Skip to main content

Attack-pattern intelligence · rolling 90-day view

Vulnerability Exploitation & Cyber Intrusions: News & Guidance

Vulnerability exploitation occurs when an attacker uses a security flaw to gain access, execute code or expand control. This page includes only incidents with explicit exploit, zero-day or CVE evidence—not every broadly reported intrusion.

Practical overview

How does vulnerability exploitation work, and what should defenders look for?

How does it work?

  • Attackers identify reachable vulnerable technology and use a flaw to bypass a control, execute code, access data or establish an initial foothold.
  • Exploitation may be automated at internet scale or carefully targeted against a specific product, organization or supply-chain position.
  • After entry, attackers can add persistence, steal credentials, move to other systems or deploy malware, so patching alone may not remove an established compromise.

Which organizations are targeted?

  • Internet-facing gateways, remote-access products, collaboration systems and management tools are attractive because one flaw can expose many organizations.
  • Widely used enterprise software and supplier platforms can create concentrated risk across customers and sectors.
  • Organizations with slow asset discovery or patch validation may remain exposed even after a vulnerability becomes public.

What are the signs and impacts?

  • Unexpected processes, web shells, unusual administrative activity and connections from exposed appliances can indicate successful exploitation.
  • Impact ranges from initial access and data theft to service disruption, lateral movement and downstream compromise.
  • Scanner activity does not prove compromise; defenders need product-specific evidence and telemetry from the relevant exposure window.

How should organizations respond?

  • Identify affected products and versions, confirm external reachability and prioritize assets by business criticality and observed exploitation evidence.
  • Apply vendor mitigations or patches, but also hunt for product-specific indicators and credentials or sessions that may have been exposed.
  • Document what was exposed, when it was remediated and how compromise was ruled in or out so risk decisions remain auditable.

Current evidence

What vulnerability exploitation incidents are being reported?

Explore all live cyber intelligence

Signals appear here only when the title, summary or a sufficiently specific VERIS value supports this classification. The feed is current reporting, not a measure of total incident prevalence.

Yonsei logoUse of stolen credentials or exploit
High

South Korean Diplomatic Academy Suffers Significant Data Leak Affecting 10,000 Diplomats

On July 21, 2026, the Korea National Diplomatic Academy, an institution affiliated with South Korea's Ministry of Foreign Affairs, confirmed a significant data leak impacting approximately 10,000 records of current and retired diplomats. The breach, which occurred in the academy's online education system, was discovered in early February 2026 after suspicious access was reported by a government agency. An unidentified attacker exploited a zero-day vulnerability in the server software and weaknesses in system security settings, maintaining unauthorized access from April to May 2025 until February 2026. The compromised data reportedly included names, user IDs, email addresses, encrypted passwords, job titles, and affiliated departments. While sensitive personal information such as resident registration numbers, mobile phone numbers, and home addresses were not present on the affected server, the leak of diplomat information raises concerns, especially given that the full list of diplomats and personnel at overseas missions is not publicly disclosed. The Foreign Ministry is investigating the incident and has urgently shut down the compromised system. They are operating under the assumption that a substantial volume of data was compromised, though the exact scale of the damage is still being assessed. The incident highlights the challenges in detecting sophisticated attacks that leverage previously unknown vulnerabilities.

Yonsei
Naic logoUse of stolen credentials or exploit
Medium

National Association of Insurance Commissioners (NAIC) Confirms Data Breach via Oracle PeopleSoft Zero-Day

The National Association of Insurance Commissioners (NAIC), a US insurance regulatory standards body, confirmed a cyberattack after the ShinyHunters group claimed theft of 3.1TB of data. The breach was reportedly achieved through an Oracle PeopleSoft zero-day vulnerability. ShinyHunters claimed access to regulatory filings, production logs, cloud configuration files, and other internal records.

Naic
Hackerone logoRansomware
Medium

HackerOne Affected by Klue Supply Chain Attack

At least nine organizations have publicly acknowledged the impact of the supply chain attack on market intelligence platform Klue. The incident occurred on June 11-12 and affected Klue’s integration with Salesforce, resulting in data being exfiltrated from the Salesforce instances of multiple Klue customers, including several cybersecurity firms. On Friday, Klue confirmed previous security reports that the attackers used compromised legacy credentials to access its systems and compromise Salesforce integrations. “The attacker used that access to obtain OAuth tokens used to connect Klue with certain third-party platforms, including Salesforce, and subsequently accessed data within a number of connected customer environments,” Klue said. The company revoked the affected credentials and tokens, disabled the integrations across multiple services, and has been investigating the attack together with CrowdStrike and law enforcement. “Based on our investigation to date, the incident was limited to the affected third-party platforms, and there is no evidence that customer content stored within the Klue platform was impacted,” the company said. Advertisement. Scroll to continue reading. To date, at least nine Klue customers have disclosed impact from the incident, including cybersecurity firms HackerOne , Huntress , Jamf , OneTrust , Recorded Future , Snyk , and Tanium . Insurity and Sprout Social also notified their customers of the incident. All the affected companies pointed out that the intrusion was limited to the Salesforce instances and did not involve their systems, as Klue said in its incident notice. Across the board, the hackers stole business information from the affected organizations’ Salesforce CRMs, including sales account data and business contact information, such as names, email addresses, job titles, phone numbers, and business addresses. Salesforce disabled the Klue integration in the wake of the incident, and revenue intelligence platform Gong did the same on Friday, warning that the hackers exploited its Klue integration to access internal licensed user data. “We can confirm no direct impact on call recordings or customer transcripts. Examples of data accessed included user names, user business titles, and user emails,” Gong said. In its analysis of the incident, Huntress suggested that a threat actor named Icarus might have been responsible for the attack. Since then, Icarus has added Klue to its Tor-based leak site, claiming responsibility for the attack and threatening to publish the information stolen from Klue customers’ Salesforce instances. Per the threat actor’s posts, the data would be released on June 22, unless Klue and the affected organizations engage in negotiations. Related: Cybersecurity Firms Impacted by Klue Supply Chain Attack Related: Atomic Arch Supply Chain Attack Hits 1,500 AUR Packages Related: ‘SymJack’ Attack Turns AI Coding Agents Into Supply Chain Attack Delivery Systems Related: Laravel-Lang Packages Poisoned for Malware Delivery Written By Ionut Arghire Ionut Arghire is an international correspondent for SecurityWeek. New HollowGraph Malware Abuses Microsoft 365 Calendar for C&C Communication Estée Lauder Discloses Impact From Oracle EBS Zero-Day Hack Clover Health Investments Discloses Data Breach Zimbra Update Patches Critical Vulnerabilities OpenSSL Silently Fixes ‘HollowByte’ DoS Vulnerability Ernst & Young Data Breach Affects Personal, Financial Information Hugging Face Hacked in Autonomous AI Attack Chrome 150 Update Patches Severe Memory Safety Bugs Fourth SharePoint Vulnerability Exploited in Past Month’s Wave of Attacks Endpoint Security Firm Glow Launches With $180M in Funding at $1.2B Valuation Oracle Patches Over 1,400 Vulnerabilities With Quarterly Security Updates Ransomware Group Threatening to Leak Data Stolen From Coca-Cola’s Fairlife OpenAI Says Its AI Models Broke Loose and Hacked Hugging Face Trump Orders Defense Contractors to Map Software, Suppliers Across Critical Supply Chains Cisco Launches Low-Cost AI Models for Source Code Security Empirical Security Raises $25 Million in Series A Funding LastPass is the latest cybersecurity firm to have disclosed the impact from the Klue hack, which resulted in unauthorized access to customers’ Salesforce instances. A threat actor calling itself Icarus used a compromised legacy credential to access Klue’s systems and generate OAuth tokens to breach third-party platforms Klue integrates with, such as Salesforce. Icarus then accessed the connected Salesforce instances and exfiltrated data in bulk , using automated scripts. Salesforce and Gong have disabled the Klue integration in response to the attack, and over a dozen organizations have already confirmed the impact. Incident notifications from the affected companies reveal that the attackers accessed business data accessible through the Klue integration, and that no internal systems were compromised. LastPass’s notice follows the same lines: “The information accessed was limited to standard business contact information and related customer relationship management (CRM) data, including customer names, phone numbers, email addresses, and physical addresses, as well as support case data and sales-related data.” The company says it has discontinued access to Klue, rotated exposed tokens, notified law enforcement, and launched an investigation together with Klue and Salesforce. Advertisement. Scroll to continue reading. “It is important to note that the scope of this incident is limited to only those systems that integrate with Klue’s application. LastPass products, services, and infrastructure were not impacted in any way, and customer vaults remain secure. There is also no evidence the threat actor accessed any Gong-related data,” LastPass said. This week, in addition to LastPass, 8×8 and Pendo announced they were affected. Late last week, HackerOne, Huntress, Insurity, Jamf, OneTrust, Recorded Future, Snyk, Sprout Social, and Tanium disclosed the impact from the attack. BeyondTrust also said business contact and sales-related information was stolen from its Salesforce instance, but the notification went unnoticed. On its Tor-based leak site, Icarus has listed several organizations as having their Salesforce data stolen, including Swiss AI communications solutions provider Gms-net. SecurityWeek has emailed the technology company for a statement and will update this article if it responds. Icarus’s website is currently down but, before becoming inaccessible, it listed at least four other companies that have yet to publicly disclose being affected by the Klue incident, which brings the number of victims to roughly 15. Per Huntress’s estimates, however, numerous other Klue customers were likely impacted by the data breach and are expected to come forward. Empirical Security Raises $25 Million in Series A Funding

