Curated Cyber Threat Intelligence

Threat Feed

Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.

scheduleUpdated 2026-09-04 · 02:17 UTC
articleTotal: 1172 reports

Filtered Reports

30 / 57 results
Active filter:✕ clear
France fines hospital €500K for breach exposing 727,000 patient recordshighpublicGeopolitical
publicGeopolitical

France fines hospital €500K for breach exposing 727,000 patient records

The enforcement action by France's CNIL represents a continuation of robust data protection regulatory activity under the EU's General Data Protection Regulation (GDPR) framework.

Hôpital privé de la Loire3 Sep · 20:01 UTC
Thomson Reuters C-Track breach exposes U.S. and Canadian court recordshighpublicGeopolitical
publicGeopolitical

Thomson Reuters C-Track breach exposes U.S. and Canadian court records

The March 2026 breach of Thomson Reuters' C-Track court case management platform represents a significant compromise of judicial infrastructure across multiple U.S. state and Canadian provincial jurisdictions.

Thomson Reuters3 Sep · 12:39 UTC
Novocure breach exposes 1,400+ U.S. cancer patient recordshighpublicGeopolitical
publicGeopolitical

Novocure breach exposes 1,400+ U.S. cancer patient records

The Novocure incident reflects the sustained targeting of healthcare infrastructure, particularly oncology and patient data repositories, which has intensified across North American providers since late 2025.

Novocure1 Sep · 12:28 UTC
Latvia's cyber threat level remains high amid Russia-linked activityhighpublicGeopolitical
publicGeopolitical

Latvia's cyber threat level remains high amid Russia-linked activity

Latvia's elevated cybersecurity posture reflects its position as a NATO frontline state and vocal supporter of Ukraine. CERT.LV's Q2 2026 report indicates that while incident volumes have moderated from peak levels, they remain substantially above hi…

CERT.LV (Latvia)1 Sep · 09:25 UTC
Berlin refuses ransom demand after Rhysida-linked breach of state networkhighpublicGeopolitical
publicGeopolitical

Berlin refuses ransom demand after Rhysida-linked breach of state network

The August 2026 compromise of Berlin's state administrative network represents a significant escalation in ransomware targeting of European critical infrastructure and government services.

The Hacker News28 Aug · 19:30 UTC
Manchester Airports Group breach exposes traveler data across UK hubshighpublicGeopolitical
publicGeopolitical

Manchester Airports Group breach exposes traveler data across UK hubs

The breach of Manchester Airports Group—the UK's largest airport operator handling over 66 million passengers annually—represents a significant incident within critical national infrastructure.

Manchester Airports Group27 Aug · 14:12 UTC
Boston Scientific cyberattack disrupts global medical device operationshighpublicGeopolitical
publicGeopolitical

Boston Scientific cyberattack disrupts global medical device operations

The cyberattack on Boston Scientific, one of the world's largest medical device manufacturers with operations in 127 countries and over $20 billion in annual revenue, underscores the persistent vulnerability of critical healthcare supply chains to cy…

Boston Scientific26 Aug · 13:19 UTC
LACMA discloses 2025 breach exposing SSNs and health datahighpublicGeopolitical
publicGeopolitical

LACMA discloses 2025 breach exposing SSNs and health data

The Los Angeles County Museum of Art breach represents a typical example of the persistent threat to U.S. cultural and public institutions from cybercriminal activity.

Los Angeles County Museum of Art (LACMA)25 Aug · 19:58 UTC
South Korean gov't platform breach exposes 5,000 via key management flawhighpublicGeopolitical
publicGeopolitical

South Korean gov't platform breach exposes 5,000 via key management flaw

The breach of South Korea's Ministry of SMEs and Startups-backed platform represents a significant governance failure in a state seeking to position itself as a regional technology leader.

BleepingComputer24 Aug · 12:00 UTC
Sakura Internet breach exposes 1.36M accounts at Japan Gov Cloud providerhighpublicGeopolitical
publicGeopolitical

Sakura Internet breach exposes 1.36M accounts at Japan Gov Cloud provider

The breach of Sakura Internet carries strategic significance beyond typical commercial cloud incidents due to the company's designation as a domestic provider for Japan's Government Cloud program.

