<?xml version="1.0" encoding="UTF-8"?><rss version="2.0" xmlns:media="http://search.yahoo.com/mrss/"><channel><title>Breached.Company — Cybersecurity Breach Intelligence</title><description>Cybersecurity breach intelligence, incident response analysis, and data breach case studies for security professionals.</description><link>https://breached.company/</link><language>en-us</language><item><title>FortiBleed: Leaked Dataset Exposes Credentials for 73,932 Fortinet Firewalls Worldwide</title><link>https://breached.company/fortibleed-73000-fortinet-firewalls-credentials-exposed-2026/</link><guid isPermaLink="true">https://breached.company/fortibleed-73000-fortinet-firewalls-credentials-exposed-2026/</guid><description>FortiBleed exposes credentials for 73,932 Fortinet firewalls in 194 countries. Researchers confirm some admin logins still work. What to do now.</description><pubDate>Wed, 17 Jun 2026 09:00:00 GMT</pubDate><media:content url="https://breached.company/images/2026-06-17-fortibleed-73000-fortinet-firewalls-credentials-exposed-2026.png" medium="image"/><enclosure url="https://breached.company/images/2026-06-17-fortibleed-73000-fortinet-firewalls-credentials-exposed-2026.png" length="0" type="image/png"/></item><item><title>Malware Dressed as Wallpaper: Kaspersky Finds Infostealers Hiding in Steam Workshop</title><link>https://breached.company/steam-workshop-wallpaper-engine-malware-campaign-2026/</link><guid isPermaLink="true">https://breached.company/steam-workshop-wallpaper-engine-malware-campaign-2026/</guid><description>Kaspersky found dozens of malicious Wallpaper Engine items on Steam Workshop delivering infostealers and stealing Steam credentials. Campaign active since late 2025.</description><pubDate>Tue, 16 Jun 2026 17:00:00 GMT</pubDate><media:content url="https://breached.company/images/2026-06-16-steam-workshop-wallpaper-engine-malware-campaign-2026.webp" medium="image"/><enclosure url="https://breached.company/images/2026-06-16-steam-workshop-wallpaper-engine-malware-campaign-2026.webp" length="0" type="image/webp"/></item><item><title>Backdoor.Turn: DragonForce Hides Its C2 Inside Microsoft Teams Call Infrastructure</title><link>https://breached.company/dragonforce-backdoor-turn-microsoft-teams-relay-c2-2026/</link><guid isPermaLink="true">https://breached.company/dragonforce-backdoor-turn-microsoft-teams-relay-c2-2026/</guid><description>Symantec found Backdoor.Turn, a DragonForce RAT that hides C2 traffic in Microsoft Teams TURN relays — the first in-the-wild abuse of Teams relays for C2.</description><pubDate>Tue, 16 Jun 2026 13:00:00 GMT</pubDate><media:content url="https://breached.company/images/2026-06-16-dragonforce-backdoor-turn-microsoft-teams-relay-c2-2026.webp" medium="image"/><enclosure url="https://breached.company/images/2026-06-16-dragonforce-backdoor-turn-microsoft-teams-relay-c2-2026.webp" length="0" type="image/webp"/></item><item><title>iRhythm Says Hackers Stole Cardiac Patients&apos; Health Data Through a Third-Party App</title><link>https://breached.company/irhythm-data-breach-cardiac-patient-phi-extortion-2026/</link><guid isPermaLink="true">https://breached.company/irhythm-data-breach-cardiac-patient-phi-extortion-2026/</guid><description>iRhythm disclosed a breach of patient PHI via a third-party app compromised through social engineering, followed by a ransom demand. Affected count undisclosed.</description><pubDate>Tue, 16 Jun 2026 09:00:00 GMT</pubDate><media:content url="https://breached.company/images/2026-06-16-irhythm-data-breach-cardiac-patient-phi-extortion-2026.webp" medium="image"/><enclosure url="https://breached.company/images/2026-06-16-irhythm-data-breach-cardiac-patient-phi-extortion-2026.webp" length="0" type="image/webp"/></item><item><title>Nine Years, 20,000 Phishing Domains: How Group-IB and INTERPOL Took Down SniperDz</title><link>https://breached.company/sniperdz-phishing-as-a-service-takedown-interpol-group-ib-2026/</link><guid isPermaLink="true">https://breached.company/sniperdz-phishing-as-a-service-takedown-interpol-group-ib-2026/</guid><description>Group-IB and INTERPOL dismantled SniperDz, a nine-year phishing-as-a-service platform with 20,000+ domains. Alleged developer &apos;Guedz&apos; arrested in Algeria.</description><pubDate>Mon, 15 Jun 2026 17:00:00 GMT</pubDate><media:content url="https://breached.company/images/2026-06-15-sniperdz-phishing-as-a-service-takedown-interpol-group-ib-2026.webp" medium="image"/><enclosure url="https://breached.company/images/2026-06-15-sniperdz-phishing-as-a-service-takedown-interpol-group-ib-2026.webp" length="0" type="image/webp"/></item><item><title>ShinyHunters Leaks 137,000 Infinite Campus Staff Records After One Salesforce Account Falls</title><link>https://breached.company/infinite-campus-shinyhunters-salesforce-breach-137000-staff-2026/</link><guid isPermaLink="true">https://breached.company/infinite-campus-shinyhunters-salesforce-breach-137000-staff-2026/</guid><description>ShinyHunters leaked 137,000 Infinite Campus school-staff records stolen from a single Salesforce account. Student academic data was not accessed.</description><pubDate>Mon, 15 Jun 2026 13:00:00 GMT</pubDate><media:content url="https://breached.company/images/2026-06-15-infinite-campus-shinyhunters-salesforce-breach-137000-staff-2026.webp" medium="image"/><enclosure url="https://breached.company/images/2026-06-15-infinite-campus-shinyhunters-salesforce-breach-137000-staff-2026.webp" length="0" type="image/webp"/></item><item><title>ShinyHunters Claims the Council of Europe: 297GB of HR and Payroll Data Held to a June 16 Deadline</title><link>https://breached.company/council-of-europe-shinyhunters-peoplesoft-extortion-2026/</link><guid isPermaLink="true">https://breached.company/council-of-europe-shinyhunters-peoplesoft-extortion-2026/</guid><description>ShinyHunters claims it stole ~297GB of HR and payroll data from the Council of Europe and set a June 16 leak deadline. The body says it is investigating.