215
Reports in 90 days
in the current rolling intelligence window
Current cyber intelligence
Shadow Tier brings verified public reporting into one current view. Start with the latest incidents below, or compare the companies, sectors, attack patterns, impacts and countries connected to them.
215
in the current rolling intelligence window
10
represented in the same 90-day window
65
high or critical reports in 90 days
Latest reporting
Showing 199–215 of 215 reports published in the last 90 days.
For the latest discoveries in cyber research for the week of 18th May, please download our Threat Intelligence Bulletin. Vodafone, a major international telecom, has sustained a source code leak claimed by the Lapsus$ extortion group. The company confirmed limited access to GitHub files through compromised third-party development software, while stating that customer data and core network infrastructure were not affected by the incident. Cryptocurrency platform THORChain, based in Switzerland, has encountered a security breach that led to the theft of about $10.7M. Trading was halted after one of six vaults was compromised, and the company said losses were limited to protocol-owned assets across several blockchains. West Pharmaceutical Services, a global manufacturer of drug delivery components, has experienced a ransomware attack that disrupted shipping, manufacturing, and shared service functions. The company disclosed that some systems were encrypted and data was stolen, but no ransomware group has publicly claimed responsibility. Foxconn, a global electronics manufacturer, has confirmed it was hit by a cyberattack on its North American operations after the Nitrogen ransomware group claimed to have stolen 8TB of data. The company confirmed disruption at some factories and said affected facilities were resuming normal production. Researchers unveiled ‘Claw Chain’, four vulnerabilities in OpenClaw, an autonomous AI agent platform, that allow attackers to bypass sandbox controls, expose restricted files, leak secrets, and gain owner-level access. The flaws include the critical CVE-2026-44112, rated CVSS 9.6. Researchers developed an AI-assisted macOS kernel exploit that bypasses Apple’s Memory Integrity Enforcement on M5 chips and grants full system control on macOS 26.4.1. Anthropic’s Mythos Preview reportedly accelerated bug discovery, and the findings were privately reported to Apple before public disclosure. Researchers detailed how threat actors abuse Vercel’s AI website generator, v0.dev, to mass-produce realistic phishing pages mimicking brands such as Microsoft and Spotify. The campaigns utilize Telegram bots to capture credentials and payment details in real time. Researchers found a popular Hugging Face repository hiding Windows-targeting malware after it amassed over 200,000 downloads. The package posed as OpenAI’s privacy filter and installed an infostealer that harvested browser passwords, cookies, SSH keys, VPN configurations, and cryptocurrency wallets before exfiltrating the data. Two Windows zero-day vulnerabilities, YellowKey and GreenPlasma, affect Windows 11 and recent Windows Server versions. YellowKey allows BitLocker bypass through Windows Recovery Environment with physical access, while GreenPlasma abuses the CTFMON framework to escalate privileges to SYSTEM. Proof-of-concept code is public, and the vulnerabilities are still unpatched. F5 has fixed CVE-2026-42945, a critical memory flaw in the NGINX rewrite module affecting versions 0.6.27 through 1.30.0. The 18-year-old bug enables denial of service and, under specific configurations, possible remote code execution. Public exploit code requires memory protections to be disabled. Check Point IPS provides protection against this threat (Nginx Heap Overflow (CVE-2026-42945)) Cisco has addressed CVE-2026-20182, a critical authentication bypass in Catalyst SD-WAN controllers that is being actively exploited. The flaw allows remote, unauthenticated attackers to gain full administrative control of affected systems. CISA ordered federal agencies to patch vulnerable devices following Cisco’s fixes. Apple has released security updates for CVE-2026-28819, an out-of-bounds write flaw in the Wi-Fi component affecting iOS, iPadOS, and macOS. Successful exploitation could allow an app to execute code with kernel privileges. The issue was addressed with improved bounds checking. Check Point Research has analyzed an internal leak from The Gentlemen ransomware operation, exposing chats, infrastructure details, affiliate roles, and ransom negotiations. The report links the zeta88 account to the administrator, maps 8 affiliate TOX IDs, and details the use of Fortinet and Cisco vulnerabilities as well as NTLM relay and OWA/M365 for initial access in attacks. Check Point Threat Emulation and Harmony Endpoint provide protection against this threat Check Point Research has summarized Q1 