216
Reports in 90 days
in the current rolling intelligence window
Current cyber intelligence
Shadow Tier brings verified public reporting into one current view. Start with the latest incidents below, or compare the companies, sectors, attack patterns, impacts and countries connected to them.
216
in the current rolling intelligence window
10
represented in the same 90-day window
65
high or critical reports in 90 days
Latest reporting
Showing 91–108 of 216 reports published in the last 90 days.
At least nine organizations have publicly acknowledged the impact of the supply chain attack on market intelligence platform Klue. The incident occurred on June 11-12 and affected Klue’s integration with Salesforce, resulting in data being exfiltrated from the Salesforce instances of multiple Klue customers, including several cybersecurity firms. On Friday, Klue confirmed previous security reports that the attackers used compromised legacy credentials to access its systems and compromise Salesforce integrations. “The attacker used that access to obtain OAuth tokens used to connect Klue with certain third-party platforms, including Salesforce, and subsequently accessed data within a number of connected customer environments,” Klue said. The company revoked the affected credentials and tokens, disabled the integrations across multiple services, and has been investigating the attack together with CrowdStrike and law enforcement. “Based on our investigation to date, the incident was limited to the affected third-party platforms, and there is no evidence that customer content stored within the Klue platform was impacted,” the company said. Advertisement. Scroll to continue reading. To date, at least nine Klue customers have disclosed impact from the incident, including cybersecurity firms HackerOne , Huntress , Jamf , OneTrust , Recorded Future , Snyk , and Tanium . Insurity and Sprout Social also notified their customers of the incident. All the affected companies pointed out that the intrusion was limited to the Salesforce instances and did not involve their systems, as Klue said in its incident notice. Across the board, the hackers stole business information from the affected organizations’ Salesforce CRMs, including sales account data and business contact information, such as names, email addresses, job titles, phone numbers, and business addresses. Salesforce disabled the Klue integration in the wake of the incident, and revenue intelligence platform Gong did the same on Friday, warning that the hackers exploited its Klue integration to access internal licensed user data. “We can confirm no direct impact on call recordings or customer transcripts. Examples of data accessed included user names, user business titles, and user emails,” Gong said. In its analysis of the incident, Huntress suggested that a threat actor named Icarus might have been responsible for the attack. Since then, Icarus has added Klue to its Tor-based leak site, claiming responsibility for the attack and threatening to publish the information stolen from Klue customers’ Salesforce instances. Per the threat actor’s posts, the data would be released on June 22, unless Klue and the affected organizations engage in negotiations. Related: Cybersecurity Firms Impacted by Klue Supply Chain Attack Related: Atomic Arch Supply Chain Attack Hits 1,500 AUR Packages Related: ‘SymJack’ Attack Turns AI Coding Agents Into Supply Chain Attack Delivery Systems Related: Laravel-Lang Packages Poisoned for Malware Delivery Written By Ionut Arghire Ionut Arghire is an international correspondent for SecurityWeek. New HollowGraph Malware Abuses Microsoft 365 Calendar for C&C Communication Estée Lauder Discloses Impact From Oracle EBS Zero-Day Hack Clover Health Investments Discloses Data Breach Zimbra Update Patches Critical Vulnerabilities OpenSSL Silently Fixes ‘HollowByte’ DoS Vulnerability Ernst & Young Data Breach Affects Personal, Financial Information Hugging Face Hacked in Autonomous AI Attack Chrome 150 Update Patches Severe Memory Safety Bugs Fourth SharePoint Vulnerability Exploited in Past Month’s Wave of Attacks Endpoint Security Firm Glow Launches With $180M in Funding at $1.2B Valuation Oracle Patches Over 1,400 Vulnerabilities With Quarterly Security Updates Ransomware Group Threatening to Leak Data Stolen From Coca-Cola’s Fairlife OpenAI Says Its AI Models Broke Loose and Hacked Hugging Face Trump Orders Defense Contractors to Map Software, Suppliers Across Critical Supply Chains Cisco Launches Low-Cost AI Models for Source Code Security Empirical Security Raises $25 Million in Series A Funding Klue OAuth breach victim list grows as Icarus hackers claim attack Market