Visualização normal

Antes de ontemStream principal

SonicWall Warns of Two Actively Exploited SMA1000 Zero-Days, One Rated Maximum Severity

3 de Setembro de 2026, 04:47

Graphic showing SonicWall SMA1000 devices, CVE-2026-83548, the maximum-severity SonicWall SMA1000 pre-authentication vulnerability

SonicWall disclosed this week that attackers are chaining two previously unknown vulnerabilities in its SMA1000 secure access appliances to run commands on unpatched devices, and urged customers to install an emergency hotfix.

The more severe flaw, CVE-2026-83548, is a pre-authentication server-side request forgery weakness in the appliance's Appliance Work Place interface, rated 10.0 on the CVSS scale. It lets a remote attacker with no credentials reach sensitive internal functionality. The second, CVE-2026-83549, is an operating-system command injection bug in the Appliance Management Console rated 7.8; on its own it requires administrative authentication, but paired with the SSRF flaw it yields remote code execution.

The vendor said it found both issues internally and then observed them being used together in live attacks. SonicWall has not published indicators of compromise or described the attackers.

Affected products are the SMA1000 series 6210, 7210 and 8200v, in both hardware and virtual form. Fixed builds are 12.4.3-03526 and later, and 12.5.0-02952 and later. SonicWall firewalls running SSL-VPN and the separate SMA 100 line are not affected.

Remediation guidance goes beyond patching. SonicWall told customers to contact its support organization to review appliances for signs of intrusion and, where compromise is suspected, to re-image or redeploy the device, rotate all credentials and reset TOTP tokens — an acknowledgment that one-time-password seeds stored on a breached appliance survive a software update. The company said customers should move to the hotfix release as quickly as possible.

Shadowserver Foundation scanning has tracked more than 400 internet-exposed SMA1000 appliances, though an unknown share of those are already patched. The small install base belies the risk profile. These are remote-access gateways that sit at the network edge and hold credentials for the environments behind them.

The disclosure extends a difficult run for the product line. Attackers exploited a separate pair of SMA1000 zero-days in July 2026, tracked as CVE-2026-15409 and CVE-2026-15410, to deploy custom malware; CISA later confirmed ransomware operators were abusing that access.

Read: CISA Adds SonicWall SMA1000 Vulnerabilities to KEV Catalog Following Active Exploitation

Another zero-day surfaced in December 2025. Seventeen SonicWall vulnerabilities across the company's product families currently sit in CISA's Known Exploited Vulnerabilities catalog. Edge appliances from SonicWall, Ivanti, Citrix and Fortinet have collectively become the preferred initial-access route for ransomware affiliates and espionage crews, because they are internet-facing by design and rarely instrumented with endpoint detection.

  • ✇Firewall Daily – The Cyber Express
  • US Treasury Launches Major Campaign to Disrupt Iran’s Global Networks Samiksha Jain
    The U.S. Department of the Treasury has launched Operation Economic Outcast, a whole-of-government campaign aimed at disrupting the economic networks and revenue channels supporting the Iranian regime and the Islamic Revolutionary Guard Corps (IRGC). The initiative expands Iran sanctions across digital assets, technology, gold, aviation and shipping, while targeting nearly 60 entities, individuals and vessels across multiple jurisdictions. Treasury said the campaign follows direction from Pre
     

US Treasury Launches Major Campaign to Disrupt Iran’s Global Networks

25 de Agosto de 2026, 03:44

Operation Economic Outcast

The U.S. Department of the Treasury has launched Operation Economic Outcast, a whole-of-government campaign aimed at disrupting the economic networks and revenue channels supporting the Iranian regime and the Islamic Revolutionary Guard Corps (IRGC). The initiative expands Iran sanctions across digital assets, technology, gold, aviation and shipping, while targeting nearly 60 entities, individuals and vessels across multiple jurisdictions. Treasury said the campaign follows direction from President Trump and is intended to systematically target financial channels used for oil smuggling, sanctions evasion and other activities linked to Iran.

Operation Economic Outcast Expands Iran Sanctions

Under Operation Economic Outcast, the Office of Foreign Assets Control (OFAC) issued five sectoral sanctions determinations covering digital assets, technology, gold, aviation and shipping. Treasury said the measures increase its ability to sanction foreign persons operating in or providing services to these sectors of the Iranian economy. The department said Iran has increasingly used cryptocurrency for sanctions evasion, while advanced technology has been sought for weapons programs. Gold has also been used to stabilize the rial, while aviation and shipping networks have been linked to the movement of fighters, weapons, sensitive technologies, oil and other assets. The new determinations build on earlier measures covering Iran’s financial, petroleum and petrochemical sectors.

OFAC Sanctions Nearly 60 Iran-Linked Targets

OFAC also sanctioned nearly 60 entities, individuals and vessels across networks associated with nuclear and missile technology procurement, cyber operations and oil revenue generation. The action includes a procurement network spanning the Middle East and East Asia that Treasury said helped Iranian entities obtain sensitive dual-use technology through front companies, financial channels and logistics intermediaries. Treasury also targeted a malicious cyber group directed by Iran’s Ministry of Intelligence and Security (MOIS). The department said members of the group compromised and exfiltrated data from U.S. companies in critical infrastructure sectors, including energy, healthcare, defense, information technology and financial services. The designations also include Iranian cyber actors accused of network compromises and digital asset theft. Treasury said one individual illicitly gained control of a Bitcoin wallet containing more than $30,000 in 2023.

Secondary Sanctions Risk Expands

The campaign also increases secondary sanctions exposure for entities that continue conducting certain business with the Iranian regime. Treasury said countries are being given timelines to address identified Iran-related activity, while entities facilitating money laundering or sanctions evasion could face restrictions involving the U.S. financial system. OFAC also suspended several general licenses that previously authorized certain remittance payments to Iran and Iranian access to parts of the U.S. cultural and academic system.

Iran’s Shadow Fleet and Oil Networks Targeted

A major component of the measures focuses on Iran’s shadow fleet and oil revenue channels. Treasury sanctioned brokers, companies, and vessels involved in transporting Iranian crude oil and petroleum products across multiple jurisdictions. The department identified shipping networks involving the UAE, Hong Kong, China, Singapore, Switzerland, Europe, and other regions. Several UAE-based entities and individuals were designated over alleged roles in facilitating Iranian oil shipments and cryptocurrency payments. OFAC also targeted five vessels identified as blocked property, including SIFRA, G SILVER, QUANTUM HOPE, VOYAGE ELITE and TELA. Treasury said these vessels had transported Iranian LPG, petroleum products or crude oil to markets in Asia. The measures mean that property and interests in property belonging to designated or blocked persons that are in the United States or under the control of U.S. persons are blocked and must be reported to OFAC. Treasury said violations of U.S. sanctions can result in civil or criminal penalties, while certain transactions involving designated persons may also expose foreign financial institutions to secondary sanctions.
  • ✇Firewall Daily – The Cyber Express
  • Cyberattack Hits Ukraine Agency Ahead of Major Asset Tender Samiksha Jain
    A suspected ARMA cyberattack has targeted Ukraine's Asset Recovery and Management Agency as it prepares to select a manager for assets linked to IDS Ukraine. ARMA said its servers experienced unauthorized interference ahead of the August 22 deadline for applications, prompting an investigation into whether the incident was part of a broader effort to disrupt its operations. The Asset Recovery and Management Agency, known as ARMA, manages assets seized by Ukrainian authorities, including asset
     

Cyberattack Hits Ukraine Agency Ahead of Major Asset Tender

19 de Agosto de 2026, 02:33

ARMA Cyberattack

A suspected ARMA cyberattack has targeted Ukraine's Asset Recovery and Management Agency as it prepares to select a manager for assets linked to IDS Ukraine. ARMA said its servers experienced unauthorized interference ahead of the August 22 deadline for applications, prompting an investigation into whether the incident was part of a broader effort to disrupt its operations. The Asset Recovery and Management Agency, known as ARMA, manages assets seized by Ukrainian authorities, including assets linked to sanctioned Russian individuals and alleged collaborators with Moscow.

ARMA Cyberattack Raises Questions Over IDS Ukraine Competition

ARMA said the attack occurred shortly before the August 22 deadline for applications to participate in the competition to select a manager for assets controlled by sanctioned Russian oligarch Mikhail Fridman. The agency said its experts and law enforcement authorities are examining the cyberattack and the events surrounding the IDS Ukraine competition. The Security Service of Ukraine, or SBU, is investigating the recent attack, while a broader National Anti-Corruption Bureau of Ukraine, or NABU, investigation is examining earlier alleged interference. According to ARMA, signs of illegal interference in processes connected to its work have been recorded since spring. These included unauthorized access to the agency's officials' register. ARMA said the combination of cyber incidents, information activity and increased inquiries from some media outlets and members of parliament had raised concerns about a possible coordinated campaign. The agency said investigators must determine whether these events were intended to disrupt its work, create pressure or affect the competition. ARMA has not identified those it believes may have organized or carried out the alleged campaign.