Hackerone
Londonhydro logoRansomware
Medium

London Hydro Discloses Data Breach Affecting Customer Information

Canadian electricity provider London Hydro is investigating a data breach that potentially impacted the personal and account information of its customers. London Hydro is a local distribution company serving the City of London, Ontario. It serves roughly 170,000 residential, institutional, commercial, and industrial customers. On June 20, the electricity provider announced that hackers had broken into its systems and that customers’ data was likely accessed. “London Hydro and the appropriate authorities are currently investigating a data security incident which may have impacted a portion of personal information on some accounts,” the company said . The potentially affected data includes personal information such as names, addresses, email addresses, and phone numbers. Account information, including account and billing numbers, service addresses, pricing plans, contract dates, and meter numbers and types, might have been impacted as well. Advertisement. Scroll to continue reading. According to London Hydro, no financial or other sensitive information might have been compromised in the data breach.   “The incident did not involve access to financial information or other sensitive categories of information, such as your date of birth, government identification numbers, payment card details, or banking information,” the company said. London Hydro urges customers to be wary of suspicious activity related to their accounts and personal information, including phishing messages, emails, or phone calls. It’s unclear who is responsible for the attack. No known cybercrime group appears to have taken credit for hacking London Hydro. Related: North Korean Hackers Blamed for Mastra NPM Supply Chain Attack Related: More Cybersecurity Firms Disclose Impact From Klue Hack Related: What the Latest ShinyHunters Breaches Reveal About Modern Cyberattacks Related: Texas Parks & Wildlife Data Breach Affects 3 Million Individuals Written By Ionut Arghire Ionut Arghire is an international correspondent for SecurityWeek. New HollowGraph Malware Abuses Microsoft 365 Calendar for C&C Communication Estée Lauder Discloses Impact From Oracle EBS Zero-Day Hack Clover Health Investments Discloses Data Breach Zimbra Update Patches Critical Vulnerabilities OpenSSL Silently Fixes ‘HollowByte’ DoS Vulnerability Ernst & Young Data Breach Affects Personal, Financial Information Hugging Face Hacked in Autonomous AI Attack Chrome 150 Update Patches Severe Memory Safety Bugs Fourth SharePoint Vulnerability Exploited in Past Month’s Wave of Attacks Endpoint Security Firm Glow Launches With $180M in Funding at $1.2B Valuation Oracle Patches Over 1,400 Vulnerabilities With Quarterly Security Updates Ransomware Group Threatening to Leak Data Stolen From Coca-Cola’s Fairlife OpenAI Says Its AI Models Broke Loose and Hacked Hugging Face Trump Orders Defense Contractors to Map Software, Suppliers Across Critical Supply Chains Cisco Launches Low-Cost AI Models for Source Code Security Empirical Security Raises $25 Million in Series A Funding Join this live webinar as we explore why exploitation is outpacing remediation, where risk is growing fastest, and what security leaders can do to close the gap before attackers take advantage. CodeSecCon bridges the gap between dev and security. Discover best practices for secure coding, innovative risk-reduction tools, and safe AI integration to cultivate a true DevSecOps culture. Safely secure your apps! Jazz has named Sean Robinson, Rickie Goyal, Danielle Guetta, Shani Nago, and Lior Magram as VPs and Michael Calev as COO.

Londonhydro
Huntress logoRansomware
Medium

Huntress Affected by Klue Supply Chain Attack, Salesforce Data Exfiltrated

At least nine organizations have publicly acknowledged the impact of the supply chain attack on market intelligence platform Klue. The incident occurred on June 11-12 and affected Klue’s integration with Salesforce, resulting in data being exfiltrated from the Salesforce instances of multiple Klue customers, including several cybersecurity firms. On Friday, Klue confirmed previous security reports that the attackers used compromised legacy credentials to access its systems and compromise Salesforce integrations. “The attacker used that access to obtain OAuth tokens used to connect Klue with certain third-party platforms, including Salesforce, and subsequently accessed data within a number of connected customer environments,” Klue said. The company revoked the affected credentials and tokens, disabled the integrations across multiple services, and has been investigating the attack together with CrowdStrike and law enforcement. “Based on our investigation to date, the incident was limited to the affected third-party platforms, and there is no evidence that customer content stored within the Klue platform was impacted,” the company said. Advertisement. Scroll to continue reading. To date, at least nine Klue customers have disclosed impact from the incident, including cybersecurity firms HackerOne , Huntress , Jamf , OneTrust , Recorded Future , Snyk , and Tanium . Insurity and Sprout Social also notified their customers of the incident. All the affected companies pointed out that the intrusion was limited to the Salesforce instances and did not involve their systems, as Klue said in its incident notice. Across the board, the hackers stole business information from the affected organizations’ Salesforce CRMs, including sales account data and business contact information, such as names, email addresses, job titles, phone numbers, and business addresses. Salesforce disabled the Klue integration in the wake of the incident, and revenue intelligence platform Gong did the same on Friday, warning that the hackers exploited its Klue integration to access internal licensed user data. “We can confirm no direct impact on call recordings or customer transcripts. Examples of data accessed included user names, user business titles, and user emails,” Gong said. In its analysis of the incident, Huntress suggested that a threat actor named Icarus might have been responsible for the attack. Since then, Icarus has added Klue to its Tor-based leak site, claiming responsibility for the attack and threatening to publish the information stolen from Klue customers’ Salesforce instances. Per the threat actor’s posts, the data would be released on June 22, unless Klue and the affected organizations engage in negotiations. Related: Cybersecurity Firms Impacted by Klue Supply Chain Attack Related: Atomic Arch Supply Chain Attack Hits 1,500 AUR Packages Related: ‘SymJack’ Attack Turns AI Coding Agents Into Supply Chain Attack Delivery Systems Related: Laravel-Lang Packages Poisoned for Malware Delivery Written By Ionut Arghire Ionut Arghire is an international correspondent for SecurityWeek. New HollowGraph Malware Abuses Microsoft 365 Calendar for C&C Communication Estée Lauder Discloses Impact From Oracle EBS Zero-Day Hack Clover Health Investments Discloses Data Breach Zimbra Update Patches Critical Vulnerabilities OpenSSL Silently Fixes ‘HollowByte’ DoS Vulnerability Ernst & Young Data Breach Affects Personal, Financial Information Hugging Face Hacked in Autonomous AI Attack Chrome 150 Update Patches Severe Memory Safety Bugs Endpoint Security Firm Glow Launches With $180M in Funding at $1.2B Valuation Oracle Patches Over 1,400 Vulnerabilities With Quarterly Security Updates Ransomware Group Threatening to Leak Data Stolen From Coca-Cola’s Fairlife OpenAI Says Its AI Models Broke Loose and Hacked Hugging Face Trump Orders Defense Contractors to Map Software, Suppliers Across Critical Supply Chains Cisco Launches Low-Cost AI Models for Source Code Security Empirical Security Raises $25 Million in Series A Funding SecurityWeek Launches Critical Impact Awards to Recognize Excellence in Industrial Cybersecurity LastPass is the latest cybersecurity firm to have disclosed the impact from the Klue hack, which resulted in unauthorized access to customers’ Salesforce instances. A threat actor calling itself Icarus used a compromised legacy credential to access Klue’s systems and generate OAuth tokens to breach third-party platforms Klue integrates with, such as Salesforce. Icarus then accessed the connected Salesforce instances and exfiltrated data in bulk , using automated scripts. Salesforce and Gong have disabled the Klue integration in response to the attack, and over a dozen organizations have already confirmed the impact. Incident notifications from the affected companies reveal that the attackers accessed business data accessible through the Klue integration, and that no internal systems were compromised. LastPass’s notice follows the same lines: “The information accessed was limited to standard business contact information and related customer relationship management (CRM) data, including customer names, phone numbers, email addresses, and physical addresses, as well as support case data and sales-related data.” The company says it has discontinued access to Klue, rotated exposed tokens, notified law enforcement, and launched an investigation together with Klue and Salesforce. Advertisement. Scroll to continue reading. “It is important to note that the scope of this incident is limited to only those systems that integrate with Klue’s application. LastPass products, services, and infrastructure were not impacted in any way, and customer vaults remain secure. There is also no evidence the threat actor accessed any Gong-related data,” LastPass said. This week, in addition to LastPass, 8×8 and Pendo announced they were affected. Late last week, HackerOne, Huntress, Insurity, Jamf, OneTrust, Recorded Future, Snyk, Sprout Social, and Tanium disclosed the impact from the attack. BeyondTrust also said business contact and sales-related information was stolen from its Salesforce instance, but the notification went unnoticed. On its Tor-based leak site, Icarus has listed several organizations as having their Salesforce data stolen, including Swiss AI communications solutions provider Gms-net. SecurityWeek has emailed the technology company for a statement and will update this article if it responds. Icarus’s website is currently down but, before becoming inaccessible, it listed at least four other companies that have yet to publicly disclose being affected by the Klue incident, which brings the number of victims to roughly 15. Per Huntress’s estimates, however, numerous other Klue customers were likely impacted by the data breach and are expected to come forward. New HollowGraph Malware Abuses Microsoft 365 Calendar for C&C Communication