2026 ransomware trends, recording 2,122 leak-site victims, which is the second-highest Q1 on record, and renewed consolidation. The top 10 groups were responsible for 71% of victims. Qilin led with 338 victims, The Gentlemen rose to third, and LockBit 5.0 returned with 163 victims. Check Point Research have quantified a World Cup 2026-driven surge in cyber activity, with weekly attacks per organization rising in Mexico, Canada, and the United States in April, across the media, hospitality, transportation and travel sectors. FIFA-themed domains reached 9,741 in April, and by early May, one in 41 were malicious. Researchers attributed a months-long intrusion against an Azerbaijani oil and gas company to the Chinese-linked FamousSparrow group. Attackers exploited an unpatched Microsoft Exchange server to deploy web shells, then alternated between Deed RAT and TernDoor across three waves of persistent activity. “The Turkish Rat” Evolved Adwind in a Massive Ongoing Phishing Campaign StealthLoader Malware Leveraging Log4Shell BFSI uses cookies on this site. We use cookies to enable faster and easier experience for you. By continuing to visit this website you agree to our use of cookies. May 2026 saw an evolution of the cyber incidents highlighted in SWK’s previous Cybersecurity News Recaps , including more suspected hacking by Iran-backed actors and an apparent major resurgence of the notorious ShinyHunters gang over the past few months. This month also saw several other significant cyber incidents within the manufacturing industry, as well as multiple upcoming compliance deadlines, though one of the latter has been disrupted due to federal funding issues and pushback from affected parties. Continue reading below to learn more about some of the top cybersecurity news stories from May 2026 in this recap by SWK Technologies: Lawsuit Filed Against OpenAI for Sharing Data A class action complaint filed in California federal court accuses OpenAI of embedding Meta’s Facebook Pixel and Google Analytics in the ChatGPT web interface, transmitting query topics, user identifiers and email addresses to those platforms without user consent. The suit argues that conversations users assumed were private — including questions about finances, health and legal matters — have been treated as marketing telemetry, in violation of the Electronic Communications Privacy Act, the California Invasion of Privacy Act and the California Constitution. SEC Regulation S-P June 3 Compliance Deadline Approaching ShinyHunters Hit Canvas, 7-Eleven and More Throughout 2026
Dutch universities disconnect Canvas after hackers claim continued access All seven Dutch universities using the Canvas education platform disconnected the system after the hacker group ShinyHunters claimed it still had access to systems operated by Canvas supplier Instructure. Universities of the Netherlands said the decision followed the appearance of a ShinyHunters message inside Canvas environments at multiple universities on the evening of May 7. In the message, the group said it still had access to Instructure’s systems. The precautionary measure was taken in close coordination with SURF, the Dutch education and research IT cooperative. As a result, students and staff cannot currently access Canvas. Universities warned that users with active sessions may still be logged in and requested that all users close Canvas and avoid using the platform until further notice. Universities in the Netherlands said Canvas will not return to regular operations until they receive “additional insights and more clarity” from Instructure on security and the measures already taken. Teaching is continuing “as much as possible,” although disruptions are expected and vary by university and degree program, the organization said. Universities are informing their own students and employees about the specific issues and available solutions. The affected institutions are Universiteit van Amsterdam, Vrije Universiteit Amsterdam, Erasmus Universiteit Rotterdam, Tilburg University, Technische Universiteit Eindhoven, Universiteit Maastricht, and Universiteit Twente. Dutch broadcaster NOS reported that several other educational institutions also blocked access to Canvas after the renewed breach, including Fontys Hogeschool. Deltion restored access at 9 a.m. Friday, after determining the system was safe to use again. ShinyHunters said earlier this week it had obtained data belonging to millions of students, teachers, and education employees through Canvas. Students use the platform to submit assignments, access teaching materials, and view grades. According to NOS, the hackers breached the system again despite additional security measures introduced after the initial attack. The group posted a new message inside Canvas demanding contact and negotiations by May 12 and threatening to publish stolen data if no agreement is reached.
