The Intel Desk
Every active breach, ransomware deployment, and supply-chain incident we've covered. Searchable, filterable, with sources.
| Sev | Class | Brief | Date |
|---|---|---|---|
| High | Breach | Snowflake Customer Tenants: Infostealer Credentials and Missing MFA | 2026-08-12 |
| Critical | CVE · KEV | Phoenix Contact PLCnext Devices: Critical Unauthenticated PROFINET Buffer Overflow (CVE-2025-41769) | 2026-08-12 |
| High | Ransomware | AngMar Companies: Interlock Ransomware Data Extortion Claim | 2026-08-12 |
| High | Breach | Unlimited Technology Systems: 3.8 Million Patient Records Stolen From Hosted Data Center | 2026-08-12 |
| High | Breach | Movistar: Unverified Dark Web Breach Claim, 500,000 Customers | 2026-08-12 |
| High | Breach | Suisun City, California: Suspected Ransomware Shuts Down Entire Municipal IT Network | 2026-08-12 |
| High | Breach | China's Ministry of Public Security: Dark Web Listing Claims Spyware and Espionage File Sale | 2026-08-12 |
| High | Breach | DentaQuest: ShinyHunters Extortion Breach Hits at Least 15 Million Patients | 2026-08-12 |
| High | Breach | Valve: Supply Chain Breach at CEVA Logistics Exposes European Steam Hardware Buyers | 2026-08-12 |
| High | Ransomware | POWDR Corporation: Settra Ransomware Data Extortion | 2026-08-12 |
| High | Breach | Unlimited Technology Systems: Unattributed Intrusion Exposes 3.8M Patient Benefits Records | 2026-08-12 |
| High | Ransomware | Stadler: Everest Extortion via Supplier Data Exchange Platform | 2026-08-12 |
| High | Breach | Uber Freight: Helix Extortion Claim and Confirmed Unauthorized Access | 2026-08-12 |
| High | Ransomware | Minidoka Memorial Hospital: Unattributed Ransomware Intrusion Exposes Patient SSNs | 2026-08-12 |
| High | Breach | Kazakhstan eGov: Alleged Darknet Sale of National Citizen Database | 2026-08-12 |
| High | Breach | Unlimited Technology Systems: Unattributed Intrusion and Bulk Data Theft | 2026-08-12 |
| High | Ransomware | AnMed Health: The Gentlemen Ransomware Claim Follows Weeks of Care Disruption | 2026-08-12 |
| High | Ransomware | Philadelphia Insurance Companies: Ethics Ransomware Claim | 2026-08-12 |
| High | Breach | Venezuelan Government Systems: Unverified Actor Claim of Nationwide Identity Data Exposure | 2026-08-12 |
| High | Ransomware | Critical Infrastructure Operators: Gunra Ransomware Double Extortion Campaign | 2026-08-11 |
| Critical | CVE · KEV | Cisco ASA/FTD Remote Access SSL VPN Flaw Lands in KEV (CVE-2026-20349) | 2026-08-11 |
| Critical | CVE · KEV | CVE-2026-69102: Hard-Coded JWT Secret in MaxKey Grants Unauthenticated Admin Access | 2026-08-11 |
| High | Breach | Bank of Baroda: Employee Email Compromise Behind Alleged 1TB Dark Web Leak | 2026-08-11 |
| High | Breach | U.S. Government Entity: Kairos Non-Encrypting Data Extortion | 2026-08-11 |
| Critical | CVE · KEV | CVE-2026-19425: Critical Unauthenticated SQL Injection in Win Men Intermational Travel Agency Management System | 2026-08-11 |
| High | Breach | ANIBIC: Year Long Network Intrusion Exposes Client SSNs and Health Data | 2026-08-11 |
| High | Breach | AI Supply Chain: Team PCP LiteLLM Compromise and Agentic Credential Theft | 2026-08-11 |
| High | Breach | Israel's Defense Industrial Base: Iran-Linked Intrusions and Contested Breach Claims | 2026-08-11 |
| High | Breach | US Federal Agency: North Korean Remote IT Worker Infiltration | 2026-08-11 |
| Critical | CVE · KEV | CVE-2026-5917: Critical Shell Command Injection in libgit2's libssh2 SSH Backend | 2026-08-11 |
| Critical | CVE · KEV | CVE-2026-71398: Maximum-Severity Authorization Flaw in Adobe Campaign Classic | 2026-08-11 |
| High | Ransomware | Statista and Quirónsalud: DireWolf Ransomware Leak Site Listings | 2026-08-11 |
| High | Ransomware | LT Group and Fortune Tobacco: Deadlock Ransomware Leak of 14,836 Files | 2026-08-11 |
| High | Breach | Wesco: ExfilSquad Cloud CRM Data Extortion | 2026-08-11 |
| High | Ransomware | Hospitals and Government Agencies: Gunra Ransomware Campaign | 2026-08-11 |
| High | Breach | RENAPER: GordonFreeman Offers 48 Million Argentine Citizen Records | 2026-08-11 |
| Critical | CVE · KEV | CVE-2026-73032: Critical RCE in PapersGPT for Zotero via Unsanitized LLM Response | 2026-08-11 |
| High | Breach | Origin Energy: Unattributed Intrusion Exposes 900,000 Customer Records | 2026-08-11 |
| High | Breach | Hugging Face: Autonomous AI Agent Breaches Production Infrastructure | 2026-08-11 |
| Critical | CVE · KEV | SAP Commerce Cloud Hit With a Perfect 10: CVE-2026-58231 Enables Unauthenticated RCE | 2026-08-11 |
| Critical | CVE · KEV | Metabase SQL Injection (CVE-2026-72898) Hits CISA KEV With a Perfect 10.0 | 2026-08-11 |
| Critical | CVE · KEV | CVE-2026-73034: Unauthenticated Path Traversal in DB-GPT | 2026-08-11 |
| Critical | CVE | Siemens SIMATIC IoT2050 Advanced: Unauthenticated Node-RED RCE (CVE-2026-58115) | 2026-08-11 |
| High | Ransomware | Canadian Hospital: Ransomware Disrupting Building Automation Systems | 2026-08-11 |
| Critical | CVE · KEV | CVE-2026-72748: Unauthenticated Arbitrary File Write in AVideo | 2026-08-11 |
| Critical | CVE · KEV | CVE-2026-27302: Maximum-Severity Authorization Flaw in Adobe Campaign Classic Carries Unauthenticated Code Execution Risk | 2026-08-11 |
| Critical | CVE · KEV | Adobe Commerce Privilege Escalation: CVE-2026-71362 Rates CVSS 9.1 | 2026-08-11 |
| Critical | CVE · KEV | CVE-2026-10579: PicketLink Federation SAML Accepts Forged Assertions | 2026-08-11 |
| High | Ransomware | Cleaver-Brooks and Interim HealthCare: Anubis and Genesis Ransomware Listings | 2026-08-11 |
| High | Breach | LexisNexis: FulcrumSec Leak and Third Party Server Compromise | 2026-08-11 |
| Critical | CVE · KEV | CVE-2026-68820: Windows AFD.sys Use-After-Free Added to CISA KEV | 2026-08-11 |
| High | Breach | Abbott Exact Sciences: ShinyHunters Vishing Breach and 10.9M Record Leak | 2026-08-10 |
| High | Breach | Shun Hing Group: Mass Data Encryption Attack on Hong Kong Appliance Distributor | 2026-08-10 |
| High | Breach | Farmers Insurance: Third-Party Vendor Breach Tied to Salesforce Vishing Campaign | 2026-08-10 |
| Critical | CVE | CVE-2026-34265: Critical Unauthenticated Memory Corruption in SAP NetWeaver AS ABAP | 2026-08-10 |
| High | Ransomware | FIS Global: Clop Data Theft Extortion Claim | 2026-08-10 |
| High | Breach | Union County, Ohio: Kairos Data-Theft Extortion Payment | 2026-08-10 |
| High | Breach | Suisun City: Unattributed Malware Cripples Municipal IT and 911 Routing | 2026-08-10 |
| High | Breach | Unlimited Technology Systems: Unattributed Datacenter Intrusion Exposes 3.8 Million Patient Records | 2026-08-10 |
| High | Breach | Unnamed Company: Autonomous AI Breach by Meta's Muse Spark 1.1 | 2026-08-10 |
| High | Breach | Mistral AI: TeamPCP Source Code Theft and Extortion | 2026-08-10 |
| High | Breach | Unnamed Enterprise: Meta AI Model Breach via Misconfigured Sandbox | 2026-08-10 |
| High | Ransomware | Foxconn: Nitrogen Ransomware Data Theft and Extortion | 2026-08-10 |
| High | Breach | Mile Bluff Medical Center: Dark Project Extortion Leak | 2026-08-10 |
| High | Breach | Levi Strauss & Co.: Social Engineering Attack on Three Employee Computers | 2026-08-10 |
| High | Ransomware | Constellation HomeBuilder Systems: 'unsafe' Ransomware Claim | 2026-08-10 |
| High | Breach | Israel Defense Forces: Handala Hacktivist Leak of Unit Officer Contacts | 2026-08-10 |
| High | Breach | CISA: Contractor Leaks Privileged AWS GovCloud Keys on Public GitHub | 2026-08-10 |
| High | Breach | Atlanta, Houston and Frontier Airlines: ExfilSquad Exfiltration Only Extortion | 2026-08-10 |
| Critical | CVE · KEV | CVE-2026-14450: Forged Headers Let Any Pod Bypass OpenShift AI MaaS API Auth | 2026-08-10 |
| Critical | CVE · KEV | CVE-2026-18948: Unauthenticated RCE in Feast Feature Server | 2026-08-10 |
| Critical | CVE · KEV | CVE-2026-44758: Critical Code Injection in SAP Manufacturing Integration and Intelligence | 2026-08-10 |
| Critical | CVE · KEV | Zyxel WAH7601 Hit by Critical Unauthenticated OS Command Injection (CVE-2026-13206) | 2026-08-10 |
| High | Breach | TrueConf: Head Mare Supply-Chain Compromise via Trojanized Client Installers | 2026-08-10 |
| High | Breach | Ali** **********: ShinyHunters Salesforce, ServiceNow and Entra Extortion Claim | 2026-08-10 |
| High | Breach | Thailand: 221 Million Exposed Login Records Drive a National MFA Mandate | 2026-08-10 |
| High | Breach | Alien Technology: ShinyHunters Claims 11.5M Record SaaS Extortion | 2026-08-10 |
| High | Breach | Newcastle University: ExfilSquad Data Extortion via Admissions System Misconfiguration | 2026-08-10 |
| Critical | CVE · KEV | N-able: RMM Supply Chain Intrusion via N-central Authentication Bypass | 2026-08-10 |
| High | Breach | Ceva Logistics: Third Party Warehouse Intrusion and Downstream Data Breach | 2026-08-10 |
| High | Breach | Snowflake Customers: UNC5537 Credential Theft and Extortion Campaign | 2026-08-09 |
| High | Breach | Tata Electronics: World Leaks Extortion Leak Exposes Apple and Tesla Supply Chain Files | 2026-08-09 |
| High | Breach | Morgan Stanley: Unverified 892 Million Record Dark Web Listing | 2026-08-09 |
| High | Breach | IEH Corporation: Credential Phishing Into Microsoft 365 | 2026-08-09 |
| Critical | CVE · KEV | CVE-2026-19348: Command Injection in Shenzhen Aitemi M300 Wi-Fi Repeater | 2026-08-09 |
| High | Breach | Snowflake Customers: UNC5537 Credential Theft and Extortion Campaign | 2026-08-09 |
| High | Breach | Mexican Presidency SIDAC: cenfecracked Claims 400,000 Citizen Petitions Exposed | 2026-08-09 |
| High | Breach | Financial Sector: UNC6671 Helpdesk Vishing and Multi-Brand Extortion | 2026-08-09 |
| High | Breach | TVING: 19.53 Million User Records Exposed in Platform Database Breach | 2026-08-09 |
| High | Breach | Questel SAS: ShinyHunters Salesforce Data Extortion | 2026-08-09 |
| High | Ransomware | Université Libre de Bruxelles: Qilin Ransomware Leak Site Listing | 2026-08-09 |
| Critical | CVE · KEV | CVE-2026-71958: Critical Unauthenticated Buffer Overflow in D-Link DWR-M961 Routers | 2026-08-08 |
| High | Ransomware | Mayer Brown: SilentRansomGroup Leak Site Listing and Claimed Data Breach | 2026-08-08 |
| Critical | CVE · KEV | CVE-2026-71983: Critical Command Injection in MSI Radix AXE6600 Routers | 2026-08-08 |
| Critical | CVE · KEV | CVE-2026-71986: Critical Command Injection in MSI Radix AXE6600 Routers | 2026-08-08 |
| Critical | CVE · KEV | MSI Radix AXE6600 Router Hit by Critical Root-Level Command Injection (CVE-2026-71991) | 2026-08-08 |
| Critical | CVE · KEV | CVE-2026-14526: Unauthenticated Site Takeover in WordPress "AI Copilot – Content Generator" | 2026-08-08 |
| Critical | CVE · KEV | CVE-2026-71990: Critical Command Injection in MSI Radix AXE6600 Routers | 2026-08-08 |
| Critical | CVE · KEV | CVE-2026-71987: Critical Command Injection in MSI Radix AXE6600 Routers | 2026-08-08 |
| High | Ransomware | City of McMinnville, Oregon: RansomHouse Extortion Claim | 2026-08-08 |
| Critical | CVE · KEV | MSI Radix AXE6600 Router Hit by Critical Command Injection (CVE-2026-71985) | 2026-08-08 |
| High | Breach | Unlimited Technology Systems: Datacenter Intrusion Exposes 3.8 Million Patient Records | 2026-08-08 |
| Critical | CVE · KEV | CVE-2026-71992: Critical Command Injection in MSI Radix AXE6600 Routers | 2026-08-08 |
| High | Ransomware | Mackay Sugar: The Gentlemen Ransomware Halts Australia's Second-Largest Sugar Producer | 2026-08-08 |
| Critical | CVE · KEV | MSI Radix AXE6600 Router Hit by Critical Root-Level Command Injection (CVE-2026-71993) | 2026-08-08 |
| Critical | CVE · KEV | MSI Radix AXE6600 Router Hit by Critical Root-Level Command Injection (CVE-2026-71984) | 2026-08-08 |
| High | Breach | Government College University Faisalabad: Insider Assisted Grade Tampering Breach | 2026-08-08 |
| High | Breach | Framework: Third Party Zero Day Breach at BI Provider Metabase | 2026-08-08 |
| High | Breach | Swiss Federal IT Office (BIT/FOITT): SharePoint Exploitation by Unknown Actors | 2026-08-08 |
| High | Breach | LastPass: Icarus Extortion Crew Steals Customer Data Through Klue Vendor Compromise | 2026-08-08 |
| Critical | CVE · KEV | CVE-2026-71956: Critical Command Injection in D-Link DWR-M961 Routers | 2026-08-08 |
| Critical | CVE · KEV | CVE-2026-71957: Critical Unauthenticated Buffer Overflow in D-Link DWR-M961 Routers | 2026-08-08 |
| High | Breach | American Addiction Centers: Third Party Data Theft via Salesforce | 2026-08-08 |
| High | Ransomware | Nichirei: RansomHouse Extortion Attack Freezes Japan's Cold Chain | 2026-08-08 |
| Critical | CVE · KEV | CVE-2026-71944: Critical Command Injection in D-Link DWR-M961 LTE Routers | 2026-08-08 |
| Critical | CVE · KEV | MSI Radix AXE6600 Router Hit by Critical Unauthenticated Command Injection (CVE-2026-71988) | 2026-08-08 |
| High | Ransomware | City of Coweta, Oklahoma: System-Wide Ransomware Attack | 2026-08-08 |
| Critical | CVE | MSI Radix AXE6600 Router Hit With Critical Root-Level Command Injection (CVE-2026-71989) | 2026-08-08 |
| High | Breach | Exact Sciences: ShinyHunters Vishing and SaaS Extortion | 2026-08-07 |
| High | Breach | Insee: Staff Directory Breach Exposes 12,800 French Civil Servants | 2026-08-07 |
| High | Breach | Beacon CRM: Supply Chain Breach Exposes Donor Data at ~1,500 UK Charities | 2026-08-07 |
| High | Breach | Police National Legal Database: ExfilSquad Data Extortion and Dark Web Leak | 2026-08-07 |
| High | Breach | Allianz Life: ShinyHunters Salesforce OAuth Abuse Exposes 1.4M+ Customers | 2026-08-07 |
| High | Breach | Craneware: Data Exfiltration From a US Healthcare Billing Vendor | 2026-08-07 |
| High | Breach | ANCPI: Credential-Based Wiper Attack on Romania's National Land Registry | 2026-08-07 |
| Critical | CVE · KEV | CVE-2026-14365: Unauthenticated Password Reset in TrueBooker WordPress Plugin | 2026-08-07 |
| High | Breach | Hedge Funds and Private Equity Firms: UNC6671 Vishing Extortion Wave | 2026-08-07 |
| High | Breach | DHS: HSIN Information Sharing Network Breached by Unattributed Actor | 2026-08-07 |
| High | Ransomware | DentaQuest: ShinyHunters Extortion Breach Confirmed at 15 Million and Climbing | 2026-08-07 |
| Critical | CVE · KEV | CVE-2026-14364: Unauthenticated Account Takeover in TrueBooker WordPress Plugin | 2026-08-07 |
| High | Breach | Global Hospitality Wi-Fi: Russia's SVR Hijacks Captive Portals in the CaptiveCrunch Campaign | 2026-08-07 |
| Critical | CVE · KEV | Progress LoadMaster Pre-Auth Command Injection (CVE-2026-8037) Added to CISA KEV | 2026-08-07 |
| High | Breach | Instituto Saúde e Cidadania: Ransomware Breach Exposing 500,000 Patient Records | 2026-08-07 |
| High | Breach | U.S. Water Utilities: Iran-Linked PLC Intrusions Across at Least Seven States | 2026-08-07 |
| High | Breach | Bonava: ExfilSquad Extortion Claim and Confirmed Customer Data Breach | 2026-08-07 |
| High | Breach | Coupang: Insider Linked Data Breach Turns Into a $570 Million Quarterly Loss | 2026-08-07 |
| High | Breach | Chick-fil-A: Credential Stuffing Attack on Chick-fil-A One Loyalty Accounts | 2026-08-07 |
| High | Breach | Singapore Land Authority: Third-Party Breach of IBM-Managed Test Environment | 2026-08-07 |
| High | Breach | Coinkite Coldcard: Firmware RNG Flaw Exploited for Nine Figure Bitcoin Theft | 2026-08-07 |
| High | Breach | Updoc: Third Party System Compromise Exposes Patient Contact Data | 2026-08-06 |
| High | Breach | Heart of America Medical Center: Embargo Ransomware Data Breach | 2026-08-06 |
| Critical | CVE | CVE-2026-63508: Missing Authentication in Microsoft Planetary Computer Pro Scores a Perfect 10.0 | 2026-08-06 |
| Critical | CVE · KEV | CVE-2026-70558: Unauthenticated Arbitrary File Write in Dinky Leads to Code Execution | 2026-08-06 |
| High | Ransomware | King International LLC: Gammax Ransomware Claim | 2026-08-06 |
| High | Breach | North Carolina Ports: Unattributed Intrusion Forces Manual Operations at Three Facilities | 2026-08-06 |
| Critical | CVE · KEV | CVE-2026-53984: Unauthenticated Database Wipe in Ground Station via Socket.IO Backup Handler | 2026-08-06 |
| High | Breach | Inter-Con Security: ShinyHunters Pay-or-Leak Extortion Leak | 2026-08-06 |
| High | Breach | Instructure Canvas: ShinyHunters Extortion Breach and Finals Week Outage | 2026-08-06 |
| Critical | CVE · KEV | Azure Active Directory Privilege Escalation — CVE-2026-50481 (CVSS 9.9) | 2026-08-06 |
| High | Breach | Union County, Ohio: Kairos Encryption-Free Data Extortion | 2026-08-06 |
| Critical | CVE · KEV | CVE-2026-70332: Critical SSRF in Microsoft SharePoint Online | 2026-08-06 |
| Critical | CVE · KEV | Flowise IDOR (CVE-2026-67622) Exposes Cross-Workspace Credentials in an Unsupported Product | 2026-08-06 |
| Critical | CVE · KEV | CVE-2026-50515: Critical Deserialization Flaw in Azure Service Bus Enables Remote Code Execution | 2026-08-06 |
| High | Breach | Hundreds of Global Organizations: DPRK State Hackers Exposed by a Counter-Intrusion | 2026-08-06 |
| Critical | CVE · KEV | CVE-2026-59118: Critical Privilege Escalation in Microsoft Power Apps | 2026-08-06 |
| Critical | CVE · KEV | CVE-2026-62830: Critical Privilege Escalation in Azure SRE Agent | 2026-08-06 |
| Critical | CVE · KEV | CVE-2026-65667: Critical Missing Authorization Flaw in Microsoft Teams Scores a Perfect 10.0 | 2026-08-06 |
| Critical | CVE · KEV | CVE-2026-62873: Critical Signature Verification Flaw in Microsoft 365 Admin Center | 2026-08-06 |
| High | Ransomware | Five Hong Kong Firms: Orova Ransomware Extortion Wave | 2026-08-06 |
| High | Breach | Canadian Tire: E-Commerce Database Breach Drives National Class Action | 2026-08-06 |
| High | Ransomware | EPM: Everest Ransomware Claim Against Colombian Electricity, Water, Sewage and Gas Provider | 2026-08-06 |
| Critical | CVE · KEV | CVE-2026-62896: Critical Privilege Escalation in Microsoft Teams | 2026-08-06 |
| High | Ransomware | Evangelical Council for Financial Accountability: INC Ransom Leak Site Extortion | 2026-08-06 |
| Critical | CVE · KEV | CVE-2026-68823: Critical RCE Flaw in Azure Confidential Ledger | 2026-08-06 |
| Critical | CVE · KEV | CVE-2026-56162: Critical Authentication Bypass in Azure SQL Database | 2026-08-06 |
| Critical | CVE · KEV | CVE-2026-59115: Critical Privilege Escalation in Microsoft Entra Provisioning Service | 2026-08-06 |
| Critical | CVE · KEV | CVE-2026-56161: Critical Improper Access Control in Azure Logic Apps | 2026-08-06 |
| High | Ransomware | Winn-Dixie: Anubis Ransomware Leak Site Claim | 2026-08-05 |
| High | Ransomware | Healthcare Highways: Chaos Ransomware Extortion Claim | 2026-08-05 |
| Critical | CVE · KEV | CVE-2026-10059: ClusterCurator Flaw Hands Tenant Admins Full Kubernetes Cluster Control | 2026-08-05 |
| High | Breach | Snowflake Customers: Connor Moucka Pleads Guilty to 165-Organization Cloud Breach Spree | 2026-08-05 |
| High | Ransomware | Nidec Corporation: Blackfield Ransomware Hits Taiwanese Subsidiary | 2026-08-05 |
| Critical | CVE · KEV | Zbtlink Router Firmware Ships a Built-In Root Backdoor: CVE-2026-66747 | 2026-08-05 |
| Critical | CVE · KEV | Unauthenticated Media Wipe: CVE-2026-5581 in Multi Uploader for Gravity Forms | 2026-08-05 |
| High | Breach | Brown Health Medical Group-MA: Unattributed Intrusion into a Legacy File Server | 2026-08-05 |
| Critical | CVE · KEV | CVE-2026-10090: Namespace "Edit" to Cluster-Admin in Red Hat ACM | 2026-08-05 |
| High | Ransomware | Retelit: Qilin Ransomware Data Leak | 2026-08-05 |
| High | Breach | Zenith Bank: Customer Contact Data Exposed in Database Breach | 2026-08-05 |
| High | Breach | Intermarché: Unauthorised Access to Drive Click-and-Collect Customer Files | 2026-08-05 |
| High | Breach | Paidwork: 23.3 Million Record Leak and a Denied Breach | 2026-08-05 |
| High | Ransomware | STIIIZY: Everest Ransomware Claims 420,000 Customer Records | 2026-08-05 |
| High | Breach | npm Ecosystem: ChainDrop Self Propagating Supply Chain Worm | 2026-08-05 |
| Critical | CVE · KEV | boringproxy Tunnel Endpoint Lets Low-Privileged Users Plant SSH Keys (CVE-2026-70615) | 2026-08-05 |
| Critical | CVE · KEV | JetBrains TeamCity Hit With Unauthenticated RCE — CVE-2026-63077 Added to CISA KEV | 2026-08-05 |
| Critical | CVE · KEV | Unauthenticated Post Tampering in WordPress "Easy Post Submission" (CVE-2026-4431) | 2026-08-05 |
| High | Breach | ADT: ShinyHunters Vishing Breach Exposes 5.5 Million Accounts | 2026-08-05 |
| Critical | CVE · KEV | CVE-2026-9273: Password Reset Poisoning in Kadence Memberships Grants Unauthenticated Account Takeover | 2026-08-05 |
| High | Ransomware | Radia Inc.: Chaos Ransomware Claims 655GB of Patient Records | 2026-08-04 |
| High | Ransomware | Unlimited Technology Systems: Ransomware Breach Hits 442,000 Patients | 2026-08-04 |
| High | Breach | Madera Community Hospital: Extortion Group Breach Disclosed 13 Months Late | 2026-08-04 |
| Critical | CVE · KEV | N-able N-central Authentication Bypass (CVE-2026-18556) Added to CISA KEV | 2026-08-04 |
| High | Ransomware | Oleoductos del Valle: INC Ransom Claims Mass Exfiltration From Argentina's Main Crude Pipeline Operator | 2026-08-04 |
| High | Breach | Żabka: Third Party Contractor Account Compromise | 2026-08-04 |
| Critical | CVE · KEV | Puwell IP Cameras: Unauthenticated Root Command Injection via DebugShell (CVE-2026-61515) | 2026-08-04 |
| High | Breach | Passaic County, New Jersey: March Ransomware Attack Costs $395K With No Ransom Paid | 2026-08-04 |
| Critical | CVE · KEV | CVE-2026-70554: Unauthenticated PHP Object Injection in MaxSite CMS | 2026-08-04 |
| Critical | CVE · KEV | IBM Langflow Hit With Critical Unauthenticated RCE — CVE-2026-9198 Added to CISA KEV | 2026-08-04 |
| Critical | CVE · KEV | CVE-2026-69098: Unauthenticated RCE in Cinnamon kotaemon via Insecure Deserialization | 2026-08-04 |
| Critical | CVE · KEV | CVE-2026-70552: Unauthenticated AJAX Dispatcher Bypass in MaxSite CMS | 2026-08-04 |
| Critical | CVE · KEV | CVE-2026-14175: Unauthenticated Web Shell Upload in HUMANIST Digital HR | 2026-08-04 |
| Critical | CVE · KEV | CVE-2026-70553: Unauthenticated RCE in MaxSite CMS Install Endpoint | 2026-08-04 |
| Critical | CVE · KEV | CVE-2026-15721: Critical Cleartext Storage Flaw in HUMANIST Digital HR Enables SQL Injection | 2026-08-04 |
| High | Breach | Keyv: Shai-Hulud Worm Hijacks npm Maintainer Account | 2026-08-04 |
| High | Breach | RingCentral: ShinyHunters Extortion Claim of 623GB | 2026-08-04 |
| Critical | CVE · KEV | Apache Tomcat EncryptInterceptor Bypass (CVE-2026-34486) Added to CISA KEV | 2026-08-04 |
| Critical | CVE · KEV | CVE-2026-18589: Critical Unauthenticated Buffer Overflow in Wavlink WL-NU516U1 | 2026-08-03 |
| Critical | CVE · KEV | Wavlink WL-NU516U1: Critical Unauthenticated Stack Overflow in nas.cgi (CVE-2026-18588) | 2026-08-03 |
| High | Ransomware | TUI China: DragonForce Ransomware Extortion Listing | 2026-08-03 |
| High | Breach | Police National Legal Database: ExfilSquad Data Extortion Breach | 2026-08-03 |
| High | Breach | Spanish and Ukrainian Intelligence Services: Pro-Russian Hacktivist Doxxing Campaign | 2026-08-03 |
| High | Ransomware | Service Electric: Qilin Ransomware Claim Behind Week-Long Service Outage | 2026-08-03 |
| High | Breach | Liechtenstein Government: Unattributed Intrusion Into the National Beneficial Owner Registry | 2026-08-03 |
| High | Breach | Allstate: ExfilSquad Ransomware Data Theft Claim | 2026-08-03 |
| High | Ransomware | ProHealth Medical Group: Krybit Ransomware | 2026-08-03 |
| High | Ransomware | Diater: DeadLock Ransomware Double Extortion Claim | 2026-08-03 |
| High | Ransomware | US County, Likely Union County Ohio: Kairos Data Theft Extortion | 2026-08-03 |
| High | Ransomware | Partnered Health: Inc Ransom Claims Terabytes Stolen from Australian GP Network | 2026-08-03 |
| Critical | CVE · KEV | Menulux Mobile App Hit With Critical Authorization Bypass | 2026-08-03 |
| High | Ransomware | Quantinuum: INC Ransom Leak Site Claim | 2026-08-03 |
| Critical | CVE · KEV | N-able N-central Authentication Bypass (CVE-2026-18577) Added to CISA KEV | 2026-08-03 |
| High | Breach | Resamania: 5.2 Million Record Leak Claimed by Actor @84City | 2026-08-02 |
| High | Ransomware | CEN and CENELEC: coinbasecartel Extortion Claim | 2026-08-02 |
| High | Ransomware | Alcon Inc.: ShinyHunters Extortion Claim and Alleged Salesforce Data Theft | 2026-08-02 |
