Intel

Threat intelligence briefs — active exploits, CVEs, data breaches, and ransomware campaigns.

INTEL 2026-03-28
Intel Brief: Lockheed Martin — APT IRAN Claims 375TB Exfiltration, IRGC Data Transfer, and $400M Ransom While Targeting Named Engineers
Pro-Iranian hacking group APT IRAN has claimed responsibility for a massive breach of Lockheed Martin, alleging exfiltration of 375 terabytes of sensitive defense data — including technical drawings, source code, missile
INTEL 2026-03-28
Intel Brief: European Commission — AWS Account Breach Exposes 350GB of EU Executive Data, Attacker Plans Public Leak
The European Commission — the executive body of the European Union, responsible for proposing legislation, enforcing EU law, and managing the bloc's day-to-day operations — is investigating a confirmed data breach after
INTEL 2026-03-28
Intel Brief: Goodwill Industries — Interlock Ransomware Hits Nonprofit Chain, 80GB Stolen, Stores Forced Cash-Only
Ransomware group Interlock has added Goodwill Industries of North Central Pennsylvania to its dark web leak site, claiming 80GB of stolen data following a confirmed attack that caused operational disruptions extending be
INTEL 2026-03-28
Intel Brief: Nova Scotia Power — Cyberattack Exposed 900,000 Utility Customers, Privacy Commissioner Forces Security Reform
Nova Scotia Power, the province's largest electrical utility and primary power provider for approximately 500,000 Nova Scotian households and businesses, has confirmed that roughly 900,000 current and former customers we
INTEL 2026-03-28
Intel Brief: AFC Ajax — API Flaws Exposed 300,000 Accounts and Enabled Hijack of 42,000 Season Tickets
Dutch football club AFC Ajax has confirmed a hacker exploited vulnerabilities in its IT systems, accessing fan personal data and gaining the ability to transfer, reassign, and manipulate tickets at scale. RTL journalists
INTEL 2026-03-28
Intel Brief: Kash Patel — Iranian State-Linked Handala Breaches FBI Director's Personal Gmail, Publishes Authenticated Documents
Iranian government-backed hacking group Handala has claimed and partially confirmed the breach of FBI Director Kash Patel's personal Gmail account, publicly releasing a cache of files including photographs and emails dat
INTEL 2026-03-28
Intel Brief: Navia Benefit Solutions — 24-Day Silent Breach Exposes 2.7 Million Benefits Records Including SSNs and Health Data
Navia Benefit Solutions, a Washington-based employee benefits administrator serving more than 10,000 employers nationwide, has confirmed a data breach exposing the personal and protected health information of 2,697,540 i
INTEL 2026-03-28
Intel Brief: Viva Ticket — Ransomware Hits Ticketing Platform Serving the Louvre and 3,500 Cultural Venues
Viva Ticket, a French ticketing and event management platform, was hit by a ransomware attack in early March 2026 that disrupted approximately 3,500 partner organizations — including the Louvre, one of the world's most v
INTEL 2026-03-28
Intel Brief: Esprinet — ALP-001 Ransomware Claims 1.2TB Breach of €4B European IT Distributor
Ransomware group ALP-001 has claimed responsibility for a major breach of Esprinet, one of Southern Europe's largest wholesale IT and consumer electronics distributors, operating across Italy and Spain with approximately
INTEL 2026-03-28
Intel Brief: IntraCare — Healthcare Cyberattack Takes Systems Offline, 28 Surgeries Deferred
New Zealand private healthcare provider IntraCare confirmed a cyberattack on March 20, 2026, forcing a complete IT shutdown and deferral of 28 patient surgical procedures. The company — which performs over 2,000 image-gu
INTEL 2026-03-27
ovhcloud-1-6m-records-darkweb-sale
This one doesn't meet the INCLUDE bar. OVHcloud's founder has flatly denied the breach, researchers doubt its authenticity (only one line of sample data provided, no proof of exfiltration), and the claim is assessed by s
INTEL 2026-03-27
Intel Brief: SATS Sports Club — The Gentlemen Ransomware Claims Nordic Fitness Giant, 733K Members at Risk
The incident is SATS *Sports Club* Sweden (Nordic fitness chain) — not SATS Singapore (the aviation ground handling company). The source slug was misleading. Now I have the full picture.