</description><pubDate>Mon, 15 Jun 2026 09:00:00 GMT</pubDate><media:content url="https://breached.company/images/2026-06-15-council-of-europe-shinyhunters-peoplesoft-extortion-2026.webp" medium="image"/><enclosure url="https://breached.company/images/2026-06-15-council-of-europe-shinyhunters-peoplesoft-extortion-2026.webp" length="0" type="image/webp"/></item><item><title>A Pill Approval and a Data Breach in the Same Hour: How Novo Nordisk&apos;s Stock Shrugged Off a Hack</title><link>https://breached.company/novo-nordisk-wegovy-pill-approval-clinical-trial-data-breach-2026/</link><guid isPermaLink="true">https://breached.company/novo-nordisk-wegovy-pill-approval-clinical-trial-data-breach-2026/</guid><description>Novo Nordisk shares rose ~3% as UK approval of the first daily GLP-1 weight-loss pill eclipsed a same-day breach of de-identified clinical-trial patient data.</description><pubDate>Sun, 14 Jun 2026 22:00:00 GMT</pubDate><media:content url="https://breached.company/images/2026-06-14-novo-nordisk-wegovy-pill-approval-clinical-trial-data-breach-2026.webp" medium="image"/><enclosure url="https://breached.company/images/2026-06-14-novo-nordisk-wegovy-pill-approval-clinical-trial-data-breach-2026.webp" length="0" type="image/webp"/></item><item><title>Harvest on Hold: A Cyberattack Shuts Two of Mackay Sugar&apos;s Mills as Queensland Aims to Restart</title><link>https://breached.company/mackay-sugar-cyberattack-mills-shutdown-queensland-harvest-2026/</link><guid isPermaLink="true">https://breached.company/mackay-sugar-cyberattack-mills-shutdown-queensland-harvest-2026/</guid><description>A cyberattack shut Mackay Sugar&apos;s Farleigh and Racecourse mills in Queensland mid-harvest, halting milling and ordering growers to stop cutting cane.</description><pubDate>Sun, 14 Jun 2026 20:00:00 GMT</pubDate><media:content url="https://breached.company/images/2026-06-14-mackay-sugar-cyberattack-mills-shutdown-queensland-harvest-2026.webp" medium="image"/><enclosure url="https://breached.company/images/2026-06-14-mackay-sugar-cyberattack-mills-shutdown-queensland-harvest-2026.webp" length="0" type="image/webp"/></item><item><title>600,000 Gaza Households Exposed: The WFP Breach May Be the Largest Theft of Humanitarian Aid Data Ever</title><link>https://breached.company/wfp-gaza-600000-households-data-breach-humanitarian-2026/</link><guid isPermaLink="true">https://breached.company/wfp-gaza-600000-households-data-breach-humanitarian-2026/</guid><description>A breach of the UN World Food Programme&apos;s registration app exposed data on ~600,000 Gaza households — names, IDs, phones, locations — possibly the largest aid-data theft ever.</description><pubDate>Sun, 14 Jun 2026 18:00:00 GMT</pubDate><media:content url="https://breached.company/images/2026-06-14-wfp-gaza-600000-households-data-breach-humanitarian-2026.webp" medium="image"/><enclosure url="https://breached.company/images/2026-06-14-wfp-gaza-600000-households-data-breach-humanitarian-2026.webp" length="0" type="image/webp"/></item><item><title>Sent Home for a Second Day: A Suspected Malware Attack Shuts Most of Great Marlow School Mid-Exams</title><link>https://breached.company/great-marlow-school-cyberattack-closure-exams-buckinghamshire-2026/</link><guid isPermaLink="true">https://breached.company/great-marlow-school-cyberattack-closure-exams-buckinghamshire-2026/</guid><description>Great Marlow School in Buckinghamshire sent most of its 1,428 pupils home for a second day after a suspected malware attack took down its ICT network mid-exams.</description><pubDate>Sun, 14 Jun 2026 16:00:00 GMT</pubDate><media:content url="https://breached.company/images/2026-06-14-great-marlow-school-cyberattack-closure-exams-buckinghamshire-2026.webp" medium="image"/><enclosure url="https://breached.company/images/2026-06-14-great-marlow-school-cyberattack-closure-exams-buckinghamshire-2026.webp" length="0" type="image/webp"/></item><item><title>Criminal Probe Opens as Nottingham Confirms ShinyHunters Breach: Passports, Bank Details, and Addresses of 454,000 Leaked</title><link>https://breached.company/nottingham-university-shinyhunters-breach-criminal-probe-2026/</link><guid isPermaLink="true">https://breached.company/nottingham-university-shinyhunters-breach-criminal-probe-2026/</guid><description>University of Nottingham confirms a criminal probe after ShinyHunters leaked passports, bank details, and addresses of ~454,600 students in a late-May breach.</description><pubDate>Sun, 14 Jun 2026 14:00:00 GMT</pubDate><media:content url="https://breached.company/images/2026-06-14-nottingham-university-shinyhunters-breach-criminal-probe-2026.webp" medium="image"/><enclosure url="https://breached.company/images/2026-06-14-nottingham-university-shinyhunters-breach-criminal-probe-2026.webp" length="0" type="image/webp"/></item><item><title>$17 Million Gone by Morning: Palm Beach Law Firm Sues Its Bank Over an Escrow Wipeout</title><link>https://breached.company/rabideau-klein-first-horizon-17-million-escrow-wire-fraud-lawsuit-2026/</link><guid isPermaLink="true">https://breached.company/rabideau-klein-first-horizon-17-million-escrow-wire-fraud-lawsuit-2026/</guid><description>Palm Beach firm Rabideau Klein sues First Horizon Bank after $17.3M vanished from escrow in 13 wire transfers enabled by a social-engineered token reset.