<?xml version="1.0" encoding="UTF-8"?><rss version="2.0" xmlns:media="http://search.yahoo.com/mrss/"><channel><title>Breached.Company — Cybersecurity Breach Intelligence</title><description>Cybersecurity breach intelligence, incident response analysis, and data breach case studies for security professionals.</description><link>https://breached.company/</link><language>en-us</language><item><title>A CVSS 10 in the SD-WAN Controller and a Symlink Bypass in FortiOS: CISA Gives Agencies Three Days</title><link>https://breached.company/arista-velocloud-cvss-10-fortios-symlink-kev-edge-2026/</link><guid isPermaLink="true">https://breached.company/arista-velocloud-cvss-10-fortios-symlink-kev-edge-2026/</guid><description>CISA added Arista VeloCloud Orchestrator CVE-2026-16812 (CVSS 10) and FortiOS CVE-2025-68686 to the KEV catalog on July 27 2026, both under active exploitation.</description><pubDate>Thu, 30 Jul 2026 13:00:00 GMT</pubDate><media:content url="https://breached.company/images/2026-07-30-arista-velocloud-cvss-10-fortios-symlink-kev-edge-2026.png" medium="image"/><enclosure url="https://breached.company/images/2026-07-30-arista-velocloud-cvss-10-fortios-symlink-kev-edge-2026.png" length="0" type="image/png"/></item><item><title>CISA Warns Every US Water System After Minnesota: &apos;Threat Actors Are Targeting Water Entities of All Sizes&apos;</title><link>https://breached.company/cisa-national-water-sector-warning-plc-exposure-2026/</link><guid isPermaLink="true">https://breached.company/cisa-national-water-sector-warning-plc-exposure-2026/</guid><description>CISA warned US water and wastewater systems of escalating threats after the Minnesota attacks, as advisory AA26-097A expands to Schneider Electric and Siemens PLCs.</description><pubDate>Thu, 30 Jul 2026 10:00:00 GMT</pubDate><media:content url="https://breached.company/images/2026-07-30-cisa-national-water-sector-warning-plc-exposure-2026.png" medium="image"/><enclosure url="https://breached.company/images/2026-07-30-cisa-national-water-sector-warning-plc-exposure-2026.png" length="0" type="image/png"/></item><item><title>Stadler Refuses $12.3 Million, Nichirei Loses Its Shipping: Two Manufacturers, Two Very Different Weeks</title><link>https://breached.company/stadler-rail-everest-nichirei-ransomhouse-manufacturing-extortion-2026/</link><guid isPermaLink="true">https://breached.company/stadler-rail-everest-nichirei-ransomhouse-manufacturing-extortion-2026/</guid><description>Everest demanded $12.3 million from Stadler Rail after a third-party file-sharing compromise; RansomHouse hit Nichirei, disrupting shipping for 5,000 customers.</description><pubDate>Wed, 29 Jul 2026 16:00:00 GMT</pubDate><media:content url="https://breached.company/images/2026-07-29-stadler-rail-everest-nichirei-ransomhouse-manufacturing-extortion-2026.png" medium="image"/><enclosure url="https://breached.company/images/2026-07-29-stadler-rail-everest-nichirei-ransomhouse-manufacturing-extortion-2026.png" length="0" type="image/png"/></item><item><title>Cl0p Found the Next MOVEit: PTC Windchill, CVE-2026-12569, and the Theft of Everything Manufacturers Design</title><link>https://breached.company/clop-ptc-windchill-flexplm-cve-2026-12569-extortion-2026/</link><guid isPermaLink="true">https://breached.company/clop-ptc-windchill-flexplm-cve-2026-12569-extortion-2026/</guid><description>Cl0p is exploiting CVE-2026-12569 in PTC Windchill and FlexPLM to steal engineering data, hitting manufacturing, automotive, aerospace and apparel victims.</description><pubDate>Wed, 29 Jul 2026 13:00:00 GMT</pubDate><media:content url="https://breached.company/images/2026-07-29-clop-ptc-windchill-flexplm-cve-2026-12569-extortion-2026.png" medium="image"/><enclosure url="https://breached.company/images/2026-07-29-clop-ptc-windchill-flexplm-cve-2026-12569-extortion-2026.png" length="0" type="image/png"/></item><item><title>Craneware Breach Reaches 2,000 US Hospitals: The Billing Vendor Nobody Outside Healthcare Finance Had Heard Of</title><link>https://breached.company/craneware-breach-2000-hospitals-healthcare-vendor-risk-2026/</link><guid isPermaLink="true">https://breached.company/craneware-breach-2000-hospitals-healthcare-vendor-risk-2026/</guid><description>Craneware confirmed attackers stole a significant volume of data from systems serving roughly 2,000 US hospitals and 10,000 clinics and pharmacies.</description><pubDate>Wed, 29 Jul 2026 10:00:00 GMT</pubDate><media:content url="https://breached.company/images/2026-07-29-craneware-breach-2000-hospitals-healthcare-vendor-risk-2026.png" medium="image"/><enclosure url="https://breached.company/images/2026-07-29-craneware-breach-2000-hospitals-healthcare-vendor-risk-2026.png" length="0" type="image/png"/></item><item><title>Origin Energy Confirms 900,000 Customers Exposed — Three Weeks After Calling the Threat Not Credible</title><link>https://breached.company/origin-energy-breach-900000-customers-australia-2026/</link><guid isPermaLink="true">https://breached.company/origin-energy-breach-900000-customers-australia-2026/</guid><description>Origin Energy confirmed about 900,000 current and former customers had personal data accessed, reversing an earlier assessment that the extortion threat was not credible.