Weekly review

ThreatNoir Weekend Brief — March 29

2026-03-29Morning5 articles
Audio
Listen to the episode

Morning Review in IT Security — March 29, 2026

March 29, 2026 brings critical security incidents spanning critical infrastructure, government systems, and consumer applications. Today's briefing covers major breaches affecting European institutions, energy sector vulnerabilities, and compromised software distribution channels that demand immediate attention from security teams worldwide.

Spanish Energy Company FENIE Energía Suffers Massive Data Breach

The Spanish electricity company FENIE Energía has been completely compromised in what represents a significant threat to critical infrastructure security. Following the company's failure to respond to extortion communications, threat actors released a sample of the company's database on a popular cybercrime forum. The breach encompasses 430 gigabytes of data containing over 1.7 million rows of information. Source: DarkWebInformer

This incident underscores the dangers of non-responsiveness to security threats and the vulnerability of energy sector organizations to targeted attacks. The scale of the breach and the public disclosure of samples suggest significant operational and privacy implications for the affected company and its customers.

European Commission Targeted by ShinyHunters in Major Data Breach

The European Commission has fallen victim to a substantial data breach attributed to the ShinyHunters threat group. Approximately 350 gigabytes of data from Commission systems bearing the europa.eu domain have been leaked by the attackers. Officials are currently investigating the breach, though independent verification of the claims remains pending. Source: HackRead

The breach of European Commission infrastructure represents a significant security incident at the highest levels of EU governance. The involvement of ShinyHunters, a known threat actor group, indicates a deliberate and sophisticated attack against one of Europe's most critical institutional targets.

White House Android Application Contains Dangerous Security Flaws

Security analysis of the official White House Android application has revealed multiple serious vulnerabilities and suspicious functionality embedded within the code. The application contains a cookie and paywall bypass injector, implements GPS tracking that activates every 4.5 minutes, and loads JavaScript code from an external GitHub Pages repository. Source: thereallo.dev

These findings raise substantial concerns about user privacy, application security practices, and the integrity of official government software. The presence of tracking functionality and external code loading mechanisms suggests either severe development oversights or intentional data collection practices that warrant immediate investigation and remediation.

BeamMP Gaming Mod Platform Compromised in Supply Chain Attack

BeamMP, a widely used modification platform for the BeamNG Drive racing simulator, has been compromised in what security researchers are investigating as a potential malware distribution incident. The compromise appears to have resulted in the delivery of malicious code to user machines through the mod distribution channel. Source: vxunderground

This supply chain attack demonstrates how threat actors continue to target gaming and modding communities as vectors for malware distribution. Users of the BeamMP platform should immediately assess their systems for signs of compromise and consider isolating affected machines pending further investigation.

Today's security landscape reflects persistent threats across multiple sectors, from critical infrastructure to government systems to consumer applications. Organizations and users must remain vigilant in monitoring for indicators of compromise and implementing immediate remediation measures for affected systems.

Sources & IOCs

Source articles and extracted indicators (defanged where appropriate).

I Decompiled the White House's New App
Domain2
  • whitehouse.gov
    WordPress REST API backend serving app content via /wp-json/whitehouse/v1 endpoints
  • ice.gov
    ICE tip reporting form hardcoded into app
URL1
  • hxxps://www[.]ice[.]gov/webform/ice-tip-form
    Direct link to ICE tip reporting form embedded in news app