiltrated

Sponsored by Hudson Rock – Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks This page displays the 100 most recent victim disclosures attributed to ransomware groups, as detected by Ransomware.live . Our platform continuously monitors and scrapes ransomware group leak sites to identify and list newly published victims. Recent Breaches › dystar.com Listed by settra Ransomware Group dystar.com Listed by settra Ransomware Group: What Was Exposed & What To Do Occurred June 2026 · publicly disclosed June 28, 2026. Dystar.com was listed by the Settra ransomware group on June 28, 2026, with internal files reported exfiltrated in the attack. An undisclosed number of people may be affected; check the listing and monitor your accounts for signs of compromise. The incident was reported on 28 June 2026. dystar.com appears on a listing attributed to the settra ransomware group. The group claims to hold 1.3 terabytes of data described as the complete digital archive of DyStar. No independent confirmation of the volume, the date of access, or the method of entry has been released. The number of people affected remains undisclosed. Settra is a ransomware operator that lists victim organisations on a public site after encrypting systems and copying files. The group’s listings function as a claim that data has been taken and may be released if demands are not met. No additional statements from settra specific to dystar.com have been verified beyond the listing itself. dystar.com belongs to an organisation that operates in the specialty chemicals sector, supplying dyes and related products to industrial clients. Entities of this type routinely maintain records on production processes, customer accounts, supplier arrangements and internal communications. A breach that exposes such material can affect both commercial operations and any personal details contained in those records. The only category named in available reports is internal files exfiltrated during a ransomware attack. The precise contents of the 1.3 terabytes referenced in the listing have not been itemised by the organisation or independently verified. Organisations in this sector commonly store employee records, contractual documents and operational data, yet the exact composition of the material in this case stays unconfirmed. Internal files can contain identifying information, financial references or communications that retain value long after the initial incident. Individuals named in those files may encounter follow-on risks such as targeted fraud or unwanted contact. For the organisation, the exposure of proprietary material can complicate business relationships and regulatory compliance even if the number of personal records remains unknown. Begin by monitoring accounts linked to any email address you have used with dystar.com or its partners. Enable multi-factor authentication on those accounts and review recent login activity. Request a copy of any personal data the organisation holds about you under applicable data-protection rules. Readers can run a free exposure scan of their email address against known breach data to check for appearances in public listings. Change passwords for any accounts that may share credentials with dystar.com systems. Watch bank and credit statements for unusual activity over the next several months. Contact dystar.com directly to ask what categories of personal information were held and whether they have been notified of the listing. Read GalaxyWarden’s full analysis of the dystar.com Listed by settra Ransomware Group → Publicly posted by settra — unverified claim, pending independent verification Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated a

Dystar
Nifty logoUse of stolen credentials or exploit
Medium

NIFTY Corporation Affected by KDDI Corporation Data Breach

NIFTY Corporation, a Japanese internet service provider, was impacted by a data breach originating from an email system provided by KDDI Corporation. Threat actors gained unauthorized access to this shared system by exploiting a vulnerability in third-party software. This led to the potential exposure of up to 14.2 million email addresses and passwords across all affected ISPs. NIFTY Corporation customers' email addresses and passwords may have been compromised.

