π INCIDENT: BRILLONCONSUMER.COM
π Date of attackers' claim: August 12, 2026
π¦ Attacker: Ransomware group Clop
π― Compromised domain: BRILLONCONSUMER.COM
π’ About the company: Brillon Consumer Products Pvt Ltd is an Indian consumer goods company, a joint venture between SC Johnson and Bansk Group. Its headquarters is located in Gurugram, Haryana, India. The company owns brands such as All Out, Baygon, Mr Muscle, Glade, Kiwi, and Dranex. Its estimated annual revenue ranges from βΉ500 to βΉ1,000 crore (~$60β120 million).
π° Ransom demanded: not specified
π¦ Total volume of the claimed archive: 22.4 GB
π WHAT IS CLAIMED ABOUT THE LEAK:
β’ Databases
β’ Project files
π§Ύ STATUS:
β οΈ Claim by the hacker group Clop. The group warned that the full data leak would be published unless the company makes contact. At this time, there is no independent confirmation of the leak and no official statement from Brillon Consumer. It should be noted that some sources flag Clop's claims as unverified.
π« Note: Brillon Consumer is a notable player in the Indian FMCG market with a portfolio of well-known brands, which makes it an attractive target for extortionists.
ββ-
π Date of attackers' claim: August 12, 2026
π¦ Attacker: Ransomware group Clop
π― Compromised domain: BRILLONCONSUMER.COM
π’ About the company: Brillon Consumer Products Pvt Ltd is an Indian consumer goods company, a joint venture between SC Johnson and Bansk Group. Its headquarters is located in Gurugram, Haryana, India. The company owns brands such as All Out, Baygon, Mr Muscle, Glade, Kiwi, and Dranex. Its estimated annual revenue ranges from βΉ500 to βΉ1,000 crore (~$60β120 million).
π° Ransom demanded: not specified
π¦ Total volume of the claimed archive: 22.4 GB
π WHAT IS CLAIMED ABOUT THE LEAK:
β’ Databases
β’ Project files
π§Ύ STATUS:
β οΈ Claim by the hacker group Clop. The group warned that the full data leak would be published unless the company makes contact. At this time, there is no independent confirmation of the leak and no official statement from Brillon Consumer. It should be noted that some sources flag Clop's claims as unverified.
π« Note: Brillon Consumer is a notable player in the Indian FMCG market with a portfolio of well-known brands, which makes it an attractive target for extortionists.
ββ-
π INCIDENT: SUUNTO.CN (SUUNTO.COM)
π Date of attackers' claim: August 12, 2026
π¦ Attacker: Ransomware group Clop
π― Compromised domain: SUUNTO.CN (SUUNTO.COM)
π’ About the company: Suunto Oy is a Finnish manufacturer of sports watches, dive computers, and precision instruments. The company was founded in 1936, and its headquarters is located in Vantaa, Finland. In 2022, Suunto was acquired from Amer Sports by Chinese company Liesheng Technology . The brand's products are sold in more than 100 countries worldwide . The estimated annual revenue is approximately $108β111 million .
π° Ransom demanded: not specified
π¦ Total volume of the claimed archive: 1470 GB
π WHAT IS CLAIMED ABOUT THE LEAK:
β’ Databases
β’ Project files
π ADDITIONAL COMPROMISE DATA (HudsonRock):
β’ Compromised employees: 1
β’ Compromised users: 3139
β’ Third-party employee credentials: 4
β’ External attack surface: 101
π§Ύ STATUS:
β οΈ Claim by the hacker group Clop. The attack is part of a large-scale Clop campaign in August 2026 linked to the exploitation of critical vulnerability CVE-2026-12569 (CVSS 9.3) in PTC Windchill and FlexPLM . The attackers deployed a custom JSP web shell capable of decrypting credentials, exfiltrating files, and enabling remote code execution . According to Clop's statement, "The full leak will be published soon, unless a company representative contacts us" . At this time, there is no independent confirmation of the leak and no official statement from Suunto.
π« Note: Suunto is a Finnish brand with a 90-year history and global recognition. The detected infostealer traces (3139 compromised users, 4 third-party employee credentials) indicate that access to the environment may have been obtained not only through the Windchill vulnerability but also through previously compromised credentials, which significantly expands the attack surface.
---
π Date of attackers' claim: August 12, 2026
π¦ Attacker: Ransomware group Clop
π― Compromised domain: SUUNTO.CN (SUUNTO.COM)
π’ About the company: Suunto Oy is a Finnish manufacturer of sports watches, dive computers, and precision instruments. The company was founded in 1936, and its headquarters is located in Vantaa, Finland. In 2022, Suunto was acquired from Amer Sports by Chinese company Liesheng Technology . The brand's products are sold in more than 100 countries worldwide . The estimated annual revenue is approximately $108β111 million .
π° Ransom demanded: not specified
π¦ Total volume of the claimed archive: 1470 GB
π WHAT IS CLAIMED ABOUT THE LEAK:
β’ Databases
β’ Project files
π ADDITIONAL COMPROMISE DATA (HudsonRock):
β’ Compromised employees: 1
β’ Compromised users: 3139
β’ Third-party employee credentials: 4
β’ External attack surface: 101
π§Ύ STATUS:
β οΈ Claim by the hacker group Clop. The attack is part of a large-scale Clop campaign in August 2026 linked to the exploitation of critical vulnerability CVE-2026-12569 (CVSS 9.3) in PTC Windchill and FlexPLM . The attackers deployed a custom JSP web shell capable of decrypting credentials, exfiltrating files, and enabling remote code execution . According to Clop's statement, "The full leak will be published soon, unless a company representative contacts us" . At this time, there is no independent confirmation of the leak and no official statement from Suunto.
π« Note: Suunto is a Finnish brand with a 90-year history and global recognition. The detected infostealer traces (3139 compromised users, 4 third-party employee credentials) indicate that access to the environment may have been obtained not only through the Windchill vulnerability but also through previously compromised credentials, which significantly expands the attack surface.
---
π INCIDENT: SMAPCENTER.UAH.EDU
π Date of attackers' claim: August 12, 2026
π¦ Attacker: Ransomware group Clop
π― Compromised domain: SMAPCENTER.UAH.EDU
π’ About the organization: SMAP Center (Systems Management and Production Center) is a research center at the University of Alabama in Huntsville (UAH). The center participates in U.S. Department of Defense research, particularly on diminishing manufacturing sources and material shortages (DMSMS) in weapon systems, and also runs STEM education and medical simulation projects (MEDNET). UAH's annual research expenditure is about $154.5 million, with 17 research centers at the university. The center's estimated revenue is $113 million.
π° Ransom demanded: not specified
π¦ Total volume of the claimed archive: 6.08 GB
π WHAT IS CLAIMED ABOUT THE LEAK:
β’ Databases
β’ Project files
π ADDITIONAL COMPROMISE DATA:
β’ Compromised employees: not disclosed
β’ Compromised users: not disclosed
β’ Third-party employee credentials: not disclosed
β’ External attack surface: not disclosed
Note: No HudsonRock data was found for SMAPCENTER.UAH.EDU. The attack vector was a server-side application vulnerability (PTC Windchill RCE), not endpoint infostealer malware, so no infostealer credential data is expected for this target. To verify manually, the domain can be checked via HudsonRock's free lookup tool.
π INFRASTRUCTURE:
β’ IP address: 146.229.99.30, Huntsville, Alabama, USA
β’ ASN: AS10364, University of Alabama in Huntsville (UAH)
β’ Subdomain:
β’ Owning entity: Systems Management and Production Center, UAH research center, network range 146.229.0.0/16
π§Ύ STATUS:
β οΈ Claim by the hacker group Clop. The attack is part of a large-scale Clop campaign in August 2026 linked to the exploitation of critical vulnerability CVE-2026-12569 (CVSS 9.3) in PTC Windchill and FlexPLM. The vulnerability is an insecure deserialization flaw enabling remote code execution via the
π« Note: The SMAP Center is tied to defense research and management systems for the U.S. Department of Defense, which makes it a particularly sensitive target for extortionists.
---
π Date of attackers' claim: August 12, 2026
π¦ Attacker: Ransomware group Clop
π― Compromised domain: SMAPCENTER.UAH.EDU
π’ About the organization: SMAP Center (Systems Management and Production Center) is a research center at the University of Alabama in Huntsville (UAH). The center participates in U.S. Department of Defense research, particularly on diminishing manufacturing sources and material shortages (DMSMS) in weapon systems, and also runs STEM education and medical simulation projects (MEDNET). UAH's annual research expenditure is about $154.5 million, with 17 research centers at the university. The center's estimated revenue is $113 million.
π° Ransom demanded: not specified
π¦ Total volume of the claimed archive: 6.08 GB
π WHAT IS CLAIMED ABOUT THE LEAK:
β’ Databases
β’ Project files
π ADDITIONAL COMPROMISE DATA:
β’ Compromised employees: not disclosed
β’ Compromised users: not disclosed
β’ Third-party employee credentials: not disclosed
β’ External attack surface: not disclosed
Note: No HudsonRock data was found for SMAPCENTER.UAH.EDU. The attack vector was a server-side application vulnerability (PTC Windchill RCE), not endpoint infostealer malware, so no infostealer credential data is expected for this target. To verify manually, the domain can be checked via HudsonRock's free lookup tool.
