Cisco Talos discovered msaRAT, a new Rust-based remote access trojan used by the Chaos ransomware group, which hides its command-and-control traffic by abusing Chrome DevTools Protocol and WebRTC through a browser process. The malware uses Cloudflare Workers for signaling and Twilio TURN for relayed communications, making its network activity difficult to trace and blending it into normal browser traffic. #msaRAT #Chaos #CloudflareWorkers #TwilioTURN #ChromeDevToolsProtocol
Category: Cyber Attack
This advisory describes an active Cl0p ransomware affiliate campaign targeting internet-exposed PTC Windchill and FlexPLM systems by chaining a FlexPLM WSDL information disclosure flaw with a Windchill login servlet vulnerability to gain unauthenticated remote code execution. It also details post-exploitation webshell deployment, data theft, and extortion emails sent to affected organizations across Manufacturing, Automotive, Aerospace, and Retail/Apparel sectors. #Cl0p #PTCWindchill #FlexPLM #CVE-2026-12569
RevolutionParts.com was allegedly targeted in a data leak involving 5,147,231 unique customer records, with the listing posted for free. The exposed data reportedly includes customer PII and device identifiers, and the actor named in the post is kitta. #RevolutionParts #kitta…
A forum user named kitta allegedly leaked the Bebunk.com database, claiming it exposed 12,324 banking customers across France and New Caledonia. The sample reportedly includes IBANs, KYC records, account balances, and tokens, creating a high-risk exposure for potential fraud and account abuse. #Bebunk #kitta #IBAN #KYC #Bebunk.com…
Get Nice Holdings, a Hong Kong-listed financial services company, was hit by a cyberattack on July 19 that temporarily disrupted electronic trading systems and share withdrawal services. The securities unit resumed operations the same day, while the futures unit remained offline as the company investigated the incident with a cybersecurity firm and notified Hong Kong authorities. #GetNiceHoldings #HongKong
Sumner County Schools in Tennessee delayed the start of classes by six days after discovering unauthorized access to its network. The district notified local and federal authorities, brought in forensic specialists, and is still investigating the scope of the compromise. #SumnerCountySchools #Tennessee
The President of the Legislative Assembly confirmed that the National Congress was the victim of a cyberattack that compromised its information systems. The announcement came during a plenary session after a deputy raised concerns about the outage of the institution’s website. #Congress #AsambleaLegislativa #asamblea.go.cr
A ransomware attack from Russian infrastructure on 15 July 2026 locked nearly all systems and forced a full rebuild after normal recovery proved impossible. Mail service was restored on 17 July 2026, but all email received before that time was lost and cannot be recovered. #Webhot
RapidFort Allegedly Breached in CanisterWorm Campaign, 569GB Across 48 S3 Buckets Listed for $40,000
A threat actor using the alias xpl0itrs claims RapidFort was breached in a CanisterWorm campaign linked to TeamPCP, with 569GB of data from 48 S3 buckets reportedly offered for sale. The alleged haul includes cloud credentials, kubeconfigs, private keys, and customer deployment materials, but the claim remains unverified. #RapidFort #CanisterWorm #TeamPCP…
Shun On Electronic confirmed it experienced an encryption-based attack after receiving an anomaly report, but its information security team quickly activated response measures and safeguards. The company said its internal information systems and official website are operating normally and were not substantially affected. #ShunOnElectronic
Cybercriminals gained access in mid-July 2026 through compromised credentials to a data exchange platform used by one of Stadler’s suppliers, exposing technical information from the supplier rather than Stadler’s own systems. Stadler says no internal IT systems were compromised, no personal data was affected, and production and train operations continue without disruption, while the Everest Group claims the attack and demands 10 million Swiss francs. #Stadler #EverestGroup #Thurgau
Arctic Wolf Labs found multiple June 2026 intrusions in which attackers used CVE-2026-0257 against Palo Alto Networks firewall appliances to gain VPN access and quickly deploy Qilin ransomware across victim networks. The activity showed shared operational patterns, including PsExec lateral movement, credential theft, log clearing, and in some cases data exfiltration for double-extortion, suggesting overlapping Qilin affiliates or shared exploitation infrastructure. #CVE-2026-0257 #PaloAltoNetworks #Qilin #GlobalProtect #PsExec
CCDR Algarve was hit by a cyberattack over the weekend after an unauthorized external access was detected, prompting the activation of internal response protocols. Some services, including communications and institutional email access, are temporarily unavailable while authorities and technical teams work to restore operations. #CCDRAlgarve
A claimed breach of Georgia’s judiciary alleges that the High Council of Justice and related court systems were compromised, with about 5TB of judicial data reportedly offered for sale. If true, the exposed material could reveal sensitive court records, personal data, and technical details that may help attackers target Georgian judicial…
A breach is alleged against Bogotá’s Secretaría Distrital de Movilidad, with 5.6GB of traffic agent and citation-related data reportedly listed for sale at $500. The data package is said to include citations, agent rosters, medical records, and multiple file types, and is attributed to PescobarLegado / NyxarGroup. #SecretaríaDistritaldeMovilidad #Bogotá #PescobarLegado #NyxarGroup…