Coca-Cola has confirmed stolen data tied to its dairy subsidiary, while key details about the attackers, scope, and entry point remain unconfirmed.
A PTC design system, a mail platform, and a rewards service all point to the same hard truth: internet-facing business software is still the most attractive shortcut into sensitive data.
Exfilsquad is tied to a fresh victim entry that alleges millions of records, but the breach itself and the data claim remain unverified.
A new ransomware bulletin names servicebypremier.com, but the visible evidence stops short of confirming stolen data or the full intrusion path.
A new victim listing tied to Jubilee Jobs is a reminder that extortion pages can signal risk, while still falling short of proving breach scope, data theft, or real-world disruption.
Internet-exposed Windchill and FlexPLM systems are being tied to a reported data-theft operation, with design files and other sensitive engineering material at the center of the risk.
A victim entry names Zynex and attaches a data-loss figure, but the allegation remains unverified and the content of the data is not described.
A fresh victim page raises a familiar ransomware question: what is verified, what is asserted, and what remains unproven.
CISA and partner agencies say a Russian state-supported campaign is using a Zimbra flaw to pull mail, directory data, and account material from exposed webmail users.
A new extortion-style victim listing tied to Booba Project puts Pelli Clarke Pelli Architects in the spotlight, but the alleged data theft is still only a claim at this stage.
A modular malware campaign tied to ClickFix lures shows how a single user action can become the start of a much larger compromise.
A reported Spirals intrusion finished data theft and file encryption in under 24 hours, a pace that leaves little room for response once access is gained.
A public victim page may signal an extortion phase, but it does not by itself confirm breach, data theft, or encryption.
A new victim entry points to an alleged breach touching hotel and casino records in Northern Cyprus, but the technical path and real scope remain unverified.
Microsoft mapped a year-long campaign tied to ShinyHunters-linked activity that appears to have moved through OAuth trust rather than a Salesforce platform flaw.
Microsoft warned that ShinyHunters-linked tradecraft may be using trusted OAuth relationships to keep Salesforce access alive while bypassing ordinary sign-in checks.
A posted victim entry tied to momenta.cn alleges encryption and theft of business-sensitive files, but the technical root cause and real scope remain unverified.
A newly posted ransomware entry tied to wrtworld.com brings a large data-theft claim into view, but the breach narrative remains unverified.
A victim listing tied to M3rx names FORECON Inc. and claims a large data haul, yet the available facts stop short of confirming the full intrusion story.
A victim post tied to eclective.ie claims a substantial data haul, but the listing remains unverified and the technical path is not established here.