INTEL 2026-03-27
ajax-amsterdam-breach-fan-data-ticket-hijack
This is a confirmed duplicate of the Ajax brief already written (same slug, same incident). No new article needed — the BleepingComputer brief covers this fully. The NL Times source adds one detail worth noting: Amsterda
INTEL 2026-03-27
Intel Brief: LiteLLM — Malicious PyPI Packages Steal 300GB and 500K Credentials via AI Proxy Supply Chain
LiteLLM, one of the most widely used open-source AI proxy libraries for routing calls across OpenAI, Anthropic, Google, and dozens of other LLM providers, has been compromised in a supply chain attack that injected malic
INTEL 2026-03-27
Intel Brief: Monmouth University — PEAR Ransomware Group Claims 16TB Exfiltration
Monmouth University in New Jersey has been hit by the PEAR (Pure Extraction and Ransom) cybercriminal group, which claims to have stolen 16 terabytes of institutional data — 28 times the average volume exfiltrated in com
INTEL 2026-03-27
Intel Brief: Hightower Holding — Credential Compromise Exposes 131,000 Wealth Management Clients
Hightower Holding, the parent company of Hightower Advisors — one of the largest independent wealth management platforms in the United States — has confirmed a data breach affecting 131,483 individuals. Attackers used co
INTEL 2026-03-26
Intel Brief: UK Biobank: Researcher Negligence Exposes Genetic and Medical Records of 500,000 Volunteers
A Guardian investigation has confirmed that confidential health and genetic data from UK Biobank (one of the world's largest medical research repositories, holding records on 500,000 British volunteers) has been exposed
INTEL 2026-03-26
Intel Brief: Navigate360 / P3 Global Intel: 8 Million Confidential Police Tips Compromised via Social Engineering
A hacker using the name "Internet Yiff Machine" claims to have breached P3 Global Intel (a law enforcement tip intelligence platform operated by Navigate360, a US safety and school security company) and stolen 93 gigabyt
INTEL 2026-03-26
Intel Brief: UK Companies House: WebFiling Browser Exploit Exposes 5 Million Business Records
UK Companies House confirmed in March 2026 that a critical vulnerability in its WebFiling system exposed personal data for directors across all 5 million registered UK companies for approximately five months. The flaw, i
INTEL 2026-03-26
Intel Brief: Trivy Vulnerability Scanner Backdoored in Supply Chain Attack: 100M+ Download Tool Turned Credential Stealer
Trivy, one of the most widely deployed open-source vulnerability scanners in the world, has been compromised in a sophisticated supply chain attack. Threat actor TeamPCP injected credential-stealing malware into official
INTEL 2026-03-26
Intel Brief: Telus Digital: ShinyHunters Data Extortion
Canadian business process outsourcing giant Telus Digital has confirmed a major cybersecurity breach after the ShinyHunters extortion group claimed to have stolen nearly one petabyte of data during a months-long intrusio
INTEL 2026-03-26
Intel Brief: Telekom Serbia: Data Breach Exposes 700,000 Customers via Secondary Application Attack
Telekom Serbia, the country's dominant state-owned telecommunications provider, has confirmed a data breach affecting approximately 700,000 customers; roughly 10% of Serbia's total population. The company's CEO Vladimir
INTEL 2026-03-26
Intel Brief: Checkmarx: TeamPCP CI/CD Supply Chain Compromise via Stolen GitHub Credentials
A threat actor tracked as TeamPCP has compromised two GitHub Actions workflows maintained by Checkmarx, a major application security vendor, in a confirmed supply chain attack detected around March 19, 2026. The attack u
INTEL 2026-03-26
Intel Brief: CGI Sverige / Sweden BankID: ByteToBreach Source Code and Credential Leak
A threat actor calling itself ByteToBreach posted a large dataset on the Breached cybercrime forum claiming to contain source code, passwords, and encryption keys stolen from CGI's Swedish division, CGI Sverige AB, a maj
INTEL 2026-03-26
Intel Brief: Stryker: Iran-Linked Handala Wiper Attack
Fortune 500 medical technology manufacturer Stryker has been crippled by one of the most operationally destructive cyberattacks ever leveled at a U.S. corporation. On March 11, 2026, the Iran-linked hacktivist group Hand
