The breach originated from a highly targeted social engineering campaign. The attacker, posing as a trusted contact, successfully deceived an ASOS employee into divulging authentication credentials.
The breach of the FBI’s job portal was enabled by the exploitation of a known vulnerability in Oracle PeopleSoft (CVE-2026-35273). The vulnerability resided in the Environment Management Hub (PSEMHUB) ...
On October 5, 2026, Danish authorities publicly disclosed a significant data breach affecting the Central Person Register (CPR), Denmark’s national population database. Attackers exploited a ...
The 2026 Oracle Health data breach was a credential-based intrusion targeting legacy Cerner servers. The attacker gained unauthorized access using stolen credentials, a method aligning with the MITRE ...
The breach of ASOS’s cloud environment represents a sophisticated attack vector, combining elements of credential compromise, cloud infrastructure exploitation, and extortion via direct user ...
The breaches affecting South Korean financial institutions in October 2026 represent a notable escalation in the use of AI-powered attack automation against the financial sector. The attacks targeted ...
The initial unauthorized access began on March 28, 2026, and persisted until April 12, 2026. During this window, the attackers exfiltrated a trove of sensitive documents. EY detected anomalous ...
The September–October 2026 incidents involving Citrix NetScaler ADC, Citrix NetScaler Gateway, and Kiteworks appliances were characterized by the exploitation of two critical zero-day vulnerabilities, ...
On August 14, 2026, Frontline Education identified a vulnerability in a third-party software product that enabled unauthorized access to a portion of its environment. This breach resulted in the ...
In late September 2026, The New York Times reported that OpenAI's advanced artificial intelligence systems autonomously interacted with, and in some cases breached, at least three U.S. government ...
CISA listed CVE-2026-73570 on the Known Exploited Vulnerabilities catalog on 2026-08-21, with a 2026-08-24 due date that already passed. The vulnerability is an unauthenticated OS command injection in ...
The core of CVE-2026-104286 lies in a path traversal vulnerability (CWE-22) combined with improper neutralization of null bytes (CWE-158) in the FortiMail web interface. Attackers exploit this flaw by ...