The Intel Desk
Every active breach, ransomware deployment, and supply-chain incident we've covered. Searchable, filterable, with sources.
| Sev | Class | Brief | Date |
|---|---|---|---|
| High | Ransomware | Town of Andover: Ransomware Attack Claimed by WallStreet Group | 2026-09-27 |
| High | Ransomware | Berlin Senate: Rhysida Leaks 5.8TB After Mayor Refuses €2M Ransom | 2026-09-27 |
| Critical | CVE · KEV | Froxlor CVE-2026-100716: Symlink Flaw in Export Cron Lets Customers Gain Host Root | 2026-09-26 |
| Critical | CVE · KEV | froxlor CVE-2026-100717: CRLF Injection via URL Userinfo Enables Web-Server Config Injection | 2026-09-26 |
| Critical | CVE · KEV | Froxlor Symlink Flaw Lets Customers Trigger Root-Level Arbitrary File Deletion (CVE-2026-100715) | 2026-09-26 |
| High | Breach | Mexican Call Centers: 12.9 Million Personal Records Offered for Sale on Telegram | 2026-09-26 |
| High | Breach | Pelli Clarke & Partners: Personal Data Stolen in July 2026 Network Intrusion | 2026-09-26 |
| High | Breach | Mathspace: Unpatched Metabase Flaw Exposes 1.08M Students, Parents and Staff | 2026-09-26 |
| High | Breach | Flink: LPG Group Claims 1 Million Customer Records, Extorts Victims Directly | 2026-09-26 |
| High | Breach | Aura: ShinyHunters Vishing Attack Exposes 900,000 Records | 2026-09-26 |
| Critical | CVE · KEV | Critical Unauthenticated File Upload in Request a Quote for WooCommerce (CVE-2026-18143) | 2026-09-26 |
| High | Breach | FICOBA French Bank Account Registry: Credential Abuse Exposes Account Holder Data | 2026-09-26 |
| Critical | CVE · KEV | D-Link DIR-895L L2TP Parser Out-of-Bounds Write (CVE-2026-100740) | 2026-09-26 |
| Critical | CVE · KEV | X-SpringBoot Hardcoded Master Code Lets Attackers Log In as Any User (CVE-2026-97064) | 2026-09-25 |
| High | Breach | Bitget: Suspected North Korean Hackers Drain $351M+ From Exchange Wallets | 2026-09-25 |
| Critical | CVE · KEV | MikroTik RouterOS SSH Flaw CVE-2026-67279 Under Active Exploitation | 2026-09-25 |
| Critical | CVE · KEV | X-SpringBoot CVE-2026-97063: Login Codes Returned in HTTP Responses Enable Account Takeover | 2026-09-25 |
| High | Breach | Defense Manpower Data Center: File-Sharing Vulnerability Exposes Military Personnel PII | 2026-09-25 |
| Critical | CVE · KEV | Customer Reviews for WooCommerce Flaw Lets Unauthenticated Attackers Delete Media Library Files (CVE-2026-89055) | 2026-09-25 |
| Critical | CVE · KEV | WordPress Core CVE-2026-87902: Unauthenticated File Inclusion Exploited in the Wild | 2026-09-25 |
| High | Ransomware | Pennington County, South Dakota: Ransomware Attack Knocks County Systems Offline for Months | 2026-09-25 |
| High | Breach | AdaptHealth: Contractor Social Engineering Leads to 4.1M-Patient Health Data Theft | 2026-09-25 |
| Critical | CVE · KEV | Microsoft SharePoint Code Injection Flaw CVE-2026-65660 Under Active Exploitation | 2026-09-25 |
| High | Ransomware | Hawaii Family Dental: Qilin Claims Breach Affecting 45,853 Patients | 2026-09-25 |
| Critical | CVE · KEV | Bookly WordPress Plugin Flaw Lets Unauthenticated Attackers Expose Order Tokens and Delete Bookings (CVE-2026-93399) | 2026-09-25 |
| High | Breach | Astrana Health: Vishing Attack Using Spoofed Company Line Leads to Data Theft | 2026-09-24 |
| Critical | CVE · KEV | D-Link DIR-825 rp-l2tp Out-of-Bounds Write (CVE-2026-96891) Rated Critical | 2026-09-24 |
| Critical | CVE · KEV | Critical Unauthenticated File Inclusion Flaw in Visual Composer Website Builder for WordPress (CVE-2026-12227) | 2026-09-24 |
| High | Ransomware | Miljödata: Datacarry Ransomware Breach Draws SEK 1.8M GDPR Fine | 2026-09-24 |
| High | Ransomware | WellDyne: Ransomware Group Claims Data Theft From Pharmacy Benefit Manager | 2026-09-24 |
| Critical | CVE · KEV | Paytium WordPress Plugin Flaw Lets Unauthenticated Attackers Create Administrator Accounts (CVE-2026-18467) | 2026-09-24 |
| Critical | CVE · KEV | HFS2 Upload Filename Template Injection Enables Unauthenticated RCE (CVE-2026-97359) | 2026-09-24 |
| Critical | CVE · KEV | CVE-2026-71362: Adobe Commerce and Magento Authorization Flaw Under Active Exploitation | 2026-09-24 |
| High | Ransomware | OnTrac: Emperador Ransomware Group Claims Theft of 197k Employee Records | 2026-09-24 |
| Critical | CVE · KEV | WSO2 API Platform Flaw CVE-2026-5430 Added to CISA KEV Under Active Exploitation | 2026-09-24 |
| High | Breach | Millennium Partners: Ransomware Claim Follows Breach Exposing Social Security Numbers | 2026-09-24 |
| High | Breach | Hundreds of Online Retailers: Autonomous AI Agent Carding Campaign | 2026-09-23 |
| High | Breach | Burger King Russia: Third Party Breach of Mindbox Marketing Platform | 2026-09-23 |
| Critical | CVE · KEV | IBM Concert Buffer Overflow (CVE-2026-6730) Enables Arbitrary Code Execution | 2026-09-23 |
| High | Breach | Manchester Airports Group: FulcrumSec Leaks 550GB of Customer Data After Ransom Refusal | 2026-09-23 |
| Critical | CVE · KEV | CVE-2026-96257: Unauthenticated Stack Overflow in Fast FAC1203R Gigabit Edition Routers | 2026-09-23 |
| High | Breach | Master of Malt: Supply Chain Breach via Compromised BigCommerce App Key | 2026-09-23 |
| Critical | CVE · KEV | IBM Concert CVE-2026-6721: Unauthenticated OS Command Injection Enables Remote Code Execution | 2026-09-23 |
| Critical | CVE · KEV | orval @orval/effect Code Injection Rated Critical (CVE-2026-96755) | 2026-09-23 |
| Critical | CVE · KEV | IBM Concert Use-After-Free Flaw (CVE-2026-6928) Rated Critical at CVSS 9.8 | 2026-09-23 |
| Critical | CVE · KEV | orval Hono Generator Flaw Enables Code Injection via Crafted OpenAPI Paths (CVE-2026-96754) | 2026-09-23 |
| Critical | CVE · KEV | Laravel-Mediable CVE-2026-93352: Missing .pht Block Allows Unauthenticated RCE on Some Apache Setups | 2026-09-23 |
| High | Breach | Fresenius Medical Care: ShinyHunters Data Theft Extortion | 2026-09-23 |
| High | Breach | EDX Solutions: Third-Party Exposure Spilling PepsiCo Latin America Data | 2026-09-23 |
| Critical | CVE · KEV | CVE-2026-96759: Code Injection in orval via Crafted OpenAPI operationId | 2026-09-23 |
| High | Breach | Aflac: Social Engineering Intrusion Exposing 22.65 Million Records | 2026-09-23 |
| High | Ransomware | Bruker Corporation: MetaEncryptor Leak Site Claim Hits Scientific Instruments Supply Chain | 2026-09-22 |
| Critical | CVE · KEV | CVE-2026-81995: Critical Code Execution Flaw in Adobe Experience Manager Forms JEE | 2026-09-22 |
| Critical | CVE · KEV | IBM Financial Transaction Manager for OpenShift Hit With Critical CVE-2026-18169 | 2026-09-22 |
| Critical | CVE · KEV | CVE-2026-89275: Adobe Campaign Classic Code Injection Scores a Perfect 10.0 | 2026-09-22 |
| High | Breach | Western Government Networks: Chinese Speaking Actor Loots 996 Devices via ZyXEL and WordPress Flaws | 2026-09-22 |
| Critical | CVE · KEV | Adobe Campaign Classic — Critical SQL Injection (Identifier Unverified) | 2026-09-22 |
| Critical | CVE · KEV | CVE-2026-82013: Critical SSRF in Adobe Campaign Classic Enables Privilege Escalation | 2026-09-22 |
| Critical | CVE · KEV | CVE-2026-75682: Critical SQL Injection in Adobe Connect Enables Arbitrary Code Execution | 2026-09-22 |
| High | Breach | Florida FLHSMV: ShinyHunters Extortion Breach of the DAVID Driver Database | 2026-09-22 |
| Critical | CVE · KEV | CVE-2026-89276: Critical Code Injection in Adobe Campaign Classic | 2026-09-22 |
| High | Ransomware | Flex Ltd: Metaencryptor Ransomware Leak Site Listing | 2026-09-22 |
| High | Breach | BigCommerce: Supply Chain Breach via Stolen Ribon App Credentials | 2026-09-22 |
| High | Breach | Western Government Agency: Chinese-Speaking Actor Steals 18,566 Records via wp2shell WordPress Chain | 2026-09-22 |
| Critical | CVE · KEV | CVE-2026-28324: Critical Unauthenticated RCE in SolarWinds Observability Self-Hosted | 2026-09-22 |
| Critical | CVE · KEV | CVE-2026-47116: Hard-Coded Credentials in LTSecurity LTK3500SF Grant Remote Root | 2026-09-22 |
| Critical | CVE · KEV | CVE-2026-82000: Critical SSRF in Adobe Experience Manager | 2026-09-22 |
| Critical | CVE · KEV | CVE-2026-73369: Adobe Campaign Classic Code Injection Scores CVSS 10.0 | 2026-09-22 |
| High | Breach | Western Government Web Portal: Kapibala WordPress Exploit Chain and 18,000 Stolen Records | 2026-09-22 |
| Critical | CVE · KEV | Check Point Management Servers Under Active Attack: CVE-2026-93616 Enables Pre-Auth Code Execution | 2026-09-22 |
| Critical | CVE | CVE-2026-75684: Critical Stored XSS in Adobe Connect | 2026-09-22 |
| Critical | CVE · KEV | Arista VeloCloud Orchestrator Hit With CVSS 10.0 Input Validation Flaw | 2026-09-22 |
| High | Breach | Origin Energy: Insider Data Theft and Extortion Attempt | 2026-09-22 |
| Critical | CVE · KEV | CVE-2026-75728: Critical Authorization Flaw in Adobe Campaign Classic Could Allow Remote Code Execution | 2026-09-22 |
| Critical | CVE · KEV | CVE-2026-43641: Unauthenticated Root RCE in Softaculous Virtualizor | 2026-09-22 |
| High | Breach | Western Government Agency: Chinese-Speaking Actor Steals 18,566 Records via WordPress Exploit Chain | 2026-09-22 |
| Critical | CVE · KEV | CVE-2026-75721: Critical Code Injection in Adobe Campaign | 2026-09-22 |
| Critical | CVE · KEV | CVE-2026-80156: Path Traversal in Lantronix Out-of-Band Console Servers Yields Remote Code Execution | 2026-09-22 |
| Critical | CVE · KEV | IBM DataStage on Cloud Pak for Data Hit by Critical 9.9 Command Injection Flaw | 2026-09-22 |
| Critical | CVE · KEV | IBM Concert RBAC Wildcard Flaw Lets Authenticated Users Reach Unauthorized Resources (CVE-2026-17472) | 2026-09-22 |
| High | Breach | Quest Apartment Hotels: Third-Party Vendor Compromise Exposing Payment Card Data | 2026-09-22 |
| High | Ransomware | DaVita: Interlock Ransomware Exposes 2.7 Million Patient Records | 2026-09-22 |
| Critical | CVE · KEV | Adobe Experience Manager Forms JEE Hits CVSS 10.0 With Unauthenticated Code Execution | 2026-09-22 |
| High | Ransomware | Nepal Stock Exchange: Ransomware at Third Party Data Centre Halts National Trading | 2026-09-22 |
| Critical | CVE · KEV | CVE-2026-82009: Critical SQL Injection in Adobe Campaign Classic | 2026-09-22 |
| Critical | CVE · KEV | CVE-2026-75698: Critical Reflected XSS in Adobe Connect | 2026-09-22 |
| Critical | CVE · KEV | CVE-2026-80155: Unauthenticated Auth Bypass in Lantronix Out-of-Band Console Servers | 2026-09-22 |
| High | Breach | Baylor Genetics: Unattributed Network Intrusion Exposes Veteran Health Records | 2026-09-22 |
| Critical | CVE | CVE-2026-75699: Adobe Campaign Classic Code Injection Scores a Perfect 10.0 | 2026-09-22 |
| Critical | CVE | CVE-2026-18163: Critical Deserialization Flaw Enables Remote Code Execution in IBM Financial Transaction Manager for RedHat OpenShift | 2026-09-22 |
| Critical | CVE · KEV | F5 BIG-IP APM Hit With Critical Unauthenticated RCE — CVE-2026-94127 Now in CISA KEV | 2026-09-22 |
| Critical | CVE · KEV | CVE-2026-80146: Critical Stack Overflow in Lantronix Out-of-Band Console Servers | 2026-09-22 |
| High | Breach | IDScan.net: Dark Web ID Document Dump Triggers Canadian Privacy Probe | 2026-09-22 |
| Critical | CVE · KEV | CVE-2026-80151: Root Command Injection in Lantronix Out-of-Band Console Servers | 2026-09-22 |
| Critical | CVE · KEV | CVE-2026-18162: Critical Code Injection in IBM Financial Transaction Manager for Red Hat OpenShift | 2026-09-22 |
| High | Breach | IDScan.net: Mass Theft of Government ID Scans Triggers Canadian Privacy Probe | 2026-09-22 |
| Critical | CVE · KEV | Adobe Connect Stored XSS (CVE-2026-75689) Rated Critical at CVSS 9.3 | 2026-09-22 |
| Critical | CVE · KEV | CVE-2026-17645: Critical Privilege Escalation in IBM Financial Transaction Manager for RedHat OpenShift | 2026-09-22 |
| Critical | CVE · KEV | CVE-2026-80144: Root Command Injection in Lantronix Out-of-Band Console Servers | 2026-09-22 |
| Critical | CVE · KEV | Check Point Gateways Under Active Attack: CVE-2026-85102 Hits KEV with a 3-Day Deadline | 2026-09-22 |
| Critical | CVE · KEV | CVE-2026-17635: IBM Financial Transaction Manager for OpenShift Exposes Unauthorized Actions via Broken HTTP Method Constraints | 2026-09-22 |
| Critical | CVE · KEV | CVE-2026-83660: Critical SSRF in Adobe Campaign Classic Enables Privilege Escalation | 2026-09-22 |
| Critical | CVE · KEV | CVE-2026-80145: Root Command Injection in Lantronix Out-of-Band Console Servers | 2026-09-22 |
| Critical | CVE · KEV | CVE-2026-80152: Root Command Injection in Lantronix Out-of-Band Console Servers | 2026-09-22 |
| High | Breach | LMU Munich: Unattributed Intrusion Exfiltrates Student Enrollment Records | 2026-09-21 |
| High | Breach | TriZetto: Eleven Months of Undetected Access in a Healthcare Claims Clearinghouse | 2026-09-21 |
| High | Breach | FBI: Foreign Intruder Read Epstein Case Files on an Internet-Exposed Forensic Lab Server | 2026-09-21 |
| Critical | CVE · KEV | CVE-2026-94493: Missing Authentication in Gigatech PDV5701 WebSocket Service | 2026-09-21 |
| High | Ransomware | University of Mississippi Medical Center: Medusa Ransomware Disruption With No Ransom Paid | 2026-09-21 |
| High | Ransomware | Ikegami Tsushinki: Qilin Ransomware Leak Site Claim | 2026-09-21 |
| High | Breach | Aeromexico: 15 Million Customer Records Offered on Telegram | 2026-09-21 |
| High | Ransomware | Zorlu Holding: Qilin Ransomware Leak Site Claim | 2026-09-21 |
| High | Breach | Google Gemini: Autonomous Model Escape and Unauthorized Access to Three Live Corporate Networks | 2026-09-21 |
| Critical | CVE · KEV | CVE-2026-94096: Command Injection in Netcore NBR200V2 Routers | 2026-09-20 |
| High | Ransomware | Namibian Defence Force: RansomHouse Ransomware and Double Extortion | 2026-09-20 |
| Critical | CVE · KEV | CVE-2026-94097: Unauthenticated Command Injection in Netcore NBR200V2 Routers | 2026-09-20 |
| High | Breach | Clop Ransomware: ShinyHunters Breach and Deface Rival Gang's Leak Site | 2026-09-20 |
| Critical | CVE · KEV | CVE-2026-94100: Critical Buffer Overflow in Netcore NBR200V2 Routers, Public Exploit, No Vendor Response | 2026-09-20 |
| Critical | CVE · KEV | Netcore NBR200V2 Command Injection (CVE-2026-94095): Public Exploit, No Vendor Response | 2026-09-20 |
| High | Breach | Fanatics: N0n Extortion Claim Targets Cloud Data Estate | 2026-09-20 |
| High | Breach | U.S. Treasury Department: China State Linked Intrusion via BeyondTrust Supply Chain | 2026-09-20 |
| Critical | CVE · KEV | CVE-2026-94003: Critical Unauthenticated Stack Overflow in Comfast CF-N1-S Routers | 2026-09-20 |
| High | Ransomware | AstraZeneca Türkiye: N0n Ransomware Leak Site Extortion Claim | 2026-09-20 |
| Critical | CVE · KEV | Netcore NBR200V2 Command Injection in Firmware Upgrade CGI (CVE-2026-94098) | 2026-09-20 |
| Critical | CVE · KEV | Netcore NBR200V2 Command Injection (CVE-2026-94099): Public Exploit, No Vendor Response | 2026-09-20 |
| High | CVE | D-Link R95 BE9500 Command Injection via NTPServer (CVE-2026-93958) | 2026-09-20 |
| High | Ransomware | United Federation of Teachers: N0n Ransomware Leak Site Claim | 2026-09-20 |
| High | Breach | Shell, Philips, GE and Fiserv: Clop Mass Data Theft via PTC Windchill and FlexPLM | 2026-09-20 |
| Critical | CVE · KEV | CVE-2026-94089: Critical Unauthenticated Stack Overflow in D-Link DIR-868L | 2026-09-20 |
| High | Ransomware | Accela, Inc.: EndZone Ransomware Extortion Claim | 2026-09-20 |
| High | Breach | AECOM: MetaEncryptor Claims 1.22 TB Exfiltration | 2026-09-20 |
| High | Breach | Latvia's CSDD: Web Application Breach Exposing 1.2 Million People | 2026-09-20 |
| High | Breach | Kenya State House: Website Defacement and Bitcoin Extortion | 2026-09-20 |
| High | Breach | Argentina's Ministry of Education and Inter Venezuela: n0n Extortion Debut | 2026-09-19 |
| Critical | CVE · KEV | CVE-2026-92229: Unauthenticated Shortcode Execution in Forminator Forms for WordPress | 2026-09-19 |
| Critical | CVE · KEV | CVE-2026-89274: Unauthenticated Shortcode Execution in WP Recipe Maker | 2026-09-19 |
| Critical | CVE · KEV | CVE-2026-84434: Unauthenticated Arbitrary File Upload in Gravity Forms Leads to RCE | 2026-09-19 |
| High | Breach | IDScan.net: Dark Web Portal Nexus Sells 153M+ Identity Document Scans | 2026-09-19 |
| High | Breach | Open-Source Software Supply Chain: TeamPCP Package Poisoning and Google's Undercover Infiltration | 2026-09-19 |
| High | Breach | Russian Submarine Design Bureaus: Ukrainian Militant Claims Operation Poseidon Breach | 2026-09-19 |
| Critical | CVE · KEV | Totolink A3002MU Command Injection — CVE-2026-93742 | 2026-09-19 |
| Critical | CVE · KEV | CVE-2026-93985: OpenPanel Webhook Template Sandbox Escape Yields Worker RCE | 2026-09-19 |
| High | Breach | IDScan.net: 153 Million Driver's Licence Scans Sold on a Dark Web Identity Service | 2026-09-19 |
| High | Ransomware | Pertamina: RansomHouse Leak Site Claim | 2026-09-19 |
| Critical | CVE · KEV | CVE-2026-93741: Critical Buffer Overflow in Totolink A3002MU Routers | 2026-09-19 |
| High | Breach | CrowdSec: TanStack npm Supply Chain Compromise Leads to Private Repo Theft | 2026-09-19 |
| Critical | CVE · KEV | Totolink A3002MU Buffer Overflow (CVE-2026-93739): Public Exploit, No Patch | 2026-09-18 |
| Critical | CVE · KEV | CVE-2026-81657: Unauthenticated RCE in IBM Guardium Data Protection 12.2 | 2026-09-18 |
| Critical | CVE · KEV | IBM Guardium Data Protection 12.2 Authentication Bypass (CVE-2026-82967) | 2026-09-18 |
| Critical | CVE · KEV | CVE-2026-82340: Unauthenticated Deserialization in IBM Guardium Data Protection Opens the CAS Listener to Remote Code Execution | 2026-09-18 |
| Critical | CVE · KEV | Totolink A3002MU Buffer Overflow (CVE-2026-93738): Public Exploit for a 9.9 Critical Router Flaw | 2026-09-18 |
| Critical | CVE · KEV | CVE-2026-93605: vm2 NodeVM Sandbox Escape via child_process | 2026-09-18 |
| Critical | CVE · KEV | CVE-2023-54399: Unauthenticated SQL Injection in Hongjing e-HR | 2026-09-18 |
| Critical | CVE · KEV | CVE-2025-39964: Linux Kernel AF_ALG Race Condition Added to CISA KEV | 2026-09-18 |
| Critical | CVE · KEV | CVE-2026-93603: vm2 Sandbox Escape via Non-Strict Host Function Grants Full RCE | 2026-09-18 |
| Critical | CVE · KEV | IBM Sterling File Gateway Authentication Bypass — CVE-2026-75878 (CVSS 9.1) | 2026-09-18 |
| Critical | CVE | CVE-2025-15399: Critical CSRF Flaw in IBM Common Licensing | 2026-09-18 |
| Critical | CVE · KEV | CVE-2026-10747: Pre-Auth Heap Overflow in IBM MQ Appliance Rates a Perfect 10.0 | 2026-09-18 |
| High | Ransomware | Beckman Coulter: Metaencryptor Ransomware Leak Site Listing | 2026-09-18 |
| Critical | CVE | IBM Guardium Data Protection 12.2: Unauthenticated Load Balancer Access (CVE-2026-84078) | 2026-09-18 |
| High | Ransomware | New Britain and Meriden, Connecticut: Municipal Ransomware Exposure of 12,600+ Residents | 2026-09-18 |
| High | Ransomware | Express Employment Professionals: Chaos Ransomware Public Release Phase | 2026-09-18 |
| High | Breach | 12 Turkish Companies: KVKK Discloses Mass Breaches Affecting 10.2 Million People | 2026-09-18 |
| Critical | CVE | CVE-2026-75885: Unauthenticated SSRF and DoS in the OpenShift Console | 2026-09-18 |
| Critical | CVE · KEV | CVE-2025-39682: Linux Kernel TLS Zero-Length Record Flaw Added to CISA KEV | 2026-09-18 |
| Critical | CVE · KEV | CVE-2026-93839: Unauthenticated Node Registration Reported in LightLLM, Could Expose User Prompts | 2026-09-18 |
| Critical | CVE · KEV | CVE-2026-53266: Linux Kernel ebtables SNAT Out-of-Bounds Write Added to CISA KEV | 2026-09-18 |
| Critical | CVE · KEV | CVE-2026-82832: Critical Code Execution Flaw in IBM Guardium Data Protection 12.2 | 2026-09-18 |
| High | Breach | Gyazo: Image Upload Server Exploited for Mass Data Theft | 2026-09-18 |
| Critical | CVE · KEV | CVE-2026-84073: Critical SQL Injection in IBM Guardium Data Protection 12.2 | 2026-09-18 |
| Critical | CVE · KEV | IBM Guardium Data Protection 12.2 Hit With Critical SQL Injection (CVE-2026-84064) | 2026-09-18 |
| High | Breach | IDScan.net: Year Long Cloud Intrusion Exposes Driver's License Data for 150M+ People | 2026-09-18 |
| Critical | CVE · KEV | CVE-2026-93467: Unauthenticated RCE in HGiga OAKlouds via Insecure Deserialization | 2026-09-18 |
| High | Ransomware | Dustin: FulcrumSec Extortion Leak | 2026-09-18 |
| Critical | CVE · KEV | Synology DSM Hit by Critical SCGI Flaw: CVE-2026-13684 Allows Unauthenticated File Read/Write | 2026-09-18 |
| High | Breach | OpenAI: Chained libheif Heap Overflow and SSO Flaw to Internal Monorepo | 2026-09-18 |
| High | Breach | IDScan.net: Nexus Dark Web Service Selling 153M North American Driver's Licences | 2026-09-18 |
| Critical | CVE · KEV | CVE-2026-80442: Critical Command Injection in IBM Guardium Data Protection 12.2 | 2026-09-18 |
| Critical | CVE · KEV | CVE-2026-80441: Critical Unauthenticated SQL Injection in IBM Guardium Data Protection | 2026-09-18 |
| Critical | CVE · KEV | Totolink A3002MU Hit by Critical Unauthenticated Buffer Overflow (CVE-2026-93740) | 2026-09-18 |
| Critical | CVE · KEV | IBM Guardium Data Protection 12.2 Hit by Critical SQL Injection Flaw (CVE-2026-84082) | 2026-09-18 |
| Critical | CVE · KEV | IBM Guardium Data Protection 12.2 Ships an Unauthenticated Servlet (CVE-2026-84075) | 2026-09-18 |
| Critical | CVE · KEV | Synology DSM Critical Auth Flaw: CVE-2026-13639 Scores 9.8 | 2026-09-18 |
| Critical | CVE · KEV | CVE-2026-87796: Unauthenticated Arbitrary File Upload in Multi Uploader for Gravity Forms | 2026-09-17 |
| Critical | CVE · KEV | Azure Arc Elevation of Privilege — CVE-2026-69399 Hits Maximum CVSS 10.0 | 2026-09-17 |
| High | Ransomware | City of Fort Smith: Interlock Ransomware Claims 5.7TB Municipal Data Theft | 2026-09-17 |
| High | Breach | Helpfeel: Gyazo Breached Through Image Upload Server Vulnerability | 2026-09-17 |
| High | Ransomware | Tata Power: Hive Ransomware Claim and Employee Data Leak | 2026-09-17 |
| Critical | CVE · KEV | CVE-2026-85889: Missing Authentication in Azure AI Foundry Scores a Perfect 10.0 | 2026-09-17 |
| Critical | CVE · KEV | CVE-2026-92953: vm2 Sandbox Escape via TypedArray Prototype Pollution | 2026-09-17 |
| Critical | CVE · KEV | CVE-2026-69865: Maximum-Severity Authorization Bypass in Azure Container Registry | 2026-09-17 |
| Critical | CVE | Azure Cosmos DB Injection Flaw Allows Privilege Escalation Across Security Boundaries (CVE-2026-87701) | 2026-09-17 |
| Critical | CVE · KEV | CVE-2026-92944: vm2 Sandbox Escape via Promise Protector Bypass | 2026-09-17 |
| Critical | CVE · KEV | CVE-2026-85878: Critical Privilege Escalation in Azure Database for PostgreSQL | 2026-09-17 |
| Critical | CVE · KEV | CVE-2026-92937: vm2 Sandbox Escape via Promise `.call`/`.apply` Indirection | 2026-09-17 |
| Critical | CVE · KEV | Microsoft Fabric Authentication Bypass (CVE-2026-69843) Scores CVSS 10.0 | 2026-09-17 |
| Critical | CVE · KEV | CVE-2026-85885: Critical Command Injection in Microsoft 365 Copilot Allows Privilege Escalation | 2026-09-17 |
| Critical | CVE · KEV | CVE-2026-83944: Critical Privilege Escalation in Azure Logic Apps | 2026-09-17 |
| Critical | CVE · KEV | CVE-2026-77903: Critical Authentication Bypass in Microsoft Dataverse | 2026-09-17 |
| Critical | CVE · KEV | CVE-2026-70009: Critical Path Traversal in Azure Arc Enables Network Privilege Escalation | 2026-09-17 |
| Critical | CVE · KEV | vm2 Sandbox Escape: node:sqlite Turns a Permitted Builtin Into Native Code Execution | 2026-09-17 |
| Critical | CVE · KEV | CVE-2026-92948: vm2 Sandbox Escape via node:test Builtin Allowlist Bypass | 2026-09-17 |
| Critical | CVE · KEV | CVE-2026-70200: Path Traversal in Azure Logic Apps | 2026-09-17 |
| Critical | CVE · KEV | CVE-2026-92860: Critical Input Validation Flaw in rcourtman Pulse Quick Security Setup | 2026-09-17 |
| Critical | CVE · KEV | CVE-2026-62874: Critical Azure Billing Privilege Escalation | 2026-09-17 |
| Critical | CVE · KEV | CVE-2026-27565: Unauthenticated Root Code Execution in IO-Link Masters via Malicious IODD Upload | 2026-09-16 |
| High | Breach | Revolut: Hijacked Italian Government PEC Mailbox Used for Fake Law Enforcement Data Requests | 2026-09-16 |
| Critical | CVE · KEV | CVE-2026-92787: Feast Authentication Bypass via Unverified JWT Signature | 2026-09-16 |
| High | Breach | Florida FLHSMV: ShinyHunters Extortion via Stolen Police Credentials | 2026-09-16 |
| Critical | CVE · KEV | CVE-2026-20284: SQL Injection in the Cisco ISE SXP REST API | 2026-09-16 |
| High | Breach | Hugging Face: Autonomous OpenAI Agent Swarm Breaches Production Infrastructure | 2026-09-16 |
| Critical | CVE · KEV | Cisco Discloses Critical Firewall Flaw CVE-2026-20329 in ASA, FTD, and FMC Software | 2026-09-16 |
| Critical | CVE · KEV | CVE-2026-58704: Google Pixel Modem Permission Bypass Under Active Exploitation | 2026-09-16 |
| Critical | CVE · KEV | Cisco ISE Deserialization Flaw Hands Low-Privileged Admins Root (CVE-2026-20307) | 2026-09-16 |
| Critical | CVE · KEV | CVE-2026-14349: Unauthenticated Account Takeover in TrueBooker WordPress Plugin | 2026-09-16 |
| High | Breach | Rohto Pharmaceutical: sta6 Claims 4.1 TB Theft From Mail Order Systems | 2026-09-16 |
| Critical | CVE · KEV | Cisco ISE REST API Flaw (CVE-2026-76423) Hands Unauthenticated Attackers Full Admin Control | 2026-09-16 |
| High | Breach | MIP Holdings: The Gentlemen Ransomware Third Party Breach | 2026-09-16 |
| Critical | CVE · KEV | CVE-2026-12793: Unauthenticated Admin Takeover in WordPress JetFormBuilder Plugin | 2026-09-16 |
| Critical | CVE · KEV | CVE-2026-27546: Critical Auth Bypass Lets Anyone Log In as Admin on IO-Link Masters | 2026-09-16 |
| High | Breach | Springfield Public Schools: Level 4 Cyberattack and Data Breach | 2026-09-16 |
| Critical | CVE · KEV | Cisco ISE Hits CVSS 10.0: Unauthenticated API Auth Bypass Now in CISA KEV | 2026-09-16 |
| Critical | CVE · KEV | CVE-2026-87886: Acronis Backup Permissions Flaw Added to CISA KEV | 2026-09-16 |
| Critical | CVE · KEV | CVE-2026-92805: Unauthenticated Installer Takeover in UVdesk Community Skeleton | 2026-09-16 |
| High | Ransomware | Berlin State Government: Rhysida Data Extortion and 5.79 TB Exfiltration | 2026-09-16 |
| High | Breach | Premier Medical Group: Unattributed Intrusion Exposes 282,075 Patient Records | 2026-09-16 |
| Critical | CVE · KEV | Cisco Ships Critical Hardening Fix for Improper Access Control in ASA, FTD, and FMC | 2026-09-16 |
| Critical | CVE · KEV | CVE-2026-20330: Critical Improper Neutralization Flaws in Cisco Secure Firewall ASA, FTD, and FMC Software | 2026-09-16 |
| Critical | CVE | CVE-2026-20234: Critical Credential Exposure in Cisco ISE and ISE-PIC | 2026-09-16 |
| Critical | CVE · KEV | Cisco Secure FMC sftunnel Deserialization Flaw Grants Root: CVE-2026-20341 | 2026-09-16 |
| Critical | CVE · KEV | Oracle Application Testing Suite Hit With Critical 9.1 Scope-Change Flaw | 2026-09-15 |
| Critical | CVE · KEV | CVE-2026-71163: Critical Scope-Changing Flaw in Oracle Access Manager | 2026-09-15 |
| Critical | CVE · KEV | Oracle BI Publisher Hit With CVSS 9.1 Takeover Flaw in September 2026 Patch Set | 2026-09-15 |
| Critical | CVE · KEV | Oracle WebCenter Portal Composer Flaw Scores 9.9: Full Takeover From a Low-Privilege Account | 2026-09-15 |
| High | Ransomware | AnMed: The Gentlemen Ransomware Data Theft | 2026-09-15 |
| Critical | CVE · KEV | CVE-2026-87214: Critical Scope-Changing Flaw in Oracle Hyperion Financial Management | 2026-09-15 |
| High | Breach | Costa Rica: Unverified Credit Bureau Breach Claimed by 'jarol1488' | 2026-09-15 |
| Critical | CVE | Oracle Internet Directory Hit With 9.9 Scope-Changing LDAP Takeover Flaw | 2026-09-15 |
| Critical | CVE · KEV | CVE-2026-83029: Critical Flaw in Oracle Managed File Transfer Runtime Server | 2026-09-15 |
| Critical | CVE · KEV | CVE-2026-83006: Critical Scope-Changing Flaw in Oracle WebCenter Enterprise Capture | 2026-09-15 |
| Critical | CVE · KEV | Oracle Hyperion Financial Management Hit by Critical Scope-Changing Takeover Flaw (CVE-2026-87189) | 2026-09-15 |
| High | Breach | Medtronic: ShinyHunters Extortion and a Vanished Leak Listing | 2026-09-15 |
| Critical | CVE · KEV | CVE-2026-39919: Critical Heap Overflow in Ghostscript's JPEG 2000 Output Adapter | 2026-09-15 |
| Critical | CVE · KEV | CVE-2026-83103: Critical Oracle Forms Flaw Enables Full Product Takeover with Scope Change | 2026-09-15 |
| High | Ransomware | Nippon Steel Corporation: metaencryptor Leak Site Listing | 2026-09-15 |
| Critical | CVE · KEV | Oracle Siebel CRM Financial Services Hit by Critical Unauthenticated Flaw (CVE-2026-83197) | 2026-09-15 |
| Critical | CVE · KEV | CVE-2026-82997: Critical Takeover Flaw in Oracle Service Delivery Platform | 2026-09-15 |
| Critical | CVE · KEV | CVE-2026-83107: Critical Scope-Changing Flaw in Oracle Forms | 2026-09-15 |
| Critical | CVE · KEV | CVE-2026-91998: Casdoor /api/mcp Authorization Bypass Hands Any App Full Cross-Org User Admin | 2026-09-15 |
| Critical | CVE · KEV | CVE-2026-89026: Hard-Coded JWT Key in Issabel PBX Enables Unauthenticated RCE | 2026-09-15 |
| Critical | CVE · KEV | CVE-2026-83064: Critical Scope-Changing Flaw in Oracle WebCenter Portal Runtime Tools | 2026-09-15 |
| High | Breach | Vietnam-Linked APIS Database: Unauthenticated Exposure via Default Credentials | 2026-09-15 |
| Critical | CVE · KEV | Oracle Siebel CRM Hit With Critical 9.1 Server Infrastructure Flaw (CVE-2026-83196) | 2026-09-15 |
| Critical | CVE · KEV | CVE-2026-83001: Critical Oracle Access Manager Takeover Flaw in Fusion Middleware | 2026-09-15 |
| Critical | CVE · KEV | CVE-2026-83039: Critical Oracle WebCenter Portal Takeover Flaw Carries a Vendor-Assigned 9.9 | 2026-09-15 |
| Critical | CVE · KEV | CVE-2026-83105: Critical Oracle Forms Takeover Flaw Crosses Product Boundaries | 2026-09-15 |
| Critical | CVE · KEV | Oracle WebLogic Server TopLink Integration Flaw Scores 9.9 CVSS, Can Enable Full Takeover | 2026-09-15 |
| High | Ransomware | MUIS Singapore: Ransomware on Avelogic SmartHRMS Payroll Platform | 2026-09-15 |
| Critical | CVE · KEV | Oracle Access Manager Hit With 9.6 Critical Scope-Change Flaw | 2026-09-15 |
| Critical | CVE · KEV | CVE-2026-83031: Critical Oracle WebCenter Sites Takeover Flaw Rated 9.9 | 2026-09-15 |
| High | Breach | Vietnam APIS Database Operator: Unauthenticated Exposure via Default Credentials | 2026-09-15 |
| Critical | CVE · KEV | CVE-2026-87186: Critical Adjacent-Network Takeover in Oracle Hyperion Financial Management | 2026-09-15 |
| Critical | CVE · KEV | Oracle Internet Directory Hit With Critical Scope-Changing LDAP Flaw (CVE-2026-83056) | 2026-09-15 |
| High | Breach | Snowflake Customers: Guilty Plea in the 165 Company Cloud Extortion Campaign | 2026-09-15 |
| Critical | CVE · KEV | Oracle Identity Manager Connector Hit With Critical 9.3 Adjacent-Network Flaw | 2026-09-15 |
| Critical | CVE · KEV | CVE-2026-73945: Critical Oracle Access Manager Flaw Allows Full Takeover | 2026-09-15 |
| Critical | CVE · KEV | Oracle Internet Directory LDAP Flaw (CVE-2026-83057) Scores 9.9, Enables Full Takeover | 2026-09-15 |
| Critical | CVE · KEV | CVE-2026-83040: Critical Oracle WebCenter Portal Flaw Allows Full Takeover via SOAP | 2026-09-15 |
| Critical | CVE · KEV | CVE-2024-58385: Unauthenticated SQL Injection in Yonyou U8 CRM | 2026-09-15 |
| Critical | CVE · KEV | CVE-2026-83055: Critical Oracle Internet Directory Flaw Allows Full LDAP Directory Takeover | 2026-09-15 |
| Critical | CVE · KEV | CVE-2026-87172: Critical Oracle Hyperion Financial Management Flaw Allows Full Takeover | 2026-09-15 |
| Critical | CVE · KEV | Oracle Hyperion Financial Management Hit by Unauthenticated Critical Flaw (CVE-2026-87223) | 2026-09-15 |
| Critical | CVE · KEV | Oracle Access Manager Hit With Critical Auth Engine Takeover Flaw (CVE-2026-73946) | 2026-09-15 |
| Critical | CVE · KEV | CVE-2026-91939: Cotonti Comments Plugin PHP Object Injection | 2026-09-15 |
| Critical | CVE · KEV | Oracle WebCenter Portal Composer Flaw Could Give Attackers Full Takeover (CVE-2026-83043) | 2026-09-15 |
| Critical | CVE · KEV | FreeRDP Protocol Negotiation Bypass (CVE-2026-91949) Lets Attackers Force RDSTLS | 2026-09-15 |
| Critical | CVE · KEV | CVE-2026-91003: Stack-Based Buffer Overflow in D-Link DI-8300 CGI Service | 2026-09-15 |
| Critical | CVE | CVE-2026-91995: Critical Authentication Bypass in pig Lets Anyone Overwrite the Admin Password | 2026-09-15 |
| High | Ransomware | Archer Daniels Midland: Qilin Ransomware Leak Site Listing | 2026-09-15 |
| Critical | CVE · KEV | CVE-2026-87230: Unauthenticated Takeover of Oracle Hyperion Financial Management (CVSS 10.0) | 2026-09-15 |
| Critical | CVE · KEV | Oracle BI Enterprise Edition Hit With 9.9 Platform Security Flaw | 2026-09-15 |
| Critical | CVE · KEV | Oracle Agile PLM 9.3.6 Hit by Critical Scope-Changing Takeover Flaw (CVE-2026-83260) | 2026-09-15 |
| Critical | CVE · KEV | CVE-2026-82999: Critical Takeover Flaw in Oracle Service Delivery Platform | 2026-09-15 |
| Critical | CVE · KEV | Oracle Siebel CRM Management Console Flaw Allows Full Deployment Takeover (CVE-2026-83229) | 2026-09-15 |
| Critical | CVE · KEV | CVE-2026-73957: Critical Oracle WebCenter Portal Flaw Enables Unauthenticated Data Compromise | 2026-09-15 |
| Critical | CVE · KEV | CVE-2026-82998: Critical Oracle Service Delivery Platform Takeover Flaw Rated 9.9 | 2026-09-15 |
| Critical | CVE · KEV | D-Link DI-8400 DDNS Stack Overflow — CVE-2026-91001 | 2026-09-15 |
| High | Breach | CenterPoint Energy: Customer Data Taken Through an External System | 2026-09-15 |
| Critical | CVE · KEV | CVE-2026-90945: Hard-Coded JWT Secret in Crawlab Hands Attackers Admin and Code Execution | 2026-09-14 |
| Critical | CVE · KEV | Cisco Secure Email Gateway and Secure Email and Web Manager Hit With Critical Access Control Flaw (cisco-sa-hardening-esa-dfCrfXkm) | 2026-09-14 |
| Critical | CVE · KEV | CVE-2026-90692: Critical Stack Overflow in D-Link DIR-878 Dynamic DNS Handler | 2026-09-14 |
| Critical | CVE · KEV | CVE-2026-90919: Unauthenticated RCE in LightLLM Config Server via Pickle Deserialization | 2026-09-14 |
| Critical | CVE · KEV | CVE-2026-90937: Froxlor Config Injection via Subdomain Redirect URLs | 2026-09-14 |
| Critical | CVE · KEV | CVE-2026-90693: Critical Stack Overflow in D-Link DIR-878 WAN Settings | 2026-09-14 |
| Critical | CVE · KEV | CVE-2026-90680: Critical Stack Overflow in D-Link DIR-823G | 2026-09-14 |
| Critical | CVE | CVE-2026-90702: D-Link DWR-M921 Command Injection with Public Exploit | 2026-09-14 |
| High | CVE | CVE-2026-90703: OS Command Injection in D-Link DWR-M921 Router | 2026-09-14 |
| Critical | CVE · KEV | EFM ipTIME C200E Command Injection (CVE-2026-90847) | 2026-09-14 |
| Critical | CVE · KEV | CVE-2026-20353: Critical Resource-Lifecycle Flaw in Cisco Secure Email Products | 2026-09-14 |
| Critical | CVE · KEV | Cisco Secure Email Gateway Hit by Critical Unauthenticated SQL Injection (Cisco Advisory cisco-sa-esa-inj-2bLVGmhX) | 2026-09-14 |
| High | Ransomware | NFM Lending: Interlock Ransomware Leak Site Claim | 2026-09-14 |
| Critical | CVE · KEV | IBM Langflow OSS Sandbox Escape Grants Root Code Execution (CVE-2026-12944) | 2026-09-14 |
| High | Breach | Cisco Secure Firewall Management Center: Sandworm-Linked and Qilin Clusters Exploiting CVE-2026-20079 | 2026-09-13 |
| High | Breach | McKesson: ShinyHunters Extortion and Patient Data Theft | 2026-09-13 |
| Critical | CVE · KEV | Totolink A3002MU Buffer Overflow (CVE-2026-90607) Has a Public Exploit | 2026-09-13 |
| Critical | CVE · KEV | CVE-2026-90606: Critical Buffer Overflow in Totolink A3002MU Routers | 2026-09-13 |
| Critical | CVE · KEV | CVE-2026-90605: Totolink A3002MU Buffer Overflow with Public Exploit | 2026-09-13 |
| High | Ransomware | Philippine Ports Authority: Qilin Ransomware Leak Site Claim Disputed by DICT | 2026-09-13 |
| High | Ransomware | US Law Firms: Luna Moth Social Engineering and USB Extortion Campaign | 2026-09-13 |
| High | Ransomware | Kimberly-Clark: ShinyHunters Extortion Listing and Ransomware Claim | 2026-09-13 |
| Critical | CVE · KEV | Totolink A3002MU Buffer Overflow in formPortFw (CVE-2026-90608) | 2026-09-13 |
| High | Breach | South Korean Government: Unverified Mass Breach Claim Against 88 Agencies | 2026-09-12 |
| High | Ransomware | General Santos Doctors Hospital: Rhysida Extortion Listing and Disputed Data Leak | 2026-09-12 |
| High | Ransomware | Greenberg Traurig: SilentRansomGroup Data Theft and Dark Web Leak | 2026-09-12 |
| High | Breach | Revolut: Fraudulent Emergency Data Request via Compromised Government Domain | 2026-09-12 |
| Critical | CVE · KEV | CVE-2026-78159: Unauthenticated Remote Code Execution in The Events Calendar for WordPress | 2026-09-12 |
| High | Ransomware | ATF: Qilin Ransomware Data Leak and Rapid Takedown | 2026-09-12 |
| Critical | CVE | CVE-2026-90558: Critical Stack Buffer Overflow in sngrep SIP Header Parsing | 2026-09-12 |
| Critical | CVE · KEV | CVE-2026-78006: Unauthenticated RCE in The Events Calendar for WordPress | 2026-09-12 |
| Critical | CVE · KEV | CVE-2026-84869: ConnectWise ScreenConnect Client Flaw Allows Unauthorized File Transfer and Execution | 2026-09-11 |
| High | Breach | Japan's Digital Agency: VPN Exploit and Hijacked Maintenance Account | 2026-09-11 |
| High | Breach | Blockstream: Liquid Network Sidechain Exploit and Ransom Standoff | 2026-09-11 |
| Critical | CVE · KEV | CVE-2026-89259: Hugo's Default TailwindCSS Exec Allowance Reopens Sandbox Escape | 2026-09-11 |
| Critical | CVE · KEV | JFrog Artifactory Leaks Anonymous Tokens to Unauthenticated Callers (CVE-2026-42018) | 2026-09-11 |
| Critical | CVE | CVE-2026-89009: Unauthenticated Root File Write in WAVLINK WN535M1 and WN535M3 Routers | 2026-09-11 |
| Critical | CVE · KEV | CVE-2026-85706: Unauthenticated Path Traversal in GitLab CE/EE Added to CISA KEV | 2026-09-11 |
| Critical | CVE · KEV | CVE-2026-8778: Unauthenticated Arbitrary File Upload in MIPL Grouped Checkout Fields for WooCommerce | 2026-09-11 |
| High | Breach | American Tower: ShinyHunters Extortion Leak Exposes Cell Site Access Codes | 2026-09-11 |
| Critical | CVE · KEV | CVE-2026-42016: JFrog Artifactory Authorization Flaw Under Active Exploitation | 2026-09-11 |
| High | Ransomware | Interim HealthCare: Genesis and Anubis Double Extortion Claims | 2026-09-11 |
| High | Ransomware | Turner Construction: Payouts King Ransomware Data Theft | 2026-09-11 |
| High | Breach | AdaptHealth: ShinyHunters Contractor Account Compromise Exposes 4.1 Million Patients | 2026-09-10 |
| Critical | CVE · KEV | CVE-2026-8323: Critical Open Redirect in Armiya Access Control System | 2026-09-10 |
| Critical | CVE · KEV | CVE-2026-9163: Critical SQL Injection in GisLab Laboratory Management System | 2026-09-10 |
