Skip to main content

Current cyber intelligence

Cybersecurity News: Latest Incidents & Threat Intelligence

Shadow Tier brings verified public reporting into one current view. Start with the latest incidents below, or compare the companies, sectors, attack patterns, impacts and countries connected to them.

216

Reports in 90 days

in the current rolling intelligence window

10

Active topics

represented in the same 90-day window

65

High priority

high or critical reports in 90 days

Latest reporting

Latest cybersecurity incidents

Showing 109126 of 216 reports published in the last 90 days.

Tinypulse logo
Medium

Nintendo Employee Data Exposed via TinyPulse Third-Party Breach, Shadowbyt3$ Shifts Ransom Demand

Nintendo of America confirmed that internal employee survey data was stolen in a cyberattack targeting TinyPulse, a third-party employee engagement platform owned by WebMD Health Services. Nintendo's own systems were not compromised, and no customer or financial data was accessed. The breach was claimed by the Shadowbyt3$ extortion group, which initially demanded a $2 million ransom from Nintendo on June 12, 2026, but shifted its demand directly to TinyPulse on June 14, 2026, after Nintendo declined to engage. The claimed dataset includes employee names, email addresses, analytics, survey records, bank statement PDFs, and W-9 tax forms.

Tinypulse
Tchap logoInfostealer
Medium

French Government Messaging Service Tchap Breached via Hijacked Account

More 70,000 French government employees had personal details stolen. Why and by whom? On June 8, 2026, DINUM announced that the official French government chat service (Tchap) had been breached on June 7. At the same time, a threat actor calling itself ‘ misere ’ claimed responsibility. DINUM is the French government’s interministerial digital directorate in charge of Tchap.  Tchap is a ‘secure’ sovereign instant messaging service for French government employees designed to combine the principle of data sovereignty with increased security over third-party foreign systems. It includes secure chat rooms that are end-to-end encrypted, and ‘public’ chat rooms that are not encrypted. Misere is… unknown. There is no public record of a threat actor known as ‘misere’. DINUM says the system was compromised following account hijacking, and states, “Of the more than 825,000 registered agents, 73,467 are reportedly affected by this incident, representing less than 9% of registered users.” Advertisement. Scroll to continue reading. Misere supposedly claimed almost precisely the same: theft of more than 70k accounts (aligning with DINUM’s statement); but added that it stole 13.5GB of files across more than 643,000 messages. However, we cannot verify misere’s claim because it was reported rather than published by the OSINT FrenchBreaches community, and the original misere claim is not or no longer available on the internet. So, we’re left with a conundrum. An official announcement states the breach occurred (not was discovered but occurred) on June 7 and was limited to 9% of the users. Classic, but not inaccurate, downplaying. But almost immediately, an unknown threat actor agrees with the number of affected accounts but claims theft of 13.5GB of actual data. We cannot verify this latter detail since we only have reports of a report – but if we assume accuracy and honesty, is it realistic to believe that this amount of data can be gathered and exfiltrated in a single day by an otherwise unknown threat actor? For additional insights into the cause and effect, we talked to Ilia Kolochenko , a qualified attorney, and CEO, founder and chief architect at ImmuniWeb. ImmuniWeb operates a dark web monitoring and threat intelligence service for its clients and sees thousands of different incidents daily. Could misere be a pseudonym adopted by a state actor for this small and relatively innocuous breach – for example, Russia embarrassing France over its pro Ukraine position; or the US doing the same for its anti-Iran war position? Kolochenko doesn’t think so, “Because it’s a little trivial. This is too small for large power intelligence agencies to bother with.” Before 2024, he had seen state actors compromise systems and rapidly act on the compromise. “But since 2024,” he continued, “state actors tend to infiltrate and lay low. What is alarming now is a new trend with state actors breaching critical national infrastructure and its suppliers silently. They just backdoor everything to get control of a nation’s infrastructure. They just go deeper and deeper and deeper, trying to get access to as many critical systems as possible.” The motivation is to pre-position with the ability to bring down multiple if not all the critical industries in an enemy nation simultaneously. This is cyberwar in preparation for or defense against a possible kinetic war. Nor does he think that the suggestion that the breach was an account take-over event is informative. It could be as simple as a hacker getting the credentials from stealer logs; but if it were an advanced hacker, that would not be necessary. “In today’s cloud and AI world, you don’t need to steal cookies with infostealers. You don’t need zero days. You just send a legitimate request to an API, and you’ll get all the records of a governmental institution or a private company, and everything will be on your hard drive within several hours.” Such an hypothesis could explain how misere could exfiltrate 3.5GB on the same day as the breach was discovered. Does the name misere give any clue to the actor or motivation? Again, no. “The name given to this actor is meaningless,” suggested Kolochenko. “Sometimes a hacker or group wants to protect a reputation for doing more meaningful hacks and adopts a ‘burner’ identity. Sometimes one group will impersonate another group that might be considered a rival or affiliated with a different adversarial nation.” The fact that the name is unknown does not mean that the actor is unknown. Overall, this attack by an unknown hacker against a secure government chat system does not present itself as an APT attack. But that could even be the purpose. After all, it involves 70,000 government employees. DINUM specifies in its breach disclosure announcement, “The potentially exposed user account data includes, at a minimum: first and last name, email address, affiliated entity, and avatar.” The affiliated entity would expose which government department is involved, the email address is provided, and Misere further claimed to have scraped 640,000 (plaintext) chat messages. This combination would be a treasure trove for subsequent targeted spear-phishing, valuable to both financially motivated cyber gangs and state actors ultimately targeting not Tchap but the ministries employing the Tchap users. But – and this is the point of this discussion – we just don’t know the truth: everything is conjecture. Frankly, trying to understand the cause and motivation behind any cyber incident is based on conjecture with little known truth. Related : Maine Disables Data Breach Portal Due to Fake Submissions Related : University of Nottingham Confirms Breach After Hackers Leak Data Related : 174,000 Impacted by Lansing Community College Data Breach Related : Nightclub Giant RCI Says Data Breach Affects 40,000 Individuals Written By Kevin Townsend Kevin Townsend is a Senior Contributor at SecurityWeek. He has been writing about high tech issues since before the birth of Microsoft. For the last 15 years he has specialized in information security; and has had many thousands of articles published in dozens of different magazines – from The Times and the Financial Times to current and long-gone computer magazines.

