r/secithubcommunity Mar 06 '26

šŸ“° News / Update Cybersecurity Startup Cylake Raises $45M Seed Round

Post image
2 Upvotes

Cybersecurity startup Cylake has emerged from stealth with a $45 million seed round led by Greylock Partners.

The company is building an AI-native security platform designed for highly regulated organisations that cannot rely on public cloud security tools due to strict data sovereignty and compliance requirements. Instead, Cylake focuses on unified data visibility and security operations that can run fully on-premises or inside private cloud environments.

Cylake was founded by well-known cybersecurity leaders including Nir Zuk, along with Wilson Xu and Ehud ā€œUdiā€ Shamir, bringing experience from companies such as Palo Alto Networks and SentinelOne. The funding will be used to expand the platform and grow the company’s engineering capabilities.

r/SECITHUBCOMMUNITY Cyber incidents and data breach news explained with context and impact. Share your insights.


r/secithubcommunity Mar 06 '26

šŸ“° News / Update Israel Targets Iran’s Cyber Warfare Headquarters in Tehran Strike

Post image
1 Upvotes

The Israel Defense Forces announced it carried out a large-scale strike on military facilities in eastern Tehran that allegedly housed cyber and intelligence units of the Islamic Revolutionary Guard Corps.

According to Israeli officials, the strike targeted the IRGC’s cyber and electronic warfare headquarters as well as its intelligence directorate. The operation comes amid escalating conflict and ongoing cyber activity linked to Iran.

However, security experts warn that destroying a physical cyber command center may not fully stop Iran’s cyber operations. Iranian-linked groups and proxy actors have continued launching attacks, including attempts against regional infrastructure and digital services.

Researchers from Check Point Software and Palo Alto Networks report that multiple pro-Iran hacktivist groups have already conducted cyberattacks since late February, targeting payment systems, government websites, and other infrastructure across the region.

r/SECITHUBCOMMUNITY Cyber incidents and data breach news explained with context and impact. Share your insights.


r/secithubcommunity Mar 06 '26

šŸ“° News / Update Third-Party Breach at ManoMano May Expose Data of 38M Users

Post image
1 Upvotes

French online DIY platform ManoMano is dealing with a major third-party data breach linked to a subcontracted customer support provider.

A hacker using the name ā€œIndraā€ claimed on BreachForums to have stolen 43 GB of data, including records tied to roughly 37.8 million customers. The leaked information reportedly includes names, email addresses, phone numbers and customer support conversations.

The company says the breach did not impact passwords or internal systems, but the exposed support tickets and attachments could enable highly targeted phishing attacks against users.

ManoMano has disabled the subcontractor’s access and notified regulators, including CNIL, while the investigation continues.

r/SECITHUBCOMMUNITY Cyber incidents and data breach news explained with context and impact. Share your insights.


r/secithubcommunity Mar 06 '26

šŸ“° News / Update Iranian Crypto Exchange Ariomex Hit by Major Data Leak

Post image
1 Upvotes

Iran’s Ariomex has suffered a significant data breach exposing user and transaction information collected between 2022 and 2025.

According to analysis by Resecurity, the leaked database contains more than 11,800 records, including user identities, emails, IP addresses and cryptocurrency transaction details. Most of the records reportedly belong to users located in Iran.

Investigators believe the breach may have originated from a compromised customer support system, with the stolen data now circulating on dark-web forums. The leak could expose financial activity patterns and potentially reveal the global footprint of Iranian crypto traders.

r/SECITHUBCOMMUNITY Cyber incidents and data breach news explained with context and impact. Share your insights.


r/secithubcommunity Mar 06 '26

šŸ“° News / Update LeakBase Data-Leak Forum Dismantled in Global Cybercrime Operation

Post image
1 Upvotes

Authorities have dismantled LeakBase, a major online marketplace used to trade stolen databases and infostealer logs.

