Brokk, a leading Swedish global remote-controlled demolition machinery manufacturer, had a 4 GB dataset allegedly stolen from its systems exposed by the Russia-linked Play ransomware operation, which threatened to leak all pilfered data should it refuse to fulfill the demanded ransom, reports Cybernews.
At least 29 other European Union entities were disclosed by CERT-EU to have had their data compromised following the TeamPCP supply chain attack against the European Commission's Amazon cloud environment, reports BleepingComputer.
The exposed data included unencrypted driver's licenses, passports, and other identity verification documents, along with selfies and personal information such as names and home addresses.
A digital forensics investigator, identified only as TR, was called in when a client suspected a rival had infiltrated their systems after a data breach.
ShinyHunters alleges access to data from three breach paths: UNC6040, Salesforce Aura, and compromised AWS accounts, claiming over three million Salesforce records, PII, GitHub repositories, AWS storage, and internal corporate data were exfiltrated.
Researchers at watchTowr identified an authentication bypass (CVE-2026-2699) and a remote code execution flaw (CVE-2026-2701) within the Storage Zones Controller (SZC) component of Progress ShareFile versions 5.x.