Huntress
Sproutsocial logoRansomware
High

Sprout Social Salesforce CRM Data Accessed via Klue Security Incident

LastPass is the latest cybersecurity firm to have disclosed the impact from the Klue hack, which resulted in unauthorized access to customers’ Salesforce instances. A threat actor calling itself Icarus used a compromised legacy credential to access Klue’s systems and generate OAuth tokens to breach third-party platforms Klue integrates with, such as Salesforce. Icarus then accessed the connected Salesforce instances and exfiltrated data in bulk , using automated scripts. Salesforce and Gong have disabled the Klue integration in response to the attack, and over a dozen organizations have already confirmed the impact. Incident notifications from the affected companies reveal that the attackers accessed business data accessible through the Klue integration, and that no internal systems were compromised. LastPass’s notice follows the same lines: “The information accessed was limited to standard business contact information and related customer relationship management (CRM) data, including customer names, phone numbers, email addresses, and physical addresses, as well as support case data and sales-related data.” The company says it has discontinued access to Klue, rotated exposed tokens, notified law enforcement, and launched an investigation together with Klue and Salesforce. Advertisement. Scroll to continue reading. “It is important to note that the scope of this incident is limited to only those systems that integrate with Klue’s application. LastPass products, services, and infrastructure were not impacted in any way, and customer vaults remain secure. There is also no evidence the threat actor accessed any Gong-related data,” LastPass said. This week, in addition to LastPass, 8×8 and Pendo announced they were affected. Late last week, HackerOne, Huntress, Insurity, Jamf, OneTrust, Recorded Future, Snyk, Sprout Social, and Tanium disclosed the impact from the attack. BeyondTrust also said business contact and sales-related information was stolen from its Salesforce instance, but the notification went unnoticed. On its Tor-based leak site, Icarus has listed several organizations as having their Salesforce data stolen, including Swiss AI communications solutions provider Gms-net. SecurityWeek has emailed the technology company for a statement and will update this article if it responds. Icarus’s website is currently down but, before becoming inaccessible, it listed at least four other companies that have yet to publicly disclose being affected by the Klue incident, which brings the number of victims to roughly 15. Per Huntress’s estimates, however, numerous other Klue customers were likely impacted by the data breach and are expected to come forward. Related: North Korean Hackers Blamed for Mastra NPM Supply Chain Attack Related: OpenAI Refocuses Cybersecurity Efforts on Patching Over Discovery Related: Russian Initial Access Broker Behind FortiBleed Campaign Related: Canadian Electricity Provider London Hydro Discloses Data Breach Written By Ionut Arghire Ionut Arghire is an international correspondent for SecurityWeek. New HollowGraph Malware Abuses Microsoft 365 Calendar for C&C Communication Estée Lauder Discloses Impact From Oracle EBS Zero-Day Hack Clover Health Investments Discloses Data Breach Zimbra Update Patches Critical Vulnerabilities OpenSSL Silently Fixes ‘HollowByte’ DoS Vulnerability Ernst & Young Data Breach Affects Personal, Financial Information Hugging Face Hacked in Autonomous AI Attack Chrome 150 Update Patches Severe Memory Safety Bugs Fourth SharePoint Vulnerability Exploited in Past Month’s Wave of Attacks Endpoint Security Firm Glow Launches With $180M in Funding at $1.2B Valuation Oracle Patches Over 1,400 Vulnerabilities With Quarterly Security Updates Ransomware Group Threatening to Leak Data Stolen From Coca-Cola’s Fairlife OpenAI Says Its AI Models Broke Loose and Hacked Hugging Face Trump Orders Defense Contractors to Map Software, Suppliers Across Critical Supply Chains Cisco Launches Low-Cost AI Models for Source Code Security Empirical Security Raises $25 Million in Series A Funding Join this live webinar as we explore why exploitation is outpacing remediation, where risk is growing fastest, and what security leaders can do to close the gap before attackers take advantage.

Sproutsocial
Siemens logoMisconfiguration or publishing error
Medium

FortiBleed Campaign Compromises Fortinet Devices, Exposing Siemens Credentials

Alert - AL26-014 – FortiBleed leak of thousands of compromised credentials impacting Fortinet devices This Alert is intended for IT professionals and managers. An Alert is used to raise awareness of a recently identified cyber threat that may impact cyber information assets, and to provide additional detection and mitigation advice to recipients. The Canadian Centre for Cyber Security ("Cyber Centre") is also available to provide additional assistance regarding the content of this Alert to recipients as requested. On June 17, 2026, the Canadian Centre for Cyber Security (Cyber Centre) became aware of open-source reporting Footnote 1 Footnote 2 Footnote 3 Footnote 4 describing a widespread malicious campaign, known as “FortiBleed,” involving exposed credentials affecting Fortinet firewalls and VPN gateways. Exploitation of these credentials could allow malicious actors to gain remote access to affected devices and connected networks, as well as modify various system settings, including critical security controls. The Cyber Centre strongly recommends that organizations : Inventory all accounts on Fortinet devices, identify unauthorized or suspicious accounts (e.g., forticloud-sync , forticloud-tech ) and disable/remove suspected or unneeded accounts. Restrict access to management interfaces to trusted networks and hosts only. Terminate all active SSL VPN and administrative sessions. Reset passwords for all Fortinet VPN and administrative accounts. Enforce Multi-Factor Authentication (MFA) across all external gateways and admin interfaces. Ensure all Fortinet devices are running the latest firmware. Specifically, check for patches related to CVE-2024-55591 (obtain high privileges) Footnote 5 and, CVE-2025-59718 Footnote 6 and CVE-2025-59719 Footnote 7 (authentication bypass) Footnote 8 . In addition, the Cyber Centre strongly recommends that organizations review and implement the Cyber Centre’s Top 10 IT Security Actions with an emphasis on the following topics Footnote 9 . Consolidate, monitor and defend Internet gateways Patch operating systems and applications Enforce the management of administrative privileges Harden operating systems and applications Should activity matching the content of this alert be discovered, recipients are encouraged to report via My Cyber Portal , or email contact@cyber.gc.ca . FortiBleed: 75,000 Fortinet Firewalls Compromised: Global Enterprises Exposed – Claim Your Ethical Disclosure Fortinet firewalls and VPN gateways serve as the primary defensive perimeter for countless organizations worldwide. However, a massive new cyber espionage campaign has silently compromised these highly trusted devices on an unprecedented global scale. Originally discovered by security researcher Volodymyr “Bob” Diachenko , with further analysis from Hudson Rock and cybersecurity expert Kevin Beaumont , this dataset exposes a massive, automated operation. Threat actors successfully targeted 73,932 unique firewall URLs across 194 countries, resulting in 21,632 unique affected domains . Astonishingly, as Beaumont highlighted, this represents roughly 50% of all Fortinet firewall devices currently facing the internet . Attacker Methodology & Unprecedented Scale According to Diachenko’s investigative report, this campaign is orchestrated by a multi-operator, Russian-speaking cybercriminal group. The operation’s footprint is staggering: the attackers executed an estimated 1.16 billion credential attempts against over 320,000 FortiGate targets, alongside an additional 2.1 billion brute-force attempts directed at over 160,000 MSSQL servers. The group’s methodology goes beyond simple credential reuse. They actively intercept SSL VPN authentication hashes and crack them using a massive, dedicated 45-GPU cluster managed via Hashtopolis. Once the perimeter is breached, the operators systematically pivot directly into internal Active Directory environments to establish deep network persistence. This aggressive methodology has led to severe, real-world consequences. Diachenko’s research confirmed full network compromises at multiple organizations across Japan, Taiwan, Vietnam, Iraq, and Turkey. Most alarmingly, this includes a Turkish NATO defense contractor from which classified defense documents were successfully exfiltrated by the group. Beaumont notes a sharp contrast between this incident and the prior “Belsen Group” leak of 15,000 devices from a 2022 zero-day. This dataset represents active, recent compromises—with many of the affected devices running recent patches. Furthermore, Beaumont observed that the formatting of the leaked data, which explicitly categorizes victims by company type, revenue, and country, is a hallmark of eCrime syndicates packaging initial access for sale on the dark web. As Beaumont explains in his blog , the attackers likely exploited older credential hashing mechanisms to pull this off. While Fortinet hardened admin credential storage in early 2025 by moving to PBKDF2, this protection only applied if administrators actively logged in after applying the firmware updates. Consequently, many devices continued storing credentials using the older, more vulnerable SHA-256 with Salt format, making them highly susceptible to offline brute-forcing once the configuration files were extracted. The scale of this breach touches nearly every sector of the global economy, sparing no industry. The threat actors have built a verified database of working credentials for some of the largest enterprises on the planet. Among the victims discovered in this dataset are massive multinational corporations, including: …and thousands of others, including major government entities and critical infrastructure providers. When examining the attacker infrastructure, it becomes clear how systematic and devastating this campaign is. The attackers maintained highly organized logs of successful breaches. A particularly alarming detail from this dataset is the high volume of extremely complex passwords that were successfully compromised. IT departments frequently lean on rigid password complexity rules as their main line of defense. However, complexity is completely neutralized when passwords are recovered in plaintext. Whether threat actors leverage specific device exploits that expose plaintext credentials, or utilize databases previously harvested by Infostealers, a 20-character complex string is just as vulnerable as a simple one. If the attackers are recycling known plaintext credentials to bypass perimeters, complexity policies offer no protection. To secure your network against this specific vector, we strongly recommend the following immediate actions: Remove Internet Exposure: Immediately ensure the FortiOS Management Interface is not exposed to the public internet unless absolutely necessary. Force Credential Rotation & Upgrade Hashing: Upgrade to the latest FortiOS release and have all admins log back in to force the system to re-hash passwords using the more secure PBKDF2 standard. Enforce Strict MFA: Ensure Multi-Factor Authentication is universally applied to all external gateways and admin interfaces, effectively neutralizing the threat of stolen plaintext passwords. 🚨 Free Look-Up Tool for Affected Organizations

