French govt agency confirms breach as hacker offers to sell data

2026-04-22T01:23:25Z26ad4b4f7be4eee2caea6d4d05032bbf845222ce236d4f31c1397a47bfd02092
CISALazarusactive-exploitationandroidapache-activemqblackcatcrypto-theftcsamdata-breachdata-wiperhelpdesk-impersonationincident-responselegal-actionmalicious-appsmalwaremobile-malwarenation-stateransomwaresd-wansystembcvulnerabilitieswallet-theftwebsite-defacement

What happened

Multiple high-impact security incidents and active threats were reported: France Titres confirmed a citizen data breach with an actor attempting to sell stolen records; a previously undocumented Lotus data-wiping malware was used against Venezuelan energy and utility firms; CISA flagged a Catalyst SD‑WAN Manager vulnerability as actively exploited and Shadowserver found >6,400 Apache ActiveMQ servers vulnerable to an actively exploited code‑injection flaw. Other notable events include a $290M KelpDAO heist linked to North Korean (Lazarus) actors, trojanized Apple Wallet apps in China stealing

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
bleepingcomputer
Record identifier
26ad4b4f7be4eee2caea6d4d05032bbf845222ce236d4f31c1397a47bfd02092
Enrichment time
2026-04-22T01:23:25Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.