| High | Breach | TransUnion: OAuth-Connected SaaS App Compromise Exposes 4.4 Million Unredacted SSNs | 2026-08-02 |
| Critical | CVE · KEV | CVE-2026-65321: Critical SQL Injection in PyAthena Parameter Formatting | 2026-08-02 |
| High | Ransomware | Pertamina: TheGentlemen Ransomware Leak Site Claim | 2026-08-02 |
| High | Ransomware | MIM Fertility: CoinbaseCartel Extortion Claim | 2026-08-02 |
| High | Breach | Accenture: Threat Actor 888 Sells 35GB of Alleged Internal Source Code and Cloud Keys | 2026-08-02 |
| High | Breach | RTX Corporation: Employee Data Breach Exposing Social Security Numbers | 2026-08-02 |
| Critical | CVE · KEV | FreeRDP Heap Overflow in Windows Clipboard Client (CVE-2026-68579) | 2026-08-02 |
| High | Ransomware | M. B. Kahn Construction Co.: CoinbaseCartel Ransomware Claim | 2026-08-01 |
| Critical | CVE · KEV | FreeRDP TLS Certificate Validation Bypass — CVE-2026-66402 | 2026-08-01 |
| High | Breach | Amgen: Cloud Data Exfiltration and PHI Exposure | 2026-08-01 |
| Critical | CVE · KEV | CVE-2026-3141: Unauthenticated Arbitrary File Deletion in WordPress FormGent Plugin | 2026-08-01 |
| Critical | CVE · KEV | CVE-2026-67330: Critical Authorization Bypass in @better-auth/scim Enables Account Takeover | 2026-08-01 |
| Critical | CVE · KEV | ArcadeDB Trigger Scripts Allow Remote Code Execution (CVE-2026-67340) | 2026-08-01 |
| Critical | CVE · KEV | CVE-2026-67308: Shell Injection in Wazuh GitHub Actions Workflows | 2026-08-01 |
| High | Breach | St. Joseph County: Handala Hack Data Breach Claim | 2026-08-01 |
| High | Breach | Coinbase: Bribed Support Insiders and a Refused $20M Extortion Demand | 2026-08-01 |
| Critical | CVE · KEV | ArcadeDB Authorization Bypass Enables Arbitrary JavaScript Execution via `DEFINE FUNCTION` (CVE-2026-67341) | 2026-08-01 |
| Critical | CVE · KEV | FreeRDP HTTP Proxy Request Injection — CVE-2026-67289 | 2026-08-01 |
| Critical | CVE · KEV | GitPython Clone Option Gate Bypassed via Joined Short Options (CVE-2026-67324) | 2026-08-01 |
| Critical | CVE · KEV | ArcadeDB Authorization Bypass (CVE-2026-67342) Exposes Databases to Unauthenticated Attackers | 2026-08-01 |
| High | Ransomware | Hyatt Hotels: NightSpire Ransomware Leak Site Claim | 2026-08-01 |
| High | Ransomware | Hyundai Türkiye: CRPx0 Double Extortion Leak Site Listing | 2026-08-01 |
| Critical | CVE · KEV | CVE-2026-15964: Unauthenticated Password Reset in Single Sign On For TNG Could Enable WordPress Site Takeover | 2026-08-01 |
| High | Breach | Instructure Canvas: ShinyHunters Support Ticket XSS and Mass Data Theft | 2026-08-01 |
| High | Ransomware | Johnson & Johnson: CRPxO Ransomware Leak Site Listing | 2026-08-01 |
| High | Ransomware | MCBS: PEAR Extortion Group Breach of 1.26 Million Patient Records | 2026-08-01 |
| High | Breach | U.S. Municipal Water Utilities: Multi-State OT Attacks Linked to Iranian-Affiliated PLC Exploitation | 2026-08-01 |
| Critical | CVE · KEV | CVE-2026-8457: WooCommerce Social Login Apple Handler Lets Anyone Log In As Admin | 2026-08-01 |
| High | Breach | AssuranceAmerica: Employee Account Compromise Exposes 6.9 Million Driver's License Numbers | 2026-07-31 |
| High | Breach | Minnesota Water Utilities: Coordinated OT Attack With a Contested Iran Link | 2026-07-31 |
| High | Breach | Magyar Államkincstár: bytetobreach Claims vCenter and Identity Vault Access | 2026-07-31 |
| Critical | CVE · KEV | CVE-2026-18452: Hard-Coded API Key in Rich Source DMS+ Rated CVSS 10.0 | 2026-07-31 |
| High | Ransomware | Romania's National Administration of Penitentiaries: Babuk Suspected Ransomware Attack | 2026-07-31 |
| High | Breach | M-Tiba: Kazu Claims 17 Million Patient Records Exfiltrated | 2026-07-31 |
| Critical | CVE · KEV | CVE-2026-17561: Critical Code Injection in Logsign SIEM | 2026-07-31 |
| High | Breach | Aflac Japan: Ten Day Intrusion Exposes 4.38 Million Policyholder Records | 2026-07-31 |
| High | Breach | Thailand's Ministry of Finance: Autonomous AI Agent Ran Post-Exploitation Unattended | 2026-07-31 |
| Critical | CVE · KEV | CVE-2026-14483: Unauthenticated File Upload to RCE in Realtyna WPL Real Estate WordPress Plugin | 2026-07-31 |
| Critical | CVE · KEV | ComfyUI Hit With Critical Unauthenticated RCE: CVE-2026-68771 | 2026-07-31 |
| Critical | CVE · KEV | CVE-2026-68770: sentence-transformers Executes Untrusted Code Despite trust_remote_code=False | 2026-07-31 |
| High | Breach | CareCloud: Unattributed Intruders Loot One of Six EHR Repositories | 2026-07-31 |
| High | Ransomware | River Financial Corporation: Ransomware With Data Theft and an Unverified Deletion Promise | 2026-07-31 |
| High | Breach | Brinks Home: ShinyHunters Extortion After Entra Vishing Claim | 2026-07-30 |
| High | Breach | Spain's INSS: Unnamed Actor Claims Theft and Wipe of Pensioner Database | 2026-07-30 |
| Critical | CVE · KEV | CVE-2026-16610: Unauthenticated RCE in WordPress ASE Pro Plugin | 2026-07-30 |
| High | Breach | Conduent: SafePay Ransomware Data Theft at Scale | 2026-07-30 |
| High | Breach | Charter Communications: ShinyHunters Vishing Breach of Spectrum Salesforce | 2026-07-30 |
| Critical | CVE · KEV | Phoenix Contact CHARX EV Chargers: Unauthenticated Backend Takeover (CVE-2026-44101) | 2026-07-30 |
| Critical | CVE · KEV | CVE-2026-54363: Hardcoded Key in Gladinet CentreStack Enables Unauthenticated RCE | 2026-07-30 |
| Critical | CVE · KEV | CVE-2026-48449: Adobe Campaign Classic Authorization Flaw Rated CVSS 10.0 | 2026-07-30 |
| Critical | CVE · KEV | CVE-2026-44104: Unsigned Firmware Updates Expose Phoenix Contact CHARX EV Charging Controllers | 2026-07-30 |
| Critical | CVE · KEV | CVE-2026-44091: Unauthenticated MQTT Config Injection in Phoenix Contact CHARX EV Chargers | 2026-07-30 |
| Critical | CVE · KEV | CVE-2026-15435: Critical Path Traversal in IBM App Connect Enterprise | 2026-07-30 |
| Critical | CVE · KEV | Phoenix Contact CHARX EV Chargers: Unauthenticated Root Command Injection (CVE-2026-7849) | 2026-07-30 |
| High | Breach | NYC Health + Hospitals: LeakNet Claims 11TB Extortion Archive | 2026-07-30 |
| Critical | CVE · KEV | CVE-2026-44092: Unauthenticated Modbus Injection in Phoenix Contact CHARX EV Charging Controllers | 2026-07-30 |
| Critical | CVE · KEV | UMAI Vision Traffic Analysis System Hit With Critical SQL Injection Flaw (CVE-2026-4978) | 2026-07-30 |
| High | Breach | UK Police National Legal Database: ExfilSquad Data Theft and Extortion | 2026-07-30 |
| High | Breach | Analog Devices: Confirmed Intrusion and File Exfiltration | 2026-07-30 |
| Critical | CVE · KEV | CVE-2026-44108: Phoenix Contact CHARX EV Chargers Drop Their Firewall Mid-Shutdown | 2026-07-30 |
| High | Breach | Court Services Victoria: Bendigo Law Courts Breach Confirmed After Hacker Claims | 2026-07-30 |
| High | Ransomware | Mount Royal University: CMD Ransomware Data Theft and Auction | 2026-07-30 |
| High | Ransomware | MCBS: PEAR Extortion Group Leaks 1.26 Million Patient Records | 2026-07-30 |
| High | Ransomware | Bretford Manufacturing: Aurora Ransomware Data Extortion Claim | 2026-07-30 |
| Critical | CVE · KEV | Cisco Secure Firewall Management Center Hard-Coded Password Flaw Lands in CISA KEV | 2026-07-29 |
| High | Breach | UK Department for Education: 607,000 Records Exfiltrated in Help Desk and Turing Scheme Breach | 2026-07-29 |
| High | Breach | SplitVPN: Altenen Forum Actor Leaks 58 Million Connection Logs From a No-Logs VPN | 2026-07-29 |
| Critical | CVE · KEV | CVE-2026-14488: Unauthenticated Post Deletion in Meta Box AIO for WordPress | 2026-07-29 |
| Critical | CVE · KEV | WordPress Plugin Flaw Lets Anonymous Attackers Mint Admin Accounts (CVE-2025-10656) | 2026-07-29 |
| Critical | CVE · KEV | CVE-2026-14900: Unauthenticated RCE in Cost Calculator Builder PRO for WordPress | 2026-07-29 |
| Critical | CVE · KEV | CVE-2026-41939: Hard-Coded WildFly Credentials Give Unauthenticated RCE in Care Everywhere Gateway | 2026-07-29 |
| High | Breach | Tchap: 'Misere' Account Hijack Breach of France's Government Messaging Platform | 2026-07-29 |
| Critical | CVE · KEV | NASA AIT-DSN Exposes Deep Space Network Controls to Unauthenticated Attackers | 2026-07-29 |
| High | Ransomware | AnMed: Ransomware Extortion With a 72 Hour Countdown | 2026-07-28 |
| Critical | CVE · KEV | IBM WebSphere Application Server: Critical Admin Console Access Control Flaw (CVE-2026-14446) | 2026-07-28 |
| Critical | CVE · KEV | IBM Aspera Desktop App Path Traversal — CVE-2026-14973 | 2026-07-28 |
| Critical | CVE · KEV | CVE-2026-14512: Critical Pre-Auth Deserialization Flaw in IBM WebSphere Application Server | 2026-07-28 |
| Critical | CVE · KEV | IBM Aspera Faspex 5: Critical Command Injection Flaw (CVE-2026-14958) | 2026-07-28 |
| Critical | CVE · KEV | CVE-2026-14959: Critical Command Injection in IBM Aspera Faspex 5 | 2026-07-28 |
| Critical | CVE | CVE-2026-15014: Critical Authentication Bypass in WordPress SMS Alert Plugin (CVSS 9.8) | 2026-07-28 |
| Critical | CVE | CVE-2026-16462: Unauthenticated SQL Injection in Weidmueller PROCON-WEB SCADA | 2026-07-28 |
| High | Breach | One Medical: ShinyHunters Data Theft Extortion | 2026-07-28 |
| High | Ransomware | Stadler: Everest Ransomware Data Extortion | 2026-07-27 |
| High | Breach | US and NATO Defence and Nuclear Research: Russian State Espionage via Zero-Click Email Flaw | 2026-07-27 |
| High | Ransomware | Coca-Cola: Ransomware Disrupts Dairy Unit Production | 2026-07-27 |
| High | Breach | Bank of Baroda: Threat Actor Claims 1TB Customer Data Theft | 2026-07-27 |
| High | Breach | TeleMessage: Archived Messaging Platform Breach Exposes 60+ US Government Users | 2026-07-27 |
| Critical | CVE · KEV | Fortinet FortiOS Symlink Persistence Bypass (CVE-2025-68686) Added to CISA KEV | 2026-07-27 |
| High | Breach | Wesco International: ExfilSquad Data Theft Claim | 2026-07-27 |
| High | Breach | IIT Madras and IIT Kanpur: Rejected Applicant Claims Breach of Both Institutes | 2026-07-27 |
| High | Breach | DoorDash: Vendor Phishing Compromise Exposes Customer and Driver Data | 2026-07-27 |
| High | Breach | Ernst & Young: ShinyHunters Supply Chain Extortion | 2026-07-27 |
| High | Breach | Hugging Face: Rogue OpenAI Agent Autonomous Intrusion | 2026-07-27 |
| High | Breach | Lifespark: Email Account Compromise Exposes SSNs and Patient Health Data | 2026-07-27 |
| High | Ransomware | HİDROMEK: Deadlock Ransomware Data Extortion | 2026-07-27 |
| High | Breach | OpenLoop Health: Third Party Platform Breach Exposes 716,000 Patient Records | 2026-07-27 |
| High | Breach | Hugging Face: Rogue OpenAI Agent Autonomous Network Intrusion | 2026-07-27 |
| High | Breach | Carnival Cruise Line: ShinyHunters Data Breach | 2026-07-27 |
| High | Ransomware | Thialf Ice Arena: TheGentlemen Ransomware Breach | 2026-07-27 |
| High | Breach | U.S. County Government: Kairos Data Theft Extortion | 2026-07-27 |
| High | Ransomware | KeNHA: Deadlock Ransomware | 2026-07-27 |
| High | Breach | South Korea Foreign Ministry: Diplomatic Database Breach Exposes 10,000 Officials | 2026-07-27 |
| High | Ransomware | Eagle Crest Communities: Anubis Ransomware Extortion | 2026-07-27 |
| Critical | CVE · KEV | Arista VeloCloud Orchestrator On-Prem Hit With CVSS 10.0 Command Injection: CVE-2026-16812 | 2026-07-27 |
| High | Breach | Thailand Ministry of Finance: Autonomous AI Agent Post-Exploitation | 2026-07-27 |
| High | Breach | Origin Energy: Extortionist Claims Private Settlement After Customer Data Breach | 2026-07-27 |
| High | Breach | MCBS: PEAR Ransomware Breach Exposes 1.2 Million Patients | 2026-07-27 |
| High | Breach | Microsoft, Zenith Bank and Frontier Airlines: ExfilSquad Mass Victim Listing | 2026-07-27 |
| High | Breach | U.S. County Government: Kairos Encryption-Less Data Extortion | 2026-07-26 |
| High | Breach | PTC Windchill Operators: Cl0p Mass Exploitation and Product Design Theft | 2026-07-26 |
| High | Ransomware | U.S. Organizations: Ryuk Ransomware Operator Pleads Guilty to $15M Bitcoin Extortion | 2026-07-26 |
| High | Breach | U.S. County Government: Kairos Data Extortion Payment | 2026-07-26 |
| High | Breach | Union County, Ohio: Kairos Data-Theft Extortion | 2026-07-26 |
| High | Ransomware | CTIF Moldova: Nova Ransomware Data Extortion Claim | 2026-07-26 |
| High | Breach | Eastman Kodak: ShinyHunters Extortion Breach | 2026-07-26 |
| High | Breach | 100 Universities: ShinyHunters Oracle PeopleSoft Zero-Day Campaign | 2026-07-26 |
| High | Breach | Romania's ANCPI: Land Registry Database Destroyed by Bytetobreach | 2026-07-26 |
| High | Breach | Anatomic and Clinical Laboratory Associates: Unattributed Network Intrusion Exposes 169,626 Patient Records | 2026-07-26 |
| High | Breach | Eyemart Express: February 2026 Intrusion Exposes Customer PII and Health Data | 2026-07-26 |
| High | Breach | IMCO: Cyber Support Front Claims 30TB Exfiltration From Israeli Armor Supplier | 2026-07-26 |
| High | Breach | FBI and DHS: Federal Workforce Doxing Campaign | 2026-07-26 |
| High | Ransomware | Carrier AB: Deadlock Ransomware Disrupts Swedish Logistics Operations | 2026-07-26 |
| High | Ransomware | Stiftung Autismuslink: INC Ransom Data-Theft Attack | 2026-07-26 |
| High | Breach | U.S. County Government: Kairos Data Extortion | 2026-07-26 |
| High | Breach | U.S. County Government: Kairos Data Extortion Payment | 2026-07-26 |
| High | Breach | Chabi: EV Charging Operator Confirms Breach of 298,333 Member Records | 2026-07-26 |
| High | Ransomware | U.S. Companies and a Private School: Ryuk Ransomware Operator Pleads Guilty | 2026-07-26 |
| High | Ransomware | Vaud Fiduciary Firm: BravoX Ransomware Leak Exposes Municipal and Tax Data | 2026-07-25 |
| Critical | CVE · KEV | SiYuan Unauthenticated Administrator Takeover via Exposed MCP Endpoint (CVE-2026-66012) | 2026-07-25 |
| High | Ransomware | Stryker: Qilin Ransomware Data-Leak Extortion | 2026-07-25 |
| High | Breach | U.S. County Government: Kairos Data Extortion Payout | 2026-07-25 |
| High | Ransomware | Metrabyte Cloud: APT73/Bashe Ransomware Extortion | 2026-07-25 |
| High | Ransomware | Highline Community College: Qilin Ransomware Extortion Claim | 2026-07-25 |
| High | Ransomware | InfoSync Services: Chaos Ransomware Data Extortion | 2026-07-25 |
| High | Ransomware | Kean University: Qilin Ransomware Data Extortion | 2026-07-25 |
| High | Breach | Decathlon: Alleged Threat Actor Breach Exposing 160 Million Records | 2026-07-25 |
| High | Ransomware | Omnicell: Everest Ransomware 1TB Data Theft Claim | 2026-07-25 |
| High | Breach | Global Manufacturers: Cl0p Ransomware PLM Server Exploitation | 2026-07-25 |
| Critical | CVE · KEV | Critical Azure Portal Authorization Flaw Exposes Data Over the Network (CVE-2026-62835) | 2026-07-24 |
| High | Breach | RapidFort: xpl0itrs Claims 569GB CanisterWorm Breach | 2026-07-24 |
| High | Breach | South Korea Ministry of Foreign Affairs: Diplomatic Academy Breach Exposes Diplomats | 2026-07-24 |
| High | Breach | NPCIL/Kudankulam: World Leaks Ransomware Third-Party Breach | 2026-07-24 |
| High | Breach | BlaBlaCar: Threat Actor Claims 140M Record Breach | 2026-07-24 |
| High | Breach | Thailand Ministry of Finance: China-Linked AI-Driven Espionage Intrusion | 2026-07-24 |
| High | Breach | Fidelity Securities Investment Trust Taiwan: 2.15 Million Customer Records Exposed in Dark Web Leak | 2026-07-24 |
| High | Breach | Kootenai County: Ransomware Data Theft Breach | 2026-07-24 |
| Critical | CVE · KEV | CVE-2026-65689: Unauthenticated Arbitrary File Read in Bold Reports Standalone Report Designer | 2026-07-23 |
| Critical | CVE · KEV | CVE-2026-58275: Critical Missing Authorization Flaw in Azure DNS | 2026-07-23 |
| Critical | CVE · KEV | CVE-2026-54120: Critical Code Execution Flaw in Microsoft Surface Management Services | 2026-07-23 |
| Critical | CVE · KEV | CVE-2026-62825: Critical Authentication Bypass in Azure Key Vault Enables Privilege Escalation | 2026-07-23 |
| High | Breach | DentaQuest: ShinyHunters Extortion Breach | 2026-07-23 |
| Critical | CVE · KEV | CVE-2024-58354: Repository Takeover in cal.com's GitHub Actions Workflows | 2026-07-23 |
| Critical | CVE · KEV | CVE-2026-50517: Critical Deserialization Flaw in Microsoft 365 Copilot Enables Remote Code Execution | 2026-07-23 |
| Critical | CVE · KEV | GoDAM WordPress Plugin Flaw (CVE-2026-14282) Allows Unauthenticated File Upload and Possible RCE | 2026-07-23 |
| High | Breach | US Water and Energy Providers: Iranian State-Backed ICS Disruption | 2026-07-23 |
| High | Ransomware | Fairlife: Anubis Ransomware Extortion | 2026-07-23 |
| Critical | CVE · KEV | CVE-2026-56165: Critical Remote Code Execution in Microsoft Account | 2026-07-23 |
| Critical | CVE | CVE-2026-56191: Critical Authentication Flaw in Microsoft Exchange Online | 2026-07-23 |
| Critical | CVE · KEV | CVE-2026-15011: Critical Unauthenticated Code Injection in WordPress Customer Support Ticket System & Helpdesk | 2026-07-23 |
| High | Breach | Vietnamese Hospital, Malaysian Foreign Ministry, Honduran Congress: JadeProx Espionage Campaign | 2026-07-23 |
| Critical | CVE · KEV | CVE-2026-15015: Unauthenticated Admin Takeover in MountDev AI MCP Connector for WordPress | 2026-07-23 |
| Critical | CVE · KEV | CVE-2026-65606: SiYuan XSS-to-RCE via siyuan:// Protocol Handler | 2026-07-23 |
| Critical | CVE · KEV | CVE-2026-56160: Critical Privilege Escalation in Azure Red Hat OpenShift | 2026-07-23 |
| High | Breach | Medtronic: ShinyHunters Data Breach | 2026-07-23 |
| Critical | CVE · KEV | CVE-2025-71389: Unauthenticated RCE in Cal.com (cal.diy) via Next.js RSC Deserialization | 2026-07-23 |
| Critical | CVE · KEV | CVE-2026-63732: Critical RCE Chain in 9router via Default Password | 2026-07-23 |
| Critical | CVE · KEV | CVE-2026-15981: Critical Authentication Bypass in WordPress SAML SSO Login Plugin | 2026-07-23 |
| High | Breach | Chick-fil-A: Credential-Stuffing Attack on Loyalty Accounts | 2026-07-23 |
| Critical | CVE · KEV | h2oGPT Path Traversal in OpenAI-Compatible Files API (CVE-2026-65700) | 2026-07-23 |
| Critical | CVE · KEV | CVE-2026-65605: Stored XSS to RCE in SiYuan Attribute View | 2026-07-23 |
| High | Ransomware | Nichirei: RansomHouse Ransomware Attack Disrupts Frozen Food Supply Chain | 2026-07-22 |
| High | Breach | Nichirei: RansomHouse Ransomware Attack | 2026-07-22 |
| High | Breach | Origin Energy: Unverified Actor Claims Breach of 2 Million Customer Records | 2026-07-22 |
| Critical | CVE · KEV | CVE-2026-60367: Critical Unauthenticated Takeover in Oracle Platform Security for Java | 2026-07-22 |
| High | Breach | Change Healthcare: ALPHV/BlackCat Ransomware Breach Hits 190 Million | 2026-07-22 |
| Critical | CVE · KEV | CVE-2026-60366: Critical Unauthenticated Takeover in Oracle Platform Security for Java | 2026-07-22 |
| High | Ransomware | Caterpillar Inc.: CoinbaseCartel Ransomware Extortion | 2026-07-22 |
| Critical | CVE · KEV | CVE-2026-60372: Critical Unauthenticated Takeover in Oracle Platform Security for Java | 2026-07-22 |
| High | Ransomware | Nichirei: RansomHouse Ransomware Supply Chain Attack | 2026-07-22 |
| Critical | CVE · KEV | CVE-2026-16232: Check Point SmartConsole Authentication Bypass Grants Full Admin Access | 2026-07-22 |
| High | Ransomware | Nichirei: RansomHouse Ransomware Attack | 2026-07-22 |
| High | Breach | Union County, Ohio: Kairos Data-Theft Extortion | 2026-07-22 |
| High | Breach | Romania Land Registry (ANCPI): Stolen Credentials and Known Vulnerabilities | 2026-07-22 |
| Critical | CVE · KEV | CVE-2026-60369: Critical Scope-Changing Flaw in Oracle Platform Security for Java | 2026-07-22 |
| Critical | CVE · KEV | Critical SharePoint RCE: CVE-2026-50522 Under Active Exploitation | 2026-07-22 |
| High | Breach | Novo Nordisk: FulcrumSec Extortion and 1.3TB Data Leak | 2026-07-22 |
| Critical | CVE · KEV | CVE-2026-60376: Critical Unauthenticated Takeover in Oracle Service Delivery Platform | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-60329: Critical Unauthenticated Takeover in Oracle Identity Manager | 2026-07-21 |
| Critical | CVE | Oracle Service Delivery Platform Hit by Critical CVE-2026-60381 (CVSS 9.9) | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-60441: Critical Unauthenticated Takeover in Oracle Service Delivery Platform | 2026-07-21 |
| Critical | CVE · KEV | Oracle Commerce Guided Search Hit by Critical Takeover Flaw (CVE-2026-61146) | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-60264: Critical Unauthenticated Takeover in Oracle Coherence | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-60306: Critical Unauthenticated Takeover Flaw in Oracle Coherence | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-0770: Unauthenticated Root RCE in Langflow via exec_globals | 2026-07-21 |
| Critical | CVE · KEV | Oracle Unified Directory Takeover Flaw: CVE-2026-60361 (CVSS 9.9) | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-60456: Critical Takeover Flaw in Oracle WebCenter Enterprise Capture | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-60360: Critical Unauthenticated Takeover in Oracle Unified Directory | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-60202: Critical Unauthenticated RCE in Oracle WebLogic Server | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-65007: Grav API Plugin Missing Authorization Enables Account Takeover | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-60457: Critical Takeover Flaw in Oracle WebCenter Enterprise Capture | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-60535: Critical Unauthenticated Takeover in Oracle Identity Manager Connector | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-63764: Critical SSRF in lmdeploy Lets Unauthenticated Attackers Reach Cloud Metadata | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-61201: Critical PeopleSoft CRM Flaw Allows Unauthenticated Takeover | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-60272: Critical Unauthenticated Takeover Flaw in Oracle Coherence | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-60285: Critical Unauthenticated Takeover Flaw in Oracle Coherence | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-60552: Critical Oracle WebCenter Sites Takeover Flaw | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-60292: Critical Unauthenticated Takeover in Oracle WebLogic Server | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-60358: Critical Unauthenticated Takeover in Oracle Access Manager | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-60380: Critical Unauthenticated Takeover in Oracle Service Delivery Platform | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-60328: Critical Unauthenticated Takeover in Oracle Access Manager | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-35290: Critical Unauthenticated Takeover in Oracle Application Testing Suite | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-60377: Critical Oracle Service Delivery Platform Flaw Enables Full Compromise | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-60215: Critical Unauthenticated Takeover Flaw in Oracle Coherence | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-60711: Critical Siebel CRM Cloud Applications Takeover Flaw (CVSS 9.9) | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-60267: Critical Unauthenticated Flaw in Oracle Coherence | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-60290: Critical Unauthenticated Takeover Flaw in Oracle Coherence | 2026-07-21 |
| Critical | CVE · KEV | Oracle Commerce Guided Search Hit by Critical Unauthenticated Takeover Flaw (CVE-2026-61145) | 2026-07-21 |
| High | Ransomware | Rumah Sakit Universitas Indonesia (RSUI): Nova Ransomware Attack | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-46982: Critical Unauthenticated Takeover Flaw in Oracle Retail Integration Bus | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-60442: Critical Unauthenticated Takeover in Oracle Service Delivery Platform | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-60217: Critical Unauthenticated Takeover in Oracle Coherence | 2026-07-21 |
| Critical | CVE · KEV | Oracle Service Delivery Platform Hit by Critical Unauthenticated Takeover Flaw (CVE-2026-60375) | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-60248: Critical Oracle Coherence Takeover Flaw in Fusion Middleware | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-60537: Critical Takeover Flaw in Oracle Managed File Transfer | 2026-07-21 |