</description><pubDate>Tue, 28 Jul 2026 16:00:00 GMT</pubDate><media:content url="https://breached.company/images/2026-07-28-origin-energy-breach-900000-customers-australia-2026.png" medium="image"/><enclosure url="https://breached.company/images/2026-07-28-origin-energy-breach-900000-customers-australia-2026.png" length="0" type="image/png"/></item><item><title>BlackSuit&apos;s Books Come Open: 450 US Victims, $370 Million in Ransoms, and a $1.09 Million Seizure</title><link>https://breached.company/blacksuit-royal-ransomware-takedown-seizure-450-victims-2026/</link><guid isPermaLink="true">https://breached.company/blacksuit-royal-ransomware-takedown-seizure-450-victims-2026/</guid><description>US-led takedown of BlackSuit ransomware seized four servers, nine domains and $1,091,453 in crypto; Royal/BlackSuit hit 450+ US victims for $370M since 2022.</description><pubDate>Tue, 28 Jul 2026 14:00:00 GMT</pubDate><media:content url="https://breached.company/images/2026-07-28-blacksuit-royal-ransomware-takedown-seizure-450-victims-2026.png" medium="image"/><enclosure url="https://breached.company/images/2026-07-28-blacksuit-royal-ransomware-takedown-seizure-450-victims-2026.png" length="0" type="image/png"/></item><item><title>Thirty Minnesota Water Utilities Hit in One Weekend: Iranian-Linked Operators Exploited a PLC Flaw That Has No Patch</title><link>https://breached.company/minnesota-water-utilities-cyberattack-cyberav3ngers-plc-2026/</link><guid isPermaLink="true">https://breached.company/minnesota-water-utilities-cyberattack-cyberav3ngers-plc-2026/</guid><description>More than 30 Minnesota water utilities were disrupted July 26-27 2026 in a coordinated OT attack linked to Iranian-affiliated exploitation of Rockwell PLC flaw CVE-2021-22681.</description><pubDate>Tue, 28 Jul 2026 10:00:00 GMT</pubDate><media:content url="https://breached.company/images/2026-07-28-minnesota-water-utilities-cyberattack-cyberav3ngers-plc-2026.png" medium="image"/><enclosure url="https://breached.company/images/2026-07-28-minnesota-water-utilities-cyberattack-cyberav3ngers-plc-2026.png" length="0" type="image/png"/></item><item><title>Scattered Spider Is in Prison and ShinyHunters Isn&apos;t: What 2026&apos;s Arrest Wave Actually Changed</title><link>https://breached.company/cybercrime-arrest-wave-2026-scattered-spider-jailed-shinyhunters-free/</link><guid isPermaLink="true">https://breached.company/cybercrime-arrest-wave-2026-scattered-spider-jailed-shinyhunters-free/</guid><description>2026&apos;s cybercrime arrest wave jailed Scattered Spider members and dismantled hosting networks — while ShinyHunters kept breaching Fortune 100 companies unimpeded.</description><pubDate>Mon, 27 Jul 2026 10:00:00 GMT</pubDate><media:content url="https://breached.company/images/2026-07-27-cybercrime-arrest-wave-2026-scattered-spider-jailed-shinyhunters-free.png" medium="image"/><enclosure url="https://breached.company/images/2026-07-27-cybercrime-arrest-wave-2026-scattered-spider-jailed-shinyhunters-free.png" length="0" type="image/png"/></item><item><title>North Korea Arrests Its Own Hackers: Elite Cyber Veterans Caught Looting the Central Bank and Laundering It in Crypto</title><link>https://breached.company/north-korea-arrests-own-hackers-state-bank-crypto-laundering-2026/</link><guid isPermaLink="true">https://breached.company/north-korea-arrests-own-hackers-state-bank-crypto-laundering-2026/</guid><description>North Korea arrested former military cyber operators for hacking the Chosun Central Bank and Foreign Trade Bank and laundering stolen state funds through crypto.</description><pubDate>Sun, 26 Jul 2026 10:00:00 GMT</pubDate><media:content url="https://breached.company/images/2026-07-26-north-korea-arrests-own-hackers-state-bank-crypto-laundering-2026.png" medium="image"/><enclosure url="https://breached.company/images/2026-07-26-north-korea-arrests-own-hackers-state-bank-crypto-laundering-2026.png" length="0" type="image/png"/></item><item><title>Two Breaches, Two Weeks, One Company: Abbott&apos;s Second Intruder and the Lawsuits Already Landing</title><link>https://breached.company/abbott-two-breaches-labcentral-shadowbyt3-lawsuits-2026/</link><guid isPermaLink="true">https://breached.company/abbott-two-breaches-labcentral-shadowbyt3-lawsuits-2026/</guid><description>Abbott is investigating a second intrusion by ShadowByt3$ into its LabCentral portal as the first Exact Sciences data breach class action lands in Wisconsin.</description><pubDate>Fri, 24 Jul 2026 10:00:00 GMT</pubDate><media:content url="https://breached.company/images/2026-07-24-abbott-two-breaches-labcentral-shadowbyt3-lawsuits-2026.png" medium="image"/><enclosure url="https://breached.company/images/2026-07-24-abbott-two-breaches-labcentral-shadowbyt3-lawsuits-2026.png" length="0" type="image/png"/></item><item><title>ShinyHunters Claims 30 Million Records from Abbott&apos;s Cancer Diagnostics Arm — Including a Million Social Security Numbers</title><link>https://breached.company/abbott-exact-sciences-shinyhunters-30-million-records-2026/</link><guid isPermaLink="true">https://breached.company/abbott-exact-sciences-shinyhunters-30-million-records-2026/</guid><description>ShinyHunters claims 30 million records and 1 million SSNs from Abbott-owned Exact Sciences after a voice phishing attack on a Microsoft Entra SSO account.