intelligence platform Klue has publicly confirmed a recent security incident that allowed threat actors to steal OAuth tokens used to connect to customers' Salesforce environments, as the new "Icarus" extortion group publicly claims the attack. The disclosure comes after cybersecurity firms Huntress and ReliaQuest detailed how attackers abused compromised Klue Battlecards integrations to steal Salesforce CRM data from multiple organizations. In a statement published this week, Klue CEO Jason Smith confirmed that the company discovered unauthorized activity on June 12 affecting part of Klue's integration infrastructure. "On June 12, we identified unauthorized activity affecting a portion of Klue's integration infrastructure. Since then, we've been working alongside trusted cybersecurity experts to understand what happened, support our customers, and restore the connections you rely on," wrote Smith . "Our investigation determined that an attacker gained access through a compromised legacy credential associated with an integration service. The attacker used that access to obtain OAuth tokens used to connect Klue with certain third-party platforms, including Salesforce, and subsequently accessed data within a number of connected customer environments." The company says there is currently no evidence that customer content stored directly within the Klue platform was impacted and that the incident was limited to third-party integrations. Klue says it immediately revoked affected credentials and tokens, removed unauthorized code, disabled impacted integrations, launched an investigation, and notified law enforcement. The company also confirmed it engaged CrowdStrike to assist with the response. ReliaQuest and Huntress found that the attackers used stolen OAuth credentials associated with Klue integrations to access customer Salesforce environments and conduct large-scale data theft. ReliaQuest observed attackers generating OAuth tokens and using Python scripts to query Salesforce's API for extended periods, as data was stolen. Huntress later disclosed that its own Salesforce environment was affected by the Klue breach and that the stolen data included business contacts, sales communications, pricing information, and other records. While BleepingComputer and Huntress previously linked the incident to the Icarus extortion operation, the threat actors have now publicly claimed responsibility on their data leak site. "As you've probably already heard, Klue.com has been impacted by us recently. A number of other companies' Salesforce instances, which were partners to Klue, were exfiltrated," reads the Icarus post. Security teams log 54% of successful attacks and alert on just 14%. The rest move through your environment unseen.
LastPass is the latest cybersecurity firm to have disclosed the impact from the Klue hack, which resulted in unauthorized access to customers’ Salesforce instances. A threat actor calling itself Icarus used a compromised legacy credential to access Klue’s systems and generate OAuth tokens to breach third-party platforms Klue integrates with, such as Salesforce. Icarus then accessed the connected Salesforce instances and exfiltrated data in bulk , using automated scripts. Salesforce and Gong have disabled the Klue integration in response to the attack, and over a dozen organizations have already confirmed the impact. Incident notifications from the affected companies reveal that the attackers accessed business data accessible through the Klue integration, and that no internal systems were compromised. LastPass’s notice follows the same lines: “The information accessed was limited to standard business contact information and related customer relationship management (CRM) data, including customer names, phone numbers, email addresses, and physical addresses, as well as support case data and sales-related data.” The company says it has discontinued access to Klue, rotated exposed tokens, notified law enforcement, and launched an investigation together with Klue and Salesforce. Advertisement. Scroll to continue reading. “It is important to note that the scope of this incident is limited to only those systems that integrate with Klue’s application. LastPass products, services, and infrastructure were not impacted in any way, and customer vaults remain secure. There is also no evidence the threat actor accessed any Gong-related data,” LastPass said. This week, in addition to LastPass, 8×8 and Pendo announced they were affected. Late last week, HackerOne, Huntress, Insurity, Jamf, OneTrust, Recorded Future, Snyk, Sprout Social, and Tanium disclosed the impact from the attack. BeyondTrust also said business contact and