IDS Ukraine Selection Continues Despite Cyberattack

Despite the incident, ARMA said the competition to select the IDS Ukraine asset manager will proceed according to the procedures and timeframe established by law. The deadline for applications is August 22, 2026, with the competition announcement published through Ukraine's Prozorro public procurement system. The agency said it has also started an audit of the financial indicators of seized IDS group assets to support the legality, objectivity and transparency of the transfer process. ARMA said additional information concerning possible unauthorized access to officials' email accounts and official information will be provided to law enforcement authorities for investigation and legal assessment. Acting ARMA Head Yaroslava Maksymenko said the agency would continue the competition despite what it described as information pressure, political interference and attempts to gain unauthorized access to its resources.

Ukraine Investigates Possible Coordinated Interference

ARMA said the latest incident is not being viewed in isolation. The agency pointed to a similar episode earlier this year, when Reuters reported on a cyberattack involving attempts at interference and hacking alongside increased information activity and inquiries. The agency said each event could have an individual explanation, but their timing and combination warranted further investigation. The cyberattack comes as Ukraine continues efforts to prevent sanctioned Russian capital from retaining control over assets seized in the country. ARMA said this includes preventing control through management arrangements, intermediaries or influence groups. Fridman has been sanctioned by Ukraine and several Western governments since Russia's invasion. ARMA said the final responsibility for determining the organizers, customers and perpetrators of the attack rests with the ongoing investigations. The agency said it will continue the IDS Ukraine competition and act within the law while law enforcement agencies examine the reported cyber incidents and possible attempts to interfere with its activities.
  • ✇Firewall Daily – The Cyber Express
  • 678,000 People Hit in French Tax Authority Data Breach Samiksha Jain
    A DGFiP cyberattack has exposed sensitive tax and cadastral information after attackers allegedly used stolen credentials to access systems belonging to France's Directorate General of Public Finances. The French Public Finances Directorate said investigations found that data linked to 678,000 individuals and professionals had been consulted and extracted during intrusions in June and July 2026. The DGFiP cyberattack incidents were identified after a malicious actor claimed illegitimate acces
     

678,000 People Hit in French Tax Authority Data Breach

18 de Agosto de 2026, 03:57

DGFiP cyberattack

A DGFiP cyberattack has exposed sensitive tax and cadastral information after attackers allegedly used stolen credentials to access systems belonging to France's Directorate General of Public Finances. The French Public Finances Directorate said investigations found that data linked to 678,000 individuals and professionals had been consulted and extracted during intrusions in June and July 2026. The DGFiP cyberattack incidents were identified after a malicious actor claimed illegitimate access to the French tax authority's information system on August 12 and 13. DGFiP said the intrusions involved the usurpation of identifiers belonging to a DGFiP agent and an authorized third party.

DGFiP Cyberattack Exposed Taxpayer Information

After detecting the intrusions, DGFiP immediately suspended access to the accounts involved. Initial access controls did not identify data theft, which the authority attributed to the sophistication of the attack. A subsequent investigation established that the compromised access points had been used to consult and extract information concerning 678,000 individuals and professionals. The exposed information included reference tax income, family quotient and withholding tax rate for individuals. For businesses, the accessed information included company names and SIREN numbers. Cadastral data, including addresses and property sizes, was also accessed. DGFiP said online accounts belonging to individual and professional users were not compromised, and user IDs and passwords were not affected. The authority notified France's data protection regulator, CNIL, after identifying the data breaches.

Cadastral Data Leak Claim Targets DGFiP

Separately, a hacker using the alias ZeroBytes claimed an attack against DGFiP's Professional Cadastral Data Server (SPDC). According to the claim cited by FrenchBreaches, the alleged extraction contains 252,149 lines of data representing 2,041,778 people, with multiple holders potentially associated with the same property plot. The claimed dataset reportedly includes names, surnames, sex, dates and places of birth, addresses, land identifiers, cadastral sections and parcel numbers, as well as information about rights held on properties. The claim would therefore link individuals to personal information and real estate assets. However, the figures and technical details in this second claim remain allegations by the cybercriminal. The claim that the system could contain information relating to approximately 20 million citizens is also an estimate made by ZeroBytes and does not establish that this number of people was affected.

Investigation Into French Tax Authority Attack Continues

DGFiP said additional security measures were implemented after investigators uncovered new information. These included preventative shutdowns of access to sensitive information systems. Investigations remain underway to determine the precise nature and volume of data extracted and the number of users affected. DGFiP teams are working with France's economic and financial ministries, the High Official for Defence and Security and the National Agency for Information Systems Security, ANSSI. The authority said it will contact affected individuals and professionals directly from the following week by email or letter. Those notifications will identify the information that may have been accessed or extracted and outline any precautionary measures where applicable. DGFiP also said it will file a complaint and provide further information as the investigation progresses. The separate cadastral data breach claim remains subject to confirmation, including the alleged number of affected people, duration of access, methods used to bypass authentication, the full scope of extracted information and whether access remained active when the claim was published. The confirmed DGFiP investigation and the separate ZeroBytes claim therefore present different sets of figures and allegations, with the full scope of the incidents still being determined.

The Cyber Express Weekly Roundup: Corporate Cyberattacks, AI Security Risks, Zero-Days, and Data Theft

14 de Agosto de 2026, 08:20

weekly roundup The Cyber Express cybersecurity 2026

This weekly roundup highlights the expanding range of threats facing businesses, technology platforms, and individuals. From social engineering attacks against corporate systems and vulnerabilities uncovered by AI agents to large-scale software patches and cyberattacks disrupting logistics operations, recent incidents demonstrate how quickly the threat landscape is evolving.  The latest developments also show that cybersecurity risks are no longer limited to traditional malware or ransomware. Attackers are increasingly exploiting human behavior, software weaknesses, interconnected supply chains, and personal online accounts. At the same time, artificial intelligence is emerging as both a defensive tool and a new way to identify security weaknesses. 

The Cyber Express Weekly Roundup 

Levi Strauss Targeted in Cyberattack, Corporate Files Accessed 

Levi Strauss & Co. disclosed a cybersecurity incident after attackers used social engineering techniques to gain access to three company-issued computers. The company believes certain corporate files were accessed and some information may have been exfiltrated. Levi Strauss said it moved quickly to contain the incident and terminate the unauthorized access, limiting the potential impact of the attack. Read more...

AI Agent Exploits Gym Booking Vulnerability 

An AI-powered agent reportedly identified an authentication weakness in an Australian gym’s online booking system. The agent, powered by Anthropic’s Claude and operated through OpenClaw, was originally instructed to help a user book a popular class. During the process, it was able to reserve classes months ahead and cancel another customer's booking. Read more...

AI Will Automate Cybersecurity Toil, Not Replace Security Professionals 

Harsha Reddy, Head of Information Security at Veterinary Emergency Group, argues that artificial intelligence is more likely to transform cybersecurity work than eliminate cybersecurity jobs. AI can assist with repetitive activities such as reviewing logs, triaging alerts, and collecting evidence, allowing security professionals to concentrate on investigation, strategy, and higher-value defensive operations. Read more...

Microsoft Fixes More Than 400 Security Flaws 

Microsoft’s August 2026 Patch Tuesday addresses roughly 400 vulnerabilities across its products, including three zero-days. One of the vulnerabilities was reportedly being actively exploited, while two others had been publicly disclosed before patches became available. The update includes 42 critical vulnerabilities, with 37 associated with remote code execution, reinforcing the importance of timely patching across enterprise environments. Read more...

CEVA Logistics Cyberattack Disrupts European Operations 

A cyberattack against CEVA Logistics disrupted activity at eight European warehouses on July 29, affecting shipments and exposing customer data connected to several major clients. The logistics company, part of the CMA CGM Group, has not publicly identified the attackers or provided detailed information about the technical nature of the incident. Read more...

FBI Warns of Theft of Explicit Content From Social Media 

The FBI has warned that cybercriminals are targeting social media and personal accounts to steal explicit images and videos, including non-consensual intimate images. Stolen material may subsequently be distributed or sold online, while associated personal information can expose victims to harassment, stalking, and sextortion. Read more...

Weekly Cybersecurity Takeaway 

This week’s incidents demonstrate that cybersecurity risks are expanding across corporate networks, software ecosystems, supply chains, AI-powered systems, and personal accounts.  Organizations should prioritize strong authentication, rapid vulnerability patching, employee awareness, third-party risk management, and continuous monitoring. At the same time, responsible use of AI could help security teams reduce repetitive workloads and respond more effectively to emerging threats.  As attackers continue finding new ways to exploit technology and human trust, organizations and individuals must strengthen security controls while remaining prepared for threats that increasingly cross traditional digital boundaries. 

💾

Enjoy the videos and music you love, upload original content, and share it all with friends, family, and the world on YouTube.

The Cyber Express Weekly Roundup: AI Fraud, Data Leaks, Malware Campaigns, and Critical Infrastructure Threats

The Cyber Express weekly Roundup July 2026 new

This weekly roundup highlights the growing complexity of digital threats affecting governments, businesses, developers, and consumers. From artificial intelligence being misused for financial fraud to large-scale customer data exposures, malicious software targeting developer ecosystems, and cyberattacks against critical infrastructure, recent incidents demonstrate how attackers are exploiting both emerging technologies and existing security weaknesses.  The latest developments show that cyber risks are expanding beyond traditional network attacks. Threat actors are targeting identities, trusted platforms, software supply chains, and operational technology environments. Organizations must strengthen security controls, improve monitoring capabilities, and adopt proactive measures to protect sensitive data and critical services. 

