Skip to content
Security matters
Security matters
  • APTs
  • Tijdlijn
  • Kill chain
  • Uitgelicht
  • Privacy
Security matters

Hacker Claims To Have Stolen 3.6 Million Records From McDonald’s, Vodafone and Other Corporate Azure Tenants

post, augustus 18, 2026augustus 24, 2026

A threat actor using the name “TheHatman” is attempting to sell approximately 3.64 million records allegedly collected from the Microsoft Azure and Entra environments of nine major international organisations. The advertised information is linked to McDonald’s, Tata Consultancy Services, Vodafone, HCL Technologies, InterContinental Hotels Group, Kyndryl, Gap, Hexaware Technologies and…

Continue Reading

Windows Task Host flaw now exploited by ransomware gangs

post, augustus 18, 2026augustus 24, 2026

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has confirmed that ransomware gangs are also exploiting a high-severity Windows Task Host vulnerability that was flagged as actively exploited in April. Task Host is a core Windows system component that allows DLL-based processes to run in the background and prevents data…

Continue Reading

Linux Botnet Turns Devices Including Routers Into Persistent Attacker Infrastructure

post, augustus 17, 2026augustus 24, 2026

A newly identified Linux botnet is exploiting years-old security vulnerabilities to compromise routers, firewalls, IP cameras and other internet-facing systems, transforming them into a distributed infrastructure for cyberattacks, credential theft and covert traffic relaying. The malware, named Evooo1Bot, is based partly on the leaked source code of the notorious Mirai…

Continue Reading

French tax authority data breach affects 678,000 individuals

post, augustus 17, 2026augustus 24, 2026

The French Ministry of the Economy and Finance has disclosed a data breach after an attacker accessed the General Directorate of Public Finances (DGFiP) systems and stole data belonging to 678,000 individuals. This incident was discovered after a threat actor using the “ZeroBytes” handle claimed the attack and listed a…

Continue Reading

Franse fiscus komt na bijna twee maanden achter een grote hack

post, augustus 14, 2026augustus 17, 2026

De Franse belastingdienst is gehackt, waarbij de gegevens van bijna 700.000 belastingbetalers zijn buitgemaakt. De hack vond eind juni plaats, maar werd deze week pas ontdekt nadat de hackersgroep met een claim was gekomen. Het ministerie van Financiën zegt dat er woensdag een claim kwam van een “kwaadwillende speler” over een hack…

Continue Reading

Hackers Move Quickly To Exploit Critical Microsoft SharePoint Authentication Bypass

post, augustus 13, 2026augustus 17, 2026

Threat actors have begun targeting internet-facing Microsoft SharePoint servers with exploit code for a critical authentication-bypass vulnerability less than 24 hours after detailed technical research and a public proof of concept were released. The vulnerability, tracked as CVE-2026-55040, affects supported on-premises editions of Microsoft SharePoint Server and carries a critical…

Continue Reading

Russische ransomwaregroep zegt Shell en Philips te hebben gehackt

post, augustus 13, 2026augustus 17, 2026

De Russische hackersgroep Clop claimt Shell en Philips te hebben gehackt. Het is nog onduidelijk wat de impact is. Shell zegt tegen de NOS “op de hoogte te zijn van een mogelijk incident”. Volgens een woordvoerder onderzoekt een team van beveiligingsexperts nog wat er precies is gebeurd.

Continue Reading

Russische ransomwaregroep claimt Shell en Philips te hebben gehackt

post, augustus 13, 2026augustus 17, 2026

De Russische hackersgroep Clop claimt een hack te hebben uitgevoerd bij Shell en Philips. De groep zegt 89 gigabyte aan informatie in handen te hebben van het olieconcern. Van Philips zou 13,5 gigabyte buitgemaakt zijn. Shell en Philips bevestigen tegenover BNR dat er een incident wordt onderzocht. Het is onduidelijk…

Continue Reading

Critical VMware vCenter RCE flaw exploited for reverse SSH access

post, augustus 13, 2026augustus 17, 2026

A recently patched critical vulnerability (CVE-2026-59310) in VMware vCenter Syslog Server is being exploited in an active campaign to deploy a reverse SSH tool for persistence and remote access. Compromises have been identified at 361 IP addresses across 47 countries, more than half located in Germany, the U.S., Turkey, Iran,…

Continue Reading

Smile, You’re on Camera. Part 2: Hiring Lazarus APT’s IT Workers in a Fake DeFi Startup

post, augustus 12, 2026augustus 17, 2026

Back in December, we were the first ever to fully record the Famous Chollima infiltration cycle. From recruiting collaborators to help them land jobs at Western companies, to forging documents, shipping laptops to facilitators’ houses, and even using AI tools for live assistance and translation during interviews. During that investigation,…

Continue Reading
  • Previous
  • 1
  • …
  • 4
  • 5
  • 6
  • …
  • 47
  • Next

2020 2023 2024 2025 2026 China Iran North Korea Russia ShinyHunters

©2026 Security matters | WordPress Theme by SuperbThemes