Security Affairs
securityaffairs · C · active
Pierluigi Paganini's outlet; broad coverage. Listing surfaces dates and article URLs cleanly. Discovery-only; always trace to the primary report (vendor advisory, victim disclosure, regulator filing) before citing. | 2026-06-20 full audit (v2.62): live=Y, drill=Y. FETCH → webfetch https://securityaffairs.com/ (listing has titles+dates+article URLs), then WebFetch the article URL for the body. Discovery-only, trace to the primary source before citing.. AVOID: Don't cite securityaffairs directly in a brief, always pivot to the primary advisory/disclosure it links.. | 2026-07-05 admiralty audit: C (MEDIUM aligned to C), re-reporting/discovery outlet; always pivot to the primary advisory it links. Status stays active.
Cited in 27 entries
Citation cadence
Citation days per ISO week (19 weeks of coverage span, total 23).
- Revolut discloses a customer KYC data breach after fulfilling a fraudulent request sent from inside a genuine government agency's own email domain2026-09-13
- Berlin's state government confirms an extortion attempt after a phishing click opens the shared Landesnetz; media reporting names Rhysida2026-08-30
- Manchester Airports Group confirms a breach touching roughly 8.7 million customers across Manchester, Stansted and East Midlands, car-park, lounge and airport-WiFi sign-up data taken; FulcrumSec later claims credit and a client-side API-credential access vector2026-08-28
- PATCHCORD, SHEETCORD and HACKERAI; one espionage cluster runs three different command-and-control channels, two of them inside Google Sheets and GitHub, and persists by rewriting the victim's browser shortcuts2026-08-17
- CVE-2026-15409, SonicWall SMA1000: unauthenticated SSRF (CVSS 10.0) chained to post-auth code injection, actively exploited2026-07-14
- Microsoft July 2026 Patch Tuesday ships two actively-exploited zero-days, AD FS local EoP (CVE-2026-56155) and unauthenticated SharePoint EoP (CVE-2026-56164)2026-07-14
- Kairos data-theft-only extortion, a US county paid ~$1M with no ransomware encryptor ever recovered2026-07-05
- Oracle E-Business Suite CVE-2026-46817: pre-auth RCE in the Payments File Transmission servlet, first in-the-wild exploitation2026-07-01
- CVE-2026-46817, Oracle E-Business Suite (Oracle Payments): pre-auth RCE now exploited in the wild2026-07-01
- Aflac discloses a Japan-subsidiary breach, 4.38 million policyholders and agents, ~10-day dwell before detection2026-07-01
- KDDI third-party email platform breach exposes up to 14.22 million credentials across six Japanese ISPs2026-06-29
- Xsolis healthcare-AI vendor breach exposes 1.4M patients across seven US health systems, third-party processor pattern2026-06-24
- CVE-2026-48907, Widget Factory Joomla Content Editor (JCE) before version 2.9.99.5: unauthenticated profile-import → PHP RCE (CVSS v4 10.0)2026-06-17
- Handala breaches California Water Service through an internet-exposed RTKBase GNSS platform, billing PII for ~2M customers leaked, no OT access2026-06-15
- CVE-2026-20253, Splunk Enterprise: unauthenticated pre-auth RCE via the PostgreSQL sidecar proxy2026-06-14
- Novo Nordisk discloses theft of clinical-trial and healthcare-professional data2026-06-13
- CVE-2026-25089, Fortinet FortiSandbox: unauthenticated OS command injection in the web UI's VNC-launch handler (CVSS 9.8)2026-06-12
- Meta discloses 20,225 Instagram account takeovers via an AI support-tool logic flaw; Maine AG notification filed 8 June2026-06-10
- CVE-2026-10520 / CVE-2026-10523, Ivanti Sentry: pre-auth OS command injection to root (CVSS 10.0), public PoC published today2026-06-10
- Luna Moth / Silent Ransom Group (UNC3753): vishing-to-physical-access data-theft extortion against legal and professional services2026-06-06
- CVE-2024-21182, Oracle WebLogic Server: unauthenticated T3/IIOP data access, KEV-listed on active exploitation2026-06-03
- ShinyHunters Salesforce campaign; Charter and 7-Eleven both confirm; 7-Eleven count put at ~185,000 affected2026-05-27
- B1ack's Stash carding marketplace publicly releases 4.6M card records, SOCRadar attributes collection to e-skimming and phishing; not confirmed by issuing banks2026-05-21
- 7-Eleven confirms ShinyHunters breach of 600,000+ Salesforce franchise-application records, same campaign as Instructure, Vimeo, Wynn Resorts, Vercel, Medtronic2026-05-19
- CVE-2026-42945 NGINX Rift, in-the-wild exploitation confirmed by VulnCheck honeypots2026-05-18
- TrickMo "TrickMo C", Android banking trojan migrates C2 to The Open Network blockchain, adds SOCKS5 / SSH device-as-pivot2026-05-13
- Inditex (Zara), ShinyHunters publishes 140 GB; 197,400 EU customer records confirmed via third-party analytics compromise2026-05-09