SMSA Express Allegedly Breached, 124.7 Million Shipment Records With Sender and Recipient Details for Sale

SMSA Express is reportedly facing a data exposure claim involving 124.7 million shipment records, including sender and recipient details, commodity descriptions, and declared values. If true, the leaked data could enable highly convincing parcel delivery fraud and reveal private purchasing behavior and relationships between senders and recipients. #SMSAExpress #ShipmentRecords #ParcelFraud…

Read More
SMSA Express Allegedly Breached, 124.7 Million Shipment Records With Sender and Recipient Details for Sale

A seller using the name LordVoldemort claims to be offering a full compromise of Podomoro University in Indonesia, including 75 databases and the university’s website source code, for $7,000 in cryptocurrency. The alleged data spans academic, financial, HR, and IT systems, but the claim remains unverified. #PodomoroUniversity #LordVoldemort…

Read More
SMSA Express Allegedly Breached, 124.7 Million Shipment Records With Sender and Recipient Details for Sale

A threat actor using the alias konata_izumi_shell claims to have leaked Bolivia’s Ministry of Health and Sports SSSRO database, exposing 41,406 SQL records tied to rural health interns. The alleged dump includes highly sensitive personal, academic, and location data, but the claim remains unverified. #Bolivia #MinistryofHealthandSports #SSSRO #konata_izumi_shell…

Read More
SMSA Express Allegedly Breached, 124.7 Million Shipment Records With Sender and Recipient Details for Sale

A forum user known as 888 allegedly published a PokemonGym.nl database containing about 19,600 player accounts, with usernames, email addresses, IP data, and Argon2id password hashes. The post also claims to include full private messages from the Dutch online Pokémon RPG, but the breach remains unverified. #PokemonGymnl #888 #Argon2id…

Read More
Chaos ransomware’s msaRAT: Living off the browser to build a covert C2 channel

Cisco Talos discovered msaRAT, a new Rust-based remote access trojan used by the Chaos ransomware group, which hides its command-and-control traffic by abusing Chrome DevTools Protocol and WebRTC through a browser process. The malware uses Cloudflare Workers for signaling and Twilio TURN for relayed communications, making its network activity difficult to trace and blending it into normal browser traffic. #msaRAT #Chaos #CloudflareWorkers #TwilioTURN #ChromeDevToolsProtocol

Read More
Cl0p Exploitation of PTC Windchill & FlexPLM (CVE-2026-12569)

This advisory describes an active Cl0p ransomware affiliate campaign targeting internet-exposed PTC Windchill and FlexPLM systems by chaining a FlexPLM WSDL information disclosure flaw with a Windchill login servlet vulnerability to gain unauthenticated remote code execution. It also details post-exploitation webshell deployment, data theft, and extortion emails sent to affected organizations across Manufacturing, Automotive, Aerospace, and Retail/Apparel sectors. #Cl0p #PTCWindchill #FlexPLM #CVE-2026-12569

Read More
SMSA Express Allegedly Breached, 124.7 Million Shipment Records With Sender and Recipient Details for Sale

Get Nice Holdings, a Hong Kong-listed financial services company, was hit by a cyberattack on July 19 that temporarily disrupted electronic trading systems and share withdrawal services. The securities unit resumed operations the same day, while the futures unit remained offline as the company investigated the incident with a cybersecurity firm and notified Hong Kong authorities. #GetNiceHoldings #HongKong

Read More