π INFRASTRUCTURE:
β’ IP address: 146.229.99.30, Huntsville, Alabama, USA
β’ ASN: AS10364, University of Alabama in Huntsville (UAH)
β’ Subdomain:
apps.smapcenter.uah.edu (time-tracking system, protected by DUO MFA)β’ Owning entity: Systems Management and Production Center, UAH research center, network range 146.229.0.0/16
π§Ύ STATUS:
β οΈ Claim by the hacker group Clop. The attack is part of a large-scale Clop campaign in August 2026 linked to the exploitation of critical vulnerability CVE-2026-12569 (CVSS 9.3) in PTC Windchill and FlexPLM. The vulnerability is an insecure deserialization flaw enabling remote code execution via the
wt.fv.uploadtocache.DoUploadToCache_Server upload path. In Windchill environments, Clop deployed a custom JSP web shell capable of decrypting credentials, enumerating file vaults, and exfiltrating engineering data, receiving commands via a custom X-windchill-req HTTP header. The same campaign wave included Shell, Philips, General Electric, and roughly 50 other organizations. According to Clop's statement, "The full leak will be published soon, unless a university representative contacts us." At this time, there is no independent confirmation of the leak and no official statement from UAH or the SMAP Center.π« Note: The SMAP Center is tied to defense research and management systems for the U.S. Department of Defense, which makes it a particularly sensitive target for extortionists.
---
π INCIDENT: TRISTAR.COM
π Date of attackers' claim: August 12, 2026
π¦ Attacker: Ransomware group Clop
π― Compromised domain: TRISTAR.COM
π’ About the company: Tristar Corporation is an American corporation headquartered in the USA. The company's exact business profile is not disclosed in open sources, but its claimed annual revenue is estimated at $1 billion.
π° Ransom demanded: not specified
π¦ Total volume of the claimed archive: 1579.9 GB
π WHAT IS CLAIMED ABOUT THE LEAK:
β’ Databases
β’ Project files
π ADDITIONAL COMPROMISE DATA (HudsonRock):
β’ Compromised employees: 0
β’ Compromised users: 1
β’ Third-party employee credentials: 8
β’ External attack surface: 1
π DETECTED INFRASTRUCTURE:
β’ MX records: tristar-com.mail.protection.outlook.com (Microsoft 365)
β’ SaaS services: Mailchimp, Mailgun, Microsoft 365
π§Ύ STATUS:
β οΈ Claim by the hacker group Clop. The attack is part of a large-scale Clop campaign in August 2026, during which the group claimed dozens of victims in a short period. The total volume of data across all victims in this wave is estimated at roughly 23 TB and appears to include CAD files, databases, backups, engineering drawings, and other documents. Tristar Corporation is listed among the victims of this campaign. At this time, there is no independent confirmation of the leak and no official statement from the company.
π« Note: The claimed $1 billion revenue combined with the relatively small footprint of detected compromise (1 user, 1 asset) may indicate that the primary value of the data for extortionists lies in the archive contents rather than in employee credentials.
___
π Date of attackers' claim: August 12, 2026
π¦ Attacker: Ransomware group Clop
π― Compromised domain: TRISTAR.COM
π’ About the company: Tristar Corporation is an American corporation headquartered in the USA. The company's exact business profile is not disclosed in open sources, but its claimed annual revenue is estimated at $1 billion.
π° Ransom demanded: not specified
π¦ Total volume of the claimed archive: 1579.9 GB
π WHAT IS CLAIMED ABOUT THE LEAK:
β’ Databases
β’ Project files
π ADDITIONAL COMPROMISE DATA (HudsonRock):
β’ Compromised employees: 0
β’ Compromised users: 1
β’ Third-party employee credentials: 8
β’ External attack surface: 1
π DETECTED INFRASTRUCTURE:
β’ MX records: tristar-com.mail.protection.outlook.com (Microsoft 365)
β’ SaaS services: Mailchimp, Mailgun, Microsoft 365
π§Ύ STATUS:
β οΈ Claim by the hacker group Clop. The attack is part of a large-scale Clop campaign in August 2026, during which the group claimed dozens of victims in a short period. The total volume of data across all victims in this wave is estimated at roughly 23 TB and appears to include CAD files, databases, backups, engineering drawings, and other documents. Tristar Corporation is listed among the victims of this campaign. At this time, there is no independent confirmation of the leak and no official statement from the company.
π« Note: The claimed $1 billion revenue combined with the relatively small footprint of detected compromise (1 user, 1 asset) may indicate that the primary value of the data for extortionists lies in the archive contents rather than in employee credentials.
___
π INCIDENT: MAMASANDPAPAS.COM
π Date of attackers' claim: August 12, 2026
π¦ Attacker: Ransomware group Clop
π― Compromised domain: MAMASANDPAPAS.COM
π’ About the company: Mamas & Papas is a British retailer of baby and nursery products, specialising in pushchairs, nursery furniture, car seats, clothing, and accessories. The company was founded in 1981, with its headquarters in Huddersfield, England. The brand operates more than 60 stores across the UK and sells its products in over 30 countries worldwide. In the 2026 financial year, the company's revenue reached Β£170 million, up 4% year over year .
π° Ransom demanded: not specified
π¦ Total volume of the claimed archive: 1.18 GB
π WHAT IS CLAIMED ABOUT THE LEAK:
β’ Databases
β’ Project files
π§Ύ STATUS:
β οΈ Claim by the hacker group Clop. The attack is part of a Clop campaign in August 2026, during which the group claimed dozens of victims. According to Clop's statement: "The data will be published if the company does not engage in negotiations within the specified timeframe" . However, on August 14, 2026, the Mamas & Papas PR team contacted security researchers and stated: "We have found no evidence of the affected software nor any indicators of unauthorised access to, or compromise of, customer or company data" . At the time of publication, there is no independent confirmation of the leak.
π« Note: Mamas & Papas is the UK market leader in baby products with a share of around 25%. The absence of any data samples, screenshots, or other evidence on the Clop page is atypical for the group, which raises further doubts about the claim's credibility .
---
π Date of attackers' claim: August 12, 2026
π¦ Attacker: Ransomware group Clop
π― Compromised domain: MAMASANDPAPAS.COM
π’ About the company: Mamas & Papas is a British retailer of baby and nursery products, specialising in pushchairs, nursery furniture, car seats, clothing, and accessories. The company was founded in 1981, with its headquarters in Huddersfield, England. The brand operates more than 60 stores across the UK and sells its products in over 30 countries worldwide. In the 2026 financial year, the company's revenue reached Β£170 million, up 4% year over year .
π° Ransom demanded: not specified
π¦ Total volume of the claimed archive: 1.18 GB
π WHAT IS CLAIMED ABOUT THE LEAK:
β’ Databases
β’ Project files
π§Ύ STATUS:
β οΈ Claim by the hacker group Clop. The attack is part of a Clop campaign in August 2026, during which the group claimed dozens of victims. According to Clop's statement: "The data will be published if the company does not engage in negotiations within the specified timeframe" . However, on August 14, 2026, the Mamas & Papas PR team contacted security researchers and stated: "We have found no evidence of the affected software nor any indicators of unauthorised access to, or compromise of, customer or company data" . At the time of publication, there is no independent confirmation of the leak.
π« Note: Mamas & Papas is the UK market leader in baby products with a share of around 25%. The absence of any data samples, screenshots, or other evidence on the Clop page is atypical for the group, which raises further doubts about the claim's credibility .
---
π INCIDENT: CORNELIUS.COM
π Date of attackers' claim: August 12, 2026
π¦ Attacker: Ransomware group Clop
π― Compromised domain: CORNELIUS.COM
π’ About the company: Cornelius Inc. is an American manufacturer of beverage dispensing equipment, founded in 1931. The company specialises in fountain, frozen, and juice dispensers, as well as commercial ice machines. Cornelius is part of Marmon Foodservice Technologies, which in turn is owned by Marmon Holdings and Berkshire Hathaway. Its headquarters is located in Osseo, Minnesota, USA. Products are supplied to more than 100 countries, and its workforce numbers between 1,000 and 5,000 employees . The claimed annual revenue is $269.8 million .
π° Ransom demanded: not specified
π¦ Total volume of the claimed archive: 3684 GB
π WHAT IS CLAIMED ABOUT THE LEAK:
β’ Databases
β’ Project files
β’ PDF documents
β’ TXT files
β’ DOC documents
π ADDITIONAL COMPROMISE DATA (HudsonRock):
β’ Compromised employees: 0
β’ Compromised users: 12
β’ Third-party employee credentials: 16
β’ External attack surface: 3
π DETECTED INFRASTRUCTURE:
β’ MX records:
β’ SaaS services: Microsoft 365, Smartsheet
π§Ύ STATUS:
β οΈ Claim by the hacker group Clop. On August 12, 2026, Clop listed Cornelius Inc. on its leak site, claiming the theft of 3684 GB of data and demanding that the company contact the group for negotiations. According to Clop's standard statement: "The full leak will be published soon unless a company representative contacts us via the channels provided" . The attack is part of a large-scale Clop campaign linked to the exploitation of critical vulnerability CVE-2026-12569 in PTC Windchill and FlexPLM. However, on August 13, 2026, it emerged that law firm Bryson, Harris, Suciu, DeMay PLLC had launched an investigation into the potential data breach, inviting current and former employees as well as commercial distributors to participate in a preliminary investigation for a potential class action lawsuit . At the time of publication, Cornelius Inc. had made no official statement confirming or denying the leak.
