WaterPlum North Korean Hackers Infect 30,000 Devices and Steal $10.7 Million in Cryptocurrency
September 19, 2026 A joint law enforcement advisory from the United States, Japan, Australia, and Germany warns that the North Korean hacking group WaterPlum compromised at least 30,000 devices worldwide. The group also transferred more than $10.7…
Gyazo Data Breach Exposes 23.6 Million Users
September 19, 2026 The Gyazo image-sharing platform has confirmed a massive data breach after attackers exploited a server vulnerability. Consequently, approximately 23.6 million user records and 490 million image metadata entries were exposed. The…
IDScan Data Breach Exposes Driver’s Licenses in Dark-Web
September 6, 2026 Identity verification company IDScan is facing multiple lawsuits after hackers allegedly breached its systems and offered more than 153 million U.S. and Canadian driver’s licenses for sale on a dark-web identity theft service…
Malicious Terraform Modules Steal Cloud Credentials via Cloudflare Infrastructure
September 4, 2026 Threat actors compromised the Cloudflare infrastructure behind Coder’s module registry and served malicious Terraform modules to developers. Consequently, organizations using the popular self-hosted development platform may have…
Critical JFrog Artifactory Auth Bypass CVE Under Active Exploitation
September 1, 2026 JFrog has released an emergency patch for a critical authentication bypass vulnerability in Artifactory, tracked as CVE-2026-82329 (CVSS 9.8), that allows unauthenticated remote attackers to obtain full administrative access. Security…
Cronos Tectonic Exploit Drained 4 Million in 20 Minutes
September 1, 2026 Cronos blockchain halted all transactions on August 30, 2026, after a threat actor exploited the Tectonic lending platform in a $74 million price-manipulation attack. The attacker artificially inflated the price of Tectonic’s…
ShinyHunters Steals 284 Million Healthcare Records in Vishing Attack
August 30, 2026 Healthcare and pharmaceutical distribution giant McKesson has disclosed a significant cybersecurity incident. The company confirmed unauthorized access to third-party applications and data exfiltration. Consequently, the ShinyHunters…
ATF Confirms Major Cybersecurity Incident After Qilin Ransomware Breach Claim
August 27, 2026 The Bureau of Alcohol, Tobacco, Firearms and Explosives (ATF) confirmed a major cybersecurity incident on August 26, 2026, after the Qilin ransomware gang listed the U.S. federal law enforcement agency on its dark web data leak portal.…
Rust Supply Chain Attack on arrayref Crate
August 21, 2026 The Rust Security Response Team has deleted malicious versions of three widely used Rust crates from crates.io after a compromised maintainer account published releases that added a typosquatted dependency. That dependency executed a…
SafePal Data Breach Crypto Wallet Customers Exposed
August 17, 2026 Cryptocurrency hardware wallet provider SafePal disclosed a data breach that exposed customer order information for approximately 39,798 users. The incident involves an authorization flaw in the company’s order-tracking system, and…