Nifty
Dialog logoMisconfiguration or publishing error
Medium

Peter Thiel's Dialog Society Data Leak Exposes Senior US Officials

Pentagon Probes Data Leak at Peter Thiel's Dialog Exposing Senior US Officials The Pentagon is investigating a data exposure at Peter Thiel's secretive Dialog group after a misconfigured website unmasked senior U.S. intelligence officials and active-duty special operations personnel, raising operational security risks. The briefing room at the Pentagon in Virginia, January 8, 2020 - Reuters The Pentagon has launched an operations security examination into a major data exposure at Dialog, a secretive private events group co-founded by Peter Thiel. The breach compromised the personal information of multiple U.S. national security personnel. These include an active-duty intelligence officer embedded with a Tier 1 special operations unit and a senior National Security Council official advising President Donald Trump, according to WIRED. The exposure revealed private details of 222 registrants for the Dialog event. The database included current and former senior military and national security officials from the United States and allied nations. The active-duty military intelligence officer and the NSC official were registered as new participants. Both were invited to attend Dialog’s upcoming August retreat located outside Dublin, Ireland. The White House declined to comment on the exposure. Officials requested that the NSC official, a former CIA officer, remain unnamed on national security grounds. Dialog internally classified the incident as a cyberattack. However, evidence indicates the files were exposed due to a misconfiguration in the group’s website. Anyone could create an account with an email address to access the files. Users simply needed to load the group’s application landing page to view the dossiers. Outside counsel for Dialog issued a letter stating that the data was stolen and demanding its return. The organization did not respond to press inquiries regarding the incident. The discovery originated from a tip by Swiss cybersecurity researcher maia arson crimew. She was indicted by federal prosecutors in 2021 on hacking-related charges but has not been convicted. Exposed files contained dates of birth, home addresses, mobile numbers, headshot photos, and private authentication tokens. Some records also listed spouses and family members as emergency contacts. Dialog collected registrant questionnaires that prompted personal disclosures. The NSC official predicted that future espionage will target behavior more than secrets. Another former Pentagon technology office director warned of domestic terrorism targeting artificial intelligence datacenters. The individual also noted possessing one of Saddam Hussein’s gold-plated AK-47s. The database exposed more than 20 current and former military and intelligence officials. This included a retired U.S. general and a retired official who held a senior security role in Israel and the Palestinian territories. GOP Facing Severe Political Dilemma Over Trump's Iran War Soaring Costs in Iran War Burn Through Pentagon's Cash

Dialog
Lvm logoRansomware
Medium

Latvijas Valsts Mezi (LVM) Suffers Cybersecurity Breach

Cybersecurity breach reveals vulnerability of Latvia's strategic infrastructure: minister RIGA, June 26 (Xinhua) -- A recent incident in which hackers managed to access IT systems of Latvia's state-owned company Latvijas Valsts Mezi (LVM) revealed the relative vulnerability of the country's strategic infrastructure, Smart Administration and Regional Development Minister Edgars Tavars said Friday. The cybersecurity breach in LVM has caused particular concerns because the company has been entrusted with developing an electoral IT platform for Latvia's parliamentary elections, which are scheduled to take place this fall. In an interview with the TV3 channel on Friday, Tavars called on all state institutions to identify cybersecurity flaws in their own systems and learn a lession from the LVM incident. The minister believes, though, that in general, Latvian IT specialists are good enough to prevent similar incidents from repeating in the future. Tavars said that the electronic voter register, on which LVM has been working, was completed before the incident and was not at risk. In general, "we are definitely not ringing alarm bells about the elections," the minister said. LVM discovered the cybersecurity breach of its IT systems last weekend. In response, the company took all its external IT systems offline and also shut down some internal communication systems. A foreign ransomware group, which has carried out similar attacks against companies and government agencies in other countries, has claimed responsibility on the cyberattack on LVM. Cyberattack on Latvian State Forests detected LVM is one of three companies developing this year’s Saeima election system . However, the company noted that the development of the election system was kept separate and was not affected. Security measures will be reviewed as a precaution. The cyberattack occurred on Monday, June 22. According to the company, since the incident began, the external information technology (IT) systems maintained by LVM, including “LVM GEO,” the mapping service system, and the hunting app “Mednis”, have been shut down and are unavailable for security reasons. Several of LVM’s internal systems, which facilitate the company’s exchange of information with service providers and clients, have also been taken offline. LVM spokesperson Tomass Kotovičs stated that the threat has been eliminated, but it will take time to restore the systems to operation. Baiba Kaškina, head of “Cert.lv,” explained that the attack was thwarted immediately. According to her, there is no reason to believe that it was specifically targeted at Latvia. “Cert.lv” is inclined to believe that this was a commercially motivated attack aimed at demanding a ransom and demonstrating the attackers’ capabilities. The State Police Cybercrime Combating Directorate, based on publicly available information, has launched an internal investigation on its own initiative to clarify the circumstances of the incident and identify the possible perpetrator, according to the LETA news agency. Select text and press Ctrl+Enter to send a suggested correction to the editor Select text and press Report a mistake to send a suggested correction to the editor

