Critical

ExfilSquad data extortion group linked to 13 victim data leaks

SCM feed for Latest
Actively Exploited

Overview

The data extortion group known as ExfilSquad, which surfaced on July 26, has claimed responsibility for stealing data from 15 organizations. So far, they have publicly leaked information from 13 victims, indicating a significant impact on businesses in various sectors. ExfilSquad's tactics include threatening to release sensitive data unless a ransom is paid, which puts additional pressure on affected organizations to comply. This incident raises concerns about data security and the potential for reputational damage for the victims involved. Organizations must remain vigilant and consider strengthening their cybersecurity measures to prevent similar attacks in the future.

Key Takeaways

  • Active Exploitation: This vulnerability is being actively exploited by attackers. Immediate action is recommended.
  • Action Required: Organizations should enhance their cybersecurity protocols, conduct regular security audits, and provide employee training on data protection and phishing prevention.
  • Timeline: Ongoing since July 26, 2023

Original Article Summary

ExfilSquad, which emerged on July 26, initially claimed to have exfiltrated data from 15 organizations.

Impact

Not specified

Exploitation Status

This vulnerability is confirmed to be actively exploited by attackers in real-world attacks. Organizations should prioritize patching or implementing workarounds immediately.

Timeline

Ongoing since July 26, 2023

Remediation

Organizations should enhance their cybersecurity protocols, conduct regular security audits, and provide employee training on data protection and phishing prevention.

Additional Information

This threat intelligence is aggregated from trusted cybersecurity sources. For the most up-to-date information, technical details, and official vendor guidance, please refer to the original article linked below.

Related Topics: This incident relates to Ransomware, Data Breach.

Related Coverage

GeoServer Zero-Day Is Already Being Probed. That’s the Problem

Security Affairs

GeoServer is currently facing a serious security issue due to an unpatched zero-day vulnerability that allows for SQL injection and potentially remote code execution (RCE). This flaw has already attracted the attention of attackers who are probing exposed systems, raising concerns for organizations using this open-source geospatial platform. A security researcher named q1uf3ng disclosed the vulnerability, but as of now, there is no available patch to fix it. Companies running GeoServer should immediately assess their systems for exposure to this vulnerability and take steps to secure their installations. The urgency of the situation is heightened by the active exploitation attempts underway, making it crucial for users to act quickly to protect their data.

Aug 15, 2026

Trezor confirms shipping partner data breach affecting over 13,000 customers

SCM feed for Latest

Trezor has confirmed a data breach involving its shipping partner, affecting over 13,000 customers. Initially, it was thought that only recent orders were compromised, but new information indicates that older orders may also be at risk. This breach raises concerns about the potential exposure of personal information, which could lead to phishing attacks or other forms of identity theft. Trezor is advising customers to remain vigilant and take steps to secure their accounts. The incident highlights the vulnerability of third-party partnerships in the cryptocurrency space, emphasizing the need for companies to ensure the security of their supply chains.

Aug 14, 2026

U.S. judiciary to publicly disclose use of hacking tools in wiretaps starting 2029

SCM feed for Latest

The U.S. judiciary will begin reporting on the use of hacking tools in wiretap investigations starting with the 2028 Wiretap Report, set to be published in 2029. This change aims to provide greater transparency regarding the methods law enforcement agencies use when conducting surveillance. By including data on network investigative techniques, the judiciary seeks to inform the public about how these tools are employed in criminal investigations. This move is significant as it could influence public perception and discussions around privacy rights and law enforcement practices. The decision reflects a growing demand for accountability in how technology is utilized by government entities.

Aug 14, 2026

California launches AI cybersecurity initiative amid growing threats

SCM feed for Latest

California has launched a new initiative to enhance cybersecurity measures in response to increasing threats. As part of this effort, every state agency is required to appoint an AI cybersecurity officer. Additionally, the state is establishing an AI cyber defense program, which will be managed by the Cybersecurity Integration Center. This initiative aims to strengthen the state's defenses against cyberattacks by integrating artificial intelligence into their security frameworks. The move is significant as it reflects a growing recognition of the need for advanced technologies to combat evolving cyber threats, ensuring that state agencies are better equipped to protect sensitive data and infrastructure.

Aug 14, 2026

Cybercriminals invest millions in expired domains for illicit activities

SCM feed for Latest

Cybercriminals are increasingly turning to expired domains, known as 'dropcatch' domains, to carry out their illicit activities. These domains are appealing because they come with existing trust, backlinks, and web traffic from their previous legitimate use, making them less suspicious to security systems compared to newly registered domains. This trend raises concerns for businesses and users alike, as these domains can be used for phishing, malware distribution, and other online scams. The use of such domains complicates the detection of malicious activities, as they can easily evade traditional security measures. It's crucial for organizations to stay vigilant and consider monitoring expired domains that could be repurposed for harmful activities.

Aug 14, 2026

MacOS screen sharing vulnerability actively exploited for crypto mining

SCM feed for Latest

A newly discovered vulnerability in macOS, identified as CVE-2026-65400, has a severity rating of 7.1 out of 10 and is being actively exploited for unauthorized cryptocurrency mining. This flaw affects the screen sharing feature of macOS, allowing attackers to hijack resources from targeted machines without user consent. Users of macOS devices should be particularly vigilant, as this vulnerability poses a risk to system performance and could lead to increased electricity costs due to the mining activities. It's crucial for users to stay updated on any patches or updates released by Apple to mitigate this issue and protect their devices from exploitation.

Aug 14, 2026