Tchap
Nottingham logoRansomware
Medium

University of Nottingham Data Breach Affects Over 450,000 Students

The University of Nottingham in the UK has confirmed suffering a data breach after the notorious ShinyHunters hacker collective leaked files stolen from the university’s systems. The University of Nottingham is a major research university in the UK, ranked among the world’s top 100 institutions and home to more than 35,000 students on its UK campuses, plus thousands more at its international branches in China and Malaysia. The ShinyHunters group listed the organization on its leak website and published gigabytes of files allegedly stolen from its systems. The hackers claimed to have obtained financial information pertaining to all of the university’s campuses.  University of Nottingham hacked by ShinyHunters An analysis of the leaked files by the account breach notification service Have I Been Pwned showed that they contain roughly 455,000 unique email addresses, along with other types of personal information such as usernames, names, addresses, phone numbers, passport numbers, genders, and details on ethnicity, disabilities, academic enrolment, c itizenship status, and fee payments. In a statement issued on Wednesday, the University of Nottingham confirmed that hackers accessed “a significant amount of data” in its student record system. The university says the data breach impacts current students and alumni. “We are working to understand the data that has been accessed and have contacted those students and alumni affected directly. We are working closely with Action Fraud, the Information Commissioner’s Office, and other regulatory bodies,” the organization said.  Advertisement. Scroll to continue reading. Related : Canvas System Is Online After a Cyberattack Disrupted Thousands of Schools Related : 1.2 Million Affected by University of Hawaii Cancer Center Data Breach Related : 3.5 Million Affected by University of Phoenix Data Breach Related : University of Sydney Data Breach Affects 27,000 Individuals Written By Eduard Kovacs Eduard Kovacs (@EduardKovacs) is senior managing editor at SecurityWeek. He worked as a high school IT teacher before starting a career in journalism in 2011. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering. Meta Paid $78,000 Bounty for Vulnerability Exposing Customer Support Data Exploitation of ServiceNow Vulnerability Seen Days After Disclosure SonicWall Zero-Days Exploited to Deliver Custom Malware for Weeks Before Patch New Index Tracks Material Breaches — And Refuses to Add Up the Losses WP2Shell WordPress Vulnerabilities Exploited in the Wild Two Scattered Spider Hackers Sentenced to Jail in UK ‘ClickLock Stealer’ Bypasses macOS Security With Social Engineering, Process Killing China’s Top Cybersecurity Firms Hit by Mounting Military Procurement Bans Fourth SharePoint Vulnerability Exploited in Past Month’s Wave of Attacks Endpoint Security Firm Glow Launches With $180M in Funding at $1.2B Valuation Oracle Patches Over 1,400 Vulnerabilities With Quarterly Security Updates Ransomware Group Threatening to Leak Data Stolen From Coca-Cola’s Fairlife OpenAI Says Its AI Models Broke Loose and Hacked Hugging Face Trump Orders Defense Contractors to Map Software, Suppliers Across Critical Supply Chains Cisco Launches Low-Cost AI Models for Source Code Security Empirical Security Raises $25 Million in Series A Funding Join this live webinar as we explore why exploitation is outpacing remediation, where risk is growing fastest, and what security leaders can do to close the gap before attackers take advantage. For the latest discoveries in cyber research for the week of 15th June, please download our Threat Intelligence Bulletin. The University of Nottingham, a UK research university, has suffered a data breach after ShinyHunters accessed its student records system. The incident affected