Cyber Incident | NSW Government

Internal monitoring detected a suspected transfer of a substantial cache of confidential commercial and financial documents affecting multiple NSW Government departments and projects. NSW Treasury reported the matter to NSW Police, who launched Strike Force Civic, led to criminal charges, and now believe the alleged stolen data has been located and secured with no external compromise and no impact to government services. #NSWTreasury #StrikeForceCivic

Read More
Ledil Immobilier (ledil.immo) Database Breached: Threat Actor 888 Leaks 6,700 French Real Estate User Records

Threat actor 888 posted a full database dump of Ledil Immobilier (ledil.immo), exposing 6,700 unique user records including names, emails, phone numbers, addresses, property and transaction details. The dataset, apparently exported from a Drupal (Search API) instance and offered as a free download on darkforums.su, greatly increases the risk of targeted…

Read More
Over 200 Japanese firms paid ransomware attackers, 60% fail to recover data

A survey found that at least 222 Japanese companies paid ransom demands but roughly 60% still failed to recover their data. Of 1,107 respondents, 507 reported ransomware attacks, and experts warn that paying ransoms does not guarantee recovery while urging updated security and regular backups. #JapanInstituteForPromotionOfDigitalEconomyAndCommunity #Proofpoint

Read More
The Price of Privacy: Atlassian to Train AI on Jira and Confluence Data Starting August 2026

Atlassian has revised its data contribution policy so that, effective August 17, 2026, it will use customer metadata and in‑app content from Jira, Confluence, and related cloud offerings to train its AI models, affecting roughly 300,000 customers. Data will be classified into de‑identified metadata (readability, complexity, task taxonomies, semantic similarity, iteration…

Read More
Anubis Ransomware Attack Hits ViaQuest and Samuel I White PC

Anubis group claims to have breached multiple organizations, exposing over five terabytes of sensitive information across the healthcare and legal sectors. The alleged victims include ViaQuest and Samuel I. White, PC, with stolen files spanning patient medical records, internal emails, financial documents, court filings, client databases, and network passwords. #Anubis #ViaQuest…

Read More
The Ghost in the Browser: Is Claude Desktop Clandestinely Installing a Surveillance Bridge?

Alexander Hanff found that Claude Desktop silently installs a native messaging bridge that pre-authorizes browser extensions to communicate with local executables, enabling browser automation, DOM access, session sharing, and other elevated actions without user consent. The manifest is autonomously generated across multiple Chromium browsers, persists and is rewritten on launch with…

Read More
Ledil Immobilier (ledil.immo) Database Breached: Threat Actor 888 Leaks 6,700 French Real Estate User Records

Threat actor Rabid is advertising a complete 250GB+ database from the Chartered Institute of Bankers of Nigeria (CIBN), claiming it contains the institute’s full records and platform source code. The archive includes member personal data, scanned ID and academic documents, and internal code that could enable identity theft, synthetic identity fraud,…

Read More
Ledil Immobilier (ledil.immo) Database Breached: Threat Actor 888 Leaks 6,700 French Real Estate User Records

A threat actor known as Sorb is selling a database attributed to Taiseer (taiseer.co) containing 71,000 user records, including bcrypt password hashes, 27,000 national ID scans, emails, phone numbers, FCM push tokens, and per-user gold balances. The listing is priced at $400 with escrow and claims ongoing access, creating high risk…

Read More
DFIR Report – The Gentlemen & SystemBC: A Sneak Peek Behind the Proxy

The Gentlemen RaaS has rapidly expanded in early 2026, claiming over 320 victims and offering multi‑platform lockers written in Go for Windows, Linux, NAS and BSD plus a C‑based ESXi variant. Incident response telemetry shows affiliates deploying SystemBC and Cobalt Strike, revealing a botnet of over 1,570 likely corporate victims and demonstrating GPO‑based mass deployment, robust lateral movement, and aggressive defense‑evasion. #TheGentlemen #SystemBC

Read More
Everest Group Breaches Frost Bank, Citizens Bank, Tokoparts, Complete Aircraft Group, Umiles, Nutrabio

The Everest ransomware group claims to have breached multiple organizations across the financial, aviation, automotive, and retail sectors and has posted large troves of highly sensitive corporate and customer data on its extortion portal with active countdowns to public release. Alleged victims include Frost Bank, Citizens Bank, Tokoparts, Complete Aircraft Group,…

Read More