The Eindhoven University of Technology (TU/e) was identified as one of the Dutch educational institutions impacted by the data breach at Canvas. Student and staff data, including names, email addresses, and student numbers, were compromised by the ShinyHunters hacking group. The university made a preliminary notification to the Dutch Data Protection Authority.
The University of Twente was among the Dutch educational institutions impacted by the data breach at Canvas. Student and staff data, including names, email addresses, and student numbers, were compromised by the ShinyHunters hacking group. The university made a preliminary notification to the Dutch Data Protection Authority.
Hackers stelen gegevens miljoenen studenten via Canvas, nog onduidelijk of EUR is getroffen Bij een cyberaanval op onderwijsplatform Canvas zouden hackers de gegevens van 275 miljoen gebruikers hebben buitgemaakt. Ook de Erasmus Universiteit gebruikt het platform, maar het is nog niet bekend of de gegevens van EUR-studenten en -medewerkers zijn gestolen. Bij de aanval zijn wereldwijd gegevens van studenten, docenten en onderwijsmedewerkers buitgemaakt, zoals namen, e-mailadressen, studentnummers en mogelijk privéberichten. Volgens Instructure, het moederbedrijf van Canvas, zijn er geen wachtwoorden, geboortedata, identiteitsbewijzen of bankgegevens gestolen. De universiteit onderzoekt nog of haar systemen zijn getroffen. Instructure heeft inmiddels extra beveiligingsmaatregelen genomen om verdere risico’s te beperken. Hierdoor kunnen tijdelijk kleine verstoringen optreden in Canvas. Studenten hoeven zelf geen actie te ondernemen. Volgens een woordvoerder heeft de EUR geen direct contact met de hackers. Gebruikers zijn maandag per e-mail geïnformeerd over de hack. Zodra er meer duidelijkheid is, worden studenten en medewerkers opnieuw geïnformeerd via MyEUR. Instructure moet uiterlijk woensdag losgeld betalen, anders dreigen de hackers de studentgegevens openbaar te maken. Wereldwijd zouden gegevens van circa 275 miljoen Canvasgebruikers zijn gestolen en zo’n 9000 onderwijsinstellingen zijn mogelijk getroffen. In Nederland maken, naast de Erasmus Universiteit, Fontys Hogescholen, Universiteit Maastricht, Hogeschool Utrecht, Universiteit van Amsterdam, Vrije Universiteit Amsterdam en Universiteit Tilburg gebruik van Canvas. De hackersgroep ShinyHunters heeft de aanval gedaan. De groep was eerder dit jaar ook verantwoordelijk voor een datalek bij Odido, waarbij gegevens van miljoenen Nederlandse klanten werden buitgemaakt. TU Delft gaat geen namen van activisten meer doorspelen aan politie Gegevens van EUR-studenten en -medewerkers gestolen na cyberaanval op Canvas
Datalek bij ontwikkelaar Canvas treft ook Tilburg University Op 4 mei is een beveiligingsincident gemeld bij de ontwikkelaar van Canvas, Instructure. Instructure heeft bevestigd dat ook gegevens van studenten en medewerkers van Tilburg University zijn getroffen. In dit bericht lees je wat dit voor jou betekent. Update: Lees meer op de website van de Universiteiten van Nederland: Stand van zaken datalek leverancier onderwijssoftware Canvas Instructure heeft gemeld dat er sprake is geweest van ongeautoriseerde toegang tot een deel van hun systemen. De volgende gegevens zijn volgens hen buitgemaakt: Er zijn geen signalen dat overige persoonlijke of financiële informatie is gestolen. De genoemde gegevens kunnen worden gebruikt voor phishing mails. We vragen daarom om extra alert te zijn op verdachte berichten, bijvoorbeeld e-mails die onverwacht binnenkomen of vragen om persoonlijke gegevens. Wees altijd oplettend wanneer je e-mails ontvangt. Kijk eerst naar de afzender voordat je een e-mail beantwoordt of bijlage opent. Outlook geeft een melding als een e-mail afkomstig is van buiten onze organisatie. Het is goed om te weten dat inloggen en het gebruik van Canvas veilig blijft. Wachtwoorden zijn geen onderdeel van het datalek. Daarnaast gebruikt Tilburg University extra beveiliging via multi-factor authentication (MFA). Alle studenten en medewerkers zijn inmiddels op de hoogte gesteld. We houden de situatie nauwlettend in de gaten en werken samen met SURFcert en Universiteiten van Nederland voor het monitoren van het incident. We blijven updates geven zodra er meer informatie beschikbaar is. Ontvang je een verdacht of onverwacht bericht? Of twijfel je over een e-mail? Neem dan contact op met IT Support via [email protected] . Heb je zorgen of behoefte om hierover in gesprek te gaan? Stuur dan een mail naar [email protected] voor ondersteuning en advies.