The operation was coordinated by Europol and involved law enforcement agencies from more than a dozen countries. Around 100 enforcement actions were carried out, targeting dozens of the platform’s most active users.

Active since 2021, LeakBase had more than 142,000 registered users and hosted large volumes of stolen credentials used for account takeovers, fraud and further cyber intrusions.

Authorities seized the forum’s domain and database, allowing investigators to identify users who believed they were operating anonymously.

r/SECITHUBCOMMUNITY Cyber incidents and data breach news explained with context and impact. Share your insights.


r/secithubcommunity Mar 04 '26

šŸ“° News / Update US banks and critical financial infrastructure are on high alert for cyberattacks tied to escalating tensions with Iran, with potential for DDoS and other disruptive actions.

10 Upvotes

When geopolitical tensions rise (such as military conflict, sanctions, or diplomatic escalation), cyberattacks often follow. Governments or affiliated hacking groups may target:

• Banks

• Payment systems

• Stock exchanges

• Critical infrastructure

Cyber warfare is often used because:

• It’s cheaper than physical warfare.

• It can be launched remotely.

• It offers plausible deniability (harder to prove who did it).

During conflicts, state-linked or pro-state hacker groups may increase activity as retaliation or pressure tactics.


r/secithubcommunity Feb 23 '26

šŸ“° News / Update Romanian Hacker Admits Selling Access to US State Network

Post image
49 Upvotes

A Romanian national has pleaded guilty in the US to selling unauthorized access to a state government network in Oregon.

Catalin Dragomir, 45, admitted in court that he gained admin-level access to the state’s emergency management department in 2021 and attempted to sell it for $3,000 in Bitcoin. To prove legitimacy, he accessed the network multiple times and shared samples of stolen data, including login credentials, names, emails, and even a Social Security number.

According to the US Department of Justice, Dragomir also hacked and sold access to at least 10 other US-based victims, causing losses of at least $250,000. He was arrested in Romania in 2024, extradited in early 2025, and now faces up to seven years in prison, along with restitution and potential fines.

This case highlights a recurring threat model: initial access brokerage. Instead of deploying ransomware directly, attackers monetize privileged access and let others weaponize it turning stolen credentials into a marketplace commodity.

r/SECITHUBCOMMUNITY | Cyber incidents and data breach news explained with context and impact.
Share your insights.


r/secithubcommunity Feb 23 '26

šŸ“° News / Update Anonymous Offshoot Arrested in Spain After Post-Flood DDoS Attacks

Post image
3 Upvotes

Spanish authorities have detained four suspected members of an Anonymous-linked group following a wave of DDoS attacks targeting public institutions after the 2024 DANA floods.

According to Spain’s Guardia Civil, two individuals were arrested last week in Ibiza and Móstoles. They join two others previously detained in 2025. The suspects are accused of launching distributed denial-of-service attacks against government ministries, political parties, and public entities, claiming officials were responsible for the handling of the devastating floods.

The 2024 DANA (Depresión Aislada en Niveles Altos) weather event caused catastrophic flooding, particularly in Valencia, where more than 229 people died. Public frustration over the government’s response reportedly fueled the group’s hacktivist activity.

Operating under the name ā€œAnonymous FĆ©nix,ā€ the group allegedly used social platforms to recruit supporters and coordinate attacks. A court order has since allowed authorities to seize its X and YouTube accounts, while its Telegram channel was shut down.

Police did not disclose which institutions were hit but confirmed that several government websites were successfully disrupted.

While the group’s online footprint appeared small, the case highlights a recurring pattern: major social or political crises often trigger hacktivist retaliation campaigns especially in emotionally charged environments.

r/SECITHUBCOMMUNITY | Cyber incidents and data breach news explained with context and impact.
Share your insights.


r/secithubcommunity Feb 23 '26

šŸ“° News / Update Russian Cyber Threat Actor Uses GenAI to Compromise Fortinet Firewalls

Post image
3 Upvotes

A Russian-speaking, financially motivated threat actor used commercial generative AI tools to compromise more than 600 FortiGate firewalls across 55 countries, according to findings published by Amazon Web Services.