π« Note: The absence of compromised employees (0) alongside 12 compromised users and 16 third-party employee credentials may indicate that access to the environment was obtained primarily through external accounts or contractors rather than through direct company employee credentials.
---
π Date of attackers' claim: August 12, 2026
π¦ Attacker: Ransomware group Clop
π― Compromised domain: CORNELIUS.COM
π’ About the company: Cornelius Inc. is an American manufacturer of beverage dispensing equipment, founded in 1931. The company specialises in fountain, frozen, and juice dispensers, as well as commercial ice machines. Cornelius is part of Marmon Foodservice Technologies, which in turn is owned by Marmon Holdings and Berkshire Hathaway. Its headquarters is located in Osseo, Minnesota, USA. Products are supplied to more than 100 countries, and its workforce numbers between 1,000 and 5,000 employees . The claimed annual revenue is $269.8 million .
π° Ransom demanded: not specified
π¦ Total volume of the claimed archive: 3684 GB
π WHAT IS CLAIMED ABOUT THE LEAK:
β’ Databases
β’ Project files
β’ PDF documents
β’ TXT files
β’ DOC documents
π ADDITIONAL COMPROMISE DATA (HudsonRock):
β’ Compromised employees: 0
β’ Compromised users: 12
β’ Third-party employee credentials: 16
β’ External attack surface: 3
π DETECTED INFRASTRUCTURE:
β’ MX records:
cornelius-com.mail.protection.outlook.com (Microsoft 365)β’ SaaS services: Microsoft 365, Smartsheet
π§Ύ STATUS:
β οΈ Claim by the hacker group Clop. On August 12, 2026, Clop listed Cornelius Inc. on its leak site, claiming the theft of 3684 GB of data and demanding that the company contact the group for negotiations. According to Clop's standard statement: "The full leak will be published soon unless a company representative contacts us via the channels provided" . The attack is part of a large-scale Clop campaign linked to the exploitation of critical vulnerability CVE-2026-12569 in PTC Windchill and FlexPLM. However, on August 13, 2026, it emerged that law firm Bryson, Harris, Suciu, DeMay PLLC had launched an investigation into the potential data breach, inviting current and former employees as well as commercial distributors to participate in a preliminary investigation for a potential class action lawsuit . At the time of publication, Cornelius Inc. had made no official statement confirming or denying the leak.
π« Note: The absence of compromised employees (0) alongside 12 compromised users and 16 third-party employee credentials may indicate that access to the environment was obtained primarily through external accounts or contractors rather than through direct company employee credentials.
---
π INCIDENT: MAMMUT.COM
π Date of attackers' claim: August 12, 2026
π¦ Attacker: Ransomware group Clop
π― Compromised domain: MAMMUT.COM
π’ About the company: Mammut Sports Group AG is a Swiss manufacturer of high-quality outdoor equipment and apparel for mountaineering and climbing. The company was founded in 1862, with its headquarters in Seon, Switzerland. Mammut operates in around 40 countries and employs approximately 800 people . In 2026, the company was acquired by Chinese private equity firm CPEζΊε³° from Jacobs Capital . Revenue for 2025 was approximately 400 million Swiss francs (roughly $281 million at current exchange rates) .
π° Ransom demanded: not specified
π¦ Total volume of the claimed archive: 136 GB
π WHAT IS CLAIMED ABOUT THE LEAK:
β’ .png files
β’ Windchill files
π ADDITIONAL COMPROMISE DATA (HudsonRock):
β’ Compromised employees: 1
β’ Compromised users: 173
β’ Third-party employee credentials: 1
β’ External attack surface: 42
π DETECTED INFRASTRUCTURE:
β’ MX records: mx1.mammut.ch, mx2.mammut.ch
β’ SaaS services: Apple, Atlassian, Microsoft 365, SendGrid
π§Ύ STATUS:
β οΈ Claim by the hacker group Clop. On August 12, 2026, Clop listed MAMMUT.COM on its leak site, claiming the theft of 136 GB of data. According to Clop's standard statement: "The full leak will be published soon unless a company representative contacts us via the channels provided" . The attack is part of a large-scale Clop campaign linked to the exploitation of critical vulnerability CVE-2026-12569 in PTC Windchill and FlexPLM. Important: RedPacket Security notes that listings attributed to Clop "have been reported as including unverified or fabricated victim claims" . At the time of publication, there is no independent confirmation of the leak and no official statement from Mammut.
π« Note: This is not the first attack on Mammut. In May 2025, the company was already targeted by ransomware group DATACARRY, which, according to trackers, also operated through credential compromise (infostealer) . A repeat appearance on victim lists within a year may indicate either persistent credential security issues or reuse of previously stolen data.
ββ
π Date of attackers' claim: August 12, 2026
π¦ Attacker: Ransomware group Clop
π― Compromised domain: MAMMUT.COM
π’ About the company: Mammut Sports Group AG is a Swiss manufacturer of high-quality outdoor equipment and apparel for mountaineering and climbing. The company was founded in 1862, with its headquarters in Seon, Switzerland. Mammut operates in around 40 countries and employs approximately 800 people . In 2026, the company was acquired by Chinese private equity firm CPEζΊε³° from Jacobs Capital . Revenue for 2025 was approximately 400 million Swiss francs (roughly $281 million at current exchange rates) .
π° Ransom demanded: not specified
π¦ Total volume of the claimed archive: 136 GB
π WHAT IS CLAIMED ABOUT THE LEAK:
β’ .png files
β’ Windchill files
π ADDITIONAL COMPROMISE DATA (HudsonRock):
β’ Compromised employees: 1
β’ Compromised users: 173
β’ Third-party employee credentials: 1
β’ External attack surface: 42
π DETECTED INFRASTRUCTURE:
β’ MX records: mx1.mammut.ch, mx2.mammut.ch
β’ SaaS services: Apple, Atlassian, Microsoft 365, SendGrid
π§Ύ STATUS:
β οΈ Claim by the hacker group Clop. On August 12, 2026, Clop listed MAMMUT.COM on its leak site, claiming the theft of 136 GB of data. According to Clop's standard statement: "The full leak will be published soon unless a company representative contacts us via the channels provided" . The attack is part of a large-scale Clop campaign linked to the exploitation of critical vulnerability CVE-2026-12569 in PTC Windchill and FlexPLM. Important: RedPacket Security notes that listings attributed to Clop "have been reported as including unverified or fabricated victim claims" . At the time of publication, there is no independent confirmation of the leak and no official statement from Mammut.
π« Note: This is not the first attack on Mammut. In May 2025, the company was already targeted by ransomware group DATACARRY, which, according to trackers, also operated through credential compromise (infostealer) . A repeat appearance on victim lists within a year may indicate either persistent credential security issues or reuse of previously stolen data.
ββ
π INCIDENT: PARTECH.COM
π Date of attackers' claim: August 12, 2026
π¦ Attacker: Ransomware group Clop
π― Compromised domain: PARTECH.COM
π’ About the company: According to Clop's claim, PARTECH.COM belongs to a company with annual revenue of $475,700,000. However, precise identification is complicated: the domain partech.com is associated with two distinct organizations β French venture capital firm Partech (offices in Paris, San Francisco, Berlin, Dakar; β¬1.5B under management) and American PAR Technology Corporation (NYSE: PAR), whose fiscal year 2026 revenue guidance is $516β523 million . The claimed revenue of $475.7 million is closer to PAR Technology's figures than to Partech's estimates ($39.2M) . Clop does not specify which entity is the actual victim.
π° Ransom demanded: not specified
π¦ Total volume of the claimed archive: 24 GB
π WHAT IS CLAIMED ABOUT THE LEAK:
β’ Databases
β’ Project files
β’ CAD files
β’ Backups
π ADDITIONAL COMPROMISE DATA (HudsonRock):
β’ Compromised employees: 2
β’ Compromised users: 8
β’ Third-party employee credentials: 16
β’ External attack surface: 16
π DETECTED INFRASTRUCTURE:
β’ MX records:
β’ SaaS services (per TXT records): Atlassian, Wrike, Amazon, Shopify, Google, Cloudflare, Smartsheet, BrowserStack, Zoom, Anthropic, Miro, ConfigCat, Intacct, and others
π§Ύ STATUS:
β οΈ Claim by the hacker group Clop. On August 12, 2026, Clop listed PARTECH.COM on its leak site, claiming the theft of 24 GB of data. According to Clop's standard statement: "The full leak will be published soon unless a company representative contacts us via the channels provided" . The attack is part of a large-scale Clop campaign in August 2026 linked to the exploitation of critical vulnerability CVE-2026-12569 in PTC Windchill and FlexPLM . At the time of publication, there is no independent confirmation of the leak and no official statement from the company.
π« Note: The most significant feature of this incident is the ambiguity in victim identification. The domain partech.com is used by at least two organizations with different profiles, which complicates assessing the credibility of the claim and the potential impact. If the victim is PAR Technology (a restaurant technology provider), the leak of CAD files and backups could affect intellectual property and client data; if Partech (a venture capital firm), it could involve confidential information of portfolio companies and investors.