The Cyber Express Weekly Roundup 

Four Men Admit to $2.2 Million Medicaid Fraud Scheme Using AI 

Four Minnesota men have pleaded guilty in connection with a Medicaid fraud scheme that allegedly generated approximately $2.2 million through fraudulent claims for housing-related services. Prosecutors stated that artificial intelligence tools, including ChatGPT, were used to create false documentation supporting fraudulent billing activity. Read more... 

Tribeca Data Leak Exposes Celebrity-Linked Information 

A reported data leak connected to the Tribeca Film Festival exposed nearly 666,000 records containing personal information associated with attendees, contacts, and individuals linked to the entertainment industry. The exposed data reportedly included names, email addresses, phone numbers, and limited device-related information. Read more... 

Origin Energy Data Breach Impacts Around 900,000 Customers 

Australian energy company Origin Energy confirmed a data breach affecting approximately 900,000 current and former customers. The exposed information may include customer names, contact details, dates of birth, and partial account information. The company is investigating the incident and has advised customers to remain alert for possible scams or suspicious communications. Read more... 

Joyfill npm Packages Found Distributing DEV#POPPER Malware 

Security researchers discovered that two beta versions of Joyfill npm packages were distributing DEV#POPPER, a remote access trojan (RAT) capable of stealing information, executing commands, and compromising developer environments. Read more... 

Student Accused of IIT Website Breaches Offered Technical Assessment 

A student accused of breaching parts of the IIT Kanpur and IIT Madras websites after being rejected from IIT Kanpur’s cybersecurity program will undergo a technical skills assessment rather than facing immediate legal action. The institute stated that admissions for the current session are closed but indicated that future opportunities may be considered if the student demonstrates strong cybersecurity abilities. Read more... 

FBI Warns of PLC Cyberattacks Targeting U.S. Water Utilities 

The FBI and the U.S. Environmental Protection Agency warned that cyberattacks targeting internet-connected programmable logic controllers (PLCs) have disrupted water utilities across multiple U.S. states. Attackers reportedly manipulated PLC settings, affecting monitoring and operational processes. Read more... 

Weekly Cybersecurity Takeaway

This week’s incidents demonstrate how cyber threats continue to evolve across multiple domains, including artificial intelligence abuse, personal data exposure, software supply chain attacks, and critical infrastructure targeting.  A common theme across these events is the exploitation of trust. Attackers are abusing trusted technologies, legitimate software ecosystems, customer databases, and connected infrastructure to achieve their objectives.  Organizations must focus on building cyber resilience through stronger identity protection, secure development practices, continuous monitoring, and effective incident response planning.  As emerging technologies such as artificial intelligence and connected industrial systems become more widespread, cybersecurity strategies must evolve alongside them. Protecting digital assets requires not only stronger technical defenses but also responsible for technology use, awareness, and proactive risk management. 
  • ✇Firewall Daily – The Cyber Express
  • Student Hacks IIT Kanpur Website After Rejection, Gets Technical Assessment Ashish Khaitan
    The IIT Kanpur Website Hack has taken an unexpected turn after the institute decided to assess the technical skills of a student who allegedly breached parts of the IIT Kanpur and IIT Madras websites following his rejection from the newly launched undergraduate cybersecurity program. Instead of immediately pursuing legal action, IIT Kanpur said it would conduct a formal technical evaluation, though admission for the current academic session remains closed. The incident of IIT Kanpur website h
     

Student Hacks IIT Kanpur Website After Rejection, Gets Technical Assessment

IIT Kanpur Website Hack

The IIT Kanpur Website Hack has taken an unexpected turn after the institute decided to assess the technical skills of a student who allegedly breached parts of the IIT Kanpur and IIT Madras websites following his rejection from the newly launched undergraduate cybersecurity program. Instead of immediately pursuing legal action, IIT Kanpur said it would conduct a formal technical evaluation, though admission for the current academic session remains closed. The incident of IIT Kanpur website hack came to light after the student shared posts on X and Reddit, claiming he had breached sections of the IIT Kanpur and IIT Madras websites after being rejected from the newly launched undergraduate cybersecurity program.

IIT Kanpur Website Hack Prompts Technical Skills Assessment

Along with screenshots of the alleged breach, he stated that his objective was not to damage the institutions but to prove his capabilities. The student also left a message on the IIT Kanpur website that read, "Site is hacked. All I need is just a fair chance." In his social media posts, he said he had completed the admission process by paying the required fees, submitting application forms and documents, and providing evidence of his work in cybersecurity. However, he claimed he was not shortlisted for the hackathon, a key stage in the admission process for the IIT Kanpur cybersecurity program.

IIT Kanpur Offers Technical Assessment Instead of Legal Action 

Speaking to PTI, IIT Kanpur Director Manindra Agrawal confirmed that the student had gained access to certain portions of the IIT Kanpur website. He explained that the applicant was not shortlisted because he lacked prior cybersecurity experience.  "The admission process for this academic session has already concluded, so admission is not possible now. However, we will invite the student to the institute, assess his technical skills through a proper test and, if he proves his competence, give him an opportunity in the next admission cycle," Agrawal said.  Agrawal also confirmed that the student had accessed parts of both the IIT Kanpur and IIT Madras websites. He added that senior faculty members and engineers would meet the student to explain that unauthorized access to computer systems is illegal and should not be repeated. 

IIT Kanpur Had Initially Considered Filing an FIR 

According to another institute official, IIT Kanpur initially considered filing a First Information Report (FIR) over the breach. However, before taking any legal action, the institute decided to verify the student's claims and independently assess his technical abilities. The official, who spoke on the condition of anonymity, said IIT Kanpur has previously recognised young cybersecurity talent. Earlier this year, the institute offered a position at its C3iHub to a youth who identified vulnerabilities in the CBSE online screen-marking portal. While the student's actions have raised legal and ethical concerns for both IIT Kanpur and IIT Madras, the authorities have opted to focus on evaluating his skills through a structured assessment rather than immediately pursuing criminal proceedings. Although he cannot join the current cybersecurity program, a successful technical evaluation could allow him to be considered during the next admission cycle. 
  • ✇Firewall Daily – The Cyber Express
  • US Seizes 1,000+ Domains Used to Illegally Stream FIFA World Cup Samiksha Jain
    The U.S. Department of Justice has seized more than 1,000 illegal World Cup streaming domains accused of broadcasting FIFA World Cup 2026 matches without authorization, marking a major enforcement action against digital piracy during the tournament. The domains were seized in three separate actions under U.S. copyright law as part of Operation Offsides, an initiative targeting websites involved in unauthorized World Cup broadcasts. The latest action includes nearly 400 websites seized by the en
     

US Seizes 1,000+ Domains Used to Illegally Stream FIFA World Cup

illegal World Cup streaming domains

The U.S. Department of Justice has seized more than 1,000 illegal World Cup streaming domains accused of broadcasting FIFA World Cup 2026 matches without authorization, marking a major enforcement action against digital piracy during the tournament. The domains were seized in three separate actions under U.S. copyright law as part of Operation Offsides, an initiative targeting websites involved in unauthorized World Cup broadcasts.

The latest action includes nearly 400 websites seized by the end of June, according to the Department of Justice. The investigation was carried out by U.S. Immigration and Customs Enforcement Homeland Security Investigations (HSI) Washington Field Office and the National Intellectual Property Rights Coordination Center.

Illegal World Cup Streaming Domains Targeted

According to an affidavit filed in support of a seizure warrant in the U.S. District Court for the Eastern District of Virginia, the seized domains were used to offer copyright-protected content through real-time streams of 2026 World Cup matches as they were being played and first broadcast.

HSI special agents confirmed that the domains were actively broadcasting World Cup matches without authorization. The domains were identified with assistance from FIFA, with additional information provided by beIN Media Group, NBC Universal, the Motion Picture Association’s Alliance for Creativity and Entertainment (ACE), Ultimate Fighting Championship (UFC), and Warner Brothers.

FIFA holds the exclusive rights to sanction and stage the FIFA World Cup 2026, which is being hosted across multiple cities in the United States, Canada and Mexico.

Operation Offsides Targets Illegal Streaming

The U.S. action is part of Operation Offsides, which focuses on identifying and seizing websites facilitating unauthorized broadcasts of World Cup matches.

The operation is led by the National Intellectual Property Rights Coordination Center and is being conducted with HSI Washington, D.C., HSI Attaché offices, private sector organizations and law enforcement partners globally.

Assistant Attorney General A. Tysen Duva of the Justice Department’s Criminal Division said the effort to seize more than 1,000 domains was aimed at protecting intellectual property rights and reducing risks to consumers from malicious software associated with some illicit streaming services.