sales-related information was stolen from its Salesforce instance, but the notification went unnoticed. On its Tor-based leak site, Icarus has listed several organizations as having their Salesforce data stolen, including Swiss AI communications solutions provider Gms-net. SecurityWeek has emailed the technology company for a statement and will update this article if it responds. Icarus’s website is currently down but, before becoming inaccessible, it listed at least four other companies that have yet to publicly disclose being affected by the Klue incident, which brings the number of victims to roughly 15. Per Huntress’s estimates, however, numerous other Klue customers were likely impacted by the data breach and are expected to come forward. Related: North Korean Hackers Blamed for Mastra NPM Supply Chain Attack Related: OpenAI Refocuses Cybersecurity Efforts on Patching Over Discovery Related: Russian Initial Access Broker Behind FortiBleed Campaign Related: Canadian Electricity Provider London Hydro Discloses Data Breach Written By Ionut Arghire Ionut Arghire is an international correspondent for SecurityWeek. New HollowGraph Malware Abuses Microsoft 365 Calendar for C&C Communication Estée Lauder Discloses Impact From Oracle EBS Zero-Day Hack Clover Health Investments Discloses Data Breach Zimbra Update Patches Critical Vulnerabilities OpenSSL Silently Fixes ‘HollowByte’ DoS Vulnerability Ernst & Young Data Breach Affects Personal, Financial Information Hugging Face Hacked in Autonomous AI Attack Chrome 150 Update Patches Severe Memory Safety Bugs Fourth SharePoint Vulnerability Exploited in Past Month’s Wave of Attacks Endpoint Security Firm Glow Launches With $180M in Funding at $1.2B Valuation Oracle Patches Over 1,400 Vulnerabilities With Quarterly Security Updates Ransomware Group Threatening to Leak Data Stolen From Coca-Cola’s Fairlife OpenAI Says Its AI Models Broke Loose and Hacked Hugging Face Trump Orders Defense Contractors to Map Software, Suppliers Across Critical Supply Chains Cisco Launches Low-Cost AI Models for Source Code Security Empirical Security Raises $25 Million in Series A Funding Join this live webinar as we explore why exploitation is outpacing remediation, where risk is growing fastest, and what security leaders can do to close the gap before attackers take advantage.
Alert - AL26-014 – FortiBleed leak of thousands of compromised credentials impacting Fortinet devices This Alert is intended for IT professionals and managers. An Alert is used to raise awareness of a recently identified cyber threat that may impact cyber information assets, and to provide additional detection and mitigation advice to recipients. The Canadian Centre for Cyber Security ("Cyber Centre") is also available to provide additional assistance regarding the content of this Alert to recipients as requested. On June 17, 2026, the Canadian Centre for Cyber Security (Cyber Centre) became aware of open-source reporting Footnote 1 Footnote 2 Footnote 3 Footnote 4 describing a widespread malicious campaign, known as “FortiBleed,” involving exposed credentials affecting Fortinet firewalls and VPN gateways. Exploitation of these credentials could allow malicious actors to gain remote access to affected devices and connected networks, as well as modify various system settings, including critical security controls. The Cyber Centre strongly recommends that organizations : Inventory all accounts on Fortinet devices, identify unauthorized or suspicious accounts (e.g., forticloud-sync , forticloud-tech ) and disable/remove suspected or unneeded accounts. Restrict access to management interfaces to trusted networks and hosts only. Terminate all active SSL VPN and administrative sessions. Reset passwords for all Fortinet VPN and administrative accounts. Enforce Multi-Factor Authentication (MFA) across all external gateways and admin interfaces. Ensure all Fortinet devices are running the latest firmware. Specifically, check for patches related to CVE-2024-55591 (obtain high privileges) Footnote 5 and, CVE-2025-59718 Footnote 6 and CVE-2025-59719 Footnote 7 (authentication bypass) Footnote 8 . In addition, the Cyber Centre strongly recommends that organizations review and implement the Cyber Centre’s Top 10 IT Security Actions with an emphasis on the following topics Footnote 9 . Consolidate, monitor and defend Internet gateways Patch operating systems and applications Enforce the management of administrative privileges Harden operating systems and applications Should activity matching the content of this alert be discovered, recipients are encouraged to report via My Cyber Portal , or email contact@cyber.gc.ca . FortiBleed: 75,000 Fortinet