Dutch authorities arrested a 24-year-old man the FBI describes as one of the alleged leaders of ShinyHunters. The FBI says the group is linked to more than 140 breaches and at least $70 million in extortion payments.
Microsoft confirmed unauthorized access to its official X account after attackers used it to promote an unauthorized Clippy-themed cryptocurrency token.
Microsoft’s 2026 Digital Defense Report says AI is compressing attack timelines, scaling phishing, and widening the gap between vulnerability discovery and patching.
Fortinet and CISA confirm active exploitation of critical FortiMail flaw CVE-2026-104286. Organizations should apply workarounds and begin forensic checks immediately.
An international police operation dismantled KillSec ransomware infrastructure, made three provisional arrests, and secured at least 110 TB of stolen data.
MetaMask is responding to an infrastructure security incident and exiting affected Ethereum validators. The company says wallets face no immediate threat.
DIVD says attackers chained two Zammad zero-days to hijack sessions, execute code, and gain root access. Review affected versions and defensive actions.
Cisco confirms attackers are exploiting CVE-2026-76504 to bypass authentication and gain administrator access to Catalyst SD-WAN Manager. Patches are available.
Keio confirmed a ransomware attack disrupted some business systems while core operations continued. Here are the confirmed facts and practical defenses.