</description><pubDate>Sun, 14 Jun 2026 12:00:00 GMT</pubDate><media:content url="https://breached.company/images/2026-06-14-rabideau-klein-first-horizon-17-million-escrow-wire-fraud-lawsuit-2026.webp" medium="image"/><enclosure url="https://breached.company/images/2026-06-14-rabideau-klein-first-horizon-17-million-escrow-wire-fraud-lawsuit-2026.webp" length="0" type="image/webp"/></item><item><title>Handala Claims a California Water Hack: Iran-Linked Group Says It Breached Bakersfield, Visalia, and Chico Billing Systems</title><link>https://breached.company/handala-california-water-bakersfield-cyberattack-iran-retaliation-2026/</link><guid isPermaLink="true">https://breached.company/handala-california-water-bakersfield-cyberattack-iran-retaliation-2026/</guid><description>Iran-linked Handala claims it breached California Water Service billing systems in Bakersfield, Visalia, and Chico, citing retaliation for U.S. strikes at Sirik.</description><pubDate>Sun, 14 Jun 2026 10:00:00 GMT</pubDate><media:content url="https://breached.company/images/2026-06-14-handala-california-water-bakersfield-cyberattack-iran-retaliation-2026.webp" medium="image"/><enclosure url="https://breached.company/images/2026-06-14-handala-california-water-bakersfield-cyberattack-iran-retaliation-2026.webp" length="0" type="image/webp"/></item><item><title>Cards Declined Across Tehran: &apos;Limited&apos; Cyberattack Knocks Out Services at Four Iranian Banks</title><link>https://breached.company/iran-four-banks-cyberattack-black-wolves-disruption-2026/</link><guid isPermaLink="true">https://breached.company/iran-four-banks-cyberattack-black-wolves-disruption-2026/</guid><description>A cyberattack disrupted four Iranian banks — Melli, Tejarat, Saderat, and EDBI — taking down ATMs and card payments. Black Wolves claimed it; no data leaked.</description><pubDate>Sun, 14 Jun 2026 08:00:00 GMT</pubDate><media:content url="https://breached.company/images/2026-06-14-iran-four-banks-cyberattack-black-wolves-disruption-2026.webp" medium="image"/><enclosure url="https://breached.company/images/2026-06-14-iran-four-banks-cyberattack-black-wolves-disruption-2026.webp" length="0" type="image/webp"/></item><item><title>One Compromised Microsoft Account: Delaware North Breach Exposes Driver&apos;s Licenses and IDs for Thousands</title><link>https://breached.company/delaware-north-data-breach-new-hampshire-residents-2026/</link><guid isPermaLink="true">https://breached.company/delaware-north-data-breach-new-hampshire-residents-2026/</guid><description>Delaware North breach exposed driver&apos;s license and state ID numbers for 10,000+ people, including 1,133 NH residents, after a compromised Microsoft account.</description><pubDate>Sat, 13 Jun 2026 17:00:00 GMT</pubDate><media:content url="https://breached.company/images/2026-06-13-delaware-north-data-breach-new-hampshire-residents-2026.webp" medium="image"/><enclosure url="https://breached.company/images/2026-06-13-delaware-north-data-breach-new-hampshire-residents-2026.webp" length="0" type="image/webp"/></item><item><title>Plaintext Passwords and Reused Credentials: Louisiana Fire District Sues Its Own Cybersecurity Vendor</title><link>https://breached.company/st-george-fire-district-sues-general-informatics-cyberattack-negligence-2026/</link><guid isPermaLink="true">https://breached.company/st-george-fire-district-sues-general-informatics-cyberattack-negligence-2026/</guid><description>St. George Fire Protection District sues vendor General Informatics over a 2023 breach, alleging plaintext passwords, no backups, and reused credentials.</description><pubDate>Sat, 13 Jun 2026 15:00:00 GMT</pubDate><media:content url="https://breached.company/images/2026-06-13-st-george-fire-district-sues-general-informatics-cyberattack-negligence-2026.webp" medium="image"/><enclosure url="https://breached.company/images/2026-06-13-st-george-fire-district-sues-general-informatics-cyberattack-negligence-2026.webp" length="0" type="image/webp"/></item><item><title>Atomic Arch: A Poisoned AUR Spreads a Rust Infostealer and an eBPF Rootkit to Hundreds of Linux Machines</title><link>https://breached.company/atomic-arch-aur-supply-chain-attack-rootkit-infostealer-2026/</link><guid isPermaLink="true">https://breached.company/atomic-arch-aur-supply-chain-attack-rootkit-infostealer-2026/</guid><description>Atomic Arch backdoored 400+ Arch Linux AUR packages with a Rust infostealer and eBPF rootkit via a malicious npm dependency. Here&apos;s what happened and how to respond.</description><pubDate>Sat, 13 Jun 2026 13:00:00 GMT</pubDate><media:content url="https://breached.company/images/2026-06-13-atomic-arch-aur-supply-chain-attack-rootkit-infostealer-2026.webp" medium="image"/><enclosure url="https://breached.company/images/2026-06-13-atomic-arch-aur-supply-chain-attack-rootkit-infostealer-2026.webp" length="0" type="image/webp"/></item><item><title>Murray County Pays $200,000 to Its Ransomware Attackers to &apos;Resolve&apos; the Breach</title><link>https://breached.company/murray-county-georgia-pays-200000-ransomware-2026/</link><guid isPermaLink="true">https://breached.company/murray-county-georgia-pays-200000-ransomware-2026/</guid><description>Murray County, Georgia paid $200,000 to ransomware attackers after a May 13 breach hit tax and court systems, choosing payment to prevent data publication.