Firewalls Compromised: Global Enterprises Exposed – Claim Your Ethical Disclosure Fortinet firewalls and VPN gateways serve as the primary defensive perimeter for countless organizations worldwide. However, a massive new cyber espionage campaign has silently compromised these highly trusted devices on an unprecedented global scale. Originally discovered by security researcher Volodymyr “Bob” Diachenko , with further analysis from Hudson Rock and cybersecurity expert Kevin Beaumont , this dataset exposes a massive, automated operation. Threat actors successfully targeted 73,932 unique firewall URLs across 194 countries, resulting in 21,632 unique affected domains . Astonishingly, as Beaumont highlighted, this represents roughly 50% of all Fortinet firewall devices currently facing the internet . Attacker Methodology & Unprecedented Scale According to Diachenko’s investigative report, this campaign is orchestrated by a multi-operator, Russian-speaking cybercriminal group. The operation’s footprint is staggering: the attackers executed an estimated 1.16 billion credential attempts against over 320,000 FortiGate targets, alongside an additional 2.1 billion brute-force attempts directed at over 160,000 MSSQL servers. The group’s methodology goes beyond simple credential reuse. They actively intercept SSL VPN authentication hashes and crack them using a massive, dedicated 45-GPU cluster managed via Hashtopolis. Once the perimeter is breached, the operators systematically pivot directly into internal Active Directory environments to establish deep network persistence. This aggressive methodology has led to severe, real-world consequences. Diachenko’s research confirmed full network compromises at multiple organizations across Japan, Taiwan, Vietnam, Iraq, and Turkey. Most alarmingly, this includes a Turkish NATO defense contractor from which classified defense documents were successfully exfiltrated by the group. Beaumont notes a sharp contrast between this incident and the prior “Belsen Group” leak of 15,000 devices from a 2022 zero-day. This dataset represents active, recent compromises—with many of the affected devices running recent patches. Furthermore, Beaumont observed that the formatting of the leaked data, which explicitly categorizes victims by company type, revenue, and country, is a hallmark of eCrime syndicates packaging initial access for sale on the dark web. As Beaumont explains in his blog , the attackers likely exploited older credential hashing mechanisms to pull this off. While Fortinet hardened admin credential storage in early 2025 by moving to PBKDF2, this protection only applied if administrators actively logged in after applying the firmware updates. Consequently, many devices continued storing credentials using the older, more vulnerable SHA-256 with Salt format, making them highly susceptible to offline brute-forcing once the configuration files were extracted. The scale of this breach touches nearly every sector of the global economy, sparing no industry. The threat actors have built a verified database of working credentials for some of the largest enterprises on the planet. Among the victims discovered in this dataset are massive multinational corporations, including: …and thousands of others, including major government entities and critical infrastructure providers. When examining the attacker infrastructure, it becomes clear how systematic and devastating this campaign is. The attackers maintained highly organized logs of successful breaches. A particularly alarming detail from this dataset is the high volume of extremely complex passwords that were successfully compromised. IT departments frequently lean on rigid password complexity rules as their main line of defense. However, complexity is completely neutralized when passwords are recovered in plaintext. Whether threat actors leverage specific device exploits that expose plaintext credentials, or utilize databases previously harvested by Infostealers, a 20-character complex string is just as vulnerable as a simple one. If the attackers are recycling known plaintext credentials to bypass perimeters, complexity policies offer no protection. To secure your network against this specific vector, we strongly recommend the following immediate actions: Remove Internet Exposure: Immediately ensure the FortiOS Management Interface is not exposed to the public internet unless absolutely necessary. Force Credential Rotation & Upgrade Hashing: Upgrade to the latest FortiOS release and have all admins log back in to force the system to re-hash passwords using the more secure PBKDF2 standard. Enforce Strict MFA: Ensure Multi-Factor Authentication is universally applied to all external gateways and admin interfaces, effectively neutralizing the threat of stolen plaintext passwords. 🚨 Free Look-Up Tool for Affected Organizations
