Microsoft brings the popular PowerToys Windows 11 mouse indicator to the OS natively. Learn how to easily locate your cursor on high-resolution screens.
Related Posts:
Windows 11 Unified Memory Allocation
Windows 11 Game Crashes Tied to RGB Drivers
Windows 11 Gaming Issues Emerge After August Update
The post Windows 11 Mouse Indicator: Find Your Cursor Instantly appeared first on Daily CyberSecurity.
Microsoft brings the popular PowerToys Windows 11 mouse indicator to the OS natively. Learn how to easily locate your cursor on high-resolution screens.
G DATA details Projextor, an Electron malware hidden in working PDF and recipe apps that runs injected scripts and captures the desktop.
Related Posts:
Android Head Unit Malware Recruits Vehicles into Botnet
Evooo1Bot Linux Botnet Employs SOCKS Relays and DDoS
AmnesiaStealer macOS Infostealer Hacks Apple Devices
The post Projextor Malware Hides in Fake PDF and Recipe Apps appeared first on Daily CyberSecurity.
A Vault Secrets Operator vulnerability, CVE-2026-8715, lets tenants read pod files and gain privilege escalation. Patch to 1.5.0 now.
Related Posts:
CVE-2026-47301: PoC Exploit Achieves SYSTEM-Level Code Execution in SCCM
CVE-2026-66780 (CVSS 9.9): MITM Flaw Hits Red Hat ACM
CVE-2026-76404: Critical Remote Code Execution Hits Splunk MCP Server App (CVSS 9.1)
The post Vault Secrets Operator Flaw CVE-2026-8715 Enables Privilege Escalation appeared first on Daily CyberSecurity.
CVE-2026-68067 (CVSS 9.8) lets attackers control user accounts on the Mira Hormone Monitor by bypassing the cloud login. Eight flaws total.
Related Posts:
Apache Struts Patches Five Flaws Including Unauthenticated DoS Bugs
Roundcube Patches RCE and SSRF Flaws in 1.6.18 and 1.7.3
CVE-2026-15826: User Profile Builder Bug Under Active Attack, Grants Full Admin Takeover (CVSS 9.8)
The post CVE-2026-68067 (CVSS 9.8): Mira Monitor Flaw Lets Attackers Control User Accounts appeared first on Daily Cy
CVE-2026-63455 and CVE-2026-63456 let attackers bypass web authentication on HPE EdgeConnect Orchestrator. CVSS 9.8. Patch now.
Related Posts:
Apache Struts Patches Five Flaws Including Unauthenticated DoS Bugs
Roundcube Patches RCE and SSRF Flaws in 1.6.18 and 1.7.3
CVE-2026-15826: User Profile Builder Bug Under Active Attack, Grants Full Admin Takeover (CVSS 9.8)
The post CVE-2026-63455: EdgeConnect Orchestrator Web Authentication Bypass Rated CVSS 9.8 appeared first on Daily CyberSecurity.
Microsoft says China-linked Storm-1175 is using a new ransomware called StormEncryptor, replacing Medusa in its latest attacks.
Microsoft says China-linked, financially motivated threat actor Storm-1175 has begun using a new ransomware strain called StormEncryptor. The group previously relied on Medusa ransomware. StormEncryptor is written in C++ and encrypts files and adds the .encrypted extension, then leaves a !!!README_FIRST!!!.txt ransom note in each scanned directory. The change sugges
Microsoft says China-linked Storm-1175 is using a new ransomware called StormEncryptor, replacing Medusa in its latest attacks.
Microsoft says China-linked, financially motivated threat actor Storm-1175 has begun using a new ransomware strain called StormEncryptor. The group previously relied on Medusa ransomware. StormEncryptor is written in C++ and encrypts files and adds the .encrypted extension, then leaves a !!!README_FIRST!!!.txt ransom note in each scanned directory. The change suggests an evolution in the group’s ransomware operations.
“While Microsoft has not confirmed the vulnerability targeted by Storm-1175 in this campaign, the threat actor is likely exploiting the CVE-2026-18577 authentication bypass vulnerability in N-able, which was disclosed on August 2, 2026 and added to the Cybersecurity and Infrastructure Security Agency (CISA) Known Exploited Vulnerabilities (KEV) catalog on August 3, 2026.” wrote Microsoft on X.
On August 2, 2026, the financially motivated cybercriminal actor tracked by Microsoft Threat Intelligence as Storm-1175 began deploying a new ransomware strain called StormEncryptor.
Storm-1175’s deployment of StormEncryptor marks the threat actor’s first activity observed by… pic.twitter.com/wNbchat8ZU
— Microsoft Threat Intelligence (@MsftSecIntel) August 7, 2026
Storm-1175 is known for fast ransomware campaigns that exploit newly disclosed vulnerabilities before organizations can patch them. In recent attacks, the group used tools such as AnyDesk and SimpleHelp for remote access, Advanced IP Scanner to map networks, and Mimikatz to dump LSASS credentials.
Microsoft says the attackers can move from initial access to data theft and ransomware deployment within days, highlighting the need for rapid patching and monitoring.
China-based actor Storm-1175 carries out fast, financially driven ransomware attacks by exploiting newly disclosed vulnerabilities before organizations patch them. The group targets exposed systems and quickly moves from initial access to data theft and ransomware deployment, sometimes within 24 hours. The financially motivated group mainly targets sectors such as healthcare, education, finance, and services across the US, UK, and Australia. The attackers often chain exploits, create new accounts for persistence, move laterally using remote tools, steal credentials, and weaken security defenses. Their speed and focus on unpatched systems make them highly effective.