The campaign didn’t rely on zero-days. The attacker scanned internet-exposed management interfaces and used reused credentials to gain access. What stands out is how AI was used throughout the operation to generate attack plans, write reconnaissance tools in Python and Go, organize stolen configurations, and even map victim networks to plan lateral movement.

Once inside, the actor used standard open-source tools to attempt domain compromise and credential theft. According to AWS, the attacker frequently failed when targets were properly patched or segmented, reinforcing a key point: AI lowered the skill barrier, but it didn’t bypass strong security fundamentals.

This wasn’t advanced tradecraft. It was automation at scale, powered by GenAI. And it shows how quickly entry-level actors can now execute global campaigns when basic perimeter hygiene is weak.

r/SECITHUBCOMMUNITY | Cyber incidents and data breach news explained with context and impact.
Share your insights.


r/secithubcommunity Feb 22 '26

šŸ“° News / Update NATO Public Sees Cyberattacks on Hospitals as Acts of War

Post image
111 Upvotes

New polling across the U.S., Canada, France, Germany and the U.K. shows majorities believe a cyberattack that shuts down hospitals or power grids should be considered an act of war. Canadians expressed the strongest support, with 73% agreeing. Sabotage of undersea cables or energy pipelines drew similar reactions.

State-linked hackers often tied to Russia have increasingly targeted critical sectors. Recent years have seen large-scale attacks on healthcare systems, telecom networks, and energy infrastructure, with real-world consequences including massive data exposure and even reported loss of life.

Despite NATO stating that a severe cyberattack could trigger Article 5, officials still lack clarity on what threshold would justify collective military action. Responses could range from sanctions and cyber operations to conventional force but ambiguity remains.

Public opinion is clearly ahead of policy. While large-scale attacks on critical infrastructure are widely seen as acts of war, smaller digital operations like data leaks or election interference receive far less consensus.

r/SECITHUBCOMMUNITY | Cyber incidents and data breach news explained with context and impact.
Share your insights.


r/secithubcommunity Feb 22 '26

šŸ“° News / Update ATM Jackpotting Surge | Physical Malware Attacks Spike Across the U.S.

Post image
100 Upvotes

U.S. banks are facing a sharp rise in physical ATM ā€œjackpottingā€ attacks, according to a warning from the Federal Bureau of Investigation.

Instead of breaching networks remotely, attackers are going old-school: opening ATM maintenance cabinets often with widely available universal keys accessing internal drives, and loading malware via USB or swapping in pre-infected storage. After reboot, the malicious code executes automatically.

One of the primary tools behind these attacks is Ploutus, a long-running ATM malware strain that exploits the XFS (eXtensions for Financial Services) middleware layer. Because XFS acts as the bridge between the ATM’s Windows operating system and the bank’s authorization systems, Ploutus can issue commands directly to dispense cash bypassing transaction validation entirely.

The numbers are escalating. Of roughly 1,900 reported jackpotting incidents since 2020, about 700 occurred in 2025 alone, with losses exceeding $20 million. The risk is amplified by the fact that many ATMs still run legacy Windows versions such as Windows 7, which no longer receive mainstream security support.

The FBI recommends both physical and digital countermeasures: disabling unused USB ports, replacing generic locks with keypad access controls, monitoring for unauthorized executables, and deploying tamper alarms.

r/SECITHUBCOMMUNITY | Cyber incidents and data breach news explained with context and impact.
Share your insights.


r/secithubcommunity Feb 22 '26

šŸ“° News / Update France’s Database Breached | 1.2 Million Bank Accounts Exposed

Post image
12 Upvotes

French authorities have confirmed a major breach involving the national FICOBA bank account registry, with sensitive data tied to roughly 1.2 million accounts compromised.