De Belastingdienst heeft een datalek gemeld bij de Autoriteit Persoonsgegevens (AP) nadat bleek dat via Adobe Analytics mogelijk persoonsgegevens van burgers zijn doorgestuurd naar een externe dienstverlener. Het incident werd ontdekt door een ethisch hacker en roept opnieuw vragen op over het gebruik van tracking- en analysetools binnen overheidsomgevingen waar gevoelige persoonsgegevens worden verwerkt. Volgens de Belastingdienst is de betreffende functionaliteit inmiddels uitgeschakeld en loopt er onderzoek naar de omvang van het incident. Ook wordt onderzocht of vergelijkbare toepassingen elders binnen de organisatie worden gebruikt. Ethisch hacker ontdekt gegevensuitwisseling Het datalek kwam aan het licht nadat een ethisch hacker constateerde dat tijdens het gebruik van een online betaalomgeving gegevens werden gedeeld met Adobe Analytics. Hoewel dergelijke analysetools veel worden ingezet om websites en online diensten te verbeteren, kunnen zij bij onzorgvuldige implementatie leiden tot ongewenste verwerking van persoonsgegevens. In dit geval zouden onder meer gegevens over belastingaanslagen, betaalprocessen en gebruikersinteracties zijn doorgestuurd naar de analysetool. De Belastingdienst onderzoekt momenteel welke gegevens precies zijn verwerkt, hoeveel burgers zijn getroffen en of sprake is geweest van een overtreding van privacywetgeving. > LEES OOK: Onderzoek legt zwakke plekken bloot na omvangrijk datalek in Epe Het incident onderstreept een probleem waar veel organisaties mee worstelen: het gebruik van commerciële tracking- en analysetools binnen omgevingen die privacygevoelige informatie bevatten. Sinds diverse uitspraken van Europese privacytoezichthouders ligt het gebruik van analyse- en trackingsoftware onder een vergrootglas. Organisaties moeten kunnen aantonen welke gegevens worden verzameld, met welk doel dit gebeurt, waar deze gegevens worden opgeslagen en welke partijen toegang hebben tot de informatie. Voor overheidsorganisaties gelden daarbij extra hoge eisen. Zij verwerken grote hoeveelheden persoonsgegevens en moeten voldoen aan strikte wettelijke verplichtingen op grond van de Algemene Verordening Gegevensbescherming (AVG). Vanuit security- en privacyperspectief laat het incident zien dat risico’s niet alleen ontstaan door cyberaanvallen of kwetsbaarheden in software, maar ook door reguliere bedrijfsprocessen en applicaties die onvoldoende worden getoetst op privacy- en securityaspecten. Voor securitymanagers en CISO’s benadrukt deze zaak het belang van: Een volledig overzicht van alle gebruikte tracking-, analyse- en marketingtools; Periodieke privacy- en securityassessments van externe leveranciers; Duidelijke governance rond de inzet van SaaS-oplossingen; Data Protection Impact Assessments (DPIA’s) bij verwerking van gevoelige persoonsgegevens; Continue monitoring van gegevensstromen naar externe partijen. Met name zogenoemde “ shadow IT ” en decentraal geïmplementeerde analysetools vormen binnen grote organisaties een groeiend risico. Zonder centrale controle kan onbedoeld een situatie ontstaan waarin persoonsgegevens worden gedeeld met derde partijen zonder dat dit voldoende is beoordeeld of gedocumenteerd. Leveranciersrisico’s blijven aandachtspunt De melding bij de Autoriteit Persoonsgegevens laat daarnaast zien dat third-party risk management een steeds belangrijkere rol speelt binnen cybersecurity en privacy compliance . Organisaties zijn niet alleen verantwoordelijk voor hun eigen systemen, maar ook voor de manier waarop leveranciers en dienstverleners omgaan met persoonsgegevens. Voor securityprofessionals vormt het incident een herinnering dat datalekken niet uitsluitend ontstaan door kwaadwillende aanvallers. Ook legitieme softwarecomponenten kunnen leiden tot ongewenste gegevensverwerking wanneer governance, configuratiebeheer en privacycontroles tekortschieten. > LEES OOK: Boete van 600.000 euro voor tracking cookies op Kruidvat.nl Breder signaal voor overheid en bedrijfsleven Hoewel het onderzoek naar het incident nog loopt, past de melding in een bredere ontwikkeling waarbij toezichthouders steeds kritischer kijken naar de inzet van trackingtechnologieën binnen organisaties die gevoelige persoonsgegevens verwerken. De uitkomsten van het onderzoek van de Belastingdienst en een eventuele beoordeling door de Autoriteit Persoonsgegevens zullen naar verwachting ook voor andere overheidsorganisaties en bedrijven relevante lessen opleveren over het verantwoord gebruik van analysetools binnen kritieke digitale processen.