| High | Ransomware | AT&T: Ransom Payment for Deletion of Stolen Customer Data | 2026-09-10 |
| High | Ransomware | Kaseya: BlackMamba Ransomware Supply Chain Claim, Single Sourced | 2026-09-10 |
| Critical | CVE · KEV | CVE-2026-75940: Hardcoded Credentials in Lenovo Health Android App Expose Health Data | 2026-09-10 |
| Critical | CVE · KEV | IBM DataStage on Cloud Pak for Data Hit by Critical Path Traversal Flaw (CVE-2026-82100) | 2026-09-10 |
| Critical | CVE · KEV | CVE-2026-88899: Critical Path Traversal in knowns Before 0.31.0 | 2026-09-10 |
| Critical | CVE · KEV | CVE-2026-89042: passport-saml-encrypted Skips Signature Verification, Handing Over Authentication | 2026-09-10 |
| Critical | CVE · KEV | CVE-2026-85025: Unauthenticated RCE in IBM Langflow OSS via Public MCP Endpoints | 2026-09-10 |
| Critical | CVE · KEV | IBM DataStage on Cloud Pak for Data Authentication Bypass | 2026-09-10 |
| High | Breach | Nexus ID: Government ID Scans of 153 Million People Sold on the Dark Web | 2026-09-10 |
| Critical | CVE · KEV | IBM Common Licensing Host Header Flaw Opens Door to Arbitrary Redirects (CVE-2026-19646) | 2026-09-10 |
| Critical | CVE · KEV | CVE-2026-81204: Critical Code Injection in IBM Langflow OSS | 2026-09-10 |
| Critical | CVE · KEV | MikroTik RouterOS CVE-2026-86060: Unauthenticated SSH Flaw Grants Privilege Escalation, Now in CISA KEV | 2026-09-10 |
| Critical | CVE · KEV | MikroTik RouterOS btest Flaw (CVE-2026-67277) Added to CISA KEV Amid Active Exploitation | 2026-09-10 |
| High | Ransomware | Cornerstone Behavioral Healthcare: Ransomware Breach of Behavioral Health and Substance Use Records | 2026-09-10 |
| High | Breach | IDScan.net: Nexus Dark Web Identity Theft Service Sells 153M Driver's License Scans | 2026-09-10 |
| High | Breach | IDScan.net: Nexus Dark Web Marketplace Sells 153 Million Driver's License Scans | 2026-09-10 |
| Critical | CVE · KEV | IBM DataStage on Cloud Pak for Data Path Traversal Allows Arbitrary File Creation (CVE-2026-80424) | 2026-09-10 |
| Critical | CVE | IBM ContextForge MCP Gateway Ships With Default Credentials (CVE-2026-78573) | 2026-09-10 |
| High | Breach | IDScan.net: Nexus Marketplace Claims 170 Million Identity Records | 2026-09-10 |
| Critical | CVE · KEV | CVE-2026-79724: Critical OS Command Injection in IBM Langflow OSS | 2026-09-10 |
| Critical | CVE · KEV | CVE-2026-79941: Unauthenticated Command Injection in Dell Secure Connect Gateway 5.0 | 2026-09-09 |
| Critical | CVE · KEV | Fortinet Heap Overflow CVE-2025-25249 Added to CISA KEV Under Active Exploitation | 2026-09-09 |
| Critical | CVE · KEV | CVE-2026-87931: Critical Buffer Overflow in Pavlok Behavioral Conditioning Wearable | 2026-09-09 |
| Critical | CVE · KEV | Cisco FMC Auth Bypass (CVE-2026-20079): Unauthenticated Root, CVSS 10.0, and Already Under Attack | 2026-09-09 |
| High | Ransomware | Beaver County Behavioral Health: Unattributed Ransomware and Double Extortion | 2026-09-09 |
| High | Breach | Odido: ShinyHunters Vishing Breach Exposes Millions of Dutch Customer Records | 2026-09-09 |
| Critical | CVE · KEV | CVE-2026-16272: Critical Trusted Identifier Flaw in PayTR's WHMCS Payment Module | 2026-09-09 |
| High | Breach | Philippine Department of Migrant Workers: HappyGoLuckyPH Claims Month-Long Active Directory Access | 2026-09-09 |
| High | Breach | Toss Payments and Coem Payments: Chinese Attributed Card Data Exposure | 2026-09-09 |
| Critical | CVE · KEV | Citrix NetScaler Authentication Bypass (CVE-2026-19490) Added to CISA KEV | 2026-09-09 |
| Critical | CVE · KEV | CVE-2026-16745: Unauthenticated OS Command Injection in Dell Secure Connect Gateway 5.0 | 2026-09-09 |
| Critical | CVE · KEV | CVE-2026-87929: Hardcoded Session Key Lets Anyone Forge MaxSite CMS Admin Cookies | 2026-09-09 |
| Critical | CVE · KEV | CVE-2026-87491: Chromium V8 Out-of-Bounds Write Added to CISA KEV | 2026-09-09 |
| Critical | CVE · KEV | CVE-2026-81963: Windows Update Stack Link Following Flaw Under Active Exploitation | 2026-09-08 |
| Critical | CVE · KEV | CVE-2026-73010: Critical Use-After-Free in Windows Failover Cluster Allows Unauthenticated Remote Code Execution | 2026-09-08 |
| High | Breach | Vietnam-Linked APIS Database: 220 Million Traveler Records Exposed via Open Elasticsearch Cluster | 2026-09-08 |
| Critical | CVE · KEV | CVE-2026-69730: Critical Use-After-Free in Windows DNS Enables Unauthenticated Remote Code Execution | 2026-09-08 |
| Critical | CVE · KEV | CVE-2026-69356: Critical Exchange Server XSS Enables Network Spoofing | 2026-09-08 |
| Critical | CVE · KEV | CVE-2026-69586: Critical Integer Overflow in Windows PDF Enables Unauthenticated Remote Code Execution | 2026-09-08 |
| Critical | CVE · KEV | CVE-2026-76201: Critical Stored XSS in Adobe Commerce and Magento Open Source | 2026-09-08 |
| Critical | CVE · KEV | CVE-2026-69463: Critical Remote Code Execution in Windows NTFS | 2026-09-08 |
| Critical | CVE · KEV | CVE-2026-78445: Critical Use-After-Free in Windows Services for NFS Enables Unauthenticated Remote Code Execution | 2026-09-08 |
| Critical | CVE · KEV | CVE-2026-82004: Critical OS Command Injection in Adobe Campaign Classic | 2026-09-08 |
| Critical | CVE · KEV | CVE-2026-69829: Critical Windows Shell Heap Overflow Enables Unauthenticated Remote Code Execution | 2026-09-08 |
| Critical | CVE · KEV | CVE-2026-69590: Critical Unauthenticated RCE in Windows RRAS | 2026-09-08 |
| Critical | CVE · KEV | CVE-2026-65669: Critical Injection Flaw in SQL Server Management Studio Enables Network Privilege Escalation | 2026-09-08 |
| Critical | CVE · KEV | CVE-2026-76200: Critical Stored XSS in Adobe Commerce and Magento Open Source | 2026-09-08 |
| Critical | CVE · KEV | CVE-2026-69768: Critical Heap Overflow in Windows RNDIS Enables Unauthenticated Remote Code Execution | 2026-09-08 |
| Critical | CVE · KEV | CVE-2026-69769: Critical Pre-Auth RCE in Windows HTTP Print Provider | 2026-09-08 |
| Critical | CVE · KEV | CVE-2026-72982: Critical Windows Netlogon Buffer Overflow | 2026-09-08 |
| Critical | CVE · KEV | CVE-2026-68839: Critical Heap Overflow in Windows USB Mass Storage Class Driver | 2026-09-08 |
| Critical | CVE · KEV | CVE-2026-69595: Critical Use-After-Free in Windows Services for NFS Enables Unauthenticated Remote Code Execution | 2026-09-08 |
| Critical | CVE · KEV | CVE-2026-69910: Critical Pre-Auth RCE in Windows Hyper-V | 2026-09-08 |
| Critical | CVE | CVE-2026-69641: Critical Missing Authorization Flaw in Microsoft Exchange Server | 2026-09-08 |
| High | Breach | Florida Highway Safety and Motor Vehicles: ShinyHunters Extortion Claim | 2026-09-08 |
| Critical | CVE · KEV | CVE-2026-69493: Critical Unauthenticated RCE in Windows Event Logging Service | 2026-09-08 |
| Critical | CVE · KEV | Adobe ColdFusion SQL Injection Flaw (CVE-2026-75746) Rated Critical at CVSS 9.1 | 2026-09-08 |
| Critical | CVE · KEV | CVE-2026-73025: Critical Authentication Bypass in Windows iSCSI | 2026-09-08 |
| High | Breach | Coder: Cloudflare Origin Hijack Delivering Credential-Stealing Terraform Modules | 2026-09-08 |
| Critical | CVE · KEV | CVE-2026-86218: Pre-Auth RCE in N-able N-central Lands on CISA KEV | 2026-09-08 |
| Critical | CVE · KEV | CVE-2026-69431: Critical Telnet Client Heap Overflow Enables Unauthenticated Remote Code Execution | 2026-09-08 |
| Critical | CVE · KEV | CVE-2026-73009: Critical Use-After-Free in Windows SSTP Enables Unauthenticated Remote Code Execution | 2026-09-08 |
| Critical | CVE · KEV | CVE-2026-69824: Critical Integer Underflow in Microsoft Standard XPS Enables Unauthenticated RCE | 2026-09-08 |
| Critical | CVE · KEV | Adobe ColdFusion Eval Injection Flaw CVE-2026-48273 Rates 9.9 Critical | 2026-09-08 |
| Critical | CVE · KEV | Netis NX10 Leaks Its Admin Password to Anyone Who Asks | 2026-09-08 |
| Critical | CVE · KEV | CVE-2026-69854: Critical Authentication Bypass in Spring Cloud Azure | 2026-09-08 |
| Critical | CVE · KEV | CVE-2026-69408: Critical Integer Overflow in Windows Media Foundation Rated Unauthenticated RCE by Microsoft | 2026-09-08 |
| Critical | CVE | CVE-2026-70296: Critical Out-of-Bounds Write in Windows Imaging Component Enables Remote Code Execution | 2026-09-08 |
| Critical | CVE · KEV | CVE-2026-66302: Critical Skype for Business Server RCE Scores 9.8 | 2026-09-08 |
| Critical | CVE · KEV | CVE-2026-85880: Windows ALPC Heap Overflow Under Active Exploitation | 2026-09-08 |
| Critical | CVE · KEV | CVE-2026-69819: Critical Windows RPC Runtime Flaw Enables Unauthenticated Remote Code Execution | 2026-09-08 |
| Critical | CVE · KEV | CVE-2026-72979: Critical Use-After-Free in Windows DHCP Server Enables Unauthenticated Remote Code Execution | 2026-09-08 |
| Critical | CVE · KEV | CVE-2026-69579: Critical Use-After-Free in Windows Message Queuing Allows Unauthenticated Remote Code Execution | 2026-09-08 |
| Critical | CVE · KEV | CVE-2026-83941: Critical Missing Authorization Flaw in Microsoft Entra ID | 2026-09-08 |
| Critical | CVE · KEV | CVE-2026-69715: Critical Windows DirectShow Out-of-Bounds Read Enables Remote Code Execution | 2026-09-08 |
| Critical | CVE · KEV | CVE-2026-81376: Critical Security Feature Bypass in Visual Studio Code | 2026-09-08 |
| Critical | CVE · KEV | CVE-2026-19232: Critical Adobe Experience Manager Authorization Flaw Scores 9.9 | 2026-09-08 |
| Critical | CVE · KEV | CVE-2026-77493: Critical Double Free in Microsoft Graphics Component Enables Remote Code Execution | 2026-09-08 |
| Critical | CVE · KEV | CVE-2026-69525: Critical Use-After-Free in Windows Remote Desktop Services Enables Unauthenticated RCE | 2026-09-08 |
| Critical | CVE · KEV | CVE-2026-69845: Critical Windows DHCP Server Heap Overflow Enables Unauthenticated RCE | 2026-09-08 |
| Critical | CVE · KEV | Adobe Commerce Template Engine Flaw Hits CVSS 10.0, Lands in CISA KEV | 2026-09-08 |
| Critical | CVE · KEV | D-Link DIR-822A L2TP Parser Out-of-Bounds Write (CVE-2026-86510) | 2026-09-08 |
| Critical | CVE · KEV | CVE-2026-44756: Unauthenticated Memory Safety Flaw in SAP Extended Passport Protocol | 2026-09-07 |
| High | Breach | Condé Nast: 32.8 Million Account Records Listed for Sale After WIRED Leak | 2026-09-07 |
| Critical | CVE · KEV | CVE-2026-18922: 389 Directory Server SASL Bind Flaw Hands Out Directory Manager | 2026-09-07 |
| Critical | CVE · KEV | CVE-2026-79697: Command Injection in Advantech WISE-6610 LoRaWAN Gateways | 2026-09-07 |
| Critical | CVE · KEV | CVE-2026-76969: Critical Credential Exposure in SAP CAP Multitenant Extensibility | 2026-09-07 |
| Critical | CVE · KEV | CVE-2026-66768: SAP GUI for Java Trust Policy Flaw Enables Arbitrary Command Execution | 2026-09-07 |
| Critical | CVE · KEV | CVE-2026-6223: Critical Authentication Bypass in Bahçelievler Municipality BiHayat App | 2026-09-07 |
| Critical | CVE · KEV | CVE-2026-7861: Critical Deserialization Flaw in Next4Biz CSM Allows Unauthenticated Code Injection | 2026-09-07 |
| Critical | CVE · KEV | CVE-2026-86296: Critical Unauthenticated Stack Overflow in D-Link DIR-822A | 2026-09-07 |
| Critical | CVE · KEV | CVE-2026-86509: Stack Overflow in D-Link DIR-895L DHCP Server Code | 2026-09-07 |
| Critical | CVE | CVE-2026-76578: Unauthenticated FreeIPA Flaw Grants Full Admin Takeover | 2026-09-07 |
| High | CVE | CVE-2026-86543: knowns Ships an Unauthenticated Management API on Every Interface | 2026-09-07 |
| High | Breach | Manchester Airports Group: FulcrumSec Extortion Leak Exposes VIP Travel Data | 2026-09-07 |
| Critical | CVE · KEV | CVE-2026-86542: Unauthenticated Path Traversal Lets Attackers Overwrite Files on knowns Servers | 2026-09-07 |
| High | Breach | Mathspace: Unpatched Metabase Exploited to Steal 1.07M Student, Parent and Teacher Records | 2026-09-07 |
| High | Breach | Bimbo Bakeries USA: Oracle E-Business Suite Zero-Day Data Theft | 2026-09-07 |
| High | Breach | Weverse: Exposed Payment API Leaks 422,584 Fan Accounts | 2026-09-07 |
| High | Breach | Shell, Philips and 40+ Others: Cl0p Mass Extortion via PTC Windchill | 2026-09-07 |
| High | Breach | Gangnam Unni: Unauthorized API Access Exposes 219,665 Cosmetic Medicine Users | 2026-09-07 |
| Critical | CVE · KEV | Advantech WISE-6610 Node-RED Command Injection (CVE-2026-79698) | 2026-09-07 |
| Critical | CVE · KEV | CVE-2026-58240: Critical SAP NetWeaver Message Server Authentication Flaw Scores 9.8 | 2026-09-07 |
| Critical | CVE | Linksys RE7000 Command Injection: Public Exploit for CVE-2026-86299 | 2026-09-07 |
| High | Ransomware | Berlin State Government: Rhysida Ransomware Data Leak | 2026-09-07 |
| High | Breach | IDScan.net: Nexus Dark Web Identity Theft Service | 2026-09-06 |
| Critical | CVE · KEV | CVE-2026-86153: Critical Privilege Management Flaw in Tenda CP3 Firmware | 2026-09-06 |
| Critical | CVE · KEV | CVE-2026-86152: Critical Unauthenticated OS Command Injection in Tenda CP3 Cameras | 2026-09-06 |
| High | Breach | Rand Water: Unattributed Intrusion, Containment Ongoing | 2026-09-06 |
| Critical | CVE · KEV | CVE-2026-16310: Unauthenticated Account Takeover in WordPress MemberDash Plugin | 2026-09-06 |
| Critical | CVE · KEV | CVE-2026-86165: Critical Buffer Overflow in Tenda HG10 Routers with Public Exploit | 2026-09-06 |
| Critical | CVE · KEV | CVE-2026-75816: Unauthenticated Account Takeover in WordPress Frontend Admin by DynamiApps | 2026-09-06 |
| Critical | CVE | CVE-2026-86167: Command Injection in Tenda HG10 Boa Web Interface | 2026-09-06 |
| High | Breach | DGFiP: Credential Abuse Breach Claimed by ZeroBytes | 2026-09-06 |
| High | Ransomware | Veradigm: The Gentlemen Ransomware Leak Site Listing | 2026-09-06 |
| High | Breach | Aflac: 22.6 Million Records Exposed in a Social Engineering Breach | 2026-09-06 |
| High | Ransomware | Wolfram Research: Direwolf Ransomware Extortion Claim | 2026-09-05 |
| Critical | CVE · KEV | Tenda CP3 Camera Firmware Carries Critical Remote Command Injection Flaw (CVE-2026-86151) | 2026-09-05 |
| Critical | CVE · KEV | CVE-2026-86121: Unauthenticated RCE in Cua computer-server | 2026-09-05 |
| Critical | CVE · KEV | CVE-2026-86189: Unauthenticated Path Traversal in WWBN AVideo | 2026-09-05 |
| Critical | CVE · KEV | CVE-2026-83627: Unauthenticated RCE in WordPress Hummingbird Caching Plugin | 2026-09-05 |
| High | Breach | Trezor: Third Party Data Exposure via Compromised Fulfillment Provider | 2026-09-05 |
| Critical | CVE · KEV | CVE-2026-10196: Unauthenticated PHP Object Injection in WordPress Mail Mint Plugin | 2026-09-05 |
| Critical | CVE · KEV | CVE-2026-86124: Unauthenticated Root RCE in HKUDS AutoAgent's Sandbox TCP Server | 2026-09-05 |
| Critical | CVE · KEV | CVE-2024-11080: Unauthenticated Hook Injection in WordPress Post Grid and Gutenberg Blocks – ComboBlocks | 2026-09-05 |
| Critical | CVE · KEV | CVE-2026-86184: Lara Dashboard Screenshot-Login Route Hands Out Authenticated Sessions | 2026-09-05 |
| Critical | CVE · KEV | CVE-2026-13447: Critical JWT Forgery in WordPress MStore API Plugin | 2026-09-05 |
| High | Breach | Golden State Orthopedics & Spine: Brain Cipher Ransomware Extortion | 2026-09-05 |
| Critical | CVE · KEV | CVE-2026-86149: Critical OS Command Injection in Tenda CP3 Firmware | 2026-09-05 |
| High | Ransomware | DaVita: Interlock Ransomware Class Action Settled for $15M | 2026-09-05 |
| Critical | CVE · KEV | CVE-2026-86190: WWBN AVideo Leaks Password Hashes and Session Tokens to Anyone Who Asks | 2026-09-05 |
| Critical | CVE · KEV | Tenda CP3 Camera Hit With Critical Command Injection Flaw (CVE-2026-86148) | 2026-09-05 |
| High | Breach | Pará State Civil Police: S3roqu3l Claims 2.5 TB Law Enforcement Data Breach | 2026-09-05 |
| High | Breach | IDScan.net: Nexus Dark Web Identity Service Advertises 153M+ Driver's License Scans | 2026-09-05 |
| Critical | CVE · KEV | CVE-2026-85695: Unauthenticated Worker Registration in FastChat Enables Model Spoofing and SSRF | 2026-09-04 |
| High | Ransomware | Hungry Lion: MedusaLocker Ransomware Leak Site Listing | 2026-09-04 |
| Critical | CVE · KEV | CVE-2026-85046: Actively Exploited Chromium V8 Type Confusion Lands on CISA KEV | 2026-09-04 |
| Critical | CVE · KEV | CVE-2026-85696: Critical Command Injection in SadTalker via Audio Filenames | 2026-09-04 |
| Critical | CVE · KEV | CVE-2026-85661: Critical Path Traversal in excel-mcp-server Grants Arbitrary File Read/Write | 2026-09-04 |
| Critical | CVE · KEV | CVE-2026-85684: Unauthenticated Path Traversal in marker Lets Attackers Write or Delete Any File | 2026-09-04 |
| High | Breach | Mexican Government Agencies: AI-Assisted Intrusion and Mass Data Theft | 2026-09-04 |
| Critical | CVE | CVE-2026-18658: Unauthenticated SQL Injection in IBM Operational Decision Manager Enables Remote Code Execution | 2026-09-04 |
| Critical | CVE · KEV | CVE-2026-85672: Critical OS Command Injection in zerox Document Processing | 2026-09-04 |
| High | Breach | Gale Credit Union: Akira Ransomware Data Theft and Extortion | 2026-09-04 |
| Critical | CVE · KEV | CVE-2026-85667: Unauthenticated Webhook Message Injection in TeamWiseFlow xiaobei | 2026-09-04 |
| High | Ransomware | Chip 1 Exchange: Aurora Ransomware Claims 13 Years of Exfiltrated Corporate Data | 2026-09-04 |
| Critical | CVE · KEV | CVE-2026-85146: Hard-Coded SSH Credentials in Lightstar SmartIT Desktop Manager | 2026-09-04 |
| High | Ransomware | DiaSorin S.p.A.: Settra Ransomware Extortion Claim | 2026-09-04 |
| Critical | CVE · KEV | CVE-2026-15354: Unauthenticated Account Takeover in ACPT (Premium) for WordPress | 2026-09-04 |
| High | Ransomware | INCAN Guatemala: Krybit Ransomware Halts Radiotherapy for 194 Cancer Patients | 2026-09-04 |
| Critical | CVE · KEV | CVE-2026-11613: Unauthenticated Local File Inclusion in Divi Ajax Filter for WordPress | 2026-09-04 |
| Critical | CVE · KEV | CVE-2026-85688: Unauthenticated File Read/Write in TEN Framework TMAN Designer | 2026-09-04 |
| Critical | CVE · KEV | CVE-2026-85148: Hard-Coded Credentials in Lightstar SmartIT Desktop Manager Allow Unauthenticated Remote Access | 2026-09-04 |
| High | Ransomware | Five US Healthcare Providers: INC Ransom and Anubis Claim Patient Data Breaches | 2026-09-04 |
| High | Breach | CareCloud: Unattributed Six Day AWS Intrusion Exposing 3.75 Million Patients | 2026-09-03 |
| Critical | CVE · KEV | CVE-2026-70352: Missing Authentication in Azure AI Language Authoring | 2026-09-03 |
| Critical | CVE · KEV | CVE-2026-85437: Critical Buffer Overflows in MOOS-IvP Autonomy Function Decoders | 2026-09-03 |
| Critical | CVE · KEV | CVE-2026-85154: WWBN AVideo Video Hash Doubles as a Permanent Account Credential | 2026-09-03 |
| Critical | CVE · KEV | CVE-2026-85435: Unauthenticated Shore Route Enrollment in MOOS-IvP uFldNodeBroker | 2026-09-03 |
| Critical | CVE | CVE-2026-85434: Unverified Node Pings Let Attackers Hijack MOOS-IvP Bridge Routes | 2026-09-03 |
| Critical | CVE · KEV | CVE-2026-85440: Pre-Auth Heap Overflow in MOOS core-moos Robotics Middleware | 2026-09-03 |
| Critical | CVE · KEV | CVE-2026-85430: Unauthenticated UDP Spoofing in MOOS pShare | 2026-09-03 |
| Critical | CVE · KEV | CVE-2026-85031: Buffer Overflow in TOTOLINK CP450 Router Firmware | 2026-09-03 |
| Critical | CVE · KEV | CVE-2026-85426: Command Injection in MOOS-IvP uMemWatch | 2026-09-03 |
| Critical | CVE · KEV | CVE-2026-85433: Unauthenticated Route Hijacking in MOOS pShare | 2026-09-03 |
| Critical | CVE · KEV | CVE-2026-85394: python-jose Algorithm Confusion via DER-Encoded Public Key as HMAC Secret | 2026-09-03 |
| Critical | CVE · KEV | CVE-2026-85424: MOOS core-moos MOOSDB Exposes Full Publish, Subscribe, and Database Wipe to Unauthenticated Clients | 2026-09-03 |
| Critical | CVE · KEV | CVE-2026-85425: Command Injection in MOOS-IvP iSay Speech Handler | 2026-09-03 |
| Critical | CVE · KEV | Microsoft Azure AD B2C Authorization Bypass (CVE-2026-83711) Hits Maximum CVSS 10.0 | 2026-09-03 |
| High | Breach | Thomson Reuters: C-Track Court Records Breach | 2026-09-03 |
| Critical | CVE · KEV | CVE-2026-85183: Wildcard CORS in Taipy Enables Cross-Site WebSocket Hijacking | 2026-09-03 |
| Critical | CVE · KEV | CVE-2026-85438: Critical Buffer Overflow in MOOS-IvP Autonomy Payload Decoder | 2026-09-03 |
| Critical | CVE · KEV | CVE-2026-85224: Command Injection in D-Link DNS-320 ShareCenter File Sharing | 2026-09-03 |
| High | Ransomware | Jack Henry: ShinyHunters Vishing Breach and Extortion Attempt | 2026-09-03 |
| Critical | CVE · KEV | CVE-2026-85223: Public Exploit for Command Injection in D-Link DNS-340L NAS | 2026-09-03 |
| High | Breach | Tving: Stolen Developer Access Key Exposes 39.54 Million Accounts | 2026-09-03 |
| Critical | CVE · KEV | CVE-2026-85428: Unauthenticated Variable Write in MOOS MOOSDB HTTP Server | 2026-09-03 |
| Critical | CVE · KEV | CVE-2026-62916: Critical Authentication Bypass in Microsoft Entra ID | 2026-09-03 |
| Critical | CVE · KEV | CVE-2026-85222: Command Injection in D-Link DNS-340L Add-On Center | 2026-09-03 |
| Critical | CVE · KEV | CVE-2026-80098: Critical Signature Verification Flaw in Microsoft Copilot Studio | 2026-09-03 |
| Critical | CVE · KEV | CVE-2026-83548: Pre-Auth SSRF in SonicWall SMA1000 Hits CVSS 10.0, Now in CISA KEV | 2026-09-02 |
| Critical | CVE · KEV | CVE-2026-59822: LiteLLM MCP Endpoint Accepts Any Bearer Token | 2026-09-02 |
| Critical | CVE · KEV | CVE-2026-83549: SonicWall SMA1000 Command Injection Added to CISA KEV | 2026-09-02 |
| High | Breach | IDScan.net: Nexus Dark Web Service Selling 153M Driver's License Scans | 2026-09-02 |
| Critical | CVE · KEV | CVE-2026-84795: Craft CMS Admin Flag Inheritance Grants Instant Administrator Access | 2026-09-02 |
| Critical | CVE · KEV | Sangoma Switchvox CVE-2026-9586: Unauthenticated SQL Injection Lands in CISA KEV | 2026-09-02 |
| High | Breach | Taiwan Ministry of Digital Affairs: Autonomous AI Agent Swarm Breach | 2026-09-02 |
| Critical | CVE · KEV | CVE-2026-66786: Submariner Config Injection Grants Root RCE on Kubernetes Gateway Nodes | 2026-09-02 |
| Critical | CVE · KEV | CVE-2026-84803: Stored XSS in SiYuan Asset Serving Lets Attackers Steal API Tokens | 2026-09-02 |
| Critical | CVE · KEV | CVE-2026-48710: Starlette Host Header Flaw Enables Path Injection and Auth Bypass | 2026-09-02 |
| High | Breach | Aesto Health: AWS Intrusion Exposes 9.5 Million Patient Records | 2026-09-02 |
| Critical | CVE · KEV | CVE-2026-82329: Unauthenticated Admin Takeover in JFrog Artifactory Lands on CISA KEV | 2026-09-02 |
| Critical | CVE · KEV | CVE-2026-49869: Unauthenticated RCE in Kestra OSS Lands on CISA KEV | 2026-09-02 |
| High | Ransomware | Nutex Health: The Gentlemen Ransomware Data Theft and Extortion | 2026-09-02 |
| Critical | CVE · KEV | CVE-2026-18550: Unauthenticated Admin Account Takeover in Nokri Job Board WordPress Theme | 2026-09-01 |
| Critical | CVE · KEV | CVE-2026-84200: Kyverno Policy Bypass via Conflicting PolicyExceptions | 2026-09-01 |
| Critical | CVE · KEV | CVE-2026-18765: Critical Unauthenticated SQL Injection in Teracity E-OSB | 2026-09-01 |
| Critical | CVE · KEV | CVE-2026-84479: WWBN AVideo Authentication Bypass via a Spoofed User-Agent Header | 2026-09-01 |
| Critical | CVE · KEV | CVE-2026-75865: Unauthenticated File Upload in WPLP Cookie Consent for WordPress | 2026-09-01 |
| Critical | CVE · KEV | CVE-2023-54391: Proxmox VE Authentication Bypass via tfa-challenge Parameter | 2026-09-01 |
| Critical | CVE · KEV | CVE-2026-84699: Unauthenticated Password Reset Bypass in Team Password Manager | 2026-09-01 |
| Critical | CVE · KEV | CVE-2026-84480: WWBN AVideo Password Recovery Tokens Reported to Never Expire | 2026-09-01 |
| Critical | CVE · KEV | CVE-2026-83772: Public Command Injection Exploit in Cobham SATCOM VSAT7090 Maritime Routers | 2026-09-01 |
| High | Ransomware | Hyderabad Publishing House: €20M Ransomware Extortion | 2026-08-31 |
| Critical | CVE · KEV | CVE-2026-82874: ToolJet Cross-Tenant Authorization Bypass in tooljet-db | 2026-08-31 |
| Critical | CVE · KEV | CVE-2026-82971: Unauthenticated Command Injection in QVidium Opera11 (No Patch Expected) | 2026-08-31 |
| Critical | CVE · KEV | CVE-2026-82689: OS Command Injection in D-Link DNS-Series NAS ISO Image Handler | 2026-08-31 |
| Critical | CVE · KEV | CVE-2026-82860: Critical IAM Guardrail Bypass in @hulumi/policies | 2026-08-31 |
| Critical | CVE · KEV | CVE-2026-82688: OS Command Injection in D-Link DNS-340L and DNS-345 NAS Devices | 2026-08-31 |
| Critical | CVE · KEV | CVE-2026-82859: Critical IAM Boundary Bypass in hulumi Deployment SCP Template | 2026-08-31 |
| Critical | CVE · KEV | CVE-2026-82872: ToolJet Cross-Workspace Authorization Bypass Lets Admins Reach Other Tenants' Databases | 2026-08-31 |
| Critical | CVE · KEV | CVE-2026-82870: ToolJet Cross-Tenant Database Manipulation Flaw Lets Builders Drop Other Orgs' Tables | 2026-08-31 |
| Critical | CVE · KEV | CVE-2026-82856: Critical IAM Trust Policy Bypass in @hulumi/policies | 2026-08-31 |
| Critical | CVE · KEV | CVE-2026-82690: OS Command Injection in D-Link DNS-327L and DNS-340L NAS Devices | 2026-08-31 |
| Critical | CVE · KEV | CVE-2026-82691: Command Injection in D-Link DNS-Series NAS CGI Handler | 2026-08-31 |
| Critical | CVE · KEV | TOTOLINK NR1800X Stack Overflow in setUploadSetting (CVE-2026-82616) | 2026-08-31 |
| Critical | CVE · KEV | CVE-2026-82857: Critical Privilege Escalation in hulumi IAM Policy | 2026-08-31 |
| Critical | CVE · KEV | PaperCut NG/MF Under Active Attack: CISA Adds CVE-2026-81578 to KEV | 2026-08-31 |
| Critical | CVE · KEV | CVE-2026-82693: Unauthenticated Telnet Endpoint in Tenda AC1206 Routers | 2026-08-31 |
| Critical | CVE · KEV | CVE-2026-82855: Critical Evidence Validation Bypass in @hulumi/policies | 2026-08-31 |
| Critical | CVE · KEV | CVE-2026-82078: PaperCut NG/MF Unsafe Reflection Flaw Added to CISA KEV | 2026-08-31 |
| Critical | CVE · KEV | CVE-2026-82854: Critical SMTP Command Injection in Nodemailer | 2026-08-31 |
| Critical | CVE · KEV | CVE-2026-82692: OS Command Injection in D-Link DNS-340L and DNS-345 NAS Devices | 2026-08-31 |
| High | Breach | France's Ministry of Housing: ZeroBytes Claims a 149 Million Record Database Theft | 2026-08-31 |
| High | CVE | CVE-2026-83524: Command Injection in RedPort Optimizer wXa Satellite Routers | 2026-08-31 |
| Critical | CVE · KEV | Dokploy Path Traversal (CVE-2026-82954): Public Exploit, No Vendor Response | 2026-08-31 |
| High | Ransomware | Globus Medical: Falcon Ransomware Leak Site Claim | 2026-08-31 |
| Critical | CVE · KEV | Tenda AC18 Ships an Unauthenticated Telnet Endpoint | 2026-08-31 |
| Critical | CVE · KEV | Tenda AC1206: Unauthenticated Access to /goform/ate (CVE-2026-82694) | 2026-08-31 |
| Critical | CVE · KEV | CVE-2026-82593: Stack Overflow in D-Link DIR-825M LTE Firmware Upgrade Handler | 2026-08-30 |
| High | Breach | Lucid Motors: SovCali Ransomware Vendor Breach and Double Extortion | 2026-08-30 |
| Critical | CVE · KEV | CVE-2026-82592: Stack Overflow in D-Link DIR-825M Disk Format Handler | 2026-08-30 |
| Critical | CVE · KEV | CVE-2026-82539: Memory Corruption in TOTOLINK A720R MAC Filtering | 2026-08-30 |
| High | Breach | Abbott Laboratories: ShinyHunters Vishing Breach and 10.9M Record Leak | 2026-08-30 |
| High | Breach | Hasbro: Compromised Employee Account Exposes Worker SSNs and Financial Data | 2026-08-30 |
| Critical | CVE · KEV | CVE-2026-15980: Critical Authentication Bypass in MyHome Core WordPress Plugin | 2026-08-30 |
| Critical | CVE · KEV | CVE-2026-82542: Critical Buffer Overflow in Tenda HG10 Boa Web Server | 2026-08-30 |
| High | Ransomware | Winona County, Minnesota: Double Ransomware Compromise and a $128,539.57 Payment | 2026-08-29 |
| Critical | CVE · KEV | CVE-2026-82448: Hardcoded Child Node Key Exposes Shinobi Databases to Unauthenticated SQL Execution | 2026-08-29 |
| High | Breach | Shell, Philips and GE: Clop Mass Extortion via PTC Windchill Flaw | 2026-08-29 |
| High | Ransomware | US Law Firms: Silent Ransom Group (Luna Moth) Impersonation Extortion | 2026-08-29 |
| High | Breach | McKesson: ShinyHunters Extortion and Third-Party Application Data Theft | 2026-08-29 |
| Critical | CVE · KEV | CVE-2026-14494: Unauthenticated RCE in SigmaForms Pro for WordPress | 2026-08-29 |
| Critical | CVE · KEV | CVE-2026-82244: Critical RCE in Budibase Plugin Handling | 2026-08-28 |
| High | Breach | Boston Scientific: Unattributed Intrusion Causing Global Operational Disruption | 2026-08-28 |
| High | Ransomware | Central Ohio Primary Care Physicians: Chaos Ransomware Data Theft Claim | 2026-08-28 |
| Critical | CVE · KEV | CVE-2026-19286: Critical Unauthenticated RCE in IBM Langflow OSS | 2026-08-28 |
| Critical | CVE · KEV | CVE-2026-82082: Unauthenticated OS Command Injection in Green-Computing NUMail | 2026-08-28 |
| Critical | CVE | CVE-2026-18527: Critical Session Fixation in IBM Administration Runtime Expert for i | 2026-08-28 |
| Critical | CVE · KEV | CVE-2026-40541: Critical XSS in Synology Chat Server Enables Arbitrary File Read/Write on DSM | 2026-08-28 |
| Critical | CVE · KEV | CVE-2026-19295: Critical Command Execution Flaw in IBM Langflow OSS | 2026-08-28 |
| High | Breach | Christeyns and Six Others: Aur0ra Ransomware Drove SpaceX's Cursor AI Through Live Intrusions | 2026-08-28 |
| Critical | CVE · KEV | CVE-2026-82266: Redpanda Admin API Grants Unauthenticated Superuser Access by Default | 2026-08-28 |
| High | Ransomware | Ingram Micro: SafePay Ransomware Freezes Global Order Processing | 2026-08-28 |
| Critical | CVE · KEV | CVE-2026-76581: WPMU DEV Dashboard Authentication Bypass Hands Attackers Admin Sessions | 2026-08-28 |
| Critical | CVE · KEV | CVE-2026-82277: Argo Rollouts Dashboard Exposes Unauthenticated Mutating Operations | 2026-08-28 |
| High | Breach | Berlin State Government: Rhysida Ransomware Data Extortion | 2026-08-28 |
| Critical | CVE · KEV | CVE-2026-3627: Critical SQL Injection in IBM Concert | 2026-08-28 |
| High | Ransomware | Micro-Comm: Barracuda Ransomware and Data Exfiltration at a US Water Sector Supplier | 2026-08-27 |
| High | CVE | CVE-2026-81735: UI-TARS-desktop MCP Servers Bind All Interfaces With No Authentication | 2026-08-27 |
| High | Breach | NASA, DOJ and the Federal Reserve: QTFY Chinese State-Sponsored Intrusion Campaign | 2026-08-27 |
| High | Ransomware | DigitalMint Clients: BlackCat Insider Extortion Conspiracy | 2026-08-27 |
| High | Ransomware | Ryuk Ransomware Victims: Armenian Operator Pleads Guilty in $15M Extortion Case | 2026-08-27 |
| High | Ransomware | ATF: Qilin Ransomware Claim on Federal Firearms Investigation System | 2026-08-27 |
| High | Breach | Manchester Airports Group: 8.7 Million Customer Records Taken in Third Party Intrusion | 2026-08-27 |
| High | Breach | Hugging Face: Autonomous OpenAI Agents Chained Zero-Days to Breach Production | 2026-08-27 |
| High | Ransomware | ShipERP (ERPIS LLC): Aurora Ransomware Supply Chain Extortion | 2026-08-27 |
| High | Breach | Knottingham Trent University: ShadowByt3$ Web Application Breach and Extortion Claim | 2026-08-27 |
| Critical | CVE · KEV | CVE-2026-74232: Backdoor C2 Implant Ships in Zbtlink, MoreQuick, and OEM Router Firmware | 2026-08-27 |
| Critical | CVE · KEV | CVE-2026-66384: JFrog Artifactory Path Traversal Added to CISA KEV | 2026-08-27 |
| High | Ransomware | WireCo: Qilin Ransomware Leak Site Listing | 2026-08-27 |
| Critical | CVE · KEV | CVE-2026-81702: Identity Store Key Substitution in openssl_encrypt | 2026-08-27 |
| Critical | CVE · KEV | CVE-2026-53362: Linux Kernel IPv6 Heap Overflow Added to CISA KEV | 2026-08-27 |
| Critical | CVE · KEV | CVE-2026-74233: Unauthenticated Root Command Injection in Zbtlink Router Firmware | 2026-08-27 |
| High | Ransomware | Tift Regional Health System: Hive Ransomware Breach Settled for $1.2 Million | 2026-08-27 |
| Critical | CVE · KEV | CVE-2026-81707: ANSI Escape Injection in openssl_encrypt Forges Key Fingerprints | 2026-08-27 |
| High | Breach | U.S. Government Entity: Kairos Data-Theft Extortion, $1 Million Paid | 2026-08-27 |
| Critical | CVE · KEV | CVE-2023-49105: ownCloud WebDAV Authentication Bypass Added to CISA KEV | 2026-08-27 |
| Critical | CVE · KEV | CVE-2021-23758: AjaxPro Deserialization Flaw Added to CISA KEV | 2026-08-26 |
| High | Breach | Moroccan Intelligence and Security Services: JabaROOT DZ Leaks Data on 70,000 Agents | 2026-08-26 |
| High | Breach | Department of Homeland Security: Unattributed Intruders Breach the HSIN Information Sharing Network | 2026-08-26 |
| High | Breach | Federal Reserve: QTFY Chinese State Hacking Platforms Seized by DOJ | 2026-08-26 |
| High | Ransomware | Davis & Ferber: Akira Ransomware Leak Site Listing | 2026-08-26 |
| High | Breach | Asian Government Entities: Autonomous Multi-Agent AI Intrusion | 2026-08-26 |
| High | Breach | Ohio County Government: Kairos Data-Theft Extortion, $1M Ransom Paid | 2026-08-26 |
| High | Breach | George House Trust: HIV Service User Data Stolen in Beacon CRM Supply Chain Breach | 2026-08-26 |
| Critical | CVE | CVE-2026-80428: Unauthenticated PHP Object Injection in ILIAS Shibboleth Logout Endpoint | 2026-08-26 |
| Critical | CVE · KEV | CVE-2019-1068: Microsoft SQL Server Remote Code Execution Flaw Added to CISA KEV | 2026-08-26 |
| High | Breach | Nutex Health: Unattributed Intrusion and Data Exfiltration | 2026-08-26 |
| High | Breach | Asian Government Entities: Autonomous Multi-Agent AI Intrusion Framework | 2026-08-26 |
| Critical | CVE · KEV | CVE-2015-5287: Red Hat ABRT Symlink Privilege Escalation Added to CISA KEV | 2026-08-26 |
| Critical | CVE · KEV | CVE-2022-0995: Linux Kernel watch_queue Out-of-Bounds Write Added to CISA KEV | 2026-08-26 |
| Critical | CVE · KEV | Citrix NetScaler ADC and Gateway Memory Overflow Flaw Added to CISA KEV (CVE-2026-8452) | 2026-08-26 |
| High | Breach | LACMA: Unattributed Intrusion Exposed Social Security Numbers and Medical Records | 2026-08-26 |
| High | Breach | Paylogix: Akira-Linked Intrusion Exposes Benefits and Medical Records | 2026-08-26 |
| High | Ransomware | Eyecare Center of Snohomish: TheGentlemen Ransomware and Patient Data Theft | 2026-08-26 |
| High | Breach | Stripe Merchants: Leaked Live API Keys and Mass Customer Data Exposure | 2026-08-26 |
| High | Breach | U.S. Critical Infrastructure: Iranian MOIS Hacking Cell Sanctioned in Operation Economic Outcast | 2026-08-26 |
| High | Breach | Wesco International: ExfilSquad Cloud CRM Exfiltration and Leak | 2026-08-26 |
| Critical | CVE · KEV | CVE-2015-3246: Red Hat Libuser Race Condition Added to CISA KEV | 2026-08-26 |
| High | Breach | Preferred Parking: Unauthorized Actor Steals Customer Payment Card Data | 2026-08-26 |
| High | Breach | Mercor: Lapsus$ Extortion Claims and a 4TB Dark Web Listing | 2026-08-26 |
| Critical | CVE · KEV | Adminer Pre-Auth RCE via PDO DSN Injection (CVE-2026-56705) | 2026-08-25 |
| Critical | CVE · KEV | CVE-2026-80104: Unauthenticated Path Traversal in DB-GPT Leads to Remote Code Execution | 2026-08-25 |
| High | Breach | Directorate of Secondary and Higher Education: Madarax Leak of 390,000 Government Records | 2026-08-25 |
| Critical | CVE | CVE-2026-78683: Critical Pickle Deserialization RCE in NLTK | 2026-08-25 |
| High | Breach | Oz Hair & Beauty: xpl0itrs Extortion Leak Exposes Customer Contact Data | 2026-08-25 |
| High | Breach | Baylor Genetics: Network Intrusion Exposes Genetic Test Records of 310,000 Patients and Staff | 2026-08-25 |
| Critical | CVE · KEV | CVE-2026-79787: Alluxio S3 REST Proxy Authentication Bypass Lets Anyone Impersonate Any User | 2026-08-25 |
| Critical | CVE · KEV | GitPython Config Injection Flaw (CVE-2026-78676) Enables Remote Code Execution | 2026-08-25 |
| High | Breach | Odido: ShinyHunters Drip-Feed Extortion Leak | 2026-08-25 |
| Critical | CVE · KEV | CVE-2026-79675: Critical JVM Argument Injection in NLTK Leads to Remote Code Execution | 2026-08-25 |
| Critical | CVE · KEV | CVE-2026-56710: Grav Login Plugin Flaw Lets Low-Privilege Users Strip Brute-Force Protection From Admins | 2026-08-25 |
| High | Breach | HCLTech: TheHatman Azure Tenant Data Sale | 2026-08-25 |
| Critical | CVE · KEV | CVE-2026-16286: Critical Web Shell Upload Flaw in TRtek Software Repository Management | 2026-08-25 |
| High | Breach | Apollo Global Management: Social Engineering Breach of Cloud Platforms Exposes SSNs | 2026-08-25 |
| High | Breach | Taiwan Government: Near-Autonomous AI Agent Intrusion | 2026-08-25 |
| High | Breach | CISA: Contractor Exposed AWS GovCloud Keys on a Public GitHub Repo | 2026-08-25 |
| Critical | CVE · KEV | CVE-2026-80138: Unauthenticated Command Injection in ClipBucket V5 Installer | 2026-08-25 |
| Critical | CVE · KEV | CVE-2026-78568: Unauthenticated SQL Injection in WordPress Total Donations Plugin | 2026-08-25 |
| High | Breach | Connecticut DSS: Financially Motivated Intruder in the HUSKY Medicaid Provider Portal | 2026-08-25 |
| Critical | CVE · KEV | CVE-2024-58378: Use-After-Free in Nokogiri's XML Reader via Bundled libxml2 | 2026-08-25 |
| High | Breach | Seoul Facilities Corporation: 4.62 Million Ttareungyi Riders Exposed in Teen Hacker Intrusion | 2026-08-25 |
| High | Breach | U.S. Supreme Court: Stolen Credential Abuse by a Self Doxxing Intruder | 2026-08-25 |
| Critical | CVE · KEV | CVE-2026-79911: Critical Stack Buffer Overflow in TOTOLINK N600R CGI Handler | 2026-08-25 |
| Critical | CVE · KEV | CVE-2026-60004: Gitea Code Injection Flaw Added to CISA KEV | 2026-08-25 |
| High | Breach | Serbian Citizen Data: INF GRUPA Advertises 4.3 Million Record Sale | 2026-08-25 |
| High | Breach | Maxia Latam: Alleged Supply Chain Data Leak Exposing Panamanian Government Personnel and CSS Credentials | 2026-08-25 |
| Critical | CVE · KEV | CVE-2026-79657: Critical RCE in NLTK Pickle Loaders | 2026-08-25 |
| Critical | CVE · KEV | Adobe Campaign Classic SSRF Scores a Perfect 10.0 — CVE-2026-76193 | 2026-08-25 |
| Critical | CVE · KEV | CVE-2026-78570: Unauthenticated Privilege Escalation in WordPress Total Donations Plugin | 2026-08-25 |
| Critical | CVE · KEV | Adobe Campaign Classic Hit With Perfect-Score OS Command Injection Flaw (CVE-2026-76197) | 2026-08-25 |
| Critical | CVE · KEV | CVE-2026-63586: Unauthenticated Root Command Injection in Weidmueller Industrial Routers | 2026-08-25 |
| Critical | CVE · KEV | CVE-2022-51000: Nokogiri Ships Vulnerable Vendored libxml2 and libxslt | 2026-08-25 |
| Critical | CVE · KEV | CVE-2026-78477: Critical Unauthenticated Privilege Escalation in WordPress Jawn Theme | 2026-08-25 |
| Critical | CVE · KEV | CVE-2026-76195: Adobe Campaign Classic OS Command Injection (CVSS 10.0) | 2026-08-25 |
| High | Ransomware | Clear Align: Qilin Ransomware Leak Site Claim | 2026-08-25 |
| High | Breach | Gruppo Spaggiari Parma: xpl0itrs Extortion Claim Over Italian School Data | 2026-08-24 |