Siemens
Recordedfuture logoRansomware
High

Recorded Future Salesforce Account Affected by Klue Security Incident

At least nine organizations have publicly acknowledged the impact of the supply chain attack on market intelligence platform Klue. The incident occurred on June 11-12 and affected Klue’s integration with Salesforce, resulting in data being exfiltrated from the Salesforce instances of multiple Klue customers, including several cybersecurity firms. On Friday, Klue confirmed previous security reports that the attackers used compromised legacy credentials to access its systems and compromise Salesforce integrations. “The attacker used that access to obtain OAuth tokens used to connect Klue with certain third-party platforms, including Salesforce, and subsequently accessed data within a number of connected customer environments,” Klue said. The company revoked the affected credentials and tokens, disabled the integrations across multiple services, and has been investigating the attack together with CrowdStrike and law enforcement. “Based on our investigation to date, the incident was limited to the affected third-party platforms, and there is no evidence that customer content stored within the Klue platform was impacted,” the company said. Advertisement. Scroll to continue reading. To date, at least nine Klue customers have disclosed impact from the incident, including cybersecurity firms HackerOne , Huntress , Jamf , OneTrust , Recorded Future , Snyk , and Tanium . Insurity and Sprout Social also notified their customers of the incident. All the affected companies pointed out that the intrusion was limited to the Salesforce instances and did not involve their systems, as Klue said in its incident notice. Across the board, the hackers stole business information from the affected organizations’ Salesforce CRMs, including sales account data and business contact information, such as names, email addresses, job titles, phone numbers, and business addresses. Salesforce disabled the Klue integration in the wake of the incident, and revenue intelligence platform Gong did the same on Friday, warning that the hackers exploited its Klue integration to access internal licensed user data. “We can confirm no direct impact on call recordings or customer transcripts. Examples of data accessed included user names, user business titles, and user emails,” Gong said. In its analysis of the incident, Huntress suggested that a threat actor named Icarus might have been responsible for the attack. Since then, Icarus has added Klue to its Tor-based leak site, claiming responsibility for the attack and threatening to publish the information stolen from Klue customers’ Salesforce instances. Per the threat actor’s posts, the data would be released on June 22, unless Klue and the affected organizations engage in negotiations. Related: Cybersecurity Firms Impacted by Klue Supply Chain Attack Related: Atomic Arch Supply Chain Attack Hits 1,500 AUR Packages Related: ‘SymJack’ Attack Turns AI Coding Agents Into Supply Chain Attack Delivery Systems Related: Laravel-Lang Packages Poisoned for Malware Delivery Written By Ionut Arghire Ionut Arghire is an international correspondent for SecurityWeek. New HollowGraph Malware Abuses Microsoft 365 Calendar for C&C Communication Estée Lauder Discloses Impact From Oracle EBS Zero-Day Hack Clover Health Investments Discloses Data Breach Zimbra Update Patches Critical Vulnerabilities OpenSSL Silently Fixes ‘HollowByte’ DoS Vulnerability Ernst & Young Data Breach Affects Personal, Financial Information Hugging Face Hacked in Autonomous AI Attack Chrome 150 Update Patches Severe Memory Safety Bugs Fourth SharePoint Vulnerability Exploited in Past Month’s Wave of Attacks Endpoint Security Firm Glow Launches With $180M in Funding at $1.2B Valuation Oracle Patches Over 1,400 Vulnerabilities With Quarterly Security Updates Ransomware Group Threatening to Leak Data Stolen From Coca-Cola’s Fairlife OpenAI Says Its AI Models Broke Loose and Hacked Hugging Face Trump Orders Defense Contractors to Map Software, Suppliers Across Critical Supply Chains Cisco Launches Low-Cost AI Models for Source Code Security Empirical Security Raises $25 Million in Series A Funding Klue OAuth breach victim list grows as Icarus hackers claim attack Market intelligence platform Klue has publicly confirmed a recent security incident that allowed threat actors to steal OAuth tokens used to connect to customers' Salesforce environments, as the new "Icarus" extortion group publicly claims the attack. The disclosure comes after cybersecurity firms Huntress and ReliaQuest detailed how attackers abused compromised Klue Battlecards integrations to steal Salesforce CRM data from multiple organizations. In a statement published this week, Klue CEO Jason Smith confirmed that the company discovered unauthorized activity on June 12 affecting part of Klue's integration infrastructure. "On June 12, we identified unauthorized activity affecting a portion of Klue's integration infrastructure. Since then, we've been working alongside trusted cybersecurity experts to understand what happened, support our customers, and restore the connections you rely on," wrote Smith . "Our investigation determined that an attacker gained access through a compromised legacy credential associated with an integration service. The attacker used that access to obtain OAuth tokens used to connect Klue with certain third-party platforms, including Salesforce, and subsequently accessed data within a number of connected customer environments." The company says there is currently no evidence that customer content stored directly within the Klue platform was impacted and that the incident was limited to third-party integrations. Klue says it immediately revoked affected credentials and tokens, removed unauthorized code, disabled impacted integrations, launched an investigation, and notified law enforcement. The company also confirmed it engaged CrowdStrike to assist with the response. ReliaQuest and Huntress found that the attackers used stolen OAuth credentials associated with Klue integrations to access customer Salesforce environments and conduct large-scale data theft. ReliaQuest observed attackers generating OAuth tokens and using Python scripts to query Salesforce's API for extended periods, as data was stolen. Huntress later disclosed that its own Salesforce environment was affected by the Klue breach and that the stolen data included business contacts, sales communications, pricing information, and other records. While BleepingComputer and Huntress previously linked the incident to the Icarus extortion operation, the threat actors have now publicly claimed responsibility on their data leak site. "As you've probably already heard, Klue.com has been impacted by us recently. A number of other companies' Salesforce instances, which were partners to Klue, were exfiltrated," reads the Icarus post. Security teams log 54% of successful attacks and alert on just 14%. The rest move through your environment unseen.

