AntiMalwareJuly 16, 2026🇷🇺Translated from Russian

Solar inRights 3.11 Automatically Blocks Corporate Accounts Whose Passwords Appear in Dark Web Leaks

GC Solar has released Solar inRights 3.11, the latest version of its identity and access management solution that can automatically detect and neutralize corporate credentials exposed in data breaches and dark web dumps.

The system is now tightly integrated with the company’s Solar AURA external-threat monitoring service. Solar AURA continuously scans open sources and the dark web for employee login-password combinations; when matches are found, Solar inRights checks whether those same credentials are still valid inside the organization’s internal systems.

If a leaked pair is confirmed as active, the platform immediately blocks the account and notifies the information-security team, dramatically shortening the window between credential exposure and remediation.

The real-world attack scenario is straightforward: an employee reuses a corporate email address and a familiar password on an external website; that site is later breached, the credentials appear on underground forums, and an attacker tests them against the company’s VPN, mail, or cloud portals. Because the login looks legitimate, traditional perimeter defenses often fail to stop it.

According to Solar’s research, one large Russian organization had more than 600 unique corporate accounts circulating in public and shadow sources at any given time. Only around 4 percent of those records directly pointed to an ongoing infrastructure compromise, yet the remainder remain dangerous because of widespread password reuse.

Supporting statistics from Yandex Cloud show that the use of valid stolen credentials featured in 54 percent of more than 25,000 attack attempts against cloud and hybrid infrastructures during the first half of 2025.

Before the automated workflow introduced in version 3.11, security teams often had to correlate dark-web findings with internal directories manually, allowing days or weeks to pass between discovery and blocking. The new release aims to reduce that interval to a minimum.

In addition to the leak-response capability, Solar inRights 3.11 includes enhancements to search functions, request filters, and pre-built integration templates for Active Directory, Exchange, and 1C.

The core value of the update, however, lies in its proactive stance: the password may never be used because the door is already closed.

Related articles

AntiMalwareData Breaches & Leaks

Kaspersky MDR Adds Automatic Correlation with Leaked Credentials via Digital Footprint Intelligence

Kaspersky has updated its Managed Detection and Response service to automatically match security events against data from compromised logins and passwords. The enhancement integrates Kaspersky Digital Footprint Intelligence to provide analysts with additional context when suspicious activity coincides with known credential leaks. According to the company, a quarter of attacks investigated in 2025 began with the use of stolen credentials. The update also introduces notifications for asset protection status, allowing administrators to address connectivity or telemetry issues that could affect monitoring quality. Managed service providers can now configure per-client license usage limits, and the service adds support for Kaspersky Embedded Systems Security for Linux 4.0. The MDR platform continues to deliver 24/7 infrastructure monitoring, threat hunting, incident investigation, and response capabilities.

AntiMalwareData Breaches & Leaks

Hacktivist Group Cyberleek Leaks Alleged GTA VI Gameplay and Map Details in Protest Against Digital-Only Releases

A hacktivist collective calling itself Cyberleek has released two purported gameplay clips from GTA VI along with images that may depict the full map of Leonida state. The group claims the leak is a protest against Rockstar's decision to sell physical editions that contain only a download code rather than an actual disc. Cyberleek is also demanding an end to digital pre-orders, the practice of selling built-in content as DLC, and mandatory online connectivity for single-player modes. Rockstar and parent company Take-Two have already filed DMCA takedown requests, which some observers view as indirect confirmation of the material's authenticity. The footage reportedly shows basketball mechanics, vehicle customization, trunk-opening animations, a stamina meter, and an honor system reminiscent of Red Dead Redemption 2. The alleged map includes five counties, an extensive rail network, and numerous small islands. At the same time, Cyberleek is promoting a Solana-based token and soliciting donations, prompting several outlets to question whether the operation is partly a cryptocurrency marketing scheme.

AntiMalwareData Breaches & Leaks

Russian Medical Data Leaks Explode in July: 88 Million Records Exposed

In July 2026 more than 100 million records containing personal data of Russian citizens appeared in open access. Experts from Perspektivny Monitoring recorded 17 separate leaks originating from commercial organizations, online platforms, government bodies, e-commerce stores and medical institutions. The medical sector accounted for the overwhelming majority with 88.37 million records leaked, a sharp increase from 1.7 million in June. Two major incidents, one involving a large medical information system, drove the spike. Head of cyber threat research Nikolay Galkin stated that medical data has now leaked for four consecutive months and that attackers are deliberately targeting highly sensitive information. Other sectors also suffered losses, with 11.12 million records from commercial entities, 8.45 million from online platforms, 8.36 million from government organizations and 2.1 million from internet shops. Stolen databases are routinely traded in messenger channels and dark web marketplaces for use in fraud schemes.

BoletimSecData Breaches & Leaks

SplitVPN Data Breach Exposes Personal Information of 865,000 Users

A data breach at the Russian VPN provider SplitVPN, formerly known as NotVPN, has exposed the personal details of approximately 865,000 users. The incident, which occurred in July 2026, involved a 17 GB SQL database containing emails, IP addresses, geolocation data, and partial payment card information. The stolen material was later distributed on a cybercrime forum, revealing 23.4 million user records, 13.6 million devices, and 2.6 million payment entries. Nearly 58 million connection logs spanning June 2025 to 21 July 2026 were also included, contradicting the company’s previous no-logs policy. The exposure is particularly concerning for users relying on the service to evade censorship and surveillance.