[caption id="attachment_113257" align="aligncenter" width="400"]illegal World Cup streaming domains Source: The U.S. Department of Justice[/caption]

HSI Deputy Executive Associate Director Matthew Millhollin also warned that users accessing unauthorized streaming platforms could face risks including malware and payment information theft.

Operation Red Card Expands Global Crackdown

The U.S. enforcement action was accompanied by international efforts under Operation Red Card, which targeted digital piracy and counterfeiting connected to the World Cup across the Western Hemisphere.

The Justice Department’s International Computer Hacking and Intellectual Property (ICHIP) program coordinated enforcement efforts involving Argentina, Brazil, Chile, Colombia, the Dominican Republic, Ecuador, Paraguay and Peru.

The coordinated actions resulted in hundreds of illegal streaming sites being blocked, including 14 in Argentina, 223 in Ecuador, 28 in Peru, 309 in Brazil, 256 in the Dominican Republic and 1,140 in Colombia.

Colombian authorities also conducted 13 nationwide search-and-seizure operations targeting counterfeit sports apparel, resulting in 11 arrests and convictions.

Cybercrime Group Arrested in Colombia

On July 10, authorities launched Phase II of Operation Red Card in Colombia, conducting simultaneous operations in Bogotá, Soacha, Maríalabaja, Manatí and Sincerín.

An ICHIP-mentored cybercrime prosecutorial team from the Colombian Attorney General’s Office arrested four members of the cybercriminal group Los Ciberinfiltrados. According to the Justice Department, the group had illegally accessed telecommunications systems since 2024 and sold pirated streaming content, including World Cup matches.

The group allegedly used fraudulent credentials, VPNs, interception of security codes and manipulation of corporate system profiles to distribute the pirated content.

In Europe, ICHIP Bucharest also coordinated with Europol and international counterparts to address illegal streaming activities during the World Cup.

World Cup Streaming Crackdown Intensifies

The latest action follows a June 2026 announcement by the U.S. Department of Justice involving the seizure of nearly 400 websites accused of illegally broadcasting FIFA World Cup 2026 matches.

That earlier enforcement action, also conducted under Operation Offsides, targeted websites accused of copyright infringement by offering unauthorized live streams of World Cup matches for profit.

With more than 1,000 domains now seized in the U.S. actions, authorities continue to target unauthorized streaming platforms and digital piracy networks linked to the tournament.

  • ✇Firewall Daily – The Cyber Express
  • Hackers Deface Kenya President William Ruto’s Website, Demand $330K Ransom Samiksha Jain
    Kenya is investigating a Kenya cyberattack that temporarily defaced President William Ruto’s official website with an anti-government message and a Bitcoin ransom demand for five bitcoins, reportedly worth about $330,000. The attackers replaced the website’s homepage with the message, displayed a cryptocurrency wallet address and threatened to publish unspecified information about President William Ruto unless the ransom was paid. The website was hacked on Saturday, July 18, 2026. Following the
     

Hackers Deface Kenya President William Ruto’s Website, Demand $330K Ransom

Kenya Cyberattack Defaces Ruto Website

Kenya is investigating a Kenya cyberattack that temporarily defaced President William Ruto’s official website with an anti-government message and a Bitcoin ransom demand for five bitcoins, reportedly worth about $330,000. The attackers replaced the website’s homepage with the message, displayed a cryptocurrency wallet address and threatened to publish unspecified information about President William Ruto unless the ransom was paid.

The website was hacked on Saturday, July 18, 2026. Following the incident, access to the presidential website was temporarily restricted as authorities began containment, forensic analysis and restoration efforts. According to local media reports, access to the website was restored by Monday.

Kenya Cyberattack Prompts Incident Response

Kenya’s Ministry of Information, Communications and the Digital Economy confirmed that the official website of the President had been affected by a cybersecurity incident.

The ministry said that after the incident was detected, the ICT Authority immediately activated established cybersecurity incident response protocols.

As a precautionary measure, access to the presidential website was temporarily restricted to facilitate containment, forensic analysis and restoration efforts.

The ministry said appropriate mitigation measures had since been implemented and that restoration of the website was underway.

[caption id="attachment_113245" align="aligncenter" width="600"]Kenya cyberattack Source: Kenya’s Ministry of Information, Communications and the Digital Economy[/caption]

At the time of the statement, the government said there was no evidence of unauthorized access to sensitive data, data exfiltration or loss of information. It also stated that government systems and digital services remained secure and operational.

The ICT Authority is working with relevant government agencies and technical partners to conduct a comprehensive forensic investigation and establish the full circumstances surrounding the incident.

Kenya President William Ruto Cyberattack Investigation

The Kenya President William Ruto cyberattack involved the defacement of the president’s official website. The attackers replaced the homepage with an anti-government message, displayed a cryptocurrency wallet address and demanded five bitcoins.

The attackers also threatened to publish unspecified information about President William Ruto if the ransom was not paid.

The government has not reported evidence of unauthorized access to sensitive data or data exfiltration. The ongoing forensic investigation is expected to establish the circumstances surrounding the incident and determine the extent of the attack.

Kenya Government Website Hack Follows Earlier Incidents

The latest Kenya government website hack follows previous cyber incidents involving government digital services and websites.

In July 2023, Kenya’s eCitizen platform, which is used for dozens of public services, was disrupted by a cyberattack. The incident affected agencies including the National Transport and Safety Authority and Kenya Power.

On November 17, 2025, hackers launched a coordinated attack on several government websites, including the presidency’s portal. The websites were temporarily knocked offline, while some pages were replaced with extremist messages.

According to the information provided by local media, the government later blamed a group calling itself PCP@Kenya, restored the affected platforms and promised stronger cyber defences.

Bitcoin Ransom Demand Targets Presidential Website

The latest incident involved a Bitcoin ransom demand for five bitcoins, reportedly valued at approximately $330,000. The attackers displayed a cryptocurrency wallet address and threatened to release unspecified information about the president.

It remains unclear from the available information whether the attackers accessed systems or data beyond the presidential website. The Kenyan government has said there is currently no evidence of unauthorized access to sensitive data, data exfiltration or loss of information.

The ICT Authority and relevant government agencies are continuing their forensic investigation to establish how the incident occurred and determine the full circumstances surrounding the Kenya cyberattack.

  • ✇Firewall Daily – The Cyber Express
  • Japan’s Aflac, KDDI, Sapporo, Nidec: Four Breaches, One Common Entry Point Samiksha Jain
    Four major Japan cyberattacks reported within two weeks point to a common trend, with attackers gaining access through subsidiaries and third-party infrastructure rather than corporate headquarters. While the incidents affected companies from different industries, including insurance, telecommunications, brewing, and manufacturing, the breaches shared one notable characteristic. Rather than directly compromising corporate headquarters, attackers gained access through subsidiaries, overseas oper
     

Japan’s Aflac, KDDI, Sapporo, Nidec: Four Breaches, One Common Entry Point

Japan cyberattacks

Four major Japan cyberattacks reported within two weeks point to a common trend, with attackers gaining access through subsidiaries and third-party infrastructure rather than corporate headquarters. While the incidents affected companies from different industries, including insurance, telecommunications, brewing, and manufacturing, the breaches shared one notable characteristic.

Rather than directly compromising corporate headquarters, attackers gained access through subsidiaries, overseas operations, or third-party infrastructure.

The affected organizations include Aflac Japan, KDDI, Sapporo Holdings, and Nidec, each of which reported separate cyber incidents during the second half of June 2026. Although the attacks involved different circumstances, the disclosures point to an expanding attack surface that extends well beyond an organization's primary network.

Aflac Japan Breach Exposed Customer Data

Aflac Japan disclosed on June 30 that attackers accessed its Japanese operations between June 15 and June 25. According to the company, approximately 4.38 million customers and agents were affected, with a subset of records including bank account information used for insurance premium payments.

The insurer stated that the incident was limited to its Japanese business and did not affect its U.S. operations.

While the company has not attributed the attack to any specific threat group, the reported tactics resemble social engineering techniques previously associated with Scattered Spider.

KDDI Incident Impacts Millions Through Shared Platform

Telecommunications provider KDDI reported unauthorized access involving an email platform used by multiple Japanese internet service providers.

The company said the incident stemmed from a vulnerability in third-party software, potentially exposing up to 14.22 million email account records across six ISPs.

The breach demonstrates how a single vulnerability within shared infrastructure can affect multiple organizations simultaneously.

Sapporo Holdings and Nidec Target Overseas Subsidiaries

Sapporo Holdings disclosed suspected unauthorized access involving two overseas subsidiaries, Singapore-based Pokka and Canadian brewer Sleeman. The company detected suspicious activity, shut down affected systems, and launched an investigation to determine whether any information had been accessed or stolen.

Meanwhile, manufacturing company Nidec confirmed a ransomware attack targeting its Taiwanese subsidiary, Nidec Chaun Choung Technology.

The BlackField ransomware group claimed responsibility for the attack, alleging it had stolen more than two terabytes of company data, including employee, financial, procurement, manufacturing, legal, and IT records. The group reportedly demanded a $2 million ransom.

A Shared Pattern Across the Japan Cyberattacks

Despite involving different industries and attack methods, the four Japan cyberattacks reveal a similar point of compromise.