Sakura Internet19 Aug · 18:53 UTC
CareCloud breach exposes 3.7M patient records in AWS environmenthighpublicGeopolitical
publicGeopolitical

CareCloud breach exposes 3.7M patient records in AWS environment

The CareCloud incident reflects the persistent vulnerability of U.S. healthcare infrastructure to cyber intrusions, particularly cloud-hosted environments containing sensitive medical data.

CareCloud19 Aug · 18:07 UTC
CEVA Logistics breach exposes Pokémon Center customer data in EUhighpublicGeopolitical
publicGeopolitical

CEVA Logistics breach exposes Pokémon Center customer data in EU

This incident exemplifies the systemic vulnerabilities inherent in globalized supply chain networks, where third-party logistics providers serve as critical nodes connecting consumer-facing platforms with physical distribution infrastructure.

Pokémon Center17 Aug · 17:12 UTC
French tax authority breach exposes 678,000 records amid rising attackshighpublicGeopolitical
publicGeopolitical

French tax authority breach exposes 678,000 records amid rising attacks

The breach of France's General Directorate of Public Finances (DGFiP) represents the latest in a sustained pattern of cyberattacks targeting French government infrastructure throughout 2026.

French Ministry of the Economy and Finance17 Aug · 08:09 UTC
Polish energy plant breached via private APN in coordinated OT attackhighpublicGeopolitical
publicGeopolitical

Polish energy plant breached via private APN in coordinated OT attack

The December 2025 incident represents a sophisticated multi-site campaign against Polish critical infrastructure, attributed by Polish authorities to the Russian Electrum threat group.

BleepingComputer10 Aug · 21:07 UTC
CEVA Logistics breach exposes European Steam customers' shipping datahighpublicGeopolitical
publicGeopolitical

CEVA Logistics breach exposes European Steam customers' shipping data

This incident exemplifies the systemic risk posed by third-party logistics providers in global supply chains. CEVA Logistics, a subsidiary of CMA CGM Group (the world's third-largest shipping company), operates critical infrastructure spanning 1,000…

Valve10 Aug · 09:47 UTC
Levi Strauss discloses social engineering breach targeting employeeshighpublicGeopolitical
publicGeopolitical

Levi Strauss discloses social engineering breach targeting employees

The incident reflects the persistent threat of social engineering attacks against major U.S. corporations, particularly within the retail and apparel sectors.

Levi Strauss & Co.7 Aug · 13:48 UTC
Cyberattack disrupts North Carolina port operations, critical infrastructurehighpublicGeopolitical
publicGeopolitical

Cyberattack disrupts North Carolina port operations, critical infrastructure

The incident at North Carolina Ports Authority facilities represents a significant disruption to U.S. critical maritime infrastructure. Port of Wilmington and Port of Morehead City together constitute key logistics nodes on the U.S.

BleepingComputer7 Aug · 11:34 UTC
Swiss government SharePoint breach exposes 200 accounts via July flawshighpublicGeopolitical
publicGeopolitical

Swiss government SharePoint breach exposes 200 accounts via July flaws

The breach of Switzerland's Federal Office for Information Technology and Telecommunication (BIT) represents a significant compromise of neutral state infrastructure.

Microsoft6 Aug · 16:14 UTC
U.K. Police Legal Database Breach Exposes Officer Contact Data on Dark WebhighpublicGeopolitical
publicGeopolitical

U.K. Police Legal Database Breach Exposes Officer Contact Data on Dark Web

The breach of the Police National Legal Database represents a targeted exposure of U.K. law enforcement and criminal justice infrastructure, albeit limited to contact metadata rather than operational intelligence.

Police National Legal Database (PNLD)3 Aug · 07:13 UTC
South Korea fines KT Corp $39M for telecom data breach violationshighpublicGeopolitical
publicGeopolitical

South Korea fines KT Corp $39M for telecom data breach violations

The substantial fine against KT Corporation, one of South Korea's largest telecommunications providers, underscores Seoul's increasingly assertive regulatory posture on data protection and critical infrastructure security.