ββ
π Date of attackers' claim: August 12, 2026
π¦ Attacker: Ransomware group Clop
π― Compromised domain: PARTECH.COM
π’ About the company: According to Clop's claim, PARTECH.COM belongs to a company with annual revenue of $475,700,000. However, precise identification is complicated: the domain partech.com is associated with two distinct organizations β French venture capital firm Partech (offices in Paris, San Francisco, Berlin, Dakar; β¬1.5B under management) and American PAR Technology Corporation (NYSE: PAR), whose fiscal year 2026 revenue guidance is $516β523 million . The claimed revenue of $475.7 million is closer to PAR Technology's figures than to Partech's estimates ($39.2M) . Clop does not specify which entity is the actual victim.
π° Ransom demanded: not specified
π¦ Total volume of the claimed archive: 24 GB
π WHAT IS CLAIMED ABOUT THE LEAK:
β’ Databases
β’ Project files
β’ CAD files
β’ Backups
π ADDITIONAL COMPROMISE DATA (HudsonRock):
β’ Compromised employees: 2
β’ Compromised users: 8
β’ Third-party employee credentials: 16
β’ External attack surface: 16
π DETECTED INFRASTRUCTURE:
β’ MX records:
partech-com.mail.protection.outlook.com (Microsoft 365)β’ SaaS services (per TXT records): Atlassian, Wrike, Amazon, Shopify, Google, Cloudflare, Smartsheet, BrowserStack, Zoom, Anthropic, Miro, ConfigCat, Intacct, and others
π§Ύ STATUS:
β οΈ Claim by the hacker group Clop. On August 12, 2026, Clop listed PARTECH.COM on its leak site, claiming the theft of 24 GB of data. According to Clop's standard statement: "The full leak will be published soon unless a company representative contacts us via the channels provided" . The attack is part of a large-scale Clop campaign in August 2026 linked to the exploitation of critical vulnerability CVE-2026-12569 in PTC Windchill and FlexPLM . At the time of publication, there is no independent confirmation of the leak and no official statement from the company.
π« Note: The most significant feature of this incident is the ambiguity in victim identification. The domain partech.com is used by at least two organizations with different profiles, which complicates assessing the credibility of the claim and the potential impact. If the victim is PAR Technology (a restaurant technology provider), the leak of CAD files and backups could affect intellectual property and client data; if Partech (a venture capital firm), it could involve confidential information of portfolio companies and investors.
ββ
π INCIDENT: STARKEY.COM
π Date of attackers' claim: August 12, 2026
π¦ Attacker: Ransomware group Clop
π― Compromised domain: STARKEY.COM
π’ About the company: Starkey Hearing Technologies, Inc. is an American hearing aid manufacturer founded in 1967. Its headquarters is located in Hopkins, Minnesota, USA. The company is the largest American-owned hearing aid manufacturer and ranks among the global top five with a market share of around 15% . Starkey specialises in AI-integrated hearing aids with features such as step tracking, fall detection, and language translation . Its annual revenue is approximately $1 billion .
π° Ransom demanded: not specified
π¦ Total volume of the claimed archive: 3030 GB
π WHAT IS CLAIMED ABOUT THE LEAK:
β’ Databases
β’ Project files
π ADDITIONAL COMPROMISE DATA (HudsonRock):
β’ Compromised employees: 10
β’ Compromised users: 11
β’ Third-party employee credentials: 18
β’ External attack surface: 38
π DETECTED INFRASTRUCTURE:
β’ MX records:
β’ SaaS services (per TXT records): Dynatrace, Google, Apple, Cisco, Anthropic, Firebase, Zapier, Microsoft, OpenAI, KnowBe4
π§Ύ STATUS:
β οΈ Claim by the hacker group Clop. On August 12, 2026, Clop listed STARKEY.COM on its leak site, claiming the theft of 3030 GB of data and demanding that the company contact the group for negotiations. According to Clop's standard statement: "The full leak will be published soon unless a company representative contacts us via the channels provided" . The attack is part of a large-scale Clop campaign linked to the exploitation of critical vulnerability CVE-2026-12569 in PTC Windchill and FlexPLM. At the time of publication, there is no independent confirmation of the leak and no official statement from Starkey.
π« Note: Starkey is the only American-owned hearing aid manufacturer and an active player in AI-driven medical technology. The 3030 GB leak volume is one of the largest in the current Clop attack wave, which may indicate a significant volume of intellectual property, including project data and research databases.
____
π Date of attackers' claim: August 12, 2026
π¦ Attacker: Ransomware group Clop
π― Compromised domain: STARKEY.COM
π’ About the company: Starkey Hearing Technologies, Inc. is an American hearing aid manufacturer founded in 1967. Its headquarters is located in Hopkins, Minnesota, USA. The company is the largest American-owned hearing aid manufacturer and ranks among the global top five with a market share of around 15% . Starkey specialises in AI-integrated hearing aids with features such as step tracking, fall detection, and language translation . Its annual revenue is approximately $1 billion .
π° Ransom demanded: not specified
π¦ Total volume of the claimed archive: 3030 GB
π WHAT IS CLAIMED ABOUT THE LEAK:
β’ Databases
β’ Project files
π ADDITIONAL COMPROMISE DATA (HudsonRock):
β’ Compromised employees: 10
β’ Compromised users: 11
β’ Third-party employee credentials: 18
β’ External attack surface: 38
π DETECTED INFRASTRUCTURE:
β’ MX records:
starkey-com.mail.protection.outlook.com (Microsoft 365) β’ SaaS services (per TXT records): Dynatrace, Google, Apple, Cisco, Anthropic, Firebase, Zapier, Microsoft, OpenAI, KnowBe4
π§Ύ STATUS:
β οΈ Claim by the hacker group Clop. On August 12, 2026, Clop listed STARKEY.COM on its leak site, claiming the theft of 3030 GB of data and demanding that the company contact the group for negotiations. According to Clop's standard statement: "The full leak will be published soon unless a company representative contacts us via the channels provided" . The attack is part of a large-scale Clop campaign linked to the exploitation of critical vulnerability CVE-2026-12569 in PTC Windchill and FlexPLM. At the time of publication, there is no independent confirmation of the leak and no official statement from Starkey.
π« Note: Starkey is the only American-owned hearing aid manufacturer and an active player in AI-driven medical technology. The 3030 GB leak volume is one of the largest in the current Clop attack wave, which may indicate a significant volume of intellectual property, including project data and research databases.
____
π INCIDENT: LARGAN.COM.TW
π Date of attackers' claim: August 12, 2026
π¦ Attacker: Ransomware group Clop
π― Compromised domain: LARGAN.COM.TW
π’ About the company: Largan Precision Co., Ltd. is a Taiwanese optical lens manufacturer and a key supplier of camera modules for Apple. The company was founded in 1987, with its headquarters in Taichung, Taiwan. Largan is the world's largest manufacturer of smartphone lenses and holds a significant share of the high-end optics market. Its claimed annual revenue is $1.7 billion.
π° Ransom demanded: not specified
π¦ Total volume of the claimed archive: 56 GB
π WHAT IS CLAIMED ABOUT THE LEAK:
β’ Project files
β’ Software (Soft)
π ADDITIONAL COMPROMISE DATA (HudsonRock):
β’ Compromised employees: 0
β’ Compromised users: 43
β’ Third-party employee credentials: 0
β’ External attack surface: 6
π DETECTED INFRASTRUCTURE:
β’ MX records:
β’ SPF record:
π§Ύ STATUS:
β οΈ Claim by the hacker group Clop. On August 12, 2026, Clop listed LARGAN.COM.TW on its leak site as part of a large-scale campaign linked to the exploitation of critical vulnerability CVE-2026-12569 (CVSS 9.8) in PTC Windchill and FlexPLM . The vulnerability involves insecure deserialization and improper input validation, allowing an unauthenticated remote attacker to execute arbitrary code . Clop used a custom JSP web shell to access Windchill data, including credential decryption and file exfiltration . Largan Precision is listed among more than 40 alleged victims in the campaign alongside Shell, Philips, Fiserv, Zebra Technologies, Mindray, and others . According to Clop's statement: "The full database will be leaked if Largan Precision Co., Ltd. does not contact us to negotiate" . At the time of publication, there is no independent confirmation of the leak and no official statement from the company.
π« Note: Largan Precision is a critical Apple supplier in the camera module supply chain, which makes a potential leak of project data and software particularly sensitive. However, the absence of compromised employees (0) alongside 43 compromised users may indicate access through external accounts or contractors rather than direct employee credentials.
π Date of attackers' claim: August 12, 2026
π¦ Attacker: Ransomware group Clop
π― Compromised domain: LARGAN.COM.TW
π’ About the company: Largan Precision Co., Ltd. is a Taiwanese optical lens manufacturer and a key supplier of camera modules for Apple. The company was founded in 1987, with its headquarters in Taichung, Taiwan. Largan is the world's largest manufacturer of smartphone lenses and holds a significant share of the high-end optics market. Its claimed annual revenue is $1.7 billion.