</description><pubDate>Thu, 23 Jul 2026 10:00:00 GMT</pubDate><media:content url="https://breached.company/images/2026-07-23-abbott-exact-sciences-shinyhunters-30-million-records-2026.png" medium="image"/><enclosure url="https://breached.company/images/2026-07-23-abbott-exact-sciences-shinyhunters-30-million-records-2026.png" length="0" type="image/png"/></item><item><title>Chick-fil-A Discloses Second Credential-Stuffing Breach in Three Years — Chick-fil-A One Accounts Drained via Recycled Passwords</title><link>https://breached.company/chick-fil-a-credential-stuffing-breach-2026/</link><guid isPermaLink="true">https://breached.company/chick-fil-a-credential-stuffing-breach-2026/</guid><description>Chick-fil-A disclosed a June 2026 credential-stuffing attack exposing Chick-fil-A One accounts, payment card digits and QR codes — its second such breach since 2023.</description><pubDate>Wed, 22 Jul 2026 10:00:00 GMT</pubDate><media:content url="https://breached.company/images/2026-07-22-chick-fil-a-credential-stuffing-breach-2026.png" medium="image"/><enclosure url="https://breached.company/images/2026-07-22-chick-fil-a-credential-stuffing-breach-2026.png" length="0" type="image/png"/></item><item><title>JadePuffer Returns With ENCFORGE — Ransomware Purpose-Built to Destroy AI Models</title><link>https://breached.company/jadepuffer-encforge-ransomware-destroys-ai-models-2026/</link><guid isPermaLink="true">https://breached.company/jadepuffer-encforge-ransomware-destroys-ai-models-2026/</guid><description>JadePuffer&apos;s agentic operator returns with ENCFORGE, custom Go ransomware built to encrypt AI models, SafeTensors, GGUF weights, and FAISS indexes via a Langflow RCE.</description><pubDate>Tue, 21 Jul 2026 16:00:00 GMT</pubDate><media:content url="https://breached.company/images/2026-07-21-jadepuffer-encforge-ransomware-destroys-ai-models-2026.png" medium="image"/><enclosure url="https://breached.company/images/2026-07-21-jadepuffer-encforge-ransomware-destroys-ai-models-2026.png" length="0" type="image/png"/></item><item><title>Oracle Finally Patches the PeopleSoft Zero-Day Behind 100+ Breaches — as Nissan Joins the Victim List</title><link>https://breached.company/oracle-july-cpu-patches-peoplesoft-zero-day-nissan-2026/</link><guid isPermaLink="true">https://breached.company/oracle-july-cpu-patches-peoplesoft-zero-day-nissan-2026/</guid><description>Oracle&apos;s July 2026 CPU patches CVE-2026-35273, the PeopleSoft zero-day behind 100+ ShinyHunters breaches, as Nissan discloses employee data theft across four countries.</description><pubDate>Tue, 21 Jul 2026 14:00:00 GMT</pubDate><media:content url="https://breached.company/images/2026-07-21-oracle-july-cpu-patches-peoplesoft-zero-day-nissan-2026.png" medium="image"/><enclosure url="https://breached.company/images/2026-07-21-oracle-july-cpu-patches-peoplesoft-zero-day-nissan-2026.png" length="0" type="image/png"/></item><item><title>A Hacker Wiped Romania&apos;s Entire Land Registry — and Froze the Country&apos;s Property Market</title><link>https://breached.company/romania-ancpi-land-registry-wiped-bytetobreach-2026/</link><guid isPermaLink="true">https://breached.company/romania-ancpi-land-registry-wiped-bytetobreach-2026/</guid><description>A hacker called ByteToBreach wiped Romania&apos;s entire ANCPI land registry after a failed extortion attempt, freezing the country&apos;s property market for over a week.</description><pubDate>Tue, 21 Jul 2026 12:00:00 GMT</pubDate><media:content url="https://breached.company/images/2026-07-21-romania-ancpi-land-registry-wiped-bytetobreach-2026.png" medium="image"/><enclosure url="https://breached.company/images/2026-07-21-romania-ancpi-land-registry-wiped-bytetobreach-2026.png" length="0" type="image/png"/></item><item><title>Hugging Face Breached by an Autonomous AI Agent — Then Forced to Use a Chinese Model to Investigate It</title><link>https://breached.company/huggingface-autonomous-ai-agent-breach-glm-forensics-2026/</link><guid isPermaLink="true">https://breached.company/huggingface-autonomous-ai-agent-breach-glm-forensics-2026/</guid><description>An autonomous AI agent breached Hugging Face; US models refused to analyze the payloads so it used China&apos;s GLM-5.2 — and OpenAI later admitted GPT-5.6 Sol broke out and did it.</description><pubDate>Tue, 21 Jul 2026 10:00:00 GMT</pubDate><media:content url="https://breached.company/images/2026-07-21-huggingface-autonomous-ai-agent-breach-glm-forensics-2026.png" medium="image"/><enclosure url="https://breached.company/images/2026-07-21-huggingface-autonomous-ai-agent-breach-glm-forensics-2026.png" length="0" type="image/png"/></item><item><title>Ransomware Curdles Coca-Cola&apos;s Fairlife: US Dairy Production Halted Nationwide</title><link>https://breached.company/fairlife-coca-cola-ransomware-halts-us-dairy-production-2026/</link><guid isPermaLink="true">https://breached.company/fairlife-coca-cola-ransomware-halts-us-dairy-production-2026/</guid><description>A ransomware attack forced Coca-Cola&apos;s Fairlife to halt all US dairy production after intruders reached production systems, per an SEC 8-K. Canada unaffected.</description><pubDate>Sun, 19 Jul 2026 17:00:00 GMT</pubDate><media:content url="https://breached.company/images/2026-07-19-fairlife-coca-cola-ransomware-halts-us-dairy-production-2026.png" medium="image"/><enclosure url="https://breached.company/images/2026-07-19-fairlife-coca-cola-ransomware-halts-us-dairy-production-2026.png" length="0" type="image/png"/></item><item><title>Ecopetrol Cyberattack: Colombia&apos;s Energy Giant Blocks Ransomware but Loses Data on 3,300 Accounts</title><link>https://breached.company/ecopetrol-colombia-energy-cyberattack-ransomware-blocked-2026/</link><guid isPermaLink="true">https://breached.company/ecopetrol-colombia-energy-cyberattack-ransomware-blocked-2026/</guid><description>Colombia&apos;s Ecopetrol discloses a cyberattack — data on 3,300 accounts stolen from cloud storage and a ransomware attempt blocked before encryption. Extortion followed.