INTEL 2026-03-26
Intel Brief: Starbucks Employee Data Breach: 889 Accounts Compromised via Partner Central Phishing
Starbucks has confirmed a data breach affecting 889 employees after attackers used phishing sites impersonating the company's internal HR portal to steal login credentials and access sensitive employment records. The bre
INTEL 2026-03-26
Intel Brief: Southwire: Qilin Ransomware Group Claims Attack on Major US Electrical Infrastructure Supplier
Southwire, one of North America's largest wire and electrical cable manufacturers with annual revenue exceeding $7 billion, has been listed as a ransomware victim by the Qilin (elf.qilin) ransomware-as-a-service group as
INTEL 2026-03-26
Intel Brief: South Africa Land Bank: RaaS Ransomware Attack via Internet-Facing Server Exploit
South Africa's Land and Agricultural Development Bank (Land Bank) was struck by a ransomware attack on January 12, 2026, confirmed by Finance Minister Enoch Godongwana in a formal parliamentary response. Attackers exploi
INTEL 2026-03-26
Intel Brief: SoundCloud: ShinyHunters Extortion Gang Breaches 29.8 Million User Accounts
SoundCloud, the audio streaming and distribution platform hosting over 400 million tracks from 40 million creators worldwide, has confirmed a data breach affecting approximately 29.8 million user accounts; roughly 20% of
INTEL 2026-03-26
Intel Brief: Salesforce Experience Cloud: ShinyHunters Mass Extortion Campaign
ShinyHunters is running an active, large-scale extortion campaign against hundreds of organizations whose Salesforce Experience Cloud instances were misconfigured to allow unauthenticated data access. As of March 9, 2026
INTEL 2026-03-26
Intel Brief: U.S. Critical Infrastructure: Seedworm (MuddyWater) Espionage Campaign with Novel Deno Backdoor
Symantec and Carbon Black have confirmed that Seedworm, the Iran-linked threat group also tracked as MuddyWater and operating under Iran's Ministry of Intelligence and Security (MOIS), maintained active footholds inside
INTEL 2026-03-26
Intel Brief: QualDerm Partners: Healthcare Data Breach, Millions of Patients Potentially Exposed
QualDerm Partners, one of the largest multi-site dermatology practice groups in the United States, has disclosed a data breach potentially affecting millions of patients. The incident represents one of the most significa
INTEL 2026-03-26
Intel Brief: Ruhnau Clarke & Biogel: Qilin Ransomware Double Extortion
The Qilin ransomware group has claimed simultaneous attacks against two firms in different industries and continents: Ruhnau Clarke, a US-based architecture firm, and Biogel, a Swiss medical and biotechnology manufacture
INTEL 2026-03-26
Intel Brief: Port of Vigo (Spain): Ransomware Attack Disrupts Europe's Largest Fishing Port
Spain's Port of Vigo, the largest fishing port in Europe and a critical node in the continent's seafood supply chain, has been struck by ransomware, forcing authorities to disconnect cargo management systems and revert t
INTEL 2026-03-26
Intel Brief: Royal Bahrain Hospital: Payload Ransomware, 110GB Patient Data Exfiltration Claimed
The Payload ransomware group has claimed responsibility for a breach of Royal Bahrain Hospital, a 70-bed private medical facility in Bahrain serving patients from across the Gulf region including Saudi Arabia, Qatar, Oma
INTEL 2026-03-26
Intel Brief: Odido: ShinyHunters Data Extortion Campaign
ShinyHunters has confirmed a sustained data extortion campaign against Odido, the Netherlands' third-largest telecom provider with roughly 5 million mobile subscribers. Odido acknowledged that 6.2 million current and for
INTEL 2026-03-26
Intel Brief: Nike: Double-Extortion Ransomware Targeting IP
Nike disclosed a ransomware incident in early 2026 that the company's public statements framed as a contained operational disruption; systems encrypted, backups restored, minimal downtime. The real story is what happened
INTEL 2026-03-26
Intel Brief: Navia Benefit Solutions: Silent 24-Day Breach Exposes 2.7 Million Across Client Organizations