</description><pubDate>Sat, 13 Jun 2026 11:00:00 GMT</pubDate><media:content url="https://breached.company/images/2026-06-13-murray-county-georgia-pays-200000-ransomware-2026.webp" medium="image"/><enclosure url="https://breached.company/images/2026-06-13-murray-county-georgia-pays-200000-ransomware-2026.webp" length="0" type="image/webp"/></item><item><title>The Thin Digital Line: How Ransomware, Surveillance Vendors, and AI Dispatch Are Rewriting the Risk Map for Global Policing</title><link>https://breached.company/policing-cybersecurity-911-ransomware-axon-flock-ai-dispatch-2026/</link><guid isPermaLink="true">https://breached.company/policing-cybersecurity-911-ransomware-axon-flock-ai-dispatch-2026/</guid><description>How ransomware on 911 centers, surveillance-vendor breaches (Axon, Flock, LAPD), and the rise of AI dispatch are reshaping policing&apos;s 2026 attack surface.</description><pubDate>Sat, 13 Jun 2026 09:00:00 GMT</pubDate><media:content url="https://breached.company/images/2026-06-13-policing-cybersecurity-911-ransomware-axon-flock-ai-dispatch-2026.webp" medium="image"/><enclosure url="https://breached.company/images/2026-06-13-policing-cybersecurity-911-ransomware-axon-flock-ai-dispatch-2026.webp" length="0" type="image/webp"/></item><item><title>DragonForce Cartel Watch: Sweden, Hong Kong, and the UAE Join a Quiet June Victim Run</title><link>https://breached.company/dragonforce-cartel-june-2026-global-victims-areco-hong-kong-parkview-2026/</link><guid isPermaLink="true">https://breached.company/dragonforce-cartel-june-2026-global-victims-areco-hong-kong-parkview-2026/</guid><description>DragonForce posts June 2026 victims across Sweden, Hong Kong, and the UAE, extending its white-label ransomware cartel beyond 2025 UK retail attacks.</description><pubDate>Fri, 12 Jun 2026 10:00:00 GMT</pubDate><media:content url="https://breached.company/images/2026-06-12-dragonforce-cartel-june-2026-global-victims-areco-hong-kong-parkview-2026.webp" medium="image"/><enclosure url="https://breached.company/images/2026-06-12-dragonforce-cartel-june-2026-global-victims-areco-hong-kong-parkview-2026.webp" length="0" type="image/webp"/></item><item><title>ShinyHunters Burns an Oracle PeopleSoft Zero-Day: 100+ Orgs Breached, Universities Hit Hardest</title><link>https://breached.company/shinyhunters-oracle-peoplesoft-zero-day-cve-2026-35273-universities-2026/</link><guid isPermaLink="true">https://breached.company/shinyhunters-oracle-peoplesoft-zero-day-cve-2026-35273-universities-2026/</guid><description>ShinyHunters exploited Oracle PeopleSoft zero-day CVE-2026-35273 (CVSS 9.8) to breach 100+ orgs, mostly universities; Nottingham confirms ~455K records.</description><pubDate>Thu, 11 Jun 2026 14:00:00 GMT</pubDate><media:content url="https://breached.company/images/2026-06-11-shinyhunters-oracle-peoplesoft-zero-day-cve-2026-35273-universities-2026.webp" medium="image"/><enclosure url="https://breached.company/images/2026-06-11-shinyhunters-oracle-peoplesoft-zero-day-cve-2026-35273-universities-2026.webp" length="0" type="image/webp"/></item><item><title>Europol Cuts Off &apos;AudiA6&apos;: The €336 Million Crypto-Laundering Pipeline Behind 15+ Ransomware Investigations</title><link>https://breached.company/audia6-crypto-laundering-takedown-europol-336-million-2026/</link><guid isPermaLink="true">https://breached.company/audia6-crypto-laundering-takedown-europol-336-million-2026/</guid><description>Europol dismantled AudiA6, a crypto-laundering service that washed €336M+ for ransomware gangs since 2021; two admins arrested in Georgia.</description><pubDate>Thu, 11 Jun 2026 09:00:00 GMT</pubDate><media:content url="https://breached.company/images/2026-06-11-audia6-crypto-laundering-takedown-europol-336-million-2026.webp" medium="image"/><enclosure url="https://breached.company/images/2026-06-11-audia6-crypto-laundering-takedown-europol-336-million-2026.webp" length="0" type="image/webp"/></item><item><title>Who Runs &apos;The Gentlemen&apos;? Krebs Names a 36-Year-Old From Izhevsk Behind 2026&apos;s Second-Busiest Ransomware Crew</title><link>https://breached.company/the-gentlemen-ransomware-krebs-attribution-yapaev-2026/</link><guid isPermaLink="true">https://breached.company/the-gentlemen-ransomware-krebs-attribution-yapaev-2026/</guid><description>Krebs links The Gentlemen ransomware operator to Alexander Yapaev of Izhevsk, Russia (handle Hastalamuerte); group ranks #2 by 2026 victim count.</description><pubDate>Wed, 10 Jun 2026 10:00:00 GMT</pubDate><media:content url="https://breached.company/images/2026-06-10-the-gentlemen-ransomware-krebs-attribution-yapaev-2026.webp" medium="image"/><enclosure url="https://breached.company/images/2026-06-10-the-gentlemen-ransomware-krebs-attribution-yapaev-2026.webp" length="0" type="image/webp"/></item><item><title>ServiceNow Says a REST API Bug Left Customer Data Reachable Without Logging In</title><link>https://breached.company/servicenow-unauthenticated-api-customer-data-exposure-2026/</link><guid isPermaLink="true">https://breached.company/servicenow-unauthenticated-api-customer-data-exposure-2026/</guid><description>ServiceNow patched an unauthenticated REST API flaw that let users query customer instance data; no CVE assigned, affected instance count undisclosed.