If you think 2025 was the year of the breaches,2026 has already gotten worse. Modern-day attackers are now devising attacks that are undetectable even by sophisticated defense systems using AI-enabled tools and advanced social engineering methods. Data breaches are now impacting global economies, and regulators have become stricter about what they expect from organizations. Organizations are now facing added pressure to timely and effectively manage security and compliance risk. Let us look at some of the top data breaches of June 2026: Victim: Reliance Group (Kudankulam Nuclear Power Plant) The Kudankulam Nuclear Power Plant project is one of the seven largest nuclear plants in India, and its major contractor is Reliance Group. The Reliance group confirmed that some of the data on a server hosted on their third-party Indian data center service provider, Yotta, has been breached. The ransomware group has claimed to have stolen 858000 Reliance Group’s files, out of which 19000 files are the most confidential files containing details of the Kudankulam Nuclear Power Plant, including blueprints and supplier details. Nissan is a Yokohama-based automobile manufacturer that was founded in 1999. It sells vehicles through Infiniti, Datsun, Nismo, and Autech brands and is one of the top automotive manufacturers in the world. Nissan became a victim of a cyber attack through the exploitation of an Oracle PeopleSoft flaw. The attack was orchestrated by the Shiny Hunterz ransomware group. The incident has impacted current and former Nissan U.S., Canada, Mexico, and Brazil employees. The data exposed includes employee contact information, banking information, SSNs, Social Insurance Numbers, National Identification Numbers, financial and tax information, and dependent and beneficiary information. The Central Bank of Libya is Libya’s monetary authority. It is based in Tripoli and was founded in 1955, replacing the Libyan Currency Commission. The CBL discovered unauthorized access to its systems and data published on the dark web. It is currently working with technical teams to determine the nature of the incident. The complete nature and quantity of data exposed is currently under investigation. Prince George’s County is a Maryland-based county that offers multiple services to its residents, including mental health services, housing support, and emergency shelters. Prince George’s County discovered unauthorized access and disruption of its systems on June 11. The data exposed includes names, addresses, Dates of Birth, driver’s licenses, and Social Security Numbers. KDDI Corporation is a Japan-based telecommunications operator that was established in 2000. It is known for its cellular services, using the Au brand along with subbrands UQ Mobile and Povo. KDDI Corporation reported unauthorized access to its mailing system that was used by six internet providers. The ransomware group has claimed to have exfiltrated 297 GB (429000 files) of Council of Europe data, including payslips, HR records, CVs, and financial information. Victim: Ukrposhta – Ukraine’s National Postal Service JSC Ukrposhta is Ukraine’s national postal service located in Kyiv. It is the member of the Universal Postal Union since 1947 and has over 73000 employees. Ukrposhta reported that due to a hostile attack on its IT systems, its applications have been temporarily disrupted. The cyber attack caused the malfunction of its systems and applications. The complete nature of the incident is currently under investigation. Officials warn that unencrypted messaging apps are easy targets for hacking and surveillance. Protect your privacy and secure your data—watch now! Twitch streamer Kai Cenat was swatted during a live stream, shocking viewers. The event unfolded mid-stream, highlighting the risks streamers face from hoaxes. Military officials installed Starlink on a Navy warship, not for operations but to provide high-speed internet for sports and Netflix. Watch to learn more. Unpatched Mazda Connect vulnerabilities allow hackers to install persistent