Restaurant Management Company of Wichita, Inc. (RMC), a major Pizza Hut franchisee, suffered a cyberattack between October 4, 2025, and October 13, 2025. The incident compromised the sensitive personal information of over 120,000 individuals, which may have included full name, Social Security number, home address, driver's license number, financial account information, medical information, and health insurance information. Law firms are investigating potential class action lawsuits.
TransGlobal Insurance Agency, Inc. discovered suspicious activity on its computer network on February 24, 2026, indicating a data breach. A forensic investigation determined that cybercriminals accessed files around February 18, 2026, potentially acquiring sensitive personal information of thousands of individuals, including names, Social Security numbers, driver's license numbers, addresses, and dates of birth. Law firms are investigating potential class action lawsuits.
Biggest Cyber Attacks, Data Breaches, Ransomware Attacks of May 2026 May 2026 delivered yet another resounding reminder that no organisation is immune to cyber threats. From attacks impacting major technology providers and healthcare institutions to incidents affecting transportation, media, and manufacturing organisations, threat actors continued to demonstrate their ability to exploit weaknesses across diverse sectors. This month's most significant cyber incidents include breaches and attacks involving Instructure, Mediaworks, Taiwan High Speed Rail Corporation (THSRC), OpenAI, Grafana, NYC Health + Hospitals, Trellix, Vimeo, and Foxconn. Vulnerabilities Discovered and Patches Released Advisories issued, reports, analysis etc. in May 2026 Collectively, these incidents highlight several key trends shaping today's threat landscape, including supply chain risks, ransomware and extortion campaigns, attacks against critical infrastructure, third-party vulnerabilities, and the growing challenges posed by increasingly sophisticated threat actors. As organisations become more interconnected and reliant on cloud platforms, SaaS services, and complex digital ecosystems, the consequences of a cyber incident continue to grow. The good news is that many of these risks can be mitigated through proactive preparation. By investing in robust cyber incident response plans , scenario-specific playbooks, cyber tabletop exercises , executive cyber crisis training, and regular cyber resilience assessments, organisations can significantly improve their ability to prevent, detect, respond to, and recover from cyber incidents. At Cyber Management Alliance, we help organisations build these capabilities through our NCSC Assured training programmes, cyber incident response services, cyber drills, tabletop exercises, incident response playbook review and creation and executive resilience training. Our complete suite of services enables businesses to stay ahead of the evolving cyber threat landscape and reduce the likelihood and impact of future attacks in 2026. Ransomware group claims breach of pro-Orbán Hungarian media firm Hungarian media company Mediaworks confirmed that attackers stole and leaked nearly 8.5 TB of internal data, including payroll records, contracts, financial files, and internal communications, exposing sensitive business information and creating serious operational and reputational risks. Ransomware attack on Hungarian media firm pro-Orbán Foxconn confirms cyber attack after Nitrogen claims Apple, Nvidia data theft Foxconn confirmed a cyber attack after the Nitrogen ransomware gang claimed it had stolen sensitive files linked to Apple and NVIDIA projects, raising concerns over supply-chain exposure, intellectual property theft, and potential operational disruption within one of the world’s largest electronics manufacturing networks. West Pharma ransomware attack disrupts operations