Weekly review

ThreatNoir Morning Brief — May 26

2026-05-26Morning4 articles
Audio
Listen to the episode

Morning Review in IT Security — May 26, 2026

The cybercrime landscape continues to show active threat actors leveraging stolen databases and malicious tools across multiple sectors. Today's threat intelligence reveals data breaches affecting technology platforms, retail operations, and automotive companies, alongside the distribution of sophisticated attack infrastructure designed to circumvent modern defenses.

Bimetica User Database Offered for Sale by Threat Actor Sorb

A threat actor operating under the handle Sorb has surfaced on a popular cybercrime forum offering to sell an alleged user database belonging to Bimetica, a Building Information Modeling objects platform. The threat actor claims the compromised dataset contains approximately 157,000 user records spanning European customers. This incident underscores the ongoing vulnerability of specialized B2B platforms to data exfiltration campaigns. Source: DarkWebInformer

ARES PRIVATE DDoS Tool Advertised by Areshun

A threat actor known as Areshun has begun marketing a DDoS attack tool branded as "ARES PRIVATE" on cybercrime forums. The tool is marketed specifically as a layer-7 script engineered to evade detection and mitigation by major DDoS protection services. The availability of such specialized attack infrastructure demonstrates the commoditization of offensive capabilities within underground communities. Source: DarkWebInformer

Vigorbuy.com Suffers MySQL Database Breach

The Chinese B2C online retail marketplace Vigorbuy.com has been targeted in a data breach involving a MySQL database dump. A threat actor group identifying itself as NCO Group claims responsibility for the leak, which allegedly contains payment card information and user credentials. The breach represents a significant compromise of sensitive customer financial and authentication data. Source: Chinese Marketplace Vigorbuy.com Hit by Alleged MySQL Dump With Payment & Credential Data

Mercedes Customer Database Exposed on Underground Forum

A threat actor using the alias Edric is actively advertising a Mercedes automobile customer database containing over 130,000 records in spreadsheet formats on underground forums. The breach affects automotive industry customers and represents a substantial exposure of personal information tied to high-value consumer records. Source: Alleged 130K-Record Mercedes Automobile Customer Database Advertised on Forum

Security teams should prioritize monitoring for indicators of compromise related to these incidents and implement enhanced access controls for sensitive customer databases across all operational sectors.

Sources & IOCs

Source articles and extracted indicators (defanged where appropriate).