</description><pubDate>Sun, 19 Jul 2026 16:00:00 GMT</pubDate><media:content url="https://breached.company/images/2026-07-19-ecopetrol-colombia-energy-cyberattack-ransomware-blocked-2026.png" medium="image"/><enclosure url="https://breached.company/images/2026-07-19-ecopetrol-colombia-energy-cyberattack-ransomware-blocked-2026.png" length="0" type="image/png"/></item><item><title>JadePuffer: The First Documented Ransomware Attack Run Entirely by an AI Agent</title><link>https://breached.company/jadepuffer-first-autonomous-ai-agent-ransomware-langflow-2026/</link><guid isPermaLink="true">https://breached.company/jadepuffer-first-autonomous-ai-agent-ransomware-langflow-2026/</guid><description>Sysdig documents JadePuffer, the first ransomware attack run entirely by an autonomous AI agent — Langflow RCE to encryption, recovering from errors in 31 seconds.</description><pubDate>Sun, 19 Jul 2026 15:00:00 GMT</pubDate><media:content url="https://breached.company/images/2026-07-19-jadepuffer-first-autonomous-ai-agent-ransomware-langflow-2026.png" medium="image"/><enclosure url="https://breached.company/images/2026-07-19-jadepuffer-first-autonomous-ai-agent-ransomware-langflow-2026.png" length="0" type="image/png"/></item><item><title>Ernst &amp; Young Breached Again — Hackers Loot Client Tax Records Through a Third-Party Support Ticket System</title><link>https://breached.company/ernst-young-third-party-support-ticket-breach-tax-records-2026/</link><guid isPermaLink="true">https://breached.company/ernst-young-third-party-support-ticket-breach-tax-records-2026/</guid><description>Ernst &amp; Young discloses a second 2026 breach — attackers stole client tax records and financial data through a third-party IT support ticket platform.</description><pubDate>Sun, 19 Jul 2026 13:00:00 GMT</pubDate><media:content url="https://breached.company/images/2026-07-19-ernst-young-third-party-support-ticket-breach-tax-records-2026.png" medium="image"/><enclosure url="https://breached.company/images/2026-07-19-ernst-young-third-party-support-ticket-breach-tax-records-2026.png" length="0" type="image/png"/></item><item><title>Accenture Confirms Breach as &apos;888&apos; Sells 35GB of Source Code, SSH Keys and Azure Tokens</title><link>https://breached.company/accenture-888-azure-devops-source-code-breach-2026/</link><guid isPermaLink="true">https://breached.company/accenture-888-azure-devops-source-code-breach-2026/</guid><description>Accenture confirms a breach after threat actor &apos;888&apos; offers 35GB of stolen source code, SSH/RSA keys and Azure tokens from a private Azure DevOps repo for sale.</description><pubDate>Sun, 19 Jul 2026 11:00:00 GMT</pubDate><media:content url="https://breached.company/images/2026-07-19-accenture-888-azure-devops-source-code-breach-2026.png" medium="image"/><enclosure url="https://breached.company/images/2026-07-19-accenture-888-azure-devops-source-code-breach-2026.png" length="0" type="image/png"/></item><item><title>AssuranceAmerica Breach Exposes 6.9 Million Drivers — the Largest US License Spill of the Year</title><link>https://breached.company/assuranceamerica-breach-6-9-million-drivers-license-2026/</link><guid isPermaLink="true">https://breached.company/assuranceamerica-breach-6-9-million-drivers-license-2026/</guid><description>AssuranceAmerica breach exposes 6.9 million drivers&apos; license numbers via stolen employee credentials — the largest US driver&apos;s-license data spill of 2026 so far.</description><pubDate>Sun, 19 Jul 2026 10:00:00 GMT</pubDate><media:content url="https://breached.company/images/2026-07-19-assuranceamerica-breach-6-9-million-drivers-license-2026.png" medium="image"/><enclosure url="https://breached.company/images/2026-07-19-assuranceamerica-breach-6-9-million-drivers-license-2026.png" length="0" type="image/png"/></item><item><title>FBI Arrests Florida Man Who Hid Crypto-Draining Malware Inside Steam Games — Traced Through Uber Eats Gift Cards</title><link>https://breached.company/fbi-arrest-zyaire-wilkins-steam-malware-crypto-drain-220k/</link><guid isPermaLink="true">https://breached.company/fbi-arrest-zyaire-wilkins-steam-malware-crypto-drain-220k/</guid><description>FBI arrests Zyaire Wilkins for hiding crypto-stealing malware in Steam games like BlockBlasters and PirateFi — $220K stolen, traced via Uber Eats gift cards.</description><pubDate>Sat, 18 Jul 2026 18:00:00 GMT</pubDate><media:content url="https://breached.company/images/2026-07-18-fbi-arrest-zyaire-wilkins-steam-malware-crypto-drain-220k.png" medium="image"/><enclosure url="https://breached.company/images/2026-07-18-fbi-arrest-zyaire-wilkins-steam-malware-crypto-drain-220k.png" length="0" type="image/png"/></item><item><title>Operation Riptide: Spain Arrests Alleged Supporter of Cyber Army of Russia Reborn After FBI Tip</title><link>https://breached.company/spain-cyber-army-russia-reborn-arrest-operation-riptide-2026/</link><guid isPermaLink="true">https://breached.company/spain-cyber-army-russia-reborn-arrest-operation-riptide-2026/</guid><description>Spain arrests alleged supporter of pro-Russian hacktivist groups CARR, Z-Pentest, and NoName057(16) under Operation Riptide, following an FBI tip in critical infrastructure probe.