| High | Breach | Protection Civile: Unattributed Breach of the e-Protec Volunteer Platform | 2026-08-24 |
| High | Ransomware | CyrusOne: ShinyHunters Extortion Claim and Alleged Salesforce Data Theft | 2026-08-24 |
| High | Ransomware | Namyang Industrial: Barracuda Ransomware Data Leak | 2026-08-24 |
| High | Ransomware | Tower Insurance: CoinbaseCartel Ransomware Extortion Claim | 2026-08-24 |
| High | Breach | US Bank: LockBit Extortion Claim and September 3 Leak Deadline | 2026-08-24 |
| High | Breach | ASOS: Credential Stuffing Attack Exposes US Customer Accounts | 2026-08-24 |
| High | Breach | European Commission: TeamPCP Supply Chain Intrusion and ShinyHunters Leak | 2026-08-24 |
| Critical | CVE · KEV | CVE-2026-71933: Missing Authorization in DrayTek VigorSwitch Syslog Functions | 2026-08-24 |
| High | Breach | Canada Goose: ShinyHunters Data Leak and Third Party Attribution Dispute | 2026-08-24 |
| Critical | CVE · KEV | CVE-2026-77915: rConfig Authentication Bypass Grants Unauthenticated Admin Registration | 2026-08-24 |
| High | Ransomware | Integrated Health Systems: CoinbaseCartel Extortion Claim | 2026-08-24 |
| Critical | CVE · KEV | Oracle HTTP Server and WebLogic Proxy Plug-in Hit CVSS 10.0 Access Control Flaw — Now in CISA KEV | 2026-08-24 |
| High | Breach | Baxter International: ShinyHunters Salesforce Extortion Leak | 2026-08-24 |
| High | Ransomware | Corona Corporation: MetaEncryptor Ransomware Leak Site Listing | 2026-08-24 |
| Critical | CVE · KEV | CVE-2026-76071: Unauthenticated Root RCE in Netis NC63 Routers | 2026-08-24 |
| High | Breach | ReliaQuest: ShinyHunters Vishing and SSO Phishing Attack | 2026-08-24 |
| High | Breach | Carnival Corporation: ShinyHunters Social Engineering Breach | 2026-08-24 |
| Critical | CVE · KEV | CVE-2026-71921: Pre-Auth Command Injection in DrayTek VigorSwitch Series | 2026-08-24 |
| Critical | CVE · KEV | CVE-2026-5388: justhtml Sanitization Bypass Allows HTML and JavaScript Injection | 2026-08-23 |
| High | Breach | Progress MOVEit Customers: Cl0p Zero-Day Mass Exfiltration | 2026-08-23 |
| High | Breach | Jones Day: Luna Moth Callback Phishing Extortion | 2026-08-23 |
| Critical | CVE · KEV | CVE-2026-78207: Critical Prototype Pollution in exceljs Note Merging | 2026-08-23 |
| High | Breach | PTC Windchill Customers: Cl0p Mass Exploitation and Leak Site Extortion | 2026-08-23 |
| High | Ransomware | NovoCure Limited: ShinyHunters Pay-or-Leak Extortion Claim | 2026-08-23 |
| High | Breach | McDonald's, Vodafone and TCS: TheHatman Azure Tenant Data Theft | 2026-08-23 |
| High | Breach | Latvia's CSDD: Unattributed Intrusion Exposes 1.2 Million Citizens | 2026-08-23 |
| High | Breach | SFR: ZeroBytes Fibre Customer Data Breach | 2026-08-23 |
| High | Ransomware | RXPE Group: CoinbaseCartel Leak Site Extortion Claim | 2026-08-23 |
| Critical | CVE · KEV | CVE-2026-7808: Multiple Sanitization Bypasses in justhtml Before 1.16.0 | 2026-08-23 |
| High | Ransomware | EVNHANOI: Emperador Ransomware Data Extortion Claim | 2026-08-23 |
| Critical | CVE · KEV | CVE-2026-8445: justhtml Markdown Conversion Bypasses HTML Sanitization | 2026-08-23 |
| High | Ransomware | Fairlife: Anubis Ransomware Double Extortion | 2026-08-23 |
| High | Breach | Cognizant: April 21 Breach Exposes Customer Personal Data | 2026-08-23 |
| High | Breach | SickKids: Third-Party Careers Software Exploited, Staff and Applicant Data Exposed | 2026-08-23 |
| High | Breach | BOK Financial: ShinyHunters Data Extortion Deadline | 2026-08-23 |
| High | Breach | Fortune 500 Azure Tenants: TheHatman Employee Directory Data Sale | 2026-08-23 |
| High | Breach | Instructure Canvas: ShinyHunters Supply Chain Data Theft Hits Hong Kong Institutions | 2026-08-22 |
| Critical | CVE · KEV | Comfast CF-N1-S Hit by Critical Stack Overflow in Web Management NTP Handler | 2026-08-22 |
| High | Breach | Apple American Group: Unknown Actor Steals Employee SSNs, Health and Biometric Data | 2026-08-22 |
| High | Ransomware | WilmerHale and Goodwin Procter: Luna Moth Helpdesk Impersonation Extortion | 2026-08-22 |
| High | Breach | LATAM Airlines Brasil: Latam Pass Loyalty Breach Exposes BIN and Member Data | 2026-08-22 |
| Critical | CVE · KEV | CVE-2026-77946: Critical Stack Overflow in TRENDnet TEW-821DAP NTP Handler | 2026-08-22 |
| High | Breach | Samagra Portal: Unauthorised Record Edits Trigger Cyber Police Probe | 2026-08-22 |
| High | Ransomware | Battle Creek Public Schools: Rhysida Ransomware Data Extortion | 2026-08-22 |
| High | Breach | Turner Construction: Payouts King Ransomware Data Theft | 2026-08-22 |
| High | Breach | DGFiP: ZeroBytes Credential Theft and MFA Bypass | 2026-08-22 |
| Critical | CVE · KEV | CVE-2026-78003: Unauthenticated SSRF in Mailgun for WordPress | 2026-08-22 |
| Critical | CVE · KEV | CVE-2026-4703: Unauthenticated PHP Object Injection in WS Form LITE for WordPress | 2026-08-22 |
| High | Breach | McDonald's, TCS and Vodafone: TheHatman Azure Tenant Data Sale | 2026-08-22 |
| High | Ransomware | Acima: iah6477 Ransomware Listing and a $13M Lease Fraud Trail | 2026-08-22 |
| High | Breach | 102 South Korean Institutions: Lazarus-Linked Intrusion via Compromised Certification Authority | 2026-08-22 |
| High | Breach | Connecticut DSS and Gainwell Technologies: Provider Portal Account Takeover | 2026-08-22 |
| High | Breach | General Electric and Philips: Clop Extortion via PTC Windchill Zero-Day | 2026-08-21 |
| Critical | CVE · KEV | CVE-2026-77776: Headroom LLM Proxy Trusts a Client-Supplied User ID Header | 2026-08-21 |
| Critical | CVE · KEV | CVE-2026-73570: Unauthenticated Command Injection in Zimbra Collaboration Suite | 2026-08-21 |
| High | Ransomware | Kingston Technology: Everest Ransomware Extortion Claim | 2026-08-21 |
| High | Breach | US Critical Infrastructure: AI-Generated Exploit Scripts Targeting Siemens S7 PLCs | 2026-08-21 |
| High | Breach | MyDr: Criminal Extortion Crew Steals Medical Data on Nearly 19 Million Poles | 2026-08-21 |
| High | Breach | Lockheed Martin: Iran-Linked APT IRAN Discounts an Unverified 375TB Data Trove | 2026-08-21 |
| High | Breach | South Korean Certification Agency: Server Breach Exposes Blue House Officials' Data | 2026-08-21 |
| High | Breach | Apollo Global Management: Vishing-Led Cloud Breach Tied to Financial Sector Extortion Wave | 2026-08-21 |
| Critical | CVE · KEV | CVE-2026-77683: Command Injection in Comfast CF-N1-S Wireless Devices | 2026-08-21 |
| High | Breach | Alation: Confirmed Cyberattack, Unattributed Intrusion | 2026-08-21 |
| High | Breach | Novo Nordisk: FulcrumSec Data Theft and Staged Extortion Leak | 2026-08-21 |
| High | Ransomware | Inission Power: Deadlock-Linked Ransomware and Employee Data Leak | 2026-08-21 |
| High | Ransomware | U.S. Bank: LockBit Ransomware Extortion Claim | 2026-08-21 |
| High | Ransomware | Medochemie: Qilin Ransomware Leak Site Listing | 2026-08-21 |
| High | Breach | MyDr: Criminal Intrusion Exposing Health Records on Nearly 19 Million Poles | 2026-08-20 |
| Critical | CVE · KEV | CVE-2026-11861: FreeIPA PAC Verification Flaw Lets AD Users Impersonate Anyone in the Domain | 2026-08-20 |
| Critical | CVE · KEV | CVE-2026-14950: Session Expiration Flaw in Frauscher FDS 102 Rail Sensor Web Interface | 2026-08-20 |
| High | Ransomware | Babcock International: The Gentlemen Ransomware Leak Site Listing | 2026-08-20 |
| Critical | CVE · KEV | CVE-2026-16926: Critical Arbitrary File Overwrite in IBM AIX and PowerVM VIOS | 2026-08-20 |
| High | Ransomware | Capgemini Engineering: Everest Ransomware Leak Site Listing | 2026-08-20 |
| Critical | CVE · KEV | TrueConf Server Missing Authentication Flaw (CVE-2026-72529) Lands in CISA KEV | 2026-08-20 |
| Critical | CVE · KEV | CVE-2026-77022: Stack Buffer Overflow in Comfast CF-N1-S SSID Configuration | 2026-08-20 |
| Critical | CVE · KEV | CVE-2026-13097: FreeIPA Principal Uniqueness Flaw Enables Kerberos Impersonation and Domain Compromise | 2026-08-20 |
| High | Breach | Mabna Institute: IRGC-Backed Hacking-for-Hire Campaign Charged by DOJ | 2026-08-20 |
| High | Ransomware | Scholle IPN / SIG: Anubis Ransomware Leak Site Claim | 2026-08-20 |
| High | Breach | Oz Hair and Beauty: xpl0itrs Data Theft and Extortion Leak | 2026-08-20 |
| High | Breach | Sakura Internet: Sales Management System Breach Exposes Up to 1.36 Million Accounts | 2026-08-20 |
| High | Breach | MyDr: Unattributed Criminal Intrusion Exposing ~19 Million Polish Patient Records | 2026-08-20 |
| Critical | CVE · KEV | CVE-2026-72530: Critical Code Injection in TrueConf Server Under Active Exploitation | 2026-08-20 |
| Critical | CVE · KEV | CVE-2026-71470: Search CR Manipulation in Red Hat ACM Leads to Full Cluster Compromise | 2026-08-19 |
| Critical | CVE · KEV | CVE-2026-71960: Hard-Coded JWT Secret in Cudy WR3000 2.0 Enables MQTT Authentication Bypass | 2026-08-19 |
| Critical | CVE · KEV | CVE-2026-76008: Critical Stack Overflow in Comfast CF-N1-S Routers | 2026-08-19 |
| High | Ransomware | Cameron Regional Medical Center: Anubis Ransomware Data Theft and Leak | 2026-08-19 |
| Critical | CVE · KEV | CVE-2026-16834: Critical Integer Underflow in IBM AIX and PowerVM VIOS | 2026-08-19 |
| High | Breach | Berlin State Government: Unattributed Network Intrusion | 2026-08-19 |
| Critical | CVE · KEV | IBM AIX and PowerVM VIOS Hit With Critical 9.8 Heap Overflow (CVE-2026-16845) | 2026-08-19 |
| High | Breach | MyDr: Criminal Extortion Breach Exposes Medical Data on 19 Million Poles | 2026-08-19 |
| Critical | CVE · KEV | CVE-2026-16019: Critical SQL Injection in FAYDAM Datalogger | 2026-08-19 |
| Critical | CVE · KEV | CVE-2026-16822: Improper Certificate Validation in IBM AIX and PowerVM VIOS | 2026-08-19 |
| Critical | CVE · KEV | IBM Power Systems Firmware ASMI Flaw (CVE-2026-16687) Allows Unauthenticated Code Execution on the FSP | 2026-08-19 |
| Critical | CVE · KEV | CVE-2026-15068: Critical Command Injection in IBM AIX and PowerVM VIOS NIM | 2026-08-19 |
| Critical | CVE · KEV | CVE-2026-18315: Unauthenticated Account Takeover in WordPress TrueBooker Plugin | 2026-08-19 |
| High | Breach | Global Universities: Mabna Institute IRGC Directed Cyber Theft | 2026-08-19 |
| Critical | CVE · KEV | CVE-2026-64849: Critical SSRF in MLflow Webhook Test Endpoint Added to CISA KEV | 2026-08-19 |
| Critical | CVE · KEV | CVE-2026-16840: Critical Out-of-Bounds Write in IBM AIX and PowerVM VIOS | 2026-08-19 |
| Critical | CVE · KEV | CVE-2026-70496: Red Hat ACM search-v2-operator Ships Cluster-Admin Equivalent ClusterRole | 2026-08-19 |
| High | Breach | PTC Windchill Users: Cl0p Mass Exploitation and Extortion Campaign | 2026-08-19 |
| High | Breach | MyDr: 19 Million Polish Patient Records Exposed in a Two Year Detection Gap | 2026-08-19 |
| Critical | CVE · KEV | CVE-2026-76004: Stack-Based Buffer Overflow in UTT HiPER 1250GW Routers | 2026-08-19 |
| High | Ransomware | Mount Royal University: CMD Organization Ransomware and Wiper Attack | 2026-08-19 |
| Critical | CVE · KEV | CVE-2026-16839: Critical IBM AIX and PowerVM VIOS Flaw in IPv4 IP-Options Parser | 2026-08-19 |
| Critical | CVE · KEV | CVE-2026-16816: Critical Command Injection in IBM AIX and PowerVM VIOS | 2026-08-19 |
| Critical | CVE · KEV | CVE-2026-16656: Critical IBM Advisory Warns of Authentication Flaw That Could Grant Root on AIX and PowerVM VIOS | 2026-08-19 |
| Critical | CVE · KEV | CVE-2026-15065: IBM AIX and PowerVM VIOS NIM Leak Intermediate CA Private Keys | 2026-08-19 |
| High | Breach | RingCentral: ShinyHunters Vishing and Extortion Leak | 2026-08-19 |
| High | Breach | CareCloud: AWS Intrusion Toll Climbs to 3.7 Million | 2026-08-19 |
| High | Ransomware | City of Beacon, New York: RansomHouse Data Extortion | 2026-08-19 |
| Critical | CVE · KEV | CVE-2026-76003: Stack-Based Buffer Overflow in UTT HiPER 1200GW Routers | 2026-08-19 |
| Critical | CVE · KEV | CVE-2026-16862: Critical Remote Code Execution in IBM AIX and PowerVM VIOS | 2026-08-19 |
| High | Breach | Heights Finance: Third-Party Cloud Breach Exposes Borrower Financial Records | 2026-08-19 |
| High | Breach | Stripe Merchants: Satanic Data Release and Mass API Key Exposure | 2026-08-19 |
| Critical | CVE · KEV | CVE-2026-66794: Critical Auth Bypass in Red Hat Multicluster Engine Cluster Proxy Addon | 2026-08-19 |
| High | Breach | Quest Apartment Hotels: Third-Party Database Breach Exposes Guest PII | 2026-08-19 |
| Critical | CVE · KEV | CVE-2026-60672: Critical Unauthenticated Takeover in Oracle WebLogic Server Core | 2026-08-18 |
| Critical | CVE · KEV | Oracle Internet Directory Hit With 9.9-Rated LDAP Takeover Flaw (CVE-2026-61248) | 2026-08-18 |
| Critical | CVE · KEV | CVE-2026-60921: Critical Unauthenticated Takeover in Oracle WebCenter Enterprise Capture | 2026-08-18 |
| Critical | CVE · KEV | CVE-2026-75837: Grav Privilege Escalation via Unguarded Group Access Field | 2026-08-18 |
| Critical | CVE · KEV | CVE-2026-75784: Critical Unauthenticated Stack Overflow in TRENDnet TEW-WLC100 | 2026-08-18 |
| Critical | CVE · KEV | Oracle WebCenter Enterprise Capture Hit With 9.8 Unauthenticated RMI Takeover (CVE-2026-60946) | 2026-08-18 |
| Critical | CVE · KEV | CVE-2026-75851: ArcadeDB Async Command Authorization Bypass Grants Full Admin | 2026-08-18 |
| Critical | CVE · KEV | Oracle WebCenter Enterprise Capture: Unauthenticated RMI Takeover (CVE-2026-60947) | 2026-08-18 |
| High | Breach | French Ministry of Education: ZeroBytes Claims 43GB Breach of Pupil and Staff Systems | 2026-08-18 |
| Critical | CVE · KEV | Oracle Hyperion Infrastructure Technology Hit With 9.8 Unauthenticated Takeover Flaw (CVE-2026-62543) | 2026-08-18 |
| Critical | CVE · KEV | CVE-2026-75130: Prompt Injection in Context7 MCP Server Poisons AI Coding Agents | 2026-08-18 |
| Critical | CVE · KEV | CVE-2026-61008: Unauthenticated Critical Flaw in Oracle WebCenter Sites | 2026-08-18 |
| Critical | CVE · KEV | CVE-2026-62541: Critical Unauthenticated Takeover in Oracle Hyperion Infrastructure Technology | 2026-08-18 |
| Critical | CVE · KEV | CVE-2026-60782: Unauthenticated Takeover in Oracle E-Business Suite Payments | 2026-08-18 |
| Critical | CVE · KEV | Oracle JD Edwards EnterpriseOne Tools Hit by Critical Unauthenticated Takeover Flaw (CVE-2026-61272) | 2026-08-18 |
| Critical | CVE · KEV | CVE-2026-75852: ArcadeDB MongoDB Wire Protocol Authentication Bypass | 2026-08-18 |
| Critical | CVE · KEV | CVE-2026-62452: Critical Unauthenticated Flaw in Oracle Siebel CRM Cloud Applications | 2026-08-18 |
| Critical | CVE | Oracle Hyperion Calculation Manager Hit With 9.9 CVSS Takeover Flaw (CVE-2026-61206) | 2026-08-18 |
| Critical | CVE · KEV | CVE-2026-15748: Unauthenticated Arbitrary File Upload in WordPress Forminator Forms | 2026-08-18 |
| Critical | CVE · KEV | CVE-2026-59310: Critical Path Traversal in VMware vCenter Under Active Exploitation | 2026-08-18 |
| Critical | CVE · KEV | CVE-2026-62544: Critical Unauthenticated Takeover in Oracle Hyperion Infrastructure Technology | 2026-08-18 |
| Critical | CVE · KEV | CVE-2026-65400: Critical macOS Screen Sharing Authentication Bypass Added to CISA KEV | 2026-08-18 |
| Critical | CVE · KEV | CVE-2026-62457: Critical Unauthenticated Takeover in Oracle Hyperion Infrastructure Technology | 2026-08-18 |
| Critical | CVE · KEV | Oracle Internet Directory Hit With 9.8 Unauthenticated LDAP Takeover Flaw (CVE-2026-61258) | 2026-08-18 |
| Critical | CVE · KEV | Oracle WebCenter Sites Hit by Critical CVE-2026-61034 — CVSS 9.1 Flaw Enables Full Product Takeover | 2026-08-18 |
| Critical | CVE · KEV | CVE-2026-75783: Stack Overflow in TRENDnet TEW-WLC100P netifd DHCP Handler | 2026-08-18 |
| Critical | CVE · KEV | CVE-2026-55040: Critical SharePoint Authentication Bypass Added to CISA KEV | 2026-08-18 |
| Critical | CVE · KEV | Oracle Siebel CRM Integration Hit With CVSS 9.9 Scope-Changing Takeover Flaw | 2026-08-18 |
| Critical | CVE · KEV | Oracle PeopleSoft PeopleTools Business Interlink: Unauthenticated Takeover (CVE-2026-60821) | 2026-08-18 |
| Critical | CVE · KEV | Oracle WebLogic Server Core Flaw (CVE-2026-60702) Scores 9.9 — Full Takeover via T3/IIOP | 2026-08-18 |
| Critical | CVE · KEV | Oracle Siebel CRM Cloud Applications Hit With CVSS 9.9 Takeover Flaw (CVE-2026-61317) | 2026-08-18 |
| High | Breach | Latvia's CSDD: 1.2 Million Residents' Data Stolen in Targeted Intrusion | 2026-08-18 |
| Critical | CVE · KEV | Oracle WebCenter Sites Hit With 9.9-Severity Takeover Flaw (CVE-2026-61021) | 2026-08-18 |
| Critical | CVE · KEV | CVE-2026-75843: ArcadeDB gRPC Flaw Lets Read-Only Users Mint Admin Accounts | 2026-08-18 |
| Critical | CVE · KEV | Oracle WebCenter Sites Hit With 9.8 Unauthenticated Takeover Flaw (CVE-2026-61018) | 2026-08-18 |
| Critical | CVE | CVE-2026-60696: Critical Unauthenticated Takeover in Oracle WebLogic Server | 2026-08-18 |
| Critical | CVE · KEV | CVE-2026-75854: ArcadeDB Redis Plugin Ships Without Authentication | 2026-08-18 |
| Critical | CVE · KEV | CVE-2026-61029: Critical Unauthenticated Takeover in Oracle WebCenter Sites | 2026-08-18 |
| High | Breach | Private Equity, Law and Ratings Firms: BlackFile Vishing Extortion Campaign | 2026-08-18 |
| Critical | CVE · KEV | CVE-2026-60861: Critical Oracle Service Delivery Platform Flaw Enables Full Data Compromise | 2026-08-18 |
| Critical | CVE · KEV | CVE-2026-60591: Critical Unauthenticated Flaw in Oracle Hospitality Simphony POS | 2026-08-18 |
| Critical | CVE · KEV | CVE-2026-60858: Critical Unauthenticated Takeover in Oracle Hyperion Calculation Manager | 2026-08-18 |
| Critical | CVE · KEV | CVE-2026-62608: Critical Oracle Reports Developer Flaw Enables Product Takeover | 2026-08-18 |
| Critical | CVE · KEV | CVE-2026-60754: Critical Unauthenticated Flaw in Oracle Siebel CRM Marketing | 2026-08-18 |
| High | Breach | France's DGFiP: ZeroBytes Credential Abuse Exposes Taxpayer Records | 2026-08-18 |
| Critical | CVE · KEV | TRENDnet TEW-823DRU Stack Overflow in wan.cgi (CVE-2026-75976) | 2026-08-18 |
| High | Breach | See's Candies: Ransomware Intrusion and Dark Web Leak | 2026-08-18 |
| Critical | CVE · KEV | Oracle Helidon Hit by Critical Unauthenticated Web Server Flaw (CVE-2026-73922) | 2026-08-18 |
| Critical | CVE · KEV | CVE-2026-75627: Critical Authentication Bypass in Bastillion SSH Gateway | 2026-08-18 |
| Critical | CVE · KEV | Oracle WebCenter Enterprise Capture: Unauthenticated Takeover via T3/IIOP (CVE-2026-60970) | 2026-08-18 |
| Critical | CVE · KEV | CVE-2026-75913: Argument Injection in CodeWhale's git_show Tool Enables Silent Arbitrary File Write | 2026-08-18 |
| Critical | CVE · KEV | CVE-2026-60990: Critical Oracle Identity Manager Connector Takeover Flaw | 2026-08-18 |
| Critical | CVE · KEV | CVE-2026-60916: Critical Unauthenticated Flaw in Oracle WebCenter Enterprise Capture | 2026-08-18 |
| Critical | CVE · KEV | CVE-2026-62582: Critical Scope-Changing Flaw in Oracle Hyperion Calculation Manager | 2026-08-18 |
| Critical | CVE · KEV | CVE-2026-73921: Critical Unauthenticated Takeover in Oracle Helidon | 2026-08-18 |
| Critical | CVE · KEV | CVE-2026-75626: Critical Stored XSS in SpiderFoot Correlation Titles | 2026-08-18 |
| Critical | CVE · KEV | Oracle WebCenter Portal Composer Flaw (CVE-2026-60730) Scores 9.9, Allows Full Takeover | 2026-08-18 |
| Critical | CVE · KEV | Oracle WebCenter Enterprise Capture Hit With 9.8 Pre-Auth Takeover Bug (CVE-2026-60971) | 2026-08-18 |
| Critical | CVE · KEV | Oracle Siebel CRM Cloud Manager Flaw Scores 9.9 — Full Takeover From a Low-Privilege Account | 2026-08-18 |
| Critical | CVE · KEV | Oracle Identity Manager Connector Hit With CVSS 9.9 Takeover Flaw (CVE-2026-60995) | 2026-08-18 |
| High | Ransomware | AnMed: The Gentlemen Ransomware Data Theft Claims | 2026-08-18 |
| Critical | CVE · KEV | Oracle Hyperion Infrastructure Technology Hit With Critical Scope-Changing Flaw (CVE-2026-62463) | 2026-08-18 |
| Critical | CVE · KEV | Oracle WebCenter Content Hit With Critical 9.6 Flaw in Content Server | 2026-08-18 |
| Critical | CVE · KEV | Oracle Hyperion Infrastructure Technology Hit With 9.8 Pre-Auth Takeover Flaw (CVE-2026-62539) | 2026-08-18 |
| Critical | CVE · KEV | CVE-2026-73924: Critical Unauthenticated Flaw in Oracle Helidon Imperative Web Server | 2026-08-18 |
| Critical | CVE · KEV | Oracle Web Services Manager Hit With CVSS 9.6 Scope-Changing Flaw | 2026-08-18 |
| Critical | CVE · KEV | CVE-2026-60698: Unauthenticated IIOP Takeover of Oracle WebLogic Server | 2026-08-18 |
| Critical | CVE · KEV | Oracle Siebel CRM Cloud Applications Hit With 9.8 Critical Pre-Auth Takeover Flaw (CVE-2026-61318) | 2026-08-18 |
| Critical | CVE · KEV | Oracle Identity Manager Hit With CVSS 9.9 RMI Takeover Flaw (CVE-2026-61066) | 2026-08-18 |
| Critical | CVE · KEV | CVE-2026-62585: Critical Unauthenticated Takeover in Oracle Siebel CRM Administration | 2026-08-18 |
| Critical | CVE · KEV | CVE-2026-75877: Stack Buffer Overflow in TRENDnet TV-IP751WIC Camera Web Server | 2026-08-18 |
| Critical | CVE · KEV | CVE-2026-75094: OS Command Injection in COMFAST CF-N1-S CGI Interface | 2026-08-18 |
| Critical | CVE · KEV | Oracle Siebel CRM Integration Hit by Critical Unauthenticated Takeover Flaw (CVE-2026-62592) | 2026-08-18 |
| Critical | CVE | Oracle Web Services Manager Hit With Critical Unauthenticated Data Compromise Flaw (CVE-2026-60737) | 2026-08-18 |
| Critical | CVE · KEV | Oracle Managed File Transfer Hit With CVSS 9.9 Takeover Flaw | 2026-08-18 |
| Critical | CVE · KEV | Oracle WebCenter Enterprise Capture Hit With 9.8 Pre-Auth Takeover Flaw (CVE-2026-60958) | 2026-08-18 |
| Critical | CVE · KEV | CVE-2026-61241: Unauthenticated LDAP Takeover of Oracle Internet Directory (CVSS 10.0) | 2026-08-18 |
| Critical | CVE · KEV | Oracle WebLogic Server RMI Flaw CVE-2026-60977 Allows Unauthenticated Takeover | 2026-08-18 |
| Critical | CVE · KEV | CVE-2026-73930: Critical Unauthenticated Flaw in Oracle Helidon Web Server | 2026-08-18 |
| Critical | CVE · KEV | CVE-2026-33824: Critical Windows IKE Extension Double Free Under Active Exploitation | 2026-08-18 |
| Critical | CVE · KEV | CVE-2025-62593: Critical RCE in Ray Exploitable Through the Browser | 2026-08-17 |
| High | Breach | Fortune 500 Azure Tenants: TheHatman Directory Data Theft | 2026-08-17 |
| High | Ransomware | COFACE: Qilin Ransomware Leak Site Listing | 2026-08-17 |
| High | Ransomware | University of Health Sciences & Pharmacy: LockBit Ransomware | 2026-08-17 |
| Critical | CVE | CVE-2026-71472: Command and SQL Injection in Red Hat ACM Search Component | 2026-08-17 |
| High | Breach | Barts Health NHS Trust: Clop Data Theft via Oracle E-Business Suite Zero-Day | 2026-08-17 |
| High | Breach | South Korea NHIS: Dark Web Actor Advertises 48 Million Citizen Records | 2026-08-17 |
| High | Ransomware | Verbandsgemeinde Rhein-Nahe: LockBit 5.0 Ransomware and Leak Threat | 2026-08-17 |
| High | Breach | Empower Group: DragonForce Ransomware Data Theft Claim | 2026-08-17 |
| High | Ransomware | Kennedy Jenks and Agricola Galbusera: Helix and LockBit 5 Leak Site Listings | 2026-08-17 |
| Critical | CVE | CVE-2026-66792: Critical Privilege Escalation in Red Hat multicloud-operators-subscription | 2026-08-17 |
| High | Breach | SafePal: Order-Tracking Plug-in Flaw Exposes ~40,000 Customers | 2026-08-17 |
| High | Breach | Wake County Board of Elections: Vendor Credential Compromise Exposes Poll Worker Data | 2026-08-17 |
| High | Ransomware | TOTVS: Direwolf Ransomware Leak Site Listing | 2026-08-17 |
| Critical | CVE · KEV | CVE-2026-66795: Critical CSR Auto-Approval Flaw in Red Hat Multicluster Engine Enables Hub Cluster Takeover | 2026-08-17 |
| High | Breach | Bits of Gold: Third-Party Software Compromise Exposes Customer Identity Data | 2026-08-17 |
| High | Breach | Vimeo: ShinyHunters Third-Party Supply Chain Breach | 2026-08-16 |
| Critical | CVE · KEV | CVE-2026-74790: Scriban Sandbox Bypass via Cached TypedObjectAccessor | 2026-08-16 |
| High | Breach | 15 Government Ministries: Jewelbug Webmail Watering Hole and Crypto Fraud Operation | 2026-08-16 |
| Critical | CVE · KEV | CVE-2024-13784: Critical PHP Object Injection in ARForms WordPress Plugin | 2026-08-16 |
| Critical | CVE · KEV | CVE-2026-73061: Scriban Template Engine Access-Modifier Bypass Allows Arbitrary Property Writes | 2026-08-16 |
| Critical | CVE · KEV | CVE-2026-18432: Unauthenticated Admin Takeover in WordPress "Frontend Admin by DynamiApps" | 2026-08-16 |
| High | Breach | McDonald's and Vodafone: TheHatman Azure/Entra Credential Theft Campaign | 2026-08-16 |
| High | Breach | Shell, GE and Philips: Cl0p Mass Exploitation of PTC Windchill | 2026-08-16 |
| High | Breach | 13 Organizations: ExfilSquad Mass Data Extortion Campaign Confirmed | 2026-08-16 |
| Critical | CVE · KEV | CVE-2026-14524: Unauthenticated Arbitrary File Deletion in ProSolution WP Client | 2026-08-16 |
| Critical | CVE · KEV | CVE-2026-18316: Missing Capability Check in Solace Extra WordPress Plugin Lets Subscribers Wipe Site Content | 2026-08-16 |
| High | Ransomware | Hong Kong Baptist University: The Gentlemen Ransomware Data Theft Claim | 2026-08-16 |
| Critical | CVE · KEV | CVE-2026-16098: Unauthenticated Arbitrary File Upload in ProSolution WP Client (CVSS 9.8) | 2026-08-16 |
| Critical | CVE · KEV | CVE-2026-19924: Tenda AC10 Authentication Bypass in httpd Handler | 2026-08-16 |
| Critical | CVE · KEV | CVE-2026-73056: Unthrottled API Token Brute Force in SiYuan Kernel | 2026-08-16 |
| High | Breach | Unlimited Technology Systems: Datacenter Intrusion and Mass Health Data Theft | 2026-08-16 |
| High | Breach | Scottish Government: Third-Party Supplier Breach Hits Prosecution Service | 2026-08-16 |
| Critical | CVE · KEV | Edimax EW-7478APC Buffer Overflow (CVE-2026-19961) — Public Exploit, No Vendor Response | 2026-08-16 |
| Critical | CVE · KEV | CVE-2026-19959: Critical Stack Buffer Overflow in Edimax EW-7478APC | 2026-08-16 |
| High | Breach | MyDr: Mass Health Record Theft and Extortion Attempt | 2026-08-15 |
| High | Breach | MyDr: Nearly 19 Million Polish Patient Records Stolen in Suspected Extortion Breach | 2026-08-15 |
| Critical | CVE · KEV | CVE-2026-18855: Unauthenticated Arbitrary File Deletion in WordPress Link Library Plugin | 2026-08-15 |
| Critical | CVE | CVE-2026-16142: Unauthenticated Account Takeover in WordPress TrueBooker Plugin | 2026-08-15 |
| Critical | CVE · KEV | CVE-2026-15826: Critical Authentication Bypass in WordPress User Profile Builder Plugin | 2026-08-15 |
| High | Breach | Bank Mellat: 32.1 Million Record Dataset Surfaces in Dark Web Listing | 2026-08-15 |
| High | Breach | Microsoft Power Pages: ExfilSquad Mass Data Exfiltration via Misconfigured Web API | 2026-08-15 |
| High | Breach | Nick Scali: Cyberattack Forces Systems Offline, Ransom Reported | 2026-08-15 |
| High | Breach | Health Sciences Centre: Ransomware Against Hospital Facility Systems | 2026-08-15 |
| High | Breach | Sogang University: 180,000 Account Records Exposed in Login System Intrusion | 2026-08-15 |
| High | Ransomware | Zebra Technologies: Clop Data Theft Extortion Claim | 2026-08-15 |
| High | Breach | Salesloft Drift: ShinyHunters OAuth Token Theft Across the Salesforce Supply Chain | 2026-08-15 |
| Critical | CVE · KEV | CVE-2026-19598: Unauthenticated Privilege Escalation in Pods WordPress Plugin (CVSS 9.8) | 2026-08-15 |
| High | Breach | MyDr: Criminal Extortion Crew Steals Health Records of Nearly 19 Million Poles | 2026-08-15 |
| Critical | CVE · KEV | CVE-2026-15303: Unauthenticated Admin Takeover in 6Storage Rentals for WordPress | 2026-08-15 |
| High | Ransomware | ASCOM S.p.A.: BlackNevas Ransomware Attack | 2026-08-15 |
| High | Breach | Bloctel: Business Account Takeover Exposes Three Million French Phone Numbers | 2026-08-15 |
| Critical | CVE · KEV | CVE-2026-73042: Critical Stored XSS to RCE in SiYuan Note | 2026-08-15 |
| Critical | CVE · KEV | CVE-2026-73043: Critical RCE in SiYuan Note via Template Calculation Operator | 2026-08-15 |
| High | Breach | Trezor: Third-Party Logistics Breach at ShipMonk | 2026-08-15 |
| Critical | CVE · KEV | CVE-2026-73041: Critical Stored XSS to RCE in SiYuan PDF Annotations | 2026-08-15 |
| Critical | CVE · KEV | CVE-2026-15341: Authentication Bypass in WordPress User Session Synchronizer Plugin | 2026-08-15 |
| Critical | CVE · KEV | CVE-2026-73044: Critical Stored XSS in SiYuan Leads to Code Execution in Electron | 2026-08-15 |
| Critical | CVE · KEV | CVE-2026-73053: Critical XSS in SiYuan Leads to Arbitrary Code Execution | 2026-08-15 |
| Critical | CVE · KEV | CVE-2026-73052: Critical Stored XSS in SiYuan Leads to Code Execution on Desktop Clients | 2026-08-15 |
| High | Breach | MyDr: Criminal Extortion Breach Exposes 19 Million Polish Patient Records | 2026-08-15 |
| Critical | CVE | CVE-2026-14484: Unauthenticated Arbitrary File Deletion in RapiSafe Multi File Upload for Contact Form 7 | 2026-08-15 |
| Critical | CVE · KEV | CVE-2026-73050: Stored XSS in SiYuan Attribute-View Select Colors | 2026-08-15 |
| High | Breach | MyDr: Suspected Criminal Extortion Breach of Nearly 19 Million Polish Patient Records | 2026-08-15 |
| Critical | CVE · KEV | CVE-2026-73046: SiYuan Access Code Brute-Force Grants Full Kernel Admin | 2026-08-15 |
| High | Breach | Questel: ShinyHunters Vishing Breach of Microsoft 365 | 2026-08-14 |
| Critical | CVE · KEV | Grav API Plugin Scope-Cap Bypass Lets a Limited Key Mint a Super Admin (CVE-2026-72829) | 2026-08-14 |
| Critical | CVE | CVE-2026-72811: Critical SQL Injection in SiYuan Backlink Search | 2026-08-14 |
| High | Breach | Middle Eastern Government Webmail Tenants: Jewelbug APT Watering-Hole Compromise | 2026-08-14 |
| High | Breach | MyDr: Criminal Extortion Breach Exposes Medical Data of Nearly 19 Million Poles | 2026-08-14 |
| Critical | CVE · KEV | CVE-2026-12949: Unauthenticated Account Takeover in WordPress Wishlist Member Plugin | 2026-08-14 |
| Critical | CVE · KEV | CVE-2026-73678: Unauthenticated RCE in MindsDB Minds Platform via Agent Scratchpad `exec()` | 2026-08-14 |
| High | Ransomware | Union County, Ohio: Kairos Data-Theft Extortion | 2026-08-14 |
| High | Breach | Carhartt: ShinyHunters Extortion Leak | 2026-08-14 |
| High | Breach | Salesforce and ServiceNow Portals: City-Forum Guest Data Harvesting Campaign | 2026-08-14 |
| Critical | CVE · KEV | CVE-2026-72824: Grav API Plugin Scope Bypass Enables SSTI and Remote Code Execution | 2026-08-14 |
| High | Breach | LiteLLM: TeamPCP Supply Chain Compromise | 2026-08-14 |
| Critical | CVE · KEV | CVE-2026-17181: Critical Path Traversal in IBM Db2 Mirror for i | 2026-08-14 |
| High | Breach | Shell, Philips and General Electric: Cl0p Mass Data Theft Claims | 2026-08-14 |
| Critical | CVE · KEV | CVE-2026-72826: Grav API Plugin Scope Bypass Lets Minimal Keys Mint Super Keys | 2026-08-14 |
| Critical | CVE · KEV | IBM Db2 Mirror for i Authentication Bypass — CVE-2026-17182 (CVSS 9.8) | 2026-08-14 |
| Critical | CVE · KEV | CVE-2026-72830: Critical Scope Bypass in Grav API Plugin Leads to Remote Code Execution | 2026-08-14 |
| High | Breach | MyDr: Criminal Extortion Breach Exposes 19 Million Polish Health Records | 2026-08-14 |
| High | Breach | Beacon CRM: Leaked AWS Access Key Leads to Full Customer Database Exfiltration | 2026-08-14 |
| High | Breach | MyDr: Medical Records of Nearly 19 Million Poles Stolen in Extortion Breach | 2026-08-14 |
| Critical | CVE · KEV | CVE-2026-17186: IBM Db2 Mirror for i Command Injection Scores CVSS 9.9 | 2026-08-14 |
| High | Breach | France's DGFiP: Identity Takeover Breach of the National Tax System | 2026-08-14 |
| High | Breach | MyDr: Criminal Extortion Crew Steals Medical Records of 19 Million Poles | 2026-08-14 |
| Critical | CVE · KEV | CVE-2026-72822: Critical Auth Bypass in Grav Plugin API Lets Attackers Disable 2FA on Non-Super Accounts | 2026-08-14 |
| High | Breach | Kazakhstan eGov: Alleged 15 Million Citizen Data Sale | 2026-08-14 |
| High | Ransomware | CommonSpirit Health: Vendor Ransomware Exposes Malpractice Insurance Database | 2026-08-14 |
| High | Ransomware | Texas Hearing Institute: Interlock Ransomware Data Theft | 2026-08-14 |
| Critical | CVE · KEV | IBM Db2 Mirror for i Hit With Critical Unauthenticated RCE (CVE-2026-17184) | 2026-08-14 |
| High | Breach | MyDr: Extortion Breach Exposes Health Records of Nearly 19 Million Poles | 2026-08-14 |
| High | Breach | MyDr: Unattributed Data Theft Hits Poland's Electronic Health Records | 2026-08-13 |
| High | Breach | Tchap: One Hijacked Account Exposes 73,467 French Government Users | 2026-08-13 |
| High | Breach | Taiwan Government Agencies: Near-Autonomous AI Agent Intrusion Campaign | 2026-08-13 |
| High | Breach | Unlimited Technology Systems: Unattributed Intrusion Exposes 3.8M Patient Records | 2026-08-13 |
| High | Breach | MyDr: Mass Data Theft From Poland's Medical Records Platform | 2026-08-13 |
| Critical | CVE · KEV | CVE-2026-72839: filebrowser Self-Signup Grants Root Scope to Anyone | 2026-08-13 |
| High | Breach | Wesco, PNLD and Analog Devices: ExfilSquad Torrent Leak Campaign | 2026-08-13 |
| High | Breach | US Water Utilities: Iran Linked Actors Suspected in Multistate PLC Hijacking | 2026-08-13 |
| High | Breach | MyDr: Nationwide Medical Records Breach Hits Nearly 19 Million Poles | 2026-08-13 |
| Critical | CVE · KEV | CVE-2026-19297: IBM Langflow OSS Authentication Brute-Force Flaw Rated Critical (CVSS 9.1) | 2026-08-13 |
| High | Ransomware | Beaver County, Pennsylvania: Unnamed Ransomware Crew Extracts $175,000 Payment | 2026-08-13 |
| High | Breach | Shwapno: 410GB Customer Database Stolen in Ransom Extortion | 2026-08-13 |
| Critical | CVE · KEV | IBM WebSphere Application Server Liberty Authentication Bypass | 2026-08-13 |
| High | Ransomware | City of Coweta, Oklahoma: Anubis Ransomware Wipes Out Municipal IT | 2026-08-13 |
| Critical | CVE · KEV | CVE-2026-72842: Critical LuCI Container ACL Flaw Grants Root on OpenWrt | 2026-08-13 |
| Critical | CVE · KEV | CVE-2026-72776: Unauthenticated RCE in AgenticSeek Query API | 2026-08-13 |
| High | Breach | Unlimited Technology Systems: Unattributed Data Center Intrusion and Exfiltration | 2026-08-13 |
| Critical | CVE · KEV | CVE-2026-72841: Path Traversal in OpenWrt luci-app-openvpn Yields Persistent Root | 2026-08-13 |
| High | Ransomware | Colombia's Ministry of Justice: Unattributed Ransomware | 2026-08-13 |
| High | Breach | MyDr: Medical Data on Nearly 19 Million Poles Stolen in Extortion Attack | 2026-08-13 |
| High | Breach | MyDr: Nearly 19 Million Polish Patient Records Stolen in Suspected Extortion Breach | 2026-08-13 |
| High | Breach | MyDr: Nearly 19 Million Polish Patient Records Stolen in Suspected Criminal Breach | 2026-08-13 |
| Critical | CVE · KEV | IBM Documentation Offline Hit With Critical Path Control Flaw (CVE-2026-17482) | 2026-08-13 |
| Critical | CVE · KEV | CVE-2026-53791: rsync Daemon PROXY Header Spoofing Bypasses IP Access Controls | 2026-08-13 |
| High | Ransomware | Largan Precision and Honghe Tech: Clop Data Extortion Claim | 2026-08-13 |
| Critical | CVE · KEV | CVE-2026-72850: Critical Path Traversal in Budibase Enables Arbitrary File Write | 2026-08-13 |
| Critical | CVE · KEV | CVE-2026-73533: Ninja Tables Pro 5.2.11 Shipped With an Embedded Backdoor | 2026-08-13 |
| High | Ransomware | Hong Kong Baptist University: The Gentlemen Ransomware Credential Breach | 2026-08-13 |
| Critical | CVE · KEV | CVE-2026-19747: Unauthenticated Command Injection in Tenda Smart Cameras | 2026-08-13 |
| Critical | CVE · KEV | CVE-2026-67614: Hard-Coded JWT Secret in CyberPanel WebTerminal | 2026-08-13 |
| High | Breach | MyDr: Mass Theft of Polish Patient Records in Suspected Extortion Attack | 2026-08-13 |
| Critical | CVE · KEV | Budibase Unauthenticated SQL Injection (CVE-2026-72851) Scores a Perfect 10.0 | 2026-08-13 |
| High | CVE | CVE-2026-73532: Fluent Forms Pro 6.2.7 Shipped With an Embedded Backdoor | 2026-08-13 |
| High | Breach | Snowflake Customer Tenants: Infostealer Credentials and Missing MFA | 2026-08-12 |
| Critical | CVE · KEV | Phoenix Contact PLCnext Devices: Critical Unauthenticated PROFINET Buffer Overflow (CVE-2025-41769) | 2026-08-12 |
| High | Ransomware | AngMar Companies: Interlock Ransomware Data Extortion Claim | 2026-08-12 |
| Critical | CVE · KEV | CVE-2026-71471: Image Override Flaw in Red Hat ACM Search Enables Fleet-Wide RCE | 2026-08-12 |
| Critical | CVE · KEV | CVE-2026-73268: Critical Job Injection in Red Hat Multicluster Engine Lets Tenants Escalate to Cluster Admin | 2026-08-12 |
| High | Breach | Unlimited Technology Systems: 3.8 Million Patient Records Stolen From Hosted Data Center | 2026-08-12 |
| High | Breach | Movistar: Unverified Dark Web Breach Claim, 500,000 Customers | 2026-08-12 |
| High | Breach | Suisun City, California: Suspected Ransomware Shuts Down Entire Municipal IT Network | 2026-08-12 |
| High | Breach | China's Ministry of Public Security: Dark Web Listing Claims Spyware and Espionage File Sale | 2026-08-12 |
| High | Breach | DentaQuest: ShinyHunters Extortion Breach Hits at Least 15 Million Patients | 2026-08-12 |
| High | Breach | Valve: Supply Chain Breach at CEVA Logistics Exposes European Steam Hardware Buyers | 2026-08-12 |
| High | Breach | MyDr: Financially Motivated Extortion Against a National EMR Provider | 2026-08-12 |
| High | Ransomware | POWDR Corporation: Settra Ransomware Data Extortion | 2026-08-12 |
| High | Breach | Unlimited Technology Systems: Unattributed Intrusion Exposes 3.8M Patient Benefits Records | 2026-08-12 |
| Critical | CVE · KEV | CVE-2026-73519: Hard-Coded Secret in WolfStack Grants Root Inside Every Container | 2026-08-12 |
| High | Ransomware | Stadler: Everest Extortion via Supplier Data Exchange Platform | 2026-08-12 |
| High | Breach | Cognizant TriZetto: Year Long Portal Intrusion Exposes 3.4 Million Patients | 2026-08-12 |
| High | Breach | Uber Freight: Helix Extortion Claim and Confirmed Unauthorized Access | 2026-08-12 |
| High | Ransomware | Minidoka Memorial Hospital: Unattributed Ransomware Intrusion Exposes Patient SSNs | 2026-08-12 |
| Critical | CVE · KEV | CVE-2024-27253: Critical Authentication Bypass in IBM DOORS Next | 2026-08-12 |
| High | Breach | Kazakhstan eGov: Alleged Darknet Sale of National Citizen Database | 2026-08-12 |
| High | Breach | Unlimited Technology Systems: Unattributed Intrusion and Bulk Data Theft | 2026-08-12 |
| High | Ransomware | AnMed Health: The Gentlemen Ransomware Claim Follows Weeks of Care Disruption | 2026-08-12 |
| High | Ransomware | Philadelphia Insurance Companies: Ethics Ransomware Claim | 2026-08-12 |
| Critical | CVE · KEV | IBM i Hit With Critical Pre-Auth RCE: CVE-2026-17083 Scores 9.8 | 2026-08-12 |