</description><pubDate>Tue, 09 Jun 2026 13:00:00 GMT</pubDate><media:content url="https://breached.company/images/2026-06-09-servicenow-unauthenticated-api-customer-data-exposure-2026.webp" medium="image"/><enclosure url="https://breached.company/images/2026-06-09-servicenow-unauthenticated-api-customer-data-exposure-2026.webp" length="0" type="image/webp"/></item><item><title>Qilin Burns a Check Point VPN Zero-Day: CISA Gives Federal Agencies Three Days to Patch CVE-2026-50751</title><link>https://breached.company/qilin-check-point-vpn-zero-day-cve-2026-50751-cisa-emergency-directive-2026/</link><guid isPermaLink="true">https://breached.company/qilin-check-point-vpn-zero-day-cve-2026-50751-cisa-emergency-directive-2026/</guid><description>Qilin exploited Check Point VPN zero-day CVE-2026-50751 (CVSS 9.3); CISA gave federal agencies three days to patch by June 11, 2026.</description><pubDate>Tue, 09 Jun 2026 09:00:00 GMT</pubDate><media:content url="https://breached.company/images/2026-06-09-qilin-check-point-vpn-zero-day-cve-2026-50751-cisa-emergency-directive-2026.webp" medium="image"/><enclosure url="https://breached.company/images/2026-06-09-qilin-check-point-vpn-zero-day-cve-2026-50751-cisa-emergency-directive-2026.webp" length="0" type="image/webp"/></item><item><title>The Unit That Ate Cybersecurity: From Stuxnet to a $32 Billion Exit, How Israel&apos;s 8200 Became the Backbone of Global Cyber Defense — and a &apos;Critical&apos; Threat</title><link>https://breached.company/stuxnet-unit-8200-israel-cybersecurity-ecosystem-venture-capital-2026/</link><guid isPermaLink="true">https://breached.company/stuxnet-unit-8200-israel-cybersecurity-ecosystem-venture-capital-2026/</guid><description>From Stuxnet to Wiz&apos;s $32B exit: how Israel&apos;s Unit 8200 became the backbone of global cybersecurity — and why the Pentagon now calls it a &apos;critical&apos; threat.</description><pubDate>Sun, 07 Jun 2026 17:00:00 GMT</pubDate><media:content url="https://breached.company/images/2026-06-07-stuxnet-unit-8200-israel-cybersecurity-ecosystem-venture-capital-2026.webp" medium="image"/><enclosure url="https://breached.company/images/2026-06-07-stuxnet-unit-8200-israel-cybersecurity-ecosystem-venture-capital-2026.webp" length="0" type="image/webp"/></item><item><title>Operation Grim Beeper: How Mossad Turned Hezbollah&apos;s Supply Chain Into a Weapon — and Rewrote the Rules of Hardware Trust</title><link>https://breached.company/hezbollah-pager-explosion-operation-grim-beeper-supply-chain-attack/</link><guid isPermaLink="true">https://breached.company/hezbollah-pager-explosion-operation-grim-beeper-supply-chain-attack/</guid><description>How Mossad&apos;s Operation Grim Beeper booby-trapped Hezbollah&apos;s pagers and walkie-talkies via a years-long supply-chain front — the definitive breakdown.</description><pubDate>Sun, 07 Jun 2026 12:00:00 GMT</pubDate><media:content url="https://breached.company/images/2026-06-07-hezbollah-pager-explosion-operation-grim-beeper-supply-chain-attack.webp" medium="image"/><enclosure url="https://breached.company/images/2026-06-07-hezbollah-pager-explosion-operation-grim-beeper-supply-chain-attack.webp" length="0" type="image/webp"/></item><item><title>Spyware on the Negotiators&apos; Phones: The DIA Just Rated Israel a &apos;Critical&apos; Counterintelligence Threat — Its Highest Designation for Any Ally</title><link>https://breached.company/dia-israel-counterintelligence-critical-spyware-us-officials-2026/</link><guid isPermaLink="true">https://breached.company/dia-israel-counterintelligence-critical-spyware-us-officials-2026/</guid><description>The DIA raised Israel&apos;s counterintelligence threat to &apos;critical&apos; after spyware was found on U.S. officials&apos; phones — its highest rating for any ally. Inside the espionage row.</description><pubDate>Sun, 07 Jun 2026 00:00:00 GMT</pubDate><media:content url="https://breached.company/images/2026-06-07-dia-israel-counterintelligence-critical-spyware-us-officials-2026.webp" medium="image"/><enclosure url="https://breached.company/images/2026-06-07-dia-israel-counterintelligence-critical-spyware-us-officials-2026.webp" length="0" type="image/webp"/></item><item><title>Charter Confirms Spectrum Breach After ShinyHunters Vishing Attack Exposes Millions of Customers</title><link>https://breached.company/charter-spectrum-shinyhunters-vishing-salesforce-breach-2026/</link><guid isPermaLink="true">https://breached.company/charter-spectrum-shinyhunters-vishing-salesforce-breach-2026/</guid><description>Charter Communications (Spectrum) confirms a ShinyHunters breach via a vishing attack on a Microsoft Entra account; HIBP lists 4.9M email addresses exposed.</description><pubDate>Sat, 06 Jun 2026 14:00:00 GMT</pubDate><media:content url="https://breached.company/images/2026-06-06-charter-spectrum-shinyhunters-vishing-salesforce-breach-2026.webp" medium="image"/><enclosure url="https://breached.company/images/2026-06-06-charter-spectrum-shinyhunters-vishing-salesforce-breach-2026.webp" length="0" type="image/webp"/></item><item><title>Lithuania Probes Theft of 600,000 State Registry Records as Officials Point to Russian Intelligence</title><link>https://breached.company/lithuania-centre-of-registers-breach-600000-records-migration-credentials-2026/</link><guid isPermaLink="true">https://breached.company/lithuania-centre-of-registers-breach-600000-records-migration-credentials-2026/</guid><description>Lithuania investigates theft of 600,000+ Centre of Registers records via compromised Migration Department credentials, with officials suspecting Russian intelligence.