LIVE · cybersecurity feed
Live wire
ransomware

ExfilSquad Targets New Victims, Shares Data via Torrents

ExfilSquad targets 13 organizations, exploiting cloud portals for data theft and using torrents to spread stolen information and amplify damage. Resecurity is tracking the activity of ExfilSquad – the group announced new victims this week. ExfilSquad is a new cybercrime group that emerged in mid-2026. Instead of using ransomware, it steals data and threatens to […]

zeroday.news ·

The cybercrime group ExfilSquad, which emerged in mid-2026, has announced new victims, targeting 13 organizations across the U.S., the UK, and Sweden. This follows a previous attack in July against a major financial institution in Nigeria. The group's modus operandi involves stealing data and threatening to publish it on a dark web leak site if a ransom is not paid, rather than deploying ransomware.

ExfilSquad has set an August 5, 2026, deadline for negotiations with its latest victims, after which it claims the stolen data will be released. The group's tactics, techniques, and procedures (TTPs) primarily involve exploiting cloud and SaaS portals to facilitate large-scale data theft. Specific targets of exploitation include misconfigured Microsoft Dataverse and Power Pages sites, as well as Case Management and Customer Relationship Management (CRM) systems.

The group gained significant attention following a cyberattack on the U.K.'s Police National Legal Database (PNLD), which resulted in the compromise of contact information for over 100,000 police officers and criminal justice professionals.

A notable tactic employed by ExfilSquad is the use of peer-to-peer (P2P) networks and torrent files to distribute stolen data. This approach, previously observed with ransomware groups like LockBit 3.0 and Cl0p, involves assigning each victim a unique torrent tracker and an initial web seed. This method makes the leaked data easily accessible to a wider audience, including other malicious actors, and complicates efforts to prevent its further circulation due to the decentralized nature of P2P networks.

Cybersecurity researchers have analyzed the nodes and seeds involved in the torrent sharing. Observations from August 7, 2026, indicated that hosts located in China and Russia were among the most active participants in the data circulation. This activity suggests either prior knowledge of the data publication by these operators or their involvement in its distribution once it became available.

ransomwarecloud
ShareXLinkedInWhatsAppFacebook

More News

view all →
CVE-2026-68820high

17th August – Threat Intelligence Report

Several significant cyber incidents were reported this week, including a ransomware attack on Colombia's Ministry of Justice and a data breach affecting Poland's primary healthcare platform, MyDr, potentially exposing data of 19 million citizens. Additionally, Levi Strauss & Co. and IEH Corporation reported cyberattacks involving social engineering and phishing, respectively, with no consumer data compromised in the former. In the realm of AI threats, researchers detailed a suspected China-linked campaign using autonomous AI agents against Taiwanese government systems and noted North Korea-linked Kimsuky's efforts to build an offline AI environment for cyberespionage. Microsoft, Apple, Adobe

ransomware

Philips and GE investigating Clop ransomware data theft claims

Tech giants General Electric (GE) and Philips have also confirmed they're investigating claims that the Clop ransomware gang breached their systems and stole data. [...]

CVE-2026-69414high

ShieldBreak bypasses Microsoft’s patch for earlier Defender flaw

A new vulnerability dubbed ShieldBreak (CVE-2026-69414) has been discovered in Microsoft Defender, which bypasses a previous patch for a similar flaw called RoguePlanet. This elevation of privilege vulnerability requires initial access to a machine and is dependent on Microsoft Defender being active. Microsoft has acknowledged the issue and is working on a fix, advising users to maintain security updates and exercise caution with untrusted code.

CVE-2026-15826critical

WordPress Plugin Flaw Exposes 40,000 Sites to Admin Takeover

A critical vulnerability in the WordPress User Profile Builder plugin, affecting over 40,000 sites, allows unauthenticated attackers to gain administrator access. The flaw, CVE-2026-15826, stems from a type confusion error that can trick the plugin into granting administrative privileges if specific configurations are met, such as the administrator using user ID 1 and automatic login after registration being enabled. The plugin developer has released a patch, version 3.16.5, to address the issue.

security

Hacking Public Wi-Fi DNS to Steal Credentials

Criminals are hacking into public Wi-Fi devices—at hotels, conference centers, and so on—around the world and changing their DNS settings. The goal is to redirect users to fake login pages and steal their credentials.

security

Fake TikTok rewards promise cash you’ll never get

TikTok-branded rewards pages offer cash for simple tasks and daily check-ins. But getting your hands on the money is another story.