| High | Breach | Venezuelan Government Systems: Unverified Actor Claim of Nationwide Identity Data Exposure | 2026-08-12 |
| Critical | CVE | Red Hat ACM Subscription Flaw Lets Tenants Take Over the Cluster (CVE-2026-72508) | 2026-08-12 |
| High | Ransomware | Critical Infrastructure Operators: Gunra Ransomware Double Extortion Campaign | 2026-08-11 |
| Critical | CVE · KEV | Cisco ASA/FTD Remote Access SSL VPN Flaw Lands in KEV (CVE-2026-20349) | 2026-08-11 |
| Critical | CVE · KEV | CVE-2026-69102: Hard-Coded JWT Secret in MaxKey Grants Unauthenticated Admin Access | 2026-08-11 |
| High | Breach | Bank of Baroda: Employee Email Compromise Behind Alleged 1TB Dark Web Leak | 2026-08-11 |
| High | Breach | U.S. Government Entity: Kairos Non-Encrypting Data Extortion | 2026-08-11 |
| Critical | CVE · KEV | CVE-2026-19425: Critical Unauthenticated SQL Injection in Win Men Intermational Travel Agency Management System | 2026-08-11 |
| High | Breach | ANIBIC: Year Long Network Intrusion Exposes Client SSNs and Health Data | 2026-08-11 |
| High | Breach | AI Supply Chain: Team PCP LiteLLM Compromise and Agentic Credential Theft | 2026-08-11 |
| High | Breach | Israel's Defense Industrial Base: Iran-Linked Intrusions and Contested Breach Claims | 2026-08-11 |
| High | Breach | US Federal Agency: North Korean Remote IT Worker Infiltration | 2026-08-11 |
| Critical | CVE · KEV | CVE-2026-5917: Critical Shell Command Injection in libgit2's libssh2 SSH Backend | 2026-08-11 |
| Critical | CVE · KEV | CVE-2026-71398: Maximum-Severity Authorization Flaw in Adobe Campaign Classic | 2026-08-11 |
| High | Ransomware | Statista and Quirónsalud: DireWolf Ransomware Leak Site Listings | 2026-08-11 |
| High | Ransomware | LT Group and Fortune Tobacco: Deadlock Ransomware Leak of 14,836 Files | 2026-08-11 |
| High | Breach | Wesco: ExfilSquad Cloud CRM Data Extortion | 2026-08-11 |
| High | Ransomware | Hospitals and Government Agencies: Gunra Ransomware Campaign | 2026-08-11 |
| High | Breach | RENAPER: GordonFreeman Offers 48 Million Argentine Citizen Records | 2026-08-11 |
| Critical | CVE · KEV | CVE-2026-73032: Critical RCE in PapersGPT for Zotero via Unsanitized LLM Response | 2026-08-11 |
| High | Breach | Origin Energy: Unattributed Intrusion Exposes 900,000 Customer Records | 2026-08-11 |
| High | Breach | Hugging Face: Autonomous AI Agent Breaches Production Infrastructure | 2026-08-11 |
| Critical | CVE · KEV | SAP Commerce Cloud Hit With a Perfect 10: CVE-2026-58231 Enables Unauthenticated RCE | 2026-08-11 |
| Critical | CVE · KEV | Metabase SQL Injection (CVE-2026-72898) Hits CISA KEV With a Perfect 10.0 | 2026-08-11 |
| Critical | CVE · KEV | CVE-2026-73034: Unauthenticated Path Traversal in DB-GPT | 2026-08-11 |
| Critical | CVE | Siemens SIMATIC IoT2050 Advanced: Unauthenticated Node-RED RCE (CVE-2026-58115) | 2026-08-11 |
| High | Ransomware | Canadian Hospital: Ransomware Disrupting Building Automation Systems | 2026-08-11 |
| Critical | CVE · KEV | CVE-2026-72748: Unauthenticated Arbitrary File Write in AVideo | 2026-08-11 |
| Critical | CVE · KEV | CVE-2026-27302: Maximum-Severity Authorization Flaw in Adobe Campaign Classic Carries Unauthenticated Code Execution Risk | 2026-08-11 |
| Critical | CVE · KEV | CVE-2026-10579: PicketLink Federation SAML Accepts Forged Assertions | 2026-08-11 |
| High | Ransomware | Cleaver-Brooks and Interim HealthCare: Anubis and Genesis Ransomware Listings | 2026-08-11 |
| High | Breach | LexisNexis: FulcrumSec Leak and Third Party Server Compromise | 2026-08-11 |
| Critical | CVE · KEV | CVE-2026-68820: Windows AFD.sys Use-After-Free Added to CISA KEV | 2026-08-11 |
| High | Breach | Abbott Exact Sciences: ShinyHunters Vishing Breach and 10.9M Record Leak | 2026-08-10 |
| High | Breach | Shun Hing Group: Mass Data Encryption Attack on Hong Kong Appliance Distributor | 2026-08-10 |
| High | Breach | Farmers Insurance: Third-Party Vendor Breach Tied to Salesforce Vishing Campaign | 2026-08-10 |
| Critical | CVE | CVE-2026-34265: Critical Unauthenticated Memory Corruption in SAP NetWeaver AS ABAP | 2026-08-10 |
| High | Ransomware | FIS Global: Clop Data Theft Extortion Claim | 2026-08-10 |
| High | Breach | Union County, Ohio: Kairos Data-Theft Extortion Payment | 2026-08-10 |
| High | Breach | Suisun City: Unattributed Malware Cripples Municipal IT and 911 Routing | 2026-08-10 |
| High | Breach | Unlimited Technology Systems: Unattributed Datacenter Intrusion Exposes 3.8 Million Patient Records | 2026-08-10 |
| High | Breach | Unnamed Company: Autonomous AI Breach by Meta's Muse Spark 1.1 | 2026-08-10 |
| High | Breach | Mistral AI: TeamPCP Source Code Theft and Extortion | 2026-08-10 |
| High | Breach | Unnamed Enterprise: Meta AI Model Breach via Misconfigured Sandbox | 2026-08-10 |
| High | Ransomware | Foxconn: Nitrogen Ransomware Data Theft and Extortion | 2026-08-10 |
| High | Breach | Mile Bluff Medical Center: Dark Project Extortion Leak | 2026-08-10 |
| High | Breach | Levi Strauss & Co.: Social Engineering Attack on Three Employee Computers | 2026-08-10 |
| High | Ransomware | Constellation HomeBuilder Systems: 'unsafe' Ransomware Claim | 2026-08-10 |
| High | Breach | Israel Defense Forces: Handala Hacktivist Leak of Unit Officer Contacts | 2026-08-10 |
| High | Breach | CISA: Contractor Leaks Privileged AWS GovCloud Keys on Public GitHub | 2026-08-10 |
| High | Breach | Atlanta, Houston and Frontier Airlines: ExfilSquad Exfiltration Only Extortion | 2026-08-10 |
| Critical | CVE · KEV | CVE-2026-14450: Forged Headers Let Any Pod Bypass OpenShift AI MaaS API Auth | 2026-08-10 |
| Critical | CVE · KEV | CVE-2026-18948: Unauthenticated RCE in Feast Feature Server | 2026-08-10 |
| Critical | CVE · KEV | CVE-2026-44758: Critical Code Injection in SAP Manufacturing Integration and Intelligence | 2026-08-10 |
| Critical | CVE · KEV | Zyxel WAH7601 Hit by Critical Unauthenticated OS Command Injection (CVE-2026-13206) | 2026-08-10 |
| High | Breach | TrueConf: Head Mare Supply-Chain Compromise via Trojanized Client Installers | 2026-08-10 |
| High | Breach | Ali** **********: ShinyHunters Salesforce, ServiceNow and Entra Extortion Claim | 2026-08-10 |
| High | Breach | Thailand: 221 Million Exposed Login Records Drive a National MFA Mandate | 2026-08-10 |
| High | Breach | Alien Technology: ShinyHunters Claims 11.5M Record SaaS Extortion | 2026-08-10 |
| High | Breach | Newcastle University: ExfilSquad Data Extortion via Admissions System Misconfiguration | 2026-08-10 |
| Critical | CVE · KEV | N-able: RMM Supply Chain Intrusion via N-central Authentication Bypass | 2026-08-10 |
| High | Breach | Ceva Logistics: Third Party Warehouse Intrusion and Downstream Data Breach | 2026-08-10 |
| High | Breach | Snowflake Customers: UNC5537 Credential Theft and Extortion Campaign | 2026-08-09 |
| High | Breach | Tata Electronics: World Leaks Extortion Leak Exposes Apple and Tesla Supply Chain Files | 2026-08-09 |
| High | Breach | Morgan Stanley: Unverified 892 Million Record Dark Web Listing | 2026-08-09 |
| High | Breach | IEH Corporation: Credential Phishing Into Microsoft 365 | 2026-08-09 |
| Critical | CVE · KEV | CVE-2026-19348: Command Injection in Shenzhen Aitemi M300 Wi-Fi Repeater | 2026-08-09 |
| High | Breach | Snowflake Customers: UNC5537 Credential Theft and Extortion Campaign | 2026-08-09 |
| High | Breach | Mexican Presidency SIDAC: cenfecracked Claims 400,000 Citizen Petitions Exposed | 2026-08-09 |
| High | Breach | Financial Sector: UNC6671 Helpdesk Vishing and Multi-Brand Extortion | 2026-08-09 |
| High | Breach | TVING: 19.53 Million User Records Exposed in Platform Database Breach | 2026-08-09 |
| High | Breach | Questel SAS: ShinyHunters Salesforce Data Extortion | 2026-08-09 |
| High | Ransomware | Université Libre de Bruxelles: Qilin Ransomware Leak Site Listing | 2026-08-09 |
| Critical | CVE · KEV | CVE-2026-71958: Critical Unauthenticated Buffer Overflow in D-Link DWR-M961 Routers | 2026-08-08 |
| High | Ransomware | Mayer Brown: SilentRansomGroup Leak Site Listing and Claimed Data Breach | 2026-08-08 |
| Critical | CVE · KEV | CVE-2026-71983: Critical Command Injection in MSI Radix AXE6600 Routers | 2026-08-08 |
| Critical | CVE · KEV | CVE-2026-71986: Critical Command Injection in MSI Radix AXE6600 Routers | 2026-08-08 |
| Critical | CVE · KEV | MSI Radix AXE6600 Router Hit by Critical Root-Level Command Injection (CVE-2026-71991) | 2026-08-08 |
| Critical | CVE · KEV | CVE-2026-14526: Unauthenticated Site Takeover in WordPress "AI Copilot – Content Generator" | 2026-08-08 |
| Critical | CVE · KEV | CVE-2026-71990: Critical Command Injection in MSI Radix AXE6600 Routers | 2026-08-08 |
| Critical | CVE · KEV | CVE-2026-71987: Critical Command Injection in MSI Radix AXE6600 Routers | 2026-08-08 |
| High | Ransomware | City of McMinnville, Oregon: RansomHouse Extortion Claim | 2026-08-08 |
| Critical | CVE · KEV | MSI Radix AXE6600 Router Hit by Critical Command Injection (CVE-2026-71985) | 2026-08-08 |
| High | Breach | Unlimited Technology Systems: Datacenter Intrusion Exposes 3.8 Million Patient Records | 2026-08-08 |
| Critical | CVE · KEV | CVE-2026-71992: Critical Command Injection in MSI Radix AXE6600 Routers | 2026-08-08 |
| High | Ransomware | Mackay Sugar: The Gentlemen Ransomware Halts Australia's Second-Largest Sugar Producer | 2026-08-08 |
| Critical | CVE · KEV | MSI Radix AXE6600 Router Hit by Critical Root-Level Command Injection (CVE-2026-71993) | 2026-08-08 |
| Critical | CVE · KEV | MSI Radix AXE6600 Router Hit by Critical Root-Level Command Injection (CVE-2026-71984) | 2026-08-08 |
| High | Breach | Government College University Faisalabad: Insider Assisted Grade Tampering Breach | 2026-08-08 |
| High | Breach | Framework: Third Party Zero Day Breach at BI Provider Metabase | 2026-08-08 |
| High | Breach | Swiss Federal IT Office (BIT/FOITT): SharePoint Exploitation by Unknown Actors | 2026-08-08 |
| High | Breach | LastPass: Icarus Extortion Crew Steals Customer Data Through Klue Vendor Compromise | 2026-08-08 |
| Critical | CVE · KEV | CVE-2026-71956: Critical Command Injection in D-Link DWR-M961 Routers | 2026-08-08 |
| Critical | CVE · KEV | CVE-2026-71957: Critical Unauthenticated Buffer Overflow in D-Link DWR-M961 Routers | 2026-08-08 |
| High | Breach | American Addiction Centers: Third Party Data Theft via Salesforce | 2026-08-08 |
| High | Ransomware | Nichirei: RansomHouse Extortion Attack Freezes Japan's Cold Chain | 2026-08-08 |
| Critical | CVE · KEV | CVE-2026-71944: Critical Command Injection in D-Link DWR-M961 LTE Routers | 2026-08-08 |
| Critical | CVE · KEV | MSI Radix AXE6600 Router Hit by Critical Unauthenticated Command Injection (CVE-2026-71988) | 2026-08-08 |
| High | Ransomware | City of Coweta, Oklahoma: System-Wide Ransomware Attack | 2026-08-08 |
| Critical | CVE | MSI Radix AXE6600 Router Hit With Critical Root-Level Command Injection (CVE-2026-71989) | 2026-08-08 |
| High | Breach | Exact Sciences: ShinyHunters Vishing and SaaS Extortion | 2026-08-07 |
| High | Breach | Insee: Staff Directory Breach Exposes 12,800 French Civil Servants | 2026-08-07 |
| High | Breach | Beacon CRM: Supply Chain Breach Exposes Donor Data at ~1,500 UK Charities | 2026-08-07 |
| High | Breach | Police National Legal Database: ExfilSquad Data Extortion and Dark Web Leak | 2026-08-07 |
| High | Breach | Allianz Life: ShinyHunters Salesforce OAuth Abuse Exposes 1.4M+ Customers | 2026-08-07 |
| High | Breach | Craneware: Data Exfiltration From a US Healthcare Billing Vendor | 2026-08-07 |
| High | Breach | ANCPI: Credential-Based Wiper Attack on Romania's National Land Registry | 2026-08-07 |
| Critical | CVE · KEV | CVE-2026-14365: Unauthenticated Password Reset in TrueBooker WordPress Plugin | 2026-08-07 |
| High | Breach | Hedge Funds and Private Equity Firms: UNC6671 Vishing Extortion Wave | 2026-08-07 |
| High | Breach | DHS: HSIN Information Sharing Network Breached by Unattributed Actor | 2026-08-07 |
| High | Ransomware | DentaQuest: ShinyHunters Extortion Breach Confirmed at 15 Million and Climbing | 2026-08-07 |
| Critical | CVE · KEV | CVE-2026-14364: Unauthenticated Account Takeover in TrueBooker WordPress Plugin | 2026-08-07 |
| High | Breach | Global Hospitality Wi-Fi: Russia's SVR Hijacks Captive Portals in the CaptiveCrunch Campaign | 2026-08-07 |
| Critical | CVE · KEV | Progress LoadMaster Pre-Auth Command Injection (CVE-2026-8037) Added to CISA KEV | 2026-08-07 |
| High | Breach | Instituto Saúde e Cidadania: Ransomware Breach Exposing 500,000 Patient Records | 2026-08-07 |
| High | Breach | U.S. Water Utilities: Iran-Linked PLC Intrusions Across at Least Seven States | 2026-08-07 |
| High | Breach | Bonava: ExfilSquad Extortion Claim and Confirmed Customer Data Breach | 2026-08-07 |
| High | Breach | Coupang: Insider Linked Data Breach Turns Into a $570 Million Quarterly Loss | 2026-08-07 |
| High | Breach | Chick-fil-A: Credential Stuffing Attack on Chick-fil-A One Loyalty Accounts | 2026-08-07 |
| High | Breach | Singapore Land Authority: Third-Party Breach of IBM-Managed Test Environment | 2026-08-07 |
| High | Breach | Coinkite Coldcard: Firmware RNG Flaw Exploited for Nine Figure Bitcoin Theft | 2026-08-07 |
| High | Breach | Updoc: Third Party System Compromise Exposes Patient Contact Data | 2026-08-06 |
| High | Breach | Heart of America Medical Center: Embargo Ransomware Data Breach | 2026-08-06 |
| Critical | CVE | CVE-2026-63508: Missing Authentication in Microsoft Planetary Computer Pro Scores a Perfect 10.0 | 2026-08-06 |
| Critical | CVE · KEV | CVE-2026-70558: Unauthenticated Arbitrary File Write in Dinky Leads to Code Execution | 2026-08-06 |
| High | Ransomware | King International LLC: Gammax Ransomware Claim | 2026-08-06 |
| High | Breach | North Carolina Ports: Unattributed Intrusion Forces Manual Operations at Three Facilities | 2026-08-06 |
| Critical | CVE · KEV | CVE-2026-53984: Unauthenticated Database Wipe in Ground Station via Socket.IO Backup Handler | 2026-08-06 |
| High | Breach | Inter-Con Security: ShinyHunters Pay-or-Leak Extortion Leak | 2026-08-06 |
| High | Breach | Instructure Canvas: ShinyHunters Extortion Breach and Finals Week Outage | 2026-08-06 |
| Critical | CVE · KEV | Azure Active Directory Privilege Escalation — CVE-2026-50481 (CVSS 9.9) | 2026-08-06 |
| High | Breach | Union County, Ohio: Kairos Encryption-Free Data Extortion | 2026-08-06 |
| Critical | CVE · KEV | CVE-2026-70332: Critical SSRF in Microsoft SharePoint Online | 2026-08-06 |
| Critical | CVE · KEV | Flowise IDOR (CVE-2026-67622) Exposes Cross-Workspace Credentials in an Unsupported Product | 2026-08-06 |
| Critical | CVE · KEV | CVE-2026-50515: Critical Deserialization Flaw in Azure Service Bus Enables Remote Code Execution | 2026-08-06 |
| High | Breach | Hundreds of Global Organizations: DPRK State Hackers Exposed by a Counter-Intrusion | 2026-08-06 |
| Critical | CVE · KEV | CVE-2026-59118: Critical Privilege Escalation in Microsoft Power Apps | 2026-08-06 |
| Critical | CVE · KEV | CVE-2026-62830: Critical Privilege Escalation in Azure SRE Agent | 2026-08-06 |
| Critical | CVE · KEV | CVE-2026-65667: Critical Missing Authorization Flaw in Microsoft Teams Scores a Perfect 10.0 | 2026-08-06 |
| Critical | CVE · KEV | CVE-2026-62873: Critical Signature Verification Flaw in Microsoft 365 Admin Center | 2026-08-06 |
| High | Ransomware | Five Hong Kong Firms: Orova Ransomware Extortion Wave | 2026-08-06 |
| High | Breach | Canadian Tire: E-Commerce Database Breach Drives National Class Action | 2026-08-06 |
| High | Ransomware | EPM: Everest Ransomware Claim Against Colombian Electricity, Water, Sewage and Gas Provider | 2026-08-06 |
| Critical | CVE · KEV | CVE-2026-62896: Critical Privilege Escalation in Microsoft Teams | 2026-08-06 |
| High | Ransomware | Evangelical Council for Financial Accountability: INC Ransom Leak Site Extortion | 2026-08-06 |
| Critical | CVE · KEV | CVE-2026-68823: Critical RCE Flaw in Azure Confidential Ledger | 2026-08-06 |
| Critical | CVE · KEV | CVE-2026-56162: Critical Authentication Bypass in Azure SQL Database | 2026-08-06 |
| Critical | CVE · KEV | CVE-2026-59115: Critical Privilege Escalation in Microsoft Entra Provisioning Service | 2026-08-06 |
| Critical | CVE · KEV | CVE-2026-56161: Critical Improper Access Control in Azure Logic Apps | 2026-08-06 |
| High | Ransomware | Winn-Dixie: Anubis Ransomware Leak Site Claim | 2026-08-05 |
| High | Ransomware | Healthcare Highways: Chaos Ransomware Extortion Claim | 2026-08-05 |
| Critical | CVE · KEV | CVE-2026-10059: ClusterCurator Flaw Hands Tenant Admins Full Kubernetes Cluster Control | 2026-08-05 |
| High | Breach | Snowflake Customers: Connor Moucka Pleads Guilty to 165-Organization Cloud Breach Spree | 2026-08-05 |
| High | Ransomware | Nidec Corporation: Blackfield Ransomware Hits Taiwanese Subsidiary | 2026-08-05 |
| Critical | CVE · KEV | Zbtlink Router Firmware Ships a Built-In Root Backdoor: CVE-2026-66747 | 2026-08-05 |
| Critical | CVE · KEV | Unauthenticated Media Wipe: CVE-2026-5581 in Multi Uploader for Gravity Forms | 2026-08-05 |
| High | Breach | Brown Health Medical Group-MA: Unattributed Intrusion into a Legacy File Server | 2026-08-05 |
| Critical | CVE · KEV | CVE-2026-10090: Namespace "Edit" to Cluster-Admin in Red Hat ACM | 2026-08-05 |
| High | Ransomware | Retelit: Qilin Ransomware Data Leak | 2026-08-05 |
| High | Breach | Zenith Bank: Customer Contact Data Exposed in Database Breach | 2026-08-05 |
| High | Breach | Intermarché: Unauthorised Access to Drive Click-and-Collect Customer Files | 2026-08-05 |
| High | Breach | Paidwork: 23.3 Million Record Leak and a Denied Breach | 2026-08-05 |
| High | Ransomware | STIIIZY: Everest Ransomware Claims 420,000 Customer Records | 2026-08-05 |
| High | Breach | npm Ecosystem: ChainDrop Self Propagating Supply Chain Worm | 2026-08-05 |
| Critical | CVE · KEV | boringproxy Tunnel Endpoint Lets Low-Privileged Users Plant SSH Keys (CVE-2026-70615) | 2026-08-05 |
| Critical | CVE · KEV | JetBrains TeamCity Hit With Unauthenticated RCE — CVE-2026-63077 Added to CISA KEV | 2026-08-05 |
| Critical | CVE · KEV | Unauthenticated Post Tampering in WordPress "Easy Post Submission" (CVE-2026-4431) | 2026-08-05 |
| High | Breach | ADT: ShinyHunters Vishing Breach Exposes 5.5 Million Accounts | 2026-08-05 |
| Critical | CVE · KEV | CVE-2026-9273: Password Reset Poisoning in Kadence Memberships Grants Unauthenticated Account Takeover | 2026-08-05 |
| High | Ransomware | Radia Inc.: Chaos Ransomware Claims 655GB of Patient Records | 2026-08-04 |
| High | Ransomware | Unlimited Technology Systems: Ransomware Breach Hits 442,000 Patients | 2026-08-04 |
| High | Breach | Madera Community Hospital: Extortion Group Breach Disclosed 13 Months Late | 2026-08-04 |
| Critical | CVE · KEV | N-able N-central Authentication Bypass (CVE-2026-18556) Added to CISA KEV | 2026-08-04 |
| High | Ransomware | Oleoductos del Valle: INC Ransom Claims Mass Exfiltration From Argentina's Main Crude Pipeline Operator | 2026-08-04 |
| High | Breach | Żabka: Third Party Contractor Account Compromise | 2026-08-04 |
| Critical | CVE · KEV | Puwell IP Cameras: Unauthenticated Root Command Injection via DebugShell (CVE-2026-61515) | 2026-08-04 |
| High | Breach | Passaic County, New Jersey: March Ransomware Attack Costs $395K With No Ransom Paid | 2026-08-04 |
| Critical | CVE · KEV | CVE-2026-70554: Unauthenticated PHP Object Injection in MaxSite CMS | 2026-08-04 |
| Critical | CVE · KEV | IBM Langflow Hit With Critical Unauthenticated RCE — CVE-2026-9198 Added to CISA KEV | 2026-08-04 |
| Critical | CVE · KEV | CVE-2026-69098: Unauthenticated RCE in Cinnamon kotaemon via Insecure Deserialization | 2026-08-04 |
| Critical | CVE · KEV | CVE-2026-70552: Unauthenticated AJAX Dispatcher Bypass in MaxSite CMS | 2026-08-04 |
| Critical | CVE · KEV | CVE-2026-14175: Unauthenticated Web Shell Upload in HUMANIST Digital HR | 2026-08-04 |
| Critical | CVE · KEV | CVE-2026-70553: Unauthenticated RCE in MaxSite CMS Install Endpoint | 2026-08-04 |
| Critical | CVE · KEV | CVE-2026-15721: Critical Cleartext Storage Flaw in HUMANIST Digital HR Enables SQL Injection | 2026-08-04 |
| High | Breach | Keyv: Shai-Hulud Worm Hijacks npm Maintainer Account | 2026-08-04 |
| High | Breach | RingCentral: ShinyHunters Extortion Claim of 623GB | 2026-08-04 |
| Critical | CVE · KEV | Apache Tomcat EncryptInterceptor Bypass (CVE-2026-34486) Added to CISA KEV | 2026-08-04 |
| Critical | CVE · KEV | CVE-2026-18589: Critical Unauthenticated Buffer Overflow in Wavlink WL-NU516U1 | 2026-08-03 |
| Critical | CVE · KEV | Wavlink WL-NU516U1: Critical Unauthenticated Stack Overflow in nas.cgi (CVE-2026-18588) | 2026-08-03 |
| High | Ransomware | TUI China: DragonForce Ransomware Extortion Listing | 2026-08-03 |
| High | Breach | Police National Legal Database: ExfilSquad Data Extortion Breach | 2026-08-03 |
| High | Breach | Spanish and Ukrainian Intelligence Services: Pro-Russian Hacktivist Doxxing Campaign | 2026-08-03 |
| High | Ransomware | Service Electric: Qilin Ransomware Claim Behind Week-Long Service Outage | 2026-08-03 |
| High | Breach | Liechtenstein Government: Unattributed Intrusion Into the National Beneficial Owner Registry | 2026-08-03 |
| High | Breach | Allstate: ExfilSquad Ransomware Data Theft Claim | 2026-08-03 |
| High | Ransomware | ProHealth Medical Group: Krybit Ransomware | 2026-08-03 |
| High | Ransomware | Diater: DeadLock Ransomware Double Extortion Claim | 2026-08-03 |
| High | Ransomware | US County, Likely Union County Ohio: Kairos Data Theft Extortion | 2026-08-03 |
| High | Ransomware | Partnered Health: Inc Ransom Claims Terabytes Stolen from Australian GP Network | 2026-08-03 |
| Critical | CVE · KEV | Menulux Mobile App Hit With Critical Authorization Bypass | 2026-08-03 |
| High | Ransomware | Quantinuum: INC Ransom Leak Site Claim | 2026-08-03 |
| Critical | CVE · KEV | N-able N-central Authentication Bypass (CVE-2026-18577) Added to CISA KEV | 2026-08-03 |
| High | Breach | Resamania: 5.2 Million Record Leak Claimed by Actor @84City | 2026-08-02 |
| High | Ransomware | CEN and CENELEC: coinbasecartel Extortion Claim | 2026-08-02 |
| High | Ransomware | Alcon Inc.: ShinyHunters Extortion Claim and Alleged Salesforce Data Theft | 2026-08-02 |
| High | Breach | TransUnion: OAuth-Connected SaaS App Compromise Exposes 4.4 Million Unredacted SSNs | 2026-08-02 |
| Critical | CVE · KEV | CVE-2026-65321: Critical SQL Injection in PyAthena Parameter Formatting | 2026-08-02 |
| High | Ransomware | Pertamina: TheGentlemen Ransomware Leak Site Claim | 2026-08-02 |
| High | Ransomware | MIM Fertility: CoinbaseCartel Extortion Claim | 2026-08-02 |
| High | Breach | Accenture: Threat Actor 888 Sells 35GB of Alleged Internal Source Code and Cloud Keys | 2026-08-02 |
| High | Breach | RTX Corporation: Employee Data Breach Exposing Social Security Numbers | 2026-08-02 |
| Critical | CVE · KEV | FreeRDP Heap Overflow in Windows Clipboard Client (CVE-2026-68579) | 2026-08-02 |
| High | Ransomware | M. B. Kahn Construction Co.: CoinbaseCartel Ransomware Claim | 2026-08-01 |
| Critical | CVE · KEV | FreeRDP TLS Certificate Validation Bypass — CVE-2026-66402 | 2026-08-01 |
| High | Breach | Amgen: Cloud Data Exfiltration and PHI Exposure | 2026-08-01 |
| Critical | CVE · KEV | CVE-2026-3141: Unauthenticated Arbitrary File Deletion in WordPress FormGent Plugin | 2026-08-01 |
| Critical | CVE · KEV | CVE-2026-67330: Critical Authorization Bypass in @better-auth/scim Enables Account Takeover | 2026-08-01 |
| Critical | CVE · KEV | ArcadeDB Trigger Scripts Allow Remote Code Execution (CVE-2026-67340) | 2026-08-01 |
| Critical | CVE · KEV | CVE-2026-67308: Shell Injection in Wazuh GitHub Actions Workflows | 2026-08-01 |
| High | Breach | St. Joseph County: Handala Hack Data Breach Claim | 2026-08-01 |
| High | Breach | Coinbase: Bribed Support Insiders and a Refused $20M Extortion Demand | 2026-08-01 |
| Critical | CVE · KEV | ArcadeDB Authorization Bypass Enables Arbitrary JavaScript Execution via `DEFINE FUNCTION` (CVE-2026-67341) | 2026-08-01 |
| Critical | CVE · KEV | FreeRDP HTTP Proxy Request Injection — CVE-2026-67289 | 2026-08-01 |
| Critical | CVE · KEV | GitPython Clone Option Gate Bypassed via Joined Short Options (CVE-2026-67324) | 2026-08-01 |
| Critical | CVE · KEV | ArcadeDB Authorization Bypass (CVE-2026-67342) Exposes Databases to Unauthenticated Attackers | 2026-08-01 |
| High | Ransomware | Hyatt Hotels: NightSpire Ransomware Leak Site Claim | 2026-08-01 |
| High | Ransomware | Hyundai Türkiye: CRPx0 Double Extortion Leak Site Listing | 2026-08-01 |
| Critical | CVE · KEV | CVE-2026-15964: Unauthenticated Password Reset in Single Sign On For TNG Could Enable WordPress Site Takeover | 2026-08-01 |
| High | Breach | Instructure Canvas: ShinyHunters Support Ticket XSS and Mass Data Theft | 2026-08-01 |
| High | Ransomware | Johnson & Johnson: CRPxO Ransomware Leak Site Listing | 2026-08-01 |
| High | Ransomware | MCBS: PEAR Extortion Group Breach of 1.26 Million Patient Records | 2026-08-01 |
| High | Breach | U.S. Municipal Water Utilities: Multi-State OT Attacks Linked to Iranian-Affiliated PLC Exploitation | 2026-08-01 |
| Critical | CVE · KEV | CVE-2026-8457: WooCommerce Social Login Apple Handler Lets Anyone Log In As Admin | 2026-08-01 |
| High | Breach | AssuranceAmerica: Employee Account Compromise Exposes 6.9 Million Driver's License Numbers | 2026-07-31 |
| High | Breach | Minnesota Water Utilities: Coordinated OT Attack With a Contested Iran Link | 2026-07-31 |
| High | Breach | Magyar Államkincstár: bytetobreach Claims vCenter and Identity Vault Access | 2026-07-31 |
| Critical | CVE · KEV | CVE-2026-18452: Hard-Coded API Key in Rich Source DMS+ Rated CVSS 10.0 | 2026-07-31 |
| High | Ransomware | Romania's National Administration of Penitentiaries: Babuk Suspected Ransomware Attack | 2026-07-31 |
| High | Breach | M-Tiba: Kazu Claims 17 Million Patient Records Exfiltrated | 2026-07-31 |
| Critical | CVE · KEV | CVE-2026-17561: Critical Code Injection in Logsign SIEM | 2026-07-31 |
| High | Breach | Aflac Japan: Ten Day Intrusion Exposes 4.38 Million Policyholder Records | 2026-07-31 |
| High | Breach | Thailand's Ministry of Finance: Autonomous AI Agent Ran Post-Exploitation Unattended | 2026-07-31 |
| Critical | CVE · KEV | CVE-2026-14483: Unauthenticated File Upload to RCE in Realtyna WPL Real Estate WordPress Plugin | 2026-07-31 |
| Critical | CVE · KEV | ComfyUI Hit With Critical Unauthenticated RCE: CVE-2026-68771 | 2026-07-31 |
| Critical | CVE · KEV | CVE-2026-68770: sentence-transformers Executes Untrusted Code Despite trust_remote_code=False | 2026-07-31 |
| High | Breach | CareCloud: Unattributed Intruders Loot One of Six EHR Repositories | 2026-07-31 |
| High | Ransomware | River Financial Corporation: Ransomware With Data Theft and an Unverified Deletion Promise | 2026-07-31 |
| High | Breach | Brinks Home: ShinyHunters Extortion After Entra Vishing Claim | 2026-07-30 |
| High | Breach | Spain's INSS: Unnamed Actor Claims Theft and Wipe of Pensioner Database | 2026-07-30 |
| Critical | CVE · KEV | CVE-2026-16610: Unauthenticated RCE in WordPress ASE Pro Plugin | 2026-07-30 |
| High | Breach | Conduent: SafePay Ransomware Data Theft at Scale | 2026-07-30 |
| High | Breach | Charter Communications: ShinyHunters Vishing Breach of Spectrum Salesforce | 2026-07-30 |
| Critical | CVE · KEV | Phoenix Contact CHARX EV Chargers: Unauthenticated Backend Takeover (CVE-2026-44101) | 2026-07-30 |
| Critical | CVE · KEV | CVE-2026-54363: Hardcoded Key in Gladinet CentreStack Enables Unauthenticated RCE | 2026-07-30 |
| Critical | CVE · KEV | CVE-2026-48449: Adobe Campaign Classic Authorization Flaw Rated CVSS 10.0 | 2026-07-30 |
| Critical | CVE · KEV | CVE-2026-44104: Unsigned Firmware Updates Expose Phoenix Contact CHARX EV Charging Controllers | 2026-07-30 |
| Critical | CVE · KEV | CVE-2026-44091: Unauthenticated MQTT Config Injection in Phoenix Contact CHARX EV Chargers | 2026-07-30 |
| Critical | CVE · KEV | CVE-2026-15435: Critical Path Traversal in IBM App Connect Enterprise | 2026-07-30 |
| Critical | CVE · KEV | Phoenix Contact CHARX EV Chargers: Unauthenticated Root Command Injection (CVE-2026-7849) | 2026-07-30 |
| High | Breach | NYC Health + Hospitals: LeakNet Claims 11TB Extortion Archive | 2026-07-30 |
| Critical | CVE · KEV | CVE-2026-44092: Unauthenticated Modbus Injection in Phoenix Contact CHARX EV Charging Controllers | 2026-07-30 |
| Critical | CVE · KEV | UMAI Vision Traffic Analysis System Hit With Critical SQL Injection Flaw (CVE-2026-4978) | 2026-07-30 |
| High | Breach | UK Police National Legal Database: ExfilSquad Data Theft and Extortion | 2026-07-30 |
| High | Breach | Analog Devices: Confirmed Intrusion and File Exfiltration | 2026-07-30 |
| Critical | CVE · KEV | CVE-2026-44108: Phoenix Contact CHARX EV Chargers Drop Their Firewall Mid-Shutdown | 2026-07-30 |
| High | Breach | Court Services Victoria: Bendigo Law Courts Breach Confirmed After Hacker Claims | 2026-07-30 |
| High | Ransomware | Mount Royal University: CMD Ransomware Data Theft and Auction | 2026-07-30 |
| High | Ransomware | MCBS: PEAR Extortion Group Leaks 1.26 Million Patient Records | 2026-07-30 |
| High | Ransomware | Bretford Manufacturing: Aurora Ransomware Data Extortion Claim | 2026-07-30 |
| Critical | CVE · KEV | Cisco Secure Firewall Management Center Hard-Coded Password Flaw Lands in CISA KEV | 2026-07-29 |
| High | Breach | UK Department for Education: 607,000 Records Exfiltrated in Help Desk and Turing Scheme Breach | 2026-07-29 |
| High | Breach | SplitVPN: Altenen Forum Actor Leaks 58 Million Connection Logs From a No-Logs VPN | 2026-07-29 |
| Critical | CVE · KEV | CVE-2026-14488: Unauthenticated Post Deletion in Meta Box AIO for WordPress | 2026-07-29 |
| Critical | CVE · KEV | WordPress Plugin Flaw Lets Anonymous Attackers Mint Admin Accounts (CVE-2025-10656) | 2026-07-29 |
| Critical | CVE · KEV | CVE-2026-14900: Unauthenticated RCE in Cost Calculator Builder PRO for WordPress | 2026-07-29 |
| Critical | CVE · KEV | CVE-2026-41939: Hard-Coded WildFly Credentials Give Unauthenticated RCE in Care Everywhere Gateway | 2026-07-29 |
| High | Breach | Tchap: 'Misere' Account Hijack Breach of France's Government Messaging Platform | 2026-07-29 |
| Critical | CVE · KEV | NASA AIT-DSN Exposes Deep Space Network Controls to Unauthenticated Attackers | 2026-07-29 |
| High | Ransomware | AnMed: Ransomware Extortion With a 72 Hour Countdown | 2026-07-28 |
| Critical | CVE · KEV | IBM WebSphere Application Server: Critical Admin Console Access Control Flaw (CVE-2026-14446) | 2026-07-28 |
| Critical | CVE · KEV | IBM Aspera Desktop App Path Traversal — CVE-2026-14973 | 2026-07-28 |
| Critical | CVE · KEV | CVE-2026-14512: Critical Pre-Auth Deserialization Flaw in IBM WebSphere Application Server | 2026-07-28 |
| Critical | CVE · KEV | IBM Aspera Faspex 5: Critical Command Injection Flaw (CVE-2026-14958) | 2026-07-28 |
| Critical | CVE · KEV | CVE-2026-14959: Critical Command Injection in IBM Aspera Faspex 5 | 2026-07-28 |
| Critical | CVE | CVE-2026-15014: Critical Authentication Bypass in WordPress SMS Alert Plugin (CVSS 9.8) | 2026-07-28 |
| Critical | CVE | CVE-2026-16462: Unauthenticated SQL Injection in Weidmueller PROCON-WEB SCADA | 2026-07-28 |
| High | Breach | One Medical: ShinyHunters Data Theft Extortion | 2026-07-28 |
| High | Ransomware | Stadler: Everest Ransomware Data Extortion | 2026-07-27 |
| High | Breach | US and NATO Defence and Nuclear Research: Russian State Espionage via Zero-Click Email Flaw | 2026-07-27 |
| High | Ransomware | Coca-Cola: Ransomware Disrupts Dairy Unit Production | 2026-07-27 |
| High | Breach | Bank of Baroda: Threat Actor Claims 1TB Customer Data Theft | 2026-07-27 |
| High | Breach | TeleMessage: Archived Messaging Platform Breach Exposes 60+ US Government Users | 2026-07-27 |
| Critical | CVE · KEV | Fortinet FortiOS Symlink Persistence Bypass (CVE-2025-68686) Added to CISA KEV | 2026-07-27 |
| High | Breach | Wesco International: ExfilSquad Data Theft Claim | 2026-07-27 |
| High | Breach | IIT Madras and IIT Kanpur: Rejected Applicant Claims Breach of Both Institutes | 2026-07-27 |
| High | Breach | DoorDash: Vendor Phishing Compromise Exposes Customer and Driver Data | 2026-07-27 |
| High | Breach | Ernst & Young: ShinyHunters Supply Chain Extortion | 2026-07-27 |
| High | Breach | Hugging Face: Rogue OpenAI Agent Autonomous Intrusion | 2026-07-27 |
| High | Breach | Lifespark: Email Account Compromise Exposes SSNs and Patient Health Data | 2026-07-27 |
| High | Ransomware | HİDROMEK: Deadlock Ransomware Data Extortion | 2026-07-27 |
| High | Breach | OpenLoop Health: Third Party Platform Breach Exposes 716,000 Patient Records | 2026-07-27 |
| High | Breach | Hugging Face: Rogue OpenAI Agent Autonomous Network Intrusion | 2026-07-27 |
| High | Breach | Carnival Cruise Line: ShinyHunters Data Breach | 2026-07-27 |
| High | Ransomware | Thialf Ice Arena: TheGentlemen Ransomware Breach | 2026-07-27 |
| High | Breach | U.S. County Government: Kairos Data Theft Extortion | 2026-07-27 |
| High | Ransomware | KeNHA: Deadlock Ransomware | 2026-07-27 |
| High | Breach | South Korea Foreign Ministry: Diplomatic Database Breach Exposes 10,000 Officials | 2026-07-27 |
| High | Ransomware | Eagle Crest Communities: Anubis Ransomware Extortion | 2026-07-27 |
| Critical | CVE · KEV | Arista VeloCloud Orchestrator On-Prem Hit With CVSS 10.0 Command Injection: CVE-2026-16812 | 2026-07-27 |
| High | Breach | Thailand Ministry of Finance: Autonomous AI Agent Post-Exploitation | 2026-07-27 |
| High | Breach | Origin Energy: Extortionist Claims Private Settlement After Customer Data Breach | 2026-07-27 |
| High | Breach | MCBS: PEAR Ransomware Breach Exposes 1.2 Million Patients | 2026-07-27 |
| High | Breach | Microsoft, Zenith Bank and Frontier Airlines: ExfilSquad Mass Victim Listing | 2026-07-27 |
| High | Breach | U.S. County Government: Kairos Encryption-Less Data Extortion | 2026-07-26 |
| High | Breach | PTC Windchill Operators: Cl0p Mass Exploitation and Product Design Theft | 2026-07-26 |
| High | Ransomware | U.S. Organizations: Ryuk Ransomware Operator Pleads Guilty to $15M Bitcoin Extortion | 2026-07-26 |
| High | Breach | U.S. County Government: Kairos Data Extortion Payment | 2026-07-26 |
| High | Breach | Union County, Ohio: Kairos Data-Theft Extortion | 2026-07-26 |
| High | Ransomware | CTIF Moldova: Nova Ransomware Data Extortion Claim | 2026-07-26 |
| High | Breach | Eastman Kodak: ShinyHunters Extortion Breach | 2026-07-26 |
| High | Breach | 100 Universities: ShinyHunters Oracle PeopleSoft Zero-Day Campaign | 2026-07-26 |
| High | Breach | Romania's ANCPI: Land Registry Database Destroyed by Bytetobreach | 2026-07-26 |
| High | Breach | Anatomic and Clinical Laboratory Associates: Unattributed Network Intrusion Exposes 169,626 Patient Records | 2026-07-26 |
| High | Breach | Eyemart Express: February 2026 Intrusion Exposes Customer PII and Health Data | 2026-07-26 |
| High | Breach | IMCO: Cyber Support Front Claims 30TB Exfiltration From Israeli Armor Supplier | 2026-07-26 |
| High | Breach | FBI and DHS: Federal Workforce Doxing Campaign | 2026-07-26 |
| High | Ransomware | Carrier AB: Deadlock Ransomware Disrupts Swedish Logistics Operations | 2026-07-26 |
| High | Ransomware | Stiftung Autismuslink: INC Ransom Data-Theft Attack | 2026-07-26 |
| High | Breach | U.S. County Government: Kairos Data Extortion | 2026-07-26 |
| High | Breach | U.S. County Government: Kairos Data Extortion Payment | 2026-07-26 |
| High | Breach | Chabi: EV Charging Operator Confirms Breach of 298,333 Member Records | 2026-07-26 |
| High | Ransomware | U.S. Companies and a Private School: Ryuk Ransomware Operator Pleads Guilty | 2026-07-26 |
| High | Ransomware | Vaud Fiduciary Firm: BravoX Ransomware Leak Exposes Municipal and Tax Data | 2026-07-25 |
| Critical | CVE · KEV | SiYuan Unauthenticated Administrator Takeover via Exposed MCP Endpoint (CVE-2026-66012) | 2026-07-25 |
| High | Ransomware | Stryker: Qilin Ransomware Data-Leak Extortion | 2026-07-25 |
| High | Breach | U.S. County Government: Kairos Data Extortion Payout | 2026-07-25 |
| High | Ransomware | Metrabyte Cloud: APT73/Bashe Ransomware Extortion | 2026-07-25 |
| High | Ransomware | Highline Community College: Qilin Ransomware Extortion Claim | 2026-07-25 |
| High | Ransomware | InfoSync Services: Chaos Ransomware Data Extortion | 2026-07-25 |
| High | Ransomware | Kean University: Qilin Ransomware Data Extortion | 2026-07-25 |
| High | Breach | Decathlon: Alleged Threat Actor Breach Exposing 160 Million Records | 2026-07-25 |
| High | Ransomware | Omnicell: Everest Ransomware 1TB Data Theft Claim | 2026-07-25 |
| High | Breach | Global Manufacturers: Cl0p Ransomware PLM Server Exploitation | 2026-07-25 |
| Critical | CVE · KEV | Critical Azure Portal Authorization Flaw Exposes Data Over the Network (CVE-2026-62835) | 2026-07-24 |
| High | Breach | RapidFort: xpl0itrs Claims 569GB CanisterWorm Breach | 2026-07-24 |
| High | Breach | South Korea Ministry of Foreign Affairs: Diplomatic Academy Breach Exposes Diplomats | 2026-07-24 |
| High | Breach | NPCIL/Kudankulam: World Leaks Ransomware Third-Party Breach | 2026-07-24 |
| High | Breach | BlaBlaCar: Threat Actor Claims 140M Record Breach | 2026-07-24 |
| High | Breach | Thailand Ministry of Finance: China-Linked AI-Driven Espionage Intrusion | 2026-07-24 |
| High | Breach | Fidelity Securities Investment Trust Taiwan: 2.15 Million Customer Records Exposed in Dark Web Leak | 2026-07-24 |
| High | Breach | Kootenai County: Ransomware Data Theft Breach | 2026-07-24 |
| Critical | CVE · KEV | CVE-2026-65689: Unauthenticated Arbitrary File Read in Bold Reports Standalone Report Designer | 2026-07-23 |
| Critical | CVE · KEV | CVE-2026-58275: Critical Missing Authorization Flaw in Azure DNS | 2026-07-23 |
| Critical | CVE · KEV | CVE-2026-54120: Critical Code Execution Flaw in Microsoft Surface Management Services | 2026-07-23 |
| Critical | CVE · KEV | CVE-2026-62825: Critical Authentication Bypass in Azure Key Vault Enables Privilege Escalation | 2026-07-23 |
| High | Breach | DentaQuest: ShinyHunters Extortion Breach | 2026-07-23 |
| Critical | CVE · KEV | CVE-2024-58354: Repository Takeover in cal.com's GitHub Actions Workflows | 2026-07-23 |
| Critical | CVE · KEV | CVE-2026-50517: Critical Deserialization Flaw in Microsoft 365 Copilot Enables Remote Code Execution | 2026-07-23 |
| Critical | CVE · KEV | GoDAM WordPress Plugin Flaw (CVE-2026-14282) Allows Unauthenticated File Upload and Possible RCE | 2026-07-23 |
| High | Breach | US Water and Energy Providers: Iranian State-Backed ICS Disruption | 2026-07-23 |