Recordedfuture
Nottingham logoRansomware
Medium

University of Nottingham Data Breach Affects Over 450,000 Students

The University of Nottingham in the UK has confirmed suffering a data breach after the notorious ShinyHunters hacker collective leaked files stolen from the university’s systems. The University of Nottingham is a major research university in the UK, ranked among the world’s top 100 institutions and home to more than 35,000 students on its UK campuses, plus thousands more at its international branches in China and Malaysia. The ShinyHunters group listed the organization on its leak website and published gigabytes of files allegedly stolen from its systems. The hackers claimed to have obtained financial information pertaining to all of the university’s campuses.  University of Nottingham hacked by ShinyHunters An analysis of the leaked files by the account breach notification service Have I Been Pwned showed that they contain roughly 455,000 unique email addresses, along with other types of personal information such as usernames, names, addresses, phone numbers, passport numbers, genders, and details on ethnicity, disabilities, academic enrolment, c itizenship status, and fee payments. In a statement issued on Wednesday, the University of Nottingham confirmed that hackers accessed “a significant amount of data” in its student record system. The university says the data breach impacts current students and alumni. “We are working to understand the data that has been accessed and have contacted those students and alumni affected directly. We are working closely with Action Fraud, the Information Commissioner’s Office, and other regulatory bodies,” the organization said.  Advertisement. Scroll to continue reading. Related : Canvas System Is Online After a Cyberattack Disrupted Thousands of Schools Related : 1.2 Million Affected by University of Hawaii Cancer Center Data Breach Related : 3.5 Million Affected by University of Phoenix Data Breach Related : University of Sydney Data Breach Affects 27,000 Individuals Written By Eduard Kovacs Eduard Kovacs (@EduardKovacs) is senior managing editor at SecurityWeek. He worked as a high school IT teacher before starting a career in journalism in 2011. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering. Meta Paid $78,000 Bounty for Vulnerability Exposing Customer Support Data Exploitation of ServiceNow Vulnerability Seen Days After Disclosure SonicWall Zero-Days Exploited to Deliver Custom Malware for Weeks Before Patch New Index Tracks Material Breaches — And Refuses to Add Up the Losses WP2Shell WordPress Vulnerabilities Exploited in the Wild Two Scattered Spider Hackers Sentenced to Jail in UK ‘ClickLock Stealer’ Bypasses macOS Security With Social Engineering, Process Killing China’s Top Cybersecurity Firms Hit by Mounting Military Procurement Bans Fourth SharePoint Vulnerability Exploited in Past Month’s Wave of Attacks Endpoint Security Firm Glow Launches With $180M in Funding at $1.2B Valuation Oracle Patches Over 1,400 Vulnerabilities With Quarterly Security Updates Ransomware Group Threatening to Leak Data Stolen From Coca-Cola’s Fairlife OpenAI Says Its AI Models Broke Loose and Hacked Hugging Face Trump Orders Defense Contractors to Map Software, Suppliers Across Critical Supply Chains Cisco Launches Low-Cost AI Models for Source Code Security Empirical Security Raises $25 Million in Series A Funding Join this live webinar as we explore why exploitation is outpacing remediation, where risk is growing fastest, and what security leaders can do to close the gap before attackers take advantage. For the latest discoveries in cyber research for the week of 15th June, please download our Threat Intelligence Bulletin. The University of Nottingham, a UK research university, has suffered a data breach after ShinyHunters accessed its student records system. The incident affected about 454,600 current and former students and exposed contact details, passport numbers, enrollment information, and fee payment records later appeared online. According to analysts, this breach is part of a larger wave of attacks targeting more than 100 organizations by ShinyHunters, exploiting CVE-2026-35273, a critical zero-day vulnerability in Oracle PeopleSoft that allows remote code execution. Check Point IPS provides protection against this threat (Oracle PeopleSoft Enterprise PeopleTools Server-Side Request Forgery (CVE-2026-35273)) Mackay Sugar, Australia’s second-largest sugar producer, has been hit by a cyberattack that disrupted operations and shut down its Farleigh and Racecourse mills in Queensland. The company instructed growers to stop harvesting and suspended cane haulage while temporary measures were deployed to maintain essential operations. Danish pharmaceutical giant Novo Nordisk has disclosed a breach after attackers accessed internal IT systems and copied pseudonymized clinical trial data from research systems. The exposed information included patient IDs, trial participation details, limited health data, and some healthcare professionals’ contact information. Check Point Research has demonstrated exploitable flaws in LangGraph, an open-source framework for stateful AI agents. Researchers chained SQL injection and unsafe deserialization issues to achieve remote code execution, with patches issued for SQLite, core, and Redis checkpointer components in affected deployments. Check Point IPS provides protection against this threat (LangChain LangGraph SQL Injection (CVE-2026-27022)) Researchers highlighted a China-based phishing-as-a-service network, Outsider, that allegedly used Gemini to generate fake websites and support SMS phishing campaigns. Google filed a lawsuit after linking the operation to thousands of phishing sites, more than 1.5 million URLs, and large-scale victim targeting. Researchers warned that prompt-injection attacks against Anthropic’s Claude Code GitHub Action could leak CI/CD workflow secrets. Malicious issue or pull request text can instruct the agent to read environment variables and expose API keys, enabling workflow abuse and impersonation inside software repositories. Check Point Research has identified active exploitation of CVE-2026-50751, a critical authentication bypass vulnerability affecting Check Point Remote Access VPN and Mobile Access deployments configured to use the deprecated IKEv1 key exchange protocol. Attacks began in May and increased in early June, affecting a limited number of organizations, with one case tied to Qilin ransomware activity. Check Point IPS provides protection against this threat (IKEv1 Remote Access Authentication Bypass PoC Exploit (CVE-2026-50751)) Microsoft released its largest Patch Tuesday update to date, addressing more than 200 Windows and Defender vulnerabilities amid an AI-driven surge in vulnerability discovery. The fixes include CVE-2026-45657, a critical Windows flaw with a CVSS score of 9.8 that could enable network-based propagation, CVE-2026-41091, which has been actively exploited to gain full system control, and CVE-2026-50507, a BitLocker bypass vulnerability.

Nottingham
Nissanusa logoUse of stolen credentials or exploit
Medium

Nissan Americas Employee Data Breach via Oracle PeopleSoft Zero-Day Exploitation

Nissan Americas disclosed a data breach affecting current and former employees, which occurred between May 27 and June 9, 2026. The breach was facilitated by attackers exploiting CVE-2026-35273, a critical Server-Side Request Forgery (SSRF) vulnerability in Oracle PeopleSoft PeopleTools. The ShinyHunters extortion group claimed responsibility for the broader campaign, which impacted over 100 organizations, primarily in the education sector. Sensitive employee data, including contact information, banking details, Social Security numbers, Social Insurance Numbers, National Identification Numbers, financial and tax information, and dependent/beneficiary information, was accessed.

Nissanusa
Nissan Global logoUse of stolen credentials or exploit
Medium

Nissan Employee Data Breach Linked to Oracle PeopleSoft Zero-Day

Nissan disclosed an employee data breach linked to the exploitation of the Oracle PeopleSoft CVE-2026-35273 vulnerability as a zero-day. The attacks, primarily impacting organizations in the education sector, occurred between May 27 and June 9, 2026.

Nissan Global
Nissanusa logoUse of stolen credentials or exploit
Medium

Nissan Americas Employee Data Compromised in Oracle PeopleSoft Zero-Day Attack by ShinyHunters

Nissan Americas confirmed a data breach affecting current and former employees, stemming from a targeted cyberattack exploiting a critical zero-day vulnerability (CVE-2026-35273) in Oracle PeopleSoft software. The exploitation, attributed to the ShinyHunters extortion group, began as early as May 27, 2026, and continued until June 9, 2026. Sensitive employee data, including contact information, banking details, Social Security numbers, and tax records, was accessed.