West Pharmaceutical suffered a ransomware attack that encrypted systems and stole data, forcing the company to shut down portions of its global network and disrupting manufacturing, shipping, and supply-chain operations critical to pharmaceutical and biotech customers worldwide. Grafana refuses to pay ransom after codebase theft Grafana Labs confirmed that attackers stole portions of its internal codebase during a supply-chain related breach, but the company refused to pay the ransom demand, raising concerns over potential source code exposure, downstream software integrity risks, and further exploitation attempts targeting customers and developers. Trellix source code breach - Hackers gain unauthorised access to repository Trellix disclosed that attackers gained unauthorised access to part of its internal source code repository, exposing sensitive proprietary code and creating potential supply-chain and vulnerability discovery risks, although there was no evidence of product tampering or customer impact. Instructure confirms data breach, ShinyHunters claims attack Instructure confirmed that attackers stole data from its systems in a cyber attack, potentially exposing information tied to its Canvas learning platform and thousands of educational institutions, raising concerns over student and staff data privacy. Later, reports suggested that Instructure most likely paid a ransom to the cyber criminals. Vimeo data breach exposes personal information of 119,000 people Vimeo’s breach exposed the personal data of over 119,000 users, including names and email addresses, after attackers exploited a third-party analytics provider, increasing the risk of phishing, impersonation, and targeted fraud against affected users. Zara data breach exposed personal information of 197,000 people the April 2026 Dark Web Breach Incident Trend Report is compiled from data breach cases posted on the deep web and dark web forums. some information is included in cases where it is difficult to fully verify the factuality of the information due to the nature of the source. data breaches and sales of initial access to military, government, financial, technology, healthcare, and energy sectors were widely observed on major dark web forums BreachForums (run by Hasan), DarkForums, Exploit, Spear, and PwnForums. ShinyHunters have claimed Data breaches against multinational organizations such as Vimeo Inc., 7-Eleven, ADT Inc., Alert 360, Udemy Inc., Zara, and others, while Cisco source code leaks and internal Telegram group chat data sharing have been observed. high-risk breaches involving military, government, and intelligence organizations were also highlighted. data from China’s People’s Liberation Army (PLA), Iran’s IRGC surveillance system and police databases, Taiwan’s military and cyber security data, Boeing’s SLS and Artemis-related data, Virginia-class submarine technical data, and initial access to firewalls for US aerospace and defense companies were traded or shared. in the South Korea Region, KAAC data, which purports to be an academic organization, was shared on DarkForums, and data related to the Family Federation for World Peace and Unification (Unification Church) was sold. vM Horizon access for an insurance company in the Korea Region was also observed being sold on Spear. The Dedale Office’s claimed breach of shared childcare and community education data was determined to be a fake AI-generated sample data, making it difficult to determine if it was a real breach. the technology, financial, and platform sectors also saw breaches. Data or source code from Blue Origin, Vercel Inc., Coinbase Global Inc., SoundCloud, Polymarket, Jaguar Land Rover Automotive PLC, and Cisco were sold or shared on forums. in the Middle East, Data from TAMM, Taif City e-Government Platform, 1Pass LLC’s CRM Panel data, Riyadh Chamber of Commerce & Industry, and talabat were traded. in Asia, Oceania and the Others Region, Japanese Driver’s License-Personal Data, Mynavi Corporation Personal Data, Singaporean Citizen Data, Agoda Malaysia Customer Data, Elite Cloud Pte. Ltd. data, Beijing Yuansxin Pharmacy Technology Co., Ltd. (Miaoshou Doctor) Data, and card data from Australia and Denmark.