| High | Ransomware | Fairlife: Anubis Ransomware Extortion | 2026-07-23 |
| Critical | CVE · KEV | CVE-2026-56165: Critical Remote Code Execution in Microsoft Account | 2026-07-23 |
| Critical | CVE | CVE-2026-56191: Critical Authentication Flaw in Microsoft Exchange Online | 2026-07-23 |
| Critical | CVE · KEV | CVE-2026-15011: Critical Unauthenticated Code Injection in WordPress Customer Support Ticket System & Helpdesk | 2026-07-23 |
| High | Breach | Vietnamese Hospital, Malaysian Foreign Ministry, Honduran Congress: JadeProx Espionage Campaign | 2026-07-23 |
| Critical | CVE · KEV | CVE-2026-15015: Unauthenticated Admin Takeover in MountDev AI MCP Connector for WordPress | 2026-07-23 |
| Critical | CVE · KEV | CVE-2026-65606: SiYuan XSS-to-RCE via siyuan:// Protocol Handler | 2026-07-23 |
| Critical | CVE · KEV | CVE-2026-56160: Critical Privilege Escalation in Azure Red Hat OpenShift | 2026-07-23 |
| High | Breach | Medtronic: ShinyHunters Data Breach | 2026-07-23 |
| Critical | CVE · KEV | CVE-2025-71389: Unauthenticated RCE in Cal.com (cal.diy) via Next.js RSC Deserialization | 2026-07-23 |
| Critical | CVE · KEV | CVE-2026-63732: Critical RCE Chain in 9router via Default Password | 2026-07-23 |
| Critical | CVE · KEV | CVE-2026-15981: Critical Authentication Bypass in WordPress SAML SSO Login Plugin | 2026-07-23 |
| High | Breach | Chick-fil-A: Credential-Stuffing Attack on Loyalty Accounts | 2026-07-23 |
| Critical | CVE · KEV | h2oGPT Path Traversal in OpenAI-Compatible Files API (CVE-2026-65700) | 2026-07-23 |
| Critical | CVE · KEV | CVE-2026-65605: Stored XSS to RCE in SiYuan Attribute View | 2026-07-23 |
| High | Ransomware | Nichirei: RansomHouse Ransomware Attack Disrupts Frozen Food Supply Chain | 2026-07-22 |
| High | Breach | Nichirei: RansomHouse Ransomware Attack | 2026-07-22 |
| High | Breach | Origin Energy: Unverified Actor Claims Breach of 2 Million Customer Records | 2026-07-22 |
| Critical | CVE · KEV | CVE-2026-60367: Critical Unauthenticated Takeover in Oracle Platform Security for Java | 2026-07-22 |
| High | Breach | Change Healthcare: ALPHV/BlackCat Ransomware Breach Hits 190 Million | 2026-07-22 |
| Critical | CVE · KEV | CVE-2026-60366: Critical Unauthenticated Takeover in Oracle Platform Security for Java | 2026-07-22 |
| High | Ransomware | Caterpillar Inc.: CoinbaseCartel Ransomware Extortion | 2026-07-22 |
| Critical | CVE · KEV | CVE-2026-60372: Critical Unauthenticated Takeover in Oracle Platform Security for Java | 2026-07-22 |
| High | Ransomware | Nichirei: RansomHouse Ransomware Supply Chain Attack | 2026-07-22 |
| Critical | CVE · KEV | CVE-2026-16232: Check Point SmartConsole Authentication Bypass Grants Full Admin Access | 2026-07-22 |
| High | Ransomware | Nichirei: RansomHouse Ransomware Attack | 2026-07-22 |
| High | Breach | Union County, Ohio: Kairos Data-Theft Extortion | 2026-07-22 |
| High | Breach | Romania Land Registry (ANCPI): Stolen Credentials and Known Vulnerabilities | 2026-07-22 |
| Critical | CVE · KEV | CVE-2026-60369: Critical Scope-Changing Flaw in Oracle Platform Security for Java | 2026-07-22 |
| Critical | CVE · KEV | Critical SharePoint RCE: CVE-2026-50522 Under Active Exploitation | 2026-07-22 |
| High | Breach | Novo Nordisk: FulcrumSec Extortion and 1.3TB Data Leak | 2026-07-22 |
| Critical | CVE · KEV | CVE-2026-60376: Critical Unauthenticated Takeover in Oracle Service Delivery Platform | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-60329: Critical Unauthenticated Takeover in Oracle Identity Manager | 2026-07-21 |
| Critical | CVE | Oracle Service Delivery Platform Hit by Critical CVE-2026-60381 (CVSS 9.9) | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-60441: Critical Unauthenticated Takeover in Oracle Service Delivery Platform | 2026-07-21 |
| Critical | CVE · KEV | Oracle Commerce Guided Search Hit by Critical Takeover Flaw (CVE-2026-61146) | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-60264: Critical Unauthenticated Takeover in Oracle Coherence | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-60306: Critical Unauthenticated Takeover Flaw in Oracle Coherence | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-0770: Unauthenticated Root RCE in Langflow via exec_globals | 2026-07-21 |
| Critical | CVE · KEV | Oracle Unified Directory Takeover Flaw: CVE-2026-60361 (CVSS 9.9) | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-60456: Critical Takeover Flaw in Oracle WebCenter Enterprise Capture | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-60360: Critical Unauthenticated Takeover in Oracle Unified Directory | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-60202: Critical Unauthenticated RCE in Oracle WebLogic Server | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-65007: Grav API Plugin Missing Authorization Enables Account Takeover | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-60457: Critical Takeover Flaw in Oracle WebCenter Enterprise Capture | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-60535: Critical Unauthenticated Takeover in Oracle Identity Manager Connector | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-63764: Critical SSRF in lmdeploy Lets Unauthenticated Attackers Reach Cloud Metadata | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-61201: Critical PeopleSoft CRM Flaw Allows Unauthenticated Takeover | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-60272: Critical Unauthenticated Takeover Flaw in Oracle Coherence | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-60285: Critical Unauthenticated Takeover Flaw in Oracle Coherence | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-60552: Critical Oracle WebCenter Sites Takeover Flaw | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-60292: Critical Unauthenticated Takeover in Oracle WebLogic Server | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-60358: Critical Unauthenticated Takeover in Oracle Access Manager | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-60380: Critical Unauthenticated Takeover in Oracle Service Delivery Platform | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-60328: Critical Unauthenticated Takeover in Oracle Access Manager | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-35290: Critical Unauthenticated Takeover in Oracle Application Testing Suite | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-60377: Critical Oracle Service Delivery Platform Flaw Enables Full Compromise | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-60215: Critical Unauthenticated Takeover Flaw in Oracle Coherence | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-60711: Critical Siebel CRM Cloud Applications Takeover Flaw (CVSS 9.9) | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-60267: Critical Unauthenticated Flaw in Oracle Coherence | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-60290: Critical Unauthenticated Takeover Flaw in Oracle Coherence | 2026-07-21 |
| Critical | CVE · KEV | Oracle Commerce Guided Search Hit by Critical Unauthenticated Takeover Flaw (CVE-2026-61145) | 2026-07-21 |
| High | Ransomware | Rumah Sakit Universitas Indonesia (RSUI): Nova Ransomware Attack | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-46982: Critical Unauthenticated Takeover Flaw in Oracle Retail Integration Bus | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-60442: Critical Unauthenticated Takeover in Oracle Service Delivery Platform | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-60217: Critical Unauthenticated Takeover in Oracle Coherence | 2026-07-21 |
| Critical | CVE · KEV | Oracle Service Delivery Platform Hit by Critical Unauthenticated Takeover Flaw (CVE-2026-60375) | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-60248: Critical Oracle Coherence Takeover Flaw in Fusion Middleware | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-60537: Critical Takeover Flaw in Oracle Managed File Transfer | 2026-07-21 |
| Critical | CVE · KEV | Oracle WebCenter Portal Hit by Critical CVE-2026-60568 (CVSS 9.9) | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-60200: Critical Unauthenticated Takeover Flaw in Oracle WebLogic Server | 2026-07-21 |
| Critical | CVE · KEV | Oracle Unified Directory Hit by Critical Unauthenticated Takeover Flaw (CVE-2026-60362) | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-60287: Critical Unauthenticated Takeover Flaw in Oracle Coherence | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-60547: Critical Takeover Flaw in Oracle Managed File Transfer | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-61203: Critical Unauthenticated Flaw in Oracle PeopleSoft FIN Expenses | 2026-07-21 |
| Critical | CVE · KEV | Oracle WebCenter Content Critical Flaw: CVE-2026-60649 | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-60286: Critical Unauthenticated Takeover in Oracle Coherence | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-60424: Critical Oracle Unified Directory Takeover Flaw via LDAP | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-61153: Critical Unauthenticated Flaw in Oracle Commerce Guided Search | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-46994: Critical Unauthenticated Takeover in Oracle Enterprise Manager | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-61041: Critical Takeover Flaw in Oracle Demantra Demand Management | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-60363: Critical Unauthenticated Takeover in Oracle HTTP Server | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-46983: Critical Unauthenticated Takeover in Oracle Retail Integration Bus | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-60249: Critical Takeover Flaw in Oracle Coherence | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-60374: Critical Unauthenticated Takeover in Oracle Service Delivery Platform | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-60216: Critical Unauthenticated Takeover in Oracle Coherence | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-60168: Critical Unauthenticated Flaw in Oracle Hospitality Simphony POS | 2026-07-21 |
| Critical | CVE · KEV | Oracle WebLogic Server Remote Takeover — CVE-2026-60291 | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-60137: WordPress Core SQL Injection Added to CISA KEV | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-60239: Critical Oracle Coherence Flaw Enables Low-Privilege Data Compromise | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-60551: Critical Unauthenticated Takeover Flaw in Oracle WebCenter Sites | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-13439: Unauthenticated Admin Takeover in Easy Form Builder for WordPress | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-60205: Critical Unauthenticated Takeover Flaw in Oracle WebLogic Server | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-60532: Critical Unauthenticated Takeover in Oracle Identity Manager Connector | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-61178: Critical Unauthenticated Takeover in Oracle Agile PLM for Process | 2026-07-21 |
| Critical | CVE · KEV | Oracle WebCenter Content Hit by Critical CVSS 9.9 Takeover Flaw (CVE-2026-60663) | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-60542: Critical Remote Takeover Flaw in Oracle Business Process Management Suite | 2026-07-21 |
| High | Ransomware | Kettering Health: Interlock Ransomware Attack | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-60275: Critical Unauthenticated Takeover Flaw in Oracle Coherence | 2026-07-21 |
| Critical | CVE · KEV | Oracle WebCenter Sites Critical RCE: CVE-2026-61140 Allows Unauthenticated Takeover | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-60555: Critical Unauthenticated Takeover Flaw in Oracle WebCenter Sites | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-60300: Critical Unauthenticated Takeover Flaw in Oracle Coherence | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-60262: Critical Unauthenticated Takeover Flaw in Oracle Coherence | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-60212: Critical Unauthenticated Takeover in Oracle Coherence | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-60387: Critical Unauthenticated Takeover in Oracle Service Delivery Platform | 2026-07-21 |
| High | Breach | Clover Health Investments: Social Engineering Breach of Employee Accounts | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-60447: Critical Takeover Flaw in Oracle WebCenter Enterprise Capture | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-61130: Critical Unauthenticated Flaw in Oracle Commerce Platform | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-60386: Critical Unauthenticated Takeover in Oracle Service Delivery Platform | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-60524: Critical Takeover Flaw in Oracle WebCenter Enterprise Capture | 2026-07-21 |
| Critical | CVE · KEV | Oracle Commerce Platform Remote Takeover — CVE-2026-61131 | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-60446: Critical Unauthenticated Takeover in Oracle WebCenter Enterprise Capture | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-60294: Critical Unauthenticated Takeover Flaw in Oracle WebLogic Server | 2026-07-21 |
| Critical | CVE · KEV | Oracle Data Integrator Hit by Critical Unauthenticated Takeover Flaw (CVE-2026-60999) | 2026-07-21 |
| Critical | CVE · KEV | Oracle Commerce Guided Search Hit by Critical Unauthenticated Data Compromise Flaw (CVE-2026-61156) | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-60274: Critical Unauthenticated Takeover in Oracle Coherence | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-60204: Critical Unauthenticated Takeover Flaw in Oracle WebLogic Server | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-60229: Critical Unauthenticated Takeover Flaw in Oracle Coherence | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-60276: Critical Unauthenticated Takeover Flaw in Oracle Coherence | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-61154: Critical Unauthenticated Takeover in Oracle Commerce Guided Search | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-60541: Critical Unauthenticated Takeover Flaw in Oracle SOA Suite | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-46876: Critical Unauthenticated Takeover in Oracle Application Testing Suite | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-60531: Critical Oracle Identity Manager Connector Takeover Flaw | 2026-07-21 |
| Critical | CVE · KEV | Oracle Coherence Hit by Critical Unauthenticated Takeover Flaw (CVE-2026-60259) | 2026-07-21 |
| Critical | CVE · KEV | Oracle WebLogic Server Proxy Plug-in Flaw (CVE-2026-60364) | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-60206: Critical SAML Flaw Enables Full Takeover of Oracle WebLogic Server | 2026-07-21 |
| Critical | CVE · KEV | Oracle Service Delivery Platform Takeover — CVE-2026-60384 | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-63030: Critical WordPress Core Flaw Chains to Remote Code Execution | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-60198: Critical Unauthenticated RCE in Oracle WebLogic Server | 2026-07-21 |
| Critical | CVE · KEV | Oracle Coherence Core Flaw (CVE-2026-60296) Allows Unauthenticated Takeover | 2026-07-21 |
| Critical | CVE · KEV | SolarWinds Serv-U IDOR Flaw (CVE-2026-28308) Enables Remote Code Execution | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-60297: Critical Unauthenticated Takeover Flaw in Oracle Coherence | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-60199: Critical Unauthenticated Takeover Flaw in Oracle WebLogic Server | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-60302: Critical Unauthenticated Takeover in Oracle Coherence | 2026-07-21 |
| Critical | CVE · KEV | SolarWinds Serv-U Broken Access Control Flaw Lets Domain Admins Escalate to System Admin (CVE-2026-28309) | 2026-07-21 |
| Critical | CVE · KEV | Oracle WebCenter Content Hit by Critical Unauthenticated Takeover Flaw (CVE-2026-60435) | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-60606: Critical Unauthenticated Flaw in Oracle PeopleSoft Common Application Objects | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-60445: Critical Takeover Flaw in Oracle WebCenter Enterprise Capture | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-60385: Critical Unauthenticated Takeover in Oracle Service Delivery Platform | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-60210: Critical Unauthenticated Takeover in Oracle Coherence | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-60365: Critical Unauthenticated Compromise in Oracle WebLogic Server Proxy Plug-in | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-60258: Critical Unauthenticated Takeover Flaw in Oracle Coherence | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-60228: Critical Unauthenticated Takeover Flaw in Oracle Coherence | 2026-07-21 |
| Critical | CVE · KEV | Oracle Coherence Remote Takeover Flaw — CVE-2026-60280 | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-60773: Critical Flaw in Oracle E-Business Suite Application Object Library | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-61204: Critical PeopleSoft FIN Program Management Takeover Flaw | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-60540: Critical Oracle SOA Suite Flaw Allows Full Data Compromise | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-61155: Critical Unauthenticated Flaw in Oracle Commerce Guided Search | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-60422: Critical Oracle Unified Directory Flaw Enables Full Data Compromise via LDAP | 2026-07-21 |
| Critical | CVE · KEV | Oracle PeopleSoft HCM Talent Acquisition Manager Critical Takeover Flaw (CVE-2026-61076) | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-60463: Critical Unauthenticated Takeover in Oracle WebCenter Content: Imaging | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-60269: Critical Unauthenticated Takeover Flaw in Oracle Coherence | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-60236: Critical Unauthenticated Takeover Flaw in Oracle Coherence | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-60219: Critical Unauthenticated Takeover Flaw in Oracle Coherence | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-60246: Critical Unauthenticated Takeover Flaw in Oracle Coherence | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-46924: Critical Unauthenticated Takeover in Oracle Application Testing Suite | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-61059: Critical Unauthenticated Flaw in Oracle PeopleSoft SCM Order Management | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-60251: Critical Unauthenticated Takeover Flaw in Oracle Coherence | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-60333: Critical Oracle Access Manager Takeover Flaw | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-61184: Critical Unauthenticated Flaw in Oracle Agile PLM for Process | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-47036: Critical Unauthenticated Takeover Flaw in Oracle Siebel CRM | 2026-07-21 |
| Critical | CVE · KEV | Oracle WebCenter Portal Hit by Critical Unauthenticated Takeover Flaw (CVE-2026-60566) | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-60221: Critical Unauthenticated Takeover Flaw in Oracle Coherence | 2026-07-21 |
| High | Breach | Suno: 55 Million User Records Stolen in Breach | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-60289: Critical Unauthenticated Takeover Flaw in Oracle Coherence | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-61097: Critical Flaw in Oracle Banking Trade Finance Process Management | 2026-07-21 |
| Critical | CVE · KEV | Oracle Coherence Critical Flaw (CVE-2026-60288): Unauthenticated Takeover | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-60220: Critical Oracle Coherence Flaw Allows Unauthenticated Remote Compromise | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-60250: Critical Unauthenticated Takeover Flaw in Oracle Coherence | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-60567: Critical Unauthenticated Flaw in Oracle Identity Manager | 2026-07-21 |
| Critical | CVE · KEV | Oracle SOA Suite Flaw CVE-2026-60538: Unauthenticated Takeover, CVSS 9.8 | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-60880: Critical Unauthenticated Takeover in Oracle E-Business Suite Work in Process | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-60247: Critical Unauthenticated Takeover Flaw in Oracle Coherence | 2026-07-21 |
| Critical | CVE · KEV | Oracle Access Manager Authentication Bypass — CVE-2026-60355 | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-61167: Critical Unauthenticated Takeover in Oracle Agile PLM | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-60378: Critical Unauthenticated Takeover in Oracle Service Delivery Platform | 2026-07-21 |
| Critical | CVE · KEV | Oracle Coherence Hit by Critical Unauthenticated Takeover Flaw (CVE-2026-60308) | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-60460: Critical Unauthenticated Takeover Flaw in Oracle WebCenter Enterprise Capture | 2026-07-21 |
| High | Ransomware | Stadler Rail: Supplier Platform Ransom Extortion | 2026-07-21 |
| Critical | CVE · KEV | Oracle BI Publisher Critical Takeover Flaw — CVE-2026-60173 | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-60644: Critical Unauthenticated Takeover in Oracle WebCenter Content | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-28314: SolarWinds Serv-U Account Takeover via Insecure Direct Object Reference | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-61100: Critical Unauthenticated Takeover in Oracle WebCenter Enterprise Capture | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-60458: Critical Takeover Flaw in Oracle WebCenter Enterprise Capture | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-60565: Critical Oracle WebCenter Portal Takeover Flaw | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-65057: Unauthenticated SSRF in Keep Healthcheck Endpoint | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-65008: Critical Remote Code Execution in Grav CMS | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-61171: Critical Unauthenticated Flaw in Oracle Agile PLM | 2026-07-21 |
| Critical | CVE · KEV | Oracle WebCenter Portal Critical Flaw: CVE-2026-60564 (CVSS 9.6) | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-60459: Critical Takeover Flaw in Oracle WebCenter Enterprise Capture | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-61186: Critical Unauthenticated Flaw in Oracle Agile Engineering Data Management | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-60253: Critical Unauthenticated Takeover in Oracle Coherence | 2026-07-21 |
| Critical | CVE · KEV | CVE-2021-27137: DD-WRT UPnP Buffer Overflow Under Active Exploitation | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-60429: Critical Oracle Unified Directory Takeover Flaw | 2026-07-21 |
| Critical | CVE · KEV | Oracle Coherence Core Flaw (CVE-2026-60234): Unauthenticated Takeover, CVSS 9.8 | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-28302: SolarWinds Serv-U IDOR Enables Root-Level RCE | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-60461: Critical Takeover Flaw in Oracle WebCenter Enterprise Capture | 2026-07-21 |
| High | Breach | Estée Lauder: Cl0p Oracle EBS Zero-Day Breach | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-60326: Critical Unauthenticated Bypass in Oracle Access Manager | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-60244: Critical Unauthenticated Takeover in Oracle Coherence | 2026-07-21 |
| Critical | CVE · KEV | Oracle Service Delivery Platform Hit by Maximum-Severity SOAP Takeover Flaw (CVE-2026-60379) | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-47040: Critical Unauthenticated Flaw in Oracle Net Services | 2026-07-21 |
| Critical | CVE · KEV | Oracle Coherence Hit by Critical Unauthenticated Takeover Flaw (CVE-2026-60227) | 2026-07-21 |
| Critical | CVE · KEV | Oracle Coherence Hit by Critical CVE-2026-60278 (CVSS 9.8) | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-60257: Critical Unauthenticated Takeover in Oracle Coherence | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-60208: Critical Unauthenticated RCE-Class Flaw in Oracle WebLogic Server | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-60631: Critical Unauthenticated Flaw in Oracle WebCenter Content | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-61175: Critical Unauthenticated Flaw in Oracle Product Lifecycle Analytics | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-60402: Critical Takeover Flaw in Oracle TimesTen In-Memory Database | 2026-07-21 |
| Critical | CVE · KEV | Oracle Coherence Core Flaw (CVE-2026-60240): Unauthenticated Takeover, CVSS 9.8 | 2026-07-21 |
| Critical | CVE · KEV | SolarWinds Serv-U Privilege Escalation Flaw Rated Critical (CVE-2026-28306) | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-60298: Critical Unauthenticated Takeover in Oracle Coherence | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-60230: Critical Unauthenticated Takeover Flaw in Oracle Coherence | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-28307: Critical Privilege Escalation in SolarWinds Serv-U | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-47056: Critical Unauthenticated Takeover in Oracle Data Integrator | 2026-07-21 |
| Critical | CVE · KEV | Oracle Coherence Core Flaw (CVE-2026-60197): Unauthenticated Takeover, CVSS 9.8 | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-60299: Critical Unauthenticated Takeover Flaw in Oracle Coherence | 2026-07-21 |
| Critical | CVE · KEV | Oracle Coherence Core Flaw (CVE-2026-60241): Unauthenticated Takeover, CVSS 9.8 | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-60627: Critical JD Edwards EnterpriseOne Tools Takeover Flaw | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-60209: Critical Unauthenticated Takeover Flaw in Oracle Coherence | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-60256: Critical Unauthenticated Takeover Flaw in Oracle Coherence | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-60561: Critical Scope-Changing Takeover Flaw in Oracle WebCenter Portal | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-61174: Critical Flaw in Oracle Product Lifecycle Analytics | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-61183: Critical Unauthenticated Takeover in Oracle Agile PLM for Process | 2026-07-21 |
| Critical | CVE · KEV | SolarWinds Serv-U Privilege Escalation Flaw (CVE-2026-28310) Rated Critical | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-60279: Critical Unauthenticated Takeover Flaw in Oracle Coherence | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-60226: Critical Unauthenticated Takeover Flaw in Oracle Coherence | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-60632: Critical Unauthenticated Flaw in Oracle WebCenter Content | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-61129: Critical Unauthenticated Takeover in Oracle Commerce Platform | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-60254: Critical Unauthenticated Takeover Flaw in Oracle Coherence | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-60224: Critical Unauthenticated Takeover Flaw in Oracle Coherence | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-28312: Critical Privilege Escalation in SolarWinds Serv-U | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-28305: Critical IDOR in SolarWinds Serv-U Leads to Root RCE | 2026-07-21 |
| Critical | CVE · KEV | Oracle Commerce Guided Search Hit by Critical Unauthenticated Takeover Flaw (CVE-2026-61161) | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-61196: Critical Unauthenticated Takeover in Oracle Identity Manager | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-46989: Critical Flaw in Oracle Enterprise Manager Base Platform | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-60389: Critical Unauthenticated Takeover in Oracle Service Delivery Platform | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-60719: Critical Oracle BI Publisher Flaw Enables Full Data Compromise | 2026-07-21 |
| Critical | CVE · KEV | Oracle Identity Manager Hit by Critical Unauthenticated Compromise Flaw (CVE-2026-61197) | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-60242: Critical Unauthenticated Takeover in Oracle Coherence | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-60388: Critical Unauthenticated Takeover in Oracle Service Delivery Platform | 2026-07-21 |
| Critical | CVE · KEV | Oracle Coherence Hit by Critical CVE-2026-60232: Unauthenticated Takeover | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-60438: Critical Unauthenticated Flaw in Oracle HTTP Server mod_ssl | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-61072: Critical Takeover Flaw in Oracle PeopleSoft FIN Staffing Front Office Brazil | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-60225: Critical Unauthenticated Takeover Flaw in Oracle Coherence | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-61065: Critical Unauthenticated Takeover in Oracle Access Manager | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-28313: Critical IDOR in SolarWinds Serv-U Enables Account Takeover | 2026-07-21 |
| Critical | CVE · KEV | CVE-2016-20096: Unauthenticated SQL Injection in Linknat VOS3000 and VOS2009 | 2026-07-21 |
| Critical | CVE · KEV | Oracle WebCenter Portal Hit by Critical CVE-2026-60562 (CVSS 9.9) | 2026-07-21 |
| Critical | CVE · KEV | CVE-2026-64620: Critical Pre-Auth Heap Overflow in FreeRDP RSA Crypto | 2026-07-20 |
| High | Breach | Rockstar Games: ShinyHunters Leaks Analytics via Anodot Integration | 2026-07-20 |
| High | Breach | Hugging Face: First Confirmed End-to-End Agentic AI Breach | 2026-07-20 |
| Critical | CVE · KEV | CVE-2026-63766: Unauthenticated Command Injection in GPT-SoVITS WebUI | 2026-07-20 |
| Critical | CVE · KEV | CVE-2026-63767: Unauthenticated Pickle Deserialization RCE in ktransformers | 2026-07-20 |
| High | Ransomware | Salina Supply: Qilin Ransomware Data Extortion | 2026-07-20 |
| High | Breach | Korea National Diplomatic Academy: Nine-Month State-Level Intrusion | 2026-07-20 |
| High | Ransomware | Reatile Group: Incransom Ransomware Data Extortion | 2026-07-20 |
| Critical | CVE · KEV | CVE-2026-64625: Critical OS Command Injection in AVideo Live Plugin | 2026-07-20 |
| High | Breach | Craneware: Customer and Staff Data Stolen in Cyber Attack | 2026-07-20 |
| High | Breach | Paidwork: 23 Million User Records Exposed in March Intrusion | 2026-07-20 |
| High | Breach | Carnival Corporation: Social Engineering Breach Exposes 6 Million Travelers | 2026-07-19 |
| High | Ransomware | Barts Health NHS Trust: Clop Ransomware Data Breach | 2026-07-19 |
| High | Breach | Ohio Living: Senior Care Network Data Breach Exposing Personal and Medical Records | 2026-07-19 |
| High | Breach | Abbott Laboratories: ShinyHunters Breach and Dual Cyber Incidents | 2026-07-19 |
| High | Breach | Bandai Namco: Teen ChatGPT-Assisted Account Cancellation Attack | 2026-07-19 |
| High | Ransomware | Government of Bermuda: Ransomware Attack With Suspected Ransom Payment | 2026-07-19 |
| High | Breach | French Government Tchap: Threat Actor Claims Mass Data Access | 2026-07-18 |
| High | Ransomware | Danone: Qilin Ransomware Data Leak | 2026-07-18 |
| High | Ransomware | Kenya State House: Website Defacement and Bitcoin Extortion | 2026-07-18 |
| High | Breach | Coupang: Insider-Linked Breach Exposing 34 Million Customers | 2026-07-18 |
| High | Breach | Ecopetrol: Cyberattack and Data Theft From 3,300 Accounts | 2026-07-18 |
| High | Ransomware | Reliance Infrastructure: Ransomware Breach Exposes Kudankulam Nuclear Files | 2026-07-18 |
| High | Ransomware | Deutsche Bank: Unsafe Ransomware Third-Party Breach Claim | 2026-07-18 |
| High | Breach | YouLend: Unauthorized Network Intrusion Exposes Social Security Numbers | 2026-07-18 |
| High | Breach | Partnered Health: Malicious Actor Breaches GP Clinic Network | 2026-07-17 |
| Critical | CVE · KEV | CVE-2026-9103: Unauthenticated Superuser Access in IBM Langflow OSS | 2026-07-17 |
| Critical | CVE · KEV | CVE-2026-8859: Critical Path Traversal in IBM Langflow OSS Enables Arbitrary File Writes | 2026-07-17 |
| High | Breach | U.S. Voter Registration Databases: China State Sponsored Data Breach | 2026-07-17 |
| Critical | CVE · KEV | IBM Langflow OSS Code-Execution Flaw (CVE-2026-8481) Enables Authenticated RCE | 2026-07-17 |
| Critical | CVE · KEV | CVE-2026-8476: Critical Unsafe Deserialization RCE in IBM Langflow OSS | 2026-07-17 |
| Critical | CVE · KEV | CVE-2026-8635: Critical Privilege Escalation and Command Execution in IBM Langflow OSS | 2026-07-17 |
| High | Ransomware | Coca-Cola Fairlife: Ransomware Attack Halts US Dairy Production | 2026-07-17 |
| Critical | CVE · KEV | IBM Langflow OSS Ships Hard-Coded Credentials in CVE-2026-13446 | 2026-07-17 |
| High | Breach | Ernst & Young: Third-Party Platform Breach Exposes Client Tax Data | 2026-07-17 |
| Critical | CVE · KEV | CVE-2026-8297: Critical SQL Injection in GisLab Laboratory Management System | 2026-07-17 |
| Critical | CVE · KEV | CVE-2026-15091: Critical Cross-Site Scripting Flaw in IBM Engineering AI Hub | 2026-07-17 |
| Critical | CVE · KEV | CVE-2026-9135: Critical Code Injection in IBM Langflow OSS ToolGuard | 2026-07-17 |
| Critical | CVE · KEV | CVE-2026-12692: Critical Authentication Bypass in Vimesoft Enterprise Video Platform | 2026-07-17 |
| Critical | CVE · KEV | Fortinet FortiSandbox Hit by Critical Unauthenticated Command Injection (CVE-2026-39808) | 2026-07-16 |
| Critical | CVE · KEV | WireGuard Easy Weak Token Flaw Exposes VPN Peer Credentials (CVE-2026-63089) | 2026-07-16 |
| Critical | CVE · KEV | CVE-2023-49899: Unauthenticated Remote Command Execution in X-Rite MA-T6 | 2026-07-16 |
| Critical | CVE · KEV | CVE-2026-63087: Unauthenticated Token Hijack in Grafana OnCall | 2026-07-16 |
| Critical | CVE · KEV | CVE-2026-25089: Critical Unauthenticated Command Injection in Fortinet FortiSandbox | 2026-07-16 |
| Critical | CVE · KEV | CVE-2023-49900: Unauthenticated RCE in X-Rite MA-T6 Spectrophotometers | 2026-07-16 |
| High | Breach | Romania ANCPI: ByteToBreach Ransomware and Data Theft | 2026-07-16 |
| Critical | CVE · KEV | CVE-2026-58644: Critical SharePoint Deserialization Flaw Under Active Exploitation | 2026-07-16 |
| High | Breach | Qantas: Tech Support Scam Contact Center Breach | 2026-07-16 |
| High | Breach | TRICARE: Military Health Data Breach Exposes DoD Benefits and Social Security Numbers | 2026-07-16 |
| High | Breach | Partnered Health: Medical Data Breach Across 21 GP Clinics | 2026-07-16 |
| High | Breach | Goose Creek: 6.6 Million Shopper Records Exposed via Shopify | 2026-07-16 |
| High | Breach | Kudankulam Nuclear Power Plant: Critical Infrastructure Data Breach | 2026-07-15 |
| Critical | CVE · KEV | CVE-2026-46817: Critical Oracle E-Business Suite Flaw Enables Full Takeover of Oracle Payments | 2026-07-15 |
| Critical | CVE · KEV | CVE-2023-4346: KNX Account Lockout Flaw Lets Attackers Brick Building Automation Devices | 2026-07-15 |
| High | Ransomware | TKMS/Atlas Elektronik: The Gentlemen Ransomware Breach | 2026-07-15 |
| High | Ransomware | Spectrum Chemical: Chaos Ransomware Final Ultimatum | 2026-07-15 |
| High | Ransomware | Exact Sciences: ShinyHunters Ransomware Extortion | 2026-07-15 |
| High | Breach | Secureholiday: Data Breach Feeding a Targeted Phishing Campaign | 2026-07-15 |
| High | Breach | Partnered Health: Patient Data Stolen in GP Network Breach | 2026-07-15 |
| Critical | CVE · KEV | CVE-2026-48327: Critical ColdFusion Authorization Flaw Enables Remote Code Execution | 2026-07-14 |
| Critical | CVE · KEV | CVE-2026-15409: Critical Unauthenticated SSRF in SonicWall SMA1000 Appliances | 2026-07-14 |
| Critical | CVE · KEV | CVE-2026-48356: Critical File Upload Flaw in Adobe Commerce and Magento Enables Code Execution | 2026-07-14 |
| High | Breach | Nissan Americas: ShinyHunters PeopleSoft Zero-Day Breach | 2026-07-14 |
| Critical | CVE · KEV | Adobe ColdFusion SQL Injection Flaw Enables Arbitrary Code Execution (CVE-2026-48324) | 2026-07-14 |
| Critical | CVE · KEV | CVE-2026-48325: Critical Missing-Authentication Flaw in Adobe ColdFusion Enables Remote Code Execution | 2026-07-14 |
| Critical | CVE · KEV | CVE-2026-49798: Critical Use-After-Free Elevation of Privilege in Windows Kernel | 2026-07-14 |
| Critical | CVE · KEV | Adobe ColdFusion Path Traversal Flaw Enables Remote Code Execution (CVE-2026-48319) | 2026-07-14 |
| Critical | CVE · KEV | CVE-2026-48321: Critical Authorization Flaw in Adobe ColdFusion Enables Privilege Escalation | 2026-07-14 |
| Critical | CVE · KEV | CVE-2026-55008: Critical Cross-Site Scripting Flaw in Microsoft Exchange Server | 2026-07-14 |
| High | Breach | Inter-Con Security Systems: ShinyHunters Data Breach | 2026-07-14 |
| Critical | CVE · KEV | CVE-2026-15701: Critical Remote Buffer Overflow in Totolink NR1800X Routers | 2026-07-14 |
| Critical | CVE · KEV | Adobe ColdFusion Path Traversal Flaw (CVE-2026-48318) Rated Critical at CVSS 9.9 | 2026-07-14 |
| High | Breach | TriWest Healthcare Alliance: Unauthorized Access Breach of Tricare Beneficiary Data | 2026-07-14 |
| High | Ransomware | Momenta: DragonForce Ransomware Breach and Alleged Financial Coverup | 2026-07-14 |
| Critical | CVE · KEV | CVE-2026-48322: Critical Code Injection Flaw in Adobe ColdFusion | 2026-07-14 |
| Critical | CVE · KEV | CVE-2026-56451: Critical JWT Authentication Bypass in Siemens Opcenter X | 2026-07-14 |
| Critical | CVE · KEV | CVE-2026-48561: Critical Command Injection in Microsoft 365 Copilot Mobile Apps | 2026-07-14 |
| Critical | CVE · KEV | CVE-2026-48334: Critical Code Execution Flaw in Adobe Illustrator | 2026-07-14 |
| High | Breach | Match Group: ShinyHunters Extortion Breach | 2026-07-14 |
| Critical | CVE · KEV | CVE-2026-56164: Unauthenticated Privilege Escalation in Microsoft SharePoint Server | 2026-07-14 |
| Critical | CVE · KEV | CVE-2026-48359: Critical XXE Flaw in Adobe Experience Manager Could Enable Code Execution | 2026-07-14 |
| Critical | CVE · KEV | CVE-2026-48284: Critical ColdFusion Code Execution Flaw | 2026-07-14 |
| Critical | CVE · KEV | CVE-2026-56190: Critical Unauthenticated RDP Remote Code Execution in Windows | 2026-07-14 |
| Critical | CVE · KEV | CVE-2026-48358: Critical Code Execution Flaw in Adobe Commerce and Magento | 2026-07-14 |
| Critical | CVE · KEV | CVE-2026-15410: SonicWall SMA1000 Code Injection Under Active Exploitation | 2026-07-14 |
