vulnerability Atlassian, Splunk Patch Dozens of Critical, High-Severity Vulnerabilities Atlassian and Splunk have released patches to address over 250 vulnerabilities across their products, including numerous critical and high-severity flaws in third-party dependencies. These updates aim to mitigate risks such as remote code execution, denial-of-service attacks, and credential theft, highlighting the ongo… SecurityWeek · Aug 20, 2026 High vulnerabilitypatchthird-party
data-breach Australian hotel chain leaks guests’ PII after breach at third-party database operator An Australian hotel chain suffered a data breach due to a vulnerability in a third-party database operator, resulting in the leakage of guests' Personally Identifiable Information (PII). The breach highlights the ongoing… The Register · Aug 19, 2026 Medium AUdata breachpiithird-party
threat-intel Beware cut-price AI services that read your every word A massive data breach occurred when hundreds of individuals paid exorbitant prices for discounted access to Anthropic's Claude AI model, exposing their personal data to malicious actors. The incident highlights the risks… Graham Cluley · Aug 7, 2026 High aidata-breachsecurity
threat-intel Polish convenience store chain Żabka hacked through third-party account Polish convenience store chain Żabka was hacked through a third-party contractor's account, leading to the potential exposure of internal data and systems. While payment systems and customer data were reportedly unaffect… The Record · Aug 4, 2026 Medium PLsupply-chainthird-partydata-breach
threat-intel Obsidian Security Raises $85 Million at $1.1 Billion Valuation Obsidian Security, a company specializing in AI agent security governance, has raised $85 million in a Series D funding round, valuing the company at $1.1 billion. The investment will fuel their expansion into governing… SecurityWeek · Aug 4, 2026 Medium aiagentic-aigovernance
threat-intel Charity bank pulls online services over third-party software flaw A charity bank in the UK has temporarily shut down its online services due to a vulnerability in third-party software. The issue stems from a flaw within a specific software component, leading to potential security risks… The Register · Jul 28, 2026 Medium vulnerabilitybankingsecurity
threat-intel EU Financial Institutions Leak Data Through Cookie Trackers European financial institutions are inadvertently exposing customer data to third-party advertising and analytics platforms through tracking pixels, even when users haven't consented to tracking. Jscrambler’s research re… Dark Reading · Jul 22, 2026 High FRPOSPdata-breachprivacygdpr
data-breach Hackers steal Lidl customer data from external service provider Lidl, a major European supermarket chain, suffered a data breach after attackers gained access to customer data stored by an external IT service provider. The stolen information included personal details like names, emai… The Record · Jul 13, 2026 Medium DEBENLdata breachcustomer dataretail
data-breach Scope of Salesforce Attacks Expands as Icarus Leaks Data A series of attacks originating from the Icarus extortion group have expanded the scope of breaches affecting Salesforce customers. Initially targeting Klue’s OAuth tokens, attackers leveraged this access to steal custom… Dark Reading · Jun 23, 2026 High USsalesforceoauthdata breach
threat-intel Salesforce Disables Klue App Integration After OAuth Token Abuse Exposes Customer Data Salesforce disabled the Klue Battlecards app integration following a security incident where the Icarus extortion group exploited compromised credentials to access customer data via Salesforce. The attackers leveraged a… The Hacker News · Jun 19, 2026 High USoauthcredentialdata-exfiltration
data-breach Nintendo confirms data stolen in WebMD subsidiary cyberattack Nintendo of America experienced a data breach following a cyberattack on its internal employee survey platform, TinyPulse, operated by WebMD’s subsidiary. Threat actor Shadowbyt3$ stole survey data and employee personal… BleepingComputer · Jun 18, 2026 High USemployee datasurvey dataransomware
other Microsoft confirms Office apps launch issues after June updates Microsoft is investigating a widespread issue affecting third-party applications after June 2026 updates to Windows, preventing them from launching or opening Microsoft Office applications. The problem stems from compati… BleepingComputer · Jun 17, 2026 Medium UScompatibilitywindows updateoffice apps
threat-intel What 345 Days of Untested Exposure Looks Like at a Bank This article details a significant security vulnerability stemming from a bank’s reliance on an annual penetration testing schedule, highlighting the risks associated with infrequent assessments. A VPN vulnerability, exp… BleepingComputer · Jun 3, 2026 High USvulnerabilityapitenant_id
threat-intel MyPillow listed on ransomware gang’s leak site, but denies it has been breached The Play ransomware gang claims to have stolen data from MyPillow, a US pillow manufacturer, and threatens to release it publicly. MyPillow denies the breach and claims it doesn't hold sensitive data internally, relying… Graham Cluley · May 28, 2026 High USransomwaredata-breachthird-party
supply-chain Hackers steal patient and billing data from German hospitals via third-party provider German hospitals are facing a significant patient data breach following an attack targeting Unimed, a third-party billing service provider. The attackers accessed sensitive patient information, including names, addresses… The Record · May 21, 2026 High DEdata-breachpatient-datathird-party
threat-intel The Boring Stuff Is Dangerous Now This article highlights a growing security challenge stemming from the widespread adoption of AI coding tools and the emergence of AI agents capable of exploiting obscure vulnerabilities. The combination creates a situat… Dark Reading · May 18, 2026 High aivulnerabilitycybersecurity