news
Breaking Cyber News From Cyberint
Breaking news feed of the latest cyber incidents, breaches, vulnerabilities, malware, ransomware and so much more.
- All Items
- Middle East
- Israel
- Data Encrypted For Impact
- Business Services
- Handala
- Asia
- Jobinfo
- Shelter Locations In Israel
- Saudi Games
- Retail
- Cyber Fattah Team
- Saudi Arabia
- Ben Horin & Alexandrovitz
- Zachary Levi And Sons - Construction
- Sivim It
- Government
- Kibbutz Almog
- Saban Brands Israel
- Manufacturing
- Mprest
- Digitalghost
- The Knesset
- Evil_Byte
- Nobitex
- Gonjeshke Darande
- exclusive
- South-Eastern Asia
- Kimia Farma
- Sentap
- Chemicals And Allied Products
- Indonesia
- Transportation
- Northern Europe
- Scania
- Sweden
- Europe
- Hensi
- Media
- Tbn Israel
- Weizmann Institute Of Science
- Education
- Resistancetrench
- Israeli Air Force
- Israel Antiquities Authority
- Dienet
- North America
- CVE-2025-24016
- Wazuh
- United States
- Cve-2025-24016
- Mirai
- Clayoxtymus1337
- Epsilor Electric Fuel
- Technology
- Southern Asia
- Advanced Weapons And Equipment India
- India
- More_Eggs
- Fin6
- Cryptocurrency
- Alex Lab
- Critical Infrastructures
- Edf Energy
- United Kingdom
- Zoldyck
- Unix Shell
- Credentials In Files
- Spectrum
- Amos
- Disable Or Modify Tools
- Spearphishing Link
- Ingress Tool Transfer
- Match Legitimate Name Or Location
- Sudo And Sudo Caching
- Telecommunications
- Israel Defense Forces
- Food And Kindred Products
- Ghna
- Coca-Cola Europacific Partners
- Southern Europe
- Automotive
- Italy
- Locauto
- Spain
- Whitecoat
- Mercadona
- Wow Health Solutions
- Healthcare
- Ups
- Rip_Real_World
- Cyprus Airways
- Netsupport Rat
- Illeak
- Tel Aviv University
- Desec0X
- Cyberlock
- Lucky_Gh0$T
- Yashma
- Unc6032
- Numero
- Chaos
- Deloitte
- 303
- Gucci
- Command And Scripting Interpreter
- Windows Credential Manager
- Virtualization/Sandbox Evasion
- Credentials From Web Browsers
- Input Capture
- System Information Discovery
- Credentials From Password Stores
- User Execution
- Phishing
- Obfuscated Files Or Information
- Data From Local System
- File And Directory Discovery
- Drive-By Compromise
- Exfiltration Over C2 Channel
- Password Managers
- Eddiestealer
- Screen Capture
- W_Tchdogs
- Australia And New Zealand
- Superloop
- Australia
- Network Service Discovery
- Smb/Windows Admin Shares
- Deploy Container
- Resource Hijacking
- Remote System Discovery
- Escape To Host
- Exploitation For Client Execution
- Change Default File Association
- Web Protocols
- Exploit Public-Facing Application
- Lateral Tool Transfer
- External Remote Services
- Docker
- Eastern Europe
- Cameleon
- Venom Rat
- Romania
- Financial Theft
- Bitdefender
- Cisco
- Macao Special Administrative Region
- Cve-2023-20118
- CVE-2023-20118
- Eastern Asia
- Vicioustrap
- Uat-6382
- Trimble
- Tetraloader
- CVE-2025-0944
- Cve-2025-0944
- China
- Reflective Code Loading
- Obfuscated Files Or Information: Encrypted Or Encoded Data
- Scheduled Task
- Rundll32
- Masquerade Task Or Service
- File Deletion
- Dynamic-Link Library Injection
- Powershell
- Valleyrat
- Regsvr32
- Silver Fox
- Process Discovery
- Malicious File
- Trickbot
- Bumblebee
- Warmcookie
- Danabot
- Qakbot
- Cetus
- Purehvnc
- Bytebreaker
- Latin America And The Caribbean
- Viralgod
- Telcel
- Mexico
- Peter Green Chilled
- Cellcom
-
Jun 16, 2025
Threat Actor Claims Breach of Scania’s Insurance Arm, 34,000 Files Allegedly Stolen
A threat actor using the alias "hensi" claims to have breached insurance.scania[.]com, a subdomain of Scania Financial Services, allegedly stealing 34,000 previously unpublished files. The breach, which reportedly targeted the Swedish manufacturer’s corporate insurance division, was announced on a forum on the dark web. Scania’s insurance services cover commercial vehicles—suggesting the stolen data may include sensitive customer and vehicle information, such as VINs. The targeted site is currently offline, citing maintenance, and Scania has yet to comment on the incident.