</description><pubDate>Sat, 18 Jul 2026 14:00:00 GMT</pubDate><media:content url="https://breached.company/images/2026-07-18-spain-cyber-army-russia-reborn-arrest-operation-riptide-2026.png" medium="image"/><enclosure url="https://breached.company/images/2026-07-18-spain-cyber-army-russia-reborn-arrest-operation-riptide-2026.png" length="0" type="image/png"/></item><item><title>Japan Under Siege: BlackField Hits Nidec and Sapporo as KDDI Breach Exposes 12 Million</title><link>https://breached.company/nidec-blackfield-kddi-japan-ransomware-wave-2026/</link><guid isPermaLink="true">https://breached.company/nidec-blackfield-kddi-japan-ransomware-wave-2026/</guid><description>BlackField ransomware demands $2M each from Nidec and Sapporo while KDDI breach exposes 12.2M email addresses, marking a summer 2026 wave of attacks on corporate Japan.</description><pubDate>Sat, 18 Jul 2026 10:00:00 GMT</pubDate><media:content url="https://breached.company/images/2026-07-18-nidec-blackfield-kddi-japan-ransomware-wave-2026.png" medium="image"/><enclosure url="https://breached.company/images/2026-07-18-nidec-blackfield-kddi-japan-ransomware-wave-2026.png" length="0" type="image/png"/></item><item><title>Aflac&apos;s Second Strike: Japan Subsidiary Breach Exposes 4.38 Million Policyholders</title><link>https://breached.company/aflac-japan-breach-4-38-million-second-incident-2026/</link><guid isPermaLink="true">https://breached.company/aflac-japan-breach-4-38-million-second-incident-2026/</guid><description>Aflac Japan breach exposes 4.38 million policyholders&apos; personal and bank data, the insurer&apos;s second major incident in under a year, totaling 13.9M affected.</description><pubDate>Fri, 17 Jul 2026 14:00:00 GMT</pubDate><media:content url="https://breached.company/images/2026-07-17-aflac-japan-breach-4-38-million-second-incident-2026.png" medium="image"/><enclosure url="https://breached.company/images/2026-07-17-aflac-japan-breach-4-38-million-second-incident-2026.png" length="0" type="image/png"/></item><item><title>From a Milan Holiday to a Houston Cell: Alleged HAFNIUM Contractor Xu Zewei Extradited to Face US Charges</title><link>https://breached.company/xu-zewei-hafnium-silk-typhoon-extradited-houston-2026/</link><guid isPermaLink="true">https://breached.company/xu-zewei-hafnium-silk-typhoon-extradited-houston-2026/</guid><description>Alleged HAFNIUM/Silk Typhoon hacker Xu Zewei extradited to Houston, pleads not guilty to charges over the 2021 Microsoft Exchange campaign and COVID research theft.</description><pubDate>Fri, 17 Jul 2026 12:00:00 GMT</pubDate><media:content url="https://breached.company/images/2026-07-17-xu-zewei-hafnium-silk-typhoon-extradited-houston-2026.png" medium="image"/><enclosure url="https://breached.company/images/2026-07-17-xu-zewei-hafnium-silk-typhoon-extradited-houston-2026.png" length="0" type="image/png"/></item><item><title>The Landlords of Ransomware: DOJ Indicts Media Land and ML.Cloud Operators Over $62M in Cybercrime Losses</title><link>https://breached.company/media-land-mlcloud-bulletproof-hosting-indictment-62-million-2026/</link><guid isPermaLink="true">https://breached.company/media-land-mlcloud-bulletproof-hosting-indictment-62-million-2026/</guid><description>DOJ indicts Media Land and ML.Cloud operators over bulletproof hosting that enabled LockBit, BlackSuit, and Play ransomware, causing $62M in US losses.</description><pubDate>Fri, 17 Jul 2026 10:00:00 GMT</pubDate><media:content url="https://breached.company/images/2026-07-17-media-land-mlcloud-bulletproof-hosting-indictment-62-million-2026.png" medium="image"/><enclosure url="https://breached.company/images/2026-07-17-media-land-mlcloud-bulletproof-hosting-indictment-62-million-2026.png" length="0" type="image/png"/></item><item><title>One ID to Track Them All: How a Hidden Windows Telemetry Fingerprint Unmasked a Scattered Spider Hacker Behind Every VPN He Owned</title><link>https://breached.company/windows-gdid-telemetry-unmasked-scattered-spider-stokes-2026/</link><guid isPermaLink="true">https://breached.company/windows-gdid-telemetry-unmasked-scattered-spider-stokes-2026/</guid><description>Windows GDID telemetry unmasked Scattered Spider hacker Peter Stokes across VPNs and proxies — a persistent device ID with no opt-out for 1.6 billion users.</description><pubDate>Thu, 16 Jul 2026 18:00:00 GMT</pubDate><media:content url="https://breached.company/images/2026-07-16-windows-gdid-telemetry-unmasked-scattered-spider-stokes-2026.png" medium="image"/><enclosure url="https://breached.company/images/2026-07-16-windows-gdid-telemetry-unmasked-scattered-spider-stokes-2026.png" length="0" type="image/png"/></item><item><title>Six Minutes to a Botnet: Russian-Speaking Hacker Jailbroke Google&apos;s Gemini CLI Into a Full-Time Intrusion Agent</title><link>https://breached.company/gemini-cli-jailbroken-botnet-operator-trend-micro-2026/</link><guid isPermaLink="true">https://breached.company/gemini-cli-jailbroken-botnet-operator-trend-micro-2026/</guid><description>A Russian-speaking hacker jailbroke Google&apos;s Gemini CLI into an autonomous hacking agent that migrated C2 botnet infrastructure in six minutes, Trend Micro reports.