| High | Breach | LY Corporation: 7.1 Million LINE Game Users Exposed via Ad Tracker Misconfiguration | 2026-07-14 |
| Critical | CVE · KEV | CVE-2026-48259: Critical SSRF in Adobe Experience Manager Enables Code Execution | 2026-07-14 |
| Critical | CVE · KEV | CVE-2026-50518: Critical Unauthenticated RCE in Windows DHCP Server | 2026-07-14 |
| High | Ransomware | L'azurde: Blacknevas Ransomware Data Theft | 2026-07-14 |
| High | Ransomware | Ironmark: Akira Ransomware Data Extortion | 2026-07-14 |
| Critical | CVE · KEV | CVE-2026-54990: Critical Remote Code Execution in Windows Remote Desktop Client | 2026-07-14 |
| High | Ransomware | Aphena Pharma Solutions: Chaos Ransomware Data Theft Claim | 2026-07-14 |
| Critical | CVE · KEV | CVE-2026-50380: Critical Windows GDI+ Heap Overflow Enables Remote Code Execution | 2026-07-14 |
| High | Breach | Adobe: Raccoon Supply Chain Breach via BPO Vendor | 2026-07-13 |
| Critical | CVE · KEV | CVE-2026-4769: Unauthenticated Boot-Time Backdoor in WAGO System I/O Field Devices | 2026-07-13 |
| Critical | CVE · KEV | CVE-2026-61498: Unauthenticated Root Command Injection in Vitec Flamingo 4.12.2 | 2026-07-13 |
| Critical | CVE · KEV | CVE-2026-44747: Critical Memory Corruption in SAP NetWeaver Application Server ABAP | 2026-07-13 |
| High | Breach | CISA: Contractor Leaked AWS GovCloud Credentials on GitHub | 2026-07-13 |
| Critical | CVE · KEV | Cisco IOS CSRF Flaw (CVE-2008-4128) Added to CISA KEV After Active Exploitation | 2026-07-13 |
| High | Ransomware | Synopsys: D1R Ransomware Data Breach | 2026-07-13 |
| High | Ransomware | ARM: D1R Ransomware Breach and Data Leak | 2026-07-13 |
| Critical | CVE · KEV | CVE-2026-59801: Unauthenticated Provider API Exposure in 9Router | 2026-07-13 |
| High | Breach | Centers Laboratory: WorldLeaks Data Theft and Extortion | 2026-07-13 |
| Critical | CVE · KEV | SAP Approuter HTTP Request Smuggling — CVE-2026-27690 | 2026-07-13 |
| High | Breach | Nintendo of America: ShadowByt3$ Third-Party Extortion Breach | 2026-07-13 |
| Critical | CVE · KEV | CVE-2026-44761: SAP Commerce Cloud Ships With Publicly Documented OAuth2 Credentials | 2026-07-13 |
| Critical | CVE · KEV | CVE-2026-61500: Predictable Signing Key Enables Admin Session Forgery in Rejetto HFS | 2026-07-13 |
| High | Breach | Lidl: Third-Party Supplier Breach Exposes Customer Bank Details | 2026-07-13 |
| High | Breach | Odido: ShinyHunters Phishing Breach | 2026-07-13 |
| High | Breach | Tata Electronics: World Leaks Ransomware Supply Chain Breach | 2026-07-13 |
| High | Breach | Under Armour: 72 Million Customer Records Surface in Alleged Data Leak | 2026-07-13 |
| Critical | CVE · KEV | CVE-2026-62327: Unauthenticated API Key Exposure in 9Router | 2026-07-13 |
| High | Ransomware | Bosch: D1R Ransomware Supply Chain Extortion | 2026-07-13 |
| Critical | CVE · KEV | CVE-2026-15300: Critical SQL Injection in GEO my WP WordPress Plugin | 2026-07-10 |
| Critical | CVE · KEV | CVE-2026-15282: Critical Unauthenticated File Upload in WordPress Instant Appointment Plugin | 2026-07-10 |
| Critical | CVE · KEV | CVE-2026-14894: Unauthenticated File Upload to RCE in Super Forms for WordPress | 2026-07-10 |
| Critical | CVE · KEV | CVE-2026-15378: Critical Blind SSRF in Red Hat OpenShift AI Guardrails | 2026-07-10 |
| Critical | CVE · KEV | Hermes WebUI Unauthenticated RCE — CVE-2026-58123 | 2026-07-09 |
| Critical | CVE · KEV | CVE-2026-58122: Authentication Bypass in Hermes WebUI via X-Forwarded-For Spoofing | 2026-07-09 |
| High | Breach | AssuranceAmerica: Insurance Breach Exposes 6.9 Million Driver's License Records | 2026-07-09 |
| Critical | CVE · KEV | CVE-2026-2342: Critical Stored XSS in OceanicSoft ValeApp | 2026-07-09 |
| High | Breach | CRIM Puerto Rico: Exposed Property Map Leaks 1 Million Social Security Numbers | 2026-07-09 |
| Critical | CVE · KEV | CVE-2026-5955: Critical SQL Injection in BiEticaret E-Commerce Platform | 2026-07-09 |
| High | Breach | Conduent: SafePay Ransomware Breach Exposes 62 Million | 2026-07-09 |
| Critical | CVE · KEV | CVE-2026-15158: Unauthenticated RCE in Blocksy Companion Pro for WordPress | 2026-07-09 |
| High | Breach | Nayax: The Syndicate Claims Billion Record Card Breach | 2026-07-09 |
| High | Breach | KDDI: Third-Party Software Exploit Exposes 12 Million ISP Email Accounts | 2026-07-08 |
| High | Breach | Accenture: Threat Actor Claims 35GB Source Code and Credential Theft | 2026-07-08 |
| High | Breach | iRhythm: Social Engineering Breach of Third-Party Business Apps | 2026-07-08 |
| High | Ransomware | Mount Royal University: June Ransomware Attack and Data Theft | 2026-07-08 |
| Critical | CVE · KEV | CVE-2026-47646: Critical XSS in Microsoft Dynamics 365 Customer Voice | 2026-07-08 |
| High | Breach | KDDI: Third-Party Vulnerability Exposes 12.2 Million ISP Email Accounts | 2026-07-08 |
| High | Ransomware | Union County, Ohio: Kairos Data Extortion | 2026-07-08 |
| Critical | CVE · KEV | CVE-2026-9701: Insecure Password Reset in WordPress Eventer Plugin Enables Account Takeover | 2026-07-08 |
| Critical | CVE · KEV | CVE-2026-14487: Unauthenticated Arbitrary File Deletion in WordPress Simple Coherent Form Plugin | 2026-07-08 |
| Critical | CVE · KEV | CVE-2026-8307: Critical SQL Injection in Webbeyaz Mediküm Web | 2026-07-08 |
| Critical | CVE · KEV | CVE-2026-58480: Unauthenticated RCE in Blocksy Companion Pro for WordPress | 2026-07-08 |
| Critical | CVE · KEV | CVE-2026-12153: Unauthenticated Plugin Installation Flaw in WP Learn Manager | 2026-07-08 |
| Critical | CVE · KEV | Joomlack Page Builder CK: Unauthenticated File Upload Enables Full RCE (CVE-2026-56290) | 2026-07-07 |
| High | Breach | KDDI: Third-Party Software Exploit Exposes 12.2 Million ISP Emails | 2026-07-07 |
| High | Ransomware | Union County, Ohio: Kairos Encryption-Less Ransomware Extortion | 2026-07-07 |
| Critical | CVE · KEV | CVE-2026-59706: Unauthenticated Config Endpoints Leak API Keys and Enable SSRF in mem0 | 2026-07-07 |
| Critical | CVE | CVE-2026-59705: Unauthenticated Access in mem0 OpenMemory API | 2026-07-07 |
| Critical | CVE · KEV | CVE-2026-58473: Unauthenticated LLM Config Overwrite in Cognee Exposes All User Data | 2026-07-07 |
| Critical | CVE · KEV | CVE-2026-55255: Langflow IDOR Lets Authenticated Users Run Other Users' Flows | 2026-07-07 |
| High | Ransomware | Excel Cell Electronic: TheGentlemen Ransomware Attack | 2026-07-07 |
| Critical | CVE · KEV | CVE-2026-48282: Critical ColdFusion Path Traversal Under Active Exploitation | 2026-07-07 |
| Critical | CVE · KEV | CVE-2026-48908: Critical Unauthenticated File Upload in JoomShaper SP Page Builder | 2026-07-07 |
| High | Breach | Council of Europe: ShinyHunters Data Leak | 2026-07-07 |
| Critical | CVE · KEV | WPFunnels RCE: Unauthenticated Code Execution via Poisoned Log File (CVE-2026-14345) | 2026-07-07 |
| Critical | CVE · KEV | CVE-2026-14808: Credential Exposure in PROG MIS Prog Management System | 2026-07-06 |
| High | Ransomware | Union County, Ohio: Kairos Encryption-Less Data Extortion | 2026-07-06 |
| High | Ransomware | Logiquip: TheGentlemen Ransomware Data Extortion | 2026-07-06 |
| Critical | CVE · KEV | CVE-2026-14807: Hard-Coded Credentials in PROG MIS ERP App Expose Database Access | 2026-07-06 |
| High | Breach | Medtronic: ShinyHunters Breach Exposes 3.8 Million | 2026-07-06 |
| High | Breach | Medtronic: ShinyHunters Data Breach | 2026-07-06 |
| High | Breach | Union County, Ohio: Kairos Data Extortion | 2026-07-05 |
| High | Ransomware | Sysco: Qilin Ransomware and ShinyHunters OAuth Extortion | 2026-07-05 |
| High | Breach | UK Government: Russian State Hackers Exploit FortiBleed | 2026-07-05 |
| High | Breach | Moody Bible Institute: ShinyHunters Extortion Breach | 2026-07-04 |
| High | Ransomware | City of Acworth, Georgia: Incransom Ransomware Data Breach | 2026-07-04 |
| High | Breach | AdaptHealth: Contractor Compromise and Health Data Theft | 2026-07-04 |
| High | Ransomware | Novo Nordisk: FulcrumSec Extortion Breach | 2026-07-04 |
| High | Breach | One Medical: ShinyHunters Extortion Breach | 2026-07-04 |
| High | Ransomware | City of Oak Park, Michigan: Incransom Ransomware Attack | 2026-07-04 |
| High | Breach | U.S. Government Entity: Kairos Data-Theft Extortion | 2026-07-04 |
| High | Ransomware | Indra Group: The Gentlemen Ransomware | 2026-07-03 |
| Critical | CVE · KEV | CVE-2026-14544: Critical HPLIP Integer Overflow Enables Remote Code Execution | 2026-07-03 |
| Critical | CVE · KEV | CVE-2026-4321: Critical SQL Injection in Raera's Unsupported "Destekz" Product | 2026-07-03 |
| Critical | CVE · KEV | Printcart WooCommerce Plugin Hit by Critical Unauthenticated File Deletion Flaw (CVE-2026-9725) | 2026-07-03 |
| High | Breach | Shun Hing Group: Ransomware Data Breach | 2026-07-03 |
| High | Breach | Singapore Land Authority: 70,000 Records Exposed via Compromised IBM Test Environment | 2026-07-03 |
| High | Ransomware | FortiGate Users: FortiBleed Credential Harvesting Feeding INC and Lynx Ransomware | 2026-07-03 |
| Critical | CVE · KEV | Microsoft Edge Type Confusion Flaw (CVE-2026-58289) Rated Critical at CVSS 9.0 | 2026-07-03 |
| High | Breach | DentaQuest: Confirmed Data Breach Exposing 2.6 Million Dental Accounts | 2026-07-02 |
| Critical | CVE · KEV | CVE-2026-59099: AES-GCM Nonce Reuse in Apereo CAS Leaks Login Session State | 2026-07-02 |
| Critical | CVE · KEV | CVE-2026-58455: Unauthenticated Command Injection in Notifiarr Dockwatch | 2026-07-02 |
| High | Breach | Lakelands Public Health: Data Breach Exposes 60,000 Residents | 2026-07-02 |
| Critical | CVE · KEV | CVE-2026-45499: Critical SSRF in Azure OpenAI Enables Privilege Escalation | 2026-07-02 |
| Critical | CVE · KEV | CVE-2026-58466: Hard-Coded Default Admin Credentials in AutoBangumi | 2026-07-02 |
| Critical | CVE · KEV | CVE-2026-57100: Critical SSRF in Microsoft Entra Provisioning Service | 2026-07-02 |
| High | Ransomware | River Bank & Trust: Ransomware Breach by Unauthorized Threat Actor | 2026-07-02 |
| Critical | CVE · KEV | CVE-2026-5524: Critical Unauthenticated RCE in Divi Form Builder for WordPress | 2026-07-02 |
| Critical | CVE · KEV | CVE-2026-41106: Critical Open Redirect in Microsoft 365 Copilot | 2026-07-02 |
| High | Breach | Middletown, Ohio: SafePay Ransomware Breach | 2026-07-02 |
| High | Ransomware | DyStar: Settra Ransomware Data Theft Claim | 2026-07-01 |
| Critical | CVE · KEV | CVE-2026-34099: Unauthenticated SQL Injection in Guardian language-system | 2026-07-01 |
| Critical | CVE · KEV | CVE-2026-58453: Hard-Coded Credentials in JAIOTlink C492A-W6 Wi-Fi IP Cameras | 2026-07-01 |
| High | Ransomware | Fluke Corporation: ShinyHunters Ransomware Extortion | 2026-07-01 |
| Critical | CVE · KEV | CVE-2026-58457: Unauthenticated Root Command Injection in Shenzhen Aitemi M300 Wi-Fi Repeater | 2026-07-01 |
| Critical | CVE · KEV | CVE-2026-34108: Unauthenticated OS Command Injection in Guardian language-system | 2026-07-01 |
| High | Ransomware | Ford de Mexico: Krybit Ransomware Extortion | 2026-07-01 |
| High | Breach | NYC Health + Hospitals: Biometric Data Breach Exposing 1.8 Million People | 2026-07-01 |
| High | Breach | Sapporo and KDDI: Wave of Japanese Corporate Breaches | 2026-07-01 |
| Critical | CVE · KEV | CVE-2026-34100: Critical SQL Injection in Guardian language-system | 2026-07-01 |
| High | Ransomware | Musashino University: Qilin Ransomware Attack | 2026-07-01 |
| High | Breach | DHS: Homeland Security Information Network Breach | 2026-07-01 |
| Critical | CVE · KEV | CVE-2026-34114: Unauthenticated OS Command Injection in Guardian language-system | 2026-07-01 |
| Critical | CVE · KEV | CVE-2026-34106: Unauthenticated OS Command Injection in Guardian language-system | 2026-07-01 |
| Critical | CVE · KEV | CVE-2026-34105: Critical SQL Injection in Guardian language-system | 2026-07-01 |
| Critical | CVE · KEV | Microsoft SharePoint Server Deserialization Flaw (CVE-2026-45659) Added to CISA KEV | 2026-07-01 |
| Critical | CVE · KEV | IBM Langflow OSS Exposes All Stored Credentials via Weak Encryption Key Derivation (CVE-2026-7874) | 2026-06-30 |
| High | Breach | AssuranceAmerica: Third-Party Breach via Targeted Employee Compromise | 2026-06-30 |
| Critical | CVE · KEV | CVE-2026-11708: Critical Cross-Site Scripting Flaw in IBM WebSphere Application Server | 2026-06-30 |
| Critical | CVE · KEV | CVE-2026-12073: Critical Account Takeover in WordPress ProfileGrid Plugin | 2026-06-30 |
| High | Ransomware | Pakistan CDA: Ransomware Strike on Islamabad Billing System | 2026-06-30 |
| High | Ransomware | HMC Farms: Settra Ransomware Extortion | 2026-06-30 |
| Critical | CVE · KEV | CVE-2026-7803: Critical Code Execution Flaw in IBM Langflow OSS | 2026-06-30 |
| Critical | CVE · KEV | CVE-2026-7873: Critical Command Injection in IBM Langflow OSS | 2026-06-30 |
| Critical | CVE · KEV | CVE-2026-7871: Critical Deserialization Flaw Enables Remote Code Execution in IBM Langflow OSS | 2026-06-30 |
| Critical | CVE · KEV | CVE-2026-56700: Critical Multiple Code-Execution Flaws in Grav CMS | 2026-06-30 |
| High | Breach | Notion: Threat Actor Claims 110M Record Breach | 2026-06-30 |
| High | Breach | Texas Parks & Wildlife: Third-Party Vendor Breach Exposes 3 Million Hunters and Anglers | 2026-06-30 |
| Critical | CVE · KEV | CVE-2026-48286: Critical Authorization Flaw in Adobe Campaign Classic Enables Remote Code Execution | 2026-06-30 |
| Critical | CVE · KEV | CVE-2026-58449: Unauthenticated RCE in txtai API /reindex Endpoint | 2026-06-30 |
| High | Ransomware | DC Housing Authority: Ransomware Attack With Data Theft Claim | 2026-06-30 |
| Critical | CVE · KEV | IBM Langflow OSS Hit by Critical CVE-2026-10134: Full Compromise via Code Injection | 2026-06-30 |
| Critical | CVE · KEV | IBM WebSphere Application Server Hit by Critical XSS Flaw (CVE-2026-11712) | 2026-06-30 |
| High | Ransomware | Nidec Corporation: Blackfield Ransomware $2M Extortion | 2026-06-30 |
| Critical | CVE · KEV | CVE-2026-48276: Critical Unauthenticated Code Execution in Adobe ColdFusion | 2026-06-30 |
| Critical | CVE · KEV | IBM Db2 Pre-Auth RCE (CVE-2026-10109): Critical DRDA Handshake Flaw | 2026-06-30 |
| Critical | CVE · KEV | Ocelot API Gateway IP Allow/Block List Bypass via WebSocket Upgrade (CVE-2026-58172) | 2026-06-30 |
| High | Breach | NAIC: ShinyHunters Oracle PeopleSoft Zero-Day Breach | 2026-06-30 |
| Critical | CVE · KEV | IBM Langflow OSS Cross-Tenant Credential Reuse (CVE-2026-10140) | 2026-06-30 |
| Critical | CVE · KEV | Adobe ColdFusion CVE-2026-48277: Critical CVSS 10.0 Remote Code Execution | 2026-06-30 |
| Critical | CVE · KEV | CVE-2026-58116: Critical RCE in LLaMA-Factory via Malicious Model Path | 2026-06-30 |
| High | Breach | Aflac Japan: Policyholder Portal Breach Exposes 4.38 Million Customers | 2026-06-30 |
| Critical | CVE · KEV | CVE-2026-58166: Unauthenticated Path Traversal in OpenBMB ChatDev Upload Handler | 2026-06-30 |
| Critical | CVE · KEV | CVE-2026-56278: Hardcoded Default Session Secret in Flowise Enables Authentication Bypass | 2026-06-30 |
| Critical | CVE · KEV | Orkes Conductor Unauthenticated RCE: CVE-2026-58138 | 2026-06-30 |
| High | Breach | Logitech: Clop Extortion via Oracle Zero-Day | 2026-06-29 |
| High | Breach | Towerpoint Wealth: Unauthorized Actor Exfiltrates Client Financial Data | 2026-06-29 |
| High | Breach | Nissan: Oracle E-Business Suite Zero-Day Data Breach | 2026-06-29 |
| High | Ransomware | Hologic: Redact Ransomware Data Extortion | 2026-06-29 |
| High | Breach | European Commission: Cloud Data Breach Confirmed | 2026-06-29 |
| Critical | CVE · KEV | SimpleHelp OIDC Authentication Bypass (CVE-2026-48558) Lands on CISA's KEV List | 2026-06-29 |
| High | Breach | Southern Illinois Ob-Gyn Associates: Network Intrusion Exposes 38,700 Patients | 2026-06-29 |
| High | Breach | DETRAN SP: pl4t0v Free Database Leak of 13 Million Records | 2026-06-29 |
| High | Breach | LexisNexis: FulcrumSec Exfiltrates 2GB From AWS Infrastructure | 2026-06-29 |
| High | Ransomware | Shwapno: Ransom-Driven Breach of Bangladesh's Largest Grocery Chain | 2026-06-29 |
| High | Breach | Connecticut Medicaid: Credential Theft Breach Exposes 22,500 Patient Records | 2026-06-29 |
| High | Breach | Queensland State Schools: Third-Party Breach via Instructure QLearn Platform | 2026-06-29 |
| High | Ransomware | Kyowon Group: Ransomware Attack Exposes Millions of Accounts | 2026-06-29 |
| High | Ransomware | TRANSCORE and 1-800-DENTIST: Qilin Ransomware Leak Site Listings | 2026-06-29 |
| High | Breach | Hartford HealthCare: Credential Compromise Breaches 22,500 Accounts | 2026-06-29 |
| High | Breach | Rockstar Games: ShinyHunters Extortion Leak | 2026-06-29 |
| High | Breach | NSW Rural Fire Service: Nova Ransomware Breach | 2026-06-28 |
| High | Ransomware | Challenge Manufacturing: Chaos Ransomware Data Theft | 2026-06-28 |
| High | Breach | French Employment and HR Apps: Unattributed Mass Data Leak | 2026-06-28 |
| High | Breach | Medtronic: ShinyHunters Data Breach | 2026-06-28 |
| High | Breach | Polymarket: Supply-Chain Phishing Attack | 2026-06-28 |
| High | Breach | Tabiq: Cloud Misconfiguration Exposes 1M+ Identity Documents | 2026-06-28 |
| High | Ransomware | GökNur Gıda: Dreamfyre Ransomware Leak of 10.7 TB | 2026-06-28 |
| High | Breach | University of Nottingham: ShinyHunters Data Breach | 2026-06-28 |
| High | Breach | Insee: Cyberattack Exposing Staff Personal Data | 2026-06-28 |
| High | Breach | Trenitalia: Customer Ticket Data Breach via Unauthorized Access | 2026-06-28 |
| High | Breach | Dutch Ministry of Finance: Unauthorized Access to Primary Process Systems | 2026-06-28 |
| High | Breach | Japan Self-Defense Forces: China-Linked USB Firmware Espionage | 2026-06-28 |
| High | Breach | Turkish Cypriot Administration: Health Ministry Breach and Dark Web Leak | 2026-06-27 |
| Critical | CVE · KEV | CVE-2026-12415: Unauthenticated Account Takeover in WordPress Invoice Generator Plugin | 2026-06-27 |
| High | Breach | Instructure Canvas: Suspected ShinyHunters Education Sector Breach | 2026-06-27 |
| High | Breach | Colorado Health Network and Kentucky Mountain Health Alliance: Cephalus Ransomware and Healthcare Data Breaches | 2026-06-27 |
| High | Breach | Nefos Cannabis ID Verification: Exposed Database Leaks One Million Passports | 2026-06-27 |
| High | Ransomware | River Financial Corporation: Ransomware Intrusion Disrupts Banking Operations | 2026-06-27 |
| High | Breach | American Tower: ShinyHunters Pay-or-Leak Extortion | 2026-06-27 |
| High | Breach | 100+ Organizations: ShinyHunters PeopleSoft Zero-Day Mass Breach | 2026-06-27 |
| High | Breach | Carnival Corporation: Social Engineering Data Breach | 2026-06-27 |
| High | Ransomware | Adapt: ShinyHunters Ransomware Extortion | 2026-06-26 |
| High | Breach | Universities and Enterprises: ShinyHunters PeopleSoft Zero-Day Campaign | 2026-06-26 |
| High | Breach | Reynella East College: Interlock Ransomware Data Dump | 2026-06-26 |
| High | Breach | Alamo Heights ISD: Ransomware Data Breach | 2026-06-26 |
| High | Breach | NAIC: PeopleSoft Zero-Day Breach | 2026-06-26 |
| High | Breach | Dialog Network: Exposed Records of NATO and US Officials | 2026-06-26 |
| High | Breach | Healthcare AI Provider: Misconfiguration Exposes 1.4M Humana and Mayo Clinic Patients | 2026-06-26 |
| High | Ransomware | Padget Technologies: Akira Ransomware Data Extortion | 2026-06-26 |
| High | Breach | Prince George County, Va.: Cyberattack Exposes Resident and Employee Data | 2026-06-26 |
| High | Breach | Latvijas valsts meži: Commercially Motivated Hacker Breaches State Forests IT Systems | 2026-06-26 |
| High | Breach | Jaguar Land Rover: Russia-Linked Ransomware Attack | 2026-06-26 |
| High | Breach | Klue: Icarus Salesforce Supply-Chain Breach | 2026-06-26 |
| Critical | CVE · KEV | CVE-2026-54636: Critical Container Escape in Dokku's Cron Plugin | 2026-06-26 |
| High | Ransomware | Barts Health NHS: Clop Ransomware via Oracle Zero-Day | 2026-06-25 |
| High | Ransomware | ISOPLUS: Qilin Ransomware Data Extortion | 2026-06-25 |
| High | Ransomware | Leo International: Akira Ransomware Data Theft Claim | 2026-06-25 |
| High | Breach | Grafana Labs: Mini Shai-Hulud npm Supply Chain Attack | 2026-06-25 |
| High | Breach | Texas Parks and Wildlife Department: Third-Party Vendor Breach Exposes 3 Million License Holders | 2026-06-25 |
| Critical | CVE · KEV | Cisco Unified CM SSRF Flaw (CVE-2026-20230) Added to CISA KEV | 2026-06-25 |
| Critical | CVE · KEV | CVE-2026-12569: Unauthenticated RCE in PTC Windchill and FlexPLM | 2026-06-25 |
| High | Breach | Xolis: Targeted Phishing Compromises Healthcare AI Vendor | 2026-06-25 |
| Critical | CVE · KEV | CVE-2026-12417: Unauthenticated Account Takeover in WordPress SignUp & SignIn Plugin | 2026-06-24 |
| High | Ransomware | Bajaj Auto: Ransomware Attack Disrupts Systems | 2026-06-24 |
| Critical | CVE · KEV | CVE-2026-12416: Unauthenticated Account Takeover in WordPress Invoice Generator Plugin | 2026-06-24 |
| High | Breach | Madison Square Garden: Vishing Breach Exposes Knicks and Talent Records | 2026-06-24 |
| High | Breach | Tchap: Account Hijack Breach of French Government Messaging | 2026-06-24 |
| High | Breach | Fortinet Firewalls: FortiBleed Mass Credential Theft Campaign | 2026-06-24 |
| High | Ransomware | Romanian Hospitals: Backmydata Ransomware (Phobos Family) | 2026-06-24 |
| Critical | CVE · KEV | CVE-2026-56237: Critical Authentication Bypass in Capgo API Key Generation | 2026-06-24 |
| High | Breach | Transport for London: Teenage Hackers Breach and 10M Passenger Data Theft | 2026-06-24 |
| Critical | CVE · KEV | CVE-2026-11807: Missing Authorization in Event-Driven Ansible Leaks Plaintext Credentials | 2026-06-23 |
| High | Ransomware | NationsBuilders Insurance Services: Aurora Ransomware Data Theft | 2026-06-23 |
| High | Breach | KDDI: Third-Party Software Exploit Exposes 14.22 Million Email Records | 2026-06-23 |
| Critical | CVE · KEV | CVE-2026-34909: Critical Path Traversal in Ubiquiti UniFi OS | 2026-06-23 |
| Critical | CVE · KEV | CVE-2026-34908: Critical Access Control Flaw in Ubiquiti UniFi OS | 2026-06-23 |
| High | Breach | LastPass: OAuth Token Theft via Klue Supply Chain Attack | 2026-06-23 |
| High | Breach | Xsolis: Phishing Driven Healthcare Data Breach | 2026-06-23 |
| High | Breach | Spectrum: ShinyHunters Vishing Breach | 2026-06-23 |
| High | Ransomware | US Law Firms: Luna Moth Social-Engineering Extortion | 2026-06-23 |
| Critical | CVE · KEV | CVE-2026-34910: Critical Command Injection in Ubiquiti UniFi OS | 2026-06-23 |
| Critical | CVE · KEV | CVE-2025-67038: Critical Root-Level Command Injection in Lantronix EDS5000 Device Servers | 2026-06-23 |
| High | Breach | Belgian State Security (VSSE): Ivanti EPMM Exploitation Exposes Employee Data | 2026-06-22 |
| High | Ransomware | Go2Joy: RansomEXX Ransomware Breach | 2026-06-22 |
| High | Ransomware | Capital Development Authority Islamabad: Billing Systems Ransomware Attack | 2026-06-22 |
| Critical | CVE · KEV | CVE-2026-10561: Critical Unauthenticated RCE in IBM Langflow OSS | 2026-06-22 |
| Critical | CVE · KEV | CVE-2026-56348: n8n Credential Exfiltration via Allowed HTTP Request Domains Bypass | 2026-06-22 |
| High | Breach | TVING: Data Breach Exposes 19.53 Million Users | 2026-06-22 |
| High | Breach | Canada Life: ShinyHunters Salesforce Extortion | 2026-06-22 |
| Critical | CVE · KEV | CVE-2026-7664: Critical Authorization Bypass in IBM Langflow OSS MCP Endpoint | 2026-06-22 |
| High | Breach | Kodak: ShinyHunters Extortion Breach | 2026-06-22 |
| High | Breach | Tata Electronics: World Leaks Ransomware Breach Exposing Apple, Tesla Trade Secrets | 2026-06-22 |
| High | Breach | Carnival Cruise Line: Social Engineering Breach Exposes 6 Million | 2026-06-22 |
| High | Breach | JCPenney: ShinyHunters PeopleSoft Zero-Day Breach | 2026-06-21 |
| High | Breach | Brazil Civil Defense: Emergency Alert System Hijack | 2026-06-21 |
| High | Breach | U.S. Classified Networks: Anthropic Mythos Autonomous AI Breach | 2026-06-21 |
| High | Ransomware | ALS Global: Aurora Ransomware Breach | 2026-06-21 |
| High | Ransomware | Desert Micro: Nova Ransomware Data Extortion | 2026-06-21 |
| High | Ransomware | Q Link Wireless: Qilin Ransomware Attack | 2026-06-21 |
| High | Ransomware | Global Schools Group: FulcrumSec Ransomware Attack | 2026-06-21 |
| High | Breach | Klue Customers: Icarus OAuth Token Abuse | 2026-06-20 |
| High | Breach | African National Congress: Black X Extortion Breach | 2026-06-20 |
| High | Breach | Inter-Con Security: ShinyHunters Extortion Leak | 2026-06-20 |
| High | Ransomware | Signature Healthcare: Anubis Ransomware | 2026-06-20 |
| High | Breach | Huntress: ShinyHunters Salesforce Data Theft via Klue App | 2026-06-20 |
| High | Ransomware | One Medical: ShinyHunters Data-Theft Extortion | 2026-06-19 |
| High | Breach | Moody Bible Institute: ShinyHunters Data Theft and Extortion | 2026-06-19 |
| High | Breach | Texas Parks & Wildlife: Vendor Breach Exposes 3 Million Licenses and Passports | 2026-06-19 |
| High | Breach | Texas Parks & Wildlife Department: Third-Party Vendor Breach Exposes 3 Million IDs | 2026-06-19 |
| High | Breach | Texas Parks & Wildlife Department: Third-Party Vendor Breach Exposes 3 Million Residents | 2026-06-19 |
| High | Ransomware | Horizon Family Medical Group: Incransom Ransomware Breach | 2026-06-19 |
| High | Breach | Texas State Agency: Third-Party Vendor Compromise | 2026-06-19 |
| High | Breach | Texas Parks & Wildlife: Third-Party Vendor Breach Exposes 3 Million | 2026-06-18 |
| High | Breach | Fortinet: Russian-Speaking Criminals Mass-Compromise FortiGate Gateways | 2026-06-17 |
| High | Breach | Madison Square Garden Sports: ShinyHunters Data Extortion | 2026-06-17 |
| High | Ransomware | Adriatic Port Authority: Anubis Ransomware Cripples Maritime Operations | 2026-06-17 |
| High | Breach | Ohio, Georgia, and Arizona Hospital Networks: Coordinated Ransomware Breach | 2026-06-16 |
| High | Breach | iRhythm Holdings: Social Engineering Breach and Extortion | 2026-06-16 |
| High | Breach | Instructure Canvas: ShinyHunters Freemium Tier Breach | 2026-06-16 |
| High | Breach | Sysco: ShinyHunters Salesforce Extortion | 2026-06-16 |
| High | Breach | World Food Programme: Unauthorized Breach of Gaza Aid Registration Platform | 2026-06-16 |
| Critical | CVE · KEV | CVE-2026-48907: Unauthenticated RCE in Widget Factory's JCE Editor for Joomla | 2026-06-16 |
| High | Breach | HDFC AMC: Morpheus Ransomware Breach and 680 GB Data Theft | 2026-06-16 |
| High | Ransomware | Three U.S. Regional Banks: SilverThread Ransomware Extortion | 2026-06-16 |
| High | Breach | Glendale Community College: ShinyHunters Exfiltrates 62GB From PeopleSoft Campus Solutions | 2026-06-16 |
| High | Breach | Nintendo: SHADOWBYT3$ Third-Party SaaS Breach | 2026-06-16 |
| Critical | CVE · KEV | CVE-2026-20262: Cisco Catalyst SD-WAN Manager Path Traversal Flaw Added to CISA KEV | 2026-06-15 |
| High | Breach | Meta Platforms: Confirmed Data Breach Exposes Up to 100,000 Records | 2026-06-15 |
| Critical | CVE · KEV | LiteSpeed cPanel Plugin Symlink Flaw (CVE-2026-54420) Added to CISA KEV | 2026-06-15 |
| High | Ransomware | Mackay Sugar: The Gentlemen Ransomware (Storm-2697) | 2026-06-15 |
| High | Breach | Humanity Protocol: North Korean Phishing Crypto Heist | 2026-06-15 |
| High | Breach | Kaluga Astral: Week-Long Service Disruption from Cyberattack | 2026-06-15 |
| High | Breach | Council of Europe: ShinyHunters PeopleSoft Data Theft | 2026-06-15 |
| High | Breach | Eastman Kodak: ShinyHunters Pay or Leak Extortion | 2026-06-15 |
| High | Breach | Infinite Campus: ShinyHunters Extortion Data Leak | 2026-06-15 |
| High | Breach | Berkadia: ShinyHunters Salesforce Extortion Breach | 2026-06-15 |
| High | Breach | 700Credit: API Abuse via Compromised Integration Partner | 2026-06-15 |
| High | Breach | North American Research Institutions: UNC6508 REDCap Espionage | 2026-06-15 |
| High | Breach | Norfolk and Norwich University Hospital: Qilin Ransomware Patient Data Theft | 2026-06-12 |
| High | Breach | Vietnam National Immunization System: Self-Taught Teen Breach | 2026-06-12 |
| Critical | CVE · KEV | IEI iRM-IEI Remote Management Hardcoded Credentials (CVE-2026-11849) | 2026-06-12 |
| High | Breach | California Water Service: Handala Hack and Leak Breach | 2026-06-12 |
| High | Breach | Ralph Lauren Corporation: ShinyHunters Data Extortion | 2026-06-12 |
| High | Breach | Novo Nordisk: Clinical Trials Data Breach | 2026-06-12 |
| Critical | CVE · KEV | CVE-2026-49973: Unauthenticated Account Takeover in Hermes WebUI Setup | 2026-06-11 |
| High | Ransomware | Singing River Health System: Anubis Ransomware Breach | 2026-06-11 |
| High | Breach | Universities: ShinyHunters Oracle PeopleSoft Mass Compromise | 2026-06-11 |
| High | Breach | Oracle PeopleSoft Customers: ShinyHunters Data Theft Extortion | 2026-06-11 |
| High | Ransomware | Isuzu Motors: Qilin Ransomware Cross-Sector Batch | 2026-06-11 |
| Critical | CVE · KEV | CVE-2026-11839: Critical Web Shell Upload Flaw in Başarsoft Rotaban | 2026-06-11 |
| High | Breach | ServiceNow: Zero-Auth API Breach Exposes Enterprise Instance Data | 2026-06-11 |
| High | Breach | Synnovis: Qilin Ransomware NHS Data Breach | 2026-06-11 |
| Critical | CVE · KEV | Ivanti Sentry CVE-2026-10520: Unauthenticated Root RCE Added to CISA KEV | 2026-06-11 |
| High | Breach | Lithuanian Health Ministry: Apache Superset Exploited in Government Breach | 2026-06-11 |
| High | Breach | France Titres (ANTS): IDOR Breach Exposes Millions of French Citizens | 2026-06-11 |
| High | Breach | VRChat: External Cloud Breach Exposes 2.4 Million Users | 2026-06-11 |
| High | Breach | Coupang: Insider-Built Backdoor Exposes 37.5 Million | 2026-06-11 |
| High | Breach | Nexstar: ShinyHunters Salesforce Data Theft | 2026-06-11 |
| Critical | CVE · KEV | CVE-2026-7852: Critical Unrestricted File Upload Flaw in Limatek LimRAD NAC | 2026-06-11 |
| High | Ransomware | University of Nottingham: ShinyHunters Ransomware Breach | 2026-06-10 |
| Critical | CVE · KEV | CVE-2026-53475: Hardcoded Insecure TLS in assisted-migration-agent Exposes vCenter Admin Credentials | 2026-06-10 |
| High | Breach | Discord: Disputed Insider Breach Filing Claims 10 Million Users Exposed | 2026-06-10 |
| Critical | CVE · KEV | CVE-2026-53474: Critical SQL Injection in migration-planner via Malicious RVTools Upload | 2026-06-10 |
| High | Breach | OkCupid: Forum Hackers Selling 35 Million Scraped User Records | 2026-06-10 |
| Critical | CVE · KEV | CVE-2026-53476: Critical Path Traversal in Red Hat assisted-migration-agent | 2026-06-10 |
| High | Breach | Delaware North: Microsoft Account Compromise and File Exfiltration | 2026-06-10 |
| Critical | CVE · KEV | CVE-2026-53470: Critical Access Control Flaw in migration-planner Exposes Other Users' OVA Images | 2026-06-10 |
| High | Ransomware | Singing River Health System: Anubis Ransomware Breach | 2026-06-10 |
| High | Ransomware | Réseau Radiologique Romand: Akira Ransomware | 2026-06-10 |
| High | Breach | H1: Soral Leaks 2M+ Medical Professional Records | 2026-06-10 |
| High | Breach | Nottingham University: ShinyHunters PeopleSoft Data Theft | 2026-06-10 |
| High | Breach | Station Casinos: Single Compromised Account Leads to PII Breach and Class Action | 2026-06-10 |
| Critical | CVE · KEV | CVE-2026-53469: Missing Authorization in migration-planner Allows Total Data Destruction | 2026-06-10 |
| Critical | CVE · KEV | Doctreat Core for WordPress: Unauthenticated Admin Registration (CVE-2025-6254) | 2026-06-10 |
| High | Ransomware | FESCO Adecco: TheGentlemen Ransomware Breach | 2026-06-10 |
| Critical | CVE · KEV | Critical Unauthenticated File Write Flaw in Splunk Enterprise and Cloud Platform (CVE-2026-20253) | 2026-06-10 |
| High | Breach | Hokkaido Medical Center and Hokkaido Cancer Center: Improper Disk Disposal Data Leak | 2026-06-09 |
| Critical | CVE · KEV | CVE-2026-11645: High-Severity Chromium V8 Flaw Lands on CISA's KEV List | 2026-06-09 |
| High | Breach | Proprietes-Privees: ChimeraZ API Breach Exposes 2.5M People | 2026-06-09 |
| Critical | CVE · KEV | Critical Code Execution Flaw in Azure Stack Edge — CVE-2026-47643 (CVSS 9.8) | 2026-06-09 |
| Critical | CVE · KEV | CVE-2026-34691: Critical Stored XSS in Adobe Experience Manager Forms JEE | 2026-06-09 |
| Critical | CVE · KEV | CVE-2026-47928: Critical ColdFusion Code Execution Flaw | 2026-06-09 |
| High | Breach | Lansing Community College: Compromised Credentials Breach Hits 174,000 | 2026-06-09 |
| Critical | CVE · KEV | CVE-2026-7486: Critical SQL Injection in Netcad E-İmar | 2026-06-09 |
| Critical | CVE · KEV | Critical RCE in Windows DHCP Client — CVE-2026-44815 | 2026-06-09 |
| High | Breach | SoFi Hong Kong: Third-Party Vendor Breach | 2026-06-09 |
| Critical | CVE · KEV | CVE-2026-45657: Critical Windows Kernel Use-After-Free Enables Remote Code Execution | 2026-06-09 |
| Critical | CVE · KEV | Arista EOS Tunnel Decapsulation Flaw (CVE-2026-7473) Hits CISA KEV Under Active Exploitation | 2026-06-09 |
| High | Ransomware | Foxconn: Nitrogen Ransomware Breach via Malvertising and ESXi Exploit | 2026-06-09 |
| Critical | CVE · KEV | CVE-2026-45602: Critical Windows DHCP Server Tampering Flaw | 2026-06-09 |
| Critical | CVE · KEV | CVE-2017-20251: Unauthenticated PHP Code Injection in WordPress Insert PHP Plugin | 2026-06-09 |
| Critical | CVE · KEV | CVE-2026-47281: Critical Privilege Escalation Flaw in Visual Studio Code | 2026-06-09 |
| Critical | CVE · KEV | CVE-2026-42904: Critical Windows TCP/IP Heap Overflow Enables Privilege Escalation | 2026-06-09 |
| Critical | CVE · KEV | CVE-2026-48303: Critical Authorization Flaw in Adobe Campaign Classic Enables Remote Code Execution | 2026-06-09 |
| Critical | CVE · KEV | CVE-2026-26142: Critical Deserialization RCE in Nuance PowerScribe | 2026-06-09 |
| High | Ransomware | Singing River Health System: Anubis Ransomware Data Theft | 2026-06-09 |
| High | Breach | Texas Capital Bank: 91,000 Customers Exposed in Data Breach | 2026-06-09 |
| Critical | CVE · KEV | Cisco Catalyst SD-WAN Manager Root Command Injection (CVE-2026-20245) | 2026-06-09 |
| Critical | CVE · KEV | CVE-2026-8025: Critical SQL Injection in MOSK CBS Platform | 2026-06-09 |
| High | Breach | World Food Programme: Unauthorized Access of Gaza Self-Registration App | 2026-06-09 |
| High | Breach | Kyushu Electric Power: Missing SSD Exposes 10.9 Million Records | 2026-06-09 |
| Critical | CVE · KEV | CVE-2026-47291: Critical HTTP.sys Integer Overflow Enables Unauthenticated Remote Code Execution | 2026-06-09 |
| High | Breach | Aflac: Scattered Spider Help-Desk Breach | 2026-06-09 |
| Critical | CVE · KEV | Check Point Security Gateway VPN Auth Bypass: CVE-2026-50751 Added to CISA KEV | 2026-06-08 |
| High | Breach | Syrian Government: Erresira Claims 20GB Diplomatic Document Breach | 2026-06-08 |
| High | Ransomware | Change Healthcare: 190M Record Ransomware Breach | 2026-06-08 |
| High | Ransomware | AT&T: ShinyHunters Ransom Payment for Stolen Call Records | 2026-06-08 |
| High | Ransomware | Nigerian Transport Carrier: Unidentified Syndicate Double-Extortion Ransomware | 2026-06-08 |
| Critical | CVE · KEV | CVE-2023-54352: Unauthenticated RCE in WordPress Seotheme | 2026-06-08 |
| High | Ransomware | Evanston Township High School District 202: Ransomware Attack Disrupts Summer Operations | 2026-06-08 |
| Critical | CVE · KEV | BerriAI LiteLLM Command Injection (CVE-2026-42271) Lands in CISA KEV | 2026-06-08 |
| High | Breach | Qantas: Scattered Lapsus$ Hunters Dark Web Leak | 2026-06-08 |
| High | Breach | TeamViewer: Russian APT29 Corporate Network Breach | 2026-06-08 |
| Critical | CVE · KEV | CVE-2024-58349: Unauthenticated RCE in WordPress Travelscape Theme | 2026-06-08 |
| Critical | CVE · KEV | CVE-2026-27671: Critical Unauthenticated RCE in SAP NetWeaver ABAP Kernel | 2026-06-08 |
| High | Breach | Medtronic: ShinyHunters Data Breach | 2026-06-08 |
| High | Breach | Tchap: Dark Web Actor Claims Massive Government Messaging Breach | 2026-06-08 |
| Critical | CVE · KEV | CVE-2026-11499: Critical Remote Stack Overflow in Tenda HG7, HG9, and HG10 XPON Routers | 2026-06-08 |
| Critical | CVE · KEV | CVE-2024-58348: Unauthenticated RCE in WordPress Background Image Cropper Plugin | 2026-06-08 |
| High | Breach | Creditas: Dark Web Actor Claims Massive Fintech Breach | 2026-06-08 |
| High | Ransomware | US Trade Association: Genesis Ransomware Claim | 2026-06-08 |
| Critical | CVE · KEV | OpenBullet2 Auth Bypass: One Empty Header Hands Over Admin (CVE-2026-25555) | 2026-06-08 |
| High | Ransomware | Lürssen: Ransomware Attack Halts Superyacht Production | 2026-06-08 |
| High | Breach | Toyota Financial Services: Medusa Ransomware Attack | 2026-06-08 |
| Critical | CVE · KEV | CVE-2026-39910: Critical Privilege Escalation in STACKIT IaaS API | 2026-06-08 |
| High | Breach | Mid and South Essex NHS Trust: Qilin Ransomware Data Theft | 2026-06-08 |
| Critical | CVE · KEV | CVE-2026-41448: AdGuard Home Authentication Bypass via Path Traversal in Admin-Token Cookie | 2026-06-08 |
| Critical | CVE · KEV | CVE-2026-40128: Critical Path Traversal in SAP NetWeaver Application Server Java | 2026-06-08 |
| High | Ransomware | Hansoll Textile: Payload Ransomware Campaign Expands | 2026-06-08 |
| Critical | CVE · KEV | CVE-2026-44748: Critical Signature Verification Flaw in SAP NetWeaver AS ABAP | 2026-06-08 |
| High | Breach | FBI: Salt Typhoon Breaches Digital Collection Systems Network | 2026-06-07 |
| High | Breach | CISA: Chemical Security Assessment Tool Breach | 2026-06-07 |
| High | Breach | Oxford University: CareerConnect Vendor Breach via Group GTI | 2026-06-07 |
| High | Ransomware | BELFOR Asia: INC Ransom Breach | 2026-06-07 |
| High | Breach | DentaQuest: ShinyHunters Leak Exposes 2.6 Million | 2026-06-07 |
| High | Ransomware | Kriete Truck Centers: Securotrop Ransomware Listing | 2026-06-07 |
| High | Breach | Baker Distributing: ShinyHunters Salesforce and SharePoint Leak | 2026-06-07 |
| High | Breach | NSCC Tianjin: Alleged 10PB Classified Data Breach | 2026-06-07 |
| High | Ransomware | Access Dental: WorldLeaks Ransomware Breach | 2026-06-07 |
| High | Breach | City of Vallejo: Constant Contact Email Platform Hijacked | 2026-06-07 |
| High | Breach | Tradeify: macaroni Leaks 240K Customer Records via Exposed API Key | 2026-06-07 |
| High | Ransomware | ICBC Financial Services: Ransomware Attack Disrupts Treasury Market | 2026-06-07 |
| High | Breach | FBI Director Kash Patel: Handala Hack Team Gmail Breach | 2026-06-07 |
| High | Ransomware | US Telecom Provider: Akira Ransomware Breach Claim | 2026-06-07 |