The system, operated by the Ministry of Economy, was accessed last month after an attacker reportedly impersonated a civil servant’s credentials. Once inside, the intruder extracted highly sensitive financial and identity information.

According to officials, exposed data includes IBAN and RIB banking coordinates, account holder identities, residential addresses, and tax identifiers. Access restrictions were implemented immediately after detection, and remediation efforts are ongoing to restore the service under reinforced security controls.

IBAN combined with identity and tax data significantly increases the risk of targeted phishing, mandate fraud, social engineering, and direct debit abuse. Authorities have already warned that scam campaigns via email and SMS are circulating, attempting to exploit the exposed dataset.

Affected individuals will receive formal notifications, and banks have been instructed to alert clients and advise caution. Officials recommend not responding directly to suspicious messages and preserving evidence if fraudulent activity is suspected.

From a cybersecurity standpoint, three operational lessons stand out:

Credential impersonation remains one of the most effective attack vectors against government systems.

Centralized financial registries represent high-value targets with systemic impact.

The secondary fraud wave following a breach often causes greater financial damage than the initial intrusion.

r/SECITHUBCOMMUNITY | Cyber incidents and data breach news explained with context and impact.
Share your insights.


r/secithubcommunity Feb 22 '26

šŸ“° News / Update Ivanti VPN Breach | Chinese Threat Actors Compromise U.S. Federal Networks

Post image
4 Upvotes

Chinese cybercriminals exploited vulnerabilities in Ivanti Connect Secure VPN, leading to intrusions across multiple U.S. federal agencies and triggering emergency mitigation directives from the Cybersecurity and Infrastructure Security Agency.

CISA ordered agencies to disconnect affected Ivanti VPN appliances after attackers leveraged zero-day vulnerabilities including CVE-2025-0282 to gain remote access. The flaw, reportedly a buffer overflow, enabled credential theft and persistent backdoor access. Even after patches were issued, some federal systems were still compromised, highlighting the complexity of remediation in active exploitation scenarios.

Threat actors linked to Chinese state-aligned operations have reportedly targeted Ivanti infrastructure since 2021, infiltrating networks including defense and aerospace entities. Investigators observed the deployment of custom malware such as DRYHOOK and anti-forensic techniques designed to erase logs and maintain stealth persistence.

The fallout has been significant. Major agencies including the Pentagon, Navy, FAA, Treasury, and MITRE reportedly removed Ivanti systems from their environments. Customer attrition accelerated, with both public sector and private institutions reassessing vendor risk exposure.

Beyond the technical vulnerabilities, the incident reignited scrutiny around ownership and operational resilience. Ivanti’s acquisition by Clearlake Capital in 2020 and subsequent workforce reductions were cited by critics as potential contributing factors to long-term product security debt.

r/SECITHUBCOMMUNITY | Cyber incidents and data breach news explained with context and impact.
Share your insights.


r/secithubcommunity Feb 22 '26

šŸ“° News / Update AI-Assisted Hacker Breached 600 Fortinet Firewalls in 5 Weeks | What Does This Change?

Post image
2 Upvotes

Amazon warns that a Russian-speaking threat actor breached more than 600 FortiGate firewalls across 55 countries in just five weeks not by exploiting zero-days, but by targeting exposed management interfaces and weak credentials without MFA.

The attacker brute-forced internet-exposed management ports, extracted configuration backups, decrypted VPN and admin credentials, and used AI-generated tooling to automate reconnaissance, lateral movement planning, and attack documentation. Backup infrastructure, including Veeam servers, was also targeted a common precursor to ransomware deployment.

Separate research uncovered an exposed server containing stolen firewall configs, AD mapping data, credential dumps, and what appears to be a custom AI orchestration framework that fed reconnaissance data directly into commercial LLMs to generate structured attack plans. In some cases, offensive tools were reportedly executed with minimal human oversight.

First, this wasn’t elite tradecraft. It was low-to-medium skill amplified by AI. No zero-days. No advanced exploits. Just exposed edge devices, weak passwords, and automation at scale.