Aflac's breach was limited to its Japanese business. KDDI's exposure originated from a shared email platform relying on vulnerable third-party software. Sapporo's investigation centers on overseas subsidiaries, while Nidec's ransomware incident affected its Taiwan-based operation rather than its headquarters.

These cases suggest attackers are increasingly targeting subsidiaries, shared services, overseas business units, and technology partners instead of attempting to breach an organization's primary corporate network.

Growing Risks Across the Extended Enterprise

The incidents highlight the importance of treating subsidiaries and external partners as part of the organization's overall security perimeter.

Organizations that rely on overseas offices, acquired businesses, vendors, or shared platforms may inherit additional cybersecurity risks if those environments are not protected to the same standard as corporate headquarters.

The KDDI incident illustrates how third-party dependencies can significantly increase the scale of a breach, while the Nidec cyberattack demonstrates how ransomware groups continue to combine data theft with extortion demands.

The reported tactics observed in the Aflac incident also reinforce the continued effectiveness of social engineering as an initial access method.

While investigations into several of the incidents remain ongoing, the recent disclosures underscore a broader trend. As enterprise environments become increasingly interconnected, subsidiaries, shared infrastructure, and external technology providers are becoming attractive targets for attackers seeking indirect access to larger organizations.

  • ✇Firewall Daily – The Cyber Express
  • Ukraine Makes History With First $8.3M Seized Crypto Transfer to ARMA Samiksha Jain
    Ukraine has transferred Seized Crypto Assets worth more than 8.3 million USDT to the country's Asset Recovery and Management Agency (ARMA), marking the first time virtual assets have been placed under the agency's management following a court decision. The transfer follows an investigation led by the State Bureau of Investigation into an international hacking group accused of carrying out cyberattacks, extortion, and money laundering across Europe and the United States. Accordin
     

Ukraine Makes History With First $8.3M Seized Crypto Transfer to ARMA

Seized Crypto Assets

Ukraine has transferred Seized Crypto Assets worth more than 8.3 million USDT to the country's Asset Recovery and Management Agency (ARMA), marking the first time virtual assets have been placed under the agency's management following a court decision. The transfer follows an investigation led by the State Bureau of Investigation into an international hacking group accused of carrying out cyberattacks, extortion, and money laundering across Europe and the United States.

According to Ukrainian authorities, the transferred cryptocurrency is valued at more than 372 million hryvnias and represents a milestone in the country's efforts to manage digital assets linked to criminal investigations.

Seized Crypto Assets Moved to ARMA After Court Order

The State Bureau of Investigation said the transfer was completed as part of an ongoing criminal investigation conducted in cooperation with the DVB of the National Police and U.S. law enforcement agencies.

Investigators determined that the virtual assets were stored in crypto wallets controlled by a member of the organized hacking group. Following a court order, more than 8.3 million USDT was transferred to ARMA's official crypto wallet.

Authorities said this is the first practical case in Ukraine where seized digital assets have been transferred to ARMA for management, demonstrating the country's ability to handle new categories of assets within the legal system.

Investigation Links Cryptocurrency to International Hacking Group

According to investigators, members of the international hacking group carried out large-scale cyberattacks against individuals and companies in Europe and the United States.

The investigation alleges the group stole confidential information, demanded ransom payments, and laundered criminal proceeds in Ukraine through the purchase of residential properties, vehicles, and other high-value assets.

Authorities estimate that the criminal group's activities caused losses exceeding $100 million.

As part of the pre-trial investigation, four members of the group, including its alleged organizer, were detained and placed in custody.

More Than $11 Million in Assets Seized

The investigation resulted in the cryptocurrency seizure and the confiscation of additional assets with a combined value exceeding $11.1 million.

According to the State Bureau of Investigation, the seized property includes residential buildings, apartments, vehicles, approximately $1 million in cash, and digital assets equivalent to more than $8.3 million.

The Office of the Prosecutor General is providing procedural oversight for the criminal proceedings.

Authorities Plan to Convert Crypto Into Military Bonds

The State Bureau of Investigation said that after converting the cryptocurrency into fiat currency, authorities plan to purchase military bonds.

According to the agency, the initiative is intended to support Ukraine's economy during martial law while ensuring that assets obtained through criminal activity are redirected for state purposes.

Officials described countering transnational cybercrime and ensuring effective mechanisms for the seizure and management of criminal assets as key priorities.

ARMA Expands Digital Asset Management

ARMA said receiving the cryptocurrency marks an important step in the evolution of Ukraine's asset management system.

The agency stated that the successful transfer reflects coordinated efforts between the State Bureau of Investigation and the Office of the Prosecutor General, enabling the execution of the court's decision and preserving the value of the seized assets.

ARMA added that it is continuing to develop mechanisms for managing all categories of seized property, including real estate, corporate rights, and virtual assets, to ensure their preservation in the interests of the state and society.

The agency said the case demonstrates that as cybercriminals increasingly use digital technologies to conceal illicit proceeds, authorities must also strengthen their ability to manage and preserve cryptocurrency and other digital assets seized during criminal investigations.

The Cyber Express Weekly Roundup: Five Eyes AI Warning, KDDI Data Breach, Garfield AI Legal Milestone, and Iranian Hacker Arrest

The Cyber Express weekly roundup June 2026

This week’s weekly roundup of cybersecurity developments highlights a rapid shift in global cyber risk conditions driven by artificial intelligence acceleration, large-scale data breaches, and expanding international enforcement actions. Across infrastructure, enterprise systems, public services, and regulated AI applications, organizations are increasingly exposed to faster-moving threats where traditional security assumptions are being challenged by automation and long-term intrusion campaigns.  The overarching theme in this weekly roundup is the erosion of response time in modern cybersecurity environments. Intelligence agencies, law enforcement bodies, and private-sector disclosures collectively point to a landscape where attackers are leveraging AI-enabled capabilities, third-party system weaknesses, and identity compromise to gain persistence across networks. At the same time, regulators and courts are beginning to define new boundaries for both cybercrime accountability and the operational use of AI in sensitive domains. 

The Cyber Express Weekly Roundup 

Five Eyes Warn AI Is Rapidly Outdating Cyber Risk Models 

The Five Eyes cybersecurity agencies warn that artificial intelligence is accelerating cyber threats and making traditional cyber risk assumptions obsolete. Attackers are exploiting vulnerabilities faster, shrinking response windows, and increasing the speed and sophistication of attacks. In guidance issued on June 23, 2026, they urged organizations to treat cyber resilience as a leadership priority, strengthen identity and access controls, accelerate patching cycles, and reduce dependence on legacy systems. Read more… 

TfL Hackers Plead Guilty After £29M Cyberattack 

Two members of the Scattered Spider cybercrime group have pleaded guilty to roles in the Transport for London cyberattack that caused £29 million in losses, disrupted services, and exposed customer data. The 2024 breach affected Oyster systems and forced mass password resets across TfL’s workforce. Investigators also linked the suspects to other attempted intrusions targeting U.S. healthcare networks. Read more… 

KDDI Data Breach May Expose 14.22 Million Email Accounts 

KDDI has disclosed a cybersecurity incident that may have exposed up to 14.22 million email addresses and passwords through systems used by multiple Japanese internet service providers. The breach, detected on June 17, 2026, stemmed from unauthorized access to a third-party email system. KDDI said it has secured the affected environment, notified partners, and is working with regulators while urging users to reset passwords as a precaution. Read more… 

Garfield AI Wins Landmark UK Case as AI-Powered Law Firm 

Garfield AI, a UK-regulated AI-powered law firm, has secured a landmark legal victory after successfully managing a small claims case in England with minimal human intervention. The AI system handled pre-trial work, including drafting court documents and preparing evidence, in a dispute over an unpaid £7,000 invoice. The case was ultimately won at Wandsworth County Court, marking a notable milestone for the use of AI in regulated legal services, though human counsel still represented the claimant at trial. Read more… 

Iranian Hacker Arrested in Montenegro Over Alleged $3.4B Cyberattack Campaign 

An alleged Iranian hacker has been arrested in Montenegro following a joint operation with the FBI over a long-running cyber campaign targeting U.S. infrastructure. Authorities say the 39-year-old suspect is linked to attacks dating back to 2013, allegedly targeting more than 150 U.S. universities and causing over $3.4 billion in damages. He now faces extradition to the United States on charges including computer fraud, hacking, conspiracy, and identity theft, while investigations into Iran-linked cyber activity continue. Read more… 

Weekly Cybersecurity Takeaway 

This week’s weekly roundup reflects a cybersecurity environment increasingly defined by the speed of AI-driven threat evolution, the scale of third-party exposure, and the persistence of long-running cybercrime operations. From the Five Eyes warning that artificial intelligence is rapidly reshaping cyber risk assumptions to the KDDI breach that may have exposed 14.22 million email accounts, organizations are facing mounting pressure to modernize defenses while reducing dependence on outdated security models. 