| High | Breach | Meridianbet: INF GRUPA Customer Database Breach | 2026-06-07 |
| High | Breach | IBM: APT10 Breach Coverup Allegations | 2026-06-07 |
| High | Breach | RCI Hospitality: IDOR Vulnerability Exposes 40,000 Contractors | 2026-06-07 |
| High | Breach | Conduent Business Services: Healthcare Data Breach Impacts 62.2M | 2026-06-06 |
| High | Ransomware | Aspire Hospital: Nova Ransomware Claim | 2026-06-06 |
| High | Breach | Erie Family Health: 570K Patient Breach After 48 Day Network Intrusion | 2026-06-06 |
| High | Ransomware | RUAG: Akira Ransomware Payment Confirmed | 2026-06-06 |
| High | Breach | UN World Food Program: Gaza Enrollment System Breach Exposes 600,000 Households | 2026-06-06 |
| High | Breach | Clarinda Regional Health Center: LockBit5 Ransomware Breach | 2026-06-06 |
| High | Ransomware | Ireland HSE: Third-Party Vendor Ransomware Outage | 2026-06-06 |
| High | Breach | Illuminate Education: FTC Finalizes Order Over Student Data Breach | 2026-06-06 |
| High | Breach | Strategic Education: Unknown Actor Exfiltrates SSNs in 87-Day Stealth Breach | 2026-06-05 |
| High | Ransomware | Mountain Park, Oklahoma: Municipal Ransomware Attack | 2026-06-05 |
| High | Ransomware | Avcon Jet: Qilin Ransomware Attack | 2026-06-05 |
| High | Breach | IBM and AT&T: Concealed Foreign Breaches of Federal Cloud Infrastructure | 2026-06-05 |
| Critical | CVE · KEV | CVE-2026-28318: SolarWinds Serv-U Unauthenticated Crash via Deflate-Encoded POST | 2026-06-05 |
| High | Ransomware | Oaks Park and Kennon Worldwide: Akira Ransomware Extortion | 2026-06-05 |
| Critical | CVE · KEV | CVE-2025-71317: Hard-Coded Backdoor in Riello NetMan 204 Grants Unauthenticated Admin Access | 2026-06-05 |
| High | Ransomware | Pyramid: Nitrogen Ransomware Attack | 2026-06-05 |
| High | Breach | Columbia University: Politically Motivated Breach Exposes 868,969 Records | 2026-06-05 |
| High | Breach | Grindr: Alleged Sale of 15 Million User Records | 2026-06-05 |
| High | Ransomware | Sicol: SpaceBears Ransomware Attack | 2026-06-05 |
| High | Ransomware | Instructure Canvas: ShinyHunters Ransomware Breach | 2026-06-05 |
| Critical | CVE · KEV | CVE-2026-10580: Unauthenticated Admin Takeover in Hippoo Mobile App for WooCommerce | 2026-06-05 |
| High | Breach | Osmose France: Alleged Dark Web Data Breach Claim | 2026-06-05 |
| High | Ransomware | SA2000: Stormous Ransomware Breach | 2026-06-05 |
| High | Ransomware | Factors Western: Akira Ransomware Attack | 2026-06-05 |
| Critical | CVE · KEV | CVE-2026-6274: Critical Authentication Bypass in DTS Redline WR3200 Routers | 2026-06-05 |
| High | Ransomware | National Standard Parts Associates: Akira Ransomware Data Leak | 2026-06-05 |
| Critical | CVE · KEV | CVE-2025-71318: NetMan 204 Missing Authentication Exposes UPS Control to Remote Attackers | 2026-06-05 |
| High | Breach | IKEA: Lapsus$ Alleged 180GB Data Leak Investigation | 2026-06-05 |
| High | Breach | Ultrahuman: Infostealer Malware Breach via Stolen Employee Credentials | 2026-06-05 |
| High | Breach | 23andMe: California AG Sues Over 2023 Credential-Stuffing Breach | 2026-06-04 |
| High | Breach | European Commission: TeamPCP and ShinyHunters Cloud Breach | 2026-06-04 |
| High | Breach | CAEM Mexico: Sativa Gang Leaks 21GB SIAF Database | 2026-06-04 |
| Critical | CVE · KEV | CVE-2026-4104: Critical SQL Injection and Authorization Bypass in Akmer TeknoPass | 2026-06-04 |
| High | Ransomware | MarketJoy: Qilin Ransomware Extortion | 2026-06-04 |
| High | Breach | Anonymous Video Chat App: 22 Million Record Exposure | 2026-06-04 |
| High | Ransomware | ViaQuest: Ransomware Attack Exposes Patient and Employee Data | 2026-06-04 |
| Critical | CVE · KEV | CVE-2019-25727: Arbitrary File Download in WordPress Ad Manager WD Plugin | 2026-06-04 |
| High | Breach | Spanish National Police and INCIBE: Granada-Based Doxing Operation | 2026-06-04 |
| Critical | CVE · KEV | CVE-2019-25741: MobaXterm 12.1 SEH Buffer Overflow via Malicious Session File | 2026-06-04 |
| High | Ransomware | Case Law Correctional Services: Black X Ransomware Breach | 2026-06-04 |
| High | Breach | UN World Food Programme: Self-Registration Platform Breach | 2026-06-04 |
| High | Breach | Carnival Cruise: ShinyHunters Social Engineering Breach | 2026-06-04 |
| High | Breach | iFood: 1.2 Million Brazilian Users Exposed in Confirmed Breach | 2026-06-04 |
| High | Breach | Pemprov DKI Jakarta: Citizen CRM and NIK Identities Leaked | 2026-06-04 |
| High | Breach | Morocco Civil Records: Jabaroot Watiqa.ma Data Leak | 2026-06-04 |
| Critical | CVE · KEV | CVE-2026-10840: OpenShift Pipelines Operator Grants Authenticated Users Write Access to Kueue and cert-manager Resources | 2026-06-04 |
| Critical | CVE · KEV | CVE-2019-25738: WordPress Hybrid Composer Unauthenticated Settings Change | 2026-06-04 |
| High | Breach | NYC Health + Hospitals: Third-Party Vendor Breach Exposes 1.8M Patients | 2026-06-04 |
| High | Breach | Iberdrola: Alleged 110 GB Customer Database Sale | 2026-06-04 |
| High | Breach | ISSSTE Mexico: Pension Database Liquidated on Dark Web | 2026-06-04 |
| High | Ransomware | Arlington ISD: Ransomware Attack Delays Summer School | 2026-06-04 |
| High | Ransomware | IQL-Nog: SafePay Ransomware Attack | 2026-06-04 |
| Critical | CVE · KEV | CVE-2019-25729: PDF Signer 3.0 Server-Side Template Injection Leads to Unauthenticated RCE | 2026-06-04 |
| High | Breach | GitHub: Supply Chain Compromise via Poisoned VS Code Extension | 2026-06-04 |
| High | Breach | IEEA Campeche: l1ghtSoulHem Claims Staff and Student Database Leak | 2026-06-04 |
| High | Ransomware | ACE Hospital: KillSec Ransomware Attack | 2026-06-04 |
| High | Breach | National Testing Agency: Superadmin Bypass and JEE Advanced Data Exposure | 2026-06-03 |
| High | Breach | Dutch Hotels: Mass Booking Data Breach Fuels Payment Scams | 2026-06-03 |
| Critical | CVE · KEV | CVE-2026-45247: Mirasvit Cache Warmer PHP Object Injection Hits CISA KEV | 2026-06-03 |
| High | Ransomware | Armenia Ministry of Internal Affairs: WOLVES OF TURAN Ransomware Claim | 2026-06-03 |
| High | Breach | Spectrum: ShinyHunters Voice Phishing Breach | 2026-06-03 |
| High | Breach | IIT Roorkee: Misconfigured Cloud Storage Exposes 1.79 Lakh JEE Advanced Candidates | 2026-06-03 |
| High | Breach | IMA Diligence Services: Genesis Ransomware Breach Exposes 525,306 | 2026-06-03 |
| High | Ransomware | Weil Gotshal & Manges: $20M Ransomware Extortion Payout | 2026-06-03 |
| High | Breach | Safaricom: Insider Data Theft Exposes 11.5 Million Subscribers | 2026-06-03 |
| High | Breach | Wiley Rein: Law Firm Data Breach and Class Action Lawsuit | 2026-06-03 |
| High | Breach | Middle East Organizations: Iran-Linked Wiper Campaign | 2026-06-03 |
| Critical | CVE · KEV | CVE-2026-35075: Hard-Coded Firmware Password Grants Unauthenticated Full Device Access | 2026-06-03 |
| High | Breach | TVING: Unknown Hackers Breach Member Database | 2026-06-03 |
| High | Breach | Tulane University: Clop Ransomware Oracle Zero-Day Breach | 2026-06-03 |
| High | Breach | Red Hat NPM: Supply Chain Worm Attack | 2026-06-02 |
| High | Ransomware | Squamish.net and Synex International: BrainCipher Ransomware Coordinated Strike | 2026-06-02 |
| High | Ransomware | Limburg-Weilburg County Administration: Abyss Ransomware Attack | 2026-06-02 |
| High | Breach | Instagram: Meta AI Prompt Injection Account Hijack | 2026-06-02 |
| Critical | CVE · KEV | CVE-2026-47117: OpenMed Privacy-Filter Loads Attacker-Controlled Models as Code | 2026-06-02 |
| Critical | CVE · KEV | CVE-2026-5076: ARMember Premium WordPress Plugin Stores Plaintext Password Reset Keys | 2026-06-02 |
| High | Breach | Lithuanian Centre of Registers: Suspected Hostile State Credential Abuse | 2026-06-02 |
| High | Breach | Luton and Dunstable Hospital: Supply Chain Ransomware Exposes 33K Patients | 2026-06-02 |
| High | Breach | Middle East Organizations: Iran-Linked MOIS Wiper Campaign | 2026-06-02 |
| High | Breach | St. Joseph County: Handala Hack Claims 2TB Data Breach | 2026-06-02 |
| High | Ransomware | Squamish.net and Synex International: BrainCipher Ransomware Cross-Continental Attack | 2026-06-02 |
| Critical | CVE · KEV | CVE-2022-0492: Linux Kernel cgroups v1 release_agent Privilege Escalation | 2026-06-02 |
| Critical | CVE · KEV | CVE-2025-48595: Android Framework Integer Overflow Enables Local Privilege Escalation | 2026-06-02 |
| High | Ransomware | Eriell: Nova Ransomware Listing | 2026-06-02 |
| Critical | CVE · KEV | CVE-2026-8206: Kirki WordPress Plugin Account Takeover via Password Reset Flaw | 2026-06-02 |
| High | Breach | Dashlane: 2FA Brute-Force Attack Steals Customer Password Vaults | 2026-06-02 |
| High | Ransomware | Buffalo Convention Center: Akira Ransomware Attack | 2026-06-02 |
| High | Breach | HungerRush: SendGrid API Extortion and Supply Chain Poisoning | 2026-06-01 |
| Critical | CVE · KEV | CVE-2026-9319: Critical Deserialization Flaw in IBM WebSphere Application Server | 2026-06-01 |
| Critical | CVE · KEV | CVE-2024-21182: Oracle WebLogic Server Unspecified Vulnerability Added to CISA KEV | 2026-06-01 |
| High | Ransomware | VVO Finance: Everest Ransomware Attack | 2026-06-01 |
| High | Breach | Mexico Ministry of Welfare: BOLA/IDOR Exploit Chain Leaks 1GB of Citizen Data | 2026-06-01 |
| High | Breach | CBSE: Teen Researcher Exposes OSM Portal Vulnerabilities | 2026-06-01 |
| High | Ransomware | Carton Craft Supply: Qilin Ransomware Attack | 2026-06-01 |
| Critical | CVE · KEV | CVE-2026-8644: Critical Identity Spoofing Flaw in IBM WebSphere Application Server | 2026-06-01 |
| High | Ransomware | Instructure Canvas: Shiny Hunters Extortion Settlement | 2026-06-01 |
| High | Breach | Pakistan Higher Education Commission: 1.5 Million Citizen Records Leaked on Cybercrime Forum | 2026-06-01 |
| High | Ransomware | Vodafone: Lapsus$ Ransomware Claim and Source Code Leak | 2026-06-01 |
| Critical | CVE · KEV | CVE-2018-25427: Stack Buffer Overflow in Arm Whois 3.11 Enables Arbitrary Code Execution | 2026-06-01 |
| High | Breach | Mercor: LiteLLM Supply-Chain Compromise | 2026-06-01 |
| Critical | CVE · KEV | CVE-2026-9311: Critical Remote Code Execution in IBM WebSphere Application Server | 2026-06-01 |
| High | Breach | LACMTA: Iranian MOIS-Linked Group Attribution | 2026-05-31 |
| High | Breach | Fortinet: Dark Web Threat Actor Claims Data Breach | 2026-05-31 |
| Critical | CVE · KEV | CVE-2026-10187: Totolink N300RH Stack-Based Buffer Overflow in setWiFiBasicConfig | 2026-05-31 |
| High | Ransomware | Asopagos S.A.: Everest Ransomware Claims Colombian Financial Entity | 2026-05-31 |
| High | Breach | Drift Protocol and KelpDAO: Lazarus Group Crypto Heist | 2026-05-31 |
| High | Breach | Vercel: ShinyHunters Breach Threatens DeFi Frontends | 2026-05-31 |
| High | Breach | Carnival Corporation: Social Engineering Breach Exposes 6M Travelers | 2026-05-31 |
| High | Breach | Industrial Acceptance Corporation: INC Ransomware Breach Exposes 79,216 SSNs | 2026-05-31 |
| High | Breach | iGreen Energy: Mass Data Liquidation via Predictable S3 URLs | 2026-05-31 |
| High | Ransomware | City of Hamilton: Ransomware Attack Cripples Municipal Services | 2026-05-31 |
| High | Ransomware | HDFC AMC: Morpheus Ransomware Breach | 2026-05-31 |
| High | Breach | UK Immigration System: Third-Party Vulnerability Exposes Visa Applicant Data | 2026-05-31 |
| High | Ransomware | Belimed AG: Incransom Ransomware Breach | 2026-05-30 |
| High | Ransomware | AKM Corporation: Everest Ransomware Attack | 2026-05-30 |
| Critical | CVE · KEV | CVE-2018-25412: Delta SQL 1.8.2 Unauthenticated Arbitrary File Upload Leading to RCE | 2026-05-30 |
| High | Breach | Home Depot Canada: Alleged DarkWeb Breach Claim | 2026-05-30 |
| High | Ransomware | Distrigaz Vest: INC Ransom Ransomware Attack | 2026-05-30 |
| High | Breach | ADT Inc.: ShinyHunters Vishing Attack | 2026-05-30 |
| High | Ransomware | LabExpress: incransom Ransomware Breach Exposes 200GB | 2026-05-30 |
| High | Breach | Carnival Corporation: ShinyHunters Vishing Breach | 2026-05-30 |
| High | Ransomware | TransferZ: Everest Ransomware Attack | 2026-05-30 |
| High | Breach | Kemper Corporation: ShinyHunters Salesforce Extortion Breach | 2026-05-29 |
| Critical | CVE · KEV | CVE-2026-10071: Unauthenticated Arbitrary File Upload in Interinfo DreamMaker | 2026-05-29 |
| High | Ransomware | Sandstone, MN: Qilin Ransomware Breach | 2026-05-29 |
| Critical | CVE · KEV | CVE-2026-8732: Unauthenticated Admin Takeover in WP Maps Pro WordPress Plugin | 2026-05-29 |
| High | Ransomware | Open Door Health Center: INC Ransomware Claim | 2026-05-29 |
| High | Breach | BCD Travel: ShinyHunters Alleged Salesforce and SharePoint Breach | 2026-05-29 |
| Critical | CVE · KEV | CVE-2026-0257: Palo Alto Networks PAN-OS GlobalProtect Authentication Bypass | 2026-05-29 |
| High | Ransomware | WG Neukölln eG: DragonForce Ransomware Attack | 2026-05-29 |
| High | Breach | Connecticut Husky Medicaid Portal: Credential Theft and Payment Diversion Attempt | 2026-05-29 |
| High | Ransomware | QLS Group: DragonForce Ransomware Breach | 2026-05-29 |
| High | Breach | Mexican Government: Chronus Group Breach | 2026-05-29 |
| High | Ransomware | EPB Insurance: DragonForce Ransomware Claim | 2026-05-29 |
| High | Breach | Lithuanian Centre of Registers: Hostile State Actors Breach National Data Systems | 2026-05-29 |
| Critical | CVE · KEV | CVE-2026-3655: Authentication Bypass in WordPress OTP Login With Phone Number Plugin | 2026-05-29 |
| Critical | CVE · KEV | CVE-2026-4290: Unauthenticated Arbitrary User Deletion in WP Travel Pro | 2026-05-29 |
| High | Ransomware | Alpha Group Holdings: Qilin Ransomware Leak Site Listing | 2026-05-28 |
| High | Breach | South Korean Electronics Giant: Seedworm APT Espionage Breach | 2026-05-28 |
| Critical | CVE · KEV | CVE-2026-34311: Critical Unauthenticated Takeover in Oracle Hospitality OPERA 5 | 2026-05-28 |
| High | Ransomware | JC Ripberger Construction: DragonForce Ransomware Leak | 2026-05-28 |
| High | Breach | Ajax FC: Unpatched Web Vulnerability Exposes 300,000 Fan Records | 2026-05-28 |
| Critical | CVE · KEV | CVE-2026-46839: Critical Takeover Flaw in Oracle REST Data Services | 2026-05-28 |
| High | Ransomware | Mt. Spokane Pediatrics: LockBit 5.0 Ransomware Attack | 2026-05-28 |
| High | Breach | LACMTA: Iranian State-Sponsored Breach | 2026-05-28 |
| High | Ransomware | Otthon Centrum: Qilin Ransomware Attack | 2026-05-28 |
| High | Ransomware | West Pharmaceutical Services: Ransomware Attack Disrupts Global Operations | 2026-05-28 |
| Critical | CVE · KEV | CVE-2026-46819: Critical Unauthenticated Flaw in Oracle Internet Procurement Connector | 2026-05-28 |
| High | Breach | Florida Physician Specialists: Network Intrusion Exposes 276K Patient Records | 2026-05-28 |
| High | Breach | Ameriprise Financial: ShinyHunters 200GB Salesforce and SharePoint Leak | 2026-05-28 |
| High | Ransomware | US Law Firms: Silent Ransom Group Physical Intrusion Campaign | 2026-05-28 |
| Critical | CVE · KEV | CVE-2026-46822: Critical Oracle iAssets Flaw Enables E-Business Suite Takeover | 2026-05-28 |
| Critical | CVE · KEV | CVE-2026-24444: Hardcoded Password Backdoor in SDMC NE6037 Cable Modem Routers | 2026-05-28 |
| High | Ransomware | Sunrise Company: Akira Ransomware Exfiltration | 2026-05-28 |
| High | Breach | Dataprev: INSS Beneficiary Data Leak | 2026-05-28 |
| Critical | CVE · KEV | CVE-2026-4408: Samba "check password script" Command Injection Enables Unauthenticated RCE | 2026-05-28 |
| Critical | CVE · KEV | CVE-2026-46840: Critical Unauthenticated Takeover in Oracle REST Data Services | 2026-05-28 |
| Critical | CVE · KEV | CVE-2026-46775: Critical Takeover Flaw in Oracle REST Data Services | 2026-05-28 |
| Critical | CVE | CVE-2026-8809: Unauthenticated Admin Takeover in ACF Extended for WordPress | 2026-05-28 |
| Critical | CVE · KEV | CVE-2026-46824: Critical Oracle E-Business Suite Universal Work Queue Takeover | 2026-05-28 |
| High | Breach | Charter Communications: ShinyHunters Vishing SaaS Extortion | 2026-05-28 |
| Critical | CVE · KEV | CVE-2026-46833: Critical Oracle Database Net Service Takeover Flaw | 2026-05-28 |
| High | Breach | Uruguay Antel Identity Service: La Pampa Leaks Data Exfiltration | 2026-05-28 |
| High | Breach | ManageMyHealth: Preventable Breach Exposes 99,416 NZ Patient Records | 2026-05-27 |
| High | Breach | Salesforce Customers: ShinyHunters Extortion Wave | 2026-05-27 |
| Critical | CVE · KEV | CVE-2025-12686: Critical Buffer Overflow in Synology BeeStation Enables Unauthenticated RCE | 2026-05-27 |
| Critical | CVE · KEV | CVE-2026-8175: Critical Buffer Overflow in IBM Aspera High-Speed Transfer | 2026-05-27 |
| High | Ransomware | SPH Value: DragonForce Ransomware Attack | 2026-05-27 |
| High | Ransomware | Enns & Company: DragonForce Ransomware Attack | 2026-05-27 |
| Critical | CVE · KEV | CVE-2026-45321: TanStack npm Supply Chain Compromise via OIDC Token Theft | 2026-05-27 |
| High | Ransomware | Cushman & Wakefield: ShinyHunters and Qilin Dual Ransomware Attack | 2026-05-27 |
| High | Ransomware | MyPillow: Play Ransomware Leak Site Listing | 2026-05-27 |
| Critical | CVE · KEV | CVE-2026-8398: Trojanized DAEMON Tools Lite Installers Distributed via Official Vendor Channel | 2026-05-27 |
| Critical | CVE · KEV | CVE-2026-48027: Malicious Nx Console Extension Pushed to VS Code Marketplace and OpenVSX | 2026-05-27 |
| High | Ransomware | IDS Group: Rhysida Ransomware Attack | 2026-05-27 |
| High | Breach | LACMTA: Iranian State-Linked Hackers Breach Los Angeles Transit | 2026-05-27 |
| High | Ransomware | Covenant Health: Qilin Ransomware Breach | 2026-05-27 |
| Critical | CVE · KEV | CVE-2026-8760: Login with OTP WordPress Plugin Auth Bypass via Brute-Forceable OTP | 2026-05-27 |
| High | Ransomware | Xchange Technology Rentals: DragonForce Ransomware Attack | 2026-05-27 |
| Critical | CVE · KEV | CVE-2026-7524: Critical RCE in IBM Langflow OSS via Symlink Archive Extraction Flaw | 2026-05-27 |
| High | Ransomware | Marks & Spencer: Scattered Spider/DragonForce Ransomware | 2026-05-26 |
| High | Ransomware | BASE SpA: SpaceBears Ransomware Attack | 2026-05-26 |
| High | Ransomware | NL Fisher: Play Ransomware Strikes Dutch Food Producer | 2026-05-26 |
| Critical | CVE · KEV | CVE-2026-48172: LiteSpeed cPanel Plugin Privilege Escalation Exploited in the Wild | 2026-05-26 |
| High | Ransomware | University of Valencia: Nova Ransomware Claim | 2026-05-26 |
| High | Ransomware | ExpoCredit: Qilin Ransomware Claim | 2026-05-26 |
| High | Breach | Station Casinos: External Threat Actor Data Breach | 2026-05-26 |
| Critical | CVE · KEV | CVE-2026-8633: Critical RCE in IBM WebSphere Web Server Plug-ins | 2026-05-26 |
| High | Ransomware | Global Retool Group: Qilin Ransomware Claim | 2026-05-26 |
| Critical | CVE · KEV | CVE-2026-48689: FastNetMon Community Edition Off-by-One Heap Overflow | 2026-05-26 |
| High | Ransomware | JAKN and GGroupCPAs: DragonForce Ransomware Double Listing | 2026-05-26 |
| High | Breach | Heartland Growers and HELIX INTERNATIONAL: DragonForce Ransomware | 2026-05-26 |
| High | Ransomware | Sanatorio Delta: thegentlemen Ransomware Claim | 2026-05-26 |
| High | Breach | OnlyFans: 340M User Records Allegedly for Sale on Leak Forum | 2026-05-26 |
| High | Ransomware | Brazil SECONT: Nova Ransomware Claims Attack on Government Transparency Body | 2026-05-26 |
| High | Breach | Romania EduSal: 331K Education Records Allegedly Leaked by Threat Actor 'somewhere' | 2026-05-26 |
| High | Breach | WisERP: Dark Web Auction of Core ERP Database | 2026-05-26 |
| High | Breach | Russia FSB: Core Intelligence Repository Leaked Across Dark Web | 2026-05-26 |
| High | Ransomware | Saver NV: DragonForce Ransomware Extortion | 2026-05-26 |
| High | Breach | EGADGETS Pakistan: Dark Web Actor Claims 80M Record Telecom Leak | 2026-05-26 |
| Critical | CVE · KEV | CVE-2026-48904: Joomla! Privilege Escalation via com_users Webservice Endpoint | 2026-05-26 |
| Critical | CVE · KEV | CVE-2026-48898: Joomla Privilege Escalation via com_users Batch Task | 2026-05-26 |
| High | Ransomware | BusinessRecord.com: DragonForce Ransomware Attack | 2026-05-26 |
| Critical | CVE · KEV | CVE-2026-7374: KubeVirt virt-handler Symlink Flaw Enables Full Cluster Takeover | 2026-05-26 |
| High | Ransomware | First VPN: Operation Saffron Takedown | 2026-05-26 |
| High | Breach | Lithuania Centre of Registers: Suspected Foreign Intelligence Breach | 2026-05-26 |
| Critical | CVE · KEV | CVE-2026-48899: Joomla Privilege Escalation via com_users | 2026-05-26 |
| High | Ransomware | Le Perreux-sur-Marne: Ransomware Attack Disrupts Municipal Services | 2026-05-26 |
| High | Breach | Radiology Associates of Richmond: 266,000 Patients Exposed in July 2025 Intrusion | 2026-05-26 |
| High | Breach | Carnival Cruise Line: ShinyHunters Data Breach and Notification Failure | 2026-05-26 |
| High | Breach | Portugal SNS: Over 100,000 Patient Records Stolen via Compromised Doctor Credentials | 2026-05-26 |
| High | Breach | Open Source Developers: TrapDoor Supply Chain Attack | 2026-05-26 |
| High | Breach | Nigeria: 80 Million Citizen Records Leaked on Dark Web | 2026-05-26 |
| High | Breach | CERVI: Alleged Breach of South African Digital Health Platform | 2026-05-26 |
| Critical | CVE · KEV | CVE-2026-8855: IBM HTTP Server RCE and DoS via TLS Mutual Authentication | 2026-05-26 |
| High | Ransomware | Openmind Networks: TheGentlemen Ransomware Breach | 2026-05-26 |
| High | Ransomware | The Adviser: Brain Cipher Ransomware Breach | 2026-05-26 |
| High | Breach | PT Bank Negara Indonesia (BNI): TripleX Data Breach | 2026-05-26 |
| Critical | CVE · KEV | CVE-2026-8856: IBM HTTP Server Denial-of-Service via Writable Configuration | 2026-05-26 |
| High | Ransomware | La Familia Adult Day Center: NightSpire Ransomware Breach | 2026-05-26 |
| High | Breach | Philippine Government Agencies: Multi-Agency Repository and Salary Ledger Leak | 2026-05-26 |
| High | Ransomware | Turkey TKGM: APT73/Bashe Ransomware Attack | 2026-05-24 |
| High | Ransomware | Cablematic: Gunra Ransomware Claim | 2026-05-24 |
| High | Breach | Hillpointe: Dark Web Actor Claims 2.5M Record Breach | 2026-05-23 |
| High | Ransomware | Vernon & Ginsburg: Qilin Ransomware Data Extortion | 2026-05-23 |
| High | Ransomware | A-Sonic Logistics: Payload Ransomware Attack | 2026-05-23 |
| High | Breach | Vietnamese Ministerial Agencies: Serious Data Theft Attack Confirmed by VNCERT | 2026-05-23 |
| High | Breach | Connecticut Medicaid (HUSKY): Credential Compromise Exposes 22,500 Enrollees | 2026-05-23 |
| High | Ransomware | University of Mississippi Medical Center: Ransomware Attack and Potential HIPAA Violation | 2026-05-23 |
| High | Ransomware | Semgrep: Qilin Ransomware Attack | 2026-05-23 |
| High | Ransomware | Robinsons Singapore: Alleged Ransomware Attack | 2026-05-23 |
| High | Ransomware | Starbucks: shadowbyt3$ Ransomware Breach | 2026-05-23 |
| High | Breach | Bit2Win: Alleged Source Code Sale on Dark Web | 2026-05-23 |
| High | Breach | Passion for a Purpose: Handala Hack and Leak Operation | 2026-05-23 |
| High | Ransomware | Charter Communications: ShinyHunters Ransomware Attack | 2026-05-23 |
| High | Breach | Education LMS Platform: Ransomware Crew Steals 275M Records | 2026-05-23 |
| High | Breach | Lithuania State Registry: 600,000 Records Exfiltrated in Cross-Border Cyber Intrusion | 2026-05-23 |
| High | Ransomware | Buffalo Niagara Convention Center: Akira Ransomware Attack | 2026-05-23 |
| High | Ransomware | Minsa: APT73/Bashe Ransomware Attack | 2026-05-23 |
| High | Ransomware | Internal Medicine and Pediatrics of Cullman: Payload Ransomware Leak Site Listing | 2026-05-23 |
| High | Breach | Atol Group: Alleged Dark Web Sale of 5.9M Customer Records | 2026-05-23 |
| High | Ransomware | GITIS: Akira Ransomware 30GB Data Extortion | 2026-05-23 |
| High | Ransomware | Karlin Foods: Akira Ransomware Attack | 2026-05-23 |
| High | Ransomware | DentaQuest: ShinyHunters Ransomware Claim | 2026-05-23 |
| High | Breach | Unimed: Billing Provider Breach Cascades Across German University Hospitals | 2026-05-23 |
| High | Breach | Medical Provider: BlackCat Insider Affiliates Sentenced | 2026-05-22 |
| High | Ransomware | Cardinal Services: Rhysida and INC Ransomware Double Breach | 2026-05-22 |
| High | Ransomware | Port of Seattle: Rhysida Ransomware Data Theft | 2026-05-22 |
| High | Breach | Trump Mobile: Customer Data Exposure via Third Party Platform | 2026-05-22 |
| High | Ransomware | Vega Corp: DragonForce Ransomware Attack | 2026-05-22 |
| Critical | CVE · KEV | CVE-2026-9082: Drupal Core SQL Injection Enables Privilege Escalation and RCE | 2026-05-22 |
| High | Breach | German University Hospitals: Third-Party Billing Provider Breach | 2026-05-22 |
| High | Ransomware | Vial Agro: Qilin Ransomware Attack | 2026-05-22 |
| High | Breach | T-Mobile and Sprint: 58 Million Consumer Lines Auctioned on Dark Web | 2026-05-22 |
| High | Breach | NYC Hospital Network: 1.8M Patient Records and Biometric Fingerprints Exfiltrated | 2026-05-22 |
| High | Ransomware | AdvancedHEALTH: DragonForce Ransomware Breach | 2026-05-22 |
| High | Breach | Almerys: 44 Million Healthcare Records Listed on Hacker Forum | 2026-05-22 |
| High | Ransomware | Exchange Group: Pear Ransomware Attack | 2026-05-22 |
| High | Ransomware | Liberty Mutual: Everest Ransomware Breach Exposes 15,000+ Policyholders | 2026-05-22 |
| High | Ransomware | Stuttgart: Rhysida Ransomware Data Theft Claim | 2026-05-22 |
| High | Ransomware | Porter W Yett: Qilin Ransomware Attack | 2026-05-22 |
| High | Ransomware | Beacon Mutual: Ransomware Attack Exposes 132,000 Rhode Islanders | 2026-05-22 |
| Critical | CVE · KEV | CVE-2026-6279: Unauthenticated RCE in Avada Builder for WordPress | 2026-05-21 |
| High | Ransomware | Kabushiki Gaisha Hodozuka Setsubi: Payload Ransomware Attack | 2026-05-21 |
| High | Breach | Perm National Research Polytechnic University: Dark Web Data Leak Exposes 360K+ Records | 2026-05-21 |
| Critical | CVE · KEV | CVE-2026-34926: Trend Micro Apex One On-Premise Directory Traversal Added to CISA KEV | 2026-05-21 |
| Critical | CVE · KEV | CVE-2026-6960: Unauthenticated Arbitrary File Upload in BookingPress Pro for WordPress | 2026-05-21 |
| High | Breach | Erie Family Health Centers: 570,000 Patient Records Exposed in 48-Day Network Intrusion | 2026-05-21 |
| High | Breach | AFC Ajax: Data Breach via Exposed APIs and Shared Keys | 2026-05-21 |
| High | Breach | Uruguay DNIC: Alleged Dark Web Leak of 5.8M Citizen Records | 2026-05-21 |
| Critical | CVE · KEV | CVE-2026-5118: Divi Form Builder WordPress Plugin Privilege Escalation to Admin | 2026-05-21 |
| High | Breach | Global Cardholders: B1ack's Stash Carding Marketplace Dump | 2026-05-21 |
| Critical | CVE · KEV | CVE-2025-34291: Langflow CORS Misconfiguration Enables Account Takeover and RCE | 2026-05-21 |
| High | Breach | Microsoft: Fox Tempest Malware-Signing-as-a-Service Disruption | 2026-05-21 |
| High | Ransomware | Monir Precision Monitoring: Qilin Ransomware Attack | 2026-05-20 |
| Critical | CVE · KEV | CVE-2008-4250: Microsoft Windows Server Service RPC Buffer Overflow Resurfaces on CISA KEV | 2026-05-20 |
| Critical | CVE · KEV | CVE-2026-7637: Unauthenticated PHP Object Injection in WordPress Boost Plugin | 2026-05-20 |
| High | Breach | Unit 221B: ShinyHunters Retaliation Campaign | 2026-05-20 |
| Critical | CVE · KEV | CVE-2009-1537: Microsoft DirectX QuickTime Parser Flaw Added to CISA KEV | 2026-05-20 |
| Critical | CVE · KEV | CVE-2010-0249: Internet Explorer Use-After-Free Resurfaces on CISA KEV | 2026-05-20 |
| High | Breach | Stewarts Care: Third-Party Recruiter Breach Exposes Staff Data | 2026-05-20 |
| Critical | CVE · KEV | CVE-2026-9139: Hard-Coded Credentials in Taiko AG1000-01A SMS Alert Gateway | 2026-05-20 |
| Critical | CVE · KEV | CVE-2026-9141: Authentication Bypass in Taiko AG1000-01A SMS Alert Gateway | 2026-05-20 |
| High | Breach | Nacogdoches Memorial Hospital: 2.5M Patient Records Exfiltrated in Network Intrusion | 2026-05-20 |
| Critical | CVE · KEV | CVE-2009-3459: Adobe Acrobat and Reader Heap-Based Buffer Overflow Resurfaces on CISA KEV | 2026-05-20 |
| High | Ransomware | Extant Aerospace: Ransomware Attack Exposes Employee SSNs at DoD Supplier | 2026-05-20 |
| High | Breach | VUMI: Dark Web Extortion Claim Over 300,000 Records | 2026-05-20 |
| Critical | CVE · KEV | CVE-2026-45498: Microsoft Defender Denial of Service Vulnerability | 2026-05-20 |
| Critical | CVE · KEV | CVE-2026-7284: Easy Elements for Elementor Plugin Allows Unauthenticated Admin Takeover | 2026-05-20 |
| Critical | CVE · KEV | CVE-2026-6555: Unauthenticated RCE in ProSolution WP Client Plugin via Arbitrary File Upload | 2026-05-20 |
| High | Breach | Uruguay DNIC: Alleged 5.8M Citizen Database Leak | 2026-05-20 |
| Critical | CVE · KEV | CVE-2010-0806: Internet Explorer Use-After-Free Resurfaces on CISA KEV | 2026-05-20 |
| High | Breach | GitHub: TeamPCP Internal Repo Breach | 2026-05-20 |
| High | Breach | SA Web Hosts and Telecoms: 'Black Matter' DDoS Extortion Campaign | 2026-05-20 |
| Critical | CVE · KEV | CVE-2026-41091: Microsoft Defender Link Following Flaw Lets Local Attackers Escalate to SYSTEM | 2026-05-20 |
| Critical | CVE · KEV | CVE-2026-20223: Cisco Secure Workload REST API Auth Bypass Grants Site Admin Access | 2026-05-20 |
| Critical | CVE · KEV | CVE-2026-4885: Unauthenticated Arbitrary File Upload in Piotnet Addons for Elementor Pro | 2026-05-19 |
| High | Breach | Arwini Niedersachsen: Kairos Ransomware Data Exfiltration | 2026-05-19 |
| High | Ransomware | Vacu-Lug: Akira Ransomware 40GB Data Heist | 2026-05-19 |
| High | Breach | Safaricom: Kenyan High Court Ruling on Telecom Data Breach | 2026-05-19 |
| Critical | CVE · KEV | CVE-2026-4883: Unauthenticated Arbitrary File Upload in Piotnet Forms WordPress Plugin | 2026-05-19 |
| High | Ransomware | Metaval: INC Ransom Claims 80GB Data Theft | 2026-05-19 |
| High | Breach | Aura: ShinyHunters Vishing Breach | 2026-05-19 |
| High | Breach | US Healthcare Sector: Multiple Breaches Expose Millions via HHS Tracker | 2026-05-19 |
| Critical | CVE · KEV | CVE-2026-43633: Unauthenticated Root RCE in HestiaCP Web Terminal | 2026-05-19 |
| High | Breach | Gîtes de France: Customer Data Theft Exposes 389,000 Records | 2026-05-19 |
| High | Breach | Tabiq: 1M+ Passports Exposed via Public S3 Bucket | 2026-05-19 |
| High | Breach | Enterprise Cloud Tenant: Storm-2949 Identity-Driven Breach | 2026-05-19 |
| High | Breach | Pitney Bowes: ShinyHunters Salesforce Breach | 2026-05-18 |
| High | Breach | Canvas (Instructure): Global LMS Breach Impacting 9,000 Institutions | 2026-05-18 |
| Critical | CVE · KEV | CVE-2026-42822: Critical Authentication Bypass in Azure Local Disconnected Operations | 2026-05-18 |
| High | Breach | US Fuel Infrastructure: Suspected Iranian ATG Intrusions | 2026-05-18 |
| High | Ransomware | Clinica Avellaneda: Qilin Ransomware Attack | 2026-05-18 |
| Critical | CVE · KEV | CVE-2026-45230: Unauthenticated Path Traversal in DumbAssets Enables Arbitrary File Deletion | 2026-05-18 |
| High | Ransomware | URG OEM: Nova Ransomware Attack | 2026-05-18 |
| High | Breach | 7-Eleven: ShinyHunters Salesforce Breach | 2026-05-18 |
| High | Ransomware | Instructure: ShinyHunters Canvas Extortion | 2026-05-18 |
| High | Breach | CISA: Contractor Leaks AWS GovCloud Keys on Public GitHub | 2026-05-18 |
| High | Breach | NYC Health + Hospitals: 1.8M Patient Records Stolen in Breach | 2026-05-18 |
| High | Ransomware | WTI Transport: Chaos Ransomware 72-Hour Ultimatum | 2026-05-18 |
| High | Breach | Samuel Shay: Handala Claims Breach of Israeli Normalization Architect | 2026-05-18 |
| High | Breach | TransUnion: Consumer Data Breach Exposes 4.4 Million Records | 2026-05-18 |
| High | Breach | Oracle: 2026 Multi-System Cloud and Health Data Breach | 2026-05-18 |
| High | Breach | Belambra: Tourism Sector Data Breach Wave | 2026-05-18 |
| Critical | CVE · KEV | CVE-2026-8836: Critical Stack Buffer Overflow in lwIP SNMPv3 USM Handler | 2026-05-18 |
| High | Breach | Irish Revenue Commissioners: 137 Staff Exposed in Pitney Bowes Ransomware Breach | 2026-05-18 |
| High | Breach | Tokee: 1.2M User Profiles Exposed via Unsecured MongoDB | 2026-05-18 |
| High | Breach | Samuel Shay: Handala Claims Breach of Israeli Normalization Architect | 2026-05-18 |
| Critical | CVE · KEV | CVE-2024-3400: Critical Command Injection in Palo Alto Networks PAN-OS GlobalProtect | 2026-05-17 |
| Critical | CVE · KEV | CVE-2026-20133: Cisco Catalyst SD-WAN Manager Leaks Sensitive Information to Remote Attackers | 2026-05-17 |
| Critical | CVE · KEV | CVE-2025-48700: Zimbra Classic UI XSS Exploited in the Wild | 2026-05-17 |
| Critical | CVE · KEV | CVE-2024-1708: ConnectWise ScreenConnect Path Traversal Enables Remote Code Execution | 2026-05-17 |
| Critical | CVE · KEV | CVE-2026-35616: Critical Unauthenticated RCE in Fortinet FortiClient EMS | 2026-05-17 |
| High | Breach | American Lending Center: 123,000 Individuals Exposed in Network Intrusion | 2026-05-17 |
| High | Ransomware | Grafana Labs: Source Code Theft and Ransom Refusal | 2026-05-17 |
| Critical | CVE · KEV | CVE-2026-0300: Critical PAN-OS Captive Portal RCE Under Active Exploitation | 2026-05-17 |
| Critical | CVE · KEV | CVE-2026-21385: Qualcomm Chipset Memory Corruption Flaw Added to CISA KEV | 2026-05-17 |
| Critical | CVE · KEV | CVE-2024-57726: SimpleHelp Privilege Escalation Flaw Hits CISA KEV with Known Ransomware Use | 2026-05-17 |
| Critical | CVE · KEV | CVE-2026-6973: Authenticated RCE in Ivanti Endpoint Manager Mobile | 2026-05-17 |
| High | Breach | African National Congress: Black Axe Data Breach | 2026-05-17 |
| Critical | CVE · KEV | CVE-2023-21529: Microsoft Exchange Server Deserialization Flaw Exploited in Medusa Ransomware Campaigns | 2026-05-17 |
| Critical | CVE · KEV | CVE-2026-24512: ingress-nginx Path Injection Enables Cluster-Wide Secret Disclosure and RCE | 2026-05-17 |
| Critical | CVE · KEV | CVE-2026-20122: Cisco Catalyst SD-WAN Manager Privileged API Abuse Lets Read-Only Users Escalate to vManage | 2026-05-17 |
| Critical | CVE · KEV | CVE-2026-41940: cPanel & WHM Authentication Bypass Under Active Ransomware Exploitation | 2026-05-17 |
| Critical | CVE · KEV | CVE-2020-9715: Adobe Acrobat Use-After-Free Enables Code Execution | 2026-05-17 |
| Critical | CVE · KEV | CVE-2024-27199: JetBrains TeamCity Path Traversal Enables Limited Admin Actions | 2026-05-17 |
| Critical | CVE · KEV | CVE-2009-0238: Microsoft Excel Invalid Object Access Enables Remote Code Execution | 2026-05-17 |
| Critical | CVE · KEV | CVE-2026-34621: Adobe Acrobat and Reader Prototype Pollution Enables Arbitrary Code Execution | 2026-05-17 |
| High | Breach | Moroccan Government Platforms: Fexus Claims Massive govma Breach | 2026-05-17 |
| Critical | CVE · KEV | CVE-2012-1854: Microsoft VBA Insecure Library Loading Resurfaces on CISA KEV | 2026-05-17 |
| Critical | CVE · KEV | CVE-2026-3502: TrueConf Client Update Mechanism Lacks Integrity Verification | 2026-05-17 |
| Critical | CVE · KEV | CVE-2026-20128: Cisco Catalyst SD-WAN Manager Stores DCA Credentials in Recoverable Format | 2026-05-17 |
| Critical | CVE · KEV | CVE-2026-39987: Pre-Auth RCE in Marimo Python Notebook | 2026-05-17 |
| Critical | CVE · KEV | CVE-2026-21643: Critical SQL Injection in Fortinet FortiClient EMS | 2026-05-17 |
| Critical | CVE · KEV | CVE-2026-5281: Use-After-Free in Chrome's Dawn Graphics Layer Hits CISA KEV | 2026-05-17 |
| Critical | CVE · KEV | CVE-2026-42208: Unauthenticated SQL Injection in BerriAI LiteLLM Proxy | 2026-05-17 |
| Critical | CVE · KEV | CVE-2026-20182: Cisco Catalyst SD-WAN Authentication Bypass Hands Attackers Admin Control | 2026-05-17 |
| Critical | CVE · KEV | CVE-2025-29635: D-Link DIR-823X Command Injection Added to CISA KEV | 2026-05-17 |
| High | Breach | Senegal Public Treasury: Cyberattack and Data Extortion Threat | 2026-05-17 |
| Critical | CVE · KEV | CVE-2026-31431: Linux Kernel algif_aead Flaw Enables Local Privilege Escalation | 2026-05-17 |
| Critical | CVE · KEV | CVE-2024-57728: SimpleHelp Zip Slip Path Traversal Enables Remote Code Execution | 2026-05-17 |
| Critical | CVE · KEV | CVE-2026-32202: Windows Shell Spoofing Flaw Added to CISA KEV | 2026-05-17 |
| Critical | CVE · KEV | CVE-2023-27351: PaperCut NG/MF Authentication Bypass Added to CISA KEV | 2026-05-17 |
| Critical | CVE · KEV | CVE-2024-7399: Samsung MagicINFO 9 Server Path Traversal Enables Arbitrary File Write as SYSTEM | 2026-05-17 |
| Critical | CVE · KEV | CVE-2026-34197: Apache ActiveMQ Jolokia Code Injection Lands on CISA KEV | 2026-05-17 |
| Critical | CVE · KEV | CVE-2026-1340: Critical Code Injection in Ivanti Endpoint Manager Mobile | 2026-05-17 |
| High | Ransomware | United Quality Cooperative: INC Ransom Ransomware Attack | 2026-05-17 |
| Critical | CVE · KEV | CVE-2026-33825: Microsoft Defender Local Privilege Escalation Added to CISA KEV | 2026-05-17 |
| Critical | CVE · KEV | CVE-2026-32201: SharePoint Server Spoofing Flaw Added to CISA KEV | 2026-05-17 |
| Critical | CVE · KEV | CVE-2023-36424: Windows CLFS Driver Elevation of Privilege Flaw Added to CISA KEV | 2026-05-17 |
| Critical | CVE · KEV | CVE-2025-32975: Quest KACE SMA Authentication Bypass Enables Full Admin Takeover | 2026-05-17 |
| Critical | CVE · KEV | CVE-2025-60710: Windows Host Process Link-Following Flaw Exploited in the Wild | 2026-05-17 |
| Critical | CVE · KEV | CVE-2025-2749: Authenticated Path Traversal to RCE in Kentico Xperience | 2026-05-17 |
| Critical | CVE · KEV | CVE-2026-42897: Microsoft Exchange Server XSS Flaw Added to CISA KEV | 2026-05-17 |
| High | Breach | Samuel Shay: Handala Hackers Claim Breach of Abraham Accords Architect | 2026-05-17 |
| Critical | CVE · KEV | CVE-2026-22719: Unauthenticated Command Injection in VMware Aria Operations | 2026-05-17 |
| High | Breach | Bono Juana Azurduy (Bolivia): Public Sector Data Leak by konata_izumi_shell | 2026-05-16 |
| High | Breach | Florida Reliability Coordinating Council: Unauthorized File Copying Exposes SSNs | 2026-05-16 |
| High | Breach | France Titres: Massive State ID Database Breach | 2026-05-16 |
| High | Breach | Aintree Hospital: Insider Snooping on Southport Attack Victims | 2026-05-16 |
| High | Breach | Qantas: Third-Party Contact Centre Platform Breach | 2026-05-16 |
| High | Breach | NHS Aintree Hospital: Insider Snooping on Southport Attack Victims | 2026-05-16 |
| High | Breach | US Tiger Securities: Ransomware Breach Exposes SSNs and Medical Data | 2026-05-16 |
