
OptinMonster WordPress Plugin Hacked in CDN Supply-Chain Attack
Hackers compromised Awesome Motive's CDN to inject malicious code into OptinMonster, TrustPulse, and PushEngage plugins. The attack affected up to 1.2 million WordPress sites and created rogue admin accounts with full backdoor access before being detected.

Cisco Patches SD-WAN Zero-Day Already Exploited in Attacks
Cisco has fixed a vulnerability in Catalyst SD-WAN Manager that attackers were already using to gain root access on enterprise networks. The flaw affects all deployment types, including cloud and on-prem installations. Security teams should patch immediately and check logs for indicators of compromise.

Council of Europe Probes ShinyHunters Breach Claim
The ShinyHunters extortion group claims to have stolen over 429,000 documents containing HR and payroll data from the Council of Europe. The intergovernmental body is investigating the alleged breach, which threatens to expose sensitive information for more than 10,000 staff members.

Chinese Hackers Stole Medical Research Data Undetected for a Year
A China-linked espionage group infiltrated REDCap servers at a North American medical institution, deploying custom malware that harvested credentials and exfiltrated sensitive research data from September 2023 through November 2025. Google researchers discovered the campaign used novel techniques including hijacking enterprise compliance features to automatically email stolen data to attacker-controlled accounts.

Microsoft 365 Copilot Flaw Enabled One-Click Data Theft
A critical vulnerability chain called SearchLeak let attackers steal emails, documents, and calendar data from Microsoft 365 Copilot Enterprise users with a single malicious link. Varonis researchers discovered the flaw, which Microsoft patched earlier this month under CVE-2026-42824.

Infinite Campus Breach Exposes 137,000 School Staff Records
The ShinyHunters extortion gang breached Infinite Campus through its Salesforce instance in March, stealing names, emails, phone numbers, and support tickets from K-12 staff accounts. The EdTech company serves 3,200 school districts and manages data for 11 million students across 46 states.

Ex-IT Worker Gets 21 Months for 21-Month Cyberattack on Iowa School
Ezekiel Dean Potter, a former IT specialist at Iowa's Saydel Community School District, received a 21-month prison sentence for systematically attacking his former employer's systems after his termination. The attacks deleted accounts, disabled device management, and disrupted classroom operations for over a year and a half.

Chinese Hackers Hid Inside Isolated Network for 10 Years
The Velvet Ant threat group compromised a critical infrastructure network with no direct internet connection and maintained access from 2016 to 2026. Sygnia researchers discovered the attackers hijacked authentication systems, turning the organization's own security tools into espionage platforms.

Maine Shuts Down Breach Portal After Fake Discord, VRChat Filings
The Maine Attorney General's Office has disabled public access to its data breach notification database after discovering fraudulent disclosures impersonating Discord and VRChat. The fake filings, which claimed millions of users were affected, exposed a critical flaw: submitted notices were automatically published without verification.

French Govt Tchap Breach Exposes 73,000 Civil Servant Accounts
A threat actor compromised France's official encrypted messaging platform through a social engineering attack, accessing names, emails, and 13.5GB of documents from unencrypted public chat rooms. The breach affects less than 9% of Tchap's 825,000 registered users but raises questions about training and platform design.

Fake Data Breach Reports Posted to Maine's Official Portal
Maine's official data breach notification portal published fraudulent reports about VRChat and Discord without verifying their authenticity. The state confirmed that anyone can submit breach notifications that go live immediately, exposing a significant flaw in the public transparency system.

South Korea Fines Coupang $409M: Largest Privacy Penalty Ever
South Korea's data regulator has imposed a record 624.6 billion won ($409 million) fine on e-commerce giant Coupang after a breach exposed 37.55 million customer records. The penalty comes alongside findings of obstruction, delayed reporting, and interference with the company's data protection officer.

Nottingham University Breach Exposes 454,600 Students' Data
ShinyHunters extortion gang claims responsibility for stealing 40GB of student records from the University of Nottingham, including passport numbers, payment details, and personal information across UK, Malaysia, and China campuses.

Ivanti Sentry Exploit Goes Live: Most Exposed Gateways Backdoored
A maximum severity vulnerability in Ivanti Sentry is being actively exploited just one day after patches were released. Shadowserver reports that most internet-exposed Sentry gateways are already compromised, with attackers gaining root access through trivial command injection.

npm v12 Blocks Install Scripts by Default to Stop Supply-Chain Attacks
GitHub will ship npm v12 next month with a secure-by-default posture. The update disables automatic execution of preinstall, install, and postinstall scripts. It also blocks Git and remote URL dependencies unless developers explicitly approve them.

ShinyHunters Steals Data From 100+ Organizations via PeopleSoft
The ShinyHunters extortion gang is exploiting Oracle PeopleSoft servers using a chain of old and zero-day vulnerabilities. The group claims to have compromised 300 instances across more than 100 organizations, with the education sector hit hardest.

Microsoft Patches Exchange Server Zero-Day Used in Active Attacks
Microsoft has released security updates for a high-severity Exchange Server vulnerability that attackers were already exploiting in the wild. The flaw allows remote attackers to execute arbitrary JavaScript through Outlook Web Access with no privileges required.