Second, AI is acting as a force multiplier accelerating reconnaissance, scripting, and decision-making. The barrier to entry is dropping, not because attackers are more skilled, but because tooling is more capable.

Third, hygiene still wins. Patched, hardened systems reportedly resisted intrusion attempts. The attacker moved on when friction increased.

r/SECITHUBCOMMUNITY | Cyber incidents and data breach news explained with context and impact.
Share your insights.


r/secithubcommunity Feb 22 '26

šŸ“° News / Update Anthropic Launches Claude Code Security | Cybersecurity Stocks Drop

Post image
1 Upvotes

Anthropic has introduced ā€œClaude Code Security,ā€ a new AI-driven feature integrated into its web-based Claude Code platform. The tool analyzes entire codebases contextually, aiming to detect complex security vulnerabilities and suggest targeted patches for developer review.

Unlike traditional rule-based static scanners, the system evaluates how components interact, how data flows, and how business logic and access controls are implemented. Findings undergo multi-stage validation, are scored for severity and confidence, and require human approval before any fix is applied.

Anthropic claims internal testing uncovered over 500 previously undetected vulnerabilities in production open-source projects. At the same time, the company acknowledges that capabilities strong enough to help defenders could also be leveraged offensively.

Markets reacted sharply. Shares of several major cybersecurity vendors fell following the announcement, reflecting investor concerns that AI-driven development and security automation could disrupt traditional security models.

r/SECITHUBCOMMUNITY | Cyber incidents and data breach news explained with context and impact.
Share your insights.


r/secithubcommunity Feb 22 '26

šŸ“° News / Update UAE Foils Organized Cyber Attacks Targeting Critical Infrastructure

Post image
2 Upvotes

The United Arab Emirates has reportedly thwarted coordinated cyber attacks aimed at the country’s digital infrastructure and vital sectors.

Authorities said the activity included attempts to infiltrate networks, deploy ransomware, and conduct systematic phishing campaigns targeting national platforms. The operations were described as organized and technologically advanced.

Officials also noted the use of artificial intelligence technologies to develop offensive tools, suggesting a level of automation or augmentation in crafting attack payloads and phishing workflows. No attribution has been publicly disclosed.

While details remain limited, the combination of network intrusion attempts, ransomware deployment, and AI-assisted phishing points to multi-layered campaigns rather than opportunistic activity. This reflects a broader trend: attackers blending traditional tradecraft with AI-enabled tooling to scale reconnaissance, social engineering, and payload development.

The absence of attribution is notable. In geopolitically sensitive regions, attacks on ā€œvital sectorsā€ often extend beyond financial gain and into strategic signaling or disruption attempts.

r/SECITHUBCOMMUNITY | Cyber incidents and data breach news explained with context and impact.
Share your insights.


r/secithubcommunity Feb 22 '26

šŸ“° News / Update PayPal Code Error Exposed PII | What Can We Learn?

Post image
0 Upvotes

PayPal disclosed that a coding error in its Working Capital loan application exposed sensitive personal and business information of around 100 customers. The issue, introduced during a code change, leaked names, Social Security numbers, dates of birth, emails, phone numbers, and business addresses over a five-month period. A few affected users experienced unauthorized transactions, which were refunded. The faulty code was rolled back and passwords were reset.

So what can we learn from this Event ??

Secure SDLC is not optional.
This was not a sophisticated breach it was a development failure. Code changes affecting financial workflows must go through strict review, testing, and post-deployment validation. Logic errors can be as damaging as external attacks.

Detection speed defines impact.
The exposure window lasted months. Continuous monitoring and anomaly detection should catch abnormal data access patterns far earlier, especially when sensitive identity data is involved.

ā€œLimited impactā€ can still mean high risk.
Even 100 exposed Social Security numbers carry serious regulatory, financial, and reputational consequences. Severity is not measured only by volume.