Microsoft researchers report that the group quickly exploits newly disclosed flaws in web-facing systems to gain access. Since 2023, the group has targeted many platforms, including Microsoft Exchange, Ivanti, ConnectWise, JetBrains, and others. It often weaponizes vulnerabilities within days, or even one day, before organizations apply patches.
“Storm-1175 rapidly weaponizes recently disclosed vulnerabilities to obtain initial access.” reads the report published by Microsoft. “Since 2023, Microsoft Threat Intelligence has observed exploitation of over 16 vulnerabilities, including:
The attackers also chain multiple exploits to achieve deeper access, such as remote code execution, and have targeted both Windows and Linux systems. In some cases, the threat actor used zero-days even before public disclosure, showing advanced capabilities. By focusing on unpatched systems and acting fast, Storm-1175 maximizes impact and maintains a strong advantage over defenders.
Storm-1175 chains multiple exploits to gain deeper access, as seen in attacks on Microsoft Exchange where it moved from initial access to remote code execution. The group also targets Linux systems and has used zero-day flaws before public disclosure, showing advanced skills.
After gaining access, it installs web shells or remote tools, creates admin accounts, and moves laterally using tools like PowerShell, PsExec, RDP, and Cloudflare tunnels. It also abuses legitimate RMM tools and software like PDQ Deployer and Impacket to spread across networks. The attackers can deploy ransomware in as little as one day, highlighting their speed and efficiency.
Cisco warns that seven ClamAV flaws affect Secure Endpoint Connector products, with two having public PoCs that could enable remote DoS attacks.
Cisco warned that seven ClamAV vulnerabilities affect its Secure Endpoint Connector on Windows, macOS and Linux. ClamAV is an open-source antivirus engine widely used to scan files and emails for malware.
The company states that two flaws have public PoCs and could let unauthenticated attackers cause DoS conditions.
“Multiple vulnerabilities
Cisco warns that seven ClamAV flaws affect Secure Endpoint Connector products, with two having public PoCs that could enable remote DoS attacks.
Cisco warned that seven ClamAV vulnerabilities affect its Secure Endpoint Connector on Windows, macOS and Linux. ClamAV is an open-source antivirus engine widely used to scan files and emails for malware.
The company states that two flaws have public PoCs and could let unauthenticated attackers cause DoS conditions.
“Multiple vulnerabilities in ClamAV could allow a remote attacker to cause a denial of service (DoS) condition, interrupting scanning operations.” reads the advisory.
The flaws, tracked as CVE-2026-20337 to CVE-2026-20339 and CVE-2026-20345 to CVE-2026-20348, affect ClamAV parsers for several file formats. ClamAV fixed them in version 1.5.4, Cisco later warned that public PoCs are available for the vulnerabilities CVE-2026-20337 and CVE-2026-20338. Company’s PSIRT said it has no evidence that attackers have exploited these vulnerabilities in the wild.
“”The Cisco PSIRT is aware that proof-of-concept exploit code is available for the vulnerabilities that are described in CVE-2026-20337 and CVE-2026-20338.The Cisco PSIRT is not aware of proof-of-concept exploit code for any of the other vulnerabilities that are described in this advisory.” continues the advisory. “The Cisco PSIRT is not aware of any malicious use of the vulnerabilities that are described in this advisory.”
Below are the descriptions of CVE-2026-20337 and CVE-2026-20338:
CVE-2026-20337 (CVSS score of 7.5) – CVE-2026-20337: ClamAV Zip File Format Processing Out-of-Bounds Write Vulnerability – A vulnerability in the zip archive parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition on an affected device. This vulnerability is due to improper boundary checks for content in zip files during scanning, which may result in an out-of-bounds write condition. An attacker could exploit this vulnerability by submitting a crafted zip file for scanning. A successful exploit could allow the attacker to cause the ClamAV scanning process to terminate, resulting in a DoS condition on the affected software.
CVE-2026-20337 (CVSS score of 7.5) – ClamAV Zip File Format Processing Memory Corruption Vulnerability – A vulnerability in the zip archive parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition on an affected device. This vulnerability is due to improper memory handling when processing content in zip files during scanning. An attacker could exploit this vulnerability by submitting a crafted zip file for scanning. A successful exploit could allow the attacker to cause the ClamAV scanning process to terminate as a result of a memory double-free, resulting in a DoS condition on the affected software.
Cisco identified the affected products in its advisory and recommends customers check the related bug IDs for details on each vulnerability.
Secure Endpoint Private Cloud is not affected, but must distribute the fixes to endpoints.
Cisco said no workaround is available. Patches will be released in August. The flaws are high risk on Windows because ClamAV runs with elevated privileges, while macOS and Linux face medium risk.
Security lapse leaves sensitive information and contact details of 51 government officials exposed for 40 hoursThe public body in charge of the UK’s state investments has been pushed to improve its internal security after a data breach left “high-level management information” publicly accessible for nearly two days.UK Government Investments (UKGI), the agency that manages the taxpayers’ interest in a swathe of companies including Channel 4 and the Post Office, said the security failure also left
Security lapse leaves sensitive information and contact details of 51 government officials exposed for 40 hours
The public body in charge of the UK’s state investments has been pushed to improve its internal security after a data breach left “high-level management information” publicly accessible for nearly two days.