KT Corporation30 Jul · 20:28 UTC
Australian drone tech firm CubePilot hit by DNS hijack amid Ukraine supporthighpublicGeopolitical
publicGeopolitical

Australian drone tech firm CubePilot hit by DNS hijack amid Ukraine support

The DNS hijacking attack against CubePilot, an Australian developer of unmanned aerial vehicle flight control systems, carries strategic significance given the company's dual-use technology profile and publicly stated support for Ukraine.

CubePilot28 Jul · 19:17 UTC
AI Agent Used in Alleged Breach of Thai Finance MinistryhighpublicGeopolitical
publicGeopolitical

AI Agent Used in Alleged Breach of Thai Finance Ministry

The alleged intrusion into Thailand's Ministry of Finance represents a significant evolution in cyber threat tradecraft, demonstrating the operational use of autonomous AI agents to automate post-exploitation activities.

Hermes AI agent24 Jul · 17:09 UTC
Illinois man sentenced for social engineering attack on 750+ Snapchat usershighpublicGeopolitical
publicGeopolitical

Illinois man sentenced for social engineering attack on 750+ Snapchat users

This case represents a domestic criminal prosecution within the United States for cybercrime targeting individual consumers. The incident reflects the persistent challenge of social engineering attacks against commercial platform users and the exploi…

Snapchat24 Jul · 09:17 UTC
Origin Energy breach exposes 2M Australian customer recordshighpublicGeopolitical
publicGeopolitical

Origin Energy breach exposes 2M Australian customer records

The breach of Origin Energy, Australia's largest energy retailer with $8.5 billion in annual revenue and cross-border holdings in UK renewable energy, underscores the persistent targeting of critical infrastructure providers in the Indo-Pacific regio…

Origin Energy23 Jul · 18:14 UTC
Microsoft 365 outage disrupts cloud services across North AmericahighpublicGeopolitical
publicGeopolitical

Microsoft 365 outage disrupts cloud services across North America

The incident represents a technical service disruption affecting critical cloud infrastructure rather than a geopolitical cyber event. Microsoft 365's position as backbone infrastructure for government, defense, and commercial operations in North Ame…

Microsoft23 Jul · 13:34 UTC
South Korea discloses 10-month breach of diplomatic training platformhighpublicGeopolitical
publicGeopolitical

South Korea discloses 10-month breach of diplomatic training platform

The compromise of South Korea's National Diplomatic Academy represents a significant intelligence collection operation targeting a key U.S. ally in Northeast Asia.

BleepingComputer22 Jul · 18:06 UTC
Mount Royal University in Calgary confirms data breach and deletionhighpublicGeopolitical
publicGeopolitical

Mount Royal University in Calgary confirms data breach and deletion

The breach of Mount Royal University represents a typical pattern in the current cyber threat landscape affecting higher education institutions across North America.

Mount Royal University8 Jul · 19:26 UTC
KDDI breach exposes 12M records across Japanese ISP ecosystemhighpublicGeopolitical
publicGeopolitical

KDDI breach exposes 12M records across Japanese ISP ecosystem

The breach of KDDI, one of Japan's three major telecommunications carriers, represents a significant compromise of critical infrastructure in a key U.S. Indo-Pacific ally.

KDDI8 Jul · 09:24 UTC
FBI seizes NetNut proxy domains linked to two-million-device botnethighpublicGeopolitical
publicGeopolitical

FBI seizes NetNut proxy domains linked to two-million-device botnet

The FBI's seizure of domains associated with NetNut, a residential proxy service operated by Israeli firm Alarum Technologies, represents a significant law enforcement action targeting the infrastructure enabling large-scale botnet operations.

Alarum Technologies2 Jul · 17:27 UTC
Kubota North America reports month-long network intrusion in 2024highpublicGeopolitical
publicGeopolitical

Kubota North America reports month-long network intrusion in 2024

The extended unauthorized access to Kubota North America's network systems highlights vulnerabilities in critical infrastructure sectors, particularly manufacturing and agriculture.

Kubota1 Jul · 19:09 UTC