</description><pubDate>Sat, 06 Jun 2026 11:30:00 GMT</pubDate><media:content url="https://breached.company/images/2026-06-06-lithuania-centre-of-registers-breach-600000-records-migration-credentials-2026.webp" medium="image"/><enclosure url="https://breached.company/images/2026-06-06-lithuania-centre-of-registers-breach-600000-records-migration-credentials-2026.webp" length="0" type="image/webp"/></item><item><title>HTTP/2 Bomb: AI-Discovered Flaw Lets One Attacker Crash NGINX, Apache, IIS, Envoy and Cloudflare</title><link>https://breached.company/http2-bomb-cve-2026-49975-remote-dos-nginx-apache-iis-envoy-pingora-2026/</link><guid isPermaLink="true">https://breached.company/http2-bomb-cve-2026-49975-remote-dos-nginx-apache-iis-envoy-pingora-2026/</guid><description>HTTP/2 Bomb (CVE-2026-49975) is a remote DoS in NGINX, Apache, IIS, Envoy and Cloudflare Pingora discovered by OpenAI Codex. Patches, mitigations and impact.</description><pubDate>Sat, 06 Jun 2026 09:00:00 GMT</pubDate><media:content url="https://breached.company/images/2026-06-06-http2-bomb-cve-2026-49975-remote-dos-nginx-apache-iis-envoy-pingora-2026.webp" medium="image"/><enclosure url="https://breached.company/images/2026-06-06-http2-bomb-cve-2026-49975-remote-dos-nginx-apache-iis-envoy-pingora-2026.webp" length="0" type="image/webp"/></item><item><title>Just Ask the Bot: How Hackers Talked Meta&apos;s AI Into Hijacking the White House&apos;s Instagram</title><link>https://breached.company/meta-ai-support-bot-instagram-account-takeover-2026/</link><guid isPermaLink="true">https://breached.company/meta-ai-support-bot-instagram-account-takeover-2026/</guid><description>Hackers tricked Meta&apos;s AI support bot into hijacking high-profile Instagram accounts, including the Obama White House account, by asking it to reset passwords. Here&apos;s how.</description><pubDate>Fri, 05 Jun 2026 00:00:00 GMT</pubDate><media:content url="https://breached.company/images/2026-06-05-meta-ai-support-bot-instagram-account-takeover-2026.webp" medium="image"/><enclosure url="https://breached.company/images/2026-06-05-meta-ai-support-bot-instagram-account-takeover-2026.webp" length="0" type="image/webp"/></item><item><title>Disruption Week: DOJ and Tech Giants Erase 1.4 Million Scam Accounts in Strike on Southeast Asian Fraud Empires</title><link>https://breached.company/doj-scam-center-strike-force-disruption-week-2026/</link><guid isPermaLink="true">https://breached.company/doj-scam-center-strike-force-disruption-week-2026/</guid><description>DOJ&apos;s Scam Center Strike Force and tech giants disrupted 1.4M scam accounts and froze $3.8M in crypto in a coordinated strike on Southeast Asian pig-butchering rings.</description><pubDate>Thu, 04 Jun 2026 00:00:00 GMT</pubDate><media:content url="https://breached.company/images/2026-06-04-doj-scam-center-strike-force-disruption-week-2026.webp" medium="image"/><enclosure url="https://breached.company/images/2026-06-04-doj-scam-center-strike-force-disruption-week-2026.webp" length="0" type="image/webp"/></item><item><title>The Doorman Gets 81 Months: Yanluowang Access Broker Aleksei Volkov Sentenced for Selling the Keys to Dozens of US Networks</title><link>https://breached.company/aleksei-volkov-yanluowang-initial-access-broker-sentenced-2026/</link><guid isPermaLink="true">https://breached.company/aleksei-volkov-yanluowang-initial-access-broker-sentenced-2026/</guid><description>Russian initial access broker Aleksei Volkov, who fed dozens of US networks to the Yanluowang ransomware crew, sentenced to 81 months and $9.16M restitution.</description><pubDate>Wed, 03 Jun 2026 00:00:00 GMT</pubDate><media:content url="https://breached.company/images/2026-06-03-aleksei-volkov-yanluowang-initial-access-broker-sentenced-2026.webp" medium="image"/><enclosure url="https://breached.company/images/2026-06-03-aleksei-volkov-yanluowang-initial-access-broker-sentenced-2026.webp" length="0" type="image/webp"/></item><item><title>74 Warrants and a Thonglor Condo: German DDoS-for-Hire Kingpin Behind Fluxstress Arrested in Bangkok</title><link>https://breached.company/noah-christopher-fluxstress-netdowner-ddos-bangkok-arrest-2026/</link><guid isPermaLink="true">https://breached.company/noah-christopher-fluxstress-netdowner-ddos-bangkok-arrest-2026/</guid><description>German national Noah Christopher, operator of the Fluxstress and Netdowner DDoS-for-hire platforms, arrested in Bangkok on 74 warrants and facing extradition to Germany.</description><pubDate>Tue, 02 Jun 2026 00:00:00 GMT</pubDate><media:content url="https://breached.company/images/2026-06-02-noah-christopher-fluxstress-netdowner-ddos-bangkok-arrest-2026.webp" medium="image"/><enclosure url="https://breached.company/images/2026-06-02-noah-christopher-fluxstress-netdowner-ddos-bangkok-arrest-2026.webp" length="0" type="image/webp"/></item><item><title>May 2026 Ransomware Report: 646 Victims, Qilin&apos;s Five-Month Reign, and the Year&apos;s First Slowdown</title><link>https://breached.company/may-2026-ransomware-report-646-victims-qilin-2026/</link><guid isPermaLink="true">https://breached.company/may-2026-ransomware-report-646-victims-qilin-2026/</guid><description>May 2026 ransomware: 646 victims, down 16% — the year&apos;s lowest month. Qilin #1 for the fifth month, TheGentlemen #2, manufacturing the top sector. Full breakdown.