ZeroHour

Search: “atf”

5 stories

ATF confirms cyberattack hit system containing info on its investigation targets

Qilin ransomware group claimed breaching the ATF, exposing data on investigation targets; the agency says a standalone system was hit with no mission impact.

The Bureau of Alcohol, Tobacco, Firearms and Explosives confirmed a cyberattack on a standalone system holding information about targets of ATF investigations, designated a major incident, with no impact on case management, lab, or eForms systems. Qilin, a Russian-speaking affiliate-based ransomware group, claimed responsibility, though ATF declined to confirm involvement or the root cause. Qilin has claimed hundreds of victims across 60+ countries since 2022 and partners with Scattered Spider and Moonstone Sleet.

CyberScoop · 19d agoRansomware in the wild

DOJ firearms agency says hackers breached system containing investigation targets

ATF confirmed a cyberattack on a standalone system containing investigation target data, calling it a major incident; Qilin listed ATF on its leak site.

The Bureau of Alcohol, Tobacco, Firearms and Explosives (ATF) confirmed a cyberattack on a standalone computer system containing information about targets of ATF investigations, with no connection to case management, laboratory, or eForms systems. The agency designated the breach a major incident and immediately terminated connections, initiating incident response and forensics. The Qilin ransomware gang added ATF to its leak site without providing stolen data samples. Qilin was the second most active ransomware gang in July 2026 with 127 reported attacks, and has previously hit Kuala Lumpur International Airport, Asahi, and Palau's government.

The Record · 20d agoRansomware in the wild

Risky Bulletin: Two TeamPCP members arrested in Australia

Australian Federal Police arrested two alleged TeamPCP members behind supply-chain worm attacks that stole over 500,000 credentials from compromised open-source libraries.

The AFP arrested alleged TeamPCP leader Ruben Thomson, 21, and Louis Gaebler, 23, near Perth; both were charged and remain in custody. The group inserted a self-spreading credential-stealing worm into open-source projects including Trivy, KICS, LiteLLM, and Telnyx, harvesting more than 500,000 credentials used for network access, ransomware, extortion, and sales. About 78,000 tokens and secrets from nearly 2,200 organizations leaked online last month, and the FBI supported the investigation that began in April.

Risky Business News · 20d agoPolicy & legal in the wild1

Microsoft discloses two actively exploited zero-days among 974 vulnerabilities

Microsoft patches 974 flaws in record Patch Tuesday, including two actively exploited Windows zero-days enabling privilege escalation.

Microsoft's largest-ever Patch Tuesday addresses 974 vulnerabilities, with CVE-2026-81963 (Windows Update Stack) and CVE-2026-85880 (Windows Advanced Local Procedure Call) exploited before disclosure. Both zero-days carry CVSS 7.8 ratings and allow privilege escalation. More than 10% of the defects are rated critical, and researchers attribute the record volume to AI-assisted vulnerability discovery without a matching rise in active exploitation.

CyberScoop · 8d agoExploit / PoC in the wildCVE-2026-81963CVE-2026-85880

Pegasus, NoviSpy variant spyware found on devices of Serbian activists

Researchers confirmed the first 2026 Pegasus infection and a new NoviSpy variant on 14 Serbian activists, likely surveillance by Serbian authorities ahead of elections.

Citizen Lab confirmed with high probability the first forensically confirmed Pegasus infection of 2026, on a Serbian student activist hacked via a zero-click exploit between December of last year and January. Amnesty International confirmed two devices infected with a new NoviSpy variant, and the SHARE Foundation documented 14 targets including a member of parliament and a local government official, the largest documented spyware wave in Serbia to date. Evidence points to Serbian police or intelligence services, with NoviSpy infections occurring around police detention ahead of key local and parliamentary elections. Apple threat notifications preceded the findings, and updated iOS versions break the exploit chain.

CyberScoop · 14d agoThreat actor in the wild