threat-intel Long-running Data Theft Campaign Targeting Salesforce, ServiceNow The "City-Forum" campaign, active since March 2025, has seen a threat actor targeting Salesforce and ServiceNow instances with custom tools to steal data. Unlike traditional attacks relying on publicly available tools, this actor has developed unique techniques to exploit less-documented interfaces, specifically the da… Dark Reading · Aug 12, 2026 High USCAGBsalesforceservicenowguest access
threat-intel Des kiosques Pokémon exposés par une fuite Firebase A clandestine publication alleges that a US-based automated distribution operator exposed sensitive data – including bank details, email addresses, source code, and technical access – across multiple continents via expos… ZATAZ · Aug 10, 2026 High USJPAUdata breachapiauthentication
threat-intel Dysphoria IoT Botnet Adds Blockchain C2 and Victim Relays After JackSkid Disruption The Dysphoria IoT botnet has evolved to become significantly harder to disrupt by incorporating blockchain-based name services and utilizing infected devices as relays. This complex architecture, stemming from the JackSk… The Hacker News · Jul 27, 2026 High CVE-2025-9528JPiotbotnetc2
threat-intel Ransomware Attack Puts a Chill On Japanese Frozen-Food Chain A ransomware attack targeting Nichirei, a Japanese frozen-food supplier and logistics firm, has disrupted its operations and impacted thousands of clients, including Kentucky Fried Chicken franchises in Japan. Russia-lin… Dark Reading · Jul 23, 2026 High JPransomwaresupply chainjapan
threat-intel Japanese food logistics giant recovers as extortion group claims cyberattack Japanese food logistics giant Nichirei Logistics Group has recovered from a cyberattack that disrupted food deliveries nationwide. RansomHouse, a group known for threatening to leak stolen data rather than encrypting it,… The Record · Jul 22, 2026 High JPcyberattackdata breachransomware
threat-intel Cyberattack Disrupts Operations of Japanese Frozen Food Giant Nichirei A cyberattack disrupted operations at Nichirei, a major Japanese frozen food producer, impacting its logistics, warehousing, and shipping services. The company disconnected systems as a precaution, and is investigating a… SecurityWeek · Jul 17, 2026 Medium JPcyberattackdata-breachransomware
supply-chain Cyberattack on Japan's largest cold-chain operator disrupts KFC, supermarket supplies A cyberattack on Japan's largest cold-chain logistics company, Nichirei Logistics Group, has severely disrupted the country's food supply chain, impacting KFC restaurants, supermarkets, and various food manufacturers. Th… The Record · Jul 15, 2026 High JPcyberattacksupply chainjapan
data-breach 12 Million Impacted by Data Breach at Japanese Telco KDDI A data breach at Japanese telecom KDDI has impacted over 12 million users due to a zero-day vulnerability exploited by hackers. The attackers gained access to email addresses and passwords, prompting a company-wide passw… SecurityWeek · Jul 9, 2026 High JPdata breachzero-daypassword reset
threat-intel Smashing Security podcast #475: JadePuffer – the AI that ran a ransomware attack all by itself A 15-year-old in Japan used an AI chatbot to automatically cancel nearly 47,000 anime streaming subscriptions within hours. Simultaneously, researchers have documented the first fully autonomous, agentic AI-driven ransom… Graham Cluley · Jul 8, 2026 High JPairansomwarecyberattack
data-breach Major Japanese telco says cyberattack exposed 12 million emails KDDI, a major Japanese telecommunications company, disclosed that a cyberattack exposed the email addresses and passwords of over 12 million customers due to a vulnerability in third-party software. The breach impacted a… The Record · Jul 7, 2026 Medium JPdata breachpasswordvulnerability