</description><pubDate>Mon, 01 Jun 2026 00:00:00 GMT</pubDate><media:content url="https://breached.company/images/2026-06-01-may-2026-ransomware-report-646-victims-qilin-2026.webp" medium="image"/><enclosure url="https://breached.company/images/2026-06-01-may-2026-ransomware-report-646-victims-qilin-2026.webp" length="0" type="image/webp"/></item><item><title>First Documented In-the-Wild Attack: LLM Agent Autonomously Pivots from Marimo RCE to Internal Database in Four Steps</title><link>https://breached.company/llm-agent-post-exploitation-marimo-cve-2026-39987-sysdig-2026/</link><guid isPermaLink="true">https://breached.company/llm-agent-post-exploitation-marimo-cve-2026-39987-sysdig-2026/</guid><description>Sysdig documented the first in-the-wild LLM agent post-exploitation attack: CVE-2026-39987 Marimo RCE to PostgreSQL database exfiltration in 4 automated pivots and under 2 minutes.</description><pubDate>Fri, 29 May 2026 12:00:00 GMT</pubDate><media:content url="https://breached.company/images/2026-05-29-llm-agent-post-exploitation-marimo-cve-2026-39987-sysdig-2026.webp" medium="image"/><enclosure url="https://breached.company/images/2026-05-29-llm-agent-post-exploitation-marimo-cve-2026-39987-sysdig-2026.webp" length="0" type="image/webp"/></item><item><title>Meet GREYVIBE: The New Russian-Linked APT Using ChatGPT and Gemini to Attack Ukraine</title><link>https://breached.company/greyvibe-russian-apt-ukraine-ai-withsecure-2026/</link><guid isPermaLink="true">https://breached.company/greyvibe-russian-apt-ukraine-ai-withsecure-2026/</guid><description>WithSecure attributed GREYVIBE — a new Russian-linked APT using ChatGPT and Gemini to attack Ukraine — targeting military, government, and civilian organizations since August 2025.</description><pubDate>Fri, 29 May 2026 00:00:00 GMT</pubDate><media:content url="https://breached.company/images/2026-05-29-greyvibe-russian-apt-ukraine-ai-withsecure-2026.webp" medium="image"/><enclosure url="https://breached.company/images/2026-05-29-greyvibe-russian-apt-ukraine-ai-withsecure-2026.webp" length="0" type="image/webp"/></item><item><title>Carnival Cruise Confirms 6 Million People Affected in ShinyHunters Breach After Social Engineering Attack</title><link>https://breached.company/carnival-cruise-shinyhunters-6-million-breach-2026/</link><guid isPermaLink="true">https://breached.company/carnival-cruise-shinyhunters-6-million-breach-2026/</guid><description>Carnival Corporation confirmed ShinyHunters breached 5.99 million customers in April 2026 via social engineering. Passport numbers and government IDs exposed. Notifications sent May 28.</description><pubDate>Thu, 28 May 2026 00:00:00 GMT</pubDate><media:content url="https://breached.company/images/2026-05-28-carnival-cruise-shinyhunters-6-million-breach-2026.webp" medium="image"/><enclosure url="https://breached.company/images/2026-05-28-carnival-cruise-shinyhunters-6-million-breach-2026.webp" length="0" type="image/webp"/></item><item><title>FortiClient EMS CVE-2026-35616 Actively Exploited — Attackers Deliver EKZ Infostealer Disguised as Fortinet Patch</title><link>https://breached.company/forticlient-ems-cve-2026-35616-ekz-infostealer-2026/</link><guid isPermaLink="true">https://breached.company/forticlient-ems-cve-2026-35616-ekz-infostealer-2026/</guid><description>FortiClient EMS CVE-2026-35616 (CVSS 9.1) is being actively exploited to deliver EKZ Infostealer disguised as a Fortinet update. CISA KEV listed. Patch immediately.</description><pubDate>Wed, 27 May 2026 12:00:00 GMT</pubDate><media:content url="https://breached.company/images/2026-05-27-forticlient-ems-cve-2026-35616-ekz-infostealer-2026.webp" medium="image"/><enclosure url="https://breached.company/images/2026-05-27-forticlient-ems-cve-2026-35616-ekz-infostealer-2026.webp" length="0" type="image/webp"/></item><item><title>Ghost CMS SQL Injection Flaw CVE-2026-26980 Weaponized to Hijack 700+ Sites Including Harvard, Oxford, and DuckDuckGo</title><link>https://breached.company/ghost-cms-cve-2026-26980-clickfix-700-websites-2026/</link><guid isPermaLink="true">https://breached.company/ghost-cms-cve-2026-26980-clickfix-700-websites-2026/</guid><description>CVE-2026-26980: A CVSS 9.4 SQL injection in Ghost CMS allowed attackers to compromise 700+ sites including Harvard and Oxford with ClickFix malware. Patch immediately.</description><pubDate>Wed, 27 May 2026 00:00:00 GMT</pubDate><media:content url="https://breached.company/images/2026-05-27-ghost-cms-cve-2026-26980-clickfix-700-websites-2026.webp" medium="image"/><enclosure url="https://breached.company/images/2026-05-27-ghost-cms-cve-2026-26980-clickfix-700-websites-2026.webp" length="0" type="image/webp"/></item><item><title>TrapDoor: 34 Malicious Packages Across npm, PyPI, and Crates.io Steal Crypto Wallets, SSH Keys, and Poison AI Assistants</title><link>https://breached.company/trapdoor-supply-chain-npm-pypi-crates-credential-stealer-2026/</link><guid isPermaLink="true">https://breached.company/trapdoor-supply-chain-npm-pypi-crates-credential-stealer-2026/</guid><description>TrapDoor supply chain attack hit npm, PyPI, and Crates.io with 34 malicious packages that steal crypto wallets, SSH keys, and poison CLAUDE.md files to manipulate AI coding assistants.</description><pubDate>Tue, 26 May 2026 12:00:00 GMT</pubDate><media:content url="https://breached.company/images/2026-05-26-trapdoor-supply-chain-npm-pypi-crates-credential-stealer-2026.webp" medium="image"/><enclosure url="https://breached.company/images/2026-05-26-trapdoor-supply-chain-npm-pypi-crates-credential-stealer-2026.webp" length="0" type="image/webp"/></item><item><title>FBI Warns: Silent Ransom Group Now Sending Operatives In Person to Law Firms Posing as IT Staff</title><link>https://breached.company/fbi-silent-ransom-group-law-firms-in-person-attack-2026/</link><guid isPermaLink="true">https://breached.company/fbi-silent-ransom-group-law-firms-in-person-attack-2026/</guid><description>FBI FLASH alert: Silent Ransom Group is physically sending operatives into law firm offices posing as IT staff. 