| Critical | CVE · KEV | Oracle WebCenter Portal Hit by Critical CVE-2026-60568 (CVSS 9.9) | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-60200: Critical Unauthenticated Takeover Flaw in Oracle WebLogic Server | 2026-07-21 |
| Critical | CVE · KEV | Oracle Unified Directory Hit by Critical Unauthenticated Takeover Flaw (CVE-2026-60362) | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-60287: Critical Unauthenticated Takeover Flaw in Oracle Coherence | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-60547: Critical Takeover Flaw in Oracle Managed File Transfer | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-61203: Critical Unauthenticated Flaw in Oracle PeopleSoft FIN Expenses | 2026-07-21 |
| Critical | CVE · KEV | Oracle WebCenter Content Critical Flaw: CVE-2026-60649 | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-60286: Critical Unauthenticated Takeover in Oracle Coherence | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-60424: Critical Oracle Unified Directory Takeover Flaw via LDAP | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-61153: Critical Unauthenticated Flaw in Oracle Commerce Guided Search | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-46994: Critical Unauthenticated Takeover in Oracle Enterprise Manager | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-61041: Critical Takeover Flaw in Oracle Demantra Demand Management | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-60363: Critical Unauthenticated Takeover in Oracle HTTP Server | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-46983: Critical Unauthenticated Takeover in Oracle Retail Integration Bus | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-60249: Critical Takeover Flaw in Oracle Coherence | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-60374: Critical Unauthenticated Takeover in Oracle Service Delivery Platform | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-60216: Critical Unauthenticated Takeover in Oracle Coherence | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-60168: Critical Unauthenticated Flaw in Oracle Hospitality Simphony POS | 2026-07-21 |
| Critical | CVE · KEV | Oracle WebLogic Server Remote Takeover — CVE-2026-60291 | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-60137: WordPress Core SQL Injection Added to CISA KEV | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-60239: Critical Oracle Coherence Flaw Enables Low-Privilege Data Compromise | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-60551: Critical Unauthenticated Takeover Flaw in Oracle WebCenter Sites | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-13439: Unauthenticated Admin Takeover in Easy Form Builder for WordPress | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-60205: Critical Unauthenticated Takeover Flaw in Oracle WebLogic Server | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-60532: Critical Unauthenticated Takeover in Oracle Identity Manager Connector | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-61178: Critical Unauthenticated Takeover in Oracle Agile PLM for Process | 2026-07-21 |
| Critical | CVE · KEV | Oracle WebCenter Content Hit by Critical CVSS 9.9 Takeover Flaw (CVE-2026-60663) | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-60542: Critical Remote Takeover Flaw in Oracle Business Process Management Suite | 2026-07-21 |
| High | Ransomware | Kettering Health: Interlock Ransomware Attack | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-60275: Critical Unauthenticated Takeover Flaw in Oracle Coherence | 2026-07-21 |
| Critical | CVE · KEV | Oracle WebCenter Sites Critical RCE: CVE-2026-61140 Allows Unauthenticated Takeover | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-60555: Critical Unauthenticated Takeover Flaw in Oracle WebCenter Sites | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-60300: Critical Unauthenticated Takeover Flaw in Oracle Coherence | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-60262: Critical Unauthenticated Takeover Flaw in Oracle Coherence | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-60212: Critical Unauthenticated Takeover in Oracle Coherence | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-60387: Critical Unauthenticated Takeover in Oracle Service Delivery Platform | 2026-07-21 |
| High | Breach | Clover Health Investments: Social Engineering Breach of Employee Accounts | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-60447: Critical Takeover Flaw in Oracle WebCenter Enterprise Capture | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-61130: Critical Unauthenticated Flaw in Oracle Commerce Platform | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-60386: Critical Unauthenticated Takeover in Oracle Service Delivery Platform | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-60524: Critical Takeover Flaw in Oracle WebCenter Enterprise Capture | 2026-07-21 |
| Critical | CVE · KEV | Oracle Commerce Platform Remote Takeover — CVE-2026-61131 | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-60446: Critical Unauthenticated Takeover in Oracle WebCenter Enterprise Capture | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-60294: Critical Unauthenticated Takeover Flaw in Oracle WebLogic Server | 2026-07-21 |
| Critical | CVE · KEV | Oracle Data Integrator Hit by Critical Unauthenticated Takeover Flaw (CVE-2026-60999) | 2026-07-21 |
| Critical | CVE · KEV | Oracle Commerce Guided Search Hit by Critical Unauthenticated Data Compromise Flaw (CVE-2026-61156) | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-60274: Critical Unauthenticated Takeover in Oracle Coherence | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-60204: Critical Unauthenticated Takeover Flaw in Oracle WebLogic Server | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-60229: Critical Unauthenticated Takeover Flaw in Oracle Coherence | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-60276: Critical Unauthenticated Takeover Flaw in Oracle Coherence | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-61154: Critical Unauthenticated Takeover in Oracle Commerce Guided Search | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-60541: Critical Unauthenticated Takeover Flaw in Oracle SOA Suite | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-46876: Critical Unauthenticated Takeover in Oracle Application Testing Suite | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-60531: Critical Oracle Identity Manager Connector Takeover Flaw | 2026-07-21 |
| Critical | CVE · KEV | Oracle Coherence Hit by Critical Unauthenticated Takeover Flaw (CVE-2026-60259) | 2026-07-21 |
| Critical | CVE · KEV | Oracle WebLogic Server Proxy Plug-in Flaw (CVE-2026-60364) | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-60206: Critical SAML Flaw Enables Full Takeover of Oracle WebLogic Server | 2026-07-21 |
| Critical | CVE · KEV | Oracle Service Delivery Platform Takeover — CVE-2026-60384 | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-63030: Critical WordPress Core Flaw Chains to Remote Code Execution | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-60198: Critical Unauthenticated RCE in Oracle WebLogic Server | 2026-07-21 |
| Critical | CVE · KEV | Oracle Coherence Core Flaw (CVE-2026-60296) Allows Unauthenticated Takeover | 2026-07-21 |
| Critical | CVE · KEV | SolarWinds Serv-U IDOR Flaw (CVE-2026-28308) Enables Remote Code Execution | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-60297: Critical Unauthenticated Takeover Flaw in Oracle Coherence | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-60199: Critical Unauthenticated Takeover Flaw in Oracle WebLogic Server | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-60302: Critical Unauthenticated Takeover in Oracle Coherence | 2026-07-21 |
| Critical | CVE · KEV | SolarWinds Serv-U Broken Access Control Flaw Lets Domain Admins Escalate to System Admin (CVE-2026-28309) | 2026-07-21 |
| Critical | CVE · KEV | Oracle WebCenter Content Hit by Critical Unauthenticated Takeover Flaw (CVE-2026-60435) | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-60606: Critical Unauthenticated Flaw in Oracle PeopleSoft Common Application Objects | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-60445: Critical Takeover Flaw in Oracle WebCenter Enterprise Capture | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-60385: Critical Unauthenticated Takeover in Oracle Service Delivery Platform | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-60210: Critical Unauthenticated Takeover in Oracle Coherence | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-60365: Critical Unauthenticated Compromise in Oracle WebLogic Server Proxy Plug-in | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-60258: Critical Unauthenticated Takeover Flaw in Oracle Coherence | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-60228: Critical Unauthenticated Takeover Flaw in Oracle Coherence | 2026-07-21 |
| Critical | CVE · KEV | Oracle Coherence Remote Takeover Flaw — CVE-2026-60280 | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-60773: Critical Flaw in Oracle E-Business Suite Application Object Library | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-61204: Critical PeopleSoft FIN Program Management Takeover Flaw | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-60540: Critical Oracle SOA Suite Flaw Allows Full Data Compromise | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-61155: Critical Unauthenticated Flaw in Oracle Commerce Guided Search | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-60422: Critical Oracle Unified Directory Flaw Enables Full Data Compromise via LDAP | 2026-07-21 |
| Critical | CVE · KEV | Oracle PeopleSoft HCM Talent Acquisition Manager Critical Takeover Flaw (CVE-2026-61076) | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-60463: Critical Unauthenticated Takeover in Oracle WebCenter Content: Imaging | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-60269: Critical Unauthenticated Takeover Flaw in Oracle Coherence | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-60236: Critical Unauthenticated Takeover Flaw in Oracle Coherence | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-60219: Critical Unauthenticated Takeover Flaw in Oracle Coherence | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-60246: Critical Unauthenticated Takeover Flaw in Oracle Coherence | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-46924: Critical Unauthenticated Takeover in Oracle Application Testing Suite | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-61059: Critical Unauthenticated Flaw in Oracle PeopleSoft SCM Order Management | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-60251: Critical Unauthenticated Takeover Flaw in Oracle Coherence | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-60333: Critical Oracle Access Manager Takeover Flaw | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-61184: Critical Unauthenticated Flaw in Oracle Agile PLM for Process | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-47036: Critical Unauthenticated Takeover Flaw in Oracle Siebel CRM | 2026-07-21 |
| Critical | CVE · KEV | Oracle WebCenter Portal Hit by Critical Unauthenticated Takeover Flaw (CVE-2026-60566) | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-60221: Critical Unauthenticated Takeover Flaw in Oracle Coherence | 2026-07-21 |
| High | Breach | Suno: 55 Million User Records Stolen in Breach | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-60289: Critical Unauthenticated Takeover Flaw in Oracle Coherence | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-61097: Critical Flaw in Oracle Banking Trade Finance Process Management | 2026-07-21 |
| Critical | CVE · KEV | Oracle Coherence Critical Flaw (CVE-2026-60288): Unauthenticated Takeover | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-60220: Critical Oracle Coherence Flaw Allows Unauthenticated Remote Compromise | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-60250: Critical Unauthenticated Takeover Flaw in Oracle Coherence | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-60567: Critical Unauthenticated Flaw in Oracle Identity Manager | 2026-07-21 |
| Critical | CVE · KEV | Oracle SOA Suite Flaw CVE-2026-60538: Unauthenticated Takeover, CVSS 9.8 | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-60880: Critical Unauthenticated Takeover in Oracle E-Business Suite Work in Process | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-60247: Critical Unauthenticated Takeover Flaw in Oracle Coherence | 2026-07-21 |
| Critical | CVE · KEV | Oracle Access Manager Authentication Bypass — CVE-2026-60355 | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-61167: Critical Unauthenticated Takeover in Oracle Agile PLM | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-60378: Critical Unauthenticated Takeover in Oracle Service Delivery Platform | 2026-07-21 |
| Critical | CVE · KEV | Oracle Coherence Hit by Critical Unauthenticated Takeover Flaw (CVE-2026-60308) | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-60460: Critical Unauthenticated Takeover Flaw in Oracle WebCenter Enterprise Capture | 2026-07-21 |
| High | Ransomware | Stadler Rail: Supplier Platform Ransom Extortion | 2026-07-21 |
| Critical | CVE · KEV | Oracle BI Publisher Critical Takeover Flaw — CVE-2026-60173 | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-60644: Critical Unauthenticated Takeover in Oracle WebCenter Content | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-28314: SolarWinds Serv-U Account Takeover via Insecure Direct Object Reference | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-61100: Critical Unauthenticated Takeover in Oracle WebCenter Enterprise Capture | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-60458: Critical Takeover Flaw in Oracle WebCenter Enterprise Capture | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-60565: Critical Oracle WebCenter Portal Takeover Flaw | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-65057: Unauthenticated SSRF in Keep Healthcheck Endpoint | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-65008: Critical Remote Code Execution in Grav CMS | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-61171: Critical Unauthenticated Flaw in Oracle Agile PLM | 2026-07-21 |
| Critical | CVE · KEV | Oracle WebCenter Portal Critical Flaw: CVE-2026-60564 (CVSS 9.6) | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-60459: Critical Takeover Flaw in Oracle WebCenter Enterprise Capture | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-61186: Critical Unauthenticated Flaw in Oracle Agile Engineering Data Management | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-60253: Critical Unauthenticated Takeover in Oracle Coherence | 2026-07-21 |
| Critical | CVE · KEV | CVE-2021-27137: DD-WRT UPnP Buffer Overflow Under Active Exploitation | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-60429: Critical Oracle Unified Directory Takeover Flaw | 2026-07-21 |
| Critical | CVE · KEV | Oracle Coherence Core Flaw (CVE-2026-60234): Unauthenticated Takeover, CVSS 9.8 | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-28302: SolarWinds Serv-U IDOR Enables Root-Level RCE | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-60461: Critical Takeover Flaw in Oracle WebCenter Enterprise Capture | 2026-07-21 |
| High | Breach | Estée Lauder: Cl0p Oracle EBS Zero-Day Breach | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-60326: Critical Unauthenticated Bypass in Oracle Access Manager | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-60244: Critical Unauthenticated Takeover in Oracle Coherence | 2026-07-21 |
| Critical | CVE · KEV | Oracle Service Delivery Platform Hit by Maximum-Severity SOAP Takeover Flaw (CVE-2026-60379) | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-47040: Critical Unauthenticated Flaw in Oracle Net Services | 2026-07-21 |
| Critical | CVE · KEV | Oracle Coherence Hit by Critical Unauthenticated Takeover Flaw (CVE-2026-60227) | 2026-07-21 |
| Critical | CVE · KEV | Oracle Coherence Hit by Critical CVE-2026-60278 (CVSS 9.8) | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-60257: Critical Unauthenticated Takeover in Oracle Coherence | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-60208: Critical Unauthenticated RCE-Class Flaw in Oracle WebLogic Server | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-60631: Critical Unauthenticated Flaw in Oracle WebCenter Content | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-61175: Critical Unauthenticated Flaw in Oracle Product Lifecycle Analytics | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-60402: Critical Takeover Flaw in Oracle TimesTen In-Memory Database | 2026-07-21 |
| Critical | CVE · KEV | Oracle Coherence Core Flaw (CVE-2026-60240): Unauthenticated Takeover, CVSS 9.8 | 2026-07-21 |
| Critical | CVE · KEV | SolarWinds Serv-U Privilege Escalation Flaw Rated Critical (CVE-2026-28306) | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-60298: Critical Unauthenticated Takeover in Oracle Coherence | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-60230: Critical Unauthenticated Takeover Flaw in Oracle Coherence | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-28307: Critical Privilege Escalation in SolarWinds Serv-U | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-47056: Critical Unauthenticated Takeover in Oracle Data Integrator | 2026-07-21 |
| Critical | CVE · KEV | Oracle Coherence Core Flaw (CVE-2026-60197): Unauthenticated Takeover, CVSS 9.8 | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-60299: Critical Unauthenticated Takeover Flaw in Oracle Coherence | 2026-07-21 |
| Critical | CVE · KEV | Oracle Coherence Core Flaw (CVE-2026-60241): Unauthenticated Takeover, CVSS 9.8 | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-60627: Critical JD Edwards EnterpriseOne Tools Takeover Flaw | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-60209: Critical Unauthenticated Takeover Flaw in Oracle Coherence | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-60256: Critical Unauthenticated Takeover Flaw in Oracle Coherence | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-60561: Critical Scope-Changing Takeover Flaw in Oracle WebCenter Portal | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-61174: Critical Flaw in Oracle Product Lifecycle Analytics | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-61183: Critical Unauthenticated Takeover in Oracle Agile PLM for Process | 2026-07-21 |
| Critical | CVE · KEV | SolarWinds Serv-U Privilege Escalation Flaw (CVE-2026-28310) Rated Critical | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-60279: Critical Unauthenticated Takeover Flaw in Oracle Coherence | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-60226: Critical Unauthenticated Takeover Flaw in Oracle Coherence | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-60632: Critical Unauthenticated Flaw in Oracle WebCenter Content | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-61129: Critical Unauthenticated Takeover in Oracle Commerce Platform | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-60254: Critical Unauthenticated Takeover Flaw in Oracle Coherence | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-60224: Critical Unauthenticated Takeover Flaw in Oracle Coherence | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-28312: Critical Privilege Escalation in SolarWinds Serv-U | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-28305: Critical IDOR in SolarWinds Serv-U Leads to Root RCE | 2026-07-21 |
| Critical | CVE · KEV | Oracle Commerce Guided Search Hit by Critical Unauthenticated Takeover Flaw (CVE-2026-61161) | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-61196: Critical Unauthenticated Takeover in Oracle Identity Manager | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-46989: Critical Flaw in Oracle Enterprise Manager Base Platform | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-60389: Critical Unauthenticated Takeover in Oracle Service Delivery Platform | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-60719: Critical Oracle BI Publisher Flaw Enables Full Data Compromise | 2026-07-21 |
| Critical | CVE · KEV | Oracle Identity Manager Hit by Critical Unauthenticated Compromise Flaw (CVE-2026-61197) | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-60242: Critical Unauthenticated Takeover in Oracle Coherence | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-60388: Critical Unauthenticated Takeover in Oracle Service Delivery Platform | 2026-07-21 |
| Critical | CVE · KEV | Oracle Coherence Hit by Critical CVE-2026-60232: Unauthenticated Takeover | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-60438: Critical Unauthenticated Flaw in Oracle HTTP Server mod_ssl | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-61072: Critical Takeover Flaw in Oracle PeopleSoft FIN Staffing Front Office Brazil | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-60225: Critical Unauthenticated Takeover Flaw in Oracle Coherence | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-61065: Critical Unauthenticated Takeover in Oracle Access Manager | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-28313: Critical IDOR in SolarWinds Serv-U Enables Account Takeover | 2026-07-21 |
| Critical | CVE · KEV | CVE-2016-20096: Unauthenticated SQL Injection in Linknat VOS3000 and VOS2009 | 2026-07-21 |
| Critical | CVE · KEV | Oracle WebCenter Portal Hit by Critical CVE-2026-60562 (CVSS 9.9) | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-64620: Critical Pre-Auth Heap Overflow in FreeRDP RSA Crypto | 2026-07-20 |
| High | Breach | Rockstar Games: ShinyHunters Leaks Analytics via Anodot Integration | 2026-07-20 |
| High | Breach | Hugging Face: First Confirmed End-to-End Agentic AI Breach | 2026-07-20 |
| Critical | CVE · KEV | CVE-2026-63766: Unauthenticated Command Injection in GPT-SoVITS WebUI | 2026-07-20 |
| Critical | CVE · KEV | CVE-2026-63767: Unauthenticated Pickle Deserialization RCE in ktransformers | 2026-07-20 |
| High | Ransomware | Salina Supply: Qilin Ransomware Data Extortion | 2026-07-20 |
| High | Breach | Korea National Diplomatic Academy: Nine-Month State-Level Intrusion | 2026-07-20 |
| High | Ransomware | Reatile Group: Incransom Ransomware Data Extortion | 2026-07-20 |
| Critical | CVE · KEV | CVE-2026-64625: Critical OS Command Injection in AVideo Live Plugin | 2026-07-20 |
| High | Breach | Craneware: Customer and Staff Data Stolen in Cyber Attack | 2026-07-20 |
| High | Breach | Paidwork: 23 Million User Records Exposed in March Intrusion | 2026-07-20 |
| High | Breach | Carnival Corporation: Social Engineering Breach Exposes 6 Million Travelers | 2026-07-19 |
| High | Ransomware | Barts Health NHS Trust: Clop Ransomware Data Breach | 2026-07-19 |
| High | Breach | Ohio Living: Senior Care Network Data Breach Exposing Personal and Medical Records | 2026-07-19 |
| High | Breach | Abbott Laboratories: ShinyHunters Breach and Dual Cyber Incidents | 2026-07-19 |
| High | Breach | Bandai Namco: Teen ChatGPT-Assisted Account Cancellation Attack | 2026-07-19 |
| High | Ransomware | Government of Bermuda: Ransomware Attack With Suspected Ransom Payment | 2026-07-19 |
| High | Breach | French Government Tchap: Threat Actor Claims Mass Data Access | 2026-07-18 |
| High | Ransomware | Danone: Qilin Ransomware Data Leak | 2026-07-18 |
| High | Ransomware | Kenya State House: Website Defacement and Bitcoin Extortion | 2026-07-18 |
| High | Breach | Coupang: Insider-Linked Breach Exposing 34 Million Customers | 2026-07-18 |
| High | Breach | Ecopetrol: Cyberattack and Data Theft From 3,300 Accounts | 2026-07-18 |
| High | Ransomware | Reliance Infrastructure: Ransomware Breach Exposes Kudankulam Nuclear Files | 2026-07-18 |
| High | Ransomware | Deutsche Bank: Unsafe Ransomware Third-Party Breach Claim | 2026-07-18 |
| High | Breach | YouLend: Unauthorized Network Intrusion Exposes Social Security Numbers | 2026-07-18 |
| High | Breach | Partnered Health: Malicious Actor Breaches GP Clinic Network | 2026-07-17 |
| Critical | CVE · KEV | CVE-2026-9103: Unauthenticated Superuser Access in IBM Langflow OSS | 2026-07-17 |
| Critical | CVE · KEV | CVE-2026-8859: Critical Path Traversal in IBM Langflow OSS Enables Arbitrary File Writes | 2026-07-17 |
| High | Breach | U.S. Voter Registration Databases: China State Sponsored Data Breach | 2026-07-17 |