Nissanusa
Theoncologyinstitute logoRansomware
Medium

The Oncology Institute Reports Third-Party Cyber Attack Impacting Patient Information

U.S. CISA adds DD-WRT, Langflow and WordPress flaws to its Known Exploited Vulnerabilities catalog OpenAI AI models exploited zero-days to reach Hugging Face in benchmark test Public PoC triggers active exploitation of critical SharePoint RCE vulnerability CVE-2026-50522 Zimbra 10.1.20 patches multiple security issues, including a critical command injection bug Qilin Ransomware Affiliates Abuse CVE-2026-0257 to Gain Unauthorized VPN Access Dutch Intelligence Warns Russia Uses Hacked IP Cameras for Military Espionage Critical 7-Zip Flaw Allows Code Execution by Opening Crafted XZ-Compressed Files. Update it now! CVE-2026-42533: Critical NGINX Bug Could Turn HTTP Requests Into Server Takeovers AI Agents Turned Into Attackers: Hugging Face Reveals Autonomous Intrusion Campaign Volexity Uncovers Zero-Day Campaign Targeting SonicWall VPN Appliances Attackers Can Take Over WordPress Sites Using Newly Released wp2shell Exploits OpenSSL Fixes HollowByte Memory Exhaustion Bug Daxin: 13-Year-Old China-Linked Malware Found Still Active on Manufacturer's Network U.S. CISA adds Fortinet FortiSandbox and Microsoft SharePoint flaws to its Known Exploited Vulnerabilities catalog Ernst & Young (EY) Investigates Data Breach Involving Third-Party Support Tickets A cyberattack hit Nichirei, one of Japan's largest food companies New Russian Campaign Uses Fake Webex and Zoom Installers to Deploy Starland RAT U.S. CISA adds KNX Association KNX Protocol Connection Authorization Option 1 and Oracle flaws to its Known Exploited Vulnerabilities catalog A deeper insight into the CloudWizard APT’s activity revealed a long-running activity Experts warn of a threat actor, tracked as CloudWizard APT, that is targeting organizations involved in the region of the Russo-Ukrainian conflict. On March 2023, researchers from Kaspersky spotted a previously unknown APT group, tracked as Bad Magic (aka Red Stinger), that targeted organizations in the region of the Russo-Ukrainian conflict. The attackers were observed using PowerMagic and CommonMagic implants. Looking for other implants with similarities with PowerMagic and CommonMagic, the researchers identified a different cluster of even more sophisticated malicious activities associated with the same threat actor. The victims of this cluster were located not only in the Donetsk, Lugansk and Crimea regions, but also in central and western Ukraine. The APT group targeted individuals, as well as diplomatic and research organizations in the area of the conflict. In the latest campaign uncovered by Kaspersky, the APT group, used a modular framework dubbed CloudWizard that supports spyware capabilities, including taking screenshots, microphone recording, harvesting Gmail inboxes, and keylogging. The Oncology Institute reports patient data potentially exposed in third-party vendor breach The Oncology Institute has confirmed that patient information was impacted in a cybersecurity incident involving a third-party software provider. The healthcare network first disclosed the security breach in November 2025, while the vendor’s investigation was still ongoing, as reported by Security Affairs. The Oncology Institute disclosed on May 20, 2026, that Kroll, a third-party administrator for an unnamed vendor, detected unauthorized access to systems that may have affected patient data. This incident follows a larger breach at Cognizant-owned TriZetto Provider Solutions in March 2026, which exposed sensitive information for over 3.4 million patients. The TriZetto breach, which began in November 2024, involved unauthorized access to records for insurance eligibility verification transactions, potentially exposing names, addresses, Social Security numbers, and insurance details. While no ransomware group has claimed responsibility for either incident, the potential exposure of patient data highlights significant risks within the healthcare supply chain. The Oncology Institute stated that the vendor has established a patient portal to provide information and address inquiries related to the breach.

Theoncologyinstitute
Fluke logoRansomware
Medium

Fluke Corporation Discloses Data Breach Affecting 18,000 Individuals; Clop Ransomware Claims Responsibility

Fluke Corporation notified over 18,000 individuals of a data breach that originally occurred in August 2025. The breach, which reportedly lasted two months, compromised highly sensitive personal information including Social Security Numbers (SSNs), birth dates, and self-identified disability status. The incident was attributed to an exploited vulnerability in a third-party application used by the company. The Clop ransomware group claimed responsibility for the breach, listing Fluke Corporation on its dark web leak site.

Fluke
Westpharma logoRansomware
High

West Pharmaceutical Services Discloses Material Cyberattack and Data Exfiltration

For the latest discoveries in cyber research for the week of 18th May, please download our Threat Intelligence Bulletin. Vodafone, a major international telecom, has sustained a source code leak claimed by the Lapsus$ extortion group. The company confirmed limited access to GitHub files through compromised third-party development software, while stating that customer data and core network infrastructure were not affected by the incident. Cryptocurrency platform THORChain, based in Switzerland, has encountered a security breach that led to the theft of about $10.7M. Trading was halted after one of six vaults was compromised, and the company said losses were limited to protocol-owned assets across several blockchains. West Pharmaceutical Services, a global manufacturer of drug delivery components, has experienced a ransomware attack that disrupted shipping, manufacturing, and shared service functions. The company disclosed that some systems were encrypted and data was stolen, but no ransomware group has publicly claimed responsibility. Foxconn, a global electronics manufacturer, has confirmed it was hit by a cyberattack on its North American operations after the Nitrogen ransomware group claimed to have stolen 8TB of data. The company confirmed disruption at some factories and said affected facilities were resuming normal production. Researchers unveiled ‘Claw Chain’, four vulnerabilities in OpenClaw, an autonomous AI agent platform, that allow attackers to bypass sandbox controls, expose restricted files, leak secrets, and gain owner-level access. The flaws include the critical CVE-2026-44112, rated CVSS 9.6. Researchers developed an AI-assisted macOS kernel exploit that bypasses Apple’s Memory Integrity Enforcement on M5 chips and grants full system control on macOS 26.4.1. Anthropic’s Mythos Preview reportedly accelerated bug discovery, and the findings were privately reported to Apple before public disclosure. Researchers detailed how threat actors abuse Vercel’s AI website generator, v0.dev, to mass-produce realistic phishing pages mimicking brands such as Microsoft and Spotify. The campaigns utilize Telegram bots to capture credentials and payment details in real time. Researchers found a popular Hugging Face repository hiding Windows-targeting malware after it amassed over 200,000 downloads. The package posed as OpenAI’s privacy filter and installed an infostealer that harvested browser passwords, cookies, SSH keys, VPN configurations, and cryptocurrency wallets before exfiltrating the data. Two Windows zero-day vulnerabilities, YellowKey and GreenPlasma, affect Windows 11 and recent Windows Server versions. YellowKey allows BitLocker bypass through Windows Recovery Environment with physical access, while GreenPlasma abuses the CTFMON framework to escalate privileges to SYSTEM. Proof-of-concept code is public, and the vulnerabilities are still unpatched. F5 has fixed CVE-2026-42945, a critical memory flaw in the NGINX rewrite module affecting versions 0.6.27 through 1.30.0. The 18-year-old bug enables denial of service and, under specific configurations, possible remote code execution. Public exploit code requires memory protections to be disabled. Check Point IPS provides protection against this threat (Nginx Heap Overflow (CVE-2026-42945)) Cisco has addressed CVE-2026-20182, a critical authentication bypass in Catalyst SD-WAN controllers that is being actively exploited. The flaw allows remote, unauthenticated attackers to gain full administrative control of affected systems. CISA ordered federal agencies to patch vulnerable devices following Cisco’s fixes. Apple has released security updates for CVE-2026-28819, an out-of-bounds write flaw in the Wi-Fi component affecting iOS, iPadOS, and macOS. Successful exploitation could allow an app to execute code with kernel privileges. The issue was addressed with improved bounds checking. Check Point Research has analyzed an internal leak from The Gentlemen ransomware operation, exposing chats, infrastructure details, affiliate roles, and ransom negotiations. The report links the zeta88 account to the administrator, maps 8 affiliate TOX IDs, and details the use of Fortinet and Cisco vulnerabilities as well as NTLM relay and OWA/M365 for initial access in attacks. Check Point Threat Emulation and Harmony Endpoint provide protection against this threat Check Point Research has summarized Q1 2026 ransomware trends, recording 2,122 leak-site victims, which is the second-highest Q1 on record, and renewed consolidation. The top 10 groups were responsible for 71% of victims. Qilin led with 338 victims, The Gentlemen rose to third, and LockBit 5.0 returned with 163 victims. Check Point Research have quantified a World Cup 2026-driven surge in cyber activity, with weekly attacks per organization rising in Mexico, Canada, and the United States in April, across the media, hospitality, transportation and travel sectors. FIFA-themed domains reached 9,741 in April, and by early May, one in 41 were malicious. Researchers attributed a months-long intrusion against an Azerbaijani oil and gas company to the Chinese-linked FamousSparrow group. Attackers exploited an unpatched Microsoft Exchange server to deploy web shells, then alternated between Deed RAT and TernDoor across three waves of persistent activity. “The Turkish Rat” Evolved Adwind in a Massive Ongoing Phishing Campaign StealthLoader Malware Leveraging Log4Shell BFSI uses cookies on this site. We use cookies to enable faster and easier experience for you. By continuing to visit this website you agree to our use of cookies. May 2026 saw an evolution of the cyber incidents highlighted in SWK’s previous Cybersecurity News Recaps , including more suspected hacking by Iran-backed actors and an apparent major resurgence of the notorious ShinyHunters gang over the past few months. This month also saw several other significant cyber incidents within the manufacturing industry, as well as multiple upcoming compliance deadlines, though one of the latter has been disrupted due to federal funding issues and pushback from affected parties. Continue reading below to learn more about some of the top cybersecurity news stories from May 2026 in this recap by SWK Technologies: Lawsuit Filed Against OpenAI for Sharing Data A class action complaint filed in California federal court accuses OpenAI of embedding Meta’s Facebook Pixel and Google Analytics in the ChatGPT web interface, transmitting query topics, user identifiers and email addresses to those platforms without user consent. The suit argues that conversations users assumed were private — including questions about finances, health and legal matters — have been treated as marketing telemetry, in violation of the Electronic Communications Privacy Act, the California Invasion of Privacy Act and the California Constitution. SEC Regulation S-P June 3 Compliance Deadline Approaching ShinyHunters Hit Canvas, 7-Eleven and More Throughout 2026