Navia Benefit Solutions, a third-party employee benefits administrator serving hundreds of U.S. organizations, has disclosed a data breach affecting nearly 2.7 million individuals across its client base. Attackers mainta
INTEL 2026-03-26
Intel Brief: University of Mississippi Medical Center: Ransomware Forces Statewide Clinic Shutdown, EHR Systems Offline
The University of Mississippi Medical Center (UMMC), Mississippi's only academic medical center and a system accounting for approximately 2% of the state's economy, has been hit by a ransomware attack that forced the shu
INTEL 2026-03-26
Intel Brief: Mazda: Vulnerability Exploitation in Warehouse Management System
Mazda Motor Corporation confirmed on March 19, 2026 that an external threat actor exploited unpatched vulnerabilities in an internal warehouse management system, exposing 692 records of employee, group company, and busin
INTEL 2026-03-26
Intel Brief: Marquis: Ransomware Attack Exposes 672K Banking Customers
Marquis, a Plano, Texas-based fintech company providing customer data analytics and marketing compliance tools to hundreds of community and regional banks, has confirmed that a ransomware attack from August 2025 exposed
INTEL 2026-03-26
Intel Brief: Lockheed Martin: Pro-Iran APT Claims 375TB Breach, Demands $400M Ransom
A pro-Iran threat actor tracked as APT Iran claims to have breached Lockheed Martin, the world's largest defense contractor, exfiltrating 375 terabytes of data including alleged blueprints of the F-35 fighter jet. The gr
INTEL 2026-03-26
Intel Brief: Loblaw Companies: Third-Party Threat Actor Breaches Canada's Largest Retailer
Loblaw Companies Limited, Canada's largest grocery and retail group, has confirmed a data breach after its security team detected unauthorized access to a portion of its internal IT network. A third-party threat actor ga
INTEL 2026-03-26
Intel Brief: AstraZeneca: Lapsus$ Claims 3GB Breach of Internal Code, Credentials, and Employee Data
Cybercrime group Lapsus$ has claimed responsibility for breaching AstraZeneca, one of the world's largest pharmaceutical companies, alleging theft of approximately 3GB of sensitive internal data including source code rep
INTEL 2026-03-26
Intel Brief: Kaplan: Server Intrusion Exposes SSNs and Driver's Licenses of 230,000+ Students and Professionals
Kaplan, the Florida-based educational services company serving approximately 1.2 million students annually, reported a data breach to state regulators in at least seven US states confirming that Social Security numbers a
INTEL 2026-03-26
Intel Brief: Kaplan: Network Intrusion Exposes 1.4 Million SSNs and Driver's License Numbers
Kaplan, the Graham Holdings-owned educational services giant serving approximately 1.2 million students and 15,000 corporate clients globally, has confirmed a data breach that ultimately affected 1.4 million individuals;
INTEL 2026-03-26
Intel Brief: IDMerit: Unauthenticated MongoDB Exposes 1 Billion KYC Records
IDMerit, an AI-powered identity verification provider processing know-your-customer (KYC) checks for banks and cryptocurrency exchanges, left a MongoDB database publicly accessible without authentication for 99 days; exp
INTEL 2026-03-26
Intel Brief: Hikvision: ALP-001 Claims 199TB Breach of World's Largest Surveillance Manufacturer ⚠️ Unverified
**Intelligence confidence: LOW.** ALP-001 ransomware claims carry documented fabrication warnings across threat intelligence platforms, and Hikvision has not issued a public statement confirming any breach. This brief co
INTEL 2026-03-26
Intel Brief: Cnous France: Data Breach Exposes 774,000 University Records
France's Centre national des œuvres universitaires et scolaires (Cnous) (the government body managing student welfare services including housing, dining, and financial aid for the national university system) has confirme
INTEL 2026-03-26
Intel Brief: France FICOBA: Credential Theft Exposes 1.2M National Bank Records
France's tax authority (DGFiP) confirmed on February 18, 2026 that an attacker spent 16 days inside FICOBA, the national registry of every bank account opened in France, using a single stolen civil servant's credentials.
