LIVE · cybersecurity feed
Live wire
CVE-2026-66066 · KindaRails2Shell threatens Ruby on Rails apps (CVE-2026-66066)Rails patches critical Active Storage flaw with RCE potentialCVE-2026-48449 · Adobe fixed a maximum-severity vulnerability flaw in Campaign ClassicRuby on Rails Patches Critical VulnerabilityHackers Poison Adform Script to Swap Crypto Wallet Addresses Across Customer SitesHijacked Hotel Wi-Fi Pushes Fake Updates to Deliver Surveillance MalwareCaptiveCrunch: Midnight Blizzard targets travelers worldwide for malware delivery and credential theftHollowFrame Loader Deploys Matryoshka Backdoor in Spear-Phishing Attack on Law FirmCVE-2026-33017 · Chinese Hacker Uses DeepSeek AI to Orchestrate Vulnerability ExploitsThis month in security with Tony Anscombe – July 2026 edition
breach

ExfilSquad hackers leak info of over 100,000 UK police officers, staff

A cyberattack on the U.K.'s Police National Legal Database (PNLD) has compromised contact data of more than 100,000 police officers and other criminal justice professionals. [...]

zeroday.news · 1h ago

A cyberattack on the UK's Police National Legal Database (PNLD) has led to the compromise of contact data for over 100,000 police officers and other criminal justice professionals. The incident, detected on Sunday, July 26, was later claimed by the ExfilSquad data extortion group, which alleges it stole 135,000 contact records.

PNLD, an online legal resource used by the 43 Home Office police forces in England and Wales, as well as the British Transport Police for over 30 years, confirmed the breach. The service also operates "Ask the Police," a public-facing website.

According to PNLD, the breach exposed the full names, organizations, and email addresses of police officers, staff, criminal justice professionals, and government partners. Additionally, the names and email addresses of users who submitted questions through the "Ask the Police" platform were also compromised.

The ExfilSquad group claimed responsibility for the attack and published sample data to substantiate its claims. The group also demanded a ransom to prevent the release of the remaining stolen data. ExfilSquad asserts it stole 1.9 GB of data from PNLD, comprising approximately 135,000 records, which includes information belonging to 114,000 PNLD subscribers and 21,000 "Ask the Police" users.

PNLD has initiated an investigation into the incident with the assistance of cybersecurity experts and the National Crime Agency (NCA). The organization stated that no evidence has been found to suggest that passwords or other security credentials were compromised.

The affected party confirmed that PNLD does not store confidential information related to victims, witnesses, or offenders, and no such data was impacted in the breach. All affected organizations were contacted in the days following the incident and provided with further information and guidance. The Information Commissioner's Office (ICO) has also been notified.

While PNLD has confirmed the breach and the publication of contact details, it has not publicly attributed the intrusion or disclosed the method by which attackers gained access to its systems. ExfilSquad is known for other recent cyberattacks, including one on the American semiconductor company Analog Devices.

breachnation-state
ShareXLinkedInWhatsAppFacebook

More News

view all →
security

Why Bitcoin Businesses Are Moving to Dedicated VPS Infrastructure

A Bitcoin business rarely runs a simple website. Payment processors, exchanges, wallet services, blockchain analytics products and Lightning…

ai

Is your SD-WAN ready for AI-powered operations?

AI is shifting enterprise traffic from human-initiated to machine-generated workflows. Discover why Cisco SD-WAN must evolve to provide the visibility, policy enforcement, and performance assurance needed to support AI operations at scale.

CVE-2026-66066critical

KindaRails2Shell threatens Ruby on Rails apps (CVE-2026-66066)

A critical security vulnerability (CVE-2026-66066) in Ruby on Rails (aka Rails), one of the most widely used frameworks for building websites and web apps, may allow attackers to read sensitive files off a server and, in some cases, take full control of it. Nicknamed “KindaRails2Shell” by the researchers who found it, the flaw lets an attacker sneak a booby-trapped file past a website’s image-uplo

security

HollowFrame Loader Uses Fake Python DLL to Evade Defender

New HollowFrame loader hid Go code in a fake Python DLL after pre-staging Defender exclusions

security

Qodana 2026.2 adds post-quantum crypto checks for JVM code

Qodana 2026.2 shipped with new security inspections, published benchmark results, post-quantum cryptography checks, and coverage reporting that no longer has to be pointed at the reports. The security work sits in the .NET linter and runs by default. Qodana tracks untrusted data across files in C#, JavaScript, and TypeScript, which turns up SQL injection, command injection, cross-site scripting, a

vulnerability

CrowdStrike: AI is now both the weapon and the target in cyberattacks

AI generates 2.5 signals for every human-triggered signal CrowdStrike has to assess. Meanwhile, attackers are using AI to weaponize vulnerabilities faster than companies can patch them. The post CrowdStrike: AI is now both the weapon and the target in cyberattacks appeared first on CyberScoop.