An actor using the name GordonFreeman claims to be selling a 15.7GB database from RENAPER, Argentina’s national identity registry, allegedly containing 48 million citizen records. The sample reportedly includes DNI numbers, home addresses, phone numbers, and even children’s data, but the claim remains unverified. #RENAPER #GordonFreeman #Argentina #DNI…
Category: Cyber Attack
Gunra is a ransomware-as-a-service operation that uses double extortion to target government, critical infrastructure, and other organizations, combining data theft with file encryption. The advisory highlights Gunra’s use of exploitable VPN and firewall devices, stolen credentials, and lateral movement tools to spread across networks and includes mitigation guidance to reduce exposure. #Gunra #Conti #CISA #FBI #KNPA
An actor posting as exfilar claims ArtNexus left a backend database publicly readable, exposing 3,314 unique email addresses, 3,455 user accounts, and 834 physical addresses with phone numbers across 37 countries. The alleged dump also includes payment source tokens, purchase records, and private negotiation messages, but the claim remains unverified and…
Digitide Solutions announced a cybersecurity incident in one of its subsidiaries, confirming unauthorized access to data. The company said there is no major operational or financial loss reported at this time, and an internal investigation is underway. #DigitideSolutions
Foresee immediately activated its information security defenses and engaged external cybersecurity experts to contain the breach, assess its scope, and strengthen its network infrastructure. The company’s preliminary internal evaluation indicates that the attack has not had a significant impact on its normal business operations. #Foresee #ForeseePharma
Microsoft Threat Intelligence has identified a new ransomware campaign by Storm-1175 deploying the previously undocumented StormEncryptor strain, which appends the .encrypted extension and drops !!!README_FIRST!!!.txt ransom notes. The activity may be linked to exploitation of CVE-2026-18577 in N-able products, with the attackers using tools like AnyDesk, SimpleHelp, Advanced IP Scanner, and Mimikatz to expand access and prepare for encryption. #Storm1175 #StormEncryptor #CVE202618577 #Nable #AnyDesk #SimpleHelp #AdvancedIPScanner #Mimikatz
Woodhaven Lakes successfully contained and stopped a ransomware attack that encrypted files on its local systems. The incident affected Microsoft Office files and locally stored documents, while the owners’ database remained untouched, and recovery is still ongoing. #WoodhavenLakes
Coryell County, Texas is restoring its systems after a technology outage that is being investigated as a possible cybersecurity incident. Essential services and public safety operations remained uninterrupted, while officials have not yet disclosed the cause, start time, or specific systems affected. #CoryellCounty #Texas
The City of Suisun declared a local emergency after a cyberattack caused a malware infection that took down the 911 dispatch line and other critical systems. Federal investigators, including the FBI and the Department of Homeland Security, are now working with the city as emergency dispatch operations were moved to Solano County. #CityofSuisun #FBI #DepartmentofHomelandSecurity #SolanoCounty
Washburn County is investigating a cyber incident discovered on August 6, 2026, and has shut down county technology to protect systems while working with cybersecurity professionals to assess the scope and restore services. The county says services may be temporarily disrupted, but offices and the court system remain open, and updates will be posted on the county website as the investigation continues. #WashburnCounty
Suisun City, California declared a state of emergency after malware disrupted 911 routing, police and fire dispatch, and other critical city systems. The city shut down its IT network to contain the incident and is working with the FBI, DHS, and state agencies while restoring services. #SuisunCity #SolanoCounty #FBI #DepartmentofHomelandSecurity
The City of Coweta was hit by a system-wide ransomware attack on August 5, disrupting city computers, files, and most computer-based services while leaving the city website, Xpress Bill Pay, and emergency services operational. Officials are working with IT and cybersecurity experts, using offsite backups for recovery, and have reported the incident to local, state, and federal authorities. #CityofCoweta #XpressBillPay #LexisNexis
The City of Coweta in Oklahoma is dealing with a system-wide ransomware attack that affected all municipal computers, files, and computerized services, while the website and third-party billing portal remained untouched. City officials say a backup exists to support data restoration once the incident is contained. #CityofCoweta
Mitchell, South Dakota, isolated part of its network after detecting a potential cybersecurity incident, while critical and emergency services remained operational. Forensic experts were brought in to assess the scope of the event, but officials have not yet confirmed the attack type, affected systems, or whether any data was compromised. #Mitchell #SouthDakota
A forum user named 888 allegedly posted a breach of ACRE Africa that claims exposure of 14,300 farmer records along with source code, configuration files, access tokens, private keys, and hardcoded credentials. The report is unverified, but the leaked data could enable convincing fraud against smallholder farmers and pose ongoing access…