π° Ransom demanded: not specified
π¦ Total volume of the claimed archive: 56 GB
π WHAT IS CLAIMED ABOUT THE LEAK:
β’ Project files
β’ Software (Soft)
π ADDITIONAL COMPROMISE DATA (HudsonRock):
β’ Compromised employees: 0
β’ Compromised users: 43
β’ Third-party employee credentials: 0
β’ External attack surface: 6
π DETECTED INFRASTRUCTURE:
β’ MX records:
mail.largan.com.tw, mailgw1.largan.com.tw, mailgw2.largan.com.tw β’ SPF record:
v=spf1 ip4:219.87.176.11 ip4:219.87.176.7 ip4:60.248.234.226 ip4:123.51.154.9 -all π§Ύ STATUS:
β οΈ Claim by the hacker group Clop. On August 12, 2026, Clop listed LARGAN.COM.TW on its leak site as part of a large-scale campaign linked to the exploitation of critical vulnerability CVE-2026-12569 (CVSS 9.8) in PTC Windchill and FlexPLM . The vulnerability involves insecure deserialization and improper input validation, allowing an unauthenticated remote attacker to execute arbitrary code . Clop used a custom JSP web shell to access Windchill data, including credential decryption and file exfiltration . Largan Precision is listed among more than 40 alleged victims in the campaign alongside Shell, Philips, Fiserv, Zebra Technologies, Mindray, and others . According to Clop's statement: "The full database will be leaked if Largan Precision Co., Ltd. does not contact us to negotiate" . At the time of publication, there is no independent confirmation of the leak and no official statement from the company.
π« Note: Largan Precision is a critical Apple supplier in the camera module supply chain, which makes a potential leak of project data and software particularly sensitive. However, the absence of compromised employees (0) alongside 43 compromised users may indicate access through external accounts or contractors rather than direct employee credentials.
4 Vulnerabilities Already Under Attack: CISA Adds SharePoint, WSO2, MikroTik, and Adobe Commerce to Catalog
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added four vulnerabilities to its catalog of flaws known to be exploited in the wild. The security gaps affect Microsoft SharePoint servers, WSO2 API management products, Adobe Commerce and Magento e-commerce stores, and devices running MikroTik RouterOS. For some of these vulnerabilities, attackers require no credentials or user interaction to succeed.
The most critical flaw, CVE-2026-5430, affects WSO2 API Manager versions 4.1.0β4.6.0, as well as API Control Plane, Traffic Manager, and Universal Gateway versions 4.5.0 and 4.6.0. WSO2 assigned the vulnerability a maximum CVSS score of 10 for certain configurations, warning that a successful attack allows for full account takeover, including administrative access.
The flaw stems from the validation process of JSON Web Tokens (JWT), which act as digital passes between applications and services. WSO2 accepted tokens signed with an unsupported algorithm, allowing malicious actors to forge tokens and bypass authentication. The vendor released patches in the spring and recommends installing the relevant updates or upgrading to an unaffected version.
The second critical vulnerability, CVE-2026-71362 (CVSS score: 9.1), impacts Adobe Commerce, Adobe Commerce B2B, and Magento Open Source. An authorization bypass flaw allows unauthenticated attackers to gain access to customer accounts. Experts at Sansec, who analyzed the patch, discovered that the system incorrectly handled user identity within a session, enabling an attacker to switch the session to another client and access their profile and personal data.
Adobe addressed CVE-2026-71362 in its August update (APSB26-92). At the time of the advisory's release, the company stated it had no evidence of active exploitation. However, Sansec claimed its security systems had already blocked attempts to exploit CVE-2026-71362. Its inclusion in the CISA catalog now confirms that active exploitation has moved beyond lab proof-of-concepts.
Microsoft SharePoint is being targeted via CVE-2026-65660 (CVSS score: 8.8). The flaw allows a low-privileged user to inject and execute code on the server over the network. Microsoft patched the vulnerability in August for SharePoint Server 2016, SharePoint Server 2019, and SharePoint Server Subscription Edition. Unlike the flaws in WSO2 and Adobe Commerce, exploiting CVE-2026-65660 requires a valid user account.
The fourth vulnerability, CVE-2026-67279, is located in the SSH server of MikroTik RouterOS. Under a specific sequence of actions, RouterOS began processing commands before the user authentication process was fully completed. As a result, an unauthenticated remote client could create, modify, and restore files within the accessible RouterOS directory, including configuration files and diagnostic data. Researchers described the issue after analyzing the September updates.
MikroTik resolved the related flaws in RouterOS versions 6.49.21, 7.23.4, 7.24.2, and 7.25 beta 3. The company advises against leaving SSH exposed to untrusted networks. Following the update, administrators should inspect devices for unknown users, scripts, or other configuration changes. RouterOS may also label a device as "Flagged" if it detects known indicators of compromise.
CISA has not disclosed who is exploiting these four vulnerabilities or which organizations are being targeted. U.S. federal agencies are required to remediate CVE-2026-5430 and CVE-2026-71362 by September 27, and CVE-2026-65660 and CVE-2026-67279 by September 28. For other organizations, inclusion in the CISA catalog serves as a high-priority alert that updates must be deployed immediately given the confirmed active exploitation, and internet-facing systems should be checked for signs of breach.
____
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added four vulnerabilities to its catalog of flaws known to be exploited in the wild. The security gaps affect Microsoft SharePoint servers, WSO2 API management products, Adobe Commerce and Magento e-commerce stores, and devices running MikroTik RouterOS. For some of these vulnerabilities, attackers require no credentials or user interaction to succeed.
The most critical flaw, CVE-2026-5430, affects WSO2 API Manager versions 4.1.0β4.6.0, as well as API Control Plane, Traffic Manager, and Universal Gateway versions 4.5.0 and 4.6.0. WSO2 assigned the vulnerability a maximum CVSS score of 10 for certain configurations, warning that a successful attack allows for full account takeover, including administrative access.
The flaw stems from the validation process of JSON Web Tokens (JWT), which act as digital passes between applications and services. WSO2 accepted tokens signed with an unsupported algorithm, allowing malicious actors to forge tokens and bypass authentication. The vendor released patches in the spring and recommends installing the relevant updates or upgrading to an unaffected version.
The second critical vulnerability, CVE-2026-71362 (CVSS score: 9.1), impacts Adobe Commerce, Adobe Commerce B2B, and Magento Open Source. An authorization bypass flaw allows unauthenticated attackers to gain access to customer accounts. Experts at Sansec, who analyzed the patch, discovered that the system incorrectly handled user identity within a session, enabling an attacker to switch the session to another client and access their profile and personal data.
Adobe addressed CVE-2026-71362 in its August update (APSB26-92). At the time of the advisory's release, the company stated it had no evidence of active exploitation. However, Sansec claimed its security systems had already blocked attempts to exploit CVE-2026-71362. Its inclusion in the CISA catalog now confirms that active exploitation has moved beyond lab proof-of-concepts.
Microsoft SharePoint is being targeted via CVE-2026-65660 (CVSS score: 8.8). The flaw allows a low-privileged user to inject and execute code on the server over the network. Microsoft patched the vulnerability in August for SharePoint Server 2016, SharePoint Server 2019, and SharePoint Server Subscription Edition. Unlike the flaws in WSO2 and Adobe Commerce, exploiting CVE-2026-65660 requires a valid user account.
The fourth vulnerability, CVE-2026-67279, is located in the SSH server of MikroTik RouterOS. Under a specific sequence of actions, RouterOS began processing commands before the user authentication process was fully completed. As a result, an unauthenticated remote client could create, modify, and restore files within the accessible RouterOS directory, including configuration files and diagnostic data. Researchers described the issue after analyzing the September updates.
MikroTik resolved the related flaws in RouterOS versions 6.49.21, 7.23.4, 7.24.2, and 7.25 beta 3. The company advises against leaving SSH exposed to untrusted networks. Following the update, administrators should inspect devices for unknown users, scripts, or other configuration changes. RouterOS may also label a device as "Flagged" if it detects known indicators of compromise.
CISA has not disclosed who is exploiting these four vulnerabilities or which organizations are being targeted. U.S. federal agencies are required to remediate CVE-2026-5430 and CVE-2026-71362 by September 27, and CVE-2026-65660 and CVE-2026-67279 by September 28. For other organizations, inclusion in the CISA catalog serves as a high-priority alert that updates must be deployed immediately given the confirmed active exploitation, and internet-facing systems should be checked for signs of breach.
____
Dangerous Flaw Discovered in Elementor: Simple URL Click Grants Superuser Privileges
A simple link can turn an active WordPress administrator session into a site takeover tool. A newly discovered vulnerability in the Elementor Website Builder allows attackers to bypass REST API Cross-Site Request Forgery (CSRF) protection and execute actions with the privileges of an authenticated user, including creating a new administrator account.
The vulnerability, tracked as CVE-2026-62062, received a CVSS 3.1 score of 8.8. It affects Elementor versions 4.3.0 and 4.3.1. Patchstack disclosed the flaw on September 25 following a report by a security researcher known as Saggre. While Elementor is installed on over 10 million sites, the potential blast radius for the vulnerable versions is estimated at around 2 million installations.
The flaw resides in the Editor Events module, which handles editor telemetry. The code attempts to identify requests directed to Elementorβs own route by searching for the string elementor/v1/events/. However, it checks for this string across the entire raw URI. This includes the query string, which is fully controlled by the request sender.
