Data Breaches & Scandals
FortiBleed just exposed 430,000 corporate firewalls—Russian hackers have been inside since February 2026
A Russian hacking operation has compromised 430,000 corporate firewalls since February, harvesting credentials from Fortune…
Scattered Spider hackers plead guilty on day one — crippled London transport in August 2024
Two Scattered Spider members admitted guilt on trial's first day for the August 2024 cyberattack…
100,000 WordPress Sites Quietly Exposing API Keys Through Gravity SMTP Plugin Bug Right Now
A medium-severity flaw in Gravity SMTP, installed on 100,000 WordPress sites, is leaking API keys…
More News
Bluekit phishing kit just added AI—now criminals can launch 40 targeted attacks in minutes
Criminals are weaponizing AI to automate phishing attacks. A new kit called Bluekit includes 40 templates and AI features to…
SAP npm packages just got hijacked by hackers calling themselves mini Shai-Hulud — stealing developer credentials at scale
Five security firms expose coordinated supply chain attack on SAP npm packages. Developers' credentials stolen via malware-laced code.
Critical GitHub flaw CVE-2026-3854 lets attackers execute code with single git push command
A critical GitHub vulnerability (CVE-2026-3854) allows authenticated users to execute remote code with a single git push command, threatening millions…
Checkmarx’s own GitHub repository just leaked on the dark web after March 23 supply chain attack
Security software maker Checkmarx confirms its own GitHub data was stolen and posted on the dark web following a March…