Lvm
Xsolis logoRansomware
Medium

Healthcare AI Company Xsolis Suffers Data Breach Impacting 1.4 Million Individuals

Healthcare technology company Xsolis, Inc. has disclosed a data breach affecting nearly 1.4 million individuals. Tennessee-based Xsolis provides utilization management and revenue cycle solutions for hospitals, health systems, and payers. The company published a data security notice in early June, revealing that unauthorized activity was detected on its systems on January 22. The intrusion resulted from a targeted phishing attack carried out two days earlier. According to Xsolis, the hackers gained access to files storing personal and protected health information received by the company from its clients, including names, dates of birth, addresses, SSNs, health insurance information, and medical treatment information.  While the data breach was disclosed two weeks ago, the US Department of Health and Human Services (HHS) has now disclosed the number of affected individuals.  The Xsolis cybersecurity incident was added to the HHS data breach tracker on Monday, with the number of affected individuals listed as 1,396,519.  Advertisement. Scroll to continue reading. No known ransomware group appears to have taken credit for the attack on the healthcare tech company. SecurityWeek has asked Xsolis whether it was targeted in an extortion attempt and, if so, whether a ransom has been paid. The company’s disclosure indicates that it’s “not aware of any actual or attempted misuse of information because of this incident”. It’s not uncommon for healthcare-related data breaches to affect millions of people. One recent example is the incident involving the dental benefits administrator DentaQuest , in which hackers stole information from 2.6 million accounts.  Related : Millions Impacted Across Several US Healthcare Data Breaches Related : 266,000 Affected by Data Breach at Radiology Associates of Richmond Related : Oncology Institute Discloses Data Breach Written By Eduard Kovacs Eduard Kovacs (@EduardKovacs) is senior managing editor at SecurityWeek. He worked as a high school IT teacher before starting a career in journalism in 2011. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering. Meta Paid $78,000 Bounty for Vulnerability Exposing Customer Support Data Exploitation of ServiceNow Vulnerability Seen Days After Disclosure SonicWall Zero-Days Exploited to Deliver Custom Malware for Weeks Before Patch New Index Tracks Material Breaches — And Refuses to Add Up the Losses WP2Shell WordPress Vulnerabilities Exploited in the Wild Two Scattered Spider Hackers Sentenced to Jail in UK ‘ClickLock Stealer’ Bypasses macOS Security With Social Engineering, Process Killing China’s Top Cybersecurity Firms Hit by Mounting Military Procurement Bans Fourth SharePoint Vulnerability Exploited in Past Month’s Wave of Attacks Endpoint Security Firm Glow Launches With $180M in Funding at $1.2B Valuation Oracle Patches Over 1,400 Vulnerabilities With Quarterly Security Updates Ransomware Group Threatening to Leak Data Stolen From Coca-Cola’s Fairlife OpenAI Says Its AI Models Broke Loose and Hacked Hugging Face Trump Orders Defense Contractors to Map Software, Suppliers Across Critical Supply Chains Cisco Launches Low-Cost AI Models for Source Code Security Empirical Security Raises $25 Million in Series A Funding Join this live webinar as we explore why exploitation is outpacing remediation, where risk is growing fastest, and what security leaders can do to close the gap before attackers take advantage. CodeSecCon bridges the gap between dev and security. Discover best practices for secure coding, innovative risk-reduction tools, and safe AI integration to cultivate a true DevSecOps culture. Safely secure your apps! Xsolis breach exposes personal and health data of 1.4 million people Healthcare technology company Xsolis has disclosed a data breach impacting nearly 1.4 million individuals following a phishing attack. The Tennessee-based firm, which provides utilization management and revenue cycle solutions for healthcare providers, became aware of unauthorized access on January 22, 2026, after a phishing attack two days prior. The breach exposed personal and protected health information received from Xsolis’s hospital and payer clients, as reported by Security Affairs. The security incident, which occurred on January 20, 2026, allowed an unauthorized actor to acquire files containing sensitive information. This data may include names, addresses, dates of birth, Social Security numbers, health insurance details, and medical treatment information. Xsolis has launched an investigation, reported the incident to law enforcement, and is implementing enhanced security measures. Affected individuals are being notified by mail and offered free credit monitoring and identity protection services, along with access to a toll-free call center. The U.S. Department of Health and Human Services reported that 1,396,519 individuals were affected. No ransomware group has claimed responsibility for the attack at this time.