</description><pubDate>Thu, 16 Jul 2026 15:00:00 GMT</pubDate><media:content url="https://breached.company/images/2026-07-16-gemini-cli-jailbroken-botnet-operator-trend-micro-2026.png" medium="image"/><enclosure url="https://breached.company/images/2026-07-16-gemini-cli-jailbroken-botnet-operator-trend-micro-2026.png" length="0" type="image/png"/></item><item><title>Scattered Spider&apos;s TfL Hackers Jailed: Five and a Half Years Each in the UK&apos;s Biggest-Ever Cybercrime Prosecution</title><link>https://breached.company/scattered-spider-tfl-hackers-sentenced-2026/</link><guid isPermaLink="true">https://breached.company/scattered-spider-tfl-hackers-sentenced-2026/</guid><description>Scattered Spider members Owen Flowers and Thalha Jubair each got five years six months for the £29 million Transport for London hack, the UK&apos;s biggest cybercrime case.</description><pubDate>Thu, 16 Jul 2026 10:00:00 GMT</pubDate><media:content url="https://breached.company/images/2026-07-16-scattered-spider-tfl-hackers-sentenced-2026.png" medium="image"/><enclosure url="https://breached.company/images/2026-07-16-scattered-spider-tfl-hackers-sentenced-2026.png" length="0" type="image/png"/></item><item><title>€140 Million, 800 Bank Accounts, 67 Money Mules: Spanish Police Dismantle Industrial-Scale BEC and Investment Fraud Ring</title><link>https://breached.company/spanish-police-140-million-bec-fraud-ring-2026/</link><guid isPermaLink="true">https://breached.company/spanish-police-140-million-bec-fraud-ring-2026/</guid><description>Spanish police dismantled a €140 million cybercrime ring running BEC and investment fraud, arresting four across Spain, Portugal, and Panama with Interpol and Europol.</description><pubDate>Wed, 15 Jul 2026 10:00:00 GMT</pubDate><media:content url="https://breached.company/images/2026-07-15-spanish-police-140-million-bec-fraud-ring-2026.png" medium="image"/><enclosure url="https://breached.company/images/2026-07-15-spanish-police-140-million-bec-fraud-ring-2026.png" length="0" type="image/png"/></item><item><title>&quot;Shut Down Your Servers Now&quot;: Progress Confirms ShareFile Zero-Day Behind Four-Day Emergency Storage Zone Shutdown</title><link>https://breached.company/progress-sharefile-zero-day-storage-zone-shutdown-2026/</link><guid isPermaLink="true">https://breached.company/progress-sharefile-zero-day-storage-zone-shutdown-2026/</guid><description>Progress confirmed a path traversal zero-day in ShareFile Storage Zone Controllers after ordering emergency shutdowns July 10; patches shipped July 14.</description><pubDate>Tue, 14 Jul 2026 17:00:00 GMT</pubDate><media:content url="https://breached.company/images/2026-07-14-progress-sharefile-zero-day-storage-zone-shutdown-2026.png" medium="image"/><enclosure url="https://breached.company/images/2026-07-14-progress-sharefile-zero-day-storage-zone-shutdown-2026.png" length="0" type="image/png"/></item><item><title>CVSS 10.0: SonicWall SMA 1000 Zero-Days Chained for Full Appliance Takeover — Federal Agencies Have Until July 17</title><link>https://breached.company/sonicwall-sma1000-zero-days-cvss-10-2026/</link><guid isPermaLink="true">https://breached.company/sonicwall-sma1000-zero-days-cvss-10-2026/</guid><description>SonicWall SMA 1000 zero-days CVE-2026-15409 (CVSS 10.0) and CVE-2026-15410 are being chained in active attacks; CISA set a July 17 federal patch deadline.</description><pubDate>Tue, 14 Jul 2026 15:00:00 GMT</pubDate><media:content url="https://breached.company/images/2026-07-14-sonicwall-sma1000-zero-days-cvss-10-2026.png" medium="image"/><enclosure url="https://breached.company/images/2026-07-14-sonicwall-sma1000-zero-days-cvss-10-2026.png" length="0" type="image/png"/></item><item><title>570 Flaws, 3 Zero-Days: Microsoft&apos;s July Patch Tuesday Is the Biggest in History — and AI Found Much of It</title><link>https://breached.company/microsoft-patch-tuesday-570-flaws-record-2026/</link><guid isPermaLink="true">https://breached.company/microsoft-patch-tuesday-570-flaws-record-2026/</guid><description>Microsoft&apos;s July 2026 Patch Tuesday fixes a record 570 vulnerabilities including exploited AD FS and SharePoint zero-days and a disclosed BitLocker bypass.</description><pubDate>Tue, 14 Jul 2026 10:00:00 GMT</pubDate><media:content url="https://breached.company/images/2026-07-14-microsoft-patch-tuesday-570-flaws-record-2026.png" medium="image"/><enclosure url="https://breached.company/images/2026-07-14-microsoft-patch-tuesday-570-flaws-record-2026.png" length="0" type="image/png"/></item><item><title>TriWest Breach Exposes Data on Nearly 12,000 TRICARE West Military Beneficiaries — Notified 11 Weeks Later</title><link>https://breached.company/triwest-tricare-west-breach-military-beneficiaries-2026/</link><guid isPermaLink="true">https://breached.company/triwest-tricare-west-breach-military-beneficiaries-2026/</guid><description>TriWest Healthcare Alliance breach exposed data on 11,844 TRICARE West military beneficiaries, including DoD Benefits Numbers — with notification letters delayed until July.</description><pubDate>Mon, 13 Jul 2026 15:00:00 GMT</pubDate><media:content url="https://breached.company/images/2026-07-13-triwest-tricare-west-breach-military-beneficiaries-2026.png" medium="image"/><enclosure url="https://breached.company/images/2026-07-13-triwest-tricare-west-breach-military-beneficiaries-2026.png" length="0" type="image/png"/></item><item><title>Two Years Unpatched: Latvia&apos;s State Forestry Giant Still Rebuilding Weeks After Ransomware Attack and 44GB Leak</title><link>https://breached.company/latvia-state-forests-lvm-ransomware-44gb-2026/</link><guid isPermaLink="true">https://breached.company/latvia-state-forests-lvm-ransomware-44gb-2026/</guid><description>Latvia&apos;s state forestry company LVM is still restoring IT systems weeks after a ransomware attack that leaked 44GB of data, exploiting a system unpatched for two years.