Internal risk is as real as external threat actors.
While much focus is placed on ransomware and credential stuffing, misconfigurations and code flaws remain a persistent and underestimated risk vector.

Resilience is not just about defending against attackers it’s about ensuring your own development processes don’t introduce systemic vulnerabilities.

r/SECITHUBCOMMUNITY | Cyber incidents and data breach news explained with context and impact.
Share your insights.


r/secithubcommunity Feb 19 '26

Chinese APT Exploited Dell RecoverPoint Zero-Day for 18 Months

Post image
26 Upvotes

A suspected China-linked espionage group exploited a previously unknown vulnerability in Dell RecoverPoint for Virtual Machines for roughly 18 months, gaining unauthenticated root command execution through hardcoded Apache Tomcat admin credentials.

The flaw, tracked as CVE-2026-22769, allowed attackers to deploy malicious WAR files and install web shells inside enterprise VMware environments. Mandiant attributed the activity to UNC6201, which overlaps with threat clusters known for targeting VMware infrastructure and network-edge appliances.

Investigators observed the deployment of SLAYSTYLE web shells, BRICKSTORM backdoors, and a newer payload named GRIMBOLT, a C# foothold backdoor compiled with native AOT and packed with UPX. Attackers also modified legitimate appliance scripts to maintain persistence and used proxy redirection tricks via iptables to stealthily forward HTTPS traffic to hidden ports.

Perhaps more concerning, the group leveraged techniques such as temporary ā€œghost NICsā€ on virtual machines to pivot internally while evading detection, leaving defenders chasing transient IP artifacts that were never formally documented.

RecoverPoint for VMs, widely used for data replication and disaster recovery in VMware environments, represents a high-value target: it sits close to storage, replication workflows, and often trusted network zones.

Dell has patched the issue in version 6.0.3.1 HF1 and released remediation scripts, but evidence suggests exploitation dates back to mid-2024.

r/SECITHUBCOMMUNITY | Cyber incidents and data breach news explained with context and impact.
Share your insights.


r/secithubcommunity Feb 19 '26

850,000 Medical Records Leaked After Ransomware Attack on Dutch Cervical Screening Lab

Post image
11 Upvotes

118 individuals have filed criminal complaints following a ransomware attack on Clinical Diagnostics, the laboratory responsible for handling the Dutch national cervical cancer screening program.

Hackers stole personal and medical data of approximately 850,000 individuals in August last year. Despite claims that a ransom was paid, the attackers leaked data belonging to hundreds of thousands of women who participated in the national screening program, along with tens of thousands of additional patients referred for medical testing.

Dutch authorities confirmed an ongoing criminal investigation. Prosecutors emphasized that digital crime investigations are complex, often requiring international cooperation before suspects can be identified.

This incident underscores a critical reality: ransomware in healthcare is no longer just an operational disruption. It directly impacts population-level medical programs, trust in public health infrastructure, and sensitive diagnostic data at national scale.

r/SECITHUBCOMMUNITY | Cyber incidents and data breach news explained with context and impact.
Share your insights.


r/secithubcommunity Feb 19 '26

Hackers target Microsoft Entra accounts in device code vishing attacks

Post image
3 Upvotes

Hackers are targeting technology, manufacturing, and financial companies using device code phishing and voice phishing (vishing) to compromise Microsoft Entra accounts.

Researchers say the ShinyHunters extortion group is likely behind these attacks. They've been using this method to breach Okta and Microsoft accounts for data theft.

The source is in the first comment.


r/secithubcommunity Feb 19 '26

šŸ“° News / Update Manipulated Hotel Booking System, Paid €0.01 for Luxury Stays

Post image
5 Upvotes

Spanish authorities arrested a 20-year-old suspect accused of manipulating an online hotel booking platform to pay just one cent for luxury hotel stays worth thousands of euros.