Xsolis
Riskstrategies logo
Medium

Risk Strategies Discloses Data Breach Involving Personal and Medical Information

Risk Strategies Data Breach Exposes Social Security Numbers Risk Strategies , officially known as RSC Insurance Brokerage Inc., disclosed a data breach involving sensitive personal and medical information. Between January 15, 2026, and January 16, 2026, an unauthorized user gained access to the Microsoft 365 account of a Risk Strategies employee. An investigation of the affected files, which concluded on June 1, 2026, determined the files contained personal information belonging to individuals. The incident compromised names, Social Security numbers and medical records. Risk Strategies began mailing affected individuals notification letters concerning the incident on June 23, 2026. A total number of 15,055 individuals were affected nationwide including 76 Nebraska residents and 47 Massachusetts residents were impacted. Risk Strategies is offering affected individuals a complimentary 24-month membership to credit monitoring services provided by Epiq. The service, called Privacy Solutions ID 3B Credit Monitoring, can be activated at privacysolutionsid.com . Affected individuals received a unique activation code and enrollment deadline in their notification letter. Affected individuals with questions about the incident can call Risk Strategies at 866-659-7098, Monday through Friday, from 9:00 a.m. to 9:00 p.m. EST. For help with the Epiq enrollment process, individuals can call 866-675-2006, Monday through Friday, from 9:00 a.m. to 5:30 p.m. ET. SUBMIT YOUR CLAIM TO THE LAW FIRM HANDLING THIS INVESTIGATION Affected information types not yet disclosed This browser does not support inline PDFs. Please download the PDF to view it: Download PDF Class actions settlements delivered to your inbox. SportsMed Physical Therapy Data Breach Exposes Health Information Trudeau Center Breach Affects 5,630 Individuals Alkegen Data Breach Exposes Personal and Protected Health Information Whitfield Hospital Breach Exposed Medical and Health Information Attorneys working with ClassAction.org are looking into whether a class action lawsuit can be filed in light of the Risk Strategies data breach. As part of their investigation, they need to hear from individuals who had their information exposed in the incident , including those who received notice of the Risk Strategies data breach or otherwise believe they are affected. Risk Strategies Security Incident: What Happened? RSC Insurance Brokerage, which operated as Risk Strategies before merging with Brown & Brown, has reported a data breach involving personal information. According to a sample notification letter (pictured below), names and Social Security numbers were involved. For some of those impacted by the Risk Strategies data breach, medical information and health, dental, and/or vision insurance information may have been compromised. A report detailing the cybersecurity incident was submitted to the Massachusetts Office of Consumer Affairs and Business Regulation on June 23, 2026. What You Can Do After the Risk Strategies Data Breach If your information was exposed in the Risk Strategies data breach, attorneys want to hear from you. You may be able to start a class action lawsuit to recover compensation for loss of privacy, time spent dealing with the breach, out-of-pocket costs, and more. A successful case could also force Risk Strategies to ensure they take proper steps to protect the information they were entrusted with. Affected by the Risk Strategies data breach? Fill out the form on this page today. If you believe your information was exposed in the Risk Strategies data breach, fill out the form on this page to get in touch with us. An attorney or legal representative may then reach out to you to explain more about this investigation and ask you a few questions. Remember, there is no cost to get in touch, and you are under no obligation to take action after speaking to someone. New cases and investigations, settlement deadlines, and news straight to your inbox. Whitfield Regional Hospital Data Breach 2026 Community Health Center of Buffalo Data Breach 2026 Advantage Home Health Care Data Breach 2026 Unlimited Technology Systems Data Breach 2026 Heart Care Centers of Illinois Data Breach 2026 Clover Health Investments Data Breach 2026 Morris Communications Company Data Breach 2026 Brown Health Medical Group-MA Data Breach 2026 Case & Associates Properties Data Breach 2026