The Cyber Express Weekly Roundup: Cybersecurity Weekly Round on Emerging Threats, Data Breaches, and Global Policy Shifts

weekly roundup TCE

This week’s weekly roundup of cybersecurity developments highlights an expanding intersection of cyber risk, regulatory action, and enterprise vulnerability. Across healthcare, technology platforms, gaming companies, and government policy, organizations continue to confront a rapidly evolving cybersecurity landscape where data exposure, advanced intrusion tactics, and platform security failures are interconnected.  The overarching theme in this weekly roundup is the growing strain on digital ecosystems as attackers refine stealth techniques while institutions attempt to secure distributed systems. From cloud-based email exploitation to AI-related enterprise vulnerabilities, this week’s cybersecurity incidents underscore the difficulty of maintaining visibility and control across modern infrastructure. 

The Cyber Express Weekly Roundup 

Novo Nordisk Security Incident Exposes Limited Patient and HCP Data 

Novo Nordisk reported an unauthorized intrusion into internal systems that resulted in the external copying of limited clinical trial data along with healthcare professional contact details. According to the disclosure, core operational systems were not disrupted during the incident, and the breach did not affect ongoing business continuity. Read more... 

UNC6508 Used Google Workspace Trick to Spy on U.S. Medical Research 

A threat group identified as UNC6508, linked to China, reportedly conducted a long-term espionage campaign targeting North American medical and research institutions. Over a period described as exceeding two years, attackers infiltrated research environments and accessed sensitive systems related to medical and defense-linked projects. Read more... 

Critical SearchLeak Flaw in Microsoft 365 Copilot Exposed Enterprise Data 

A newly addressed vulnerability, identified as CVE-2026-42824, affected Microsoft 365 Copilot and carried the potential for significant enterprise data exposure. Researchers found that a chain of weaknesses—including prompt injection, HTML rendering issues, and server-side request forgery—could be exploited to extract sensitive data. Read more... 

UK Plans Social Media Ban for Under-16s by 2027 

The United Kingdom has proposed a policy restricting social media access for users under the age of 16, with implementation potentially targeted for spring 2027. If enacted, the ban would apply to major platforms including TikTok, Instagram, Snapchat, Facebook, YouTube, and X. Read more... 

Operation Endgame Disrupts SocGholish Malware Network 

International law enforcement agencies, operating under “Operation Endgame,” dismantled significant parts of the SocGholish malware infrastructure. The operation resulted in the cleanup of nearly 15,000 compromised websites and the takedown of multiple servers associated with cybercriminal activity. Read more... 

Nintendo Confirms Limited Employee Data Exposed in TinyPulse Attack 

Nintendo confirmed that employee survey data was exposed following a cyberattack involving the third-party platform TinyPulse. The company clarified that its internal systems and customer-facing data were not impacted by the incident. Read more... 

Weekly Cybersecurity Takeaway 

This week’s weekly roundup reflects a cybersecurity environment increasingly shaped by cloud exploitation, AI-driven vulnerabilities, and cross-border espionage campaigns. From healthcare breaches like Novo Nordisk’s limited data exposure to long-running intrusions such as UNC6508’s email-forwarding operations, attackers continue to prioritize stealth and persistence over direct system disruption.  At the same time, critical vulnerabilities like the Microsoft 365 Copilot SearchLeak flaw demonstrate how AI integration is expanding enterprise risk surfaces. Meanwhile, enforcement actions under Operation Endgame and policy shifts such as the UK’s proposed under-16 social media restrictions show that both technical and regulatory responses are evolving in parallel. 
  • ✇Firewall Daily – The Cyber Express
  • Nintendo Confirms Employee Data Exposed in TinyPulse Cyberattack Ashish Khaitan
    Nintendo of America has confirmed that employee survey data was exposed in the recent TinyPulse cyberattack, although the company emphasized that its own systems were not breached and that no customer or financial information was accessed. The disclosure follows claims by the threat actor Shadowbyt3$, which alleged it had stolen sensitive information linked to Nintendo employees.  In a statement addressing the TinyPulse cyberattack, Nintendo said it was aware of an issue involving TinyPulse,
     

Nintendo Confirms Employee Data Exposed in TinyPulse Cyberattack

TinyPulse cyberattack

Nintendo of America has confirmed that employee survey data was exposed in the recent TinyPulse cyberattack, although the company emphasized that its own systems were not breached and that no customer or financial information was accessed. The disclosure follows claims by the threat actor Shadowbyt3$, which alleged it had stolen sensitive information linked to Nintendo employees.  In a statement addressing the TinyPulse cyberattack, Nintendo said it was aware of an issue involving TinyPulse, a third-party platform used for internal employee surveys. According to the company, the incident was limited to data held by the service provider rather than Nintendo's internal infrastructure.  “We are aware of an issue involving TinyPulse, a third-party service used for internal employee surveys at Nintendo of America,” Nintendo stated.  The company further clarified that “Nintendo’s systems have not been compromised, and no personal customer or financial data has been accessed.” 

Nintendo Says Exposure Was Limited in the TinyPulse Cyberattack

According to Nintendo, the data affected by the TinyPulse cyberattack consisted of internal survey content involving only a small subset of employees. The company added that most of the information dated back several years.  “The data involved is limited to internal survey content comprising a small subset of our employees, and most of the information dates back several years,” Nintendo told media outlets.  Nintendo of America, a subsidiary of the Japanese gaming giant Nintendo, oversees operations across the United States, Canada, and parts of Latin America. TinyPulse is an employee engagement and feedback platform that supports anonymous surveys, workplace culture assessments, engagement analytics, and feedback collection.  Nintendo said it is currently “working with the service provider to address the issue.”  The Cyber Express has also reached out to Nintendo for additional details regarding the TinyPulse cyberattack. However, no further statement had been received at the time of publication. 

Shadowbyt3$ Claims Broader Data Theft

Despite Nintendo's assessment of the incident, the threat actor Shadowbyt3$ has claimed that the stolen information extends beyond employee survey responses and includes personal employee data.  In an initial message, Shadowbyt3$ alleged that nearly 1GB of data had been exfiltrated from Nintendo and gave the company 48 hours to enter negotiations before the information would be leaked.  The threat actor claimed the dataset contains full names, email addresses, analytics and survey data, bank statements, W-9 forms with employee IDs, progress plans, and reports spanning from 2016 to 2026.  “If you contact us we give you an extra day to think this through. We are demanding a ransom payment of 2 million dollars,” the Shadowbyt3$ post stated. 

Threat Actor Issues Additional Warnings

In a follow-up message, Shadowbyt3$ clarified that the alleged breach “doesn't affect nintendo gaming” but instead impacts “a small amount of employees that work for nintendo and have used tinypulse.”  The threat actor later published another post warning that more victims would emerge. The message included a link to allegedly leaked data containing direct messages and employee conversations, suggesting Nintendo did not agree to pay the $2 million ransom demand.  As of now, Nintendo maintains that the TinyPulse cyberattack was limited in scope and did not compromise its internal systems, while Shadowbyt3$ continues to assert that more sensitive employee information was stolen. 

The Cyber Express Weekly Roundup: AI Security Controls, Major Patch Releases, Public Sector Audits, and Emerging Online Scams

TCE The Cyber Express Weekly Roundup

This week's cybersecurity developments highlight a growing emphasis on proactive security measures, governance oversight, and risk management across both public and private sectors. From large-scale vulnerability remediation efforts and AI security enhancements to government-led technology reviews and event-driven cybercrime campaigns, organizations continue to face a complex threat landscape.  A common theme across this week's stories is the balance between innovation and security. As institutions adopt AI-powered systems, expand digital services, and move critical operations online, security teams are being challenged to strengthen protections without slowing modernization efforts. At the same time, threat actors continue to capitalize on public-interest events and trusted digital platforms to conduct fraud and data-theft campaigns. 

The Cyber Express Weekly Roundup 

CBSE Re-Evaluation Portal Receives Final Security Clearance 

The Central Board of Secondary Education (CBSE) has completed the final cybersecurity review of its examiner-facing re-evaluation platform, clearing the way for the reassessment of Class 12 answer scripts. Following an IIT-led audit and security testing process, examiners can now access the system to process applications submitted by more than 70,000 students. Read more... 

OpenAI Expands Lockdown Mode Across ChatGPT Accounts 

OpenAI has extended its Lockdown Mode security feature to all personal ChatGPT users, including Free, Go, Plus, Pro, and self-service Business accounts. The feature is designed to reduce the risk of prompt injection-related data exposure by limiting access to high-risk capabilities such as live web browsing, Deep Research, Agent Mode, and external file interactions. Read more... 

UK Courts Explore AI-Powered Legal Assistance 

The UK government has announced plans to test AI legal assistants within Crown Courts as part of broader judicial modernization efforts. The tools are expected to assist with legal research, case review, scheduling, and administrative processes while remaining under human supervision. Read more... 

Microsoft Issues Largest Patch Tuesday Update on Record 

Microsoft's June 2026 Patch Tuesday addressed a record-breaking 200 security vulnerabilities across its product ecosystem, including Windows, Office, Azure, and Exchange. The release included fixes for three publicly disclosed zero-day vulnerabilities and dozens of critical flaws. Read more... 

