Critical

ExfilSquad Targets New Victims, Shares Data via Torrents

Security Affairs
Actively Exploited

Overview

ExfilSquad, a new cybercrime group that surfaced in mid-2026, has targeted 13 organizations by exploiting cloud portals to steal sensitive data. Unlike traditional ransomware attacks, this group focuses on data theft and then threatens to release the stolen information to amplify the damage. They have started distributing the stolen data through torrents, making it more difficult for affected organizations to contain the breach. Researchers from Resecurity are actively monitoring ExfilSquad's activities as they announce new victims. This incident raises concerns about the security of cloud services and the need for organizations to strengthen their defenses against data theft.

Key Takeaways

  • Active Exploitation: This vulnerability is being actively exploited by attackers. Immediate action is recommended.
  • Affected Systems: Cloud portals, data storage services
  • Action Required: Organizations should enhance cloud security measures, conduct regular security audits, and implement data loss prevention strategies.
  • Timeline: Ongoing since mid-2026

Original Article Summary

ExfilSquad targets 13 organizations, exploiting cloud portals for data theft and using torrents to spread stolen information and amplify damage. Resecurity is tracking the activity of ExfilSquad – the group announced new victims this week. ExfilSquad is a new cybercrime group that emerged in mid-2026. Instead of using ransomware, it steals data and threatens to […]

Impact

Cloud portals, data storage services

Exploitation Status

This vulnerability is confirmed to be actively exploited by attackers in real-world attacks. Organizations should prioritize patching or implementing workarounds immediately.

Timeline

Ongoing since mid-2026

Remediation

Organizations should enhance cloud security measures, conduct regular security audits, and implement data loss prevention strategies.

Additional Information

This threat intelligence is aggregated from trusted cybersecurity sources. For the most up-to-date information, technical details, and official vendor guidance, please refer to the original article linked below.

Related Topics: This incident relates to Ransomware, Data Breach.

Related Coverage

CISA adds Zimbra Collaboration Suite bug to exploited vulnerabilities list

SCM feed for Latest

The Cybersecurity and Infrastructure Security Agency (CISA) has added a vulnerability in the Zimbra Collaboration Suite to its list of actively exploited vulnerabilities. This marks the fifth time this year that Zimbra has appeared on the Known Exploited Vulnerabilities (KEV) list, indicating a troubling trend for users of this software. The vulnerability could allow attackers to gain unauthorized access to sensitive information, which poses a significant risk for organizations that rely on Zimbra for communication and collaboration. Users are advised to take immediate action to secure their systems, as the ongoing exploitation of this flaw highlights the importance of timely software updates and patches. Organizations using Zimbra should ensure they are running the latest versions and monitor for any signs of compromise.

Aug 24, 2026

Foul Language: WordlistLoader Disguises Malware as Ordinary Text

darkreading

Recent threat campaigns are utilizing a new method to deliver Amatera, a type of infostealer malware, by disguising it as ordinary text using a technique called WordlistLoader. This approach helps the malware evade detection systems, making it harder for security measures to identify and block it. The attack primarily targets users who may unknowingly engage with seemingly harmless documents or messages. As Amatera becomes more prevalent, individuals and organizations need to be vigilant and cautious about the files they open, as this new tactic poses a significant risk to sensitive information. Researchers are urging users to implement stronger security practices to mitigate the threat posed by this evolving technique.

Aug 24, 2026

Hackers target WordPress sites in miniOrange auth bypass attacks

BleepingComputer

Hackers are exploiting two serious vulnerabilities in the miniOrange SAML 2.0 Single Sign On plugin for WordPress. These flaws allow attackers to bypass authentication, potentially enabling them to log in as site administrators without proper credentials. This poses a significant risk to websites using the affected plugin, as unauthorized access could lead to data breaches or site manipulation. WordPress site owners need to be aware of this security issue and take prompt action to secure their installations. It's crucial for users to update their plugins and monitor for any suspicious activity to mitigate these risks.

Aug 24, 2026

Bipartisan Senate bill aims to prepare energy sector for Q-Day

CyberScoop

A new bipartisan Senate bill aims to enhance the energy sector's defenses against emerging cyber threats posed by quantum computing. The legislation directs the Federal Energy Regulatory Commission (FERC) to take into account the potential risks from quantum computers and the need for post-quantum cryptography in its reliability standards. This is significant because quantum computing has the potential to break traditional encryption methods, which could leave critical infrastructure vulnerable. By proactively addressing these threats, the bill seeks to ensure that the energy sector can maintain its security and reliability in the face of rapidly evolving technology. This move illustrates a growing recognition among lawmakers of the need to prepare for future cybersecurity challenges.

Aug 24, 2026

CMMC Phase 2 suspended: What defense contractors need to know

SCM feed for Latest

The Department of Defense has paused the implementation of CMMC Phase 2, which was intended to enhance cybersecurity standards among defense contractors. Despite this suspension, companies in the defense sector are still required to comply with existing cybersecurity requirements to protect sensitive information. This decision affects a wide range of contractors who must continue to meet the standards set by previous phases of the Cybersecurity Maturity Model Certification (CMMC). The pause raises questions about future compliance timelines and the overall effectiveness of cybersecurity measures within the defense supply chain. Contractors should stay informed and maintain their cybersecurity protocols to safeguard their systems against potential threats.

Aug 24, 2026

Cybercriminals Turn GTA VI Leaks Into Malware Bait

Security Affairs

Cybercriminals are exploiting the excitement surrounding the upcoming game, GTA VI, by distributing a fake 113GB build that contains malware. This malicious software is cleverly concealed within massive empty files, hiding a small but dangerous payload. Many eager fans are falling victim to this scam, with some even encouraging each other to download the file to verify the authenticity of the leaks. This situation raises significant concerns about user safety, as individuals risk infecting their own computers in pursuit of gaming news. It's a stark reminder that in the world of gaming, especially during hype periods, caution is essential to avoid malware traps.

Aug 24, 2026