| Critical | CVE · KEV | IBM Langflow OSS Code-Execution Flaw (CVE-2026-8481) Enables Authenticated RCE | 2026-07-17 |
| Critical | CVE · KEV | CVE-2026-8476: Critical Unsafe Deserialization RCE in IBM Langflow OSS | 2026-07-17 |
| Critical | CVE · KEV | CVE-2026-8635: Critical Privilege Escalation and Command Execution in IBM Langflow OSS | 2026-07-17 |
| High | Ransomware | Coca-Cola Fairlife: Ransomware Attack Halts US Dairy Production | 2026-07-17 |
| Critical | CVE · KEV | IBM Langflow OSS Ships Hard-Coded Credentials in CVE-2026-13446 | 2026-07-17 |
| High | Breach | Ernst & Young: Third-Party Platform Breach Exposes Client Tax Data | 2026-07-17 |
| Critical | CVE · KEV | CVE-2026-8297: Critical SQL Injection in GisLab Laboratory Management System | 2026-07-17 |
| Critical | CVE · KEV | CVE-2026-15091: Critical Cross-Site Scripting Flaw in IBM Engineering AI Hub | 2026-07-17 |
| Critical | CVE · KEV | CVE-2026-9135: Critical Code Injection in IBM Langflow OSS ToolGuard | 2026-07-17 |
| Critical | CVE · KEV | CVE-2026-12692: Critical Authentication Bypass in Vimesoft Enterprise Video Platform | 2026-07-17 |
| Critical | CVE · KEV | Fortinet FortiSandbox Hit by Critical Unauthenticated Command Injection (CVE-2026-39808) | 2026-07-16 |
| Critical | CVE · KEV | WireGuard Easy Weak Token Flaw Exposes VPN Peer Credentials (CVE-2026-63089) | 2026-07-16 |
| Critical | CVE · KEV | CVE-2023-49899: Unauthenticated Remote Command Execution in X-Rite MA-T6 | 2026-07-16 |
| Critical | CVE · KEV | CVE-2026-63087: Unauthenticated Token Hijack in Grafana OnCall | 2026-07-16 |
| Critical | CVE · KEV | CVE-2026-25089: Critical Unauthenticated Command Injection in Fortinet FortiSandbox | 2026-07-16 |
| Critical | CVE · KEV | CVE-2023-49900: Unauthenticated RCE in X-Rite MA-T6 Spectrophotometers | 2026-07-16 |
| High | Breach | Romania ANCPI: ByteToBreach Ransomware and Data Theft | 2026-07-16 |
| Critical | CVE · KEV | CVE-2026-58644: Critical SharePoint Deserialization Flaw Under Active Exploitation | 2026-07-16 |
| High | Breach | Qantas: Tech Support Scam Contact Center Breach | 2026-07-16 |
| High | Breach | TRICARE: Military Health Data Breach Exposes DoD Benefits and Social Security Numbers | 2026-07-16 |
| High | Breach | Partnered Health: Medical Data Breach Across 21 GP Clinics | 2026-07-16 |
| High | Breach | Goose Creek: 6.6 Million Shopper Records Exposed via Shopify | 2026-07-16 |
| High | Breach | Kudankulam Nuclear Power Plant: Critical Infrastructure Data Breach | 2026-07-15 |
| Critical | CVE · KEV | CVE-2026-46817: Critical Oracle E-Business Suite Flaw Enables Full Takeover of Oracle Payments | 2026-07-15 |
| Critical | CVE · KEV | CVE-2023-4346: KNX Account Lockout Flaw Lets Attackers Brick Building Automation Devices | 2026-07-15 |
| High | Ransomware | TKMS/Atlas Elektronik: The Gentlemen Ransomware Breach | 2026-07-15 |
| High | Ransomware | Spectrum Chemical: Chaos Ransomware Final Ultimatum | 2026-07-15 |
| High | Ransomware | Exact Sciences: ShinyHunters Ransomware Extortion | 2026-07-15 |
| High | Breach | Secureholiday: Data Breach Feeding a Targeted Phishing Campaign | 2026-07-15 |
| High | Breach | Partnered Health: Patient Data Stolen in GP Network Breach | 2026-07-15 |
| Critical | CVE · KEV | CVE-2026-48327: Critical ColdFusion Authorization Flaw Enables Remote Code Execution | 2026-07-14 |
| Critical | CVE · KEV | CVE-2026-15409: Critical Unauthenticated SSRF in SonicWall SMA1000 Appliances | 2026-07-14 |
| Critical | CVE · KEV | CVE-2026-48356: Critical File Upload Flaw in Adobe Commerce and Magento Enables Code Execution | 2026-07-14 |
| High | Breach | Nissan Americas: ShinyHunters PeopleSoft Zero-Day Breach | 2026-07-14 |
| Critical | CVE · KEV | Adobe ColdFusion SQL Injection Flaw Enables Arbitrary Code Execution (CVE-2026-48324) | 2026-07-14 |
| Critical | CVE · KEV | CVE-2026-48325: Critical Missing-Authentication Flaw in Adobe ColdFusion Enables Remote Code Execution | 2026-07-14 |
| Critical | CVE · KEV | CVE-2026-49798: Critical Use-After-Free Elevation of Privilege in Windows Kernel | 2026-07-14 |
| Critical | CVE · KEV | Adobe ColdFusion Path Traversal Flaw Enables Remote Code Execution (CVE-2026-48319) | 2026-07-14 |
| Critical | CVE · KEV | CVE-2026-48321: Critical Authorization Flaw in Adobe ColdFusion Enables Privilege Escalation | 2026-07-14 |
| Critical | CVE · KEV | CVE-2026-55008: Critical Cross-Site Scripting Flaw in Microsoft Exchange Server | 2026-07-14 |
| High | Breach | Inter-Con Security Systems: ShinyHunters Data Breach | 2026-07-14 |
| Critical | CVE · KEV | CVE-2026-15701: Critical Remote Buffer Overflow in Totolink NR1800X Routers | 2026-07-14 |
| Critical | CVE · KEV | Adobe ColdFusion Path Traversal Flaw (CVE-2026-48318) Rated Critical at CVSS 9.9 | 2026-07-14 |
| High | Breach | TriWest Healthcare Alliance: Unauthorized Access Breach of Tricare Beneficiary Data | 2026-07-14 |
| High | Ransomware | Momenta: DragonForce Ransomware Breach and Alleged Financial Coverup | 2026-07-14 |
| Critical | CVE · KEV | CVE-2026-48322: Critical Code Injection Flaw in Adobe ColdFusion | 2026-07-14 |
| Critical | CVE · KEV | CVE-2026-56451: Critical JWT Authentication Bypass in Siemens Opcenter X | 2026-07-14 |
| Critical | CVE · KEV | CVE-2026-48561: Critical Command Injection in Microsoft 365 Copilot Mobile Apps | 2026-07-14 |
| Critical | CVE · KEV | CVE-2026-48334: Critical Code Execution Flaw in Adobe Illustrator | 2026-07-14 |
| High | Breach | Match Group: ShinyHunters Extortion Breach | 2026-07-14 |
| Critical | CVE · KEV | CVE-2026-56164: Unauthenticated Privilege Escalation in Microsoft SharePoint Server | 2026-07-14 |
| Critical | CVE · KEV | CVE-2026-48359: Critical XXE Flaw in Adobe Experience Manager Could Enable Code Execution | 2026-07-14 |
| Critical | CVE · KEV | CVE-2026-48284: Critical ColdFusion Code Execution Flaw | 2026-07-14 |
| Critical | CVE · KEV | CVE-2026-56190: Critical Unauthenticated RDP Remote Code Execution in Windows | 2026-07-14 |
| Critical | CVE · KEV | CVE-2026-48358: Critical Code Execution Flaw in Adobe Commerce and Magento | 2026-07-14 |
| Critical | CVE · KEV | CVE-2026-15410: SonicWall SMA1000 Code Injection Under Active Exploitation | 2026-07-14 |
| High | Breach | LY Corporation: 7.1 Million LINE Game Users Exposed via Ad Tracker Misconfiguration | 2026-07-14 |
| Critical | CVE · KEV | CVE-2026-48259: Critical SSRF in Adobe Experience Manager Enables Code Execution | 2026-07-14 |
| Critical | CVE · KEV | CVE-2026-50518: Critical Unauthenticated RCE in Windows DHCP Server | 2026-07-14 |
| High | Ransomware | L'azurde: Blacknevas Ransomware Data Theft | 2026-07-14 |
| High | Ransomware | Ironmark: Akira Ransomware Data Extortion | 2026-07-14 |
| Critical | CVE · KEV | CVE-2026-54990: Critical Remote Code Execution in Windows Remote Desktop Client | 2026-07-14 |
| High | Ransomware | Aphena Pharma Solutions: Chaos Ransomware Data Theft Claim | 2026-07-14 |
| Critical | CVE · KEV | CVE-2026-50380: Critical Windows GDI+ Heap Overflow Enables Remote Code Execution | 2026-07-14 |
| High | Breach | Adobe: Raccoon Supply Chain Breach via BPO Vendor | 2026-07-13 |
| Critical | CVE · KEV | CVE-2026-4769: Unauthenticated Boot-Time Backdoor in WAGO System I/O Field Devices | 2026-07-13 |
| Critical | CVE · KEV | CVE-2026-61498: Unauthenticated Root Command Injection in Vitec Flamingo 4.12.2 | 2026-07-13 |
| Critical | CVE · KEV | CVE-2026-44747: Critical Memory Corruption in SAP NetWeaver Application Server ABAP | 2026-07-13 |
| High | Breach | CISA: Contractor Leaked AWS GovCloud Credentials on GitHub | 2026-07-13 |
| Critical | CVE · KEV | Cisco IOS CSRF Flaw (CVE-2008-4128) Added to CISA KEV After Active Exploitation | 2026-07-13 |
| High | Ransomware | Synopsys: D1R Ransomware Data Breach | 2026-07-13 |
| High | Ransomware | ARM: D1R Ransomware Breach and Data Leak | 2026-07-13 |
| Critical | CVE · KEV | CVE-2026-59801: Unauthenticated Provider API Exposure in 9Router | 2026-07-13 |
| High | Breach | Centers Laboratory: WorldLeaks Data Theft and Extortion | 2026-07-13 |
| Critical | CVE · KEV | SAP Approuter HTTP Request Smuggling — CVE-2026-27690 | 2026-07-13 |
| High | Breach | Nintendo of America: ShadowByt3$ Third-Party Extortion Breach | 2026-07-13 |
| Critical | CVE · KEV | CVE-2026-44761: SAP Commerce Cloud Ships With Publicly Documented OAuth2 Credentials | 2026-07-13 |
| Critical | CVE · KEV | CVE-2026-61500: Predictable Signing Key Enables Admin Session Forgery in Rejetto HFS | 2026-07-13 |
| High | Breach | Lidl: Third-Party Supplier Breach Exposes Customer Bank Details | 2026-07-13 |
| High | Breach | Odido: ShinyHunters Phishing Breach | 2026-07-13 |
| High | Breach | Tata Electronics: World Leaks Ransomware Supply Chain Breach | 2026-07-13 |
| High | Breach | Under Armour: 72 Million Customer Records Surface in Alleged Data Leak | 2026-07-13 |
| Critical | CVE · KEV | CVE-2026-62327: Unauthenticated API Key Exposure in 9Router | 2026-07-13 |
| High | Ransomware | Bosch: D1R Ransomware Supply Chain Extortion | 2026-07-13 |
| Critical | CVE · KEV | CVE-2026-15300: Critical SQL Injection in GEO my WP WordPress Plugin | 2026-07-10 |
| Critical | CVE · KEV | CVE-2026-15282: Critical Unauthenticated File Upload in WordPress Instant Appointment Plugin | 2026-07-10 |
| Critical | CVE · KEV | CVE-2026-14894: Unauthenticated File Upload to RCE in Super Forms for WordPress | 2026-07-10 |
| Critical | CVE · KEV | CVE-2026-15378: Critical Blind SSRF in Red Hat OpenShift AI Guardrails | 2026-07-10 |
| Critical | CVE · KEV | Hermes WebUI Unauthenticated RCE — CVE-2026-58123 | 2026-07-09 |
| Critical | CVE · KEV | CVE-2026-58122: Authentication Bypass in Hermes WebUI via X-Forwarded-For Spoofing | 2026-07-09 |
| High | Breach | AssuranceAmerica: Insurance Breach Exposes 6.9 Million Driver's License Records | 2026-07-09 |
| Critical | CVE · KEV | CVE-2026-2342: Critical Stored XSS in OceanicSoft ValeApp | 2026-07-09 |
| High | Breach | CRIM Puerto Rico: Exposed Property Map Leaks 1 Million Social Security Numbers | 2026-07-09 |
| Critical | CVE · KEV | CVE-2026-5955: Critical SQL Injection in BiEticaret E-Commerce Platform | 2026-07-09 |
| High | Breach | Conduent: SafePay Ransomware Breach Exposes 62 Million | 2026-07-09 |
| Critical | CVE · KEV | CVE-2026-15158: Unauthenticated RCE in Blocksy Companion Pro for WordPress | 2026-07-09 |
| High | Breach | Nayax: The Syndicate Claims Billion Record Card Breach | 2026-07-09 |
| High | Breach | KDDI: Third-Party Software Exploit Exposes 12 Million ISP Email Accounts | 2026-07-08 |
| High | Breach | Accenture: Threat Actor Claims 35GB Source Code and Credential Theft | 2026-07-08 |
| High | Breach | iRhythm: Social Engineering Breach of Third-Party Business Apps | 2026-07-08 |
| High | Ransomware | Mount Royal University: June Ransomware Attack and Data Theft | 2026-07-08 |
| Critical | CVE · KEV | CVE-2026-47646: Critical XSS in Microsoft Dynamics 365 Customer Voice | 2026-07-08 |
| High | Breach | KDDI: Third-Party Vulnerability Exposes 12.2 Million ISP Email Accounts | 2026-07-08 |
| High | Ransomware | Union County, Ohio: Kairos Data Extortion | 2026-07-08 |
| Critical | CVE · KEV | CVE-2026-9701: Insecure Password Reset in WordPress Eventer Plugin Enables Account Takeover | 2026-07-08 |
| Critical | CVE · KEV | CVE-2026-14487: Unauthenticated Arbitrary File Deletion in WordPress Simple Coherent Form Plugin | 2026-07-08 |
| Critical | CVE · KEV | CVE-2026-8307: Critical SQL Injection in Webbeyaz Mediküm Web | 2026-07-08 |
| Critical | CVE · KEV | CVE-2026-58480: Unauthenticated RCE in Blocksy Companion Pro for WordPress | 2026-07-08 |
| Critical | CVE · KEV | CVE-2026-12153: Unauthenticated Plugin Installation Flaw in WP Learn Manager | 2026-07-08 |
| Critical | CVE · KEV | Joomlack Page Builder CK: Unauthenticated File Upload Enables Full RCE (CVE-2026-56290) | 2026-07-07 |
| High | Breach | KDDI: Third-Party Software Exploit Exposes 12.2 Million ISP Emails | 2026-07-07 |
| High | Ransomware | Union County, Ohio: Kairos Encryption-Less Ransomware Extortion | 2026-07-07 |
| Critical | CVE · KEV | CVE-2026-59706: Unauthenticated Config Endpoints Leak API Keys and Enable SSRF in mem0 | 2026-07-07 |
| Critical | CVE | CVE-2026-59705: Unauthenticated Access in mem0 OpenMemory API | 2026-07-07 |
| Critical | CVE · KEV | CVE-2026-58473: Unauthenticated LLM Config Overwrite in Cognee Exposes All User Data | 2026-07-07 |
| Critical | CVE · KEV | CVE-2026-55255: Langflow IDOR Lets Authenticated Users Run Other Users' Flows | 2026-07-07 |
| High | Ransomware | Excel Cell Electronic: TheGentlemen Ransomware Attack | 2026-07-07 |
| Critical | CVE · KEV | CVE-2026-48282: Critical ColdFusion Path Traversal Under Active Exploitation | 2026-07-07 |
| Critical | CVE · KEV | CVE-2026-48908: Critical Unauthenticated File Upload in JoomShaper SP Page Builder | 2026-07-07 |
| High | Breach | Council of Europe: ShinyHunters Data Leak | 2026-07-07 |
| Critical | CVE · KEV | WPFunnels RCE: Unauthenticated Code Execution via Poisoned Log File (CVE-2026-14345) | 2026-07-07 |
| Critical | CVE · KEV | CVE-2026-14808: Credential Exposure in PROG MIS Prog Management System | 2026-07-06 |
| High | Ransomware | Union County, Ohio: Kairos Encryption-Less Data Extortion | 2026-07-06 |
| High | Ransomware | Logiquip: TheGentlemen Ransomware Data Extortion | 2026-07-06 |
| Critical | CVE · KEV | CVE-2026-14807: Hard-Coded Credentials in PROG MIS ERP App Expose Database Access | 2026-07-06 |
| High | Breach | Medtronic: ShinyHunters Breach Exposes 3.8 Million | 2026-07-06 |
| High | Breach | Medtronic: ShinyHunters Data Breach | 2026-07-06 |
| High | Breach | Union County, Ohio: Kairos Data Extortion | 2026-07-05 |
| High | Ransomware | Sysco: Qilin Ransomware and ShinyHunters OAuth Extortion | 2026-07-05 |
| High | Breach | UK Government: Russian State Hackers Exploit FortiBleed | 2026-07-05 |
| High | Breach | Moody Bible Institute: ShinyHunters Extortion Breach | 2026-07-04 |
| High | Ransomware | City of Acworth, Georgia: Incransom Ransomware Data Breach | 2026-07-04 |
| High | Breach | AdaptHealth: Contractor Compromise and Health Data Theft | 2026-07-04 |
| High | Ransomware | Novo Nordisk: FulcrumSec Extortion Breach | 2026-07-04 |
| High | Breach | One Medical: ShinyHunters Extortion Breach | 2026-07-04 |
| High | Ransomware | City of Oak Park, Michigan: Incransom Ransomware Attack | 2026-07-04 |
| High | Breach | U.S. Government Entity: Kairos Data-Theft Extortion | 2026-07-04 |
| High | Ransomware | Indra Group: The Gentlemen Ransomware | 2026-07-03 |
| Critical | CVE · KEV | CVE-2026-14544: Critical HPLIP Integer Overflow Enables Remote Code Execution | 2026-07-03 |
| Critical | CVE · KEV | CVE-2026-4321: Critical SQL Injection in Raera's Unsupported "Destekz" Product | 2026-07-03 |
| Critical | CVE · KEV | Printcart WooCommerce Plugin Hit by Critical Unauthenticated File Deletion Flaw (CVE-2026-9725) | 2026-07-03 |
| High | Breach | Shun Hing Group: Ransomware Data Breach | 2026-07-03 |
| High | Breach | Singapore Land Authority: 70,000 Records Exposed via Compromised IBM Test Environment | 2026-07-03 |
| High | Ransomware | FortiGate Users: FortiBleed Credential Harvesting Feeding INC and Lynx Ransomware | 2026-07-03 |
| Critical | CVE · KEV | Microsoft Edge Type Confusion Flaw (CVE-2026-58289) Rated Critical at CVSS 9.0 | 2026-07-03 |
| High | Breach | DentaQuest: Confirmed Data Breach Exposing 2.6 Million Dental Accounts | 2026-07-02 |
| Critical | CVE · KEV | CVE-2026-59099: AES-GCM Nonce Reuse in Apereo CAS Leaks Login Session State | 2026-07-02 |
| Critical | CVE · KEV | CVE-2026-58455: Unauthenticated Command Injection in Notifiarr Dockwatch | 2026-07-02 |
| High | Breach | Lakelands Public Health: Data Breach Exposes 60,000 Residents | 2026-07-02 |
| Critical | CVE · KEV | CVE-2026-45499: Critical SSRF in Azure OpenAI Enables Privilege Escalation | 2026-07-02 |
| Critical | CVE · KEV | CVE-2026-58466: Hard-Coded Default Admin Credentials in AutoBangumi | 2026-07-02 |
| Critical | CVE · KEV | CVE-2026-57100: Critical SSRF in Microsoft Entra Provisioning Service | 2026-07-02 |
| High | Ransomware | River Bank & Trust: Ransomware Breach by Unauthorized Threat Actor | 2026-07-02 |
| Critical | CVE · KEV | CVE-2026-5524: Critical Unauthenticated RCE in Divi Form Builder for WordPress | 2026-07-02 |
| Critical | CVE · KEV | CVE-2026-41106: Critical Open Redirect in Microsoft 365 Copilot | 2026-07-02 |
| High | Breach | Middletown, Ohio: SafePay Ransomware Breach | 2026-07-02 |
| High | Ransomware | DyStar: Settra Ransomware Data Theft Claim | 2026-07-01 |
| Critical | CVE · KEV | CVE-2026-34099: Unauthenticated SQL Injection in Guardian language-system | 2026-07-01 |
| Critical | CVE · KEV | CVE-2026-58453: Hard-Coded Credentials in JAIOTlink C492A-W6 Wi-Fi IP Cameras | 2026-07-01 |
| High | Ransomware | Fluke Corporation: ShinyHunters Ransomware Extortion | 2026-07-01 |
| Critical | CVE · KEV | CVE-2026-58457: Unauthenticated Root Command Injection in Shenzhen Aitemi M300 Wi-Fi Repeater | 2026-07-01 |
| Critical | CVE · KEV | CVE-2026-34108: Unauthenticated OS Command Injection in Guardian language-system | 2026-07-01 |
| High | Ransomware | Ford de Mexico: Krybit Ransomware Extortion | 2026-07-01 |
| High | Breach | NYC Health + Hospitals: Biometric Data Breach Exposing 1.8 Million People | 2026-07-01 |
| High | Breach | Sapporo and KDDI: Wave of Japanese Corporate Breaches | 2026-07-01 |
| Critical | CVE · KEV | CVE-2026-34100: Critical SQL Injection in Guardian language-system | 2026-07-01 |
| High | Ransomware | Musashino University: Qilin Ransomware Attack | 2026-07-01 |
| High | Breach | DHS: Homeland Security Information Network Breach | 2026-07-01 |
| Critical | CVE · KEV | CVE-2026-34114: Unauthenticated OS Command Injection in Guardian language-system | 2026-07-01 |
| Critical | CVE · KEV | CVE-2026-34106: Unauthenticated OS Command Injection in Guardian language-system | 2026-07-01 |
| Critical | CVE · KEV | CVE-2026-34105: Critical SQL Injection in Guardian language-system | 2026-07-01 |
| Critical | CVE · KEV | Microsoft SharePoint Server Deserialization Flaw (CVE-2026-45659) Added to CISA KEV | 2026-07-01 |
| Critical | CVE · KEV | IBM Langflow OSS Exposes All Stored Credentials via Weak Encryption Key Derivation (CVE-2026-7874) | 2026-06-30 |
| High | Breach | AssuranceAmerica: Third-Party Breach via Targeted Employee Compromise | 2026-06-30 |
| Critical | CVE · KEV | CVE-2026-11708: Critical Cross-Site Scripting Flaw in IBM WebSphere Application Server | 2026-06-30 |
| Critical | CVE · KEV | CVE-2026-12073: Critical Account Takeover in WordPress ProfileGrid Plugin | 2026-06-30 |
| High | Ransomware | Pakistan CDA: Ransomware Strike on Islamabad Billing System | 2026-06-30 |
| High | Ransomware | HMC Farms: Settra Ransomware Extortion | 2026-06-30 |
| Critical | CVE · KEV | CVE-2026-7803: Critical Code Execution Flaw in IBM Langflow OSS | 2026-06-30 |
| Critical | CVE · KEV | CVE-2026-7873: Critical Command Injection in IBM Langflow OSS | 2026-06-30 |
| Critical | CVE · KEV | CVE-2026-7871: Critical Deserialization Flaw Enables Remote Code Execution in IBM Langflow OSS | 2026-06-30 |
| Critical | CVE · KEV | CVE-2026-56700: Critical Multiple Code-Execution Flaws in Grav CMS | 2026-06-30 |
| High | Breach | Notion: Threat Actor Claims 110M Record Breach | 2026-06-30 |
| High | Breach | Texas Parks & Wildlife: Third-Party Vendor Breach Exposes 3 Million Hunters and Anglers | 2026-06-30 |
| Critical | CVE · KEV | CVE-2026-48286: Critical Authorization Flaw in Adobe Campaign Classic Enables Remote Code Execution | 2026-06-30 |
| Critical | CVE · KEV | CVE-2026-58449: Unauthenticated RCE in txtai API /reindex Endpoint | 2026-06-30 |
| High | Ransomware | DC Housing Authority: Ransomware Attack With Data Theft Claim | 2026-06-30 |
| Critical | CVE · KEV | IBM Langflow OSS Hit by Critical CVE-2026-10134: Full Compromise via Code Injection | 2026-06-30 |
| Critical | CVE · KEV | IBM WebSphere Application Server Hit by Critical XSS Flaw (CVE-2026-11712) | 2026-06-30 |
| High | Ransomware | Nidec Corporation: Blackfield Ransomware $2M Extortion | 2026-06-30 |
| Critical | CVE · KEV | CVE-2026-48276: Critical Unauthenticated Code Execution in Adobe ColdFusion | 2026-06-30 |
| Critical | CVE · KEV | IBM Db2 Pre-Auth RCE (CVE-2026-10109): Critical DRDA Handshake Flaw | 2026-06-30 |
| Critical | CVE · KEV | Ocelot API Gateway IP Allow/Block List Bypass via WebSocket Upgrade (CVE-2026-58172) | 2026-06-30 |
| High | Breach | NAIC: ShinyHunters Oracle PeopleSoft Zero-Day Breach | 2026-06-30 |
| Critical | CVE · KEV | IBM Langflow OSS Cross-Tenant Credential Reuse (CVE-2026-10140) | 2026-06-30 |
| Critical | CVE · KEV | Adobe ColdFusion CVE-2026-48277: Critical CVSS 10.0 Remote Code Execution | 2026-06-30 |
| Critical | CVE · KEV | CVE-2026-58116: Critical RCE in LLaMA-Factory via Malicious Model Path | 2026-06-30 |
| High | Breach | Aflac Japan: Policyholder Portal Breach Exposes 4.38 Million Customers | 2026-06-30 |
| Critical | CVE · KEV | CVE-2026-58166: Unauthenticated Path Traversal in OpenBMB ChatDev Upload Handler | 2026-06-30 |
| Critical | CVE · KEV | CVE-2026-56278: Hardcoded Default Session Secret in Flowise Enables Authentication Bypass | 2026-06-30 |
| Critical | CVE · KEV | Orkes Conductor Unauthenticated RCE: CVE-2026-58138 | 2026-06-30 |
| High | Breach | Logitech: Clop Extortion via Oracle Zero-Day | 2026-06-29 |
| High | Breach | Towerpoint Wealth: Unauthorized Actor Exfiltrates Client Financial Data | 2026-06-29 |
| High | Breach | Nissan: Oracle E-Business Suite Zero-Day Data Breach | 2026-06-29 |
| High | Ransomware | Hologic: Redact Ransomware Data Extortion | 2026-06-29 |
| High | Breach | European Commission: Cloud Data Breach Confirmed | 2026-06-29 |
| Critical | CVE · KEV | SimpleHelp OIDC Authentication Bypass (CVE-2026-48558) Lands on CISA's KEV List | 2026-06-29 |
| High | Breach | Southern Illinois Ob-Gyn Associates: Network Intrusion Exposes 38,700 Patients | 2026-06-29 |
| High | Breach | DETRAN SP: pl4t0v Free Database Leak of 13 Million Records | 2026-06-29 |
| High | Breach | LexisNexis: FulcrumSec Exfiltrates 2GB From AWS Infrastructure | 2026-06-29 |
| High | Ransomware | Shwapno: Ransom-Driven Breach of Bangladesh's Largest Grocery Chain | 2026-06-29 |
| High | Breach | Connecticut Medicaid: Credential Theft Breach Exposes 22,500 Patient Records | 2026-06-29 |
| High | Breach | Queensland State Schools: Third-Party Breach via Instructure QLearn Platform | 2026-06-29 |
| High | Ransomware | Kyowon Group: Ransomware Attack Exposes Millions of Accounts | 2026-06-29 |
| High | Ransomware | TRANSCORE and 1-800-DENTIST: Qilin Ransomware Leak Site Listings | 2026-06-29 |
| High | Breach | Hartford HealthCare: Credential Compromise Breaches 22,500 Accounts | 2026-06-29 |
| High | Breach | Rockstar Games: ShinyHunters Extortion Leak | 2026-06-29 |
| High | Breach | NSW Rural Fire Service: Nova Ransomware Breach | 2026-06-28 |
| High | Ransomware | Challenge Manufacturing: Chaos Ransomware Data Theft | 2026-06-28 |
| High | Breach | French Employment and HR Apps: Unattributed Mass Data Leak | 2026-06-28 |
| High | Breach | Medtronic: ShinyHunters Data Breach | 2026-06-28 |
| High | Breach | Polymarket: Supply-Chain Phishing Attack | 2026-06-28 |
| High | Breach | Tabiq: Cloud Misconfiguration Exposes 1M+ Identity Documents | 2026-06-28 |
| High | Ransomware | GökNur Gıda: Dreamfyre Ransomware Leak of 10.7 TB | 2026-06-28 |
| High | Breach | University of Nottingham: ShinyHunters Data Breach | 2026-06-28 |
| High | Breach | Insee: Cyberattack Exposing Staff Personal Data | 2026-06-28 |
| High | Breach | Trenitalia: Customer Ticket Data Breach via Unauthorized Access | 2026-06-28 |
| High | Breach | Dutch Ministry of Finance: Unauthorized Access to Primary Process Systems | 2026-06-28 |
| High | Breach | Japan Self-Defense Forces: China-Linked USB Firmware Espionage | 2026-06-28 |
| High | Breach | Turkish Cypriot Administration: Health Ministry Breach and Dark Web Leak | 2026-06-27 |
| Critical | CVE · KEV | CVE-2026-12415: Unauthenticated Account Takeover in WordPress Invoice Generator Plugin | 2026-06-27 |
| High | Breach | Instructure Canvas: Suspected ShinyHunters Education Sector Breach | 2026-06-27 |
| High | Breach | Colorado Health Network and Kentucky Mountain Health Alliance: Cephalus Ransomware and Healthcare Data Breaches | 2026-06-27 |
| High | Breach | Nefos Cannabis ID Verification: Exposed Database Leaks One Million Passports | 2026-06-27 |