threat-intel Japanese teen arrested over cyberattack that disrupted anime streaming service A 15-year-old Japanese student was arrested for a cyberattack that disrupted an anime streaming service, Bandai Channel. The suspect exploited a vulnerability in the service’s servers and used ChatGPT to automate the fra… The Record · Jul 6, 2026 Medium JPcyberattackvulnerabilitychatgpt
ransomware Ransomware Thugs Masquerade as Interpol to Entice Small Biz A new ransomware campaign is targeting small businesses globally, impersonating Interpol to lure victims into downloading malware. The campaign utilizes basic social engineering techniques, delivering a rudimentary ranso… Dark Reading · Jul 2, 2026 Medium USEUSAsocial engineeringphishingsmall business
threat-intel Phishers Gain Persistence at EU, Asia Hospitality Orgs Phishing campaigns targeting hospitality organizations in Europe and Asia are utilizing malicious zip files containing disguised image files to install persistent malware. These attacks, observed by Microsoft and Trend M… Dark Reading · Jun 30, 2026 High GBJPphishingpersistencesocial engineering
vulnerability Mitsubishi Electric MELSOFT Update Manager SW1DND-UDM-M This advisory details a vulnerability (CVE-2025-53816, CVE-2025-53817, CVE-2025-55188, CVE-2025-11001) within the Mitsubishi Electric MELSOFT Update Manager SW1DND-UDM-M software. The vulnerability, a heap-based buffer o… CISA Advisories · Jun 30, 2026 High CVE-2025-53816CVE-2025-53817CVE-2025-55188JPbuffer overflowheapdenial of service
threat-intel Microsoft Warns of Photo ZIP Phishing Campaign Targeting Hotels with Node.js Implant A phishing campaign targeting hotels and hospitality organizations is underway, utilizing deceptive ZIP files containing Node.js implants to gain access to front-desk machines. The campaign, discovered by Microsoft, empl… The Hacker News · Jun 26, 2026 High GBJPDKphishingnode.jston
threat-intel Close Encounters of the Human Kind This article from Cisco Talos details a novel approach to reverse engineering that leverages AI agents alongside traditional tools like the VB6 disassembler. The key innovation is exposing the disassembler's parsed data… Cisco Talos · Jun 18, 2026 High GBFRUSreverse engineeringaiautomation
threat-intel ThreatsDay Bulletin: Claude Chat Abuse, NastyC2 npm Packages, Device-Code Phishing + 25 More Stories This week’s ThreatDay Bulletin highlights several concerning security incidents, including browser extension abuse, macOS malware attacks, AI-powered malware delivery, and a global phishing campaign targeting travel book… The Hacker News · Jun 18, 2026 High CVE-2026-20127CVE-2026-49975USCNJPbrowser extensionsmacos malwareai abuse
vulnerability Mitsubishi Electric MELSEC iQ-F Series This advisory from CISA details a vulnerability (CVE-2026-8805) in the Mitsubishi Electric MELSEC iQ-F Series FX5-EIP EtherNet/IP Module. The vulnerability, stemming from an integer overflow, allows a remote attacker to… CISA Advisories · Jun 18, 2026 High CVE-2026-8805JPethernet/ipdenial of serviceinteger overflow
vulnerability Mitsubishi Electric Co.'s MELSEC iQ-F Series FX5-ENET/IP Ethernet Module This advisory from CISA details a denial-of-service (DoS) vulnerability in Mitsubishi Electric's MELSEC iQ-F Series FX5-ENET/IP Ethernet Module. The vulnerability, CVE-2026-8806, allows a remote attacker to overwhelm the… CISA Advisories · Jun 18, 2026 High CVE-2026-8806JPdenial-of-serviceethernetcve-2026-8806
data-breach FortiBleed leak exposes Fortinet VPN credentials for 73,000 devices. A significant data leak, dubbed "FortiBleed," has exposed approximately 73,932 Fortinet VPN credentials for firewall URLs across numerous organizations worldwide. The leak, discovered by Bob Diachenko, reveals a multi-op… BleepingComputer · Jun 17, 2026 High USGBJPvpncredentialsbreach