Threat Actor Selling Email Credentials for Israeli Government Agencies, Organizations, and International Targets Including Israel Police, Ministry of Justice, and Quebec Education Board

A threat actor known as swag is advertising stolen email credentials from multiple Israeli government agencies, Israeli organizations, and international targets on the open web. Compromised accounts include Israel Police, the Ministry of Justice, and the Quebec Central Board of Education, posing high-severity risks like spear-phishing and unauthorized access to sensitive…

Read More
Threat Actor Selling Email Credentials for Israeli Government Agencies, Organizations, and International Targets Including Israel Police, Ministry of Justice, and Quebec Education Board

A threat actor going by bobby_killa is auctioning full WordPress admin access to an unnamed Spanish e-commerce site that uses the REDSYS payment gateway and handles roughly 1,150–1,200 monthly card orders. The listing, posted on a Russian-language forum with a $1,000 starting bid and a $3,000 blitz price, creates high risk…

Read More
Threat Actor Selling Email Credentials for Israeli Government Agencies, Organizations, and International Targets Including Israel Police, Ministry of Justice, and Quebec Education Board

A threat actor known as xorcat has posted an alleged Canva dataset containing 900,000 user records as a free download on an online forum, accompanied by a 20-record sample to demonstrate authenticity. The dump includes bcrypt ($2y$10$) hashed passwords, OAuth provider links (Google/Facebook/Email), account identifiers, and platform usage metadata that could…

Read More
Threat Actor Selling Email Credentials for Israeli Government Agencies, Organizations, and International Targets Including Israel Police, Ministry of Justice, and Quebec Education Board

On Sunday 29 March 2026 the Iran-linked hacking group Pay2Key encrypted and paralysed the IT systems of Haepo Tire Center in Winterthur using ransomware, also destroying backups. The incident has caused daily losses of several tens of thousands of Swiss francs and the loss of current accounting data; Haepo has informed police and its insurer and the management does not plan to pay the demanded ransom for now. #Pay2Key #HaepoTireCenter

Read More
Threat Actor Selling Email Credentials for Israeli Government Agencies, Organizations, and International Targets Including Israel Police, Ministry of Justice, and Quebec Education Board

A technical malfunction in a CharitƩ Berlin data center caused an IT outage affecting three hospital sites and prevented the fire brigade from accessing the Virchow, Mitte, and Steglitz clinics. Patient care remained stable while emergency entrances were temporarily closed as a precaution, and CharitƩ states the cause is a technical fault rather than a cyberattack. #Charite #Virchow #Mitte #Steglitz

Read More
Abacel SA Data Breach Exposes Over 500,000 User Records

Abacel SA, a prominent wholesale technology and consumer electronics distributor in Paraguay, has allegedly been compromised and a database tied to its domain (abacel.com.py) is being advertised on a cybercrime forum. The seller claims the dataset includes country of residence, full names, approximately 345,000 email addresses, approximately 510,000 telephone numbers verified…

Read More
Dubai International Airport Suffers Alleged Data Breach

The Nasir Security group (also referring to themselves as the Nasir Resistance) claims to have compromised Dubai International Airport (DXB) and maintained active operational access to the airport’s classified intelligence systems for several months. They say the breach includes classified intelligence, roughly 1,000 sensitive internal documents, and photos/reproductions of passports from…

Read More
Anthropic Accidentally Leaks Claude Code’s ā€œSecret Sauceā€ via npm Blunder

Anthropic’s Claude Code source was exposed after developers accidentally published source maps to its public npm registry, allowing anyone to reconstruct the original TypeScript source. The leak revealed core internals—like the 46,000-line QueryEngine.ts, 40+ agent tools, the permission system, and unreleased feature flags—and although Anthropic secured the registry, copies are already…

Read More
Threat Actor Selling Email Credentials for Israeli Government Agencies, Organizations, and International Targets Including Israel Police, Ministry of Justice, and Quebec Education Board

A ransomware attack by the Qilin group against Netalia Srl paralyzed Genoa’s municipal fine payment systems, prompting the city to extend payment deadlines and grant a 30% discount to avoid unequal treatment. Authorities are investigating the suspected digital extortion; initial checks appear to rule out a data leak, but encrypted administrative archives present an immediate economic risk to the city. #Qilin #NetaliaSrl

Read More
EU Confirms Data Exfiltration in Attack on Europa.eu Cloud Infrastructure

The European Commission disclosed on March 24 that a cyber-attack against the cloud infrastructure hosting its Europa.eu platform led to early findings of data exfiltration. The Commission contained the intrusion, kept Europa websites online while confirming internal administrative systems were unaffected, and is notifying potentially affected Union entities as it uses…

Read More