about 454,600 current and former students and exposed contact details, passport numbers, enrollment information, and fee payment records later appeared online. According to analysts, this breach is part of a larger wave of attacks targeting more than 100 organizations by ShinyHunters, exploiting CVE-2026-35273, a critical zero-day vulnerability in Oracle PeopleSoft that allows remote code execution. Check Point IPS provides protection against this threat (Oracle PeopleSoft Enterprise PeopleTools Server-Side Request Forgery (CVE-2026-35273)) Mackay Sugar, Australia’s second-largest sugar producer, has been hit by a cyberattack that disrupted operations and shut down its Farleigh and Racecourse mills in Queensland. The company instructed growers to stop harvesting and suspended cane haulage while temporary measures were deployed to maintain essential operations. Danish pharmaceutical giant Novo Nordisk has disclosed a breach after attackers accessed internal IT systems and copied pseudonymized clinical trial data from research systems. The exposed information included patient IDs, trial participation details, limited health data, and some healthcare professionals’ contact information. Check Point Research has demonstrated exploitable flaws in LangGraph, an open-source framework for stateful AI agents. Researchers chained SQL injection and unsafe deserialization issues to achieve remote code execution, with patches issued for SQLite, core, and Redis checkpointer components in affected deployments. Check Point IPS provides protection against this threat (LangChain LangGraph SQL Injection (CVE-2026-27022)) Researchers highlighted a China-based phishing-as-a-service network, Outsider, that allegedly used Gemini to generate fake websites and support SMS phishing campaigns. Google filed a lawsuit after linking the operation to thousands of phishing sites, more than 1.5 million URLs, and large-scale victim targeting. Researchers warned that prompt-injection attacks against Anthropic’s Claude Code GitHub Action could leak CI/CD workflow secrets. Malicious issue or pull request text can instruct the agent to read environment variables and expose API keys, enabling workflow abuse and impersonation inside software repositories. Check Point Research has identified active exploitation of CVE-2026-50751, a critical authentication bypass vulnerability affecting Check Point Remote Access VPN and Mobile Access deployments configured to use the deprecated IKEv1 key exchange protocol. Attacks began in May and increased in early June, affecting a limited number of organizations, with one case tied to Qilin ransomware activity. Check Point IPS provides protection against this threat (IKEv1 Remote Access Authentication Bypass PoC Exploit (CVE-2026-50751)) Microsoft released its largest Patch Tuesday update to date, addressing more than 200 Windows and Defender vulnerabilities amid an AI-driven surge in vulnerability discovery. The fixes include CVE-2026-45657, a critical Windows flaw with a CVSS score of 9.8 that could enable network-based propagation, CVE-2026-41091, which has been actively exploited to gain full system control, and CVE-2026-50507, a BitLocker bypass vulnerability.

Nottingham
Servicenow logoUse of stolen credentials or exploit
Medium

ServiceNow Discloses Security Incident Exposing Customer Data

ServiceNow disclosed a security incident on June 12, 2026, where customer data was exposed due to an unauthenticated API vulnerability. The company patched the vulnerability but did not provide specific details on the exact data impacted or the number of affected customers. ServiceNow instances typically store sensitive enterprise information, including IT support tickets, employee records, internal documentation, asset inventories, security incident reports, workflow data, and configuration details for corporate systems and services.