INTEL 2026-03-26
Intel Brief: France: Criminal Data Broker Mega-Aggregation Exposes 45M Citizens
Cybernews researchers have confirmed the discovery of a publicly exposed cloud database containing approximately 45 million French citizens' records; one of the largest data exposures in French history. The archive is no
INTEL 2026-03-26
Intel Brief: Foster City, California: Ransomware Attack Forces State of Emergency Declaration
Foster City, California (a Bay Area municipality of approximately 34,000 residents) has declared a formal state of emergency following a ransomware attack that took down the city's entire network. The city council approv
INTEL 2026-03-26
Intel Brief: FBI New York Field Office: Human Error Exposes Epstein Investigation Server to Foreign Hacker
The FBI has confirmed that a foreign hacker infiltrated a server at its New York field office in February 2023, gaining unauthorized access to sensitive investigative files related to Jeffrey Epstein. The breach, charact
INTEL 2026-03-26
Intel Brief: Dutch Ministry of Finance: Unauthorized Access to Policy Department Systems
The Dutch Ministry of Finance confirmed on March 24, 2026 that its systems were breached in a cyberattack detected the previous Thursday, March 19. Unauthorized access was gained to systems supporting primary processes w
INTEL 2026-03-26
Intel Brief: Social Security Administration: DOGE Insider Data Exfiltration
The Social Security Administration's inspector general is investigating a whistleblower complaint alleging that a former U.S. DOGE Service software engineer exfiltrated two of the federal government's most sensitive citi
INTEL 2026-03-26
Intel Brief: DigitalMint Negotiator Charged: Ran Ransomware Attacks While Negotiating for Victims
The DOJ has unsealed charges against Angelo John Martino III, a former ransomware negotiator at DigitalMint, accusing him of conducting at least 10 ransomware attacks while simultaneously negotiating ransom payments on b
INTEL 2026-03-26
Intel Brief: Crunchyroll (Sony): Third-Party Vendor Malware, 100GB Exfiltration, $5M Extortion
Crunchyroll, the Sony-owned anime streaming platform with tens of millions of subscribers globally, has confirmed a data breach stemming from a malware infection on a third-party vendor employee's device. A single threat
INTEL 2026-03-26
Intel Brief: Conduent: Covert Intrusion Exposes 25 Million Americans' Government Benefits Data
Conduent, a business process services giant that administers healthcare eligibility, Medicaid, SNAP benefits, and other government programs for hundreds of US agencies, suffered a covert network intrusion between October
INTEL 2026-03-26
Intel Brief: Cognizant TriZetto: 11-Month Undetected Intrusion Exposes 3.4M Patient Records
Cognizant's healthcare IT subsidiary TriZetto Provider Solutions has disclosed a data breach affecting more than 3.4 million patients across the United States. Unauthorized access began in November 2024 and went undetect
INTEL 2026-03-26
Intel Brief: CIRO: Phishing Attack Exposes 750,000 Canadian Investors
Canada's Investment Regulatory Organization (CIRO) has confirmed a data breach affecting up to 750,000 investors, stemming from a phishing attack that occurred in August 2025. The breach, initially disclosed as limited t
INTEL 2026-03-26
Intel Brief: Chile's Ley del Lobby Platform: Government Lobbying Records Breach Exposes 8 Years of Political Intelligence
