A critical security incident at Coder exposed users of its Terraform module registry to malicious packages designed to steal credentials from cloud development environments. The attack involved unauthorized changes to …
ShinyHunters Gained Access to 6 Million Customers’ Records Using a Single Call
A single phone call was all it took to trigger one of the largest data breaches in Dutch history. In early February 2026, Dutch telecom giant Odido and its budget …
Shai-Hulud npm Worm Resurfaces After 111 Days and Slips Past Malware Scanning
A familiar npm worm has returned after more than three months of silence, carrying the same malicious file linked to an earlier supply-chain incident. The reappearance shows how a known …
New InjectEave Attack Allows Hackers to Recover Audio Playing on Headphones from 30 Meters
Researchers have unveiled a novel electromagnetic (EM) attack called InjectEave that lets an adversary eavesdrop on audio playing through wired and wireless headphones from as far as 30 meters away, …
Bimbo Bakeries USA Confirms Data Breach in Oracle EBS Zero-Day Attack
Bimbo Bakeries USA, the American arm of the world’s largest baking company, has confirmed that hackers stole employee data by exploiting a zero-day vulnerability in Oracle’s E-Business Suite (EBS), joining …
Linux Rootkit Injects Fileless PHP Web Shells Into Compromised F5 BIG-IP Servers
A stealthy Linux rootkit is giving attackers a new way to keep control of compromised F5 BIG-IP Access Policy Manager servers. Instead of leaving an obvious malicious PHP file behind, …
Online Maths Learning Platform Mathspace Disclosed Data Breach Impacts 1 Million Users
Online maths learning platform Mathspace has confirmed a data breach that exposed the personal information of more than one million students, parents, guardians, and school staff across Australia and New …
Switzerland Moves Away From Microsoft 365 to Open-Source Alternatives
Switzerland’s federal administration is preparing to test a sovereign, open-source digital workplace that could reduce its long-term dependence on Microsoft 365 for sensitive government operations. The Swiss Federal Council was …
Hackers Abuse Trusted Google Services to Hide Credential-Stealing Phishing Attacks
Criminals are using trusted Google services as cover for a wide phishing campaign that steals corporate credentials and, in some cases, installs remote-access software. The malicious path runs through Google-owned …
Natural Resources Wales Exposes Sensitive Employee Data in Spreadsheet Breach
Natural Resources Wales has disclosed a personal data breach involving a spreadsheet containing sensitive diversity information belonging to former and current employees. The incident affected people employed by Natural Resources …