Servicenow
Dinum logoPhishing
Medium

French government messaging platform Tchap breached via compromised user account

DINUM, the French government's digital affairs directorate, warned that hackers breached Tchap, France's encrypted messaging platform for public sector workers, using a compromised user account. The incident was detected by ANSSI, after which the affected account was blocked and an investigation launched into what conversations and data may have been accessed. DINUM has notified France's data protection authority, CNIL, due to the potential exposure of personal data. A threat actor claimed responsibility, alleging they used social engineering to access an education-related account and scrape messages, account information, and files, including 13.5GB of data from the French tax authority and other civil servants.

Dinum
Kyuden logo
Medium

Kyushu Electric Power Co. Discloses Data Breach Affecting Over 10 Million Customers

On June 12, 2026, Kyushu Electric Power Co., Inc., a Japanese energy firm, disclosed a physical security incident involving the loss of a drive containing unencrypted private data for more than 10 million customers. The incident highlights data protection failures beyond cyberattacks and is expected to trigger regulatory scrutiny and erode public trust due to the scale of exposed unencrypted customer Personally Identifiable Information (PII).

Kyuden
Chipsoft logoMisconfiguration or publishing error
Medium

Dutch hospitals restore digital access after cyberattack on ChipSoft

On June 12, 2026, reports indicated that Dutch hospitals were restoring digital access following a cyberattack on ChipSoft, a major healthcare software provider. The attack had previously caused patient files to become inaccessible at multiple locations, leading fifteen hospitals to preventively block all electronic patient information. This measure forced doctors to revert to paper records and oral transfers. While the incident was not a data leak in the traditional sense, it was a significant attack on the health infrastructure of the Netherlands, carried out through a single supplier serving numerous hospitals.

Chipsoft
Tanium logo
Medium

Tanium Affected by Klue Supply Chain Data Breach

Tanium was identified as one of the organizations impacted by the Klue supply chain breach, which involved the compromise of OAuth tokens and subsequent data exfiltration from connected Salesforce environments.

Tanium
Jamf logo
Medium

Jamf Affected by Klue Supply Chain Data Breach

Jamf was identified as one of the organizations impacted by the Klue supply chain breach, which involved the compromise of OAuth tokens and subsequent data exfiltration from connected Salesforce environments.

Jamf
Settra logoRansomware
Medium

Settra Suffers Ransomware Attack, Corporate Accounting Data Compromised

Settra, a company based in Singapore, was impacted by a ransomware attack with an estimated attack date of June 11, 2026. The attackers gained deep access to Microsoft Dynamics GP, compromising complete corporate accounting, invoices, and vendor details. This incident was disclosed on Ransomware.live.

Settra
Insurity logo
Medium

Insurity Affected by Klue Supply Chain Data Breach

Insurity was identified as one of the organizations impacted by the Klue supply chain breach, which involved the compromise of OAuth tokens and subsequent data exfiltration from connected Salesforce environments.

Insurity
Dystar logoRansomware
High

DyStar Group Hit by Settra Ransomware Attack, 1.3 TB of Internal Data Exfiltrated

