Ransomware: shinyhunters named Questel SAS (FR)
1. Executive summary On 2 August 2026, the actor "shinyhunters" publicly named Questel SAS (France, questel.com) as a ransomware victim, claiming exfiltration of
1. Executive summary On 2 August 2026, the actor "shinyhunters" publicly named Questel SAS (France, questel.com) as a ransomware victim, claiming exfiltration of
1. Executive summary Between mid-2025 and mid-2026, Microsoft tracked a series of campaigns targeting customer SaaS-based applications — predominantly Salesforce instances — using tradecraft associated
1. Executive summary A critical vulnerability in Oracle E-Business Suite (EBS) Payments — CVE-2026-46817 — is being actively exploited in the wild following Oracle'
1. Executive summary An anonymous researcher using the pseudonym "Bikini" has published proof-of-concept exploit code and write-ups for more than a
1. Executive summary Nissan has disclosed a data breach affecting current and former employees across the US, Canada, Mexico, and Brazil, linked to the widespread exploitation
1. Executive summary Nissan Americas has notified current and former employees across the US, Canada, Mexico, and Brazil that a cyberattack against Oracle PeopleSoft may have
1. Executive summary Oracle's June 2026 Critical Security Patch Update (CSPU) addresses 243 CVEs across 245 patches in 11 product families, with 122 critical-
1. Executive summary The Council of Europe has confirmed it is investigating a breach in which the ShinyHunters extortion crew claims to have stolen more than
1. Executive summary Oracle has issued an out-of-band patch for CVE-2026-35273, a critical vulnerability (CVSS 9.8, IN CISA KEV since 2026-
1. Executive summary The threat actor group "ShinyHunters" claims to have compromised over 100 organizations, including the University of Nottingham, by exploiting CVE-2026-
1. Executive summary Threat actor UNC6240 (attributed publicly to "ShinyHunters") is actively exploiting CVE-2026-35273, a critical remote code execution vulnerability (CVSS 9.
1. Executive summary The ShinyHunters extortion group claims to have compromised over 100 organizations by exploiting a "gadget chain" of legacy and zero-day