| High | Ransomware | River Financial Corporation: Ransomware Intrusion Disrupts Banking Operations | 2026-06-27 |
| High | Breach | American Tower: ShinyHunters Pay-or-Leak Extortion | 2026-06-27 |
| High | Breach | 100+ Organizations: ShinyHunters PeopleSoft Zero-Day Mass Breach | 2026-06-27 |
| High | Breach | Carnival Corporation: Social Engineering Data Breach | 2026-06-27 |
| High | Ransomware | Adapt: ShinyHunters Ransomware Extortion | 2026-06-26 |
| High | Breach | Universities and Enterprises: ShinyHunters PeopleSoft Zero-Day Campaign | 2026-06-26 |
| High | Breach | Reynella East College: Interlock Ransomware Data Dump | 2026-06-26 |
| High | Breach | Alamo Heights ISD: Ransomware Data Breach | 2026-06-26 |
| High | Breach | NAIC: PeopleSoft Zero-Day Breach | 2026-06-26 |
| High | Breach | Dialog Network: Exposed Records of NATO and US Officials | 2026-06-26 |
| High | Breach | Healthcare AI Provider: Misconfiguration Exposes 1.4M Humana and Mayo Clinic Patients | 2026-06-26 |
| High | Ransomware | Padget Technologies: Akira Ransomware Data Extortion | 2026-06-26 |
| High | Breach | Prince George County, Va.: Cyberattack Exposes Resident and Employee Data | 2026-06-26 |
| High | Breach | Latvijas valsts meži: Commercially Motivated Hacker Breaches State Forests IT Systems | 2026-06-26 |
| High | Breach | Jaguar Land Rover: Russia-Linked Ransomware Attack | 2026-06-26 |
| High | Breach | Klue: Icarus Salesforce Supply-Chain Breach | 2026-06-26 |
| Critical | CVE · KEV | CVE-2026-54636: Critical Container Escape in Dokku's Cron Plugin | 2026-06-26 |
| High | Ransomware | Barts Health NHS: Clop Ransomware via Oracle Zero-Day | 2026-06-25 |
| High | Ransomware | ISOPLUS: Qilin Ransomware Data Extortion | 2026-06-25 |
| High | Ransomware | Leo International: Akira Ransomware Data Theft Claim | 2026-06-25 |
| High | Breach | Grafana Labs: Mini Shai-Hulud npm Supply Chain Attack | 2026-06-25 |
| High | Breach | Texas Parks and Wildlife Department: Third-Party Vendor Breach Exposes 3 Million License Holders | 2026-06-25 |
| Critical | CVE · KEV | Cisco Unified CM SSRF Flaw (CVE-2026-20230) Added to CISA KEV | 2026-06-25 |
| Critical | CVE · KEV | CVE-2026-12569: Unauthenticated RCE in PTC Windchill and FlexPLM | 2026-06-25 |
| High | Breach | Xolis: Targeted Phishing Compromises Healthcare AI Vendor | 2026-06-25 |
| Critical | CVE · KEV | CVE-2026-12417: Unauthenticated Account Takeover in WordPress SignUp & SignIn Plugin | 2026-06-24 |
| High | Ransomware | Bajaj Auto: Ransomware Attack Disrupts Systems | 2026-06-24 |
| Critical | CVE · KEV | CVE-2026-12416: Unauthenticated Account Takeover in WordPress Invoice Generator Plugin | 2026-06-24 |
| High | Breach | Madison Square Garden: Vishing Breach Exposes Knicks and Talent Records | 2026-06-24 |
| High | Breach | Tchap: Account Hijack Breach of French Government Messaging | 2026-06-24 |
| High | Breach | Fortinet Firewalls: FortiBleed Mass Credential Theft Campaign | 2026-06-24 |
| High | Ransomware | Romanian Hospitals: Backmydata Ransomware (Phobos Family) | 2026-06-24 |
| Critical | CVE · KEV | CVE-2026-56237: Critical Authentication Bypass in Capgo API Key Generation | 2026-06-24 |
| High | Breach | Transport for London: Teenage Hackers Breach and 10M Passenger Data Theft | 2026-06-24 |
| Critical | CVE · KEV | CVE-2026-11807: Missing Authorization in Event-Driven Ansible Leaks Plaintext Credentials | 2026-06-23 |
| High | Ransomware | NationsBuilders Insurance Services: Aurora Ransomware Data Theft | 2026-06-23 |
| High | Breach | KDDI: Third-Party Software Exploit Exposes 14.22 Million Email Records | 2026-06-23 |
| Critical | CVE · KEV | CVE-2026-34909: Critical Path Traversal in Ubiquiti UniFi OS | 2026-06-23 |
| Critical | CVE · KEV | CVE-2026-34908: Critical Access Control Flaw in Ubiquiti UniFi OS | 2026-06-23 |
| High | Breach | LastPass: OAuth Token Theft via Klue Supply Chain Attack | 2026-06-23 |
| High | Breach | Xsolis: Phishing Driven Healthcare Data Breach | 2026-06-23 |
| High | Breach | Spectrum: ShinyHunters Vishing Breach | 2026-06-23 |
| High | Ransomware | US Law Firms: Luna Moth Social-Engineering Extortion | 2026-06-23 |
| Critical | CVE · KEV | CVE-2026-34910: Critical Command Injection in Ubiquiti UniFi OS | 2026-06-23 |
| Critical | CVE · KEV | CVE-2025-67038: Critical Root-Level Command Injection in Lantronix EDS5000 Device Servers | 2026-06-23 |
| High | Breach | Belgian State Security (VSSE): Ivanti EPMM Exploitation Exposes Employee Data | 2026-06-22 |
| High | Ransomware | Go2Joy: RansomEXX Ransomware Breach | 2026-06-22 |
| High | Ransomware | Capital Development Authority Islamabad: Billing Systems Ransomware Attack | 2026-06-22 |
| Critical | CVE · KEV | CVE-2026-10561: Critical Unauthenticated RCE in IBM Langflow OSS | 2026-06-22 |
| Critical | CVE · KEV | CVE-2026-56348: n8n Credential Exfiltration via Allowed HTTP Request Domains Bypass | 2026-06-22 |
| High | Breach | TVING: Data Breach Exposes 19.53 Million Users | 2026-06-22 |
| High | Breach | Canada Life: ShinyHunters Salesforce Extortion | 2026-06-22 |
| Critical | CVE · KEV | CVE-2026-7664: Critical Authorization Bypass in IBM Langflow OSS MCP Endpoint | 2026-06-22 |
| High | Breach | Kodak: ShinyHunters Extortion Breach | 2026-06-22 |
| High | Breach | Tata Electronics: World Leaks Ransomware Breach Exposing Apple, Tesla Trade Secrets | 2026-06-22 |
| High | Breach | Carnival Cruise Line: Social Engineering Breach Exposes 6 Million | 2026-06-22 |
| High | Breach | JCPenney: ShinyHunters PeopleSoft Zero-Day Breach | 2026-06-21 |
| High | Breach | Brazil Civil Defense: Emergency Alert System Hijack | 2026-06-21 |
| High | Breach | U.S. Classified Networks: Anthropic Mythos Autonomous AI Breach | 2026-06-21 |
| High | Ransomware | ALS Global: Aurora Ransomware Breach | 2026-06-21 |
| High | Ransomware | Desert Micro: Nova Ransomware Data Extortion | 2026-06-21 |
| High | Ransomware | Q Link Wireless: Qilin Ransomware Attack | 2026-06-21 |
| High | Ransomware | Global Schools Group: FulcrumSec Ransomware Attack | 2026-06-21 |
| High | Breach | Klue Customers: Icarus OAuth Token Abuse | 2026-06-20 |
| High | Breach | African National Congress: Black X Extortion Breach | 2026-06-20 |
| High | Breach | Inter-Con Security: ShinyHunters Extortion Leak | 2026-06-20 |
| High | Ransomware | Signature Healthcare: Anubis Ransomware | 2026-06-20 |
| High | Breach | Huntress: ShinyHunters Salesforce Data Theft via Klue App | 2026-06-20 |
| High | Ransomware | One Medical: ShinyHunters Data-Theft Extortion | 2026-06-19 |
| High | Breach | Moody Bible Institute: ShinyHunters Data Theft and Extortion | 2026-06-19 |
| High | Breach | Texas Parks & Wildlife: Vendor Breach Exposes 3 Million Licenses and Passports | 2026-06-19 |
| High | Breach | Texas Parks & Wildlife Department: Third-Party Vendor Breach Exposes 3 Million IDs | 2026-06-19 |
| High | Breach | Texas Parks & Wildlife Department: Third-Party Vendor Breach Exposes 3 Million Residents | 2026-06-19 |
| High | Ransomware | Horizon Family Medical Group: Incransom Ransomware Breach | 2026-06-19 |
| High | Breach | Texas State Agency: Third-Party Vendor Compromise | 2026-06-19 |
| High | Breach | Texas Parks & Wildlife: Third-Party Vendor Breach Exposes 3 Million | 2026-06-18 |
| High | Breach | Fortinet: Russian-Speaking Criminals Mass-Compromise FortiGate Gateways | 2026-06-17 |
| High | Breach | Madison Square Garden Sports: ShinyHunters Data Extortion | 2026-06-17 |
| High | Ransomware | Adriatic Port Authority: Anubis Ransomware Cripples Maritime Operations | 2026-06-17 |
| High | Breach | Ohio, Georgia, and Arizona Hospital Networks: Coordinated Ransomware Breach | 2026-06-16 |
| High | Breach | iRhythm Holdings: Social Engineering Breach and Extortion | 2026-06-16 |
| High | Breach | Instructure Canvas: ShinyHunters Freemium Tier Breach | 2026-06-16 |
| High | Breach | Sysco: ShinyHunters Salesforce Extortion | 2026-06-16 |
| High | Breach | World Food Programme: Unauthorized Breach of Gaza Aid Registration Platform | 2026-06-16 |
| Critical | CVE · KEV | CVE-2026-48907: Unauthenticated RCE in Widget Factory's JCE Editor for Joomla | 2026-06-16 |
| High | Breach | HDFC AMC: Morpheus Ransomware Breach and 680 GB Data Theft | 2026-06-16 |
| High | Ransomware | Three U.S. Regional Banks: SilverThread Ransomware Extortion | 2026-06-16 |
| High | Breach | Glendale Community College: ShinyHunters Exfiltrates 62GB From PeopleSoft Campus Solutions | 2026-06-16 |
| High | Breach | Nintendo: SHADOWBYT3$ Third-Party SaaS Breach | 2026-06-16 |
| Critical | CVE · KEV | CVE-2026-20262: Cisco Catalyst SD-WAN Manager Path Traversal Flaw Added to CISA KEV | 2026-06-15 |
| High | Breach | Meta Platforms: Confirmed Data Breach Exposes Up to 100,000 Records | 2026-06-15 |
| Critical | CVE · KEV | LiteSpeed cPanel Plugin Symlink Flaw (CVE-2026-54420) Added to CISA KEV | 2026-06-15 |
| High | Ransomware | Mackay Sugar: The Gentlemen Ransomware (Storm-2697) | 2026-06-15 |
| High | Breach | Humanity Protocol: North Korean Phishing Crypto Heist | 2026-06-15 |
| High | Breach | Kaluga Astral: Week-Long Service Disruption from Cyberattack | 2026-06-15 |
| High | Breach | Council of Europe: ShinyHunters PeopleSoft Data Theft | 2026-06-15 |
| High | Breach | Eastman Kodak: ShinyHunters Pay or Leak Extortion | 2026-06-15 |
| High | Breach | Infinite Campus: ShinyHunters Extortion Data Leak | 2026-06-15 |
| High | Breach | Berkadia: ShinyHunters Salesforce Extortion Breach | 2026-06-15 |
| High | Breach | 700Credit: API Abuse via Compromised Integration Partner | 2026-06-15 |
| High | Breach | North American Research Institutions: UNC6508 REDCap Espionage | 2026-06-15 |
| High | Breach | Norfolk and Norwich University Hospital: Qilin Ransomware Patient Data Theft | 2026-06-12 |
| High | Breach | Vietnam National Immunization System: Self-Taught Teen Breach | 2026-06-12 |
| Critical | CVE · KEV | IEI iRM-IEI Remote Management Hardcoded Credentials (CVE-2026-11849) | 2026-06-12 |
| High | Breach | California Water Service: Handala Hack and Leak Breach | 2026-06-12 |
| High | Breach | Ralph Lauren Corporation: ShinyHunters Data Extortion | 2026-06-12 |
| High | Breach | Novo Nordisk: Clinical Trials Data Breach | 2026-06-12 |
| Critical | CVE · KEV | CVE-2026-49973: Unauthenticated Account Takeover in Hermes WebUI Setup | 2026-06-11 |
| High | Ransomware | Singing River Health System: Anubis Ransomware Breach | 2026-06-11 |
| High | Breach | Universities: ShinyHunters Oracle PeopleSoft Mass Compromise | 2026-06-11 |
| High | Breach | Oracle PeopleSoft Customers: ShinyHunters Data Theft Extortion | 2026-06-11 |
| High | Ransomware | Isuzu Motors: Qilin Ransomware Cross-Sector Batch | 2026-06-11 |
| Critical | CVE · KEV | CVE-2026-11839: Critical Web Shell Upload Flaw in Başarsoft Rotaban | 2026-06-11 |
| High | Breach | ServiceNow: Zero-Auth API Breach Exposes Enterprise Instance Data | 2026-06-11 |
| High | Breach | Synnovis: Qilin Ransomware NHS Data Breach | 2026-06-11 |
| Critical | CVE · KEV | Ivanti Sentry CVE-2026-10520: Unauthenticated Root RCE Added to CISA KEV | 2026-06-11 |
| High | Breach | Lithuanian Health Ministry: Apache Superset Exploited in Government Breach | 2026-06-11 |
| High | Breach | France Titres (ANTS): IDOR Breach Exposes Millions of French Citizens | 2026-06-11 |
| High | Breach | VRChat: External Cloud Breach Exposes 2.4 Million Users | 2026-06-11 |
| High | Breach | Coupang: Insider-Built Backdoor Exposes 37.5 Million | 2026-06-11 |
| High | Breach | Nexstar: ShinyHunters Salesforce Data Theft | 2026-06-11 |
| Critical | CVE · KEV | CVE-2026-7852: Critical Unrestricted File Upload Flaw in Limatek LimRAD NAC | 2026-06-11 |
| High | Ransomware | University of Nottingham: ShinyHunters Ransomware Breach | 2026-06-10 |
| Critical | CVE · KEV | CVE-2026-53475: Hardcoded Insecure TLS in assisted-migration-agent Exposes vCenter Admin Credentials | 2026-06-10 |
| High | Breach | Discord: Disputed Insider Breach Filing Claims 10 Million Users Exposed | 2026-06-10 |
| Critical | CVE · KEV | CVE-2026-53474: Critical SQL Injection in migration-planner via Malicious RVTools Upload | 2026-06-10 |
| High | Breach | OkCupid: Forum Hackers Selling 35 Million Scraped User Records | 2026-06-10 |
| Critical | CVE · KEV | CVE-2026-53476: Critical Path Traversal in Red Hat assisted-migration-agent | 2026-06-10 |
| High | Breach | Delaware North: Microsoft Account Compromise and File Exfiltration | 2026-06-10 |
| Critical | CVE · KEV | CVE-2026-53470: Critical Access Control Flaw in migration-planner Exposes Other Users' OVA Images | 2026-06-10 |
| High | Ransomware | Singing River Health System: Anubis Ransomware Breach | 2026-06-10 |
| High | Ransomware | Réseau Radiologique Romand: Akira Ransomware | 2026-06-10 |
| High | Breach | H1: Soral Leaks 2M+ Medical Professional Records | 2026-06-10 |
| High | Breach | Nottingham University: ShinyHunters PeopleSoft Data Theft | 2026-06-10 |
| High | Breach | Station Casinos: Single Compromised Account Leads to PII Breach and Class Action | 2026-06-10 |
| Critical | CVE · KEV | CVE-2026-53469: Missing Authorization in migration-planner Allows Total Data Destruction | 2026-06-10 |
| Critical | CVE · KEV | Doctreat Core for WordPress: Unauthenticated Admin Registration (CVE-2025-6254) | 2026-06-10 |
| High | Ransomware | FESCO Adecco: TheGentlemen Ransomware Breach | 2026-06-10 |
| Critical | CVE · KEV | Critical Unauthenticated File Write Flaw in Splunk Enterprise and Cloud Platform (CVE-2026-20253) | 2026-06-10 |
| High | Breach | Hokkaido Medical Center and Hokkaido Cancer Center: Improper Disk Disposal Data Leak | 2026-06-09 |
| Critical | CVE · KEV | CVE-2026-11645: High-Severity Chromium V8 Flaw Lands on CISA's KEV List | 2026-06-09 |
| High | Breach | Proprietes-Privees: ChimeraZ API Breach Exposes 2.5M People | 2026-06-09 |
| Critical | CVE · KEV | Critical Code Execution Flaw in Azure Stack Edge — CVE-2026-47643 (CVSS 9.8) | 2026-06-09 |
| Critical | CVE · KEV | CVE-2026-34691: Critical Stored XSS in Adobe Experience Manager Forms JEE | 2026-06-09 |
| Critical | CVE · KEV | CVE-2026-47928: Critical ColdFusion Code Execution Flaw | 2026-06-09 |
| High | Breach | Lansing Community College: Compromised Credentials Breach Hits 174,000 | 2026-06-09 |
| Critical | CVE · KEV | CVE-2026-7486: Critical SQL Injection in Netcad E-İmar | 2026-06-09 |
| Critical | CVE · KEV | Critical RCE in Windows DHCP Client — CVE-2026-44815 | 2026-06-09 |
| High | Breach | SoFi Hong Kong: Third-Party Vendor Breach | 2026-06-09 |
| Critical | CVE · KEV | CVE-2026-45657: Critical Windows Kernel Use-After-Free Enables Remote Code Execution | 2026-06-09 |
| Critical | CVE · KEV | Arista EOS Tunnel Decapsulation Flaw (CVE-2026-7473) Hits CISA KEV Under Active Exploitation | 2026-06-09 |
| High | Ransomware | Foxconn: Nitrogen Ransomware Breach via Malvertising and ESXi Exploit | 2026-06-09 |
| Critical | CVE · KEV | CVE-2026-45602: Critical Windows DHCP Server Tampering Flaw | 2026-06-09 |
| Critical | CVE · KEV | CVE-2017-20251: Unauthenticated PHP Code Injection in WordPress Insert PHP Plugin | 2026-06-09 |
| Critical | CVE · KEV | CVE-2026-47281: Critical Privilege Escalation Flaw in Visual Studio Code | 2026-06-09 |
| Critical | CVE · KEV | CVE-2026-42904: Critical Windows TCP/IP Heap Overflow Enables Privilege Escalation | 2026-06-09 |
| Critical | CVE · KEV | CVE-2026-48303: Critical Authorization Flaw in Adobe Campaign Classic Enables Remote Code Execution | 2026-06-09 |
| Critical | CVE · KEV | CVE-2026-26142: Critical Deserialization RCE in Nuance PowerScribe | 2026-06-09 |
| High | Ransomware | Singing River Health System: Anubis Ransomware Data Theft | 2026-06-09 |
| High | Breach | Texas Capital Bank: 91,000 Customers Exposed in Data Breach | 2026-06-09 |
| Critical | CVE · KEV | Cisco Catalyst SD-WAN Manager Root Command Injection (CVE-2026-20245) | 2026-06-09 |
| Critical | CVE · KEV | CVE-2026-8025: Critical SQL Injection in MOSK CBS Platform | 2026-06-09 |
| High | Breach | World Food Programme: Unauthorized Access of Gaza Self-Registration App | 2026-06-09 |
| High | Breach | Kyushu Electric Power: Missing SSD Exposes 10.9 Million Records | 2026-06-09 |
| Critical | CVE · KEV | CVE-2026-47291: Critical HTTP.sys Integer Overflow Enables Unauthenticated Remote Code Execution | 2026-06-09 |
| High | Breach | Aflac: Scattered Spider Help-Desk Breach | 2026-06-09 |
| Critical | CVE · KEV | Check Point Security Gateway VPN Auth Bypass: CVE-2026-50751 Added to CISA KEV | 2026-06-08 |
| High | Breach | Syrian Government: Erresira Claims 20GB Diplomatic Document Breach | 2026-06-08 |
| High | Ransomware | Change Healthcare: 190M Record Ransomware Breach | 2026-06-08 |
| High | Ransomware | AT&T: ShinyHunters Ransom Payment for Stolen Call Records | 2026-06-08 |
| High | Ransomware | Nigerian Transport Carrier: Unidentified Syndicate Double-Extortion Ransomware | 2026-06-08 |
| Critical | CVE · KEV | CVE-2023-54352: Unauthenticated RCE in WordPress Seotheme | 2026-06-08 |
| High | Ransomware | Evanston Township High School District 202: Ransomware Attack Disrupts Summer Operations | 2026-06-08 |
| Critical | CVE · KEV | BerriAI LiteLLM Command Injection (CVE-2026-42271) Lands in CISA KEV | 2026-06-08 |
| High | Breach | Qantas: Scattered Lapsus$ Hunters Dark Web Leak | 2026-06-08 |
| High | Breach | TeamViewer: Russian APT29 Corporate Network Breach | 2026-06-08 |
| Critical | CVE · KEV | CVE-2024-58349: Unauthenticated RCE in WordPress Travelscape Theme | 2026-06-08 |
| Critical | CVE · KEV | CVE-2026-27671: Critical Unauthenticated RCE in SAP NetWeaver ABAP Kernel | 2026-06-08 |
| High | Breach | Medtronic: ShinyHunters Data Breach | 2026-06-08 |
| High | Breach | Tchap: Dark Web Actor Claims Massive Government Messaging Breach | 2026-06-08 |
| Critical | CVE · KEV | CVE-2026-11499: Critical Remote Stack Overflow in Tenda HG7, HG9, and HG10 XPON Routers | 2026-06-08 |
| Critical | CVE · KEV | CVE-2024-58348: Unauthenticated RCE in WordPress Background Image Cropper Plugin | 2026-06-08 |
| High | Breach | Creditas: Dark Web Actor Claims Massive Fintech Breach | 2026-06-08 |
| High | Ransomware | US Trade Association: Genesis Ransomware Claim | 2026-06-08 |
| Critical | CVE · KEV | OpenBullet2 Auth Bypass: One Empty Header Hands Over Admin (CVE-2026-25555) | 2026-06-08 |
| High | Ransomware | Lürssen: Ransomware Attack Halts Superyacht Production | 2026-06-08 |
| High | Breach | Toyota Financial Services: Medusa Ransomware Attack | 2026-06-08 |
| Critical | CVE · KEV | CVE-2026-39910: Critical Privilege Escalation in STACKIT IaaS API | 2026-06-08 |
| High | Breach | Mid and South Essex NHS Trust: Qilin Ransomware Data Theft | 2026-06-08 |
| Critical | CVE · KEV | CVE-2026-41448: AdGuard Home Authentication Bypass via Path Traversal in Admin-Token Cookie | 2026-06-08 |
| Critical | CVE · KEV | CVE-2026-40128: Critical Path Traversal in SAP NetWeaver Application Server Java | 2026-06-08 |
| High | Ransomware | Hansoll Textile: Payload Ransomware Campaign Expands | 2026-06-08 |
| Critical | CVE · KEV | CVE-2026-44748: Critical Signature Verification Flaw in SAP NetWeaver AS ABAP | 2026-06-08 |
| High | Breach | FBI: Salt Typhoon Breaches Digital Collection Systems Network | 2026-06-07 |
| High | Breach | CISA: Chemical Security Assessment Tool Breach | 2026-06-07 |
| High | Breach | Oxford University: CareerConnect Vendor Breach via Group GTI | 2026-06-07 |
| High | Ransomware | BELFOR Asia: INC Ransom Breach | 2026-06-07 |
| High | Breach | DentaQuest: ShinyHunters Leak Exposes 2.6 Million | 2026-06-07 |
| High | Ransomware | Kriete Truck Centers: Securotrop Ransomware Listing | 2026-06-07 |
| High | Breach | Baker Distributing: ShinyHunters Salesforce and SharePoint Leak | 2026-06-07 |
| High | Breach | NSCC Tianjin: Alleged 10PB Classified Data Breach | 2026-06-07 |
| High | Ransomware | Access Dental: WorldLeaks Ransomware Breach | 2026-06-07 |
| High | Breach | City of Vallejo: Constant Contact Email Platform Hijacked | 2026-06-07 |
| High | Breach | Tradeify: macaroni Leaks 240K Customer Records via Exposed API Key | 2026-06-07 |
| High | Ransomware | ICBC Financial Services: Ransomware Attack Disrupts Treasury Market | 2026-06-07 |
| High | Breach | FBI Director Kash Patel: Handala Hack Team Gmail Breach | 2026-06-07 |
| High | Ransomware | US Telecom Provider: Akira Ransomware Breach Claim | 2026-06-07 |
| High | Breach | Meridianbet: INF GRUPA Customer Database Breach | 2026-06-07 |
| High | Breach | IBM: APT10 Breach Coverup Allegations | 2026-06-07 |
| High | Breach | RCI Hospitality: IDOR Vulnerability Exposes 40,000 Contractors | 2026-06-07 |
| High | Breach | Conduent Business Services: Healthcare Data Breach Impacts 62.2M | 2026-06-06 |
| High | Ransomware | Aspire Hospital: Nova Ransomware Claim | 2026-06-06 |
| High | Breach | Erie Family Health: 570K Patient Breach After 48 Day Network Intrusion | 2026-06-06 |
| High | Ransomware | RUAG: Akira Ransomware Payment Confirmed | 2026-06-06 |
| High | Breach | UN World Food Program: Gaza Enrollment System Breach Exposes 600,000 Households | 2026-06-06 |
| High | Breach | Clarinda Regional Health Center: LockBit5 Ransomware Breach | 2026-06-06 |
| High | Ransomware | Ireland HSE: Third-Party Vendor Ransomware Outage | 2026-06-06 |
| High | Breach | Illuminate Education: FTC Finalizes Order Over Student Data Breach | 2026-06-06 |
| High | Breach | Strategic Education: Unknown Actor Exfiltrates SSNs in 87-Day Stealth Breach | 2026-06-05 |
| High | Ransomware | Mountain Park, Oklahoma: Municipal Ransomware Attack | 2026-06-05 |
| High | Ransomware | Avcon Jet: Qilin Ransomware Attack | 2026-06-05 |
| High | Breach | IBM and AT&T: Concealed Foreign Breaches of Federal Cloud Infrastructure | 2026-06-05 |
| Critical | CVE · KEV | CVE-2026-28318: SolarWinds Serv-U Unauthenticated Crash via Deflate-Encoded POST | 2026-06-05 |
| High | Ransomware | Oaks Park and Kennon Worldwide: Akira Ransomware Extortion | 2026-06-05 |
| Critical | CVE · KEV | CVE-2025-71317: Hard-Coded Backdoor in Riello NetMan 204 Grants Unauthenticated Admin Access | 2026-06-05 |
| High | Ransomware | Pyramid: Nitrogen Ransomware Attack | 2026-06-05 |
| High | Breach | Columbia University: Politically Motivated Breach Exposes 868,969 Records | 2026-06-05 |
| High | Breach | Grindr: Alleged Sale of 15 Million User Records | 2026-06-05 |
| High | Ransomware | Sicol: SpaceBears Ransomware Attack | 2026-06-05 |
| High | Ransomware | Instructure Canvas: ShinyHunters Ransomware Breach | 2026-06-05 |
| Critical | CVE · KEV | CVE-2026-10580: Unauthenticated Admin Takeover in Hippoo Mobile App for WooCommerce | 2026-06-05 |
| High | Breach | Osmose France: Alleged Dark Web Data Breach Claim | 2026-06-05 |
| High | Ransomware | SA2000: Stormous Ransomware Breach | 2026-06-05 |
| High | Ransomware | Factors Western: Akira Ransomware Attack | 2026-06-05 |
| Critical | CVE · KEV | CVE-2026-6274: Critical Authentication Bypass in DTS Redline WR3200 Routers | 2026-06-05 |
| High | Ransomware | National Standard Parts Associates: Akira Ransomware Data Leak | 2026-06-05 |
| Critical | CVE · KEV | CVE-2025-71318: NetMan 204 Missing Authentication Exposes UPS Control to Remote Attackers | 2026-06-05 |
| High | Breach | IKEA: Lapsus$ Alleged 180GB Data Leak Investigation | 2026-06-05 |
| High | Breach | Ultrahuman: Infostealer Malware Breach via Stolen Employee Credentials | 2026-06-05 |
| High | Breach | 23andMe: California AG Sues Over 2023 Credential-Stuffing Breach | 2026-06-04 |
| High | Breach | European Commission: TeamPCP and ShinyHunters Cloud Breach | 2026-06-04 |
| High | Breach | CAEM Mexico: Sativa Gang Leaks 21GB SIAF Database | 2026-06-04 |
| Critical | CVE · KEV | CVE-2026-4104: Critical SQL Injection and Authorization Bypass in Akmer TeknoPass | 2026-06-04 |
| High | Ransomware | MarketJoy: Qilin Ransomware Extortion | 2026-06-04 |
| High | Breach | Anonymous Video Chat App: 22 Million Record Exposure | 2026-06-04 |
| High | Ransomware | ViaQuest: Ransomware Attack Exposes Patient and Employee Data | 2026-06-04 |
| Critical | CVE · KEV | CVE-2019-25727: Arbitrary File Download in WordPress Ad Manager WD Plugin | 2026-06-04 |
| High | Breach | Spanish National Police and INCIBE: Granada-Based Doxing Operation | 2026-06-04 |
| Critical | CVE · KEV | CVE-2019-25741: MobaXterm 12.1 SEH Buffer Overflow via Malicious Session File | 2026-06-04 |