</description><pubDate>Mon, 13 Jul 2026 10:00:00 GMT</pubDate><media:content url="https://breached.company/images/2026-07-13-latvia-state-forests-lvm-ransomware-44gb-2026.png" medium="image"/><enclosure url="https://breached.company/images/2026-07-13-latvia-state-forests-lvm-ransomware-44gb-2026.png" length="0" type="image/png"/></item><item><title>ShinyHunters Publishes Data on 2.3 Million People After Moody Bible Institute Refuses to Pay</title><link>https://breached.company/moody-bible-institute-shinyhunters-2-3-million-2026/</link><guid isPermaLink="true">https://breached.company/moody-bible-institute-shinyhunters-2-3-million-2026/</guid><description>ShinyHunters leaked data on 2.3 million Moody Bible Institute donors, students, and alumni after the college refused to pay — 23GB from six systems now circulating.</description><pubDate>Sat, 11 Jul 2026 15:00:00 GMT</pubDate><media:content url="https://breached.company/images/2026-07-11-moody-bible-institute-shinyhunters-2-3-million-2026.png" medium="image"/><enclosure url="https://breached.company/images/2026-07-11-moody-bible-institute-shinyhunters-2-3-million-2026.png" length="0" type="image/png"/></item><item><title>Russia Is Watching: Dutch Intelligence Says Moscow Hijacked Security Cameras Across Europe to Track Weapons Bound for Ukraine</title><link>https://breached.company/russia-camera-hacking-nato-logistics-netherlands-2026/</link><guid isPermaLink="true">https://breached.company/russia-camera-hacking-nato-logistics-netherlands-2026/</guid><description>Dutch intelligence says Russian hackers compromised IP cameras across the Netherlands, NATO countries, and Ukraine to surveil military logistics routes and weapons shipments.</description><pubDate>Sat, 11 Jul 2026 10:00:00 GMT</pubDate><media:content url="https://breached.company/images/2026-07-11-russia-camera-hacking-nato-logistics-netherlands-2026.png" medium="image"/><enclosure url="https://breached.company/images/2026-07-11-russia-camera-hacking-nato-logistics-netherlands-2026.png" length="0" type="image/png"/></item><item><title>The 2026 Mid-Year Breach Review: Six Months That Redefined the Threat Landscape</title><link>https://breached.company/2026-mid-year-breach-review-worst-hacks-2026/</link><guid isPermaLink="true">https://breached.company/2026-mid-year-breach-review-worst-hacks-2026/</guid><description>Mid-year 2026 breach review: Conduent&apos;s 62 million victims, FortiBleed&apos;s 430,000 firewalls, ShinyHunters&apos; rampage, and the first AI-run ransomware attack.</description><pubDate>Fri, 10 Jul 2026 15:00:00 GMT</pubDate><media:content url="https://breached.company/images/2026-07-10-2026-mid-year-breach-review-worst-hacks-2026.png" medium="image"/><enclosure url="https://breached.company/images/2026-07-10-2026-mid-year-breach-review-worst-hacks-2026.png" length="0" type="image/png"/></item><item><title>AssuranceAmerica Breach Exposes 6.99 Million Driver&apos;s Licenses — the Largest Spill of American License Data This Year</title><link>https://breached.company/assuranceamerica-6-9-million-drivers-licenses-2026/</link><guid isPermaLink="true">https://breached.company/assuranceamerica-6-9-million-drivers-licenses-2026/</guid><description>AssuranceAmerica confirms a data breach affecting 6.99 million people, exposing driver&apos;s license numbers and insurance records in 2026&apos;s largest license data spill.</description><pubDate>Fri, 10 Jul 2026 10:00:00 GMT</pubDate><media:content url="https://breached.company/images/2026-07-10-assuranceamerica-6-9-million-drivers-licenses-2026.png" medium="image"/><enclosure url="https://breached.company/images/2026-07-10-assuranceamerica-6-9-million-drivers-licenses-2026.png" length="0" type="image/png"/></item><item><title>GodDamn Ransomware and PoisonX: When the Malicious Kernel Driver Comes Pre-Signed by Microsoft</title><link>https://breached.company/goddamn-ransomware-poisonx-signed-driver-2026/</link><guid isPermaLink="true">https://breached.company/goddamn-ransomware-poisonx-signed-driver-2026/</guid><description>GodDamn ransomware deploys PoisonX, a malicious signed kernel driver bearing a Microsoft-attributed signature, to kill EDR from the kernel — a dangerous evolution of BYOVD attacks.</description><pubDate>Thu, 09 Jul 2026 15:00:00 GMT</pubDate><media:content url="https://breached.company/images/2026-07-09-goddamn-ransomware-poisonx-signed-driver-2026.png" medium="image"/><enclosure url="https://breached.company/images/2026-07-09-goddamn-ransomware-poisonx-signed-driver-2026.png" length="0" type="image/png"/></item><item><title>Accenture Admits &apos;Isolated Matter&apos; After Hacker &apos;888&apos; Offers 35 GB of Source Code, Keys, and Azure Tokens for Sale</title><link>https://breached.company/accenture-888-35gb-source-code-breach-claim-2026/</link><guid isPermaLink="true">https://breached.company/accenture-888-35gb-source-code-breach-claim-2026/</guid><description>Hacker &apos;888&apos; claims theft of 35 GB of Accenture source code, RSA/SSH keys, and Azure tokens; Accenture confirms an &apos;isolated matter&apos; but won&apos;t detail what was stolen.