Riskstrategies
Huntsvillehospital logo
Medium

Huntsville Hospital Health System Notifies Patients of Data Exposure from Cerner Breach

Huntsville Hospital Health System informed patients on June 26, 2026, about a data exposure stemming from a 2025 breach on Cerner's (now Oracle Health) legacy systems. The breach, which occurred on January 22, 2025, exposed personal and medical information. Cerner had notified its healthcare clients, including Huntsville Hospital, on August 12, 2025, but patient notification was delayed at the request of law enforcement.

Huntsvillehospital
Snyk logo
Medium

Snyk CRM Data Accessed in Klue OAuth Breach

Snyk, a developer security company, was among the confirmed victims of the Klue OAuth breach. The Icarus extortion group compromised Klue's infrastructure, a market intelligence platform, gaining access to CRM data of its customers, including Snyk. The attack, which occurred on June 11, 2026, exploited a compromised legacy credential at Klue.

Snyk
Ahisd logoRansomware
Medium

Alamo Heights ISD Reports Data Breach Following Ransomware Attack

Alamo Heights Independent School District (ISD) reported a data breach impacting over 26,000 people, disclosed to the Texas Attorney General's office on June 25, 2026 (published June 26, 2026 UTC). The breach was linked to a ransomware attack by the Qilin group, which occurred on April 9, 2026. The compromised information included names, Social Security numbers, driver's license numbers, and bank and medical information.

Ahisd
Trenitalia logoUse of stolen credentials or exploit
Medium

Trenitalia Suffers Cyberattack, Customer Data Compromised

Trenitalia, the Italian state-owned railway company, notified customers on June 26, 2026, about a cyberattack that led to unauthorized access of personal data related to travel tickets. The company detected the incident through internal checks and attributed it to 'unidentified external parties.' The attack itself reportedly occurred in November 2025. Compromised data included demographic and identification details, contact information, travel specifics, and loyalty card numbers, but no payment information or account credentials were affected.

Trenitalia
Insee logo
Medium

France's National Statistics Department (Insee) Reports Cyberattack on Staff Data

France's national statistics department, Insee, reported a cyberattack that exposed identity and professional contact data for approximately 12,800 current and former staff and related civil service personnel. The breach, detected on June 19, 2026, involved an internal staff directory (trombi.insee.fr). Insee stated that no sensitive information such as passwords, personal contact details, bank details, social security numbers, or health information was accessed. News of the incident was widely reported on June 26, 2026.

Insee
Agelessrx logo
Medium

AgelessRx Data Breach Exposes Patient Health Information

AgelessRx, a telehealth platform specializing in longevity and anti-aging treatments, disclosed a data breach. An unauthorized actor gained access to certain help-desk tickets within the company's system between April 17 and April 22, 2026. The breach exposed sensitive patient health information, including names, dates of birth, health diagnoses or conditions, medications, and prescription details. The incident was reported to attorneys general on June 24, 2026, and notification letters to affected individuals began on June 23, 2026.

Agelessrx
Atlas Elektronik logoRansomware
Medium

ATLAS ELEKTRONIK GmbH Hit by TheGentlemen Ransomware Attack

On June 25, 2026, the ransomware group 'TheGentlemen' claimed responsibility for a cyberattack on ATLAS ELEKTRONIK GmbH, a German defense technology company specializing in maritime electronics and naval systems. The group issued an ultimatum, threatening to leak sensitive company data unless negotiations commence. The attack was reported on June 25, 2026, and is being monitored by cybersecurity intelligence platforms.