ServiceNow Clarifies Nature of Recent Security Incident 

ServiceNow has provided additional details regarding a recently disclosed security vulnerability, stating that observed activity originated from security researchers and customer investigations rather than malicious attackers. The company released a security update to address the issue and emphasized that there is no evidence of customer data misuse. Read more... 

World Cup-Themed Scams Target Fans Ahead of FIFA 2026 

Cybercriminals are already leveraging interest in the FIFA World Cup 2026 to launch phishing campaigns, fake ticket sales, and fraudulent recruitment schemes. Security researchers and law enforcement agencies have identified numerous lookalike domains impersonating official FIFA services in an effort to steal personal and financial information. Read more... 

Weekly Cybersecurity Takeaway 

This week's developments demonstrate that cybersecurity is becoming a foundational requirement for digital transformation rather than a separate consideration. Whether securing AI platforms, protecting educational systems, modernizing public services, or managing enterprise vulnerabilities, organizations are being forced to address security challenges alongside innovation initiatives.  Meanwhile, threat actors continue to exploit trust, familiarity, and public interest to achieve their objectives. From phishing campaigns targeting global sporting events to attacks focused on cloud services and enterprise platforms, the most effective defenses remain strong security governance, timely patching, user awareness, and continuous monitoring of emerging risks. 

The Cyber Express Weekly Roundup: Cloud Extortion, Long-Term Espionage, Android Zero-Days, and Public Sector Security Reviews

weekly roundup TCE cybersecurity news

The cybersecurity landscape in this weekly roundup continues to show a clear shift toward identity-driven attacks, long-term persistence operations, and exploitation of trusted cloud environments. Threat actors are increasingly focusing on stealing credentials, abusing administrative access, and leveraging legitimate platforms to scale impact across organizations.  Rather than relying on one-off intrusions, attackers are now building sustained access paths into enterprise systems, enabling repeated exploitation, data theft, and extortion from within trusted environments. 

The Cyber Express Weekly Roundup

Pink Extortion Group Targets Microsoft 365 Users via Voice Phishing 

A newly identified cyber extortion group known as “Pink” is using voice phishing (vishing) campaigns to steal credentials for Microsoft 365 accounts. Once access is gained, the group rapidly exfiltrates data from cloud platforms such as SharePoint and OneDrive and sends extortion messages directly from compromised internal accounts to pressure victims. Read more… 

China-Linked VerdantBamboo Maintains 18-Month Network Access 

Researchers have uncovered an 18-month intrusion attributed to the China-linked threat group VerdantBamboo. The attackers maintained long-term access using compromised MSP credentials, multiple malware families, and repeated re-entry techniques after remediation attempts. Read more… 

DPDP and Cybersecurity: Why Less Data Means Better Security

India’s DPDP framework promotes data minimization as a key cybersecurity strategy. Organizations are urged to collect only necessary data, store it briefly, and delete unused information to reduce breach risk. Excess data increases attack surface and impact, making deletion as important as protection in modern security practices. Read more...

Google Patches Actively Exploited Android Zero-Day (CVE-2025-48595) 

Google’s June 2026 security update addresses 124 vulnerabilities in Android, including CVE-2025-48595, a high-severity zero-day that was actively exploited in targeted attacks. The flaw enables local privilege escalation without user interaction, underscoring the growing focus of sophisticated threat actors on mobile devices as high-value entry points. Read more… 

CBSE Launches Security Review of OSM Platform After Vulnerability Reports 

The Central Board of Secondary Education (CBSE) has engaged experts from the Indian Institute of Technology Madras and the Indian Institute of Technology Kanpur to review security concerns in its On-Screen Marking (OSM) system used for Class 12 board examinations. The audit follows reports of weak authentication controls and potential cloud storage exposure, prompting a full-scale security assessment and hardening exercise.  Read more… 

Weekly Cybersecurity Takeaway 

This week’s incidents reinforce a consistent pattern: attackers are prioritizing identity compromise and trusted cloud platforms over traditional perimeter breaches. From phishing-as-a-service extortion campaigns targeting Microsoft 365 to long-term espionage operations and mobile zero-days, the common thread is the abuse of legitimate access rather than forced intrusion.  As organizations continue to expand cloud and mobile reliance, the attack surface is increasingly defined not by infrastructure boundaries, but by identity trust and administrative privilege. 
  • ✇Firewall Daily – The Cyber Express
  • Threat Actors Target Critical Windows Netlogon Flaw CVE-2026-41089 Ashish Khaitan
    A critical Windows Netlogon vulnerability, tracked as CVE-2026-41089, has emerged as a significant security concern after authorities warned that threat actors are actively attempting to exploit the flaw to gain remote code execution capabilities on vulnerable systems.  The security issue, which carries a CVSS severity score of 9.8, was publicly disclosed on May 12, 2026, when Microsoft addressed it alongside 136 other vulnerabilities as part of its monthly Patch Tuesday security updates.
     

Threat Actors Target Critical Windows Netlogon Flaw CVE-2026-41089

CVE-2026-41089

A critical Windows Netlogon vulnerability, tracked as CVE-2026-41089, has emerged as a significant security concern after authorities warned that threat actors are actively attempting to exploit the flaw to gain remote code execution capabilities on vulnerable systems.  The security issue, which carries a CVSS severity score of 9.8, was publicly disclosed on May 12, 2026, when Microsoft addressed it alongside 136 other vulnerabilities as part of its monthly Patch Tuesday security updates. While several of the bugs fixed during that release were identified as likely candidates for exploitation, CVE-2026-41089 was not initially included among those expected to be targeted by attackers. 

Threat Actors Reportedly Exploiting CVE-2026-41089 

The Centre for Cybersecurity Belgium (CCB) issued a warning on Friday, stating that threat actors have begun exploiting the critical Windows Netlogon vulnerability in real-world attacks. The agency urged organizations to deploy available security updates immediately to reduce the risk of compromise.  According to the CCB, the flaw is “now actively exploited in the wild,” raising concerns that attackers may already be targeting unpatched systems. The organization noted that successful exploitation could allow remote attackers to execute arbitrary code with System-level privileges, providing extensive control over affected environments.  Despite the warning, no additional public reports have surfaced confirming exploitation attempts involving CVE-2026-41089. Furthermore, Microsoft has not updated its advisory to indicate that active attacks have been verified. 

How the Windows Netlogon Vulnerability Works 

Microsoft’s advisory describes CVE-2026-41089 as a stack-based buffer overflow vulnerability affecting the Netlogon service. The flaw can be triggered through specially crafted network requests sent to a Windows server operating as a domain controller.  Importantly, the vulnerability can be exploited by unauthenticated attackers, meaning no valid credentials or prior access to the targeted environment are required.  Microsoft explained the risk in its advisory, stating:  “If successful, this could cause the Netlogon service to improperly handle the request, potentially allowing the attacker to run code on the affected system without needing to sign in or have prior access.”  Because the flaw enables remote code execution and does not require authentication, security experts consider CVE-2026-41089 one of the more dangerous vulnerabilities addressed during the May 2026 Patch Tuesday release. 

Why the Netlogon Service Remains a High-Value Target 

The Netlogon service plays a critical role in Windows domain-based environments by handling authentication processes between users, computers, and domain controllers. As a core background service, it is essential to maintain secure communication and identity verification across enterprise networks.  Historically, weaknesses in Netlogon have attracted the attention of threat actors because successful exploitation can provide access to highly privileged systems. Critical flaws affecting the service can potentially allow attackers to gain control over a domain controller and, by extension, influence or compromise connected machines throughout the network.  Given the importance of the service, security professionals have long viewed any severe Windows Netlogon vulnerability as a high-priority issue requiring rapid remediation. Regardless of the differing assessments, security experts recommend that organizations prioritize patching CVE-2026-41089 as soon as possible.   The combination of its critical severity rating, the potential for unauthenticated remote code execution, and reports of activity by threat actors makes the vulnerability a significant risk for organizations operating Windows domain environments. 

The Cyber Express Weekly Roundup: Supply Chain Attacks, Mobile Banking Malware, and Expanding Cloud Phishing Campaigns

The Cyber Express weekly roundup TCE

The cybersecurity landscape in this weekly roundup shows how attackers are shifting away from isolated systems and focusing instead on the trusted ecosystems that underpin modern digital infrastructure. Developer platforms, software supply chains, mobile app environments, and enterprise cloud services are now prime targets because they offer far greater reach; one compromise can quickly ripple across thousands of downstream users and services.  This shift matters because these systems sit at the core of how software is built, delivered, and accessed. CI/CD pipelines, package registries, mobile applications, and identity systems are no longer supporting components; they are high-value entry points. Once compromised, they allow attackers to scale rapidly, turning a single breach into a widespread impact event. 

The Cyber Express Weekly Roundup 

Iranian-linked Group Blamed for LA Transit Cyberattack 

A cyberattack targeting Los Angeles’ public transit infrastructure in March has now been attributed by researchers to a group known as “Ababil of Minab,” which is believed to have links to Iranian intelligence operations. Read more... 

Critical WordPress Plugin Flaw Enabled Full Site Takeover 

A severe vulnerability in the WP Maps Pro plugin has placed more than 15,000 WordPress websites at risk of complete compromise. The flaw, present in versions up to 6.1.0, stemmed from missing access control checks in an AJAX function. This allowed unauthenticated attackers to create administrator accounts, effectively granting full control over affected sites. Read more... 