| High | Ransomware | Case Law Correctional Services: Black X Ransomware Breach | 2026-06-04 |
| High | Breach | UN World Food Programme: Self-Registration Platform Breach | 2026-06-04 |
| High | Breach | Carnival Cruise: ShinyHunters Social Engineering Breach | 2026-06-04 |
| High | Breach | iFood: 1.2 Million Brazilian Users Exposed in Confirmed Breach | 2026-06-04 |
| High | Breach | Pemprov DKI Jakarta: Citizen CRM and NIK Identities Leaked | 2026-06-04 |
| High | Breach | Morocco Civil Records: Jabaroot Watiqa.ma Data Leak | 2026-06-04 |
| Critical | CVE · KEV | CVE-2026-10840: OpenShift Pipelines Operator Grants Authenticated Users Write Access to Kueue and cert-manager Resources | 2026-06-04 |
| Critical | CVE · KEV | CVE-2019-25738: WordPress Hybrid Composer Unauthenticated Settings Change | 2026-06-04 |
| High | Breach | NYC Health + Hospitals: Third-Party Vendor Breach Exposes 1.8M Patients | 2026-06-04 |
| High | Breach | Iberdrola: Alleged 110 GB Customer Database Sale | 2026-06-04 |
| High | Breach | ISSSTE Mexico: Pension Database Liquidated on Dark Web | 2026-06-04 |
| High | Ransomware | Arlington ISD: Ransomware Attack Delays Summer School | 2026-06-04 |
| High | Ransomware | IQL-Nog: SafePay Ransomware Attack | 2026-06-04 |
| Critical | CVE · KEV | CVE-2019-25729: PDF Signer 3.0 Server-Side Template Injection Leads to Unauthenticated RCE | 2026-06-04 |
| High | Breach | GitHub: Supply Chain Compromise via Poisoned VS Code Extension | 2026-06-04 |
| High | Breach | IEEA Campeche: l1ghtSoulHem Claims Staff and Student Database Leak | 2026-06-04 |
| High | Ransomware | ACE Hospital: KillSec Ransomware Attack | 2026-06-04 |
| High | Breach | National Testing Agency: Superadmin Bypass and JEE Advanced Data Exposure | 2026-06-03 |
| High | Breach | Dutch Hotels: Mass Booking Data Breach Fuels Payment Scams | 2026-06-03 |
| Critical | CVE · KEV | CVE-2026-45247: Mirasvit Cache Warmer PHP Object Injection Hits CISA KEV | 2026-06-03 |
| High | Ransomware | Armenia Ministry of Internal Affairs: WOLVES OF TURAN Ransomware Claim | 2026-06-03 |
| High | Breach | Spectrum: ShinyHunters Voice Phishing Breach | 2026-06-03 |
| High | Breach | IIT Roorkee: Misconfigured Cloud Storage Exposes 1.79 Lakh JEE Advanced Candidates | 2026-06-03 |
| High | Breach | IMA Diligence Services: Genesis Ransomware Breach Exposes 525,306 | 2026-06-03 |
| High | Ransomware | Weil Gotshal & Manges: $20M Ransomware Extortion Payout | 2026-06-03 |
| High | Breach | Safaricom: Insider Data Theft Exposes 11.5 Million Subscribers | 2026-06-03 |
| High | Breach | Wiley Rein: Law Firm Data Breach and Class Action Lawsuit | 2026-06-03 |
| High | Breach | Middle East Organizations: Iran-Linked Wiper Campaign | 2026-06-03 |
| Critical | CVE · KEV | CVE-2026-35075: Hard-Coded Firmware Password Grants Unauthenticated Full Device Access | 2026-06-03 |
| High | Breach | TVING: Unknown Hackers Breach Member Database | 2026-06-03 |
| High | Breach | Tulane University: Clop Ransomware Oracle Zero-Day Breach | 2026-06-03 |
| High | Breach | Red Hat NPM: Supply Chain Worm Attack | 2026-06-02 |
| High | Ransomware | Squamish.net and Synex International: BrainCipher Ransomware Coordinated Strike | 2026-06-02 |
| High | Ransomware | Limburg-Weilburg County Administration: Abyss Ransomware Attack | 2026-06-02 |
| High | Breach | Instagram: Meta AI Prompt Injection Account Hijack | 2026-06-02 |
| Critical | CVE · KEV | CVE-2026-47117: OpenMed Privacy-Filter Loads Attacker-Controlled Models as Code | 2026-06-02 |
| Critical | CVE · KEV | CVE-2026-5076: ARMember Premium WordPress Plugin Stores Plaintext Password Reset Keys | 2026-06-02 |
| High | Breach | Lithuanian Centre of Registers: Suspected Hostile State Credential Abuse | 2026-06-02 |
| High | Breach | Luton and Dunstable Hospital: Supply Chain Ransomware Exposes 33K Patients | 2026-06-02 |
| High | Breach | Middle East Organizations: Iran-Linked MOIS Wiper Campaign | 2026-06-02 |
| High | Breach | St. Joseph County: Handala Hack Claims 2TB Data Breach | 2026-06-02 |
| High | Ransomware | Squamish.net and Synex International: BrainCipher Ransomware Cross-Continental Attack | 2026-06-02 |
| Critical | CVE · KEV | CVE-2022-0492: Linux Kernel cgroups v1 release_agent Privilege Escalation | 2026-06-02 |
| Critical | CVE · KEV | CVE-2025-48595: Android Framework Integer Overflow Enables Local Privilege Escalation | 2026-06-02 |
| High | Ransomware | Eriell: Nova Ransomware Listing | 2026-06-02 |
| Critical | CVE · KEV | CVE-2026-8206: Kirki WordPress Plugin Account Takeover via Password Reset Flaw | 2026-06-02 |
| High | Breach | Dashlane: 2FA Brute-Force Attack Steals Customer Password Vaults | 2026-06-02 |
| High | Ransomware | Buffalo Convention Center: Akira Ransomware Attack | 2026-06-02 |
| High | Breach | HungerRush: SendGrid API Extortion and Supply Chain Poisoning | 2026-06-01 |
| Critical | CVE · KEV | CVE-2026-9319: Critical Deserialization Flaw in IBM WebSphere Application Server | 2026-06-01 |
| Critical | CVE · KEV | CVE-2024-21182: Oracle WebLogic Server Unspecified Vulnerability Added to CISA KEV | 2026-06-01 |
| High | Ransomware | VVO Finance: Everest Ransomware Attack | 2026-06-01 |
| High | Breach | Mexico Ministry of Welfare: BOLA/IDOR Exploit Chain Leaks 1GB of Citizen Data | 2026-06-01 |
| High | Breach | CBSE: Teen Researcher Exposes OSM Portal Vulnerabilities | 2026-06-01 |
| High | Ransomware | Carton Craft Supply: Qilin Ransomware Attack | 2026-06-01 |
| Critical | CVE · KEV | CVE-2026-8644: Critical Identity Spoofing Flaw in IBM WebSphere Application Server | 2026-06-01 |
| High | Ransomware | Instructure Canvas: Shiny Hunters Extortion Settlement | 2026-06-01 |
| High | Breach | Pakistan Higher Education Commission: 1.5 Million Citizen Records Leaked on Cybercrime Forum | 2026-06-01 |
| High | Ransomware | Vodafone: Lapsus$ Ransomware Claim and Source Code Leak | 2026-06-01 |
| Critical | CVE · KEV | CVE-2018-25427: Stack Buffer Overflow in Arm Whois 3.11 Enables Arbitrary Code Execution | 2026-06-01 |
| High | Breach | Mercor: LiteLLM Supply-Chain Compromise | 2026-06-01 |
| Critical | CVE · KEV | CVE-2026-9311: Critical Remote Code Execution in IBM WebSphere Application Server | 2026-06-01 |
| High | Breach | LACMTA: Iranian MOIS-Linked Group Attribution | 2026-05-31 |
| High | Breach | Fortinet: Dark Web Threat Actor Claims Data Breach | 2026-05-31 |
| Critical | CVE · KEV | CVE-2026-10187: Totolink N300RH Stack-Based Buffer Overflow in setWiFiBasicConfig | 2026-05-31 |
| High | Ransomware | Asopagos S.A.: Everest Ransomware Claims Colombian Financial Entity | 2026-05-31 |
| High | Breach | Drift Protocol and KelpDAO: Lazarus Group Crypto Heist | 2026-05-31 |
| High | Breach | Vercel: ShinyHunters Breach Threatens DeFi Frontends | 2026-05-31 |
| High | Breach | Carnival Corporation: Social Engineering Breach Exposes 6M Travelers | 2026-05-31 |
| High | Breach | Industrial Acceptance Corporation: INC Ransomware Breach Exposes 79,216 SSNs | 2026-05-31 |
| High | Breach | iGreen Energy: Mass Data Liquidation via Predictable S3 URLs | 2026-05-31 |
| High | Ransomware | City of Hamilton: Ransomware Attack Cripples Municipal Services | 2026-05-31 |
| High | Ransomware | HDFC AMC: Morpheus Ransomware Breach | 2026-05-31 |
| High | Breach | UK Immigration System: Third-Party Vulnerability Exposes Visa Applicant Data | 2026-05-31 |
| High | Ransomware | Belimed AG: Incransom Ransomware Breach | 2026-05-30 |
| High | Ransomware | AKM Corporation: Everest Ransomware Attack | 2026-05-30 |
| Critical | CVE · KEV | CVE-2018-25412: Delta SQL 1.8.2 Unauthenticated Arbitrary File Upload Leading to RCE | 2026-05-30 |
| High | Breach | Home Depot Canada: Alleged DarkWeb Breach Claim | 2026-05-30 |
| High | Ransomware | Distrigaz Vest: INC Ransom Ransomware Attack | 2026-05-30 |
| High | Breach | ADT Inc.: ShinyHunters Vishing Attack | 2026-05-30 |
| High | Ransomware | LabExpress: incransom Ransomware Breach Exposes 200GB | 2026-05-30 |
| High | Breach | Carnival Corporation: ShinyHunters Vishing Breach | 2026-05-30 |
| High | Ransomware | TransferZ: Everest Ransomware Attack | 2026-05-30 |
| High | Breach | Kemper Corporation: ShinyHunters Salesforce Extortion Breach | 2026-05-29 |
| Critical | CVE · KEV | CVE-2026-10071: Unauthenticated Arbitrary File Upload in Interinfo DreamMaker | 2026-05-29 |
| High | Ransomware | Sandstone, MN: Qilin Ransomware Breach | 2026-05-29 |
| Critical | CVE · KEV | CVE-2026-8732: Unauthenticated Admin Takeover in WP Maps Pro WordPress Plugin | 2026-05-29 |
| High | Ransomware | Open Door Health Center: INC Ransomware Claim | 2026-05-29 |
| High | Breach | BCD Travel: ShinyHunters Alleged Salesforce and SharePoint Breach | 2026-05-29 |
| Critical | CVE · KEV | CVE-2026-0257: Palo Alto Networks PAN-OS GlobalProtect Authentication Bypass | 2026-05-29 |
| High | Ransomware | WG Neukölln eG: DragonForce Ransomware Attack | 2026-05-29 |
| High | Breach | Connecticut Husky Medicaid Portal: Credential Theft and Payment Diversion Attempt | 2026-05-29 |
| High | Ransomware | QLS Group: DragonForce Ransomware Breach | 2026-05-29 |
| High | Breach | Mexican Government: Chronus Group Breach | 2026-05-29 |
| High | Ransomware | EPB Insurance: DragonForce Ransomware Claim | 2026-05-29 |
| High | Breach | Lithuanian Centre of Registers: Hostile State Actors Breach National Data Systems | 2026-05-29 |
| Critical | CVE · KEV | CVE-2026-3655: Authentication Bypass in WordPress OTP Login With Phone Number Plugin | 2026-05-29 |
| Critical | CVE · KEV | CVE-2026-4290: Unauthenticated Arbitrary User Deletion in WP Travel Pro | 2026-05-29 |
| High | Ransomware | Alpha Group Holdings: Qilin Ransomware Leak Site Listing | 2026-05-28 |
| High | Breach | South Korean Electronics Giant: Seedworm APT Espionage Breach | 2026-05-28 |
| Critical | CVE · KEV | CVE-2026-34311: Critical Unauthenticated Takeover in Oracle Hospitality OPERA 5 | 2026-05-28 |
| High | Ransomware | JC Ripberger Construction: DragonForce Ransomware Leak | 2026-05-28 |
| High | Breach | Ajax FC: Unpatched Web Vulnerability Exposes 300,000 Fan Records | 2026-05-28 |
| Critical | CVE · KEV | CVE-2026-46839: Critical Takeover Flaw in Oracle REST Data Services | 2026-05-28 |
| High | Ransomware | Mt. Spokane Pediatrics: LockBit 5.0 Ransomware Attack | 2026-05-28 |
| High | Breach | LACMTA: Iranian State-Sponsored Breach | 2026-05-28 |
| High | Ransomware | Otthon Centrum: Qilin Ransomware Attack | 2026-05-28 |
| High | Ransomware | West Pharmaceutical Services: Ransomware Attack Disrupts Global Operations | 2026-05-28 |
| Critical | CVE · KEV | CVE-2026-46819: Critical Unauthenticated Flaw in Oracle Internet Procurement Connector | 2026-05-28 |
| High | Breach | Florida Physician Specialists: Network Intrusion Exposes 276K Patient Records | 2026-05-28 |
| High | Breach | Ameriprise Financial: ShinyHunters 200GB Salesforce and SharePoint Leak | 2026-05-28 |
| High | Ransomware | US Law Firms: Silent Ransom Group Physical Intrusion Campaign | 2026-05-28 |
| Critical | CVE · KEV | CVE-2026-46822: Critical Oracle iAssets Flaw Enables E-Business Suite Takeover | 2026-05-28 |
| Critical | CVE · KEV | CVE-2026-24444: Hardcoded Password Backdoor in SDMC NE6037 Cable Modem Routers | 2026-05-28 |
| High | Ransomware | Sunrise Company: Akira Ransomware Exfiltration | 2026-05-28 |
| High | Breach | Dataprev: INSS Beneficiary Data Leak | 2026-05-28 |
| Critical | CVE · KEV | CVE-2026-4408: Samba "check password script" Command Injection Enables Unauthenticated RCE | 2026-05-28 |
| Critical | CVE · KEV | CVE-2026-46840: Critical Unauthenticated Takeover in Oracle REST Data Services | 2026-05-28 |
| Critical | CVE · KEV | CVE-2026-46775: Critical Takeover Flaw in Oracle REST Data Services | 2026-05-28 |
| Critical | CVE | CVE-2026-8809: Unauthenticated Admin Takeover in ACF Extended for WordPress | 2026-05-28 |
| Critical | CVE · KEV | CVE-2026-46824: Critical Oracle E-Business Suite Universal Work Queue Takeover | 2026-05-28 |
| High | Breach | Charter Communications: ShinyHunters Vishing SaaS Extortion | 2026-05-28 |
| Critical | CVE · KEV | CVE-2026-46833: Critical Oracle Database Net Service Takeover Flaw | 2026-05-28 |
| High | Breach | Uruguay Antel Identity Service: La Pampa Leaks Data Exfiltration | 2026-05-28 |
| High | Breach | ManageMyHealth: Preventable Breach Exposes 99,416 NZ Patient Records | 2026-05-27 |
| High | Breach | Salesforce Customers: ShinyHunters Extortion Wave | 2026-05-27 |
| Critical | CVE · KEV | CVE-2025-12686: Critical Buffer Overflow in Synology BeeStation Enables Unauthenticated RCE | 2026-05-27 |
| Critical | CVE · KEV | CVE-2026-8175: Critical Buffer Overflow in IBM Aspera High-Speed Transfer | 2026-05-27 |
| High | Ransomware | SPH Value: DragonForce Ransomware Attack | 2026-05-27 |
| High | Ransomware | Enns & Company: DragonForce Ransomware Attack | 2026-05-27 |
| Critical | CVE · KEV | CVE-2026-45321: TanStack npm Supply Chain Compromise via OIDC Token Theft | 2026-05-27 |
| High | Ransomware | Cushman & Wakefield: ShinyHunters and Qilin Dual Ransomware Attack | 2026-05-27 |
| High | Ransomware | MyPillow: Play Ransomware Leak Site Listing | 2026-05-27 |
| Critical | CVE · KEV | CVE-2026-8398: Trojanized DAEMON Tools Lite Installers Distributed via Official Vendor Channel | 2026-05-27 |
| Critical | CVE · KEV | CVE-2026-48027: Malicious Nx Console Extension Pushed to VS Code Marketplace and OpenVSX | 2026-05-27 |
| High | Ransomware | IDS Group: Rhysida Ransomware Attack | 2026-05-27 |
| High | Breach | LACMTA: Iranian State-Linked Hackers Breach Los Angeles Transit | 2026-05-27 |
| High | Ransomware | Covenant Health: Qilin Ransomware Breach | 2026-05-27 |
| Critical | CVE · KEV | CVE-2026-8760: Login with OTP WordPress Plugin Auth Bypass via Brute-Forceable OTP | 2026-05-27 |
| High | Ransomware | Xchange Technology Rentals: DragonForce Ransomware Attack | 2026-05-27 |
| Critical | CVE · KEV | CVE-2026-7524: Critical RCE in IBM Langflow OSS via Symlink Archive Extraction Flaw | 2026-05-27 |
| High | Ransomware | Marks & Spencer: Scattered Spider/DragonForce Ransomware | 2026-05-26 |
| High | Ransomware | BASE SpA: SpaceBears Ransomware Attack | 2026-05-26 |
| High | Ransomware | NL Fisher: Play Ransomware Strikes Dutch Food Producer | 2026-05-26 |
| Critical | CVE · KEV | CVE-2026-48172: LiteSpeed cPanel Plugin Privilege Escalation Exploited in the Wild | 2026-05-26 |
| High | Ransomware | University of Valencia: Nova Ransomware Claim | 2026-05-26 |
| High | Ransomware | ExpoCredit: Qilin Ransomware Claim | 2026-05-26 |
| High | Breach | Station Casinos: External Threat Actor Data Breach | 2026-05-26 |
| Critical | CVE · KEV | CVE-2026-8633: Critical RCE in IBM WebSphere Web Server Plug-ins | 2026-05-26 |
| High | Ransomware | Global Retool Group: Qilin Ransomware Claim | 2026-05-26 |
| Critical | CVE · KEV | CVE-2026-48689: FastNetMon Community Edition Off-by-One Heap Overflow | 2026-05-26 |
| High | Ransomware | JAKN and GGroupCPAs: DragonForce Ransomware Double Listing | 2026-05-26 |
| High | Breach | Heartland Growers and HELIX INTERNATIONAL: DragonForce Ransomware | 2026-05-26 |
| High | Ransomware | Sanatorio Delta: thegentlemen Ransomware Claim | 2026-05-26 |
| High | Breach | OnlyFans: 340M User Records Allegedly for Sale on Leak Forum | 2026-05-26 |
| High | Ransomware | Brazil SECONT: Nova Ransomware Claims Attack on Government Transparency Body | 2026-05-26 |
| High | Breach | Romania EduSal: 331K Education Records Allegedly Leaked by Threat Actor 'somewhere' | 2026-05-26 |
| High | Breach | WisERP: Dark Web Auction of Core ERP Database | 2026-05-26 |
| High | Breach | Russia FSB: Core Intelligence Repository Leaked Across Dark Web | 2026-05-26 |
| High | Ransomware | Saver NV: DragonForce Ransomware Extortion | 2026-05-26 |
| High | Breach | EGADGETS Pakistan: Dark Web Actor Claims 80M Record Telecom Leak | 2026-05-26 |
| Critical | CVE · KEV | CVE-2026-48904: Joomla! Privilege Escalation via com_users Webservice Endpoint | 2026-05-26 |
| Critical | CVE · KEV | CVE-2026-48898: Joomla Privilege Escalation via com_users Batch Task | 2026-05-26 |
| High | Ransomware | BusinessRecord.com: DragonForce Ransomware Attack | 2026-05-26 |
| Critical | CVE · KEV | CVE-2026-7374: KubeVirt virt-handler Symlink Flaw Enables Full Cluster Takeover | 2026-05-26 |
| High | Ransomware | First VPN: Operation Saffron Takedown | 2026-05-26 |
| High | Breach | Lithuania Centre of Registers: Suspected Foreign Intelligence Breach | 2026-05-26 |
| Critical | CVE · KEV | CVE-2026-48899: Joomla Privilege Escalation via com_users | 2026-05-26 |
| High | Ransomware | Le Perreux-sur-Marne: Ransomware Attack Disrupts Municipal Services | 2026-05-26 |
| High | Breach | Radiology Associates of Richmond: 266,000 Patients Exposed in July 2025 Intrusion | 2026-05-26 |
| High | Breach | Carnival Cruise Line: ShinyHunters Data Breach and Notification Failure | 2026-05-26 |
| High | Breach | Portugal SNS: Over 100,000 Patient Records Stolen via Compromised Doctor Credentials | 2026-05-26 |
| High | Breach | Open Source Developers: TrapDoor Supply Chain Attack | 2026-05-26 |
| High | Breach | Nigeria: 80 Million Citizen Records Leaked on Dark Web | 2026-05-26 |
| High | Breach | CERVI: Alleged Breach of South African Digital Health Platform | 2026-05-26 |
| Critical | CVE · KEV | CVE-2026-8855: IBM HTTP Server RCE and DoS via TLS Mutual Authentication | 2026-05-26 |
| High | Ransomware | Openmind Networks: TheGentlemen Ransomware Breach | 2026-05-26 |
| High | Ransomware | The Adviser: Brain Cipher Ransomware Breach | 2026-05-26 |
| High | Breach | PT Bank Negara Indonesia (BNI): TripleX Data Breach | 2026-05-26 |
| Critical | CVE · KEV | CVE-2026-8856: IBM HTTP Server Denial-of-Service via Writable Configuration | 2026-05-26 |
| High | Ransomware | La Familia Adult Day Center: NightSpire Ransomware Breach | 2026-05-26 |
| High | Breach | Philippine Government Agencies: Multi-Agency Repository and Salary Ledger Leak | 2026-05-26 |
| High | Ransomware | Turkey TKGM: APT73/Bashe Ransomware Attack | 2026-05-24 |
| High | Ransomware | Cablematic: Gunra Ransomware Claim | 2026-05-24 |
| High | Breach | Hillpointe: Dark Web Actor Claims 2.5M Record Breach | 2026-05-23 |
| High | Ransomware | Vernon & Ginsburg: Qilin Ransomware Data Extortion | 2026-05-23 |
| High | Ransomware | A-Sonic Logistics: Payload Ransomware Attack | 2026-05-23 |
| High | Breach | Vietnamese Ministerial Agencies: Serious Data Theft Attack Confirmed by VNCERT | 2026-05-23 |
| High | Breach | Connecticut Medicaid (HUSKY): Credential Compromise Exposes 22,500 Enrollees | 2026-05-23 |
| High | Ransomware | University of Mississippi Medical Center: Ransomware Attack and Potential HIPAA Violation | 2026-05-23 |
| High | Ransomware | Semgrep: Qilin Ransomware Attack | 2026-05-23 |
| High | Ransomware | Robinsons Singapore: Alleged Ransomware Attack | 2026-05-23 |
| High | Ransomware | Starbucks: shadowbyt3$ Ransomware Breach | 2026-05-23 |
| High | Breach | Bit2Win: Alleged Source Code Sale on Dark Web | 2026-05-23 |
| High | Breach | Passion for a Purpose: Handala Hack and Leak Operation | 2026-05-23 |
| High | Ransomware | Charter Communications: ShinyHunters Ransomware Attack | 2026-05-23 |
| High | Breach | Education LMS Platform: Ransomware Crew Steals 275M Records | 2026-05-23 |
| High | Breach | Lithuania State Registry: 600,000 Records Exfiltrated in Cross-Border Cyber Intrusion | 2026-05-23 |
| High | Ransomware | Buffalo Niagara Convention Center: Akira Ransomware Attack | 2026-05-23 |
| High | Ransomware | Minsa: APT73/Bashe Ransomware Attack | 2026-05-23 |
| High | Ransomware | Internal Medicine and Pediatrics of Cullman: Payload Ransomware Leak Site Listing | 2026-05-23 |
| High | Breach | Atol Group: Alleged Dark Web Sale of 5.9M Customer Records | 2026-05-23 |
| High | Ransomware | GITIS: Akira Ransomware 30GB Data Extortion | 2026-05-23 |
| High | Ransomware | Karlin Foods: Akira Ransomware Attack | 2026-05-23 |
| High | Ransomware | DentaQuest: ShinyHunters Ransomware Claim | 2026-05-23 |
| High | Breach | Unimed: Billing Provider Breach Cascades Across German University Hospitals | 2026-05-23 |
| High | Breach | Medical Provider: BlackCat Insider Affiliates Sentenced | 2026-05-22 |
| High | Ransomware | Cardinal Services: Rhysida and INC Ransomware Double Breach | 2026-05-22 |
| High | Ransomware | Port of Seattle: Rhysida Ransomware Data Theft | 2026-05-22 |
| High | Breach | Trump Mobile: Customer Data Exposure via Third Party Platform | 2026-05-22 |
| High | Ransomware | Vega Corp: DragonForce Ransomware Attack | 2026-05-22 |
| Critical | CVE · KEV | CVE-2026-9082: Drupal Core SQL Injection Enables Privilege Escalation and RCE | 2026-05-22 |
| High | Breach | German University Hospitals: Third-Party Billing Provider Breach | 2026-05-22 |
| High | Ransomware | Vial Agro: Qilin Ransomware Attack | 2026-05-22 |
| High | Breach | T-Mobile and Sprint: 58 Million Consumer Lines Auctioned on Dark Web | 2026-05-22 |
| High | Breach | NYC Hospital Network: 1.8M Patient Records and Biometric Fingerprints Exfiltrated | 2026-05-22 |
| High | Ransomware | AdvancedHEALTH: DragonForce Ransomware Breach | 2026-05-22 |
| High | Breach | Almerys: 44 Million Healthcare Records Listed on Hacker Forum | 2026-05-22 |
| High | Ransomware | Exchange Group: Pear Ransomware Attack | 2026-05-22 |
| High | Ransomware | Liberty Mutual: Everest Ransomware Breach Exposes 15,000+ Policyholders | 2026-05-22 |
| High | Ransomware | Stuttgart: Rhysida Ransomware Data Theft Claim | 2026-05-22 |
| High | Ransomware | Porter W Yett: Qilin Ransomware Attack | 2026-05-22 |
| High | Ransomware | Beacon Mutual: Ransomware Attack Exposes 132,000 Rhode Islanders | 2026-05-22 |
| Critical | CVE · KEV | CVE-2026-6279: Unauthenticated RCE in Avada Builder for WordPress | 2026-05-21 |
| High | Ransomware | Kabushiki Gaisha Hodozuka Setsubi: Payload Ransomware Attack | 2026-05-21 |
| High | Breach | Perm National Research Polytechnic University: Dark Web Data Leak Exposes 360K+ Records | 2026-05-21 |
| Critical | CVE · KEV | CVE-2026-34926: Trend Micro Apex One On-Premise Directory Traversal Added to CISA KEV | 2026-05-21 |
| Critical | CVE · KEV | CVE-2026-6960: Unauthenticated Arbitrary File Upload in BookingPress Pro for WordPress | 2026-05-21 |
| High | Breach | Erie Family Health Centers: 570,000 Patient Records Exposed in 48-Day Network Intrusion | 2026-05-21 |
| High | Breach | AFC Ajax: Data Breach via Exposed APIs and Shared Keys | 2026-05-21 |
| High | Breach | Uruguay DNIC: Alleged Dark Web Leak of 5.8M Citizen Records | 2026-05-21 |
| Critical | CVE · KEV | CVE-2026-5118: Divi Form Builder WordPress Plugin Privilege Escalation to Admin | 2026-05-21 |
| High | Breach | Global Cardholders: B1ack's Stash Carding Marketplace Dump | 2026-05-21 |
| Critical | CVE · KEV | CVE-2025-34291: Langflow CORS Misconfiguration Enables Account Takeover and RCE | 2026-05-21 |
| High | Breach | Microsoft: Fox Tempest Malware-Signing-as-a-Service Disruption | 2026-05-21 |
| High | Ransomware | Monir Precision Monitoring: Qilin Ransomware Attack | 2026-05-20 |
| Critical | CVE · KEV | CVE-2008-4250: Microsoft Windows Server Service RPC Buffer Overflow Resurfaces on CISA KEV | 2026-05-20 |
| Critical | CVE · KEV | CVE-2026-7637: Unauthenticated PHP Object Injection in WordPress Boost Plugin | 2026-05-20 |
| High | Breach | Unit 221B: ShinyHunters Retaliation Campaign | 2026-05-20 |
| Critical | CVE · KEV | CVE-2009-1537: Microsoft DirectX QuickTime Parser Flaw Added to CISA KEV | 2026-05-20 |
| Critical | CVE · KEV | CVE-2010-0249: Internet Explorer Use-After-Free Resurfaces on CISA KEV | 2026-05-20 |
| High | Breach | Stewarts Care: Third-Party Recruiter Breach Exposes Staff Data | 2026-05-20 |
| Critical | CVE · KEV | CVE-2026-9139: Hard-Coded Credentials in Taiko AG1000-01A SMS Alert Gateway | 2026-05-20 |
| Critical | CVE · KEV | CVE-2026-9141: Authentication Bypass in Taiko AG1000-01A SMS Alert Gateway | 2026-05-20 |
| High | Breach | Nacogdoches Memorial Hospital: 2.5M Patient Records Exfiltrated in Network Intrusion | 2026-05-20 |
| Critical | CVE · KEV | CVE-2009-3459: Adobe Acrobat and Reader Heap-Based Buffer Overflow Resurfaces on CISA KEV | 2026-05-20 |
| High | Ransomware | Extant Aerospace: Ransomware Attack Exposes Employee SSNs at DoD Supplier | 2026-05-20 |
| High | Breach | VUMI: Dark Web Extortion Claim Over 300,000 Records | 2026-05-20 |
