View Ridge Security
Back to Cyber HoseActive Exploits & Incidents

Threat actor claims 3.6 million records stolen from Azure tenants

πŸ’₯ BREACHES & INCIDENTS

  • Threat actor claims 3.6 million records stolen from Azure tenants
    A threat actor claims to have stolen millions of employee records from Azure tenants.
    • Nine large enterprises across IT services, hospitality, telecommunications, retail, and logistics are named.
    • The alleged haul totals 3.64 million records, including 1.7 million from McDonald’s and 800,000 from TCS.
    • Exposed data allegedly includes employee identities, contact details, reporting structures, service accounts, and Global Administrator accounts.
    • TheHatman claims the data was downloaded from Azure and Entra tenants using compromised credentials.
    • Hudson Rock linked compromised Azure credentials at most named companies to infostealer-infected machines, but the access vector remains unconfirmed.
      πŸ“Ž Coverage: theregister.com Β· πŸ‘ via BleepingComputer

πŸ•΅οΈ RESEARCH & DEEP DIVES

  • BlackFile Rebrand Redact Targets Financial and Professional Services Firms
    BlackFile-linked actors are extorting financial and professional services firms.
    • UNC6671, formerly BlackFile, is targeting private equity firms, law firms and financial-rating agencies.
    • The group operates under Redact, Pink, Helix and Falcon brands and also targets healthcare, technology and hospitality organizations.
    • Attackers impersonate IT help desks in voice-phishing calls to steal credentials and MFA tokens through spoofed authentication pages.
    • Compromised accounts enable scripted data theft from Microsoft 365, SharePoint, OneDrive and Okta without encrypting files.
    • Shared infrastructure includes passkeyhelpdesk[.]com and passkeydeploy[.]com; ransom demands often start near $3 million.
      πŸ“Ž Coverage: cyberscoop.com Β· πŸ‘ via CyberScoop

πŸ“‹ ADVISORIES

  • Critical GitLab flaws could let attackers delete projects or inject code CVE-2026-19478 CVE-2026-19650
    GitLab has fixed two vulnerabilities affecting its CE and EE editions.
    • GitLab Community Edition and Enterprise Edition are affected.
    • CVE-2026-19478 is a critical GraphQL flaw with a CVSS score of 9.4.
    • Unauthenticated attackers could remotely modify or delete public projects and user data.
    • CVE-2026-19650 is a code-injection flaw exploitable under certain conditions.
    • Affected versions include 18.2 before 18.11.11, 19.0 before 19.0.8, 19.1 before 19.1.6, and 19.2 before 19.2.4.
      πŸ“Ž Coverage: thehackernews.com Β· πŸ‘ via The Hacker News, CVE ThreatInt (+1)

⚠️ Naming Error Sent AI Models From Simulations Into a Real Company

  • πŸ“„ Source for Naming Error Sent AI Models From Simulations Into a Real Company β€” anthropic.com

πŸ”“ CVEs & KEV

  • CVE-2026-19478 β€” CVSS 9.4 β€” Improper Control of Generation of Code ('Code Injection') in GitLabGitLab has...

  • CVE-2026-71472 β€” CVSS 9.1 β€” Acm-search-v2-rhel9: search-v2-operator: shell-command and sql injection in p...

  • CVE-2026-73410 β€” CVSS 8.5 β€” Budibase: SSRF via DNS rebinding in the REST datasource integrationBudibase i...

  • CVE-2026-57485 β€” CVSS 8.5 β€” Stirling-PDF: Internal Service Account API Key Disclosure via Pipeline Endpoi...

  • CVE-2026-64657 β€” CVSS 8.4 β€” Budibase: Database Connector SQL Injections in PostgreSQL, MS SQL, and MySQLB...

  • CVE-2026-57233 β€” CVSS 8.1 β€” Notepad++: Path Traversal (Zip Slip) in WinGup Plugin ExtractionNotepad++ is ...

  • CVE-2026-54758 β€” CVSS 7.8 β€” Notepad++: Stack Buffer Overflow in expandNppEnvironmentStrsNotepad++ is a fr...

  • CVE-2026-19589 β€” CVSS 7.1 β€” Packer vulnerable to arbitrary file write via crafted plugin archive during i...

  • CVE-2026-19650 β€” CVSS 7.1 β€” Cross-Site Request Forgery (CSRF) in GitLabGitLab has remediated an issue in ...

  • CVE-2026-71553 β€” CVSS 7.1 β€” ApostropheCMS: 2nd-order prototype pollution via PATCH leading to single-requ...

  • CVE-2026-73560 β€” CVSS 6.5 β€” vLLM: SSRF + arbitrary local file read in MiMoV2OmniMultiModalProcessor `_fet...

  • CVE-2026-63667 β€” CVSS 6.5 β€” ApostropheCMS: Arbitrary file read via import-export attachment-name path tra...

  • CVE-2026-63669 β€” CVSS 6.5 β€” ApostropheCMS: Missing destination-parent authorization in page move() allo...

  • CVE-2026-63670 β€” CVSS 6.1 β€” ApostropheCMS: Mutation-XSS / allowedTags bypass via literal \</textarea/> s...

Need help assessing your exposure?

Start with the free Posture Self-Check to see where you stand against the current threat landscape.

Free Posture Self-Check