Critical

ExfilSquad hackers leak info of over 100,000 UK police officers, staff

BleepingComputer

Overview

A cyberattack targeting the U.K.'s Police National Legal Database (PNLD) has resulted in the exposure of contact information for over 100,000 police officers and other personnel within the criminal justice system. The breach has raised concerns about the potential misuse of this sensitive data, which includes names, phone numbers, and email addresses of law enforcement staff. The attack highlights vulnerabilities in the security of critical databases that house personal information. With such a large number of individuals affected, there is a heightened risk of phishing attacks and other forms of identity theft. Authorities are investigating the breach to determine the extent of the damage and to implement necessary security measures to prevent future incidents.

Key Takeaways

  • Affected Systems: Police National Legal Database (PNLD), contact data of police officers and criminal justice professionals
  • Action Required: Authorities are investigating and likely implementing enhanced security measures, but specific remediation steps have not been detailed.
  • Timeline: Newly disclosed

Original Article Summary

A cyberattack on the U.K.'s Police National Legal Database (PNLD) has compromised contact data of more than 100,000 police officers and other criminal justice professionals. [...]

Impact

Police National Legal Database (PNLD), contact data of police officers and criminal justice professionals

Exploitation Status

The exploitation status is currently unknown. Monitor vendor advisories and security bulletins for updates.

Timeline

Newly disclosed

Remediation

Authorities are investigating and likely implementing enhanced security measures, but specific remediation steps have not been detailed.

Additional Information

This threat intelligence is aggregated from trusted cybersecurity sources. For the most up-to-date information, technical details, and official vendor guidance, please refer to the original article linked below.

Related Topics: This incident relates to Phishing, Data Breach, Critical.

Related Coverage

New XCSSET variant targets macOS devs via compromised Xcode projects

BleepingComputer

A new variant of the XCSSET malware has emerged, specifically targeting macOS developers by exploiting compromised Xcode projects and GitHub repositories. This malware is designed to infiltrate the development environment, potentially affecting thousands of users who download these compromised projects. Researchers have identified that the malware can steal sensitive information, including user credentials and private data, which poses a significant risk to both developers and their end users. As this malware spreads, it raises concerns about the security of development tools and the integrity of software supply chains. Developers are urged to be vigilant about the sources of their code and to implement security measures to protect their environments.

Aug 4, 2026

Iran Cyberattacks Against Minnesota Water Systems

Schneier on Security

Recent cyberattacks appear to be targeting water systems in Minnesota as part of a broader campaign affecting at least seven states. Although initial reports suggest no significant damage, these incidents raise concerns about the security of critical infrastructure. Former President Trump has publicly dismissed the notion that Iran is behind the attacks, instead blaming Minnesota officials for incompetence. This situation highlights ongoing vulnerabilities in U.S. water systems, which could potentially be exploited by hostile actors. The implications of such attacks are serious, as they could disrupt essential services and compromise public safety.

Aug 4, 2026

Smoke#Screen RMM Takeover Gambit Exposes Threat Actor Playbook

darkreading

Recent attacks have revealed a methodical approach by threat actors using social engineering tactics to compromise networks. The attackers employ various lures to deliver ScreenConnect, a tool that allows for remote access, ensuring they can maintain persistent control over affected systems. This type of attack can expose sensitive information and disrupt business operations, potentially impacting organizations across sectors. As these tactics evolve, it becomes increasingly important for companies to enhance their security awareness and response strategies to mitigate such risks. Users and organizations must remain vigilant against social engineering techniques that can lead to unauthorized access.

Aug 4, 2026

Shai-Hulud npm Worm Returns, Poisoning Over 1,280 npm Packages

Hackread – Cybersecurity News, Data Breaches, AI and More

The Shai-Hulud npm worm has resurfaced, infecting over 1,280 npm packages that collectively receive around 2 billion downloads each month. This malware is designed to steal sensitive credentials from various platforms, including npm, GitHub, cloud services, and continuous integration (CI) tools, in real-time. The worm spreads through Keyv and other related packages, posing a significant risk to developers and organizations that rely on these tools for their software development processes. With the potential for widespread credential theft, users need to be vigilant and consider enhancing their security measures to protect their accounts. The incident serves as a reminder of the vulnerabilities that can arise within popular development ecosystems.

Aug 4, 2026

Dem senators criticize Trump administration decisionmaking on AI security risks

CyberScoop

Five Democratic senators have expressed their concerns over the Trump administration's approach to managing artificial intelligence (AI) security risks. They argue that the administration has been inconsistent, sometimes too passive and at other times overreaching, which they believe has created an environment where China could gain an advantage in AI development. The senators are urging for a more balanced and proactive strategy to address the growing security challenges posed by AI technologies. This situation is critical as AI continues to evolve rapidly, impacting various sectors, including defense and cybersecurity. The senators' critique highlights the need for a clear and effective policy to mitigate potential risks associated with AI advancements.

Aug 4, 2026

Massive ChainDrop npm supply-chain attack infects hundreds of packages

BleepingComputer

A new self-propagating malware called 'ChainDrop' has infected over 1,300 packages in the Node Package Manager (npm) registry, which collectively see around 2 billion downloads each month. This attack allows the malware to spread rapidly across various software projects that rely on npm packages. Developers and companies using these compromised packages are at risk of introducing vulnerabilities into their applications. The incident raises significant concerns about supply chain security, as it demonstrates how a single attack can impact a vast number of users and systems. Those affected should take immediate steps to identify and remove the compromised packages from their projects to mitigate potential damage.

Aug 4, 2026