Avada Builder WordPress plugin flaws allow site credential theft
Avada Builder plugin flaws expose database credentials and sensitive data on 1M+ WordPress sites, allowing attackers to achieve complete site takeover.
ACTIVE THREATS: Cisco FMC flaws exploited by ransomware gang, state-sponsored hackers • AI-powered attack exploited PaperCut flaws to hack 395 organizations • Microsoft Excel KB5002914 update breaks copy and paste for some users • Surfshark VPN says hackers breached internal testing, proxy servers • PaperCut Attacker Uses Hundreds of AI Agents to Compromise 440+ Instances ACTIVE THREATS: Cisco FMC flaws exploited by ransomware gang, state-sponsored hackers • AI-powered attack exploited PaperCut flaws to hack 395 organizations • Microsoft Excel KB5002914 update breaks copy and paste for some users • Surfshark VPN says hackers breached internal testing, proxy servers • PaperCut Attacker Uses Hundreds of AI Agents to Compromise 440+ Instances
Latest cybersecurity breaches news, analysis, and intelligence.
Avada Builder plugin flaws expose database credentials and sensitive data on 1M+ WordPress sites, allowing attackers to achieve complete site takeover.
**node-ipc npm package (690K weekly downloads) compromised with credential-stealing malware in three versions.** The attack automatically exfiltrates developer credentials via obfuscated DNS TXT queries, with no persistence mechanism—suggesting rapid theft was the sole objective.
Nvidia's GeForce NOW breach exposed millions via a regional partner, highlighting supply chain risks. Modern threats exploit interconnected cloud infrastructure faster than defenders can contain them.
REMUS has transformed into a commercial malware-as-a-service platform offering 24/7 support and ~90% callback rates, representing a shift toward legitimate-seeming cybercrime operations. The infostealer's rapid evolution signals a more resilient threat landscape where barriers to large-scale credent
Two OpenAI devices fell victim to a TanStack supply chain attack, exposing internal source code and credentials but no user data. The company revoked affected signing certificates, requiring macOS users to update ChatGPT Desktop and related apps before the old certificates are blocked on June 12.
TeamPCP is auctioning 450 stolen Mistral AI code repositories for $25,000, threatening public release if no buyer emerges within a week. The breach highlights vulnerabilities in AI supply chains and the lucrative market for proprietary training data.
OpenAI's devices were breached in the TanStack supply chain attack, affecting hundreds of npm and PyPI packages. The company rotated code-signing certificates, illustrating that even major tech firms face supply chain risks.
Ghostwriter targets Ukraine's government with geofenced spear-phishing PDFs that only activate for Ukrainian IPs, deploying PicassoLoader for reconnaissance and Cobalt Strike Beacon for exploitation.
AI hallucinations generate confident false intelligence that security teams act on without verification, creating operational threats. A 2025 benchmark found most AI models more likely to be confidently wrong than right—turning trusted AI tools into critical security vulnerabilities.
KongTuke impersonates IT on Teams to trick employees into running malicious PowerShell commands in under five minutes. They rotate Microsoft 365 tenants to avoid detection.
ShinyHunters' Canvas LMS breach hit 9,000 institutions and 30 million students during finals season—history's largest educational compromise. Attackers exploited unpatched secondary access despite remediation efforts.
Canvas experienced a service outage and data breach affecting millions of students. The House Committee on Homeland Security is demanding answers, treating educational tech infrastructure as a critical national security concern.
Nitrogen ransomware stole 8TB of confidential data from Foxconn, compromising Apple, Intel, Google, and other major tech clients. The breach included sensitive product designs and internal communications, posted on the darknet in March 2026.
MuddyWater (Iran-linked APT) compromised 9+ targets including South Korean electronics firms. The sophisticated campaign targeted industrial and government secrets using legitimate tools for intelligence gathering.
West Pharmaceutical Services suffered a cyberattack on May 4, 2026, with data exfiltration and system encryption. Manufacturing remains disrupted with no recovery timeline provided.
The Gentlemen ransomware gang was breached, exposing 16GB of malware code and communications for $10K. The gang hit 332 organizations in 2026, making them the second-most prolific operation worldwide.
Two threat groups use AI to automate cyberattacks on Latin American governments and banks. They generate custom hacking tools and social engineering tailored to each target in real-time.
Attackers are chaining small vulnerabilities across code, pipelines, and cloud infrastructure to bypass security tools. Alert fatigue leaves teams unable to spot these "lethal chains" connecting low-risk issues into critical threats.
Sophisticated cyberattacks now assume they'll breach networks, making prevention alone obsolete. Organizations must adopt integrated cyber resilience—combining defense, detection, backup, and rapid recovery—to survive inevitable breaches.
Anthropic's Mythos AI found thousands of exploits in weeks; real-world attacks already compromise thousands of devices in minutes using known bugs. Human patching cannot keep pace.
Security teams close remediation tickets without verifying fixes actually work. With exploits now preceding patches, confirming remediation effectiveness—not just deployment speed—is critical.
Alert fatigue blinds teams to real threats. Attackers exploit this by chaining minor vulnerabilities across code and infrastructure into "lethal chains"—attack paths isolated AppSec tools miss.
South Staffordshire Water Plc fined $1.3M for a 20-month data breach exposing 663,887 customers' and employees' data. The attack, linked to Cl0p ransomware, reveals critical infrastructure security gaps.
Škoda disclosed a breach exposing customer names, emails, orders, and password hashes via an e-commerce vulnerability. Credit card data stayed safe as third parties handle payments.
Instructure settled with ransomware group ShinyHunters to delete Canvas data from 9,000 schools and 275 million students, taking the platform offline during exam season. Experts doubt the deletion is verified and warn the deal sets a dangerous precedent for future attacks on critical education infra
BWH Hotels disclosed a six-month data breach (October 2025–April 2026) exposing guest names, emails, and reservation details across 4,000+ properties. Payment information was not compromised, though the total number of affected customers remains undisclosed.
Organizations are deploying agentic AI in production without meaningful security oversight. Security professionals lack the technical fluency to defend these systems, risking systematic bypass by engineering teams—repeating the pattern from firewalls and cloud security where deep understanding must
Despite unprecedented visibility, SOCs systematically fail to investigate critical threats from WAF, DLP, OT, and dark web signals. The root cause is structural—not tool gaps—and affects all delivery models equally.
**Shai Hulud compromised 400+ npm/PyPI packages with credential-stealing malware, using valid cryptographic signatures to evade detection.** The attack exposed a critical gap between code verification and actual integrity, targeting GitHub tokens, AWS credentials, Kubernetes, and crypto wallets.
Canvas LMS breach exposed 275M records from 9,000 schools. Instructure paid ShinyHunters ransom to prevent data publication after attackers exploited a Free-for-Teacher vulnerability.