| Critical | CVE · KEV | CVE-2026-45498: Microsoft Defender Denial of Service Vulnerability | 2026-05-20 |
| Critical | CVE · KEV | CVE-2026-7284: Easy Elements for Elementor Plugin Allows Unauthenticated Admin Takeover | 2026-05-20 |
| Critical | CVE · KEV | CVE-2026-6555: Unauthenticated RCE in ProSolution WP Client Plugin via Arbitrary File Upload | 2026-05-20 |
| High | Breach | Uruguay DNIC: Alleged 5.8M Citizen Database Leak | 2026-05-20 |
| Critical | CVE · KEV | CVE-2010-0806: Internet Explorer Use-After-Free Resurfaces on CISA KEV | 2026-05-20 |
| High | Breach | GitHub: TeamPCP Internal Repo Breach | 2026-05-20 |
| High | Breach | SA Web Hosts and Telecoms: 'Black Matter' DDoS Extortion Campaign | 2026-05-20 |
| Critical | CVE · KEV | CVE-2026-41091: Microsoft Defender Link Following Flaw Lets Local Attackers Escalate to SYSTEM | 2026-05-20 |
| Critical | CVE · KEV | CVE-2026-20223: Cisco Secure Workload REST API Auth Bypass Grants Site Admin Access | 2026-05-20 |
| Critical | CVE · KEV | CVE-2026-4885: Unauthenticated Arbitrary File Upload in Piotnet Addons for Elementor Pro | 2026-05-19 |
| High | Breach | Arwini Niedersachsen: Kairos Ransomware Data Exfiltration | 2026-05-19 |
| High | Ransomware | Vacu-Lug: Akira Ransomware 40GB Data Heist | 2026-05-19 |
| High | Breach | Safaricom: Kenyan High Court Ruling on Telecom Data Breach | 2026-05-19 |
| Critical | CVE · KEV | CVE-2026-4883: Unauthenticated Arbitrary File Upload in Piotnet Forms WordPress Plugin | 2026-05-19 |
| High | Ransomware | Metaval: INC Ransom Claims 80GB Data Theft | 2026-05-19 |
| High | Breach | Aura: ShinyHunters Vishing Breach | 2026-05-19 |
| High | Breach | US Healthcare Sector: Multiple Breaches Expose Millions via HHS Tracker | 2026-05-19 |
| Critical | CVE · KEV | CVE-2026-43633: Unauthenticated Root RCE in HestiaCP Web Terminal | 2026-05-19 |
| High | Breach | Gîtes de France: Customer Data Theft Exposes 389,000 Records | 2026-05-19 |
| High | Breach | Tabiq: 1M+ Passports Exposed via Public S3 Bucket | 2026-05-19 |
| High | Breach | Enterprise Cloud Tenant: Storm-2949 Identity-Driven Breach | 2026-05-19 |
| High | Breach | Pitney Bowes: ShinyHunters Salesforce Breach | 2026-05-18 |
| High | Breach | Canvas (Instructure): Global LMS Breach Impacting 9,000 Institutions | 2026-05-18 |
| Critical | CVE · KEV | CVE-2026-42822: Critical Authentication Bypass in Azure Local Disconnected Operations | 2026-05-18 |
| High | Breach | US Fuel Infrastructure: Suspected Iranian ATG Intrusions | 2026-05-18 |
| High | Ransomware | Clinica Avellaneda: Qilin Ransomware Attack | 2026-05-18 |
| Critical | CVE · KEV | CVE-2026-45230: Unauthenticated Path Traversal in DumbAssets Enables Arbitrary File Deletion | 2026-05-18 |
| High | Ransomware | URG OEM: Nova Ransomware Attack | 2026-05-18 |
| High | Breach | 7-Eleven: ShinyHunters Salesforce Breach | 2026-05-18 |
| High | Ransomware | Instructure: ShinyHunters Canvas Extortion | 2026-05-18 |
| High | Breach | CISA: Contractor Leaks AWS GovCloud Keys on Public GitHub | 2026-05-18 |
| High | Breach | NYC Health + Hospitals: 1.8M Patient Records Stolen in Breach | 2026-05-18 |
| High | Ransomware | WTI Transport: Chaos Ransomware 72-Hour Ultimatum | 2026-05-18 |
| High | Breach | Samuel Shay: Handala Claims Breach of Israeli Normalization Architect | 2026-05-18 |
| High | Breach | TransUnion: Consumer Data Breach Exposes 4.4 Million Records | 2026-05-18 |
| High | Breach | Oracle: 2026 Multi-System Cloud and Health Data Breach | 2026-05-18 |
| High | Breach | Belambra: Tourism Sector Data Breach Wave | 2026-05-18 |
| Critical | CVE · KEV | CVE-2026-8836: Critical Stack Buffer Overflow in lwIP SNMPv3 USM Handler | 2026-05-18 |
| High | Breach | Irish Revenue Commissioners: 137 Staff Exposed in Pitney Bowes Ransomware Breach | 2026-05-18 |
| High | Breach | Tokee: 1.2M User Profiles Exposed via Unsecured MongoDB | 2026-05-18 |
| High | Breach | Samuel Shay: Handala Claims Breach of Israeli Normalization Architect | 2026-05-18 |
| Critical | CVE · KEV | CVE-2024-3400: Critical Command Injection in Palo Alto Networks PAN-OS GlobalProtect | 2026-05-17 |
| Critical | CVE · KEV | CVE-2026-20133: Cisco Catalyst SD-WAN Manager Leaks Sensitive Information to Remote Attackers | 2026-05-17 |
| Critical | CVE · KEV | CVE-2025-48700: Zimbra Classic UI XSS Exploited in the Wild | 2026-05-17 |
| Critical | CVE · KEV | CVE-2024-1708: ConnectWise ScreenConnect Path Traversal Enables Remote Code Execution | 2026-05-17 |
| Critical | CVE · KEV | CVE-2026-35616: Critical Unauthenticated RCE in Fortinet FortiClient EMS | 2026-05-17 |
| High | Breach | American Lending Center: 123,000 Individuals Exposed in Network Intrusion | 2026-05-17 |
| High | Ransomware | Grafana Labs: Source Code Theft and Ransom Refusal | 2026-05-17 |
| Critical | CVE · KEV | CVE-2026-0300: Critical PAN-OS Captive Portal RCE Under Active Exploitation | 2026-05-17 |
| Critical | CVE · KEV | CVE-2026-21385: Qualcomm Chipset Memory Corruption Flaw Added to CISA KEV | 2026-05-17 |
| Critical | CVE · KEV | CVE-2024-57726: SimpleHelp Privilege Escalation Flaw Hits CISA KEV with Known Ransomware Use | 2026-05-17 |
| Critical | CVE · KEV | CVE-2026-6973: Authenticated RCE in Ivanti Endpoint Manager Mobile | 2026-05-17 |
| High | Breach | African National Congress: Black Axe Data Breach | 2026-05-17 |
| Critical | CVE · KEV | CVE-2023-21529: Microsoft Exchange Server Deserialization Flaw Exploited in Medusa Ransomware Campaigns | 2026-05-17 |
| Critical | CVE · KEV | CVE-2026-24512: ingress-nginx Path Injection Enables Cluster-Wide Secret Disclosure and RCE | 2026-05-17 |
| Critical | CVE · KEV | CVE-2026-20122: Cisco Catalyst SD-WAN Manager Privileged API Abuse Lets Read-Only Users Escalate to vManage | 2026-05-17 |
| Critical | CVE · KEV | CVE-2026-41940: cPanel & WHM Authentication Bypass Under Active Ransomware Exploitation | 2026-05-17 |
| Critical | CVE · KEV | CVE-2020-9715: Adobe Acrobat Use-After-Free Enables Code Execution | 2026-05-17 |
| Critical | CVE · KEV | CVE-2024-27199: JetBrains TeamCity Path Traversal Enables Limited Admin Actions | 2026-05-17 |
| Critical | CVE · KEV | CVE-2009-0238: Microsoft Excel Invalid Object Access Enables Remote Code Execution | 2026-05-17 |
| Critical | CVE · KEV | CVE-2026-34621: Adobe Acrobat and Reader Prototype Pollution Enables Arbitrary Code Execution | 2026-05-17 |
| High | Breach | Moroccan Government Platforms: Fexus Claims Massive govma Breach | 2026-05-17 |
| Critical | CVE · KEV | CVE-2012-1854: Microsoft VBA Insecure Library Loading Resurfaces on CISA KEV | 2026-05-17 |
| Critical | CVE · KEV | CVE-2026-3502: TrueConf Client Update Mechanism Lacks Integrity Verification | 2026-05-17 |
| Critical | CVE · KEV | CVE-2026-20128: Cisco Catalyst SD-WAN Manager Stores DCA Credentials in Recoverable Format | 2026-05-17 |
| Critical | CVE · KEV | CVE-2026-39987: Pre-Auth RCE in Marimo Python Notebook | 2026-05-17 |
| Critical | CVE · KEV | CVE-2026-21643: Critical SQL Injection in Fortinet FortiClient EMS | 2026-05-17 |
| Critical | CVE · KEV | CVE-2026-5281: Use-After-Free in Chrome's Dawn Graphics Layer Hits CISA KEV | 2026-05-17 |
| Critical | CVE · KEV | CVE-2026-42208: Unauthenticated SQL Injection in BerriAI LiteLLM Proxy | 2026-05-17 |
| Critical | CVE · KEV | CVE-2026-20182: Cisco Catalyst SD-WAN Authentication Bypass Hands Attackers Admin Control | 2026-05-17 |
| Critical | CVE · KEV | CVE-2025-29635: D-Link DIR-823X Command Injection Added to CISA KEV | 2026-05-17 |
| High | Breach | Senegal Public Treasury: Cyberattack and Data Extortion Threat | 2026-05-17 |
| Critical | CVE · KEV | CVE-2026-31431: Linux Kernel algif_aead Flaw Enables Local Privilege Escalation | 2026-05-17 |
| Critical | CVE · KEV | CVE-2024-57728: SimpleHelp Zip Slip Path Traversal Enables Remote Code Execution | 2026-05-17 |
| Critical | CVE · KEV | CVE-2026-32202: Windows Shell Spoofing Flaw Added to CISA KEV | 2026-05-17 |
| Critical | CVE · KEV | CVE-2023-27351: PaperCut NG/MF Authentication Bypass Added to CISA KEV | 2026-05-17 |
| Critical | CVE · KEV | CVE-2024-7399: Samsung MagicINFO 9 Server Path Traversal Enables Arbitrary File Write as SYSTEM | 2026-05-17 |
| Critical | CVE · KEV | CVE-2026-34197: Apache ActiveMQ Jolokia Code Injection Lands on CISA KEV | 2026-05-17 |
| Critical | CVE · KEV | CVE-2026-1340: Critical Code Injection in Ivanti Endpoint Manager Mobile | 2026-05-17 |
| High | Ransomware | United Quality Cooperative: INC Ransom Ransomware Attack | 2026-05-17 |
| Critical | CVE · KEV | CVE-2026-33825: Microsoft Defender Local Privilege Escalation Added to CISA KEV | 2026-05-17 |
| Critical | CVE · KEV | CVE-2026-32201: SharePoint Server Spoofing Flaw Added to CISA KEV | 2026-05-17 |
| Critical | CVE · KEV | CVE-2023-36424: Windows CLFS Driver Elevation of Privilege Flaw Added to CISA KEV | 2026-05-17 |
| Critical | CVE · KEV | CVE-2025-32975: Quest KACE SMA Authentication Bypass Enables Full Admin Takeover | 2026-05-17 |
| Critical | CVE · KEV | CVE-2025-60710: Windows Host Process Link-Following Flaw Exploited in the Wild | 2026-05-17 |
| Critical | CVE · KEV | CVE-2025-2749: Authenticated Path Traversal to RCE in Kentico Xperience | 2026-05-17 |
| Critical | CVE · KEV | CVE-2026-42897: Microsoft Exchange Server XSS Flaw Added to CISA KEV | 2026-05-17 |
| High | Breach | Samuel Shay: Handala Hackers Claim Breach of Abraham Accords Architect | 2026-05-17 |
| Critical | CVE · KEV | CVE-2026-22719: Unauthenticated Command Injection in VMware Aria Operations | 2026-05-17 |
| High | Breach | Bono Juana Azurduy (Bolivia): Public Sector Data Leak by konata_izumi_shell | 2026-05-16 |
| High | Breach | Florida Reliability Coordinating Council: Unauthorized File Copying Exposes SSNs | 2026-05-16 |
| High | Breach | France Titres: Massive State ID Database Breach | 2026-05-16 |
| High | Breach | Aintree Hospital: Insider Snooping on Southport Attack Victims | 2026-05-16 |
| High | Breach | Qantas: Third-Party Contact Centre Platform Breach | 2026-05-16 |
| High | Breach | NHS Aintree Hospital: Insider Snooping on Southport Attack Victims | 2026-05-16 |
| High | Breach | US Tiger Securities: Ransomware Breach Exposes SSNs and Medical Data | 2026-05-16 |
| High | Breach | US Gas Stations: Suspected Iranian Intrusion Into Fuel Tank Readers | 2026-05-16 |
| High | Ransomware | Spirit Medical Transport: Qilin Ransomware Attack | 2026-05-16 |
| High | Breach | Opexus: Insider Revenge Attack by Akhter Twins | 2026-05-16 |
| High | Breach | Pierre et Vacances-Center Parcs: Platform Vulnerability Exploited | 2026-05-16 |
| High | Breach | Comcast: $117M Settlement Over Confirmed Customer Data Breach | 2026-05-16 |
| High | Ransomware | York City, PA: July 2025 Ransomware Attack | 2026-05-15 |
| High | Breach | British Airways: Infrastructure Destruction Squad Claims Breach | 2026-05-15 |
| High | Breach | OpenLoop Health: Telehealth Breach Exposes 716,000 Patients | 2026-05-15 |
| High | Breach | OpenAI: Mini Shai-Hulud npm Supply Chain Worm | 2026-05-15 |
| High | Breach | Mistral AI: TeamPCP Supply Chain Breach | 2026-05-15 |
| High | Breach | Abrigo: ShinyHunters Pay or Leak Extortion | 2026-05-15 |
| High | Breach | Excelas: Cl0p Ransomware Breach Exposes Medical Records | 2026-05-15 |
| High | Ransomware | Bluize: Qilin Ransomware Claim | 2026-05-15 |
| High | Breach | Rockstar Games: ShinyHunters Snowflake Token Abuse | 2026-05-14 |
| High | Ransomware | Ahmed Al-Kadi Private Hospital: Ransomware Breach Encrypts Portions of IT Environment | 2026-05-13 |
| High | Ransomware | Earth Systems: INC Ransom Claims 600GB Breach | 2026-05-13 |
| High | Breach | PACI Kuwait: Alleged State Level Infrastructure Breach | 2026-05-13 |
| High | Breach | Thales Group: Alleged Data Leak Tied to LuxTrust Identity Infrastructure | 2026-05-13 |
| High | Breach | Chevin Fleet Solutions: FleetWave SaaS Breach Exposes Customer Data | 2026-05-13 |
| High | Breach | Lockheed Martin: APT Iran Data Exfiltration | 2026-05-13 |
| High | Ransomware | West Pharmaceutical Services: Ransomware Attack Disrupts Global Manufacturing | 2026-05-13 |
| High | Breach | Checkmarx: TeamPCP Jenkins Plugin Supply Chain Attack | 2026-05-12 |
| High | Ransomware | Foxconn: Nitrogen Ransomware 8TB Data Theft | 2026-05-12 |
| High | Breach | Enterprise Cloud Environments: FulcrumSec Extortion Campaign | 2026-05-12 |
| High | Breach | Hong Kong Canvas Users: ShinyHunters Data Breach | 2026-05-12 |
| High | Breach | Canvas LMS: ShinyHunters Global Breach | 2026-05-11 |
| High | Ransomware | Unoaerre: Ransomware Attack Halts Italian Jewelry Manufacturing | 2026-05-11 |
| High | Breach | Egypt Ministry of Civil Aviation: Alleged Dark Web Breach | 2026-05-11 |
| High | Breach | Indian Customs Department: Insider Data Theft to China-Based Firms | 2026-05-11 |
| High | Breach | Aerospace and Drone Operators: HeartlessSoul Espionage Campaign | 2026-05-11 |
| High | Breach | Medtronic: ShinyHunters Steals 9 Million Records | 2026-05-11 |
| High | Ransomware | VP Brands International: LockBit 5.0 Ransomware Breach | 2026-05-11 |
| High | Breach | SFR: Alleged Dark Web Data Breach Claim | 2026-05-11 |
| High | Ransomware | AMS Group: Stormous Ransomware 33GB Data Dump | 2026-05-11 |
| High | Breach | Vodafone: Lapsus$ Source Code Leak | 2026-05-11 |
| High | Breach | Maryland University: Exfil-Ware Ransomware Breach | 2026-05-11 |
| High | Ransomware | TDS Telecommunications: TheGentlemen Ransomware Attack | 2026-05-11 |
| High | Breach | Coupang Taiwan: 33.7 Million Account Data Breach | 2026-05-10 |
| High | Ransomware | Minidoka Memorial Hospital: Blackwater Ransomware Attack | 2026-05-10 |
| High | Ransomware | Serveis Mèdics Penedès: SafePay Ransomware 48-Hour Extortion | 2026-05-10 |
| High | Breach | Canada Goose: ShinyHunters Historical Data Leak | 2026-05-09 |
| High | Breach | Zara: ShinyHunters Third-Party Breach | 2026-05-09 |
| High | Ransomware | US Healthcare and Middle East Org: Lazarus Group Medusa Ransomware | 2026-05-09 |
| High | Breach | US Federal Agencies: Insider Threat Database Destruction | 2026-05-09 |
| High | Breach | CarGurus: ShinyHunters Voice Phishing Breach | 2026-05-09 |
| High | Breach | US Federal Agencies: Insider Threat Database Destruction | 2026-05-09 |
| High | Breach | Mexican Water Utility: Claude AI Abused in OT Compromise Attempt | 2026-05-09 |
| High | Breach | US Federal Agencies: Insider Database Destruction by Terminated Contractors | 2026-05-09 |
| High | Ransomware | Nostrum Corporation: The Gentlemen Ransomware Attack | 2026-05-08 |
| High | Breach | Government Agencies: UAT-8302 China-Linked Espionage Campaign | 2026-05-08 |
| High | Breach | Canadian Government: $8.7M Settlement Over 2020 CRA Account Breach | 2026-05-08 |
| High | Ransomware | University of Pennsylvania: ShinyHunters Canvas Ransom Attack | 2026-05-08 |
| High | Breach | ANTS (France Titres): Teen Hacker Breaches National ID Agency | 2026-05-08 |
| High | Breach | Flemish Universities and VUB: ShinyHunters Canvas Breach | 2026-05-08 |
| High | Ransomware | Change Healthcare: BlackCat Ransomware Attack | 2026-05-08 |
| High | Ransomware | Liberty Mutual: Everest Ransomware Leak | 2026-05-07 |
| High | Breach | Finland's Valtori: Suspected State Espionage Breach | 2026-05-07 |
| High | Ransomware | Expeditor Systems: Incransom Ransomware Attack | 2026-05-07 |
| High | Breach | Vercel: ShinyHunters OAuth Token Supply Chain Attack | 2026-05-07 |
| High | Ransomware | TTT Corporation: Stormous Ransomware 5TB Data Theft | 2026-05-07 |
| High | Breach | Woflow: ShinyHunters Leak Exposes 447,600 Accounts | 2026-05-07 |
| High | Ransomware | Energy Action: SafePay Ransomware Breach | 2026-05-07 |
| High | Ransomware | Sandhills Medical Foundation: Ransomware Attack | 2026-05-07 |
| High | Breach | Oman Government Ministries: Iranian-Nexus Webshell Intrusion | 2026-05-06 |
| High | Breach | INSS: Handala Multi-Year Breach | 2026-05-06 |
| High | Breach | DigiCert: Screensaver Phish Yields EV Code Signing Certificates | 2026-05-06 |
| High | Breach | Sterling Bank: ByteToBreach Data Breach | 2026-05-06 |
| High | Ransomware | Russian Government: Karakurt Ransomware Gang Insider Access | 2026-05-06 |
| High | Breach | City of Suffolk, Virginia: Cloak Ransomware Data Breach | 2026-05-05 |
| High | Ransomware | Ardmore Police Department: Phishing-Triggered Ransomware Attack | 2026-05-05 |
| High | Breach | Rhode Island RIBridges: Brain Cipher Ransomware Settlement | 2026-05-05 |
| High | Ransomware | Mediaworks: World Leaks Ransomware Breach | 2026-05-05 |
| High | Ransomware | Frost Bank: Everest Ransomware Vendor Breach | 2026-05-05 |
| High | Breach | Canvas LMS: ShinyHunters Claims 3.65TB Breach Affecting 275M Users | 2026-05-04 |
| High | Breach | TriZetto Provider Solutions: Web Portal Breach Exposes 3.4M Patients | 2026-05-04 |
| High | Breach | Conduent Business Services: Ransomware Breach of 25M Americans | 2026-05-04 |
| High | Breach | Lotte Card: 2.97M Customer Data Breach | 2026-05-04 |
| High | Breach | Prime Properties: M3rx Ransomware Darknet Leak | 2026-05-04 |
| High | Breach | NVIDIA GeForce NOW: ShinyHunters Claims Millions of User Records Stolen | 2026-05-04 |
| High | Breach | Capita: Civil Service Pension Data Exposure | 2026-05-04 |
| High | Breach | Capital One: $425M Settlement Approved for 2019 Cloud Breach | 2026-05-04 |
| High | Ransomware | Cushman & Wakefield: ShinyHunters Ransomware Attack | 2026-05-04 |
| High | Breach | Alberta Residents: Centurion Project Data Exposure | 2026-05-04 |
| High | Breach | Sistemi Informativi: Salt Typhoon Espionage Breach | 2026-05-04 |
| High | Breach | MoneyForward: GitHub Credential Compromise | 2026-05-04 |
| High | Breach | US Navy: Handala Claims Personnel Data Breach | 2026-05-03 |
| High | Breach | European Commission: ShinyHunters Cloud Data Breach | 2026-05-03 |
| High | Breach | ANTS (France Titres): Teen Hacker Breaches National ID Agency | 2026-05-03 |
| High | Breach | Nepal Public Procurement System: Insider Bid-Rigging Hack Ring | 2026-05-03 |
| High | Breach | Trellix: Source Code Repository Breach | 2026-05-03 |
| High | Ransomware | Wyoming County Government: ThreeAM Ransomware Attack | 2026-05-03 |
| High | Ransomware | Orange: Babuk Ransomware Breach Claim | 2026-05-03 |
| Critical | CVE | cPanel Servers: Sorry Ransomware Mass Exploitation | 2026-05-03 |
| High | Breach | Instructure: Canvas LMS Maker Discloses Cyber Incident | 2026-05-03 |
| High | Breach | Pakistan Government and Military: Alleged 39GB Dark Web Leak | 2026-05-02 |
| High | Breach | McGraw-Hill: ShinyHunters Salesforce Breach | 2026-05-02 |
| High | Ransomware | Follett Software LLC: ShinyHunters Ransomware Leak Listing | 2026-05-02 |
| High | Breach | MST (Sanko Makina/ASKO Holding): Blacknevas 7-Month Cyber Siege | 2026-05-02 |
| High | Breach | Aman: ShinyHunters Pay or Leak Extortion | 2026-05-02 |
| High | Breach | Checkmarx KICS: Supply Chain Compromise via Trojanized Docker and IDE Extensions | 2026-05-02 |
| High | Breach | France Titres (ANTS): Teen Hacker Breaches State ID Agency | 2026-05-02 |
| High | Breach | Moldova CNAM: Mysterious Healthcare Database Breach | 2026-05-02 |
| High | Breach | Canonical: 313 Team DDoS and Extortion | 2026-05-02 |
| High | Breach | ZenBusiness: ShinyHunters Extortion Breach | 2026-05-02 |
| High | Ransomware | Adams County, PA: Ransomware Attack Disrupts County Services | 2026-05-02 |
| High | Breach | ChipSoft: Embargo Ransomware Breach | 2026-05-02 |
| High | Ransomware | KINAS Solicitors: BlackNevas Ransomware Breach | 2026-05-02 |
| High | Breach | PowerSchool: Teen Hacker Credential Theft Breach | 2026-05-02 |
| High | Breach | Medicare: Doctor Data Breach | 2026-05-02 |
| High | Breach | Canada Life: ShinyHunters Breach via Compromised Employee Account | 2026-05-02 |
| High | Ransomware | Integer Holdings: coinbasecartel Ransomware Breach | 2026-05-01 |
| High | Ransomware | Gregory Jewellers: Kairos Ransomware Breach | 2026-05-01 |
| High | Ransomware | Sandhills Medical Foundation: Inc Ransom Ransomware Breach | 2026-05-01 |
| High | Breach | Canadian Tire: 38.3 Million Customer Accounts Exposed in E-commerce Database Breach | 2026-05-01 |
| High | Ransomware | Prime Properties: M3rx Ransomware Breach | 2026-05-01 |
| High | Breach | SMSA Express: 1.2M Customer Shipment Records Listed for Sale by lulzintel | 2026-05-01 |
| High | Breach | Polymarket: xorcat Data Breach | 2026-04-30 |
| High | Breach | SAP: Mini Shai-Hulud npm Supply Chain Attack | 2026-04-30 |
| High | Breach | Cuban Embassy DC: Chinese State-Linked Espionage Breach | 2026-04-30 |
| High | Ransomware | Winona County, Minnesota: Ransomware Data Leak After Refusal to Pay | 2026-04-30 |
| High | Breach | Scattered Spider: Federal Charges Filed Against Teen Member Arrested in Finland | 2026-04-30 |
| High | Breach | Lower Hutt City Council: Phishing Compromise Exposes Resident Data | 2026-04-30 |
| High | Breach | Foreign Governments and Activists: I-Soon Contractor Leak | 2026-04-30 |
| High | Ransomware | Illinois and Texas Healthcare Providers: Insomnia Ransomware Breach | 2026-04-30 |
| High | Ransomware | UPSRTC: Third-Party Ransomware Attack Cripples Electronic Ticketing System | 2026-04-30 |
| High | Ransomware | City of Ardmore, Oklahoma: Ransomware Attack Exposes Resident Data | 2026-04-29 |
| High | Ransomware | STELIA Aerospace: Rhysida Ransomware Hits North American Systems | 2026-04-29 |
| High | Ransomware | Sumac Inc.: Incransom Ransomware Attack | 2026-04-29 |
| High | Breach | Vimeo: ShinyHunters Exfiltration via Anodot Supply Chain Breach | 2026-04-29 |
| High | Breach | US DOJ: Silk Typhoon MSS Contractor Extradited | 2026-04-28 |
| High | Ransomware | Synmosa Biopharma: DragonForce Ransomware Breach | 2026-04-28 |
| High | Breach | U.S. Justice System: Chinese State Hacker Xu Zewei Extradited | 2026-04-28 |
| High | Ransomware | Wm. Sopko & Sons Co.: DragonForce Ransomware Attack | 2026-04-28 |
| High | Breach | Pitney Bowes: ShinyHunters Extortion Leak | 2026-04-28 |
| High | Ransomware | Selex Gruppo Commerciale: INC Ransom Ransomware Breach | 2026-04-28 |
| High | Breach | Silk Typhoon: Alleged MSS Contract Hacker Extradited to US | 2026-04-28 |
| High | Breach | Fidelity: $1.25M Massachusetts Fine Over Customer Data Breach | 2026-04-28 |
| High | Breach | Pine Bluff School District: Business Email Compromise Wire Fraud | 2026-04-28 |
| High | Ransomware | Gelatissimo: DragonForce Ransomware Data Theft | 2026-04-28 |
| High | Breach | Lee & Lee Country Club: Suspected North Korean State-Sponsored Breach | 2026-04-27 |
| High | Ransomware | 100+ Global Enterprises: Coinbase Cartel Infostealer Extortion Spree | 2026-04-27 |
| High | Breach | U.S. Universities: Hafnium MSS Operative Extradited | 2026-04-27 |
| High | Breach | Generation Life: Third-Party Vendor Compromise | 2026-04-27 |
| High | Ransomware | Heinrichs Logistic: LockBit 5 Ransomware Listing | 2026-04-27 |
| High | Breach | Itron: Internal Network Breach Disclosed in SEC 8-K Filing | 2026-04-27 |
| High | Breach | Vodafone UK: LAPSUS$ Claims Internal Network Breach | 2026-04-27 |
| High | Breach | Marcus & Millichap: ShinyHunters Salesforce Extortion | 2026-04-27 |
| High | Ransomware | BELFOR Asia: INC Ransom Ransomware Listing | 2026-04-27 |
| High | Ransomware | Merlo.de: LockBit5 Ransomware Listing | 2026-04-26 |
| High | Breach | Medtronic: IT Systems Cybersecurity Breach Disclosed | 2026-04-26 |
| High | Ransomware | TruGreen: Incransom Ransomware Double Extortion | 2026-04-26 |
| High | Breach | Southern Illinois Dermatology: Hacking Incident Exposes 160,312 Patients | 2026-04-26 |
| High | Breach | Transport Workers Union Local 100: Confirmed Data Breach Affecting Up to 100,000 Records | 2026-04-26 |
| High | Ransomware | Buckley Powder and Leistritz Turbine Technology: Qilin Ransomware Double Extortion | 2026-04-26 |
| High | Breach | BePrime: Admin Account Compromise via Missing MFA | 2026-04-26 |
| High | Breach | Retail and Hospitality: BlackFile Extortion Campaign | 2026-04-26 |
| High | Ransomware | NPK Fertilizer Sdn Bhd: Lamashtu Ransomware Attack | 2026-04-25 |
| High | Breach | Sagent Pharmaceuticals: Worldleaks Network Intrusion Exposes SSNs | 2026-04-25 |
| High | Breach | LACOE: Tax Portal Breach and Employee Identity Theft | 2026-04-25 |
| High | Ransomware | Five U.S. Victim Organizations: Insider Leak to BlackCat/ALPHV Ransomware | 2026-04-25 |
| High | Breach | ADT: ShinyHunters Vishing Breach | 2026-04-25 |