Atlas Elektronik
Hackerone logoRansomware
Medium

HackerOne Affected by Klue Supply Chain Attack

At least nine organizations have publicly acknowledged the impact of the supply chain attack on market intelligence platform Klue. The incident occurred on June 11-12 and affected Klue’s integration with Salesforce, resulting in data being exfiltrated from the Salesforce instances of multiple Klue customers, including several cybersecurity firms. On Friday, Klue confirmed previous security reports that the attackers used compromised legacy credentials to access its systems and compromise Salesforce integrations. “The attacker used that access to obtain OAuth tokens used to connect Klue with certain third-party platforms, including Salesforce, and subsequently accessed data within a number of connected customer environments,” Klue said. The company revoked the affected credentials and tokens, disabled the integrations across multiple services, and has been investigating the attack together with CrowdStrike and law enforcement. “Based on our investigation to date, the incident was limited to the affected third-party platforms, and there is no evidence that customer content stored within the Klue platform was impacted,” the company said. Advertisement. Scroll to continue reading. To date, at least nine Klue customers have disclosed impact from the incident, including cybersecurity firms HackerOne , Huntress , Jamf , OneTrust , Recorded Future , Snyk , and Tanium . Insurity and Sprout Social also notified their customers of the incident. All the affected companies pointed out that the intrusion was limited to the Salesforce instances and did not involve their systems, as Klue said in its incident notice. Across the board, the hackers stole business information from the affected organizations’ Salesforce CRMs, including sales account data and business contact information, such as names, email addresses, job titles, phone numbers, and business addresses. Salesforce disabled the Klue integration in the wake of the incident, and revenue intelligence platform Gong did the same on Friday, warning that the hackers exploited its Klue integration to access internal licensed user data. “We can confirm no direct impact on call recordings or customer transcripts. Examples of data accessed included user names, user business titles, and user emails,” Gong said. In its analysis of the incident, Huntress suggested that a threat actor named Icarus might have been responsible for the attack. Since then, Icarus has added Klue to its Tor-based leak site, claiming responsibility for the attack and threatening to publish the information stolen from Klue customers’ Salesforce instances. Per the threat actor’s posts, the data would be released on June 22, unless Klue and the affected organizations engage in negotiations. Related: Cybersecurity Firms Impacted by Klue Supply Chain Attack Related: Atomic Arch Supply Chain Attack Hits 1,500 AUR Packages Related: ‘SymJack’ Attack Turns AI Coding Agents Into Supply Chain Attack Delivery Systems Related: Laravel-Lang Packages Poisoned for Malware Delivery Written By Ionut Arghire Ionut Arghire is an international correspondent for SecurityWeek. New HollowGraph Malware Abuses Microsoft 365 Calendar for C&C Communication Estée Lauder Discloses Impact From Oracle EBS Zero-Day Hack Clover Health Investments Discloses Data Breach Zimbra Update Patches Critical Vulnerabilities OpenSSL Silently Fixes ‘HollowByte’ DoS Vulnerability Ernst & Young Data Breach Affects Personal, Financial Information Hugging Face Hacked in Autonomous AI Attack Chrome 150 Update Patches Severe Memory Safety Bugs Fourth SharePoint Vulnerability Exploited in Past Month’s Wave of Attacks Endpoint Security Firm Glow Launches With $180M in Funding at $1.2B Valuation Oracle Patches Over 1,400 Vulnerabilities With Quarterly Security Updates Ransomware Group Threatening to Leak Data Stolen From Coca-Cola’s Fairlife OpenAI Says Its AI Models Broke Loose and Hacked Hugging Face Trump Orders Defense Contractors to Map Software, Suppliers Across Critical Supply Chains Cisco Launches Low-Cost AI Models for Source Code Security Empirical Security Raises $25 Million in Series A Funding LastPass is the latest cybersecurity firm to have disclosed the impact from the Klue hack, which resulted in unauthorized access to customers’ Salesforce instances. A threat actor calling itself Icarus used a compromised legacy credential to access Klue’s systems and generate OAuth tokens to breach third-party platforms Klue integrates with, such as Salesforce. Icarus then accessed the connected Salesforce instances and exfiltrated data in bulk , using automated scripts. Salesforce and Gong have disabled the Klue integration in response to the attack, and over a dozen organizations have already confirmed the impact. Incident notifications from the affected companies reveal that the attackers accessed business data accessible through the Klue integration, and that no internal systems were compromised. LastPass’s notice follows the same lines: “The information accessed was limited to standard business contact information and related customer relationship management (CRM) data, including customer names, phone numbers, email addresses, and physical addresses, as well as support case data and sales-related data.” The company says it has discontinued access to Klue, rotated exposed tokens, notified law enforcement, and launched an investigation together with Klue and Salesforce. Advertisement. Scroll to continue reading. “It is important to note that the scope of this incident is limited to only those systems that integrate with Klue’s application. LastPass products, services, and infrastructure were not impacted in any way, and customer vaults remain secure. There is also no evidence the threat actor accessed any Gong-related data,” LastPass said. This week, in addition to LastPass, 8×8 and Pendo announced they were affected. Late last week, HackerOne, Huntress, Insurity, Jamf, OneTrust, Recorded Future, Snyk, Sprout Social, and Tanium disclosed the impact from the attack. BeyondTrust also said business contact and sales-related information was stolen from its Salesforce instance, but the notification went unnoticed. On its Tor-based leak site, Icarus has listed several organizations as having their Salesforce data stolen, including Swiss AI communications solutions provider Gms-net. SecurityWeek has emailed the technology company for a statement and will update this article if it responds. Icarus’s website is currently down but, before becoming inaccessible, it listed at least four other companies that have yet to publicly disclose being affected by the Klue incident, which brings the number of victims to roughly 15. Per Huntress’s estimates, however, numerous other Klue customers were likely impacted by the data breach and are expected to come forward. Empirical Security Raises $25 Million in Series A Funding