-
Jun 10, 2025
Threat Actor Claims Breach of UK-based EDF Energy
In June 2025, a threat actor named Zoldyck claimed to have breached EDF Energy Company and to have gained access to its database. According to the threat actor, over 12 million lines of data belonging to EDF's customers were taken, including sensitive information such as customer IDs, full names, dates of birth, national IDs, addresses, email addresses, phone numbers, and payment details.
-
Jun 05, 2025
Coca-Cola Europacific Partners - Breach - 2025-05-22
On May 22, 2025, the threat actor Gehenna claimed responsibility for breaching Coca-Cola Europacific Partners’ Salesforce infrastructure, exfiltrating a substantial volume of business data. The breach reportedly includes over 75 million records spanning accounts, contacts, products, and customer service cases from 2016 to 2025, totaling more than 63 GB of sensitive CRM data. Gehenna, linked to previous incidents involving Samsung Germany and Royal Mail, is offering this data for sale, emphasizing the scale and commercial relevance of the compromised information.
-
Jun 05, 2025
Threat Actor Claims Breach of Locauto Rent
In June 2025, a threat actor named Zoldyck claimed to have breached LocautoRent, an Italian car rental company, and to have gained access to its database. According to the threat actor, approximately 850,000 unique records belonging to LocautoRent's customers were taken, including sensitive data such as customer IDs, tax IDs, names, addresses, emails, phone numbers, and payment methods.
-
Jun 05, 2025
Threat Actor Claims Breach of Mercadona's Home Brand - Hacendado
In June 2025, a threat actor named WhiteCoat claimed to have breached Mercadona's home brand Hacendado through a third-party vendor and to have gained access to its database. According to the threat actor, over 27 million unique users' data was taken, including full names, emails, hashed passwords, location data, purchase history, internal employee emails, operational logs, fragmented payment metadata, and tokens and access credentials.
-
Jun 01, 2025
Deloitte Reportedly Breached, Source Code and GitHub Credentials Leaked
A threat actor known as "303" claimed on the dark net forum "darkforums" to have breached "Deloitte," leaking GitHub credentials and internal source code from a "Deloitte" repository. A sample Git configuration file was posted, showing what appears to be access to a private GitHub project related to Deloitte’s U.S. consulting services. "Deloitte," headquartered in London, is one of the "Big Four" accounting and consulting firms, providing services in audit, tax, consulting, risk, and financial advisory across over 150 countries.
-
Jun 01, 2025
Threat Actor Claims Gucci Supplier Data Leak on darkforum
A threat actor known as "303" claimed on the dark net forum "darkforum" to have compromised a subdomain of the luxury fashion brand "Gucci" and leaked internal documents. The alleged data includes detailed information on Gucci’s suppliers, including their addresses, countries, and the percentage of immigrant workers. The post also contains sample images and a pay-to-unlock download link for the full leak.
-
May 28, 2025
New Malicious Campaign Exploits Fake Antivirus Website to Distribute Venom RAT
Cybersecurity researchers have uncovered a malicious campaign that utilizes a fraudulent website masquerading as Bitdefender's antivirus software to distribute a remote access trojan known as Venom RAT. The site, bitdefender-download[.]com, tricks users into downloading a zip file containing malware disguised as an installer. This campaign aims to compromise victims' credentials and crypto wallets, highlighting a trend of sophisticated, modular malware that leverages open-source components for more effective attacks.
-
May 21, 2025
Peter Green Chilled Reports Shuts Operations Down Following Ransomware Attack
In May 2025, Peter Green Chilled became the victim of a ransomware attack when yet unknown threat actors managed to gain access to its systems, forcing the company to halt operations. According to Peter Green, the attack has severely disrupted its ability to process orders and manage logistics, impacting its supply chain for fresh products supplied to major retailers such as Aldi, Sainsbury’s, and Tesco.