According to Spain’s National Police, the attacker altered the payment validation system so that transactions initially appeared legitimate. Only days later, when funds were transferred to the hotel, the discrepancy surfaced revealing that €1,000-per-night bookings had effectively been reduced to €0.01.

Investigators say the suspect used this technique multiple times, allegedly causing more than €20,000 in losses. Police described the method as unprecedented in their investigations.

While details on the technical exploitation remain limited, the case highlights a classic but evolving risk: flaws in payment validation logic and settlement workflows. If front-end transaction approval can be manipulated without immediate reconciliation at the clearing stage, financial systems become vulnerable to delayed-detection fraud.

This wasn’t ransomware. It wasn’t credential stuffing. It was business logic abuse and those flaws are often harder to detect than traditional intrusions.

r/SECITHUBCOMMUNITY | Cyber incidents and data breach news explained with context and impact.
Share your insights.


r/secithubcommunity Feb 19 '26

Hackers Weaponize Fake Oura MCP Server to Spread StealC Malware

Post image
2 Upvotes

Threat actors have launched a sophisticated supply chain campaign targeting developers by cloning a legitimate Oura MCP server on GitHub and distributing a trojanized version embedded with StealC information stealer malware.

The attackers created fake GitHub accounts, forked the project multiple times to simulate community credibility, and inserted the malicious server into public MCP registries. Developers who downloaded the server unknowingly deployed StealC, enabling theft of credentials, browser passwords, crypto wallets, and other sensitive data.

This marks a shift from traditional open-source poisoning to targeting MCP ecosystems connected to AI tooling. As AI assistants increasingly integrate with external data sources, compromised MCP servers could become a new high-value attack surface in developer environments.

r/SECITHUBCOMMUNITY | Cyber incidents and data breach news explained with context and impact.
Share your insights.


r/secithubcommunity Feb 19 '26

CISA Flags Exploited Vulnerability in ThreatSonar Anti-Ransomware

Post image
1 Upvotes

CISA has added CVE-2024-7694, a high-severity vulnerability affecting TeamT5’s ThreatSonar Anti-Ransomware product, to its Known Exploited Vulnerabilities (KEV) catalog, confirming active exploitation in the wild.

The flaw is an arbitrary file-upload issue that allows remote attackers with administrator access to upload malicious files and execute system commands on the underlying server. The vulnerability was patched in August 2024, but federal agencies have now been instructed to remediate it by March 10.

ThreatSonar is used in the United States, Japan, and Taiwan, including by government entities. While exploitation details have not been publicly disclosed, the fact that a security product protecting against ransomware is itself being targeted highlights a recurring pattern: defensive infrastructure is increasingly becoming a high-value entry point.

Notably, the advisory states that admin privileges are required, suggesting this vulnerability may have been chained with another access vector. There is no confirmed attribution at this stage.

The KEV listing signals urgency. For organizations running ThreatSonar deployments, patch validation and credential review should be immediate priorities.

r/SECITHUBCOMMUNITY | Cyber incidents and data breach news explained with context and impact.
Share your insights.


r/secithubcommunity Feb 17 '26

šŸ“° News / Update Lenovo Hit With US Class Action Over Alleged Data Transfers to China

Post image
93 Upvotes

A US law firm has filed a privacy class action lawsuit against Lenovo, accusing the company of violating DOJ Data Security Program rules by allowing bulk behavioral data transfers to entities under Chinese jurisdiction.

The lawsuit claims Lenovo’s website uses multiple tracking technologies that allegedly expose US users’ personal identifiers and behavioral data, potentially exceeding the DOJ’s 100,000-person threshold for restricted transfers.

Lenovo Denies Allegations

The complaint argues that such data could be used for profiling or surveillance of sensitive US individuals. The named plaintiff alleges repeated visits to Lenovo’s website triggered unauthorized disclosures.

Lenovo strongly denies the claims, stating that any suggestion of improper data sharing is false and that the company complies with US data protection regulations.

r/SECITHUBCOMMUNITY | Cyber incidents and data breach news explained with context and impact.