UK Government Investments (UKGI), the agency that manages the taxpayers’ interest in a swathe of companies including Channel 4 and the Post Office, said the security failure also left more than 50 government officials’ personal details exposed for nearly 40 hours.
Created by legendary hardware hacker Andrew “bunnie” Huang, the badges for this year’s famed security conference aim to push the boundaries of security and transparency.
Created by legendary hardware hacker Andrew “bunnie” Huang, the badges for this year’s famed security conference aim to push the boundaries of security and transparency.
Ransomware often dominates cybersecurity headlines, but stolen data has become an equally valuable commodity in the cybercrime economy. In the first half of 2026, one threat actor stood out in the data leak ecosystem: Tanaka, a prolific data leak broker responsible for more publicized leak activity than any other actor tracked by Cyble.
Cyble researchers recorded 367 data breach and leak incidents worldwide between January and June 2026. While dozens of actors participated in selling or publ
Ransomware often dominates cybersecurity headlines, but stolen data has become an equally valuable commodity in the cybercrime economy. In the first half of 2026, one threat actor stood out in the data leak ecosystem: Tanaka, a prolific data leak broker responsible for more publicized leak activity than any other actor tracked by Cyble.Cyble researchers recorded 367 data breach and leak incidents worldwide between January and June 2026. While dozens of actors participated in selling or publishing stolen information, Tanaka emerged as the most active, accounting for 25 distinct leak posts — more than double the activity of several other major actors.
A Data Leak Operation Without Industry Boundaries
Unlike threat actors that specialize in a single vertical, Tanaka followed a broad targeting approach across multiple industries and regions. The actor’s campaigns showed no strict preference for a specific sector, instead focusing on organizations where stolen information could hold financial or strategic value.The Banking, Financial Services, and Insurance (BFSI) sector remained the most targeted industry globally, accounting for 38 breach incidents during the reporting period. Financial organizations continue to attract attackers due to the value of customer information, account data, and personally identifiable information (PII).Government and Technology organizations were also frequent targets, reflecting the wider value of sensitive records, intellectual property, and institutional data.
Regional Presence Across Major Markets
Tanaka’s activity was visible across multiple regions. In North America, the actor was responsible for seven leak posts, making it the most active data leak actor in the region alongside other prominent sellers.Europe and the UK also saw significant activity, with Tanaka linked to six leak posts during H1 2026. The region’s BFSI, Telecommunications, and Retail sectors faced heightened exposure due to the amount of valuable customer and financial data they hold.The actor’s global footprint demonstrates how modern data leak operations can function independently of geography. Instead of focusing on a single country or industry, operators like Tanaka exploit opportunities wherever valuable information becomes available.
The Rise of the Data Leak Marketplace
Tanaka’s activity reflects a broader shift in the cybercrime ecosystem. Data leaks are no longer only a byproduct of ransomware attacks; they have become a standalone business model.Threat actors monetize stolen information through underground marketplaces, using leaked databases for fraud, extortion, intelligence gathering, or resale. This specialization mirrors other parts of the cybercrime economy, where access brokers, ransomware affiliates, and data sellers perform separate roles.For organizations, this means a breach does not always begin with a ransomware demand. A stolen database appearing in underground channels may indicate an earlier compromise that requires immediate investigation.
Staying Ahead of Data Exposure Risks
Security teams must treat underground data exposure monitoring as part of their broader defense strategy. Identifying leaked credentials, compromised databases, or mentions in cybercrime marketplaces can provide early warning before stolen information is weaponized.To understand the 2026 data breach landscape, including the most active threat actors, targeted industries, and regional trends, access the full Cyble H1 2026 Cyber Threat Landscape Report.
The Fairlife ransomware attack has temporarily halted production operations at Coca-Cola-owned dairy company fairlife in the United States after unauthorized access was detected in a portion of its systems, including production-related systems.
According to The Coca-Cola Company, fairlife identified unauthorized access by a third party in connection with a ransomware event. Following the discovery, the company activated its incident response and business continuity protocols while launching a
The Fairlife ransomware attack has temporarily halted production operations at Coca-Cola-owned dairy company fairlife in the United States after unauthorized access was detected in a portion of its systems, including production-related systems.
According to The Coca-Cola Company, fairlife identified unauthorized access by a third party in connection with a ransomware event. Following the discovery, the company activated its incident response and business continuity protocols while launching an investigation with the support of external advisors and cybersecurity experts. Law enforcement has also been notified.
The company said the investigation is ongoing and that the full scope, nature, and impact of the incident are not yet known.
Fairlife Ransomware Attack Suspends U.S. Production
The Fairlife ransomware attack has resulted in the temporary suspension of production operations at fairlife facilities across the United States. However, the company stated that product quality and safety have not been affected by the incident.
According to the company's statement, fairlife's production operations in Canada remain operational and have not been impacted by the ransomware event.
The Coca-Cola Company also confirmed in a Form 8-K filing dated July 16, 2026, that fairlife detected the unauthorized access on Thursday. The filing reiterated that the company immediately activated its incident response procedures and business continuity protocols after identifying the intrusion.
While the company continues to assess the incident, it said it has not yet determined whether the ransomware attack is reasonably likely to materially affect its business because the full impact remains unknown.
The company added that it is working to complete its investigation and restore affected systems and production operations as quickly as possible.