OverlayPhantom Android Trojan Spreads Across Banking Apps 

A newly identified Android malware strain, dubbed “OverlayPhantom,” is actively targeting users of more than 180 banking and cryptocurrency applications across at least 10 countries. The malware spreads through deceptive update prompts, tricking users into installing malicious packages. Read more... 

“Megalodon” Supply Chain Attack Hits Thousands of GitHub Projects 

Security researchers have uncovered a large-scale supply chain compromise affecting more than 5,500 repositories hosted on GitHub within a six-hour window. The campaign, dubbed “Megalodon,” used malicious GitHub Actions workflows to inject code into development pipelines. Read more... 

FBI Flags Kali365 Phishing-as-a-service Targeting Microsoft 365 

The U.S. Federal Bureau of Investigation has issued a warning about a phishing toolkit known as “Kali365,” which is being used to compromise Microsoft 365 accounts at scale. Unlike traditional phishing campaigns that rely on stolen passwords, Kali365 is designed to intercept authentication tokens, allowing attackers to bypass multi-factor authentication protections. Read more... 

Weekly Cybersecurity Takeaway 

This week’s incidents highlight a cybersecurity environment defined by scale and automation rather than isolated breaches. From state-linked intrusions into public infrastructure to supply chain attacks affecting thousands of repositories in hours, attackers are clearly prioritizing systems that can multiply impact through trust relationships.  At the same time, mobile malware and phishing-as-a-service platforms continue to lower the barrier for entry, enabling both sophisticated actors and low-skill operators to conduct high-impact campaigns. The consistent theme across all cases is simple: once trust in a platform is compromised, whether a plugin, a CI/CD pipeline, or a login system, the downstream consequences can spread far beyond the initial target. 

Massive npm Supply Chain Attack Hits AntV Ecosystem; Hundreds of JavaScript Packages Compromised

19 de Maio de 2026, 15:26

AntV, Shai-Hulud, NPM, Supply Chain, Supply Chain Attacks, Malware, Worm, Golden Path

A major software supply chain attack has compromised hundreds of widely used npm packages tied to the AntV ecosystem, exposing developers and organizations to credential theft, malware delivery, and potentially broader infrastructure compromise.

Security researchers at Socket.dev and Snyk say the incident is linked to the ongoing “Mini Shai-Hulud” malware campaign, a rapidly evolving threat operation targeting the JavaScript ecosystem through hijacked maintainer accounts and poisoned package updates.

Hundreds of Packages Affected

According to researchers, attackers compromised the npm maintainer account “atool” and used it to publish malicious versions across more than 300 packages in a matter of minutes. The affected libraries include several high-profile packages with millions of weekly downloads, such as:

  • echarts-for-react
  • size-sensor
  • timeago.js
  • @antv/g6
  • @antv/g2
  • @antv/x6

The broader AntV ecosystem, which was originally developed within Alibaba and widely used for data visualization and enterprise dashboards, has extensive adoption across financial services, analytics platforms and web applications.

Researchers estimate the compromised packages collectively account for tens of millions of downloads per month, dramatically increasing the potential blast radius.

Credential Theft and Self-Propagation

The malicious payloads reportedly go far beyond simple backdoors.

Socket researchers said the malware was designed to steal sensitive information from developer environments and CI/CD systems, including:

  • AWS credentials
  • GitHub tokens
  • npm authentication tokens
  • SSH keys
  • Docker configurations
  • Kubernetes secrets

In some environments, the malware also attempted container escape techniques if Docker sockets were exposed.

Security analysts linked the attack to the same “Mini Shai-Hulud” campaign previously observed targeting SAP and AI-related npm packages earlier this year.

The malware family has gained attention for its worm-like behavior and aggressive propagation techniques, including attempts to infect additional packages and developer workflows.

A Familiar Pattern in npm Attacks

The latest compromise adds to a growing list of high-profile attacks targeting the npm ecosystem in 2026.

Recent incidents involving packages tied to Axios, TanStack, and SAP all followed a similar pattern. Attackers compromise a trusted maintainer account or CI/CD workflow, publish malicious package updates, and rely on automated dependency updates to spread malware rapidly.

Read: OpenAI Responds to Axios npm Supply Chain Attack, Rotates macOS Certificates

In this case, researchers believe the malicious packages were published during a narrow 22-minute window before detection efforts began. Some malicious versions were later deprecated or removed from npm, though security experts warn that anyone who installed affected versions should assume compromise.

Microsoft and Security Researchers Warn Developers

Researchers from Microsoft and Socket Security publicly warned developers to immediately audit dependencies, pin known-safe versions, and rotate credentials potentially exposed during installation.

Security teams are also advising organizations to:

  • Run installs with --ignore-scripts where feasible
  • Review CI/CD secrets and environment variables
  • Monitor for suspicious outbound network traffic
  • Audit recently updated dependencies

Because many npm malware campaigns now execute during installation rather than runtime, compromised systems may show little evidence after the initial infection.

Modern JavaScript applications often rely on hundreds—or thousands—of indirect dependencies. That means compromising a single popular maintainer account can create a cascading effect across enterprise environments worldwide.

Academic research published this year found that over 21% of npm packages inherit at least one known vulnerability through dependency chains, highlighting how interconnected—and fragile—the ecosystem has become.

Also read: New Shai-Hulud Attack Hits Nearly 500 npm Packages with 100+ Million Downloads

The Cyber Express Weekly Roundup: AI Threat Escalation, Ransomware Disruption, Supply Chain Attacks, and Expanding Cybersecurity Risks

TCE weekly roundup TCE

In this weekly roundup from The Cyber Express, the global cybersecurity landscape in 2026 continues to shift rapidly as emerging technologies and evolving cyber threats reshape the digital environment. Governments are increasing oversight of artificial intelligence and data practices, while ransomware groups, nation-state actors, and cybercriminal networks are refining their tactics to target enterprises, critical infrastructure, and software supply chains.

This week’s developments highlight how modern cyber risks are becoming more interconnected across industries, with AI-driven attacks, ransomware operations, privacy concerns, and software supply chain compromises continuing to place pressure on organizations worldwide.

The Cyber Express Weekly Roundup 

AI Cyberattacks Surge Across the Americas in Early 2026 

Americas cyber threat landscape Cyber activity linked to artificial intelligence has intensified across the Americas during Q1 2026, with attackers increasingly leveraging AI-driven tools to scale ransomware campaigns, automate reconnaissance, and enhance social engineering operations. A scheduled webinar on May 28 by Cyble will bring together security specialists to examine emerging cyber trends, including ransomware evolution, nation-state activity, and defensive strategies to improve cyber resilience. Read more... 

Foxconn Confirms Cyberattack Amid Ransomware Claims of Massive Data Theft 

Manufacturing giant Foxconn confirmed a cyberattack that disrupted operations at several North American facilities following claims from the Nitrogen ransomware group. The attackers alleged they had stolen more than 8TB of corporate data, including over 11 million files. Foxconn activated incident response procedures and stated that operations were gradually returning to normal. Read more... 

Microsoft Patches 120 Vulnerabilities in May 2026 Security Update 

In its May 2026 Patch Tuesday release, Microsoft addressed approximately 120 security vulnerabilities across a wide range of products, including Windows, Office, SharePoint, DNS services, and enterprise platforms. Among these were 17 classified as critical severity issues. Although no actively exploited zero-day vulnerabilities were reported in this cycle, multiple high-risk remote code execution flaws prompted security researchers to recommend immediate patch deployment across enterprise environments. Read more... 

California Issues Record $12.75 Million Privacy Settlement Against GM 

California regulators reached a $12.75 million settlement with General Motors over allegations tied to violations of the California Consumer Privacy Act (CCPA). Authorities claimed the company collected, retained, and sold driver data without proper consent. The investigation alleged that General Motors shared sensitive geolocation and driving behavior data from its OnStar platform with data brokers LexisNexis and Verisk between 2020 and 2024. Read more... 

Malicious npm Packages Fuel JavaScript Supply Chain Attack 

Security researchers have identified a supply chain compromise targeting the widely used node-ipc npm package ecosystem. Several versions—including 9.1.6, 9.2.3, and 12.0.1—were found to contain malicious code designed to act as a credential-stealing backdoor. The compromised packages reportedly collected sensitive system information, developer credentials, and CI/CD pipeline secrets from affected environments. Read more... 

Weekly cybersecurity takeaway 

This week’s The Cyber Express weekly roundup highlights how modern cybersecurity threats are increasingly interconnected across technology, regulation, and supply chains. AI-driven attacks are expanding operational scale; ransomware groups continue to rely on data theft and disruption, and software supply chain compromises are increasingly targeting developer ecosystems. At the same time, regulatory and legal responses, from privacy settlements to vulnerability patch cycles, continue to evolve in parallel. The overall landscape suggests that cyber risk in 2026 is no longer confined to individual incidents but is instead shaped by continuous pressure across infrastructure, software, and data governance layers.
❌
❌