ctipilot.ch

Rhysida Stuttgart claim

incident · incident:rhysida-claims-stuttgart-municipal-data-5btc-city-denies-confirmed-incident

Rhysida claims Landeshauptstadt Stuttgart municipal-data theft for 5 BTC; the city denies a confirmed incident.

Coverage timeline
1
first 2026-05-18 → last 2026-05-18
Peak priority
notable
1 notable
Sources cited
2
2 hosts
Sections touched
1
weekly-sector-patterns
Co-occurring entities
0
no co-occurrence
ATT&CK techniques
0
no mapped behavior yet

Story timeline

  1. 2026-05-18Public administration — web-CMS and identity estate under multi-vector pressure
    weekly-sector-patterns

Where this entity is cited

  • weekly-sector-patterns1

Source distribution

  • cert.ssi.gouv.fr1 (50%)
  • krebsonsecurity.com1 (50%)

explore in graph

Entries about Rhysida Stuttgart claim (1)

2026-05-18 · view entry permalink →

NOTABLE

Public administration — web-CMS and identity estate under multi-vector pressure

Public-sector web and identity infrastructure took hits from several directions this week: the actively-exploited Drupal pre-auth SQLi (§ 1), ANSSI/CERT-FR's CERTFR-2026-AVI-0635 on SPIP < 4.4.15 (the dominant French public-administration CMS), the unpatched Sparx Enterprise Architect chain and the Keycloak IAM cluster (§ 3), and Webworm's pivot to EU government targets (§ 7). Add the Krebs-reported CISA-contractor exposure of AWS GovCloud admin keys in a public GitHub repo for ~6 months (daily 2026-05-19) and the Rhysida Stuttgart claim (§ 5), and the week's signal is that the public-administration estate's CMS, IAM and cloud-credential surfaces are all live targets simultaneously. Prioritise the CMS/IAM patch SLAs and audit cloud-credential hygiene in contractor repositories.

synthesis18 May 05:00Zmulti-sourceOpen finding ↗