Investigation Into Unauthorized Access Continues
The ongoing investigation is being conducted with assistance from outside cybersecurity experts. According to the company, the incident involved unauthorized access to a portion of fairlife's systems, including systems related to production.
At this stage, The Coca-Cola Company has not disclosed how the attackers gained access, whether any data was compromised, or if a ransomware group has claimed responsibility for the attack.
The company emphasized that its assessment is still underway and that additional details will be shared as more information becomes available.
Food and Beverage Sector Faces Growing Cybersecurity Risks
The food and beverage cyberattack trend has continued to affect manufacturers and logistics providers worldwide in recent months.
On July 16, a cyberattack targeting Nichirei disrupted food deliveries across Japan after the frozen food and logistics provider confirmed unauthorized access to its servers. The incident affected logistics operations supporting KFC Japan, leading to temporary service disruptions while systems were being restored.
Earlier this year, in February 2026, Australian poultry processor Hazeldenes also experienced a cybersecurity incident that disrupted production across its network. The Victoria-based company later announced it had begun a phased return to production to restore operations safely and securely while investigations continued.
The latest incident involving fairlife adds another major food producer to the list of companies dealing with operational disruptions linked to cyber incidents. While production has been paused at fairlife's U.S. facilities, the company has maintained that product quality and safety remain unaffected and that its Canadian production continues without disruption.
As the investigation progresses, The Coca-Cola Company said it remains focused on restoring impacted systems and resuming normal production operations. The company also noted that the complete scope and potential business impact of the incident have not yet been determined.
The investigation into the Odido cyberattack has uncovered possible involvement of Dutch nationals, according to Dutch police, as authorities continue to investigate the ShinyHunters ransomware-linked attack that exposed the personal data of approximately 6.39 million customers. Law enforcement has urged the public to come forward with information as investigators work to identify those responsible for one of the country's largest telecom data breaches.
The cyberattack took place on February 5
The investigation into the Odido cyberattack has uncovered possible involvement of Dutch nationals, according to Dutch police, as authorities continue to investigate the ShinyHunters ransomware-linked attack that exposed the personal data of approximately 6.39 million customers. Law enforcement has urged the public to come forward with information as investigators work to identify those responsible for one of the country's largest telecom data breaches.
The cyberattack took place on February 5 and 6 after attackers allegedly used voice phishing (vishing) to deceive Odido's customer service team.
According to the company, the attackers posed as members of its internal IT staff, gaining unauthorized access before exfiltrating customer data. Odido said its teams detected the unauthorized access immediately on both occasions and revoked the attackers' access, but the incident still resulted in a large-scale data breach.
Odido Cyberattack Investigation Finds Possible Dutch Link
Under the direction of the National Public Prosecution Service, the High Tech Crime Team (THTC) of the National Investigation and Intervention Unit launched an extensive investigation into the breach.
Authorities said investigators have found strong indications that Dutch criminals may have been involved. One key lead centers on a phone call made shortly before the breach in which a Dutch-speaking man allegedly impersonated an Odido IT employee while speaking with customer service representatives. Police are continuing efforts to identify the caller and have indicated that his voice could be made public if necessary.
Investigators believe people within cybercrime circles may have information about those responsible and are encouraging anyone with relevant details to contact law enforcement.
ShinyHunters Named as Threat Actor
Odido attributed the attack to the cybercriminal group ShinyHunters, which the company said carried out the social engineering campaign.
Chief Executive Officer Søren Abildgaard acknowledged the incident in a public statement, apologizing to customers and outlining the company's commitment to strengthening its cybersecurity capabilities. He said Odido would continue investing in security, improve data protection practices, expand customer support, and share lessons learned from the incident.
The CEO also explained why the company refused to pay the ransom demand. According to Odido, paying cybercriminals would reward illegal activity and could encourage future attacks against other Dutch organizations. The company said the decision was made following guidance from authorities, despite knowing that stolen data could eventually be published.
Millions of Customers Impacted
Odido confirmed that approximately 6.39 million active and former customers of Odido and its Ben brand were affected by the breach. Customers of Simpel were not impacted.
The exposed information varied by individual and included names, addresses, mobile phone numbers, customer numbers, email addresses, IBAN numbers, dates of birth, identification details, nationality, and gender.
The company clarified that My Odido account passwords, call records, location data, billing information, and scans of identity documents were not compromised.
Odido also addressed reports claiming customer passwords had been leaked, stating that login passwords remain securely encrypted and were never accessible during the attack. Instead, a separate telephone verification field known as "password_c," used as a customer challenge code, was included for a limited number of customers. The company has since discontinued using that verification method.
Customer Support and Security Measures Expanded
Following the breach, Odido increased customer support by adding more than 140 service agents and introduced additional security measures. These include its "Check je Gesprek" verification service, allowing customers to confirm whether communications claiming to be from Odido are legitimate, along with access to the F-Secure digital security service.
The telecom provider said all customers identified as affected have been notified by email or SMS, while customer service teams continue assisting users with questions related to their specific data exposure.
Meanwhile, Dutch authorities expect investigations into the Odido cyberattack to continue for several months. Police have also warned that cyberattacks targeting businesses and institutions are becoming increasingly common, urging organizations to strengthen cybersecurity defenses and encouraging citizens to remain vigilant against follow-on fraud and phishing attempts.
A newly disclosed zero-day vulnerability, CVE-2026-20245, has been exploited by a threat actor targeting Cisco Catalyst SD-WAN Manager. By exploiting a flaw in the platform's file to upload functionality, the threat actor escalated privileges from a compromised administrative account to root access and used extensive anti-forensic measures to erase evidence of the attack.
