Threat Intelligence
A Stalker's Own Database Exposed 86,859 Surveillance Images
The operator who installed the spyware was the one who left the cloud bucket open.
Threat Intelligence
The operator who installed the spyware was the one who left the cloud bucket open.
Policy & Government
The breach didn't need a hack. It needed an interoperability framework that took fake clinics at their word.
Cyber Attacks
Instructure confirmed ShinyHunters breached Canvas, exposing student data across nearly 9,000 institutions — then paid the ransom. The real lesson is ed-tech concentration risk: one platform's breach is thousands of schools' breach at once.
Threat Intelligence
The OAuth phishing kit is plumbed end-to-end through legitimate SaaS, which is exactly the point.
Trending
CISA added CVE-2026-31431 — "Copy Fail" — to its KEV catalog after confirming active exploitation of a Linux kernel privilege escalation flaw affecting every distribution running kernels since 2017, allowing unprivileged users to gain root.
Trending
Vietnamese-linked operation "AccountDumpling" has compromised 30,000 Facebook Business accounts by sending phishing emails from Google's legitimate AppSheet address — bypassing spam filters and running a criminal resale storefront for stolen accounts.
Trending
CVE-2026-42208 in LiteLLM — the open-source AI gateway with 45K GitHub stars — was exploited within 36 hours of disclosure with no public PoC. A successful attack yields OpenAI org keys, Anthropic workspace admin keys, and AWS Bedrock credentials.
Trending
276 suspects arrested and 9 cryptocurrency fraud centers dismantled in a joint US-China operation targeting pig-butchering scams that have cost American victims millions — the DOJ called it "unprecedented" bilateral cooperation.
Trending
Official SAP npm packages were backdoored on April 29 in the latest Mini Shai-Hulud wave — adding browser credential theft across Chrome, Safari, and Edge to the campaign's existing cloud secret harvesting. Over 1,100 victim repositories confirmed.
Trending
Wiz discovered CVE-2026-3854 — a critical GitHub RCE where a single crafted git push gave attackers cross-tenant code execution and access to millions of private repositories. 88% of GHES instances were still unpatched at public disclosure.
Trending
Ryan Goldberg (Sygnia) and Kevin Martin (DigitalMint) were sentenced to 4 years in federal prison for acting as BlackCat ransomware affiliates while employed as incident response professionals — attacking the same clients they were hired to help.
Trending
Trend Micro publishes full technical analysis of Shadow-Earth-053 — a China-aligned cluster targeting journalists and civil society activists alongside governments and defense across Asia and Poland, with no strong overlap to any publicly reported group.