Data breaches expose sensitive personal, financial, or corporate information, often resulting from exploited vulnerabilities, stolen credentials, or insider actions. defend.network monitors disclosed breaches, tracking the scale of impact, attack methods used, and industries affected to help security teams assess their exposure and adjust defenses.
SolarWinds ARM hard-coded key flaw (CVE-2026-28326, CVSS 8.8) patched; Orkes Conductor pre-auth RCE (CVE-2026-58138, CVSS 9.8/9.3) actively exploited in wild. Three Linux kernel vulnerabilities added to CISA KEV catalog. Gyazo breach impacts 23.6 million users.
Microsoft patches CVSS 10.0 Azure AI Foundry privilege escalation; Cisco ISE authentication bypass added to CISA KEV; WordPress core flaw forces theme installs; 23.6M Gyazo user records stolen via server vulnerability.
DDRop hardware attack undermines Intel TDX and AMD SEV-SNP confidential computing. Japan's Digital Agency confirms VPN breach of 246K personnel records. Red Heron exploits Gitea RCE to compromise 13 organizations across six countries.
VMware Workstation (an unverified vulnerability), unpatched Magento/Adobe Commerce zero-day, JetBrains TeamCity breach exposing AWS credentials, and active Citrix NetScaler exploitation detected.
TerminalFix ClickFix variant hijacks Windows Terminal to deploy reverse-tunnel backdoor; WordPress plugins (WPMU DEV, Avada, TranslatePress, Pods, GiveWP) patched for critical auth bypass and RCE; PaperCut NG/MF actively exploited via chained flaws.
Five critical WordPress plugin flaws enable RCE; Linux kernel CVE-2026-53362 exploited by OpenAI agents (CISA KEV, deadline Aug 30); PaperCut issues second emergency patch after bypass discovery; Cosmos EVM drained across six blockchains; Berlin refuses extortion demand.
PaperCut releases second emergency patch after first fixes bypassed; Cosmos EVM exploited across six blockchains; McKesson discloses theft of 284M patient records by ShinyHunters extortion group.
Hundreds of AI agents coordinated a breach of Hugging Face; Next.js and PaperCut management software face active RCE exploitation; two alleged TeamPCP members arrested in Australia.
Rust crate supply-chain poisoning (245M downloads); Russian cyber espionage hijacking OAuth accounts; Microsoft patches 398 flaws including active exploitation; AI-generated Siemens PLC exploits target U.S. critical infrastructure.
CISA added four actively exploited vulnerabilities affecting Microsoft IKE, VMware vCenter, SharePoint, Dahua devices compromised en masse, and healthcare breaches expose millions.
GitLab patched critical GraphQL flaw; Forminator WordPress plugin RCE affects 600K+ sites; threat actor claims 3.6M Azure account records stolen from Fortune 500 companies.
SharePoint CVE-2026-55040 (CVSS 9.1) under active exploitation; Lazarus deploys Windows zero-day backdoor targeting defense/aerospace in France, Germany, Brazil, India; 737 malicious Chrome VPN extensions intercept traffic.
CISA designated IBM Langflow (unauthenticated RCE), Apache Tomcat (encryption bypass), and N-able N-central (auth bypass) as actively exploited with federal remediation deadlines. Snowflake attacker pleads guilty to 165-organization breach; Ransom Cartel creator sentenced 16 years.
Ubuntu snap-confine LPE (CVE-2026-8933), Adobe Acrobat extension WhatsApp hijacking, and Windmill path traversal actively exploited. CISA adds four KEV flaws
Oracle PeopleSoft zero-day exploited at Nissan and NAIC; malicious Chrome extension intercepted searches and address bar input; Mustang Panda uses Zoho WorkDrive in Indian government campaigns.
ShapedPlugin WordPress Pro plugins backdoored via build-pipeline compromise, Dify AI platform has four cross-tenant data-exposure flaws, immediate deployment required.
GitHub suffered breach of 3,800+ internal repos via TeamPCP. Microsoft disrupted malware-signing operation. SonicWall VPN and Drupal require urgent patching.
FBI Director's email breached by Iran-linked hackers; critical Citrix and F5 vulnerabilities under active exploitation; wiper attacks target Stryker; nation-state exploit kits leaked publicly.
Iran-linked actors breached FBI Director Kash Patel's email and launched wiper attacks on Stryker. Critical Citrix and F5 vulnerabilities under active exploitation with no patches available.
Subscribe free and never miss a threat briefing.