Threat Actor Abused Cisco Catalyst SD-WAN Manager to Gain Root Access
Mandiant found that the threat actor initially esta
A newly disclosed zero-day vulnerability, CVE-2026-20245, has been exploited by a threat actor targeting Cisco Catalyst SD-WAN Manager. By exploiting a flaw in the platform's file to upload functionality, the threat actor escalated privileges from a compromised administrative account to root access and used extensive anti-forensic measures to erase evidence of the attack.
Threat Actor Abused Cisco Catalyst SD-WAN Manager to Gain Root Access
Mandiant found that the threat actor initially established unauthorized peering connections before accessing Cisco Catalyst SD-WAN Manager over SSH. In March 2026, the attacker authenticated using the default vmanage-admin account, changed the default admin account password, logged into the web interface, and exfiltrated SD-WAN fabric configurations, including device, controller, and template information. The original password was then restored to reduce the likelihood of detection. The researchers noted that neither the vmanage-admin nor admin accounts provide root shell access, prompting the attacker to exploit CVE-2026-20245 for privilege escalation.
CVE-2026-20245 was Exploited Through a Malicious CSV Upload
The vulnerability exists because Cisco Catalyst SD-WAN Manager fails to properly filter malicious data uploaded through its tenant file upload feature. The threat actor exploited CVE-2026-20245 by uploading a crafted file named evil_tenant.csv using the command:
Reported to Cisco by Mandiant, CVE-2026-20245 affects the command-line interface of Cisco Catalyst SD-WAN Controllers and allows an authenticated local attacker to execute arbitrary commands as root through a specially crafted file.The malicious payload backed up configuration files, preserved copies of /etc/passwd and /etc/shadow, and created a new root-level account named troot. Mandiant later observed the threat actor switching from the admin account to troot using the su command.
Rogue Peering Activity Preceded Exploitation
Mandiant observed multiple unauthorized peering connections between late 2025 and January 2026. Researchers believe these may have exploited CVE-2026-20127 or CVE-2026-20182, two critical Cisco vulnerabilities affecting peering authentication that allow remote attackers to bypass authentication and gain administrative privileges.Further rogue peering activity in March 2026 targeted software versions not vulnerable to CVE-2026-20127. Cisco confirmed the activity also did not rely on CVE-2026-20182, suggesting the threat actor may have reused stolen certificate material from an earlier compromise. Mandiant said it remains unclear whether the same group conducted both campaigns.To conceal the intrusion, the threat actor deleted evil_tenant.csv, restored modified configuration files, removed temporary artifacts, and executed a validation script to confirm that malicious files, the troot account, and altered configuration files had been removed or restored.
Implications and Mitigation
Mandiant said the campaign reflects the growing "living off the edge" trend, where attackers target network appliances that often lack detailed forensic visibility while providing centralized control over enterprise environments. Such platforms remain attractive to state-sponsored actors seeking long-term intelligence collection.Organizations are advised to collect diagnostic logs using the request admin-tech command, investigate any indicators of compromise, and report confirmed incidents to Cisco TAC. Cisco recommends upgrading Cisco Catalyst SD-WAN Manager to versions 20.9.9.2, 20.12.7.2, 20.15.4.5, 20.15.5.3, 20.18.3.1, 26.1.1.2, or later to remediate CVE-2026-20245 and following its SD-WAN hardening guidance.Recovered indicators include the malicious evil_tenant.csv file with SHA-256 hash b82936f37648518425c7d3cf9e09eaffa41d7cdb3840f6a40287e3a108880f7b and rogue IP addresses including 126.51.108[.]152, 76.92.245[.]217, 207.190.37[.]94, 23.245.7[.]178, 153.186.231[.]233, 167.179.79[.]189, 45.32.38[.]160, and 209.137.225[.]101. Google SecOps also released detections covering behaviors associated with the threat actor, while Mandiant acknowledged Cisco PSIRT for its collaboration during the coordinated disclosure process.
The legal fallout from the Stryker cyberattack continues to unfold, as the medical technology manufacturer has asked a federal court to dismiss a proposed class action lawsuit brought by current and former employees. The plaintiffs allege that their personal information was compromised during the cyberattack on Stryker, but the company argues that its investigation found no evidence supporting those claims.
Employee Data Was Not Accessed During the Stryker Cyberattack
In a court filing submi
The legal fallout from the Stryker cyberattack continues to unfold, as the medical technology manufacturer has asked a federal court to dismiss a proposed class action lawsuit brought by current and former employees. The plaintiffs allege that their personal information was compromised during the cyberattack on Stryker, but the company argues that its investigation found no evidence supporting those claims.
Employee Data Was Not Accessed During the Stryker Cyberattack
In a court filing submitted Monday, Michigan-based Stryker said an internal review conducted with independent experts found that none of the eight named plaintiffs had personally identifiable information (PII) accessed during the incident. According to a statement from Chief Information Security Officer Juan Pablo Calderon, investigators examined files and data that the threat actor may have accessed during the attack.“Those files and data were searched for plaintiffs' PII, and Stryker determined as a purely factual matter that none of the plaintiffs' PII exists in those files and data,” Calderon stated. He added that business email addresses belonging to two plaintiffs were found, but no sensitive personal information was identified.