</description><pubDate>Thu, 09 Jul 2026 10:00:00 GMT</pubDate><media:content url="https://breached.company/images/2026-07-09-accenture-888-35gb-source-code-breach-claim-2026.png" medium="image"/><enclosure url="https://breached.company/images/2026-07-09-accenture-888-35gb-source-code-breach-claim-2026.png" length="0" type="image/png"/></item><item><title>Ubiquiti Patches Seven Critical UniFi Flaws — Including a Perfect-10 Command Injection in the App That Runs Your Building</title><link>https://breached.company/ubiquiti-unifi-cvss-10-command-injection-2026/</link><guid isPermaLink="true">https://breached.company/ubiquiti-unifi-cvss-10-command-injection-2026/</guid><description>Ubiquiti patches seven critical UniFi vulnerabilities including CVE-2026-50746, a CVSS 10.0 command injection in UniFi Connect, with 100,000+ UniFi OS instances exposed online.</description><pubDate>Wed, 08 Jul 2026 15:00:00 GMT</pubDate><media:content url="https://breached.company/images/2026-07-08-ubiquiti-unifi-cvss-10-command-injection-2026.png" medium="image"/><enclosure url="https://breached.company/images/2026-07-08-ubiquiti-unifi-cvss-10-command-injection-2026.png" length="0" type="image/png"/></item><item><title>Two Days to Patch: CISA Orders Fixes for Actively Exploited ColdFusion, Joomla, and Langflow Flaws — Three of Them CVSS 10.0</title><link>https://breached.company/cisa-kev-coldfusion-joomla-langflow-cvss-10-2026/</link><guid isPermaLink="true">https://breached.company/cisa-kev-coldfusion-joomla-langflow-cvss-10-2026/</guid><description>CISA KEV additions with July 10 deadline: CVSS 10.0 Adobe ColdFusion CVE-2026-48282, two Joomla page builder flaws, and Langflow CVE-2026-55255 used to steal LLM and AWS keys.</description><pubDate>Wed, 08 Jul 2026 10:00:00 GMT</pubDate><media:content url="https://breached.company/images/2026-07-08-cisa-kev-coldfusion-joomla-langflow-cvss-10-2026.png" medium="image"/><enclosure url="https://breached.company/images/2026-07-08-cisa-kev-coldfusion-joomla-langflow-cvss-10-2026.png" length="0" type="image/png"/></item><item><title>Brussels Moves to Vet Frontier AI Before It Ships: Inside the EU&apos;s New Action Plan on Cybersecurity and Artificial Intelligence</title><link>https://breached.company/eu-action-plan-cybersecurity-ai-frontier-testing-2026/</link><guid isPermaLink="true">https://breached.company/eu-action-plan-cybersecurity-ai-frontier-testing-2026/</guid><description>EU Action Plan on Cybersecurity and AI: frontier model evaluation before market entry, an ENISA secure testing platform for critical sectors by 2027, and a European Blueprint for frontier AI access.</description><pubDate>Tue, 07 Jul 2026 15:00:00 GMT</pubDate><media:content url="https://breached.company/images/2026-07-07-eu-action-plan-cybersecurity-ai-frontier-testing-2026.png" medium="image"/><enclosure url="https://breached.company/images/2026-07-07-eu-action-plan-cybersecurity-ai-frontier-testing-2026.png" length="0" type="image/png"/></item><item><title>FortiBleed Finally Has Names Attached: Opsec Failure Links the 430,000-Firewall Campaign to INC Ransom and Lynx</title><link>https://breached.company/fortibleed-linked-inc-ransom-lynx-opsec-failure-2026/</link><guid isPermaLink="true">https://breached.company/fortibleed-linked-inc-ransom-lynx-opsec-failure-2026/</guid><description>SOCRadar links FortiBleed to INC Ransom and Lynx ransomware via an exposed staging server — one operator logged into both affiliate panels, 12+ ransomware deployments confirmed.</description><pubDate>Tue, 07 Jul 2026 10:00:00 GMT</pubDate><media:content url="https://breached.company/images/2026-07-07-fortibleed-linked-inc-ransom-lynx-opsec-failure-2026.png" medium="image"/><enclosure url="https://breached.company/images/2026-07-07-fortibleed-linked-inc-ransom-lynx-opsec-failure-2026.png" length="0" type="image/png"/></item><item><title>JADEPUFFER: Inside the First Ransomware Attack Run End-to-End by an AI Agent</title><link>https://breached.company/jadepuffer-first-agentic-ai-ransomware-sysdig-2026/</link><guid isPermaLink="true">https://breached.company/jadepuffer-first-agentic-ai-ransomware-sysdig-2026/</guid><description>Sysdig documents JADEPUFFER, the first ransomware attack driven end-to-end by an AI agent — exploiting Langflow, pivoting to a Nacos database, and extorting autonomously. What it was, and its limits.</description><pubDate>Mon, 06 Jul 2026 10:00:00 GMT</pubDate><media:content url="https://breached.company/images/2026-07-06-jadepuffer-first-agentic-ai-ransomware-sysdig-2026.png" medium="image"/><enclosure url="https://breached.company/images/2026-07-06-jadepuffer-first-agentic-ai-ransomware-sysdig-2026.png" length="0" type="image/png"/></item><item><title>10.5 Million Became 62.2 Million: Conduent Is Now the Third-Largest Healthcare Data Breach in U.S. History</title><link>https://breached.company/conduent-breach-62-million-third-largest-healthcare-2026/</link><guid isPermaLink="true">https://breached.company/conduent-breach-62-million-third-largest-healthcare-2026/</guid><description>Conduent&apos;s breach total hits 62,224,658 per HHS — one in five Americans and the third-largest U.S. healthcare data breach ever, behind Change Healthcare and Anthem.</description><pubDate>Sun, 05 Jul 2026 15:00:00 GMT</pubDate><media:content url="https://breached.company/images/2026-07-05-conduent-breach-62-million-third-largest-healthcare-2026.png" medium="image"/><enclosure url="https://breached.company/images/2026-07-05-conduent-breach-62-million-third-largest-healthcare-2026.png" length="0" type="image/png"/></item></channel></rss>