A threat actor called Straightonumberone claims to be selling data stolen from Grupo ATC after ransom negotiations reportedly failed. The unverified listing says the dataset includes employee PII, credentials, business emails, GPS and freight-routing data, and details tied to major partners like Ford and Toyota. #GrupoATC #Straightonumberone #Ford #Toyota #Tesla #GeneralMotors…
Category: Cyber Attack
The initial access broker miyako advertised five separate listings for root-level access to Linux firewalls, each offering Root RCE and shell access. The access was priced at $400 per listing and was observed on July 2, 2026, with contacts withheld through a session-based channel. #miyako #Linux #Firewall…
Gogolook detected a cybersecurity incident involving unauthorized access attempts to its test server environment, and its security team has activated defenses while investigating with external partners. Current findings indicate that no member personal data or internal confidential information was accessed, and the company plans to strengthen its protections. #Gogolook
Laster Tech was the target of a cyberattack against its information systems, prompting the company to activate its defense mechanisms and bring in external experts. The affected systems have been gradually restored, and the preliminary assessment suggests the impact on operations will not be significant. #LasterTech
Arctic Wolf found that Anubis ransomware affiliates used valid VPN credentials and exploited CitrixBleed 2 (CVE-2025-5777) to gain initial access, then relied on legitimate RMM tools, RDP, PsExec, and tunneling utilities to move through victim networks and maintain persistence. The campaign targeted critical infrastructure such as domain controllers, hypervisors, backup systems, and NAS devices, with exfiltration and defense evasion often occurring before Anubis encryption began. #Anubis #CitrixBleed2 #CVE20255777 #ScreenConnect #ZohoAssist #MeshAgent #cloudflared
Atlas Elektronik, a subsidiary of TKMS, was hit by a cyberattack that targeted its North American branch supporting U.S. military projects. While no sensitive military data was compromised, general administrative documents and file lists were exposed on the darknet, and the attack was attributed to the Russian ransomware group The Gentleman. #AtlasElektronik #TKMS #TheGentleman #ThyssenKruppMarineSystems #Bremen
The City Government of León, Guanajuato, reported a cyberattack that compromised information from its Citizen Services System. Authorities filed a criminal complaint with the State Public Prosecutor’s Office and are continuing technical and institutional follow-up to determine the full scope of the incident. #CiudaddeLeón #SistemaDeServicioaCiudadanos
Abans Financial Services disclosed a ransomware attack targeting the IT infrastructure of its overseas subsidiaries after a CERT-In alert on June 30, 2026. The company said its own systems were not affected and that the incident had no material impact on operations while it continues monitoring and remediation efforts. #AbansFinancialServices #CERTIn
A threat actor known as lucy is allegedly offering a private one-time sale of data from Netim.com, a French domain registrar and hosting provider, for $5,000 in cryptocurrency. The claimed trove includes customer records, password hashes, source code, configuration files, and infrastructure details, but the report remains unverified. #Netim #lucy #Netimcom…
A report claims the Libyan Civil Aviation Authority was breached, with an actor advertising access to about 300 GB of aviation data spanning 2015 to 2026. The alleged data samples include pilot and engineer licences as well as medical certificates, with claims of the ability to retrieve and modify records. #LibyanCivilAviationAuthority…
Indra reported that it maintained the security and continuity of its services after a subsidiary was targeted in a ransomware attack, with its CSIRT immediately activating internal analysis and verification protocols. The company said the incident was minimal, limited to a non-critical environment, and that it continues investigating the origin while strengthening cybersecurity controls to protect its systems and operations. #Indra #CSIRT
Flexi Parking, used by 64 local authorities across Malaysia, was hit by a cyberattack that disrupted transaction data and related systems. In response, local authorities were instructed to suspend parking summons issuance while restoration work is underway. #FlexiParking
A threat actor known as ChimeraZ allegedly posted data claimed to be a juvenile-prison database for Le Pontet, but the sample appears to be municipal police and city-services records from the French town instead. The disputed dataset may expose residents’ names, home addresses, phone numbers, vehicle details, and vacation-watch records that…
Pachatours, a French travel and tour operator, was allegedly breached through SQL injection via an unprotected web endpoint, with attackers claiming to have extracted a full database of about 2GB and more than 2.2 million rows. The exposed data reportedly includes passports, payment details, B2B credentials, and PNRs. #Pachatours #SQLinjection #ChimeraZ…
GSW Kamen, a municipal utility near Dortmund, was hit by a cyberattack on June 28, causing internal services and the customer portal, including the app, to go offline while electricity and water supply remained unaffected. The Landeskriminalamt is investigating the incident with external experts to determine the scope of the damage and the nature of the attack. #GSWKamen #Landeskriminalamt #Dortmund