malware, exposing vehicles to remote attacks and unauthorized access. In this video, we explore Deloitte’s recent data breach, the data compromised, and what the company is doing to address the situation. We reveal a TSA security flaw that allowed hackers to bypass protocols and access cockpits. Explore the implications of this breach and what can be done. .more-dropdown-link]:hidden" data-nav-href="/products/" data-nav-type="static-posts"> Best Products Best Products Top Articles View All Link to Top Cybersecurity Companies Top Cybersecurity Companies The cybersecurity industry is constantly evolving. Learn about the top cybersecurity companies and what each does best. Link to Threat Intelligence Platforms Threat Intelligence Platforms Threat intelligence platforms help analyze and share cyber threat data. Discover top TIPs , their features, use cases, and comparisons. Link to GRC Tools GRC Tools Discover the top governance, risk and compliance (GRC) tools and software to help identify products that may suit your enterprise's needs. Link to Network Access Control Solutions Network Access Control Solutions Explore the top NAC solutions to ensure your network is only accessed by trusted users and avoid unwanted risks. Link to Top NGFW Top NGFW Explore the top next-generation firewall solutions. Assess features and pricing to discover the ideal NGFW solution for your needs. Link to EDR Solutions EDR Solutions EDR solutions ensure an organization's endpoints are running properly by monitoring and troubleshooting tech on the network. Compare the top tools now. .more-dropdown-link]:hidden" data-nav-type="content-hub-resources"> Resources Resources Resource Hubs Modern SIEM, Minus the Noise Security That Endures A Playbook for True Cyber Resilience Videos Partner Content Featured Resources Link to US Officials Recommend Using Encrypted Apps for Messaging US Officials Recommend Using Encrypted Apps for Messaging .more-dropdown-link]:hidden" data-nav-href="/networks/" data-nav-type="static-posts"> Networks Networks Top Articles View All Link to What is Network Security? Definition, Threats & Protections What is Network Security? Definition, Threats & Protections Learn about the fundamentals of network security and how to protect your organization from cyber threats. Link to Network Protection: How to Secure a Network in 13 Steps Network Protection: How to Secure a Network in 13 Steps Securing a network is a continuous process. Discover the process of securing networks from unwanted threats. Link to Top 19 Network Security Threats + Defenses for Each Top 19 Network Security Threats + Defenses for Each Discover the most common network security threats and how to protect your organization against them.
Chubu Telecommunications C., Inc., one of the Japanese internet service providers sharing KDDI Corporation's email system, had its customer email addresses and passwords potentially exposed due to a vulnerability exploited by unauthorized actors.
Comcast was among the organizations affected by the 'FortiBleed' cyber espionage campaign, which compromised Fortinet firewalls and VPN gateways globally. The attackers gained unauthorized access by exploiting exposed Fortinet instances and brute-forcing credentials. The Canadian Centre for Cyber Security reported on June 17, 2026, about the widespread malicious activity.
A widespread cyber espionage campaign, dubbed 'FortiBleed,' compromised thousands of Fortinet firewalls and VPN gateways globally, including devices used by Foxconn. The attackers exploited exposed Fortinet instances to extract and brute-force credentials, potentially allowing deep network persistence. The Canadian Centre for Cyber Security became aware of open-source reporting on June 17, 2026, detailing the campaign.
Amsterdam-based fashion and streetwear brand Patta was listed as a victim on the extortion site of the LockBit 5.0 ransomware group on June 17, 2026. LockBit 5.0 is known for encrypting systems and stealing sensitive data, then demanding a ransom under threat of public disclosure.