An attacker can append this specific string as a harmless parameter to a request aimed at a completely different REST route. Elementor mistakenly recognizes the request as its own and returns a successful result in the authentication filter before standard WordPress checks take place. Consequently, the core skips the REST nonce verification, which is supposed to ensure that the action was genuinely initiated by the authorized user.
However, authorization checks are not completely bypassed. The REST API still verifies whether the specific action is permitted for the current user, meaning the impact depends on the victim's privileges. If the crafted URL is opened by a logged-in administrator, a request to the standard user route can create a secondary administrative account with the attackerβs credentials.
This attack scenario requires no JavaScript, HTML forms, or an attacker-controlled website. WordPress supports the _method parameter, which can turn a standard GET request into a state-changing write operation. As a result, the entire malicious payload fits directly into a URL that can be delivered via email, direct message, or comment. The victim only needs to open the link during an active session.
This bypass affects more than just Elementor's routes. Because the check triggers before WordPress identifies the actual REST route, the vulnerability extends to the entire available REST API, including functions from other plugins. The actual scope of achievable actions depends on the user's permissions and installed components, with administrator creation being the most critical exploit scenario.
The issue specifically impacts versions 4.3.0 and 4.3.1. Older releases do not contain the vulnerable Editor Events proxy, though they may have other flaws. In early September, threat actors were already targeting Elementor Pro via a different critical vulnerability that allowed arbitrary PHP file uploads and remote code execution (RCE).
Elementor released version 4.3.2 on September 24. The patched code no longer parses the raw URI alongside its parameters; instead, it checks the pre-determined WordPress REST route and requires the Elementor namespace to be strictly at the beginning. This approach prevents attackers from injecting the required string via the query string.
A similar class of attacks recently affected the WordPress core itself. In the Click2Shell chain, an authenticated administrator's browser also executed an unintended action after opening a crafted resource, though the underlying technical mechanism differed. As of now, there is no public evidence of active exploitation (in the wild) for CVE-2026-62062. Patchstack strongly recommends upgrading to Elementor 4.3.2 or later.
A simple link can turn an active WordPress administrator session into a site takeover tool. A newly discovered vulnerability in the Elementor Website Builder allows attackers to bypass REST API Cross-Site Request Forgery (CSRF) protection and execute actions with the privileges of an authenticated user, including creating a new administrator account.
The vulnerability, tracked as CVE-2026-62062, received a CVSS 3.1 score of 8.8. It affects Elementor versions 4.3.0 and 4.3.1. Patchstack disclosed the flaw on September 25 following a report by a security researcher known as Saggre. While Elementor is installed on over 10 million sites, the potential blast radius for the vulnerable versions is estimated at around 2 million installations.
The flaw resides in the Editor Events module, which handles editor telemetry. The code attempts to identify requests directed to Elementorβs own route by searching for the string elementor/v1/events/. However, it checks for this string across the entire raw URI. This includes the query string, which is fully controlled by the request sender.
An attacker can append this specific string as a harmless parameter to a request aimed at a completely different REST route. Elementor mistakenly recognizes the request as its own and returns a successful result in the authentication filter before standard WordPress checks take place. Consequently, the core skips the REST nonce verification, which is supposed to ensure that the action was genuinely initiated by the authorized user.
However, authorization checks are not completely bypassed. The REST API still verifies whether the specific action is permitted for the current user, meaning the impact depends on the victim's privileges. If the crafted URL is opened by a logged-in administrator, a request to the standard user route can create a secondary administrative account with the attackerβs credentials.
This attack scenario requires no JavaScript, HTML forms, or an attacker-controlled website. WordPress supports the _method parameter, which can turn a standard GET request into a state-changing write operation. As a result, the entire malicious payload fits directly into a URL that can be delivered via email, direct message, or comment. The victim only needs to open the link during an active session.
This bypass affects more than just Elementor's routes. Because the check triggers before WordPress identifies the actual REST route, the vulnerability extends to the entire available REST API, including functions from other plugins. The actual scope of achievable actions depends on the user's permissions and installed components, with administrator creation being the most critical exploit scenario.
The issue specifically impacts versions 4.3.0 and 4.3.1. Older releases do not contain the vulnerable Editor Events proxy, though they may have other flaws. In early September, threat actors were already targeting Elementor Pro via a different critical vulnerability that allowed arbitrary PHP file uploads and remote code execution (RCE).
Elementor released version 4.3.2 on September 24. The patched code no longer parses the raw URI alongside its parameters; instead, it checks the pre-determined WordPress REST route and requires the Elementor namespace to be strictly at the beginning. This approach prevents attackers from injecting the required string via the query string.
A similar class of attacks recently affected the WordPress core itself. In the Click2Shell chain, an authenticated administrator's browser also executed an unintended action after opening a crafted resource, though the underlying technical mechanism differed. As of now, there is no public evidence of active exploitation (in the wild) for CVE-2026-62062. Patchstack strongly recommends upgrading to Elementor 4.3.2 or later.
π INCIDENT: TOASTTAB.COM
π Date of attackers' claim: August 12, 2026
π¦ Attacker: Ransomware group Clop
π― Compromised domain: TOASTTAB.COM
π’ About the company: Toast, Inc. is an American technology company providing cloud-based POS solutions, payment processing, and management tools for the restaurant industry. Its headquarters is located in Boston, Massachusetts, USA. Revenue for 2025 was $6.15 billion , and for the first half of 2026 β $3.54 billion . The company serves restaurants of all sizes across the United States and internationally .
π° Ransom demanded: not specified
π¦ Total volume of the claimed archive: 215 GB
π WHAT IS CLAIMED ABOUT THE LEAK:
β’ Project files
β’ Backup databases
β’ Logs
π ADDITIONAL COMPROMISE DATA (HudsonRock):
β’ Compromised employees: 9
β’ Compromised users: 6928
β’ Third-party employee credentials: 20
β’ External attack surface: 105
π DETECTED INFRASTRUCTURE:
β’ MX records:
β’ SaaS services (per TXT records): Apple, DocuSign, Stripe, Miro, Loom, OpenAI, Salesforce, Mailgun, Google, Microsoft
π§Ύ STATUS:
β οΈ Claim by the hacker group Clop. On August 12, 2026, Clop listed TOASTTAB.COM on its leak site as part of a large-scale campaign linked to the exploitation of a critical vulnerability in PTC Windchill . However, Toast, Inc. has officially confirmed the incident: "Toast identified unauthorized access to a limited number of files; to date, the files identified contain nonsensitive internal documents. We isolated the affected systems the same day we detected the activity, and the situation has been contained" . Company spokesperson Allie Rosenberg emphasised that no customer data was affected .
π« Note: The incident is notable in that Toast is one of the few companies in the current Clop attack wave to promptly confirm unauthorized access and issue an official comment. This contrasts with most alleged victims, which either remain silent or deny the incident. It is also important to note that, according to a RedPacket Security warning, listings attributed to Clop "have been reported as including unverified or fabricated victim claims" .
π Date of attackers' claim: August 12, 2026
π¦ Attacker: Ransomware group Clop
π― Compromised domain: TOASTTAB.COM
π’ About the company: Toast, Inc. is an American technology company providing cloud-based POS solutions, payment processing, and management tools for the restaurant industry. Its headquarters is located in Boston, Massachusetts, USA. Revenue for 2025 was $6.15 billion , and for the first half of 2026 β $3.54 billion . The company serves restaurants of all sizes across the United States and internationally .
π° Ransom demanded: not specified
π¦ Total volume of the claimed archive: 215 GB
π WHAT IS CLAIMED ABOUT THE LEAK:
β’ Project files
β’ Backup databases
β’ Logs
π ADDITIONAL COMPROMISE DATA (HudsonRock):
β’ Compromised employees: 9
β’ Compromised users: 6928
β’ Third-party employee credentials: 20
β’ External attack surface: 105
π DETECTED INFRASTRUCTURE:
β’ MX records:
aspmx.l.google.com, alt1.aspmx.l.google.com, etc. (Google Workspace) β’ SaaS services (per TXT records): Apple, DocuSign, Stripe, Miro, Loom, OpenAI, Salesforce, Mailgun, Google, Microsoft
π§Ύ STATUS:
β οΈ Claim by the hacker group Clop. On August 12, 2026, Clop listed TOASTTAB.COM on its leak site as part of a large-scale campaign linked to the exploitation of a critical vulnerability in PTC Windchill . However, Toast, Inc. has officially confirmed the incident: "Toast identified unauthorized access to a limited number of files; to date, the files identified contain nonsensitive internal documents. We isolated the affected systems the same day we detected the activity, and the situation has been contained" . Company spokesperson Allie Rosenberg emphasised that no customer data was affected .
π« Note: The incident is notable in that Toast is one of the few companies in the current Clop attack wave to promptly confirm unauthorized access and issue an official comment. This contrasts with most alleged victims, which either remain silent or deny the incident. It is also important to note that, according to a RedPacket Security warning, listings attributed to Clop "have been reported as including unverified or fabricated victim claims" .
π INCIDENT: IRCO.COM
π Date of attackers' claim: August 12, 2026
π¦ Attacker: Ransomware group Clop
π― Compromised domain: IRCO.COM
π’ About the company: Ingersoll Rand Inc. is an American industrial conglomerate and one of the global leaders in mission-critical flow creation and industrial solutions. The company was founded in 1859, with its headquarters in Davidson, North Carolina, USA. Revenue for 2025 was $7.65 billion, up 6% year over year . Guidance for 2026 is $8.1β8.5 billion . The company manages a portfolio of more than 80 brands and serves customers in manufacturing, construction, and energy .