Iranian Hacktivists Claimed Massive Data Theft and Destruction
The Stryker cyberattack was claimed by Handala, a group widely suspected of acting as a front for Iran’s Ministry of Intelligence. The Iranian hacktivists alleged in March that they had stolen 50 terabytes of critical company data. They further claimed to have erased 200,000 devices and 12 petabytes of data “in just a few hours,” describing the information as assets that had taken years to collect and billions of dollars to protect.The cyberattack on Stryker occurred nearly two weeks after the United States and Israel launched major military operations against Iran on February 28. While Stryker maintained that customer-connected devices and systems were not affected, the incident disrupted electronic ordering and related services used by clients. Those systems remained unavailable for several weeks before being fully restored in early April.
Legal Experts Weigh In on the Cyberattack on Stryker
Stryker also argued that the plaintiffs rushed to court, filing lawsuits “merely 48 hours” after the company disclosed the cyberattack on March 11. According to the company, the lawsuits relied on speculation that names, Social Security numbers, and other personal information had been exposed.The company further contends that each plaintiff’s PII had already been exposed in previous breaches involving other organizations, making it difficult to connect any alleged harm, including identity theft, directly to the cyberattack on Stryker. None of the named plaintiffs received breach notifications from the company, yet they seek to represent all U.S. individuals whose information was allegedly compromised.Legal experts say the case highlights broader questions surrounding data breach litigation. Steven Teppler of Mandelbaum Barrett noted that “the complaint may outrun the facts” when lawsuits are filed immediately after a cyberattack. He added that courts increasingly require plaintiffs to show “more than speculation” that their information was affected.
Japanese telecommunications company KDDI has disclosed a major cybersecurity incident in which up to 14.22 million email addresses and passwords may have been exposed through systems used by multiple internet service providers. The KDDI data breach has now become one of the most recent security events involving shared ISP infrastructure in Japan.
The company confirmed that the data breach at KDDI was detected on June 17, 2026, after unauthorized access was identified in an email system provi
Japanese telecommunications company KDDI has disclosed a major cybersecurity incident in which up to 14.22 million email addresses and passwords may have been exposed through systems used by multiple internet service providers. The KDDI data breach has now become one of the most recent security events involving shared ISP infrastructure in Japan.The company confirmed that the data breach at KDDI was detected on June 17, 2026, after unauthorized access was identified in an email system provided to ISP operators. KDDI said it immediately took steps to modify the affected system and deployed protective measures after identifying the entry point used by a threat actor.
KDDI Data Breach Linked to Third-Party Software Vulnerability
The data breach at KDDI impacted email services operated through six internet service providers: STNet, KDDI Web Communications, JCOM, Chubu Telecommunications, Nifty, and Biglobe. Affected services include Pikara Hikari Service, Pikara Mobile Service, Oshigoto Pikara Service, CPI rental server email services, J:COM NET, Commufa Hikari, Business Commufa, @nifty Mail, and BIGLOBE Mail.KDDI’s investigation found that the threat actor exploited vulnerabilities in third-party software integrated into the email system. This allowed unauthorized access to information associated with user mailboxes, potentially exposing credentials needed to operate email accounts.According to the company, the compromised data may include email addresses and passwords linked to user accounts created across the affected services. The maximum number of records potentially exposed is estimated at 14.22 million. This figure includes inactive accounts and users who had previously closed their services. Some passwords were stored in hashed or encrypted form, though KDDI emphasized that the number represents a worst-case estimate while investigations continue.In its official disclosure, KDDI apologized to ISP partners, customers, and stakeholders for the disruption caused by the incident. The company also confirmed that it is cooperating with Japan’s Personal Information Protection Commission and the Ministry of Internal Affairs and Communications in line with legal and regulatory obligations related to the KDDI data breach.
KDDI Data Breach Prompts Password Reset Measures and Ongoing Response
Following the detection of the data breach at KDDI, the company has been working with affected ISPs to notify users and encourage them to change their passwords immediately. KDDI stated that although security controls have been strengthened, there remains a possibility that email credentials were obtained by a threat actor, making user action necessary to reduce ongoing risk.The company has been contacting affected providers since June 17 and continues to coordinate mitigation efforts, including customer alerts and system-level countermeasures. It has also urged users to follow guidance issued by their respective ISPs and update login credentials without delay.
Rising Cybersecurity Risks Highlighted by KDDI Data Breach
The KDDI data breach has emerged amid a broader increase in cyberattacks affecting Japanese organizations. According to Tokyo Shoko Research, listed companies and their subsidiaries reported 180 personal information breach cases in 2025, exposing data tied to approximately 30.6 million individuals. More than 60% of these incidents involved unauthorized access or malware infections.Ransomware activity has also continued to rise, with Japanese police confirming 226 cases of ransomware-related incidents last year, marking the second-highest total on record. While small and midsize firms accounted for roughly 60% of victims, several large organizations also suffered significant operational disruption.Among them, Asahi Group Holdings reported that a ransomware attack in September exposed 115,513 personal records and disrupted production and distribution across most domestic facilities, forcing manual order processing for an extended period. Similarly, Askul disclosed that a ransomware incident discovered in October resulted in the exposure of approximately 740,000 records involving customers, corporate clients, and employees.
Microsoft researchers warn of a new dual-action cryptocurrency clipper (CryptoBandits Malware) spreading through USB devices to alter wallet addresses and steal crypto assets.