| High | Ransomware | AT&T Careers: Everest Ransomware Leak | 2026-04-25 |
| High | Ransomware | Progressive Propane: Qilin Ransomware Claims US Energy Sector Attack | 2026-04-25 |
| High | Breach | Ransomware Victims: Insider Betrayal by BlackCat Negotiator | 2026-04-25 |
| High | Ransomware | Studio Più: LockBit 5.0 Ransomware Attack | 2026-04-25 |
| High | Breach | Bitwarden CLI: Shai-Hulud Supply Chain Worm | 2026-04-25 |
| High | Breach | Harrison County, WV: Courthouse and Sheriff's Tax Office Cyber Incident | 2026-04-25 |
| High | Breach | Rich Products: Third-Party Phishing Breach via First Advantage | 2026-04-24 |
| High | Ransomware | Teamsters Local 773: Incransom Ransomware Attack | 2026-04-24 |
| High | Ransomware | Aptim: Coinbase Cartel Ransomware Attack | 2026-04-24 |
| High | Breach | Ameriprise Financial: Unauthorized Third-Party Data Access | 2026-04-24 |
| High | Ransomware | OrthopedicsNY: INC Ransom Attack Triggers $1.95M Penalty | 2026-04-24 |
| High | Breach | Udemy: ShinyHunters Claims 1.4M Record Breach | 2026-04-24 |
| High | Breach | Universal Pure: Six Week Network Intrusion Exposes SSNs and Medical Data | 2026-04-24 |
| High | Breach | French Institutions: HexDex Data Leak Campaign | 2026-04-24 |
| High | Ransomware | Manulife Wealth: Qilin Ransomware Claim | 2026-04-24 |
| High | Breach | French Government Agency: 19 Million Records Allegedly Stolen in Data Breach | 2026-04-24 |
| High | Breach | FOSPIBAY: SQL Injection Breach Exposes Peruvian Citizen Records | 2026-04-24 |
| High | Breach | Sri Lanka Finance Ministry: $3.7M Stolen in Payment Diversion Attack | 2026-04-24 |
| High | Breach | Carnival: ShinyHunters Breach Exposes 7.5M Loyalty Accounts | 2026-04-24 |
| High | Breach | ANTS France: 19 Million Records Allegedly Stolen in Confirmed Breach | 2026-04-24 |
| High | Breach | Epe Municipality: Resident Data Theft from Council Server | 2026-04-24 |
| High | Ransomware | Genealogy SA: SafePay Ransomware Data Theft | 2026-04-23 |
| High | Ransomware | Rusk County, Wisconsin: Qilin Ransomware Claim | 2026-04-23 |
| High | Breach | French Ministries: Hexdex Data Leaks | 2026-04-23 |
| High | Breach | Ransomware Victims: Insider Betrayal by BlackCat Negotiator | 2026-04-23 |
| High | Ransomware | Samuel I. White, PC: Anubis Ransomware Attack | 2026-04-23 |
| High | Breach | Favelle Favco: SafePay Ransomware Data Leak | 2026-04-23 |
| High | Breach | DigitalMint: ALPHV/BlackCat Insider Collusion | 2026-04-23 |
| High | Breach | Rituals: Customer Membership Database Breach | 2026-04-23 |
| High | Breach | UK Biobank: Researcher Insider Leak to Alibaba Marketplace | 2026-04-23 |
| High | Ransomware | Hospital Caribbean Medical Center: The Gentlemen Ransomware Attack | 2026-04-23 |
| High | Ransomware | Rheem Manufacturing: INC Ransom Ransomware Leak | 2026-04-22 |
| High | Breach | Valtori: Suspected State Espionage Breach | 2026-04-22 |
| High | Ransomware | Sprendlingen-Gensingen: Ransomware Attack Paralyzes Municipal Administration | 2026-04-22 |
| High | Ransomware | STERIMED: Qilin Ransomware Leak Site Listing | 2026-04-22 |
| High | Ransomware | Uniview Technologies: The Gentlemen Ransomware Listing | 2026-04-22 |
| High | Breach | Anthropic: Mythos AI Model Breached via Third-Party Vendor | 2026-04-22 |
| High | Ransomware | Nordenta: Kairos Ransomware Cartel Targets Danish Dental Supplier | 2026-04-22 |
| High | Breach | Bol: 400K Belgian Customer Records Allegedly Leaked | 2026-04-22 |
| High | Breach | US Federal Networks: Credential Abuse by Instagram Braggart | 2026-04-22 |
| High | Ransomware | Yamachi Electronics Philippines: INC Ransom Attack | 2026-04-22 |
| High | Breach | NSW Government: Insider Threat Data Breach | 2026-04-22 |
| High | Breach | Piazza San Marco: Infrastructure Destruction Squad Breaches Venice Flood Defenses | 2026-04-22 |
| High | Ransomware | Adaptavist Group: The Gentlemen Ransomware Breach | 2026-04-21 |
| High | Ransomware | ViaQuest: Anubis Ransomware Breach | 2026-04-21 |
| High | Ransomware | Engie: coinbasecartel Ransomware Attack | 2026-04-21 |
| High | Ransomware | Minidoka Memorial Hospital: Blackwater Ransomware Attack | 2026-04-21 |
| High | Ransomware | Champion Homes: DragonForce Ransomware Leak Site Listing | 2026-04-21 |
| High | Breach | NSW Treasury: Insider Threat Data Exfiltration | 2026-04-21 |
| High | Ransomware | NutraBio: Everest Ransomware Claim | 2026-04-21 |
| High | Breach | Nexus Grid: Cobalt Veil IoT Supply Chain Breach | 2026-04-21 |
| High | Breach | Qantas: 6 Million Customer Accounts Exposed in Third-Party Call Centre Breach | 2026-04-20 |
| High | Ransomware | Strata Republic: Kairos Ransomware Breach | 2026-04-20 |
| High | Breach | Metro Pakistan: Alleged Breach by Threat Actor xklahadore | 2026-04-20 |
| High | Ransomware | Complete Aircraft Group: Everest Ransomware Claim | 2026-04-20 |
| High | Breach | Champhunt: Cricket Fan Platform Breached, 224K User Records for Sale | 2026-04-20 |
| High | Ransomware | Canada Life Assurance: ShinyHunters Ransomware Breach | 2026-04-20 |
| High | Ransomware | Citizens Bank: Everest Ransomware Listing | 2026-04-20 |
| High | Ransomware | Aman Resorts: ShinyHunters Ransomware Attack | 2026-04-20 |
| High | Breach | Cylance: 34M Record Database Offered for Sale on Dark Web | 2026-04-20 |
| High | Breach | Seiko USA: Website Defacement and Shopify Data Extortion | 2026-04-20 |
| High | Breach | IDMerit: Unsecured MongoDB Exposes 1 Billion Identity Records | 2026-04-20 |
| High | Breach | Polmed: ShinyHunters Ransomware Breach | 2026-04-20 |
| High | Breach | ANTS (ants.gouv.fr): IDOR Flaw Exposes 19M French Identity Records | 2026-04-20 |
| High | Ransomware | 7-Eleven: ShinyHunters Claims Salesforce Breach | 2026-04-20 |
| High | Breach | LAUSD & Edgenuity: 4M Student Records Listed for Sale via Snowflake Breach | 2026-04-20 |
| High | Ransomware | Securitevolfeu: CoinbaseCartel Ransomware Listing | 2026-04-19 |
| High | Breach | DarkForums: PwnForums Database Leak Exposes 44K Cybercriminal IPs | 2026-04-19 |
| High | Ransomware | Millennium Dental Technologies: Termite Ransomware Attack | 2026-04-19 |
| High | Breach | Kelp DAO: $293M LayerZero Cross-Chain Bridge Exploit | 2026-04-19 |
| High | Ransomware | Altpro: Coinbasecartel Ransomware Attack | 2026-04-19 |
| High | Ransomware | HS Technology Group: Qilin Ransomware Attack | 2026-04-19 |
| High | Breach | Carnival Corporation: ShinyHunters Extortion Breach | 2026-04-19 |
| High | Breach | Vercel: ShinyHunters Internal Systems Breach | 2026-04-19 |
| High | Ransomware | Pharmathek: Akira Ransomware Listing | 2026-04-19 |
| High | Ransomware | Nanometrics: Qilin Ransomware Claim | 2026-04-19 |
| High | Ransomware | SOGO Auction: RansomExx Ransomware Breach | 2026-04-19 |
| High | Breach | PowerSchool: Teen Hacker Sentenced for Historic Student Data Breach | 2026-04-19 |
| High | Ransomware | ASTM Group: CoinbaseCartel Ransomware Claim | 2026-04-19 |
| High | Breach | Hims & Hers Health: Social Engineering Breach Exposes Support Tickets | 2026-04-19 |
| High | Breach | Conrad Capital Management: Unknown Third Party Intrusion Exposes SSNs and Financial Data | 2026-04-18 |
| High | Breach | Trivy Ecosystem: Vect Ransomware Supply Chain Extortion | 2026-04-18 |
| High | Ransomware | HBX Group: Qilin Ransomware Leak Site Listing | 2026-04-18 |
| High | Breach | TruView BSI: Background Check Firm Confirms 2024 Breach Exposing SSNs | 2026-04-18 |
| High | Breach | Europa.eu: IAM Misconfiguration Breach by ShinyHunters | 2026-04-18 |
| High | Breach | Phoenix Art Museum: Unauthorized Network Intrusion Exposes SSNs | 2026-04-18 |
| High | Breach | Eurail: Data Breach Exposes 300,000+ Travelers | 2026-04-18 |
| High | Ransomware | medicalnetworks CJ GmbH: DragonForce Ransomware Breach | 2026-04-18 |
| High | Breach | Amtrak: ShinyHunters Salesforce Breach | 2026-04-18 |
| High | Breach | Kemper Corporation: ShinyHunters Salesforce Leak | 2026-04-18 |
| High | Breach | LA County Office of Education: W-2 Vendor Breach Enables Tax Refund Fraud | 2026-04-18 |
| High | Breach | National Supercomputing Center Tianjin: FlamingChina Data Theft | 2026-04-18 |
| High | Breach | Mossad and Shin Bet: Handala Claims Intelligence Breach | 2026-04-17 |
| High | Breach | Nigeria CAC: Corporate Registry Breach Triggers NITDA Probe | 2026-04-17 |
| High | Breach | PicBackMan: Cloud Backup Database Leak Exposes User Credentials | 2026-04-17 |
| High | Breach | Take-Two Interactive: ShinyHunters Snowflake Breach | 2026-04-17 |
| High | Ransomware | Stockton Cardiology: GENESIS Ransomware Breach | 2026-04-17 |
| High | Breach | French Ministry of National Education: Student Data Exfiltration | 2026-04-17 |
| High | Breach | Comcast Xfinity: Citrix Bleed Exploitation Reaches $117.5M Settlement | 2026-04-17 |
| High | Breach | Basic-Fit: 1 Million Members Exposed in European Data Breach | 2026-04-17 |
| High | Breach | Axios Supply Chain: North Korean UNC1069 Crypto Heist | 2026-04-17 |
| High | Breach | Longevity Health Plan: Confirmed Healthcare Data Breach | 2026-04-17 |
| High | Breach | Hellenic National Defense General Staff: Russia-Linked Email Breach | 2026-04-17 |
| High | Ransomware | Gruppo ICM SPA: Qilin Ransomware Attack | 2026-04-17 |
| High | Breach | Humana: Vendor Software Vulnerability Exposes Customer Data Across Six States | 2026-04-17 |
| High | Breach | Grinex: Suspected Western Intelligence Crypto Heist | 2026-04-17 |
| High | Breach | Ukrainian Hospitals and Governments: UAC-0247 Data Theft Campaign | 2026-04-17 |
| High | Ransomware | Canada Goose: Coinbasecartel Ransomware Claim | 2026-04-17 |
| High | Breach | Standard Bank: 1.2TB Data Leak Exposes Credit Card Details | 2026-04-17 |
| High | Breach | OFPPT Morocco: 400K Student Records Leaked via MyWay Platform | 2026-04-16 |
| High | Breach | Ukrainian Prosecutors: Fancy Bear Email Compromise Campaign | 2026-04-16 |
| High | Breach | Khyber Pakhtunkhwa Government: Admin Database Leak Exposes MD5 Credentials | 2026-04-16 |
| High | Breach | Banco BBVA: Customer Database Leaked by Threat Actor MAGO SPEAK | 2026-04-16 |
| High | Breach | Chipsoft: Ransomware Attack Exposes Dutch Hospital Patient Data | 2026-04-16 |
| High | Breach | McGraw-Hill: ShinyHunters Compromise Salesforce Platform, 45 Million Records Exposed | 2026-04-16 |
| High | Breach | Chekin and Gastrodat: Massive Booking Data Theft Exposes 5 Million Hotel Guests | 2026-04-16 |
| High | Breach | Romanian Air Force: Russian-Linked Hackers Compromise 67 Email Accounts | 2026-04-16 |
| High | Breach | Signature Healthcare: Anubis Ransomware Attack Disrupts Hospital Operations | 2026-04-16 |
| High | Ransomware | Autovista: Ransomware Disrupts Automotive Data Services | 2026-04-16 |
| High | Ransomware | Dencom New Zealand: Krybit Ransomware Breach | 2026-04-16 |
| High | Breach | RCI Hospitality: Cyberattack Exposes Corporate and Customer Records | 2026-04-16 |
| High | Breach | Booking.com: Millions of Customer Reservations Exposed in Storm-1865 Supply Chain Breach | 2026-04-16 |
| High | Breach | Hallmark: ShinyHunters Dump 6.2M Customer Records After Failed Extortion | 2026-04-16 |
| High | Ransomware | Cookeville Regional Medical Center: Rhysida Ransomware Attack Exposes 337K Patient Records | 2026-04-16 |
| High | Breach | Mexican Government Agencies: AI-Powered Solo Breach Campaign | 2026-04-15 |
| High | Breach | Rockstar Games: ShinyHunters Breach Exposes 78.6 Million Records via Snowflake | 2026-04-15 |
| High | Breach | Israeli Unit 8200: Handala Hacker Group Claims Breach Exposing 80 Senior Officers | 2026-04-15 |
| High | Breach | PowerSchool: Gen Z Hacker Confirms $2.8M Extortion After Credential Breach | 2026-04-15 |
| High | Breach | National Supercomputing Center Tianjin: Six-Month Silent Breach by FlamingChina | 2026-04-15 |
| High | Ransomware | Eldorado Trading Group: DragonForce Ransomware Attack | 2026-04-15 |
| High | Breach | Mercor AI — LiteLLM Supply Chain Attack Breach | 2026-04-05 |
| High | Breach | Drift Cryptocurrency Exchange — North Korea Social Engineering Attack | 2026-04-05 |
| High | Breach | FBI Surveillance System — China-Linked Breach Pen Register Data Exposure | 2026-04-05 |
| High | Breach | Hong Kong Hospital Authority — Patient Data Breach | 2026-04-05 |
| High | Ransomware | Advanced Vehicle Assemblies — Nightspire Ransomware Attack | 2026-04-05 |
| High | Ransomware | Shwapno Bangladesh Supermarket — Ransomware Attack Customer Data Breach | 2026-04-05 |
| High | Ransomware | United Finance Egypt — Ransomware Attack Financial Services Breach | 2026-04-05 |
| High | Ransomware | Uffizi Gallery Florence — Medusalocker Ransomware Attack Cultural Heritage Institution | 2026-04-05 |
| High | Breach | Hims & Hers Telehealth Platform — Customer Support System Breach | 2026-04-05 |
| High | Ransomware | Groupe SERAP — Akira Ransomware Attack Agricultural Equipment Manufacturer | 2026-04-05 |
| High | Breach | Hasbro — Major Cyber Incident and Operational Disruption | 2026-04-05 |
| High | Ransomware | Minot Water Treatment Plant — Critical Infrastructure Ransomware Attack | 2026-04-05 |
| High | Breach | Nacogdoches Memorial Hospital — Patient Data Breach | 2026-04-05 |
| High | Ransomware | Charles River Insurance — Akira Ransomware Attack Insurance Sector | 2026-04-05 |
| High | Ransomware | Nissan Automotive — Everest Ransomware Third-Party Vendor Attack | 2026-04-04 |
| High | Breach | SUTEX Ltda Colombian Textile — DragonForce Ransomware Attack | 2026-04-04 |
| High | Breach | PSK Wind Technologies - Handala Iran-Linked Defense Contractor Breach | 2026-04-04 |
| High | Breach | FSSAI India Food Authority — Official Document Breach | 2026-04-04 |
| High | Breach | Asmar Schor & McKenna Construction Law Firm — DragonForce Ransomware Attack | 2026-04-04 |
| High | Breach | Adobe — Mr. Raccoon BPO Supply Chain Attack | 2026-04-04 |
| High | Breach | Bunch Ltd. Canadian Constructor — DragonForce Ransomware Attack | 2026-04-04 |
| High | Breach | Anthropic Claude Code Source Code Leaked via npm Misconfiguration | 2026-04-04 |
| High | Ransomware | Manage My Health New Zealand — Kazu Ransomware Healthcare Attack | 2026-04-04 |
| High | Breach | Cisco & Salesforce — CRM Data Breach | 2026-04-03 |
| High | Breach | Corewell Health — 19,000 Patients' Medical and Personal Data Compromised in Michigan Hospital Network Breach | 2026-04-01 |
| High | Ransomware | UMMC Hit by Medusa Ransomware — $800K Demanded, 1TB of Patient and Employee Data Exfiltrated | 2026-04-01 |
| High | Breach | CareCloud — Confirmed Breach of Electronic Health Records System Exposes Patient Data Across Provider Network | 2026-04-01 |
| High | Breach | Feníe Energía — Unattributed Data Exfiltration, 1.7M Records | 2026-03-31 |
| High | Breach | Tamir Pardo (Former Mossad Chief) — Handala Email Breach | 2026-03-31 |
| High | Breach | axios npm Supply Chain Attack — Hijacked Maintainer Drops Multi-Platform RAT | 2026-03-31 |
| High | Ransomware | Stats SA — XP95 Cyber-Extortion | 2026-03-30 |
| High | Ransomware | Kyocera Document Solutions Europe & Polsat — ALP-001 Ransomware, 150GB Exfiltrated | 2026-03-30 |
| High | Breach | Castilla-La Mancha Education System — Organized Cybercrime Ring | 2026-03-29 |
| High | Ransomware | Namibia Airports Company — INC Ransomware Group Dumps 500GB of Critical Infrastructure Data | 2026-03-29 |
| High | Ransomware | CommonSpirit Health — Patient Data Exposed via Third-Tier Subcontractor Ransomware Attack | 2026-03-29 |
| High | Ransomware | Rocky Mountain Care — Qilin Ransomware Hits Utah Senior Care Network | 2026-03-29 |
| High | Ransomware | Schlam Stone & Dolan LLP — Anubis Ransomware Targets U.S. Law Firm Representing Government and Fortune 500 Clients | 2026-03-29 |
| High | Ransomware | Lacor.es and Polsat — ALP-001 Ransomware European Expansion | 2026-03-29 |
| High | Ransomware | ARENCO Group & ITWAL — Dual Ransomware Claims Target Dubai Conglomerate and Canada's National Food Distribution Network | 2026-03-29 |
| High | Ransomware | Terix — ALP-001 Ransomware Hits U.S. Data Center Provider with $26.5M Demand | 2026-03-29 |
| High | Ransomware | Woodfords Family Services — Ransomware Attack on Disability Services Provider Yields Two-Year Notification Failure | 2026-03-29 |
| High | Ransomware | TPIS Industrial Services — Play Ransomware Hits U.S. Manufacturer | 2026-03-28 |
| High | Breach | Doctor Alliance — Credential Theft Exposes Patient Health Records Across Multiple Texas Home Healthcare Providers | 2026-03-28 |
| High | Breach | Nova Scotia Power — Cyberattack Exposed 900,000 Utility Customers, Privacy Commissioner Forces Security Reform | 2026-03-28 |
| High | Breach | Kash Patel — Iranian State-Linked Handala Breaches FBI Director's Personal Gmail, Publishes Authenticated Documents | 2026-03-28 |
| High | Ransomware | Esprinet — ALP-001 Ransomware Claims 1.2TB Breach of €4B European IT Distributor | 2026-03-28 |
| High | Ransomware | Goodwill Industries — Interlock Ransomware Hits Nonprofit Chain, 80GB Stolen, Stores Forced Cash-Only | 2026-03-28 |
| High | Breach | European Commission — AWS Account Breach Exposes 350GB of EU Executive Data, Attacker Plans Public Leak | 2026-03-28 |
| High | Breach | Hong Kong Correctional Services Department — IT System Breach Exposes 6,800 Employee Records | 2026-03-28 |
| High | Ransomware | Germany's Left Party — Qilin Ransomware Attack on Political Party Infrastructure | 2026-03-28 |
| High | Ransomware | City of Meriden, Connecticut — Incransom Ransomware Group Claims Municipal Government Attack | 2026-03-28 |
| High | Ransomware | Viva Ticket — Ransomware Hits Ticketing Platform Serving the Louvre and 3,500 Cultural Venues | 2026-03-28 |
| High | Breach | IntraCare — Healthcare Cyberattack Takes Systems Offline, 28 Surgeries Deferred | 2026-03-28 |
| High | Breach | AFC Ajax — API Flaws Exposed 300,000 Accounts and Enabled Hijack of 42,000 Season Tickets | 2026-03-28 |
| High | Breach | Centauro.net — 4.3 Million Customer Records Exposed in Data Breach | 2026-03-28 |
| High | Breach | LiteLLM — Malicious PyPI Packages Steal 300GB and 500K Credentials via AI Proxy Supply Chain | 2026-03-27 |
| High | Ransomware | SATS Sports Club — The Gentlemen Ransomware Claims Nordic Fitness Giant, 733K Members at Risk | 2026-03-27 |
| High | Breach | Hightower Holding — Credential Compromise Exposes 131,000 Wealth Management Clients | 2026-03-27 |
| High | Ransomware | Monmouth University — PEAR Ransomware Group Claims 16TB Exfiltration | 2026-03-27 |
| High | Breach | Crunchyroll (Sony): Third-Party Vendor Malware, 100GB Exfiltration, $5M Extortion | 2026-03-26 |
| High | Ransomware | Port of Vigo (Spain): Ransomware Attack Disrupts Europe's Largest Fishing Port | 2026-03-26 |
| High | Breach | QualDerm Partners: Healthcare Data Breach, Millions of Patients Potentially Exposed | 2026-03-26 |
| High | Breach | Cnous France: Data Breach Exposes 774,000 University Records | 2026-03-26 |
| High | Breach | Navia Benefit Solutions: Silent 24-Day Breach Exposes 2.7 Million Across Client Organizations | 2026-03-26 |
| High | Breach | AstraZeneca: Lapsus$ Claims 3GB Breach of Internal Code, Credentials, and Employee Data | 2026-03-26 |
| High | Ransomware | Foster City, California: Ransomware Attack Forces State of Emergency Declaration | 2026-03-26 |
| High | Ransomware | Nike: Double-Extortion Ransomware Targeting IP | 2026-03-25 |
| High | Breach | Checkmarx: TeamPCP CI/CD Supply Chain Compromise via Stolen GitHub Credentials | 2026-03-25 |
| High | Breach | Mazda: Vulnerability Exploitation in Warehouse Management System | 2026-03-25 |
| High | Breach | Dutch Ministry of Finance: Unauthorized Access to Policy Department Systems | 2026-03-25 |
| High | Breach | Kaplan: Server Intrusion Exposes SSNs and Driver's Licenses of 230,000+ Students and Professionals | 2026-03-24 |
| High | Breach | BMW & 35+ Automakers: IDOR Exploit Fuels Ongoing Multi-Brand Data Exfiltration | 2026-03-24 |
| High | Ransomware | South Africa Land Bank: RaaS Ransomware Attack via Internet-Facing Server Exploit | 2026-03-24 |
| High | Breach | CIRO: Phishing Attack Exposes 750,000 Canadian Investors | 2026-03-24 |
| High | Breach | Chile's Ley del Lobby Platform: Government Lobbying Records Breach Exposes 8 Years of Political Intelligence | 2026-03-24 |
| High | Breach | Lockheed Martin: Pro-Iran APT Claims 375TB Breach, Demands $400M Ransom | 2026-03-24 |
| High | Breach | Telekom Serbia: Data Breach Exposes 700,000 Customers via Secondary Application Attack | 2026-03-24 |
| High | Ransomware | Bell Ambulance: Medusa Ransomware Exposes 238,000 Patients' Healthcare and Identity Data | 2026-03-24 |
| High | Breach | Conduent: Covert Intrusion Exposes 25 Million Americans' Government Benefits Data | 2026-03-24 |
| High | Ransomware | Southwire: Qilin Ransomware Group Claims Attack on Major US Electrical Infrastructure Supplier | 2026-03-23 |
| High | Ransomware | Hikvision: ALP-001 Claims 199TB Breach of World's Largest Surveillance Manufacturer ⚠️ Unverified | 2026-03-23 |
| High | Breach | SoundCloud: ShinyHunters Extortion Gang Breaches 29.8 Million User Accounts | 2026-03-23 |
| High | Breach | Trivy Vulnerability Scanner Backdoored in Supply Chain Attack: 100M+ Download Tool Turned Credential Stealer | 2026-03-22 |
| High | Ransomware | University of Mississippi Medical Center: Ransomware Forces Statewide Clinic Shutdown, EHR Systems Offline | 2026-03-22 |
| High | Ransomware | Marquis: Ransomware Attack Exposes 672K Banking Customers | 2026-03-19 |
| High | Breach | CGI Sverige / Sweden BankID: ByteToBreach Source Code and Credential Leak | 2026-03-19 |
| High | Ransomware | Royal Bahrain Hospital: Payload Ransomware, 110GB Patient Data Exfiltration Claimed | 2026-03-19 |
| High | Ransomware | AkzoNobel: Anubis RaaS, 170GB Exfiltration from US Facility | 2026-03-19 |
| High | Breach | Navigate360 / P3 Global Intel: 8 Million Confidential Police Tips Compromised via Social Engineering | 2026-03-19 |
| High | Breach | Aura: ShinyHunters Voice Phishing Attack, 900,000 Records Leaked | 2026-03-19 |
| High | Breach | UK Companies House: WebFiling Browser Exploit Exposes 5 Million Business Records | 2026-03-18 |
| High | Breach | Salesforce Experience Cloud: ShinyHunters Mass Extortion Campaign | 2026-03-18 |
| High | Ransomware | Ruhnau Clarke & Biogel: Qilin Ransomware Double Extortion | 2026-03-18 |
| High | Breach | France FICOBA: Credential Theft Exposes 1.2M National Bank Records | 2026-03-18 |
| High | Breach | Odido: ShinyHunters Data Extortion Campaign | 2026-03-17 |
| High | Breach | France: Criminal Data Broker Mega-Aggregation Exposes 45M Citizens | 2026-03-17 |
| High | Breach | UK Biobank: Researcher Negligence Exposes Genetic and Medical Records of 500,000 Volunteers | 2026-03-16 |
| High | Breach | U.S. Critical Infrastructure: Seedworm (MuddyWater) Espionage Campaign with Novel Deno Backdoor | 2026-03-16 |
| High | Breach | CarGurus: ShinyHunters Breach Exposes 12.4 Million User Records | 2026-03-16 |
| High | Breach | Starbucks Employee Data Breach: 889 Accounts Compromised via Partner Central Phishing | 2026-03-15 |
| High | Breach | IDMerit: Unauthenticated MongoDB Exposes 1 Billion KYC Records | 2026-03-15 |
| High | Breach | FBI New York Field Office: Human Error Exposes Epstein Investigation Server to Foreign Hacker | 2026-03-15 |
| High | Breach | Cognizant TriZetto: 11-Month Undetected Intrusion Exposes 3.4M Patient Records | 2026-03-15 |
| High | Breach | Loblaw Companies: Third-Party Threat Actor Breaches Canada's Largest Retailer | 2026-03-15 |
| High | Ransomware | DigitalMint Negotiator Charged: Ran Ransomware Attacks While Negotiating for Victims | 2026-03-14 |
| High | Breach | Social Security Administration: DOGE Insider Data Exfiltration | 2026-03-13 |
| High | Breach | Stryker: Iran-Linked Handala Wiper Attack | 2026-03-13 |
| Critical | CVE · KEV | CVE-2026-3909 | 2026-03-13 |
| High | Breach | Telus Digital: ShinyHunters Data Extortion | 2026-03-13 |
| Critical | CVE · KEV | CVE-2026-3910 | 2026-03-13 |
| High | Breach | Sweden E-Government / CGI Sverige: National Codebase Leak | 2026-03-13 |
| Critical | CVE · KEV | CVE-2024-21762 FortiOS Out-of-Bound Write Vulnerability | 2026-03-10 |
| Critical | CVE · KEV | Threat Brief: CVE-2025-26399 SolarWinds Web Help Desk RCE | 2026-03-09 |
| Critical | CVE · KEV | CVE-2017-7921: Hikvision Improper Authentication Vulnerability | 2026-03-07 |
Showing 1888 of 1888