An unidentified threat actor claims to have breached Chile's official Ley del Lobby platform, the government's mandatory lobbying transparency registry, and exfiltrated 250 gigabytes of lobbying records spanning 2018 to
INTEL 2026-03-26
Intel Brief: Sweden E-Government / CGI Sverige: National Codebase Leak
The full source code of Sweden's e-government platform has been leaked to the dark web following a confirmed breach of CGI Sverige, the Swedish subsidiary of CGI Group; one of the world's largest IT and business consulti
INTEL 2026-03-26
Intel Brief: CarGurus: ShinyHunters Breach Exposes 12.4 Million User Records
CarGurus, one of the largest online automotive marketplaces in the United States with over 30 million monthly visitors, has suffered a confirmed data breach linked to the ShinyHunters threat group. Approximately 12.4 mil
INTEL 2026-03-26
Intel Brief: BMW & 35+ Automakers: IDOR Exploit Fuels Ongoing Multi-Brand Data Exfiltration
A threat actor tracked as **xpl0itts**, collaborating with groups DarkRomance and teamPCP, claims an ongoing and expanding data exfiltration campaign against BMW and at least 35 additional automakers (including Toyota, M
INTEL 2026-03-26
Intel Brief: Bell Ambulance: Medusa Ransomware Exposes 238,000 Patients' Healthcare and Identity Data
Bell Ambulance, a US emergency medical services provider offering ambulance transport and paramedic care, confirmed a ransomware attack that exposed the personal and healthcare data of 237,830 individuals. The Medusa ran
INTEL 2026-03-26
Intel Brief: Aura: ShinyHunters Voice Phishing Attack, 900,000 Records Leaked
Aura, a consumer digital safety company selling identity theft protection, credit monitoring, and fraud protection services, confirmed on March 18, 2026 that ShinyHunters stole approximately 900,000 customer records via
INTEL 2026-03-26
Intel Brief: AkzoNobel: Anubis RaaS, 170GB Exfiltration from US Facility
AkzoNobel, the Dutch multinational paints and coatings company behind Dulux, Sikkens, International, and Interpon, confirmed a cyberattack at one of its US facilities after the Anubis ransomware gang published sample dat
INTEL 2026-03-13
Intel Brief: CVE-2026-3910
Google Chromium V8 contains a memory buffer vulnerability allowing remote code execution via crafted HTML pages, affecting multiple web browsers.
INTEL 2026-03-13
Intel Brief: CVE-2026-3909
CISA has added a Google Skia out-of-bounds write vulnerability to its Known Exploited Vulnerabilities catalog, mandating remediation by late March 2026.
INTEL 2026-03-11
Intel Brief: CVE-2026-24512
This high-severity vulnerability in ingress-nginx allows attackers to inject configuration via Ingress fields, resulting in arbitrary code execution and potential secret disclosure.
INTEL 2026-03-10
Intel Brief: CVE-2024-21762 FortiOS Out-of-Bound Write Vulnerability
This critical vulnerability in Fortinet FortiOS and FortiProxy allows unauthenticated remote code execution and is currently listed as a known exploited vulnerability by CISA.
INTEL 2026-03-09
Threat Brief: CVE-2025-26399 SolarWinds Web Help Desk RCE
A critical unauthenticated remote code execution vulnerability in SolarWinds Web Help Desk AjaxProxy is now listed on CISA’s Known Exploited Vulnerabilities catalog.
INTEL 2026-03-07
CVE-2017-7921: Hikvision Improper Authentication Vulnerability
Hikvision IP cameras contain a critical improper authentication flaw allowing privilege escalation and unauthorized data access.
INTEL 2026-03-07
CVE-2024-3400: PAN-OS Command Injection
A command injection in GlobalProtect portal/gateway on Palo Alto PAN-OS.