ASOS confirmed unauthorized activity involving customer-communication platforms and says names and contact details may have been accessed. Payment-card data and passwords are not believed affected.
The FBI confirmed a contractor was removed after a missed security patch contributed to an employee-data breach. Reuters identified Accenture and Oracle PeopleSoft.
Google has paused product vulnerability submissions to its open-source bug bounty program after a sharp rise in invalid automated reports, while supply-chain reports and other reporting channels remain open.
Citrix released emergency NetScaler updates for actively exploited CVE-2026-88779, a SAML-related memory flaw that can cause prolonged service outages.
Citrix confirmed targeted attacks exploiting CVE-2026-88779 in customer-managed NetScaler systems using SAML authentication. Fixed builds are now available.
Vercel confirmed a KVM zero-day that reportedly enables a guest-to-host virtual machine escape. No CVE, affected-version list, public exploit, or malicious exploitation has been disclosed.
Reuters reports that Jordanian authorities detained alleged ShinyHunters member Saif al-Din Khader and that he is helping investigators locate other hackers.
The Technical University of Denmark says attackers accessed its identity system and downloaded data that may involve about 200,000 current and former users.
Vicksburg shut down city computer systems after a ransomware attack disrupted utility payments. Emergency services remain operational as investigators assess possible data exposure.
Frontline Education is notifying school districts after a third-party software vulnerability enabled unauthorized access to employee records, including sensitive personal data in at least one district.