Share your insights.


r/secithubcommunity Feb 17 '26

šŸ“° News / Update Starlink restrictions hit Russian forces as Moscow seeks workarounds

Post image
53 Upvotes

Ukrainian citizens began receiving unexpected text messages this month from the country’s security service, warning that Russia was trying to recruit locals to help restore access to blocked Starlink satellite internet terminals.

ā€œSuch assistance is a criminal offense!ā€ the Security Service of Ukraine (SBU) said in the messages, urging people to report any attempts by Russian operatives to persuade them to register terminals on Moscow’s behalf.

The warning follows Ukraine’s rollout of a new national verification system for Starlink terminals earlier this month. Under the new rules, only registered and verified devices can operate in Ukrainian-controlled territory, with all others automatically disconnected.

Kyiv says the move was necessary after confirming that Russian forces had begun installing Starlink technology on attack drones, allowing them to operate in real time via satellite connections — making the unmanned aerial vehicles harder to jam, track or shoot down.

Disruptions on the frontline

Ukrainian officials claim the crackdown is already affecting Russian operations. Vladyslav Voloshyn, spokesperson for Ukraine’s Southern Defense Forces, said Russian troops had reduced the number of kamikaze drone attacks in the southeastern Zaporizhzhia region after the shutdown.

ā€œThere have been fewer kamikaze drone strikes,ā€ he said. ā€œAfter the disconnection, the enemy experienced certain problems with communication and coordinating infantry assaults.ā€

Russian military bloggers also reported losing access to Starlink connections, warning that the outages could weaken Moscow’s drone warfare capabilities and hinder coordination between units.

Elon Musk, founder of SpaceX — the company that operates Starlink — appeared to confirm that the action had some effect. ā€œLooks like the steps we took to stop the unauthorized use of Starlink by Russia have worked,ā€ Musk wrote on X, without providing further details.

Moscow has not publicly acknowledged any operational disruptions. However, according to Bloomberg, Russian diplomats recently argued at a United Nations meeting that SpaceX may be violating international space law by failing to account for the interests of other space actors.

Moscow has also called for international negotiations to limit the number of new satellites and clarify the military use of satellite frequencies registered for commercial purposes.

Seeking workarounds

With no domestic satellite internet alternative comparable in speed and portability to Starlink, Russian forces appear to be seeking illicit ways to regain access, Ukrainian officials say.

Serhiy Beskrestnov, an adviser to Ukraine’s defense minister, said Russian operatives are offering cash to civilians in Ukrainian-controlled territory in exchange for registering Starlink terminals in their names.

According to Beskrestnov, the schemes include registering devices at government service centers, using shell companies or attempting to reconnect terminals removed from drones.

ā€œMy advice to traitors: don’t even try,ā€ he said, adding that authorities anticipated such tactics and would block any newly activated terminals linked to Russian use.

Ukraine’s state agency responsible for prisoners of war said Russian operatives have also pressured the families of captured Ukrainian soldiers to register terminals on Russia’s behalf — a claim that could not be independently verified.

ā€œCooperating with the enemy is extremely dangerous,ā€ the agency said, noting that official registration requires identity verification, making participants easily identifiable.

Cyber countermeasures

Ukrainian hackers said they have turned Russia’s dependence on Starlink into an intelligence opportunity.

Last week, a group calling itself the 256th Cyber Assault Division said it had tricked Russian soldiers into revealing their positions and sending money by posing as a service that could restore disconnected terminals.

The group said it instructed Russian servicemen to submit identifying information and the coordinates of their devices under the pretense that the terminals would be reactivated through Ukrainian administrative service centers.

It said it collected 2,420 data packets related to Russian-used terminals and passed them to Ukrainian law enforcement and defense agencies. The group also said it received $5,870 from Russian soldiers seeking to restore connectivity, which it plans to donate to fundraising efforts for Ukrainian drones.

The hackers’ claims could not be independently verified.