Japanese telecommunications operator KDDI Corporation disclosed a data breach where threat actors gained access to one of its email systems, which is also used by five other internet service providers in the country. The company discovered the intrusion on June 17, 2026, and immediately blocked the attackers. The breach was caused by exploiting a vulnerability in unnamed third-party software used in the email system. Up to 14.2 million email addresses and passwords, including those of current and former customers, may have been exposed.
Klue, a market intelligence platform, experienced a supply chain breach where attackers used compromised legacy credentials to access its integration environment and obtain OAuth tokens. These tokens were then used to access connected Salesforce environments, leading to the exfiltration of CRM data. Salesforce disabled the Klue Battlecards integration on June 17, 2026, and Klue revoked affected credentials, removed unauthorized code, and disabled impacted integrations. The attack unfolded between June 11 and June 12, 2026, but the impact on customer Salesforce environments was identified and reported by various victims on or around June 17, 2026.
PwC was identified as one of the global enterprises impacted by the 'FortiBleed' cyber espionage campaign. This campaign involved the compromise of Fortinet firewalls and VPN gateways, where attackers exploited exposed instances to extract and brute-force credentials. The Canadian Centre for Cyber Security became aware of the widespread malicious activity on June 17, 2026.
Lenovo was among the high-profile victims of the 'FortiBleed' cyber espionage campaign, which compromised Fortinet firewalls and VPN gateways worldwide. Attackers gained unauthorized access by exploiting exposed Fortinet instances and brute-forcing credentials. The Canadian Centre for Cyber Security issued an alert on June 17, 2026, detailing the widespread malicious activity.
On June 16, 2026, the French government announced that its volunteering platform, Jeveuxaider.gouv.fr, had been a victim of a personal data leak affecting approximately 550,000 accounts.
On June 16, 2026, reports emerged that the hacking group FulcrumSec claimed responsibility for a data breach at pharmaceutical giant Novo Nordisk, demanding a $25 million ransom. Novo Nordisk confirmed an IT security incident involving unauthorized access to a limited number of internal IT systems and the copying of non-public and clinical trial-related patient data. The exposed data for healthcare professionals may include names, registration numbers, email addresses, phone numbers, WhatsApp details, and office locations.
The municipality of Epe publicly released its evaluation report on a data breach that occurred on March 10, 2026, affecting nearly all its residents. The report details how attackers gained access to the municipal network via a 'ClickFix' method, cracked an administrator password, and accessed an emergency account, leading to the exfiltration of 871 GB of data, including personal data like names, addresses, birth dates, and BSNs. State Secretary Van der Burg (BZK) expressed regret over the consequences and praised the municipality for its transparency.
River Financial Corporation, including River Bank & Trust, reported a cybersecurity incident where an unauthorized threat actor gained access to its network environment on or about June 16, 2026. Ransomware was deployed across parts of its server infrastructure. The company discovered the malicious activity around June 19, 2026, and quickly disabled affected administrative accounts and took impacted systems offline. An investigation is ongoing to determine if any personally identifiable information was accessed or taken.
Sand Hills Medical Foundation in South Carolina was impacted by the Inc ransomware group, which claimed responsibility and leaked stolen data on June 15, 2026. Approximately 169,000 patients were affected, with exposed data including Protected Health Information (PHI), Social Security numbers, driver's licenses, and passports.
Explore the intelligence
Compare incidents across industries and critical services.
Explore all sectors →Follow recurring intrusion methods and adversary behaviour.
Explore all attack patterns →Track consequences such as disruption and data exposure.
Explore all impacts →Compare reports by explicitly affected country.
Explore all countries →Explore the intelligence
Explore concise answers about the latest reporting, intelligence taxonomies and the rolling coverage metrics on this page.
12 answers across 4 topics
How to read and use the current intelligence overview.
It brings source-backed cybersecurity reports from the rolling 90-day window into one view, then connects them to companies, sectors, attack patterns, impacts and affected countries.
Start with Latest reporting for individual incidents, or use the taxonomy section to compare recurring patterns across industries, consequences and locations.
No. It is a curated view of public reports that meet Shadow Tier's publication and classification criteria, not an exhaustive record of every incident worldwide.