Westpharma
Adt logoRansomware
Medium

ADT Data Breach Exposes 5.5 Million Records by ShinyHunters

New Interpol report shows cybercrime surging across Africa Critical Linux zero-day Copy Fail enables root access EU regulator warns on AI-driven cyber risks Social media scams drive $2.1bn in losses in the USA US based home security giant ADT is facing renewed scrutiny after reports that the ShinyHunters extortion group stole the personal information of 5.5 million individuals. The figure was highlighted by data breach notification service Have I Been Pwned following analysis of the stolen dataset. ADT said it detected suspicious activity on 20 April and launched an investigation. According to the company, exposed data included names, phone numbers and addresses, with a smaller number of records also containing dates of birth and the last four digits of Social Security numbers or Tax IDs. ADT stressed that no payment data was accessed and customer security systems were not impacted. The attackers reportedly gained entry through a voice phishing campaign that compromised an employee Okta single sign-on account before moving into connected systems. The incident highlights the growing risk posed by identity-focused attacks targeting SaaS environments. Stronger authentication controls, staff awareness training and continuous monitoring remain critical to defending against modern extortion groups. Cybercrime now represents a growing share of overall crime across Africa, according to INTERPOL’s latest Africa Cyberthreat Assessment Report. Two-thirds of surveyed member countries said cyber-related offences make up a medium-to-high proportion of all crime, rising to more than 30% in Western and Eastern Africa. Online scams remain the most common threat, with phishing attacks widespread across the continent. Ransomware, business email compromise and digital sextortion were also heavily reported, highlighting how financially motivated crime continues to evolve. The report found major capability gaps remain. Ninety percent of countries said law enforcement or prosecution capacity requires significant improvement, while many also cited shortages in training, specialist tools and cyber investigation infrastructure. Despite these challenges, progress is being made. Several nations have strengthened legal frameworks, expanded digital forensics capabilities and invested in dedicated cybercrime units. INTERPOL-led operations have also resulted in more than 1,000 arrests and the disruption of large-scale criminal networks. The findings underline that cybersecurity resilience depends not only on technology, but also on skills, legislation, international cooperation and public-private collaboration. A newly disclosed Linux kernel zero-day vulnerability, tracked as CVE-2026-31431 and nicknamed “Copy Fail”, has raised urgent concerns across the cybersecurity community. The flaw affects Linux distributions using kernel versions released since 2017 and could allow an unprivileged local user to gain full root access. Researchers said the vulnerability can be exploited using a lightweight Python script with no need for race conditions, custom payloads or complex kernel offsets, making exploitation significantly easier than many past privilege escalation flaws. The issue reportedly impacts several major enterprise and cloud platforms, including Ubuntu, Amazon Linux, RHEL and SUSE. Security researchers also warned that the flaw could be used as a container escape technique in Kubernetes environments, potentially allowing compromise of shared host systems. An official patch has now been released, with administrators urged to prioritise updates through their normal distribution channels. Temporary mitigations, including disabling the affected kernel module, have also been recommended. The incident is a reminder that foundational infrastructure remains a prime target, and rapid patch management is essential to reduce exposure when critical vulnerabilities emerge. Europe’s top securities regulator has warned that cyberattacks are becoming faster and more dangerous as artificial intelligence accelerates the threat landscape. Verena Ross, chair of the European Securities and Markets Authority (ESMA), said regulators are closely assessing how advanced AI models could increase the speed and scale of attacks against financial institutions. The warning follows growing industry concern over new AI systems reportedly capable of identifying and exploiting previously unknown vulnerabilities. Financial supervisors across Europe are now reviewing whether firms have the resilience, controls and oversight needed to manage these evolving risks. Ross also stressed that regulators must strengthen their own expertise to effectively supervise both financial entities and the critical third-party technology providers they rely on. Operational resilience and supply chain risk remain key priorities as the sector becomes more dependent on external digital services.

Adt
Lacityattorney logoRansomware
Medium

Los Angeles City Attorney's Office Data Breach Reported by LAPD

For the latest discoveries in cyber research for the week of 13th April, please download our Threat Intelligence Bulletin. The Los Angeles Police Department has reported a data breach involving a digital storage system used by the L.A. City Attorney’s Office. The exposure included 7.7 terabytes and more than 337,000 files, including personnel records, internal affairs material, and unredacted personal information. ChipSoft, a Dutch healthcare software vendor whose HiX platform is used by hospitals across the Netherlands, has suffered a ransomware attack that forced it to disable patient and provider services. Multiple hospitals disconnected from its systems, disrupting operations, and the company warned that the threat actor may have gained unauthorized access to patient data. Ransomware group Qilin has taken responsibility for a cyber-attack targeting German political party Die Linke, which forced the party to shut down its IT infrastructure in late March. The party said membership databases were unaffected, while Qilin threatens to leak stolen sensitive employee and party information. Check Point Endpoint and Threat Emulation provide protection against these threats ( Ransomware.Wins.Qilin*) Bitcoin Depot, a US cryptocurrency ATM operator with more than 25,000 kiosks and checkout locations, has disclosed a cyberattack that allowed attackers to steal credentials tied to digital asset settlement accounts. The attackers transferred more than 50 BTC worth more than $3.6M from company-controlled wallets before access was blocked. Researchers identified GrafanaGhost, an attack against Grafana’s AI components that can silently exfiltrate enterprise data by chaining indirect prompt injection with image URL validation bypass. The technique can expose financial, infrastructure, and customer information in the background, and Grafana has already addressed the weakness. Researchers outlined AI Agent Traps, a framework describing six web-based attack classes that can manipulate autonomous AI agents through malicious content. The methods can inject hidden instructions, poison reasoning, corrupt memory, and steer tool use, showing how web pages can turn agent workflows into attack surfaces. Researchers measured a growing AI supply chain risk, finding that third-party API routers for AI models can hijack agent tool calls to alter commands and steal credentials. In testing, several routers injected malicious code, abused intercepted cloud keys, and even triggered wallet theft from a researcher environment. CISA warns of active exploitation of Ivanti CVE-2026-1340, a critical code injection flaw in Endpoint Manager Mobile that allows unauthenticated remote code execution and full compromise of affected servers. The vulnerability carries a CVSS score of 9.8, affects multiple 12.5 through 12.7 releases, and has been exploited in the wild. Check Point IPS provides protection against this threat (Ivanti Endpoint Manager Mobile Code Injection (CVE-2026-1340)) Adobe Reader is affected by an actively exploited zero-day that uses malicious PDF files to invoke privileged features on fully updated systems, enabling local data theft. Researchers said the activity has run since at least December 2025, uses Russian-language oil and gas lures, and may also enable further compromise. Marimo maintainers released a fix for CVE-2026-39987, a critical remote code execution flaw in the Marimo Python notebook that allowed attackers to open a terminal without authentication and run commands. Exploitation was observed within hours of disclosure against internet-exposed instances, and fixes are available in version 0.23.0. Fortinet has fixed CVE-2026-35616, a critical improper access control flaw in FortiClient EMS that enables unauthenticated code or command execution through crafted requests. The issue been actively exploited in the wild, prompting Fortinet to release an emergency hotfix. Check Point Research have analyzed March 2026’s threat landscape, with organizations averaging 1,995 weekly attacks. Education remained the most targeted sector, ransomware rose to 672 incidents led by Qilin, Akira, and DragonForce, and GenAI exposure remained high across enterprise environments. Researchers discovered a coordinated software supply chain campaign that planted 36 malicious npm packages impersonating Strapi plugins. The packages executed on installation to search for secrets, maintain command and control, and in some cases enable Redis remote code execution, credential harvesting, and direct PostgreSQL exploitation. Researchers linked Storm-1175, a financially motivated group associated with Medusa ransomware, to high-velocity exploitation of n-day and zero-day flaws. Microsoft said the actor moves quickly from initial access to data theft and ransomware deployment, sometimes weaponizing vulnerabilities within a day and heavily impacting healthcare, education, finance, and services. Researchers identified a hack-for-hire campaign linked to BITTER APT that targeted journalists, activists, and government figures across the Middle East and North Africa. The operators used phishing to access iCloud backups and Signal accounts, and deployed Android spyware disguised as messaging applications to take over victim devices. “The Turkish Rat” Evolved Adwind in a Massive Ongoing Phishing Campaign StealthLoader Malware Leveraging Log4Shell BFSI uses cookies on this site. We use cookies to enable faster and easier experience for you. By continuing to visit this website you agree to our use of cookies.