Microsoft researchers warn of a new dual-action cryptocurrency clipper (CryptoBandits Malware) spreading through USB devices to alter wallet addresses and steal crypto assets.
USB .lnk malware steals crypto via clipboard hijack, replaces wallet addresses, steals seed phrases, and screenshots.
Microsoft Threat Intelligence has been tracking a clipboard-stealing malware (Clipper) campaign since February 2026 that targets cryptocurrency wallets. A clipper is a type of malicious software that monitors and manipulates your clipboard, the temporary memory where data is stored when you copy and paste.
It spreads through malicious shortcut files on USB drives, hides it
USB .lnk malware steals crypto via clipboard hijack, replaces wallet addresses, steals seed phrases, and screenshots.
Microsoft Threat Intelligence has been tracking a clipboard-stealing malware (Clipper) campaign since February 2026 that targets cryptocurrency wallets. A clipper is a type of malicious software that monitors and manipulates your clipboard, the temporary memory where data is stored when you copy and paste.
It spreads through malicious shortcut files on USB drives, hides its command server inside the Tor network, and can replace wallet addresses in your clipboard before you paste them. The attacker collects the crypto; you collect the confusion.
What makes it harder to spot is that this clipper doesn’t use a traditional installer or expose any real IP addresses. It ships with its own Tor client, routes traffic through a local proxy on port 9050, and resolves everything to .onion domains inside Tor.
“The clipper in this campaign relies on Windows Script Host and ActiveX-driven logic to launch a bundled Tor proxy and poll a hidden-service C2 server. It carries out high-frequency clipboard theft, screenshot exfiltration, and wallet-address substitution.” reads the report published by Microsoft. “The execution of this clipper is notable because it does not depend on a traditional installer or exposed IP-based C2 infrastructure. Instead, it deploys a portable Tor client, routes traffic through a local SOCKS5 proxy, and blends data theft with remote code execution, turning a financially motivated stealer into a lightweight backdoor.”
The attack chain starts when someone opens a .lnk shortcut file from a USB drive. The malware then scans the device for document files like .doc, .xlsx, and .pdf, hides the originals, and replaces them with malicious shortcuts carrying the same names. Open what you think is a spreadsheet and you’re running malware. It also sets up scheduled tasks to copy itself onto any new USB drive that gets plugged in.
Malware steals crypto data from clipboard by capturing BIP39 seed phrases and private keys, exfiltrates via Tor, and sends screenshots for context.
“The malware detects 12 or 24-word BIP39 seed phrases in clipboard data. It saves the seed to local file (GOOD path) as a backup and exfiltrates it to the C2 domain via Tor.” states the report. “It retries network transmission until it is acknowledged and deletes local backup after successful transmission.”
Beyond seed phrases, it also grabs Ethereum and Bitcoin WIF private keys, and checks the clipboard every 500 milliseconds for wallet addresses across Bitcoin, Ethereum, Tron, and Monero. When it finds one, it swaps it out for an attacker-controlled address that partially resembles the original, so a quick glance won’t catch the swap.
The stealer also takes five screenshots every ten seconds and sends them over Tor, giving the attacker a live view of what the victim is doing with their wallet. There’s also a remote code execution channel: the C2 can send an EVAL instruction, the malware downloads JavaScript into a file called “cfile,” and runs it. That turns what looks like a simple crypto thief into something with full backdoor potential.
Microsoft researchers highlight that all the malware components are encrypted and only decrypted at runtime, wrapped in PyArmor-obfuscated Python and packaged with PyInstaller. The JavaScript payloads get two layers of obfuscation on top of that. It also checks for Task Manager before doing anything, and exits if it’s running.
“For defenders, the strongest signals are behavioral: script interpreters spawning suspicious child processes, localhost:9050 proxy usage, screen-capture commands in PowerShell, and signs of clipboard inspection or crypto-address replacement.” Microsoft continues.
Microsoft Defender for Endpoint detects components of this threat and flags it as Trojan:Win32/CryptoBandits.A. If you’re handling any sensitive financial workflows, monitoring wscript.exe and cscript.exe activity and blocking .lnk execution from removable drives via Group Policy are the right places to start.
“This malware family shows how lightweight, script-based stealers can deliver outsized impact when paired with anonymized communications and runtime tasking.” concludes the report. “The combination of Tor-routed C2, clipboard targeting, screenshot capture, and remote code execution gives attackers both immediate monetization paths and continued control over compromised devices.”
Nintendo of America has confirmed that employee survey data was exposed in the recent TinyPulse cyberattack, although the company emphasized that its own systems were not breached and that no customer or financial information was accessed. The disclosure follows claims by the threat actor Shadowbyt3$, which alleged it had stolen sensitive information linked to Nintendo employees.
In a statement addressing the TinyPulse cyberattack, Nintendo said it was aware of an issue involving TinyPulse,
Nintendo of America has confirmed that employee survey data was exposed in the recent TinyPulse cyberattack, although the company emphasized that its own systems were not breached and that no customer or financial information was accessed. The disclosure follows claims by the threat actor Shadowbyt3$, which alleged it had stolen sensitive information linked to Nintendo employees.In a statement addressing the TinyPulse cyberattack, Nintendo said it was aware of an issue involving TinyPulse, a third-party platform used for internal employee surveys. According to the company, the incident was limited to data held by the service provider rather than Nintendo's internal infrastructure.“We are aware of an issue involving TinyPulse, a third-party service used for internal employee surveys at Nintendo of America,” Nintendo stated.The company further clarified that “Nintendo’s systems have not been compromised, and no personal customer or financial data has been accessed.”