Hackerone
Bajajauto logoRansomware
Medium

Bajaj Auto Hit by Ransomware Attack

Bajaj Auto and its wholly-owned subsidiary, Bajaj Auto Technology Ltd, were affected by a ransomware attack detected on June 23, 2026, impacting their IT infrastructure. The company initiated precautionary actions and reported the incident to the Indian Computer Emergency Response Team (CERT-In).

Bajajauto
Ayabank logoRansomware
Medium

AYA BANK Hit by Lapsus$ Ransomware Attack

AYA BANK, a prominent financial institution in Myanmar, fell victim to a ransomware attack by the Lapsus$ group, discovered on June 23, 2026. Lapsus$ claimed to have stolen over 120 gigabytes of data, including a full dump and PII, and threatened to sell it if a ransom was not paid. AYA Bank acknowledged a breach of an older application portal exposing some customer information but stated its core financial networks remained secure.

Ayabank
Whise logoMisconfiguration or publishing error
Medium

Whise.eu (European Real Estate CRM) Data Leak by ChimeraZ

The threat actor ChimeraZ claimed to have leaked a database from Whise, a Belgian CRM system for the real estate sector, on the dark web on June 23, 2026. The leaked data reportedly consists of 40.85 million records, approximately 15.8 GB of JSON files. Whise is a market leader in Belgium and also active in France.

Whise

Explore the intelligence

Explore current intelligence taxonomies

Explore the intelligence

Questions about current cybersecurity intelligence

Explore concise answers about the latest reporting, intelligence taxonomies and the rolling coverage metrics on this page.

12 answers across 4 topics

How to read and use the current intelligence overview.

What does this cybersecurity intelligence overview contain?

It brings source-backed cybersecurity reports from the rolling 90-day window into one view, then connects them to companies, sectors, attack patterns, impacts and affected countries.

Where should I start exploring?

Start with Latest reporting for individual incidents, or use the taxonomy section to compare recurring patterns across industries, consequences and locations.

Does this page list every cybersecurity incident?

No. It is a curated view of public reports that meet Shadow Tier's publication and classification criteria, not an exhaustive record of every incident worldwide.

Browse current topics