Lacityattorney
Booking logoUse of stolen credentials or exploit
High

Booking.com Confirms Data Leak Exposing Customer Booking Information

New Booking.com data breach forces reservation PIN resets Booking.com is - as the name suggests - a website that allows users to book travel including flights, car rentals, hotels, and more. They are one of the largest such sites. Users have reported getting emails from noreply@booking.com informing them of a "cybersecurity incident" that may have exposed full names, email addresses, postal addresses, phone numbers, and communication with property providers. Booking.com is not being transparent about the number of users impacted, but said all users will be individually notified. They are also resetting user reservation PINs out of caution. European Gym giant Basic-Fit data breach affects 1 million members Basic-Fit is one of the largest gym chains in Europe with over 1700 clubs and 430 franchises in 12 countries. In a disclosure published on their website, they have announced a cyberattack that impacted full name, physical address, email address, phone number, date of birth, bank account details, and "other membership information." It appears to have impacted about 1 million members. McGraw-Hill confirms data breach following extortion threat McGraw-Hill is an education company that offers textbooks, online portals, and systems for K-12 schools and universities. This attack appears to have come from a misconfigured Salesforce page. McGraw-Hill says the data exposed was "limited and non-sensitive," but the attacker claims to have 45 million records containing personally identifiable information. Crypto-exchange Kraken extorted by hackers after insider breach Kraken says that attackers are threatening to release a video that shows internal systems that host client data. The article is a bit unclear but it does seem that the attackers were showing that they had actual access to the data, though it seems it was through inside employees and not via a technical hack (such as a vulnerability). Kraken said that funds are safe and employees have been terminated. They say the breach was limited to about 2,000 customers but have not shared what information was impacted. Fashion retailer Express left customers’ personal data and order details exposed to the internet This was a flaw appears to have been an "insecure direct object reference" vulnerability - where simply tweaking the web address is enough to pull up other pages you may not necessarily have been meant to see. In this case a researcher was able to access other users' order confirmation pages, which included names, phone numbers, email addresses; postal, billing, and delivery addresses; order details including the items that a customer purchased, and partial payment card information including the card type and the last four-digits. Fiverr Exposes Private Information of its Users Publicly on Google Search Results From our own staff writer Fria, a researcher on Hacker News claimed that Fiverr - a freelancer job board - was exposing sensitive personal documents such as tax forms containing Social Security Numbers. The data could easily be found by searching site:fiverr-res.cloudinary.com [keywords of choice, such as "form 1040" or a name] on most search engines including Google and even DuckDuckGo. According to our internal news chat, the data itself does appear to have been secured. Privacy Guides Executive Director Jonah Aragon was unable to reproduce the results on Google, but both Jonah and Fria were able to find the results on DuckDuckGo, though they no longer linked to a valid address. Russian-linked hackers escalate attacks on European energy infrastructure Microsoft Patch Tuesday fixes 167 flaws, including two zero-days Rockstar Games data breach linked to third-party SaaS compromise Basic-Fit breach exposes data of one million members Booking.com breach exposes customer booking data Sweden has revealed that Russian state-linked hackers attempted to disrupt operations at a thermal power plant in early 2025, marking another escalation in attacks against European critical infrastructure. While the intrusion was ultimately unsuccessful due to built-in protections, officials have warned that the nature of these threats is shifting. According to Civil Defence Minister Carl-Oskar Bohlin, groups previously associated with low-level disruption are now attempting far more destructive cyberattacks. This incident reflects a broader pattern of increasingly aggressive activity targeting energy and utility systems. Similar operations have been reported across Europe, including attempts to interfere with Poland’s power grid and a breach of a Norwegian dam, where floodgates were briefly opened. Ukraine has also faced repeated attacks on its energy infrastructure in recent years. The trend highlights a growing convergence between cyber operations and real-world disruption, reinforcing the need for stronger resilience across critical national infrastructure. Microsoft’s April 2026 Patch Tuesday delivered security updates for 167 vulnerabilities, including two zero-day flaws and eight rated Critical. The majority of issues centre on elevation of privilege vulnerabilities, alongside 20 remote code execution bugs that could enable attackers to take control of affected systems. Of particular concern is an actively exploited zero-day, CVE-2026-32201, impacting SharePoint Server and allowing spoofing attacks that could expose or manipulate sensitive data. A second zero-day, CVE-2026-33825, affects Microsoft Defender and enables privilege escalation to SYSTEM level, significantly increasing the risk of full system compromise. Multiple critical vulnerabilities were also identified across Microsoft Office, including Word and Excel, where malicious documents or even preview pane interactions could trigger exploitation. This makes email-based attack vectors especially dangerous. The update highlights the continued scale and complexity of patch management, with organisations urged to prioritise updates across SharePoint, Defender, and Office to reduce exposure to active threats. Rockstar Games has confirmed a data breach following a wider security incident involving Anodot, with the ShinyHunters gang now leaking what it claims are 78.6 million records. The attackers allege the data was accessed via compromised authentication tokens tied to Snowflake environments, highlighting the growing risk posed by third-party SaaS integrations. According to Rockstar, the breach involved a limited amount of non-material company information and has not impacted operations or players. However, the leaked datasets reportedly include internal analytics tied to Grand Theft Auto Online and Red Dead Online, such as revenue metrics, player behaviour tracking, and support system data.

Booking

Explore related intelligence

Explore this reporting from another angle

Based on all published signals currently classified as vulnerability exploitation. Counts describe this reporting set, not overall incident prevalence.

Which Shadow Tier articles add context?

Questions answered

Questions about vulnerability exploitation

What is vulnerability exploitation?

Vulnerability exploitation is the deliberate use of a software or hardware flaw to bypass security, execute actions or gain unauthorized access.

A vulnerability describes a weakness; exploitation describes an attacker successfully using or attempting to use it. Risk depends on reachability, prerequisites, available exploit activity, the affected asset and what control or data the flaw exposes.

What makes a zero-day vulnerability different?

A zero-day is exploited before defenders have a broadly available fix or sufficient time and knowledge to apply effective protection.

The term is often used loosely in reporting. Security teams should distinguish confirmed in-the-wild exploitation from research demonstrations and should follow authoritative vendor or coordination guidance for the exact affected versions and mitigations.

How do attackers find vulnerable internet-facing systems?

Attackers scan public services, reuse product fingerprints and exploit lists, and target known technologies exposed through gateways, applications or appliances.

Internet-scale discovery can make exploitation begin soon after details are published. Organizations need an accurate external asset view connected to ownership and version information so they can identify relevant exposure faster than a periodic inventory cycle allows.

How should teams prioritize an actively exploited CVE?

Prioritize confirmed affected and reachable assets, then consider exploitation evidence, privileges gained, business criticality and compensating controls.

A severity score alone cannot show whether the vulnerable component exists or can be reached in a specific environment. Good triage connects authoritative technical guidance to asset evidence, service impact and a named remediation owner.

Does installing a patch remove an existing intrusion?

No. A patch can close the vulnerability but may not remove persistence, stolen credentials or other changes made before remediation.

When an asset was exposed during a known exploitation window, teams should pair remediation with product-specific threat hunting and review connected identities and systems. The investigation should determine whether exploitation occurred, not merely whether the version is now current.

Which evidence shows that a vulnerability was actually exploited?

Reliable evidence may include vendor-defined indicators, exploit requests, spawned processes, created accounts, web shells or follow-on attacker activity.

Evidence quality varies by product and logging coverage. Scanner hits or a vulnerable version establish exposure, while compromise assessment needs telemetry that connects the exploit path to an action on the affected system or a documented absence of relevant evidence.

How can organizations learn from current exploitation news?

Map each confirmed case to your technology inventory, exposed services and suppliers, then trigger focused remediation and compromise assessment where overlap exists.

Incident news becomes useful when it changes a decision. Teams should record whether the affected product is present, who owns it, whether it was reachable during the exposure window and which evidence supports the final risk conclusion.