FortiBleed Leak Exposes Fortinet VPN Credentials for 73,000 Devices
June 17, 2026 A newly discovered data leak dubbed FortiBleed has exposed Fortinet VPN credentials for 73,932 firewall URLs at organizations worldwide. Consequently, security researchers warn that the leaked data could enable direct access to enterprise…
UNC6508 Abuses Google Workspace Rules to Steal US Medical and Defense Research
June 16, 2026 Google’s Threat Intelligence Group has disrupted a China-nexus espionage campaign that hid inside North American medical and military research networks for more than a year. The threat actor, tracked as UNC6508, abused legitimate…
Meta AI Support Breach Hijacks 20,000 Instagram Accounts
June 8, 2026 Meta has disclosed that attackers exploited a vulnerability in its AI-powered Instagram account recovery system to hijack more than 20,000 user accounts. Consequently, the breach raises serious questions about how AI-assisted support tools…
DentaQuest Data Breach Exposes 2.6M Accounts: ShinyHunters Leak
June 7, 2026 DentaQuest, one of the largest dental benefits administrators in the United States, confirmed a major data breach that exposed the personal and health information of approximately 2.6 million accounts. The incident was carried out by the…
ShinyHunters Breach Charter Communications: 4.9M Accounts Exposed
May 29, 2026 The ShinyHunters extortion gang has breached Charter Communications, exposing 4.9 million customer and business accounts. Consequently, the telecom giant confirmed the incident while disputing the severity of the stolen data. Charter…
7-Eleven Data Breach Exposes 185,000 People: ShinyHunters Extortion Gang Strikes
May 26, 2026 Convenience store giant 7-Eleven has confirmed a data breach that exposed the personal information of 185,300 people after the ShinyHunters extortion gang compromised its systems in early April 2026. Consequently, the cybercriminals leaked a…
Kali365 PhaaS Hijacks Microsoft 365 Accounts via Device Code Phishing
May 25, 2026 The FBI is warning organizations about Kali365, a phishing-as-a-service (PhaaS) platform that hijacks Microsoft 365 accounts by abusing OAuth device code authentication. The service bypasses multi-factor authentication (MFA) and has already…
Laravel Lang Supply Chain Attack Spreads Credential-Stealing Malware to Developers
May 23, 2026 A sophisticated supply chain attack has compromised the Laravel Lang localization packages after attackers rewrote GitHub version tags to distribute credential-stealing malware through Composer. Security researchers from StepSecurity, Aikido…
US Gas Station Tank Gauges Breached by Unknown Threat Actors
May 18, 2026 Unknown threat actors have breached automatic tank gauge (ATG) systems at US gas stations in multiple states. The attackers exploited these systems to manipulate display readings on fuel tanks. However, they did not alter the actual fuel…
Iranian Threat Actor Exfiltrates 26,000 Oman Ministry of Justice Records
May 5, 2026 An Iranian-nexus threat actor carried out a targeted data theft attack against the Omani government on April 8 and April 10, 2026. The attackers compromised the Ministry of Justice and Legal Affairs and exfiltrated over 26,000 user records.…