Nintendo Says Exposure Was Limited in the TinyPulse Cyberattack
According to Nintendo, the data affected by the TinyPulse cyberattack consisted of internal survey content involving only a small subset of employees. The company added that most of the information dated back several years.“The data involved is limited to internal survey content comprising a small subset of our employees, and most of the information dates back several years,” Nintendo told media outlets.Nintendo of America, a subsidiary of the Japanese gaming giant Nintendo, oversees operations across the United States, Canada, and parts of Latin America. TinyPulse is an employee engagement and feedback platform that supports anonymous surveys, workplace culture assessments, engagement analytics, and feedback collection.Nintendo said it is currently “working with the service provider to address the issue.”The Cyber Express has also reached out to Nintendo for additional details regarding the TinyPulse cyberattack. However, no further statement had been received at the time of publication.
Shadowbyt3$ Claims Broader Data Theft
Despite Nintendo's assessment of the incident, the threat actor Shadowbyt3$ has claimed that the stolen information extends beyond employee survey responses and includes personal employee data.In an initial message, Shadowbyt3$ alleged that nearly 1GB of data had been exfiltrated from Nintendo and gave the company 48 hours to enter negotiations before the information would be leaked.The threat actor claimed the dataset contains full names, email addresses, analytics and survey data, bank statements, W-9 forms with employee IDs, progress plans, and reports spanning from 2016 to 2026.“If you contact us we give you an extra day to think this through. We are demanding a ransom payment of 2 million dollars,” the Shadowbyt3$ post stated.
Threat Actor Issues Additional Warnings
In a follow-up message, Shadowbyt3$ clarified that the alleged breach “doesn't affect nintendo gaming” but instead impacts “a small amount of employees that work for nintendo and have used tinypulse.”The threat actor later published another post warning that more victims would emerge. The message included a link to allegedly leaked data containing direct messages and employee conversations, suggesting Nintendo did not agree to pay the $2 million ransom demand.As of now, Nintendo maintains that the TinyPulse cyberattack was limited in scope and did not compromise its internal systems, while Shadowbyt3$ continues to assert that more sensitive employee information was stolen.
Cardiac monitoring company iRhythm Technologies has disclosed a cybersecurity incident involving unauthorized access to data stored within certain third-party-hosted business applications. The company revealed details of the iRhythm data breach in a recent SEC filing, stating that sensitive information, including protected health information (PHI), may have been accessed and exfiltrated by a threat actor.
According to the SEC filing, iRhythm identified suspicious activity on June 8 and immed
Cardiac monitoring company iRhythm Technologies has disclosed a cybersecurity incident involving unauthorized access to data stored within certain third-party-hosted business applications. The company revealed details of the iRhythm data breach in a recent SEC filing, stating that sensitive information, including protected health information (PHI), may have been accessed and exfiltrated by a threat actor.According to the SEC filing, iRhythm identified suspicious activity on June 8 and immediately activated its cybersecurity response protocols. The company launched an investigation with assistance from external advisors and cybersecurity specialists to determine the scope of the incident and implement containment measures.
Decoding the iRhythm Data Breach
The company reported that on June 9, it received communications from a threat actor who claimed to have obtained "sensitive information" from the affected systems. According to iRhythm, the allegedly compromised data included proprietary company information, patient protected health information, and other forms of personal information.The threat actor also demanded payment in exchange for withholding the information from public disclosure.Following the communication, iRhythm conducted additional reviews and confirmed that certain data had indeed been exfiltrated from the impacted third-party-hosted applications. By June 10, the company determined that the incident was material due to the volume of potentially affected information.The SEC filing noted that the company continues to investigate the full nature and scope of the iRhythm data breach.
Company Says Core Operations Remain Unaffected
Despite the seriousness of the incident, iRhythm stated that it has not identified any disruption to its products, patient services, or operational capabilities.According to the SEC filing, the company has found no impact on:
Products and services
Clinical systems
Medical device systems
Patient safety
Manufacturing operations
Distribution activities
Financial reporting systems
The company's ability to continue serving patients
iRhythm said the data breach at iRhythm stemmed from a social engineering attack targeting certain third-party-hosted business applications rather than its clinical infrastructure.The company further emphasized that the incident did not affect its clinical or medical device systems, nor did it involve connections used by customers. Additionally, iRhythm stated that it does not store or retain individual financial account information or payment card information, reducing the likelihood that such data was compromised.
Investigation Continues as Company Assesses Impact
As of the latest SEC filing, iRhythm reported that it has found no evidence of ongoing unauthorized access within its systems.The company stated that its investigation remains active and that it is continuing to evaluate the extent of the exposure and any potential consequences arising from the incident. At present, iRhythm believes the cybersecurity event is "not reasonably likely" to have a material effect on its financial condition or operating results.The company also noted that it maintains cybersecurity insurance that could potentially offset certain losses related to the incident. However, iRhythm cautioned that there can be no assurance that insurance coverage would fully compensate for all losses associated with the breach.
Threat actors are deploying an updated SHub Stealer variant named Reaper that exploits the native macOS Script Editor to bypass OS-level protections and compromise cryptocurrency assets.
Threat actors are deploying an updated SHub Stealer variant named Reaper that exploits the native macOS Script Editor to bypass OS-level protections and compromise cryptocurrency assets.