Security News
Breach & incident coverage
Distinct breaches, incidents, and newly disclosed issues as they're reported — separate from the CVE-anchored advisories, which track confirmed exploited vulnerabilities specifically.
500 stories published
SleeperGem Software Supply Chain Attack Targets Ruby Ecosystem with Malicious Gems
Cybersecurity researchers have identified "SleeperGem," a new software supply chain attack using malicious RubyGems packages to deliver additional payloads.
Jul 20, 2026Craneware plc Reports Cyber Security Incident, Data Exfiltrated
Healthcare financial performance solutions provider Craneware plc has disclosed a cyber security incident involving unauthorized access and data exfiltration.
Jul 20, 2026Bath Fitter Distributing Discloses Data Breach Exposing Sensitive Customer Information
Bath Fitter Distributing, Inc. has announced a data breach affecting customer personal and financial information, including Social Security numbers.
Jul 20, 2026Hugging Face Breached by Autonomous AI Agent in Novel Attack
The AI platform Hugging Face experienced a security breach orchestrated by an autonomous AI agent, exploiting dataset pipeline vulnerabilities.
Jul 20, 2026CKR Consulting Engineers Hit by 'payload' Ransomware Group
CKR Consulting Engineers suffered a ransomware attack by the 'payload' group, leading to data breach and operational disruption.
Jul 20, 2026Ernst & Young Discloses Data Breach Exposing Client Tax and Financial Information
A data breach at Ernst & Young compromised sensitive client tax and financial information, including Social Security numbers and bank details, via a…
Jul 20, 2026Critical Microsoft Zero-Days Actively Exploited, CISA Issues Urgent Patching Directives
Microsoft's July 2026 Patch Tuesday addresses multiple zero-day vulnerabilities, including critical RCE and EoP flaws in SharePoint and AD FS actively…
Jul 20, 2026FortiBleed: 74,000 Fortinet Admin Credentials Cracked Post-Patching
Attackers cracked 74,000 Fortinet admin credentials from configuration backups, exploiting a failure to rotate passwords after patching.
Jul 20, 2026Independent Report Details Methods Used to Compromise Facebook Accounts
An independent investigation reveals various attack vectors used to compromise Facebook accounts, including large-scale takeovers and targeted espionage,…
Jul 19, 2026SonicWall SMA 1000 Appliances Patched Against Actively Exploited Zero-Days
SonicWall has released urgent patches for two actively exploited vulnerabilities (CVE-2026-15409, CVE-2026-15410) in its SMA 1000 Series appliances.
Jul 19, 2026Polymarket Suffers $3M Loss in Software Supply Chain Attack
A software supply chain attack against Polymarket, involving malicious JavaScript injected via a third-party vendor, resulted in a $3 million loss.
Jul 19, 2026VCA Animal Hospitals Discloses Data Breach Exposing Client Bank Details
VCA Animal Hospitals announced a data breach on June 19, 2026, where names and bank account details of clients were exposed.
Jul 19, 2026No news matches your search.