| High | Breach | US Gas Stations: Suspected Iranian Intrusion Into Fuel Tank Readers | 2026-05-16 |
| High | Ransomware | Spirit Medical Transport: Qilin Ransomware Attack | 2026-05-16 |
| High | Breach | Opexus: Insider Revenge Attack by Akhter Twins | 2026-05-16 |
| High | Breach | Pierre et Vacances-Center Parcs: Platform Vulnerability Exploited | 2026-05-16 |
| High | Breach | Comcast: $117M Settlement Over Confirmed Customer Data Breach | 2026-05-16 |
| High | Ransomware | York City, PA: July 2025 Ransomware Attack | 2026-05-15 |
| High | Breach | British Airways: Infrastructure Destruction Squad Claims Breach | 2026-05-15 |
| High | Breach | OpenLoop Health: Telehealth Breach Exposes 716,000 Patients | 2026-05-15 |
| High | Breach | OpenAI: Mini Shai-Hulud npm Supply Chain Worm | 2026-05-15 |
| High | Breach | Mistral AI: TeamPCP Supply Chain Breach | 2026-05-15 |
| High | Breach | Abrigo: ShinyHunters Pay or Leak Extortion | 2026-05-15 |
| High | Breach | Excelas: Cl0p Ransomware Breach Exposes Medical Records | 2026-05-15 |
| High | Ransomware | Bluize: Qilin Ransomware Claim | 2026-05-15 |
| High | Breach | Rockstar Games: ShinyHunters Snowflake Token Abuse | 2026-05-14 |
| High | Ransomware | Ahmed Al-Kadi Private Hospital: Ransomware Breach Encrypts Portions of IT Environment | 2026-05-13 |
| High | Ransomware | Earth Systems: INC Ransom Claims 600GB Breach | 2026-05-13 |
| High | Breach | PACI Kuwait: Alleged State Level Infrastructure Breach | 2026-05-13 |
| High | Breach | Thales Group: Alleged Data Leak Tied to LuxTrust Identity Infrastructure | 2026-05-13 |
| High | Breach | Chevin Fleet Solutions: FleetWave SaaS Breach Exposes Customer Data | 2026-05-13 |
| High | Breach | Lockheed Martin: APT Iran Data Exfiltration | 2026-05-13 |
| High | Ransomware | West Pharmaceutical Services: Ransomware Attack Disrupts Global Manufacturing | 2026-05-13 |
| High | Breach | Checkmarx: TeamPCP Jenkins Plugin Supply Chain Attack | 2026-05-12 |
| High | Ransomware | Foxconn: Nitrogen Ransomware 8TB Data Theft | 2026-05-12 |
| High | Breach | Enterprise Cloud Environments: FulcrumSec Extortion Campaign | 2026-05-12 |
| High | Breach | Hong Kong Canvas Users: ShinyHunters Data Breach | 2026-05-12 |
| High | Breach | Canvas LMS: ShinyHunters Global Breach | 2026-05-11 |
| High | Ransomware | Unoaerre: Ransomware Attack Halts Italian Jewelry Manufacturing | 2026-05-11 |
| High | Breach | Egypt Ministry of Civil Aviation: Alleged Dark Web Breach | 2026-05-11 |
| High | Breach | Indian Customs Department: Insider Data Theft to China-Based Firms | 2026-05-11 |
| High | Breach | Aerospace and Drone Operators: HeartlessSoul Espionage Campaign | 2026-05-11 |
| High | Breach | Medtronic: ShinyHunters Steals 9 Million Records | 2026-05-11 |
| High | Ransomware | VP Brands International: LockBit 5.0 Ransomware Breach | 2026-05-11 |
| High | Breach | SFR: Alleged Dark Web Data Breach Claim | 2026-05-11 |
| High | Ransomware | AMS Group: Stormous Ransomware 33GB Data Dump | 2026-05-11 |
| High | Breach | Vodafone: Lapsus$ Source Code Leak | 2026-05-11 |
| High | Breach | Maryland University: Exfil-Ware Ransomware Breach | 2026-05-11 |
| High | Ransomware | TDS Telecommunications: TheGentlemen Ransomware Attack | 2026-05-11 |
| High | Breach | Coupang Taiwan: 33.7 Million Account Data Breach | 2026-05-10 |
| High | Ransomware | Minidoka Memorial Hospital: Blackwater Ransomware Attack | 2026-05-10 |
| High | Ransomware | Serveis Mèdics Penedès: SafePay Ransomware 48-Hour Extortion | 2026-05-10 |
| High | Breach | Canada Goose: ShinyHunters Historical Data Leak | 2026-05-09 |
| High | Breach | Zara: ShinyHunters Third-Party Breach | 2026-05-09 |
| High | Ransomware | US Healthcare and Middle East Org: Lazarus Group Medusa Ransomware | 2026-05-09 |
| High | Breach | US Federal Agencies: Insider Threat Database Destruction | 2026-05-09 |
| High | Breach | CarGurus: ShinyHunters Voice Phishing Breach | 2026-05-09 |
| High | Breach | US Federal Agencies: Insider Threat Database Destruction | 2026-05-09 |
| High | Breach | Mexican Water Utility: Claude AI Abused in OT Compromise Attempt | 2026-05-09 |
| High | Breach | US Federal Agencies: Insider Database Destruction by Terminated Contractors | 2026-05-09 |
| High | Ransomware | Nostrum Corporation: The Gentlemen Ransomware Attack | 2026-05-08 |
| High | Breach | Government Agencies: UAT-8302 China-Linked Espionage Campaign | 2026-05-08 |
| High | Breach | Canadian Government: $8.7M Settlement Over 2020 CRA Account Breach | 2026-05-08 |
| High | Ransomware | University of Pennsylvania: ShinyHunters Canvas Ransom Attack | 2026-05-08 |
| High | Breach | ANTS (France Titres): Teen Hacker Breaches National ID Agency | 2026-05-08 |
| High | Breach | Flemish Universities and VUB: ShinyHunters Canvas Breach | 2026-05-08 |
| High | Ransomware | Change Healthcare: BlackCat Ransomware Attack | 2026-05-08 |
| High | Ransomware | Liberty Mutual: Everest Ransomware Leak | 2026-05-07 |
| High | Breach | Finland's Valtori: Suspected State Espionage Breach | 2026-05-07 |
| High | Ransomware | Expeditor Systems: Incransom Ransomware Attack | 2026-05-07 |
| High | Breach | Vercel: ShinyHunters OAuth Token Supply Chain Attack | 2026-05-07 |
| High | Ransomware | TTT Corporation: Stormous Ransomware 5TB Data Theft | 2026-05-07 |
| High | Breach | Woflow: ShinyHunters Leak Exposes 447,600 Accounts | 2026-05-07 |
| High | Ransomware | Energy Action: SafePay Ransomware Breach | 2026-05-07 |
| High | Ransomware | Sandhills Medical Foundation: Ransomware Attack | 2026-05-07 |
| High | Breach | Oman Government Ministries: Iranian-Nexus Webshell Intrusion | 2026-05-06 |
| High | Breach | INSS: Handala Multi-Year Breach | 2026-05-06 |
| High | Breach | DigiCert: Screensaver Phish Yields EV Code Signing Certificates | 2026-05-06 |
| High | Breach | Sterling Bank: ByteToBreach Data Breach | 2026-05-06 |
| High | Ransomware | Russian Government: Karakurt Ransomware Gang Insider Access | 2026-05-06 |
| High | Breach | City of Suffolk, Virginia: Cloak Ransomware Data Breach | 2026-05-05 |
| High | Ransomware | Ardmore Police Department: Phishing-Triggered Ransomware Attack | 2026-05-05 |
| High | Breach | Rhode Island RIBridges: Brain Cipher Ransomware Settlement | 2026-05-05 |
| High | Ransomware | Mediaworks: World Leaks Ransomware Breach | 2026-05-05 |
| High | Ransomware | Frost Bank: Everest Ransomware Vendor Breach | 2026-05-05 |
| High | Breach | Canvas LMS: ShinyHunters Claims 3.65TB Breach Affecting 275M Users | 2026-05-04 |
| High | Breach | TriZetto Provider Solutions: Web Portal Breach Exposes 3.4M Patients | 2026-05-04 |
| High | Breach | Conduent Business Services: Ransomware Breach of 25M Americans | 2026-05-04 |
| High | Breach | Lotte Card: 2.97M Customer Data Breach | 2026-05-04 |
| High | Breach | Prime Properties: M3rx Ransomware Darknet Leak | 2026-05-04 |
| High | Breach | NVIDIA GeForce NOW: ShinyHunters Claims Millions of User Records Stolen | 2026-05-04 |
| High | Breach | Capita: Civil Service Pension Data Exposure | 2026-05-04 |
| High | Breach | Capital One: $425M Settlement Approved for 2019 Cloud Breach | 2026-05-04 |
| High | Ransomware | Cushman & Wakefield: ShinyHunters Ransomware Attack | 2026-05-04 |
| High | Breach | Alberta Residents: Centurion Project Data Exposure | 2026-05-04 |
| High | Breach | Sistemi Informativi: Salt Typhoon Espionage Breach | 2026-05-04 |
| High | Breach | MoneyForward: GitHub Credential Compromise | 2026-05-04 |
| High | Breach | US Navy: Handala Claims Personnel Data Breach | 2026-05-03 |
| High | Breach | European Commission: ShinyHunters Cloud Data Breach | 2026-05-03 |
| High | Breach | ANTS (France Titres): Teen Hacker Breaches National ID Agency | 2026-05-03 |
| High | Breach | Nepal Public Procurement System: Insider Bid-Rigging Hack Ring | 2026-05-03 |
| High | Breach | Trellix: Source Code Repository Breach | 2026-05-03 |
| High | Ransomware | Wyoming County Government: ThreeAM Ransomware Attack | 2026-05-03 |
| High | Ransomware | Orange: Babuk Ransomware Breach Claim | 2026-05-03 |
| Critical | CVE | cPanel Servers: Sorry Ransomware Mass Exploitation | 2026-05-03 |
| High | Breach | Instructure: Canvas LMS Maker Discloses Cyber Incident | 2026-05-03 |
| High | Breach | Pakistan Government and Military: Alleged 39GB Dark Web Leak | 2026-05-02 |
| High | Breach | McGraw-Hill: ShinyHunters Salesforce Breach | 2026-05-02 |
| High | Ransomware | Follett Software LLC: ShinyHunters Ransomware Leak Listing | 2026-05-02 |
| High | Breach | MST (Sanko Makina/ASKO Holding): Blacknevas 7-Month Cyber Siege | 2026-05-02 |
| High | Breach | Aman: ShinyHunters Pay or Leak Extortion | 2026-05-02 |
| High | Breach | Checkmarx KICS: Supply Chain Compromise via Trojanized Docker and IDE Extensions | 2026-05-02 |
| High | Breach | France Titres (ANTS): Teen Hacker Breaches State ID Agency | 2026-05-02 |
| High | Breach | Moldova CNAM: Mysterious Healthcare Database Breach | 2026-05-02 |
| High | Breach | Canonical: 313 Team DDoS and Extortion | 2026-05-02 |
| High | Breach | ZenBusiness: ShinyHunters Extortion Breach | 2026-05-02 |
| High | Ransomware | Adams County, PA: Ransomware Attack Disrupts County Services | 2026-05-02 |
| High | Breach | ChipSoft: Embargo Ransomware Breach | 2026-05-02 |
| High | Ransomware | KINAS Solicitors: BlackNevas Ransomware Breach | 2026-05-02 |
| High | Breach | PowerSchool: Teen Hacker Credential Theft Breach | 2026-05-02 |
| High | Breach | Medicare: Doctor Data Breach | 2026-05-02 |
| High | Breach | Canada Life: ShinyHunters Breach via Compromised Employee Account | 2026-05-02 |
| High | Ransomware | Integer Holdings: coinbasecartel Ransomware Breach | 2026-05-01 |
| High | Ransomware | Gregory Jewellers: Kairos Ransomware Breach | 2026-05-01 |
| High | Ransomware | Sandhills Medical Foundation: Inc Ransom Ransomware Breach | 2026-05-01 |
| High | Breach | Canadian Tire: 38.3 Million Customer Accounts Exposed in E-commerce Database Breach | 2026-05-01 |
| High | Ransomware | Prime Properties: M3rx Ransomware Breach | 2026-05-01 |
| High | Breach | SMSA Express: 1.2M Customer Shipment Records Listed for Sale by lulzintel | 2026-05-01 |
| High | Breach | Polymarket: xorcat Data Breach | 2026-04-30 |
| High | Breach | SAP: Mini Shai-Hulud npm Supply Chain Attack | 2026-04-30 |
| High | Breach | Cuban Embassy DC: Chinese State-Linked Espionage Breach | 2026-04-30 |
| High | Ransomware | Winona County, Minnesota: Ransomware Data Leak After Refusal to Pay | 2026-04-30 |
| High | Breach | Scattered Spider: Federal Charges Filed Against Teen Member Arrested in Finland | 2026-04-30 |
| High | Breach | Lower Hutt City Council: Phishing Compromise Exposes Resident Data | 2026-04-30 |
| High | Breach | Foreign Governments and Activists: I-Soon Contractor Leak | 2026-04-30 |
| High | Ransomware | Illinois and Texas Healthcare Providers: Insomnia Ransomware Breach | 2026-04-30 |
| High | Ransomware | UPSRTC: Third-Party Ransomware Attack Cripples Electronic Ticketing System | 2026-04-30 |
| High | Ransomware | City of Ardmore, Oklahoma: Ransomware Attack Exposes Resident Data | 2026-04-29 |
| High | Ransomware | STELIA Aerospace: Rhysida Ransomware Hits North American Systems | 2026-04-29 |
| High | Ransomware | Sumac Inc.: Incransom Ransomware Attack | 2026-04-29 |
| High | Breach | Vimeo: ShinyHunters Exfiltration via Anodot Supply Chain Breach | 2026-04-29 |
| High | Breach | US DOJ: Silk Typhoon MSS Contractor Extradited | 2026-04-28 |
| High | Ransomware | Synmosa Biopharma: DragonForce Ransomware Breach | 2026-04-28 |
| High | Breach | U.S. Justice System: Chinese State Hacker Xu Zewei Extradited | 2026-04-28 |
| High | Ransomware | Wm. Sopko & Sons Co.: DragonForce Ransomware Attack | 2026-04-28 |
| High | Breach | Pitney Bowes: ShinyHunters Extortion Leak | 2026-04-28 |
| High | Ransomware | Selex Gruppo Commerciale: INC Ransom Ransomware Breach | 2026-04-28 |
| High | Breach | Silk Typhoon: Alleged MSS Contract Hacker Extradited to US | 2026-04-28 |
| High | Breach | Fidelity: $1.25M Massachusetts Fine Over Customer Data Breach | 2026-04-28 |
| High | Breach | Pine Bluff School District: Business Email Compromise Wire Fraud | 2026-04-28 |
| High | Ransomware | Gelatissimo: DragonForce Ransomware Data Theft | 2026-04-28 |
| High | Breach | Lee & Lee Country Club: Suspected North Korean State-Sponsored Breach | 2026-04-27 |
| High | Ransomware | 100+ Global Enterprises: Coinbase Cartel Infostealer Extortion Spree | 2026-04-27 |
| High | Breach | U.S. Universities: Hafnium MSS Operative Extradited | 2026-04-27 |
| High | Breach | Generation Life: Third-Party Vendor Compromise | 2026-04-27 |
| High | Ransomware | Heinrichs Logistic: LockBit 5 Ransomware Listing | 2026-04-27 |
| High | Breach | Itron: Internal Network Breach Disclosed in SEC 8-K Filing | 2026-04-27 |
| High | Breach | Vodafone UK: LAPSUS$ Claims Internal Network Breach | 2026-04-27 |
| High | Breach | Marcus & Millichap: ShinyHunters Salesforce Extortion | 2026-04-27 |
| High | Ransomware | BELFOR Asia: INC Ransom Ransomware Listing | 2026-04-27 |
| High | Ransomware | Merlo.de: LockBit5 Ransomware Listing | 2026-04-26 |
| High | Breach | Medtronic: IT Systems Cybersecurity Breach Disclosed | 2026-04-26 |
| High | Ransomware | TruGreen: Incransom Ransomware Double Extortion | 2026-04-26 |
| High | Breach | Southern Illinois Dermatology: Hacking Incident Exposes 160,312 Patients | 2026-04-26 |
| High | Breach | Transport Workers Union Local 100: Confirmed Data Breach Affecting Up to 100,000 Records | 2026-04-26 |
| High | Ransomware | Buckley Powder and Leistritz Turbine Technology: Qilin Ransomware Double Extortion | 2026-04-26 |
| High | Breach | BePrime: Admin Account Compromise via Missing MFA | 2026-04-26 |
| High | Breach | Retail and Hospitality: BlackFile Extortion Campaign | 2026-04-26 |
| High | Ransomware | NPK Fertilizer Sdn Bhd: Lamashtu Ransomware Attack | 2026-04-25 |
| High | Breach | Sagent Pharmaceuticals: Worldleaks Network Intrusion Exposes SSNs | 2026-04-25 |
| High | Breach | LACOE: Tax Portal Breach and Employee Identity Theft | 2026-04-25 |
| High | Ransomware | Five U.S. Victim Organizations: Insider Leak to BlackCat/ALPHV Ransomware | 2026-04-25 |
| High | Breach | ADT: ShinyHunters Vishing Breach | 2026-04-25 |
| High | Ransomware | AT&T Careers: Everest Ransomware Leak | 2026-04-25 |
| High | Ransomware | Progressive Propane: Qilin Ransomware Claims US Energy Sector Attack | 2026-04-25 |
| High | Breach | Ransomware Victims: Insider Betrayal by BlackCat Negotiator | 2026-04-25 |
| High | Ransomware | Studio Più: LockBit 5.0 Ransomware Attack | 2026-04-25 |
| High | Breach | Bitwarden CLI: Shai-Hulud Supply Chain Worm | 2026-04-25 |
| High | Breach | Harrison County, WV: Courthouse and Sheriff's Tax Office Cyber Incident | 2026-04-25 |
| High | Breach | Rich Products: Third-Party Phishing Breach via First Advantage | 2026-04-24 |
| High | Ransomware | Teamsters Local 773: Incransom Ransomware Attack | 2026-04-24 |
| High | Ransomware | Aptim: Coinbase Cartel Ransomware Attack | 2026-04-24 |
| High | Breach | Ameriprise Financial: Unauthorized Third-Party Data Access | 2026-04-24 |
| High | Ransomware | OrthopedicsNY: INC Ransom Attack Triggers $1.95M Penalty | 2026-04-24 |
| High | Breach | Udemy: ShinyHunters Claims 1.4M Record Breach | 2026-04-24 |
| High | Breach | Universal Pure: Six Week Network Intrusion Exposes SSNs and Medical Data | 2026-04-24 |
| High | Breach | French Institutions: HexDex Data Leak Campaign | 2026-04-24 |
| High | Ransomware | Manulife Wealth: Qilin Ransomware Claim | 2026-04-24 |
| High | Breach | French Government Agency: 19 Million Records Allegedly Stolen in Data Breach | 2026-04-24 |
| High | Breach | FOSPIBAY: SQL Injection Breach Exposes Peruvian Citizen Records | 2026-04-24 |
| High | Breach | Sri Lanka Finance Ministry: $3.7M Stolen in Payment Diversion Attack | 2026-04-24 |
| High | Breach | Carnival: ShinyHunters Breach Exposes 7.5M Loyalty Accounts | 2026-04-24 |
| High | Breach | ANTS France: 19 Million Records Allegedly Stolen in Confirmed Breach | 2026-04-24 |
| High | Breach | Epe Municipality: Resident Data Theft from Council Server | 2026-04-24 |
| High | Ransomware | Genealogy SA: SafePay Ransomware Data Theft | 2026-04-23 |
| High | Ransomware | Rusk County, Wisconsin: Qilin Ransomware Claim | 2026-04-23 |
| High | Breach | French Ministries: Hexdex Data Leaks | 2026-04-23 |
| High | Breach | Ransomware Victims: Insider Betrayal by BlackCat Negotiator | 2026-04-23 |
| High | Ransomware | Samuel I. White, PC: Anubis Ransomware Attack | 2026-04-23 |
| High | Breach | Favelle Favco: SafePay Ransomware Data Leak | 2026-04-23 |
| High | Breach | DigitalMint: ALPHV/BlackCat Insider Collusion | 2026-04-23 |
| High | Breach | Rituals: Customer Membership Database Breach | 2026-04-23 |
| High | Breach | UK Biobank: Researcher Insider Leak to Alibaba Marketplace | 2026-04-23 |
| High | Ransomware | Hospital Caribbean Medical Center: The Gentlemen Ransomware Attack | 2026-04-23 |
| High | Ransomware | Rheem Manufacturing: INC Ransom Ransomware Leak | 2026-04-22 |
| High | Breach | Valtori: Suspected State Espionage Breach | 2026-04-22 |
| High | Ransomware | Sprendlingen-Gensingen: Ransomware Attack Paralyzes Municipal Administration | 2026-04-22 |
| High | Ransomware | STERIMED: Qilin Ransomware Leak Site Listing | 2026-04-22 |
| High | Ransomware | Uniview Technologies: The Gentlemen Ransomware Listing | 2026-04-22 |
| High | Breach | Anthropic: Mythos AI Model Breached via Third-Party Vendor | 2026-04-22 |
| High | Ransomware | Nordenta: Kairos Ransomware Cartel Targets Danish Dental Supplier | 2026-04-22 |
| High | Breach | Bol: 400K Belgian Customer Records Allegedly Leaked | 2026-04-22 |
| High | Breach | US Federal Networks: Credential Abuse by Instagram Braggart | 2026-04-22 |
| High | Ransomware | Yamachi Electronics Philippines: INC Ransom Attack | 2026-04-22 |
| High | Breach | NSW Government: Insider Threat Data Breach | 2026-04-22 |
| High | Breach | Piazza San Marco: Infrastructure Destruction Squad Breaches Venice Flood Defenses | 2026-04-22 |
| High | Ransomware | Adaptavist Group: The Gentlemen Ransomware Breach | 2026-04-21 |
| High | Ransomware | ViaQuest: Anubis Ransomware Breach | 2026-04-21 |
| High | Ransomware | Engie: coinbasecartel Ransomware Attack | 2026-04-21 |
| High | Ransomware | Minidoka Memorial Hospital: Blackwater Ransomware Attack | 2026-04-21 |
| High | Ransomware | Champion Homes: DragonForce Ransomware Leak Site Listing | 2026-04-21 |
| High | Breach | NSW Treasury: Insider Threat Data Exfiltration | 2026-04-21 |
| High | Ransomware | NutraBio: Everest Ransomware Claim | 2026-04-21 |
| High | Breach | Nexus Grid: Cobalt Veil IoT Supply Chain Breach | 2026-04-21 |
| High | Breach | Qantas: 6 Million Customer Accounts Exposed in Third-Party Call Centre Breach | 2026-04-20 |
| High | Ransomware | Strata Republic: Kairos Ransomware Breach | 2026-04-20 |
| High | Breach | Metro Pakistan: Alleged Breach by Threat Actor xklahadore | 2026-04-20 |
| High | Ransomware | Complete Aircraft Group: Everest Ransomware Claim | 2026-04-20 |
| High | Breach | Champhunt: Cricket Fan Platform Breached, 224K User Records for Sale | 2026-04-20 |
| High | Ransomware | Canada Life Assurance: ShinyHunters Ransomware Breach | 2026-04-20 |
| High | Ransomware | Citizens Bank: Everest Ransomware Listing | 2026-04-20 |
| High | Ransomware | Aman Resorts: ShinyHunters Ransomware Attack | 2026-04-20 |
| High | Breach | Cylance: 34M Record Database Offered for Sale on Dark Web | 2026-04-20 |
| High | Breach | Seiko USA: Website Defacement and Shopify Data Extortion | 2026-04-20 |
| High | Breach | IDMerit: Unsecured MongoDB Exposes 1 Billion Identity Records | 2026-04-20 |
| High | Breach | Polmed: ShinyHunters Ransomware Breach | 2026-04-20 |
| High | Breach | ANTS (ants.gouv.fr): IDOR Flaw Exposes 19M French Identity Records | 2026-04-20 |
| High | Ransomware | 7-Eleven: ShinyHunters Claims Salesforce Breach | 2026-04-20 |
| High | Breach | LAUSD & Edgenuity: 4M Student Records Listed for Sale via Snowflake Breach | 2026-04-20 |
| High | Ransomware | Securitevolfeu: CoinbaseCartel Ransomware Listing | 2026-04-19 |
| High | Breach | DarkForums: PwnForums Database Leak Exposes 44K Cybercriminal IPs | 2026-04-19 |
| High | Ransomware | Millennium Dental Technologies: Termite Ransomware Attack | 2026-04-19 |
| High | Breach | Kelp DAO: $293M LayerZero Cross-Chain Bridge Exploit | 2026-04-19 |
| High | Ransomware | Altpro: Coinbasecartel Ransomware Attack | 2026-04-19 |
| High | Ransomware | HS Technology Group: Qilin Ransomware Attack | 2026-04-19 |
| High | Breach | Carnival Corporation: ShinyHunters Extortion Breach | 2026-04-19 |
| High | Breach | Vercel: ShinyHunters Internal Systems Breach | 2026-04-19 |
| High | Ransomware | Pharmathek: Akira Ransomware Listing | 2026-04-19 |
| High | Ransomware | Nanometrics: Qilin Ransomware Claim | 2026-04-19 |
| High | Ransomware | SOGO Auction: RansomExx Ransomware Breach | 2026-04-19 |
| High | Breach | PowerSchool: Teen Hacker Sentenced for Historic Student Data Breach | 2026-04-19 |
| High | Ransomware | ASTM Group: CoinbaseCartel Ransomware Claim | 2026-04-19 |
| High | Breach | Hims & Hers Health: Social Engineering Breach Exposes Support Tickets | 2026-04-19 |
| High | Breach | Conrad Capital Management: Unknown Third Party Intrusion Exposes SSNs and Financial Data | 2026-04-18 |
| High | Breach | Trivy Ecosystem: Vect Ransomware Supply Chain Extortion | 2026-04-18 |
| High | Ransomware | HBX Group: Qilin Ransomware Leak Site Listing | 2026-04-18 |
| High | Breach | TruView BSI: Background Check Firm Confirms 2024 Breach Exposing SSNs | 2026-04-18 |
| High | Breach | Europa.eu: IAM Misconfiguration Breach by ShinyHunters | 2026-04-18 |
| High | Breach | Phoenix Art Museum: Unauthorized Network Intrusion Exposes SSNs | 2026-04-18 |
| High | Breach | Eurail: Data Breach Exposes 300,000+ Travelers | 2026-04-18 |
| High | Ransomware | medicalnetworks CJ GmbH: DragonForce Ransomware Breach | 2026-04-18 |
| High | Breach | Amtrak: ShinyHunters Salesforce Breach | 2026-04-18 |
| High | Breach | Kemper Corporation: ShinyHunters Salesforce Leak | 2026-04-18 |
| High | Breach | LA County Office of Education: W-2 Vendor Breach Enables Tax Refund Fraud | 2026-04-18 |
| High | Breach | National Supercomputing Center Tianjin: FlamingChina Data Theft | 2026-04-18 |
| High | Breach | Mossad and Shin Bet: Handala Claims Intelligence Breach | 2026-04-17 |
| High | Breach | Nigeria CAC: Corporate Registry Breach Triggers NITDA Probe | 2026-04-17 |
| High | Breach | PicBackMan: Cloud Backup Database Leak Exposes User Credentials | 2026-04-17 |
| High | Breach | Take-Two Interactive: ShinyHunters Snowflake Breach | 2026-04-17 |
| High | Ransomware | Stockton Cardiology: GENESIS Ransomware Breach | 2026-04-17 |
| High | Breach | French Ministry of National Education: Student Data Exfiltration | 2026-04-17 |
| High | Breach | Comcast Xfinity: Citrix Bleed Exploitation Reaches $117.5M Settlement | 2026-04-17 |
| High | Breach | Basic-Fit: 1 Million Members Exposed in European Data Breach | 2026-04-17 |
| High | Breach | Axios Supply Chain: North Korean UNC1069 Crypto Heist | 2026-04-17 |
| High | Breach | Longevity Health Plan: Confirmed Healthcare Data Breach | 2026-04-17 |
| High | Breach | Hellenic National Defense General Staff: Russia-Linked Email Breach | 2026-04-17 |
| High | Ransomware | Gruppo ICM SPA: Qilin Ransomware Attack | 2026-04-17 |
| High | Breach | Humana: Vendor Software Vulnerability Exposes Customer Data Across Six States | 2026-04-17 |
| High | Breach | Grinex: Suspected Western Intelligence Crypto Heist | 2026-04-17 |
| High | Breach | Ukrainian Hospitals and Governments: UAC-0247 Data Theft Campaign | 2026-04-17 |
| High | Ransomware | Canada Goose: Coinbasecartel Ransomware Claim | 2026-04-17 |
| High | Breach | Standard Bank: 1.2TB Data Leak Exposes Credit Card Details | 2026-04-17 |
| High | Breach | OFPPT Morocco: 400K Student Records Leaked via MyWay Platform | 2026-04-16 |
| High | Breach | Ukrainian Prosecutors: Fancy Bear Email Compromise Campaign | 2026-04-16 |
| High | Breach | Khyber Pakhtunkhwa Government: Admin Database Leak Exposes MD5 Credentials | 2026-04-16 |
| High | Breach | Banco BBVA: Customer Database Leaked by Threat Actor MAGO SPEAK | 2026-04-16 |
| High | Breach | Chipsoft: Ransomware Attack Exposes Dutch Hospital Patient Data | 2026-04-16 |
| High | Breach | McGraw-Hill: ShinyHunters Compromise Salesforce Platform, 45 Million Records Exposed | 2026-04-16 |
| High | Breach | Chekin and Gastrodat: Massive Booking Data Theft Exposes 5 Million Hotel Guests | 2026-04-16 |
| High | Breach | Romanian Air Force: Russian-Linked Hackers Compromise 67 Email Accounts | 2026-04-16 |
| High | Breach | Signature Healthcare: Anubis Ransomware Attack Disrupts Hospital Operations | 2026-04-16 |
| High | Ransomware | Autovista: Ransomware Disrupts Automotive Data Services | 2026-04-16 |
| High | Ransomware | Dencom New Zealand: Krybit Ransomware Breach | 2026-04-16 |
| High | Breach | RCI Hospitality: Cyberattack Exposes Corporate and Customer Records | 2026-04-16 |
| High | Breach | Booking.com: Millions of Customer Reservations Exposed in Storm-1865 Supply Chain Breach | 2026-04-16 |
| High | Breach | Hallmark: ShinyHunters Dump 6.2M Customer Records After Failed Extortion | 2026-04-16 |
| High | Ransomware | Cookeville Regional Medical Center: Rhysida Ransomware Attack Exposes 337K Patient Records | 2026-04-16 |
| High | Breach | Mexican Government Agencies: AI-Powered Solo Breach Campaign | 2026-04-15 |
| High | Breach | Rockstar Games: ShinyHunters Breach Exposes 78.6 Million Records via Snowflake | 2026-04-15 |
| High | Breach | Israeli Unit 8200: Handala Hacker Group Claims Breach Exposing 80 Senior Officers | 2026-04-15 |
| High | Breach | PowerSchool: Gen Z Hacker Confirms $2.8M Extortion After Credential Breach | 2026-04-15 |
| High | Breach | National Supercomputing Center Tianjin: Six-Month Silent Breach by FlamingChina | 2026-04-15 |
| High | Ransomware | Eldorado Trading Group: DragonForce Ransomware Attack | 2026-04-15 |
| High | Breach | Mercor AI — LiteLLM Supply Chain Attack Breach | 2026-04-05 |
| High | Breach | Drift Cryptocurrency Exchange — North Korea Social Engineering Attack | 2026-04-05 |
| High | Breach | FBI Surveillance System — China-Linked Breach Pen Register Data Exposure | 2026-04-05 |
| High | Breach | Hong Kong Hospital Authority — Patient Data Breach | 2026-04-05 |
| High | Ransomware | Advanced Vehicle Assemblies — Nightspire Ransomware Attack | 2026-04-05 |
| High | Ransomware | Shwapno Bangladesh Supermarket — Ransomware Attack Customer Data Breach | 2026-04-05 |
| High | Ransomware | United Finance Egypt — Ransomware Attack Financial Services Breach | 2026-04-05 |
| High | Ransomware | Uffizi Gallery Florence — Medusalocker Ransomware Attack Cultural Heritage Institution | 2026-04-05 |
| High | Breach | Hims & Hers Telehealth Platform — Customer Support System Breach | 2026-04-05 |
| High | Ransomware | Groupe SERAP — Akira Ransomware Attack Agricultural Equipment Manufacturer | 2026-04-05 |
| High | Breach | Hasbro — Major Cyber Incident and Operational Disruption | 2026-04-05 |
| High | Ransomware | Minot Water Treatment Plant — Critical Infrastructure Ransomware Attack | 2026-04-05 |
| High | Breach | Nacogdoches Memorial Hospital — Patient Data Breach | 2026-04-05 |
| High | Ransomware | Charles River Insurance — Akira Ransomware Attack Insurance Sector | 2026-04-05 |
| High | Ransomware | Nissan Automotive — Everest Ransomware Third-Party Vendor Attack | 2026-04-04 |
| High | Breach | SUTEX Ltda Colombian Textile — DragonForce Ransomware Attack | 2026-04-04 |
| High | Breach | PSK Wind Technologies - Handala Iran-Linked Defense Contractor Breach | 2026-04-04 |
| High | Breach | FSSAI India Food Authority — Official Document Breach | 2026-04-04 |
| High | Breach | Asmar Schor & McKenna Construction Law Firm — DragonForce Ransomware Attack | 2026-04-04 |
| High | Breach | Adobe — Mr. Raccoon BPO Supply Chain Attack | 2026-04-04 |
| High | Breach | Bunch Ltd. Canadian Constructor — DragonForce Ransomware Attack | 2026-04-04 |
| High | Breach | Anthropic Claude Code Source Code Leaked via npm Misconfiguration | 2026-04-04 |
| High | Ransomware | Manage My Health New Zealand — Kazu Ransomware Healthcare Attack | 2026-04-04 |
| High | Breach | Cisco & Salesforce — CRM Data Breach | 2026-04-03 |
| High | Breach | Corewell Health — 19,000 Patients' Medical and Personal Data Compromised in Michigan Hospital Network Breach | 2026-04-01 |
| High | Ransomware | UMMC Hit by Medusa Ransomware — $800K Demanded, 1TB of Patient and Employee Data Exfiltrated | 2026-04-01 |
| High | Breach | CareCloud — Confirmed Breach of Electronic Health Records System Exposes Patient Data Across Provider Network | 2026-04-01 |
| High | Breach | Feníe Energía — Unattributed Data Exfiltration, 1.7M Records | 2026-03-31 |
| High | Breach | Tamir Pardo (Former Mossad Chief) — Handala Email Breach | 2026-03-31 |
| High | Breach | axios npm Supply Chain Attack — Hijacked Maintainer Drops Multi-Platform RAT | 2026-03-31 |
| High | Ransomware | Stats SA — XP95 Cyber-Extortion | 2026-03-30 |
| High | Ransomware | Kyocera Document Solutions Europe & Polsat — ALP-001 Ransomware, 150GB Exfiltrated | 2026-03-30 |
| High | Breach | Castilla-La Mancha Education System — Organized Cybercrime Ring | 2026-03-29 |
| High | Ransomware | Namibia Airports Company — INC Ransomware Group Dumps 500GB of Critical Infrastructure Data | 2026-03-29 |
| High | Ransomware | CommonSpirit Health — Patient Data Exposed via Third-Tier Subcontractor Ransomware Attack | 2026-03-29 |
| High | Ransomware | Rocky Mountain Care — Qilin Ransomware Hits Utah Senior Care Network | 2026-03-29 |
| High | Ransomware | Schlam Stone & Dolan LLP — Anubis Ransomware Targets U.S. Law Firm Representing Government and Fortune 500 Clients | 2026-03-29 |
| High | Ransomware | Lacor.es and Polsat — ALP-001 Ransomware European Expansion | 2026-03-29 |
| High | Ransomware | ARENCO Group & ITWAL — Dual Ransomware Claims Target Dubai Conglomerate and Canada's National Food Distribution Network | 2026-03-29 |
| High | Ransomware | Terix — ALP-001 Ransomware Hits U.S. Data Center Provider with $26.5M Demand | 2026-03-29 |
| High | Ransomware | Woodfords Family Services — Ransomware Attack on Disability Services Provider Yields Two-Year Notification Failure | 2026-03-29 |
| High | Ransomware | TPIS Industrial Services — Play Ransomware Hits U.S. Manufacturer | 2026-03-28 |
| High | Breach | Doctor Alliance — Credential Theft Exposes Patient Health Records Across Multiple Texas Home Healthcare Providers | 2026-03-28 |
| High | Breach | Nova Scotia Power — Cyberattack Exposed 900,000 Utility Customers, Privacy Commissioner Forces Security Reform | 2026-03-28 |
| High | Breach | Kash Patel — Iranian State-Linked Handala Breaches FBI Director's Personal Gmail, Publishes Authenticated Documents | 2026-03-28 |
| High | Ransomware | Esprinet — ALP-001 Ransomware Claims 1.2TB Breach of €4B European IT Distributor | 2026-03-28 |
| High | Ransomware | Goodwill Industries — Interlock Ransomware Hits Nonprofit Chain, 80GB Stolen, Stores Forced Cash-Only | 2026-03-28 |
| High | Breach | European Commission — AWS Account Breach Exposes 350GB of EU Executive Data, Attacker Plans Public Leak | 2026-03-28 |
| High | Breach | Hong Kong Correctional Services Department — IT System Breach Exposes 6,800 Employee Records | 2026-03-28 |
| High | Ransomware | Germany's Left Party — Qilin Ransomware Attack on Political Party Infrastructure | 2026-03-28 |
| High | Ransomware | City of Meriden, Connecticut — Incransom Ransomware Group Claims Municipal Government Attack | 2026-03-28 |
| High | Ransomware | Viva Ticket — Ransomware Hits Ticketing Platform Serving the Louvre and 3,500 Cultural Venues | 2026-03-28 |
| High | Breach | IntraCare — Healthcare Cyberattack Takes Systems Offline, 28 Surgeries Deferred | 2026-03-28 |
| High | Breach | AFC Ajax — API Flaws Exposed 300,000 Accounts and Enabled Hijack of 42,000 Season Tickets | 2026-03-28 |
| High | Breach | Centauro.net — 4.3 Million Customer Records Exposed in Data Breach | 2026-03-28 |
| High | Breach | LiteLLM — Malicious PyPI Packages Steal 300GB and 500K Credentials via AI Proxy Supply Chain | 2026-03-27 |
| High | Ransomware | SATS Sports Club — The Gentlemen Ransomware Claims Nordic Fitness Giant, 733K Members at Risk | 2026-03-27 |
| High | Breach | Hightower Holding — Credential Compromise Exposes 131,000 Wealth Management Clients | 2026-03-27 |
| High | Ransomware | Monmouth University — PEAR Ransomware Group Claims 16TB Exfiltration | 2026-03-27 |
| High | Breach | Crunchyroll (Sony): Third-Party Vendor Malware, 100GB Exfiltration, $5M Extortion | 2026-03-26 |
| High | Ransomware | Port of Vigo (Spain): Ransomware Attack Disrupts Europe's Largest Fishing Port | 2026-03-26 |
| High | Breach | QualDerm Partners: Healthcare Data Breach, Millions of Patients Potentially Exposed | 2026-03-26 |
| High | Breach | Cnous France: Data Breach Exposes 774,000 University Records | 2026-03-26 |
| High | Breach | Navia Benefit Solutions: Silent 24-Day Breach Exposes 2.7 Million Across Client Organizations | 2026-03-26 |
| High | Breach | AstraZeneca: Lapsus$ Claims 3GB Breach of Internal Code, Credentials, and Employee Data | 2026-03-26 |
| High | Ransomware | Foster City, California: Ransomware Attack Forces State of Emergency Declaration | 2026-03-26 |
| High | Ransomware | Nike: Double-Extortion Ransomware Targeting IP | 2026-03-25 |
| High | Breach | Checkmarx: TeamPCP CI/CD Supply Chain Compromise via Stolen GitHub Credentials | 2026-03-25 |
| High | Breach | Mazda: Vulnerability Exploitation in Warehouse Management System | 2026-03-25 |
| High | Breach | Dutch Ministry of Finance: Unauthorized Access to Policy Department Systems | 2026-03-25 |
| High | Breach | Kaplan: Server Intrusion Exposes SSNs and Driver's Licenses of 230,000+ Students and Professionals | 2026-03-24 |
| High | Breach | BMW & 35+ Automakers: IDOR Exploit Fuels Ongoing Multi-Brand Data Exfiltration | 2026-03-24 |
| High | Ransomware | South Africa Land Bank: RaaS Ransomware Attack via Internet-Facing Server Exploit | 2026-03-24 |
| High | Breach | CIRO: Phishing Attack Exposes 750,000 Canadian Investors | 2026-03-24 |
| High | Breach | Chile's Ley del Lobby Platform: Government Lobbying Records Breach Exposes 8 Years of Political Intelligence | 2026-03-24 |
| High | Breach | Lockheed Martin: Pro-Iran APT Claims 375TB Breach, Demands $400M Ransom | 2026-03-24 |
| High | Breach | Telekom Serbia: Data Breach Exposes 700,000 Customers via Secondary Application Attack | 2026-03-24 |
| High | Ransomware | Bell Ambulance: Medusa Ransomware Exposes 238,000 Patients' Healthcare and Identity Data | 2026-03-24 |
| High | Breach | Conduent: Covert Intrusion Exposes 25 Million Americans' Government Benefits Data | 2026-03-24 |
| High | Ransomware | Southwire: Qilin Ransomware Group Claims Attack on Major US Electrical Infrastructure Supplier | 2026-03-23 |
| High | Ransomware | Hikvision: ALP-001 Claims 199TB Breach of World's Largest Surveillance Manufacturer ⚠️ Unverified | 2026-03-23 |
| High | Breach | SoundCloud: ShinyHunters Extortion Gang Breaches 29.8 Million User Accounts | 2026-03-23 |
| High | Breach | Trivy Vulnerability Scanner Backdoored in Supply Chain Attack: 100M+ Download Tool Turned Credential Stealer | 2026-03-22 |
| High | Ransomware | University of Mississippi Medical Center: Ransomware Forces Statewide Clinic Shutdown, EHR Systems Offline | 2026-03-22 |
| High | Ransomware | Marquis: Ransomware Attack Exposes 672K Banking Customers | 2026-03-19 |
| High | Breach | CGI Sverige / Sweden BankID: ByteToBreach Source Code and Credential Leak | 2026-03-19 |
| High | Ransomware | Royal Bahrain Hospital: Payload Ransomware, 110GB Patient Data Exfiltration Claimed | 2026-03-19 |
| High | Ransomware | AkzoNobel: Anubis RaaS, 170GB Exfiltration from US Facility | 2026-03-19 |
| High | Breach | Navigate360 / P3 Global Intel: 8 Million Confidential Police Tips Compromised via Social Engineering | 2026-03-19 |
| High | Breach | Aura: ShinyHunters Voice Phishing Attack, 900,000 Records Leaked | 2026-03-19 |
| High | Breach | UK Companies House: WebFiling Browser Exploit Exposes 5 Million Business Records | 2026-03-18 |
| High | Breach | Salesforce Experience Cloud: ShinyHunters Mass Extortion Campaign | 2026-03-18 |
| High | Ransomware | Ruhnau Clarke & Biogel: Qilin Ransomware Double Extortion | 2026-03-18 |
| High | Breach | France FICOBA: Credential Theft Exposes 1.2M National Bank Records | 2026-03-18 |
| High | Breach | Odido: ShinyHunters Data Extortion Campaign | 2026-03-17 |
| High | Breach | France: Criminal Data Broker Mega-Aggregation Exposes 45M Citizens | 2026-03-17 |
| High | Breach | UK Biobank: Researcher Negligence Exposes Genetic and Medical Records of 500,000 Volunteers | 2026-03-16 |
| High | Breach | U.S. Critical Infrastructure: Seedworm (MuddyWater) Espionage Campaign with Novel Deno Backdoor | 2026-03-16 |
| High | Breach | CarGurus: ShinyHunters Breach Exposes 12.4 Million User Records | 2026-03-16 |
| High | Breach | Starbucks Employee Data Breach: 889 Accounts Compromised via Partner Central Phishing | 2026-03-15 |
| High | Breach | IDMerit: Unauthenticated MongoDB Exposes 1 Billion KYC Records | 2026-03-15 |
| High | Breach | FBI New York Field Office: Human Error Exposes Epstein Investigation Server to Foreign Hacker | 2026-03-15 |
| High | Breach | Cognizant TriZetto: 11-Month Undetected Intrusion Exposes 3.4M Patient Records | 2026-03-15 |
| High | Breach | Loblaw Companies: Third-Party Threat Actor Breaches Canada's Largest Retailer | 2026-03-15 |
| High | Ransomware | DigitalMint Negotiator Charged: Ran Ransomware Attacks While Negotiating for Victims | 2026-03-14 |
| High | Breach | Social Security Administration: DOGE Insider Data Exfiltration | 2026-03-13 |
| High | Breach | Stryker: Iran-Linked Handala Wiper Attack | 2026-03-13 |
| Critical | CVE · KEV | CVE-2026-3909 | 2026-03-13 |
| High | Breach | Telus Digital: ShinyHunters Data Extortion | 2026-03-13 |
| Critical | CVE · KEV | CVE-2026-3910 | 2026-03-13 |
| High | Breach | Sweden E-Government / CGI Sverige: National Codebase Leak | 2026-03-13 |
| Critical | CVE · KEV | CVE-2024-21762 FortiOS Out-of-Bound Write Vulnerability | 2026-03-10 |
| Critical | CVE · KEV | Threat Brief: CVE-2025-26399 SolarWinds Web Help Desk RCE | 2026-03-09 |
| Critical | CVE · KEV | CVE-2017-7921: Hikvision Improper Authentication Vulnerability | 2026-03-07 |
Showing 2890 of 2890