π° Ransom demanded: not specified
π¦ Total volume of the claimed archive: 5564 GB
π WHAT IS CLAIMED ABOUT THE LEAK:
β’ CAD files
β’ PDF drawings
β’ Diagrams
β’ Product presentations
β’ Specifications
β’ Manuals and instructions
π ADDITIONAL COMPROMISE DATA (HudsonRock):
β’ Compromised employees: 125
β’ Compromised users: 45
β’ Third-party employee credentials: 108
β’ External attack surface: 83
π DETECTED INFRASTRUCTURE:
β’ MX records:
β’ SPF record: includes
π§Ύ STATUS:
β οΈ Claim by the hacker group Clop. On August 12, 2026, Clop listed IRCO.COM on its leak site as part of a campaign linked to the exploitation of critical vulnerability CVE-2026-12569 in PTC Windchill and FlexPLM . According to Clop's standard statement: "The full leak will be published soon unless a company representative contacts us via the channels provided" . However: Ransomware.live flags this entry as a "duplicate" β the same domain appears in the database with a note about possible duplication . Moreover, IRCO.COM had already appeared in other groups' lists: in March 2026 it was "attacked" by the ALP-001 group with a ransom deadline of March 29 and a claimed volume of 5.9 TB , and in August by the Everest group . At the time of publication, there is no independent confirmation of the leak and no official statement from Ingersoll Rand.
π« Note: The incident raises significant doubts about its credibility. The same domain has been claimed by at least three different ransomware groups (ALP-001, Everest, Clop) within a few months, and the Clop entry is flagged as a duplicate in tracking databases. The data claimed to have been leaked (CAD files, drawings, specifications) relates to engineering documentation, which is typical for attacks via PLM systems, but the 5.5 TB volume and repeated claims may indicate either a real compromise with repeated monetization or an extortion attempt using previously stolen or fabricated data. Notably, Ingersoll Rand's 2025 financial statements include a line item "Cybersecurity incident costs" with a negative value (-$1.3M), which may indirectly indicate settlement of incident consequences in the past .
π Date of attackers' claim: August 12, 2026
π¦ Attacker: Ransomware group Clop
π― Compromised domain: IRCO.COM
π’ About the company: Ingersoll Rand Inc. is an American industrial conglomerate and one of the global leaders in mission-critical flow creation and industrial solutions. The company was founded in 1859, with its headquarters in Davidson, North Carolina, USA. Revenue for 2025 was $7.65 billion, up 6% year over year . Guidance for 2026 is $8.1β8.5 billion . The company manages a portfolio of more than 80 brands and serves customers in manufacturing, construction, and energy .
π° Ransom demanded: not specified
π¦ Total volume of the claimed archive: 5564 GB
π WHAT IS CLAIMED ABOUT THE LEAK:
β’ CAD files
β’ PDF drawings
β’ Diagrams
β’ Product presentations
β’ Specifications
β’ Manuals and instructions
π ADDITIONAL COMPROMISE DATA (HudsonRock):
β’ Compromised employees: 125
β’ Compromised users: 45
β’ Third-party employee credentials: 108
β’ External attack surface: 83
π DETECTED INFRASTRUCTURE:
β’ MX records:
irco-com.mail.protection.outlook.com (Microsoft 365)β’ SPF record: includes
spf.protection.outlook.com, mail.zendesk.com, servers.mcsv.net, amazonses.com, and othersπ§Ύ STATUS:
β οΈ Claim by the hacker group Clop. On August 12, 2026, Clop listed IRCO.COM on its leak site as part of a campaign linked to the exploitation of critical vulnerability CVE-2026-12569 in PTC Windchill and FlexPLM . According to Clop's standard statement: "The full leak will be published soon unless a company representative contacts us via the channels provided" . However: Ransomware.live flags this entry as a "duplicate" β the same domain appears in the database with a note about possible duplication . Moreover, IRCO.COM had already appeared in other groups' lists: in March 2026 it was "attacked" by the ALP-001 group with a ransom deadline of March 29 and a claimed volume of 5.9 TB , and in August by the Everest group . At the time of publication, there is no independent confirmation of the leak and no official statement from Ingersoll Rand.
π« Note: The incident raises significant doubts about its credibility. The same domain has been claimed by at least three different ransomware groups (ALP-001, Everest, Clop) within a few months, and the Clop entry is flagged as a duplicate in tracking databases. The data claimed to have been leaked (CAD files, drawings, specifications) relates to engineering documentation, which is typical for attacks via PLM systems, but the 5.5 TB volume and repeated claims may indicate either a real compromise with repeated monetization or an extortion attempt using previously stolen or fabricated data. Notably, Ingersoll Rand's 2025 financial statements include a line item "Cybersecurity incident costs" with a negative value (-$1.3M), which may indirectly indicate settlement of incident consequences in the past .
π‘ The DMDC Breach: 9 Months of Silence and 3M Service Members' Unencrypted Data Exposed
The Pentagon has officially acknowledged a massive security incident. A vulnerability at the Defense Manpower Data Center (DMDC) has compromised the personal data of over 3 million individuals β spanning active-duty military personnel, reservists, contractors, and veterans.
π Timeline and Hard Figures:
β’ Dwell Time: From October 2025 to July 16, 2026. Attackers maintained undetected, persistent access for 9 full months.
β’ Breach Scale: The incident impacts 2,76 million living personnel and 294,000 records of deceased individuals. (The total DMDC repository holds over 60 million records).
β’ Exfiltrated Data: Unencrypted PII (Personally Identifiable Information) β full names, SSNs (Social Security Numbers), dates of birth, contact details, and critically β military occupational specialties and duty stations.
π Technical Vector: Where the Pentagon Erred
Official DMDC notification letters sent to victims remain light on specifics, but cybersecurity analysts can piece together the technical reality:
1. File-Sharing System Vulnerability: The attack did not target the secure core database. Instead, it exploited a peripheral file-sharing server. Hackers likely leveraged a Path Traversal or Pre-Auth RCE vulnerability in a third-party software layer to gain an initial foothold.
2. Lack of Encryption (Unencrypted PII): The administrative critical failure lies in the data handling. Files stored on or passing through this transit server were kept in cleartext.
3. Logging and SIEM Failure: The fact that a "limited number of unauthorized users" spent 9 months roaming the server points to a complete lack of anomalous data exfiltration detection and substandard log auditing.
π― Threat Actors and Real-World Impact
The Pentagon claims there is "no evidence of data misuse" and suggests hackers might have just "viewed" the data rather than downloading it. In the InfoSec community, this is a joke β threat actors do not maintain persistence in a military network for nearly a year just to "browse."
The broader context is telling: in late September 2026, the ShinyHunters threat group simultaneously claimed a breach of the FBI's recruiting portal (FBIJobs.gov). While attribution for the DMDC breach remains unconfirmed, the stolen data feeds two distinct threat vectors:
1. Cybercrime (Financial Fraud): A complete Name + DOB + SSN package is a turn-key asset for Identity Theft. It allows fraudsters to open fraudulent lines of credit, hijack tax refunds, and exploit medical insurance.
2. APT Groups (Espionage): Mapping real identities to specific military occupational specialties and locations is a goldmine for foreign intelligence. This data will likely power highly sophisticated Spear-Phishing campaigns and social engineering operations targeting officers and critical infrastructure operators.
π Remediation Efforts
The Pentagon patched the flaw in July but waited until September to begin notifications. Victims are being offered the standard consolation prize: a complimentary year of IDX credit monitoring. But as the joke goes in InfoSec circles: "Credit monitoring won't erase your military clearance profile from a foreign intelligence database."
++++
The Pentagon has officially acknowledged a massive security incident. A vulnerability at the Defense Manpower Data Center (DMDC) has compromised the personal data of over 3 million individuals β spanning active-duty military personnel, reservists, contractors, and veterans.
π Timeline and Hard Figures:
β’ Dwell Time: From October 2025 to July 16, 2026. Attackers maintained undetected, persistent access for 9 full months.
β’ Breach Scale: The incident impacts 2,76 million living personnel and 294,000 records of deceased individuals. (The total DMDC repository holds over 60 million records).
β’ Exfiltrated Data: Unencrypted PII (Personally Identifiable Information) β full names, SSNs (Social Security Numbers), dates of birth, contact details, and critically β military occupational specialties and duty stations.
π Technical Vector: Where the Pentagon Erred
Official DMDC notification letters sent to victims remain light on specifics, but cybersecurity analysts can piece together the technical reality:
1. File-Sharing System Vulnerability: The attack did not target the secure core database. Instead, it exploited a peripheral file-sharing server. Hackers likely leveraged a Path Traversal or Pre-Auth RCE vulnerability in a third-party software layer to gain an initial foothold.
2. Lack of Encryption (Unencrypted PII): The administrative critical failure lies in the data handling. Files stored on or passing through this transit server were kept in cleartext.
3. Logging and SIEM Failure: The fact that a "limited number of unauthorized users" spent 9 months roaming the server points to a complete lack of anomalous data exfiltration detection and substandard log auditing.
