Security Affairs
securityaffairs · C · active
Pierluigi Paganini's outlet; broad coverage. Listing surfaces dates and article URLs cleanly. Discovery-only — always trace to the primary report (vendor advisory, victim disclosure, regulator filing) before citing. | 2026-06-20 full audit (v2.62): live=Y, drill=Y. FETCH → webfetch https://securityaffairs.com/ (listing has titles+dates+article URLs), then WebFetch the article URL for the body. Discovery-only — trace to the primary source before citing.. AVOID: Don't cite securityaffairs directly in a brief — always pivot to the primary advisory/disclosure it links.. | 2026-07-05 admiralty audit: C (MEDIUM aligned to C) — re-reporting/discovery outlet; always pivot to the primary advisory it links. Status stays active.
Cited in 31 entries
Citation cadence
Citation days per ISO week (12 weeks of coverage span, total 21).
- CVE-2026-50522 — SharePoint Server pre-auth deserialization RCE moves to active exploitation via public PoC; attackers steal machine keys for persistent forged authentication2026-07-22
- Two internet-facing Oracle enterprise product lines were under active exploitation this week — E-Business Suite RCE joins the PeopleSoft campaign2026-07-05
- Kairos data-theft-only extortion — a US county paid ~$1M with no ransomware encryptor ever recovered2026-07-05
- Oracle E-Business Suite CVE-2026-46817: pre-auth RCE in the Payments File Transmission servlet, first in-the-wild exploitation2026-07-01
- CVE-2026-46817 — Oracle E-Business Suite (Oracle Payments): pre-auth RCE now exploited in the wild2026-07-01
- Aflac discloses a Japan-subsidiary breach — 4.38 million policyholders and agents, ~10-day dwell before detection2026-07-01
- KDDI third-party email platform breach exposes up to 14.22 million credentials across six Japanese ISPs2026-06-29
- FortiBleed2026-06-29
- Xsolis healthcare-AI vendor breach exposes 1.4M patients across seven US health systems — third-party processor pattern2026-06-24
- CVE-2026-25089 / CVE-2026-39808 / CVE-2026-39813 — FortiSandbox: three critical flaws exploited in one 24-hour window2026-06-22
- FortiSandbox — three critical flaws now exploited simultaneously, including the previously disclosure-only CVE-2026-250892026-06-17
- CVE-2026-48907 — Widget Factory Joomla Content Editor (JCE) before version 2.9.99.5: unauthenticated profile-import → PHP RCE (CVSS v4 10.0)2026-06-17
- Novo Nordisk clarifies stolen-data scope — non-pseudonymised HCP data in play2026-06-16
- Handala breaches California Water Service through an internet-exposed RTKBase GNSS platform — billing PII for ~2M customers leaked, no OT access2026-06-15
- Ivanti Sentry CVE-2026-10520 — exploitation confirmed in the wild, gateways backdoored2026-06-14
- CVE-2026-20253 — Splunk Enterprise: unauthenticated pre-auth RCE via the PostgreSQL sidecar proxy2026-06-14
- CVE-2026-10520 / CVE-2026-10523 — Ivanti Sentry: pre-auth command injection to root, now confirmed exploited and gateways backdoored2026-06-14
- Meta discloses 20,225 Instagram account takeovers via an AI support-tool logic flaw; Maine AG notification filed 8 June2026-06-10
- Luna Moth / Silent Ransom Group (UNC3753): vishing-to-physical-access data-theft extortion against legal and professional services2026-06-06
- CVE-2024-21182 — Oracle WebLogic Server: unauthenticated T3/IIOP data access, KEV-listed on active exploitation2026-06-03
- ShinyHunters publishes the Charter Communications dataset after ransom refusal2026-06-02
- Public sector — most-targeted sector this week by volume and by operational severity2026-06-01
- Luna Moth / UNC3753: vishing-to-physical-USB data-theft extortion reaches ~$20 M suppression payment and DNS fast-flux C22026-06-01
- ENISA NIS360 2026 (3rd edition) — seven sectors in the persistent risk zone where criticality outpaces maturity2026-06-01
- B1ack's Stash carding marketplace publicly releases 4.6M card records — SOCRadar attributes collection to e-skimming and phishing; not confirmed by issuing banks2026-05-21
- 7-Eleven confirms ShinyHunters breach of 600,000+ Salesforce franchise-application records — same campaign as Instructure, Vimeo, Wynn Resorts, Vercel, Medtronic2026-05-19
- CVE-2026-42945 NGINX Rift — in-the-wild exploitation confirmed by VulnCheck honeypots2026-05-18
- TrickMo "TrickMo C" — Android banking trojan migrates C2 to The Open Network blockchain, adds SOCKS5 / SSH device-as-pivot2026-05-13
- Inditex (Zara) — ShinyHunters publishes 140 GB; 197,400 EU customer records confirmed via third-party analytics compromise2026-05-09
- ShinyHunters / WorldLeaks — week-long cross-incident operator activity touching Inditex, Vimeo, ADT, and Instructure / Canvas2026-05-04
- ShinyHunters / WorldLeaks family (financial-data extortion, third-party-SaaS pivot)2026-05-04