Medtronic, a global medical device maker, disclosed a cyberattack on its corporate IT systems on May 4, 2026. An unauthorized party accessed data, and the threat group ShinyHunters claimed the theft of 9 million records. The company reported no impact on products, operations, or financial systems and is evaluating what data was exposed.
Rutgers University was notified by Instructure, the Canvas LMS vendor, that it was impacted by a widespread data breach. While Instructure stated there was no indication of passwords, dates of birth, government identifiers, or financial information being involved, the specific Rutgers data compromised was under investigation. Rutgers-specific Canvas features were temporarily affected.
Mediaworks Hungary disclosed a serious hacker attack on May 4, 2026, stating that it became the victim of the attack on April 30, 2026. Hungary's data protection authority later reported that hackers unlawfully obtained nearly 15 million files, totaling about 8.5 terabytes, and published them on the dark web. The exposed material reportedly included names, addresses, bank account details, internal records, and public-interest documents.
Art Jetter & Company publicly disclosed an external system breach on May 4, 2026, resulting from a hacking incident. The breach, which occurred on February 21, 2026, affected 150 individuals, with sensitive personal or professional information potentially compromised. The company began sending written notifications to affected consumers on May 4, 2026.
Connected Credit Union experienced a data breach, publicly reported on May 4, 2026, involving unauthorized access to an employee's email account through a phishing scheme. The forensic investigation determined that the compromised emails contained personal and financial information, including names, Social Security numbers, credit and debit card numbers, financial account numbers, and financial account security codes.
Braintrust, an AI evaluation and observability startup, confirmed unauthorized access to one of its AWS accounts after suspicious behavior was reported on May 4, 2026. The company advised customers to rotate their organization-level AI provider keys stored within the platform. One customer was confirmed impacted, and broader exposure had not been identified at the time of reporting. Exposed data included AI provider API keys and customer secrets used to access cloud-based AI models.
Ikron Corp., a nonprofit organization providing behavioral health and employment services, disclosed a data breach to the U.S. Department of Health and Human Services on May 4, 2026. The incident, a ransomware attack from December 2025, led to two unauthorized parties accessing systems and exfiltrating sensitive data. This included names, addresses, dates of birth, Social Security numbers, driver's license numbers, client health information (PHI), and employment-related information, affecting approximately 11,845 individuals.
Murata Electronics North America, Inc. experienced a data breach, publicly reported on May 4, 2026, where an unknown, unauthorized third-party gained access to its IT environment. The breach, which occurred between March 2025 and February 28, 2026, exposed sensitive personal information for 331 individuals, including names, addresses, email addresses, Social Security numbers, citizenship and marital status, driver's license and passport information, insurance policy information, health or medical condition related information, and financial account numbers.
Explore the intelligence
Compare incidents across industries and critical services.
Explore all sectors →Follow recurring intrusion methods and adversary behaviour.
Explore all attack patterns →Track consequences such as disruption and data exposure.
Explore all impacts →Compare reports by explicitly affected country.
Explore all countries →Explore the intelligence
Explore concise answers about the latest reporting, intelligence taxonomies and the rolling coverage metrics on this page.
12 answers across 4 topics
How to read and use the current intelligence overview.
It brings source-backed cybersecurity reports from the rolling 90-day window into one view, then connects them to companies, sectors, attack patterns, impacts and affected countries.
Start with Latest reporting for individual incidents, or use the taxonomy section to compare recurring patterns across industries, consequences and locations.
No. It is a curated view of public reports that meet Shadow Tier's publication and classification criteria, not an exhaustive record of every incident worldwide.