π― Threat Actors and Real-World Impact
The Pentagon claims there is "no evidence of data misuse" and suggests hackers might have just "viewed" the data rather than downloading it. In the InfoSec community, this is a joke β threat actors do not maintain persistence in a military network for nearly a year just to "browse."
The broader context is telling: in late September 2026, the ShinyHunters threat group simultaneously claimed a breach of the FBI's recruiting portal (FBIJobs.gov). While attribution for the DMDC breach remains unconfirmed, the stolen data feeds two distinct threat vectors:
1. Cybercrime (Financial Fraud): A complete Name + DOB + SSN package is a turn-key asset for Identity Theft. It allows fraudsters to open fraudulent lines of credit, hijack tax refunds, and exploit medical insurance.
2. APT Groups (Espionage): Mapping real identities to specific military occupational specialties and locations is a goldmine for foreign intelligence. This data will likely power highly sophisticated Spear-Phishing campaigns and social engineering operations targeting officers and critical infrastructure operators.
π Remediation Efforts
The Pentagon patched the flaw in July but waited until September to begin notifications. Victims are being offered the standard consolation prize: a complimentary year of IDX credit monitoring. But as the joke goes in InfoSec circles: "Credit monitoring won't erase your military clearance profile from a foreign intelligence database."
++++
π₯ Retaliation & PR: How ShinyHunters Breached the FBI for "Marketing"
While the Pentagon is still recovering from the exposure of 3 million service members' records, the Federal Bureau of Investigation (FBI) is facing its own, arguably more embarrassing, security fiasco. The notorious ShinyHunters cybercrime group has breached FBIJobs.gov, exfiltrating the personal data of nearly every active agent, employee, and applicant.
π― The Motive: Money?
No. This was pure "retaliation" and a PR stunt. In May 2026, the FBI issued a public Public Service Announcement (PSA) warning against ShinyHunters' tactics, labeling them as mere extortionists, swatters, and blackmailers.
The threat actors took offense. They claimed the FBI breach was a "marketing campaign to protect our business and fight disinformation." Their demand? The FBI's leadership must delete or revise the May PSA. In exchange, they promised not to sell the database.
π Technical Vector: How Did They Get In?
Unlike past major breaches (such as the Snowflake campaign) that relied heavily on stolen credentials, this attack was purely technical:
1. Application Vulnerability: The attack targeted a flaw within the web application hosted on the public-facing FBIJobs.gov server.
2. Missing Patches: Mandiant analysts discovered that hackers exploited a critical, newly discovered flaw in Oracle PeopleSoft (CVE-2026-35273). A patch had been available since June 2026, but the FBI simply... failed to apply it.
3. Data Volume: Once inside the server, ShinyHunters claimed to have exfiltrated between 2 and 3 terabytes of data.
π¦ Inside the Archives (Spoiler: It's Worse Than It Looks)
To prove the breach, the group shared a sample of 5,000 records with journalists. The FBI has officially acknowledged the incident and sent out internal alerts: the bureau is operating under the assumption that every employee's data has been compromised.
The leaked data includes:
β’ Full names, home addresses, personal phone numbers, SSNs, and emergency contact details.
β’ Information on employee spouses.
β’ π©Έ The most absurd part: Medical screening results for special agents (ranging from blood and urine analysis to medical notes like "banana allergy").
π΅οΈββοΈ The Real-World Danger
For undercover operatives and counterintelligence officers, this is a national security nightmare. Stolen samples already show data of personnel assigned to sensitive desks (including operations involving Russia, China, and Iran). Their residential addresses are now exposed, leaving them and their families vulnerable to physical and digital targeting.
βοΈ An Ironic Twist
While ShinyHunters was busy issuing ultimatums to the Bureau, the Dutch National Police quietly arrested one of the group's key members in Amsterdam.
Immediately following the arrest (around September 28β29), the group's tone shifted dramatically. They walked back their threats, stating they would fully refrain from leaking or selling the FBI database. It seems the "marketing campaign" went a step too far.
The takeaway: Even if you are the world's leading law enforcement agency, patching Oracle PeopleSoft on time is not a luxuryβit's basic hygiene.
++++
While the Pentagon is still recovering from the exposure of 3 million service members' records, the Federal Bureau of Investigation (FBI) is facing its own, arguably more embarrassing, security fiasco. The notorious ShinyHunters cybercrime group has breached FBIJobs.gov, exfiltrating the personal data of nearly every active agent, employee, and applicant.
π― The Motive: Money?
No. This was pure "retaliation" and a PR stunt. In May 2026, the FBI issued a public Public Service Announcement (PSA) warning against ShinyHunters' tactics, labeling them as mere extortionists, swatters, and blackmailers.
The threat actors took offense. They claimed the FBI breach was a "marketing campaign to protect our business and fight disinformation." Their demand? The FBI's leadership must delete or revise the May PSA. In exchange, they promised not to sell the database.
π Technical Vector: How Did They Get In?
Unlike past major breaches (such as the Snowflake campaign) that relied heavily on stolen credentials, this attack was purely technical:
1. Application Vulnerability: The attack targeted a flaw within the web application hosted on the public-facing FBIJobs.gov server.
2. Missing Patches: Mandiant analysts discovered that hackers exploited a critical, newly discovered flaw in Oracle PeopleSoft (CVE-2026-35273). A patch had been available since June 2026, but the FBI simply... failed to apply it.
3. Data Volume: Once inside the server, ShinyHunters claimed to have exfiltrated between 2 and 3 terabytes of data.
π¦ Inside the Archives (Spoiler: It's Worse Than It Looks)
To prove the breach, the group shared a sample of 5,000 records with journalists. The FBI has officially acknowledged the incident and sent out internal alerts: the bureau is operating under the assumption that every employee's data has been compromised.
The leaked data includes:
β’ Full names, home addresses, personal phone numbers, SSNs, and emergency contact details.
β’ Information on employee spouses.
β’ π©Έ The most absurd part: Medical screening results for special agents (ranging from blood and urine analysis to medical notes like "banana allergy").
π΅οΈββοΈ The Real-World Danger
For undercover operatives and counterintelligence officers, this is a national security nightmare. Stolen samples already show data of personnel assigned to sensitive desks (including operations involving Russia, China, and Iran). Their residential addresses are now exposed, leaving them and their families vulnerable to physical and digital targeting.
βοΈ An Ironic Twist
While ShinyHunters was busy issuing ultimatums to the Bureau, the Dutch National Police quietly arrested one of the group's key members in Amsterdam.
Immediately following the arrest (around September 28β29), the group's tone shifted dramatically. They walked back their threats, stating they would fully refrain from leaking or selling the FBI database. It seems the "marketing campaign" went a step too far.
The takeaway: Even if you are the world's leading law enforcement agency, patching Oracle PeopleSoft on time is not a luxuryβit's basic hygiene.
++++
π¨ The Kiteworks Global Kill Switch: A "Rescue" from Intelligence Agencies or the Death of Privacy?
US cybersecurity giant Kiteworks (formerly Accellion)βwhose "secure" file-sharing platforms are used by thousands of corporations worldwideβorchestrated an unprecedented spectacle. On September 25, 2026, the company announced an emergency nine-hour global system shutdown, forcing administrators to manually take servers offline.
But stripping away the rhetoric, for any information security specialist, the picture
looks like this:
* A convenient excuse: Blaming oneβs own buggy code and yet another developer screw-up on a "Big Brother warning" is a stroke of genius for avoiding lawsuits. No admission of fault means no compensation for nine hours of business downtime.
* Kiteworks is an unreliable partner: instead of releasing a hotfix that wouldn't interrupt operations, the vendor simply offloaded the problem onto its customers.
* Goodbye, privacy: The statement regarding "assistance from intelligence agencies" is an official admission that Kiteworks software is under the complete surveillance of the likes of the FBI or CISA. If these agencies spot vulnerabilities within a proprietary product before the vendor itself does, it means backdoors are present. For commercial clients, this spells the automatic end of privacy.
Bottom line: The company's statement directly implies cooperation with intelligence agencies, as well as its complete inability to ensure the uninterrupted and secure operation of its systems.
US cybersecurity giant Kiteworks (formerly Accellion)βwhose "secure" file-sharing platforms are used by thousands of corporations worldwideβorchestrated an unprecedented spectacle. On September 25, 2026, the company announced an emergency nine-hour global system shutdown, forcing administrators to manually take servers offline.
But stripping away the rhetoric, for any information security specialist, the picture
looks like this:
* A convenient excuse: Blaming oneβs own buggy code and yet another developer screw-up on a "Big Brother warning" is a stroke of genius for avoiding lawsuits. No admission of fault means no compensation for nine hours of business downtime.
* Kiteworks is an unreliable partner: instead of releasing a hotfix that wouldn't interrupt operations, the vendor simply offloaded the problem onto its customers.
* Goodbye, privacy: The statement regarding "assistance from intelligence agencies" is an official admission that Kiteworks software is under the complete surveillance of the likes of the FBI or CISA. If these agencies spot vulnerabilities within a proprietary product before the vendor itself does, it means backdoors are present. For commercial clients, this spells the automatic end of privacy.
Bottom line: The company's statement directly implies cooperation with intelligence agencies, as well as its complete inability to ensure the uninterrupted and secure operation of its systems.