Sponsored by Hudson Rock – Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks This page displays the 100 most recent victim disclosures attributed to ransomware groups, as detected by Ransomware.live . Our platform continuously monitors and scrapes ransomware group leak sites to identify and list newly published victims. Recent Breaches › dystar.com Listed by settra Ransomware Group dystar.com Listed by settra Ransomware Group: What Was Exposed & What To Do Occurred June 2026 · publicly disclosed June 28, 2026. Dystar.com was listed by the Settra ransomware group on June 28, 2026, with internal files reported exfiltrated in the attack. An undisclosed number of people may be affected; check the listing and monitor your accounts for signs of compromise. The incident was reported on 28 June 2026. dystar.com appears on a listing attributed to the settra ransomware group. The group claims to hold 1.3 terabytes of data described as the complete digital archive of DyStar. No independent confirmation of the volume, the date of access, or the method of entry has been released. The number of people affected remains undisclosed. Settra is a ransomware operator that lists victim organisations on a public site after encrypting systems and copying files. The group’s listings function as a claim that data has been taken and may be released if demands are not met. No additional statements from settra specific to dystar.com have been verified beyond the listing itself. dystar.com belongs to an organisation that operates in the specialty chemicals sector, supplying dyes and related products to industrial clients. Entities of this type routinely maintain records on production processes, customer accounts, supplier arrangements and internal communications. A breach that exposes such material can affect both commercial operations and any personal details contained in those records. The only category named in available reports is internal files exfiltrated during a ransomware attack. The precise contents of the 1.3 terabytes referenced in the listing have not been itemised by the organisation or independently verified. Organisations in this sector commonly store employee records, contractual documents and operational data, yet the exact composition of the material in this case stays unconfirmed. Internal files can contain identifying information, financial references or communications that retain value long after the initial incident. Individuals named in those files may encounter follow-on risks such as targeted fraud or unwanted contact. For the organisation, the exposure of proprietary material can complicate business relationships and regulatory compliance even if the number of personal records remains unknown. Begin by monitoring accounts linked to any email address you have used with dystar.com or its partners. Enable multi-factor authentication on those accounts and review recent login activity. Request a copy of any personal data the organisation holds about you under applicable data-protection rules. Readers can run a free exposure scan of their email address against known breach data to check for appearances in public listings. Change passwords for any accounts that may share credentials with dystar.com systems. Watch bank and credit statements for unusual activity over the next several months. Contact dystar.com directly to ask what categories of personal information were held and whether they have been notified of the listing. Read GalaxyWarden’s full analysis of the dystar.com Listed by settra Ransomware Group → Publicly posted by settra — unverified claim, pending independent verification Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available. Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

Dystar
Americanexpress logo
Medium

American Express Insider Breach Exposes Personal Financial Information

American Express disclosed a security breach on June 11, 2026, which was identified as an insider incident. An investigation by the Australian Privacy Commissioner revealed that an American Express employee accessed the personal financial information of a former partner. The company was found to have breached privacy laws by failing to implement adequate restrictions on staff access to customer accounts. The breach involved personal financial information.

Americanexpress
Gong logo
Medium

Gong Affected by Klue Supply Chain Data Breach

Gong was identified as one of the organizations impacted by the Klue supply chain breach, which involved the compromise of OAuth tokens and subsequent data exfiltration from connected Salesforce environments.

Gong
Nissan Global logoUse of stolen credentials or exploit
Medium

Nissan Employee Data Breach Linked to Oracle PeopleSoft Zero-Day

Nissan disclosed an employee data breach linked to the exploitation of the Oracle PeopleSoft CVE-2026-35273 vulnerability as a zero-day. The attacks, primarily impacting organizations in the education sector, occurred between May 27 and June 9, 2026.

Nissan Global
Nissanusa logoUse of stolen credentials or exploit
Medium

Nissan Americas Employee Data Breach via Oracle PeopleSoft Zero-Day Exploitation

Nissan Americas disclosed a data breach affecting current and former employees, which occurred between May 27 and June 9, 2026. The breach was facilitated by attackers exploiting CVE-2026-35273, a critical Server-Side Request Forgery (SSRF) vulnerability in Oracle PeopleSoft PeopleTools. The ShinyHunters extortion group claimed responsibility for the broader campaign, which impacted over 100 organizations, primarily in the education sector. Sensitive employee data, including contact information, banking details, Social Security numbers, Social Insurance Numbers, National Identification Numbers, financial and tax information, and dependent/beneficiary information, was accessed.

Nissanusa
Irhythmtech logo
Medium

iRhythm Confirms Data Stolen in Cyberattack, Ransom Demanded

Digital health company iRhythm Holdings confirmed a cyberattack involving certain third-party-hosted business applications. The company learned of the breach on June 8, 2026, which resulted in the theft of patient protected health information, proprietary data, and other personal data. Attackers subsequently demanded a ransom.

Irhythmtech

Explore the intelligence

Explore current intelligence taxonomies

Explore the intelligence

Questions about current cybersecurity intelligence

Explore concise answers about the latest reporting, intelligence taxonomies and the rolling coverage metrics on this page.

12 answers across 4 topics

How to read and use the current intelligence overview.

What does this cybersecurity intelligence overview contain?

It brings source-backed cybersecurity reports from the rolling 90-day window into one view, then connects them to companies, sectors, attack patterns, impacts and affected countries.

Where should I start exploring?

Start with Latest reporting for individual incidents, or use the taxonomy section to compare recurring patterns across industries, consequences and locations.

Does this page list every cybersecurity incident?

No. It is a curated view of public reports that meet Shadow Tier's publication and classification criteria, not an exhaustive record of every incident worldwide.

Browse current topics