38+ firms breached, 100+ total attacks in an escalating extortion campaign.</description><pubDate>Tue, 26 May 2026 00:00:00 GMT</pubDate><media:content url="https://breached.company/images/2026-05-26-fbi-silent-ransom-group-law-firms-in-person-attack-2026.webp" medium="image"/><enclosure url="https://breached.company/images/2026-05-26-fbi-silent-ransom-group-law-firms-in-person-attack-2026.webp" length="0" type="image/webp"/></item><item><title>Incident Responder and Ransomware Negotiator Sentenced After Pleading Guilty to Running BlackCat Attacks on US Hospitals</title><link>https://breached.company/alphv-blackcat-us-cybersecurity-pros-guilty-plea-2026/</link><guid isPermaLink="true">https://breached.company/alphv-blackcat-us-cybersecurity-pros-guilty-plea-2026/</guid><description>A Sygnia incident responder and DigitalMint ransomware negotiator pleaded guilty to running ALPHV/BlackCat attacks against US hospitals. Both face 20 years for attacking the victims they were supposed to help.</description><pubDate>Mon, 25 May 2026 15:00:00 GMT</pubDate><media:content url="https://breached.company/images/2026-05-25-alphv-blackcat-us-cybersecurity-pros-guilty-plea-2026.webp" medium="image"/><enclosure url="https://breached.company/images/2026-05-25-alphv-blackcat-us-cybersecurity-pros-guilty-plea-2026.webp" length="0" type="image/webp"/></item><item><title>Malicious NuGet Package Impersonates Sicoob Banking SDK to Steal PFX Certificates and Pix Credentials</title><link>https://breached.company/sicoob-nuget-supply-chain-attack-brazil-banking-2026/</link><guid isPermaLink="true">https://breached.company/sicoob-nuget-supply-chain-attack-brazil-banking-2026/</guid><description>A malicious NuGet package impersonated the Sicoob banking SDK to steal PFX certificates and Pix credentials from Brazilian fintech developers. ~500 downloads before takedown.</description><pubDate>Mon, 25 May 2026 12:00:00 GMT</pubDate><media:content url="https://breached.company/images/2026-05-25-sicoob-nuget-supply-chain-attack-brazil-banking-2026.webp" medium="image"/><enclosure url="https://breached.company/images/2026-05-25-sicoob-nuget-supply-chain-attack-brazil-banking-2026.webp" length="0" type="image/webp"/></item><item><title>Trellix Source Code Breached by RansomHouse — Cybersecurity Vendor With 53,000 Customers Hacked</title><link>https://breached.company/trellix-source-code-breach-ransomhouse-2026/</link><guid isPermaLink="true">https://breached.company/trellix-source-code-breach-ransomhouse-2026/</guid><description>RansomHouse hacked Trellix, stealing source code from the cybersecurity firm&apos;s repository. The April 2026 breach affects 53,000+ customers across 185 countries.</description><pubDate>Mon, 25 May 2026 00:00:00 GMT</pubDate><media:content url="https://breached.company/images/2026-05-25-trellix-source-code-breach-ransomhouse-2026.webp" medium="image"/><enclosure url="https://breached.company/images/2026-05-25-trellix-source-code-breach-ransomhouse-2026.webp" length="0" type="image/webp"/></item><item><title>Kimwolf Update: Butler Faces Dual US/Canada Charges, DoD Networks Were Targeted, May 26 Hearing Set</title><link>https://breached.company/kimwolf-jacob-butler-update-dod-targeting-canadian-charges-may26-hearing/</link><guid isPermaLink="true">https://breached.company/kimwolf-jacob-butler-update-dod-targeting-canadian-charges-may26-hearing/</guid><description>Kimwolf update: Jacob Butler faces both US and Canadian charges, a May 26 custody hearing, and newly disclosed DOJ details confirm Kimwolf customers targeted US Department of Defense networks.</description><pubDate>Sun, 24 May 2026 00:00:00 GMT</pubDate><media:content url="https://breached.company/images/2026-05-24-kimwolf-jacob-butler-update-dod-targeting-canadian-charges-may26-hearing.webp" medium="image"/><enclosure url="https://breached.company/images/2026-05-24-kimwolf-jacob-butler-update-dod-targeting-canadian-charges-may26-hearing.webp" length="0" type="image/webp"/></item><item><title>Laravel-Lang Supply Chain Attack: 700+ Composer Package Versions Poisoned with Credential Stealer</title><link>https://breached.company/laravel-lang-supply-chain-attack-composer-700-versions-2026/</link><guid isPermaLink="true">https://breached.company/laravel-lang-supply-chain-attack-composer-700-versions-2026/</guid><description>A supply chain attack on May 22–23 poisoned 700+ historical release tags across four Laravel-Lang Composer packages, delivering a credential stealer that activates on install across PHP environments.</description><pubDate>Sat, 23 May 2026 12:00:00 GMT</pubDate><media:content url="https://breached.company/images/2026-05-23-laravel-lang-supply-chain-attack-composer-700-versions-2026.webp" medium="image"/><enclosure url="https://breached.company/images/2026-05-23-laravel-lang-supply-chain-attack-composer-700-versions-2026.webp" length="0" type="image/webp"/></item><item><title>CoinbaseCartel Claims Panasonic Avionics — 118 Victims and Counting</title><link>https://breached.company/panasonic-avionics-coinbasecartel-data-breach-2026/</link><guid isPermaLink="true">https://breached.company/panasonic-avionics-coinbasecartel-data-breach-2026/</guid><description>CoinbaseCartel claims Panasonic Avionics Corporation in its latest data exfiltration breach, now totaling 118 victims. The group never encrypts — making conventional ransomware defenses useless against it.</description><pubDate>Sat, 23 May 2026 00:00:00 GMT</pubDate><media:content url="https://breached.company/images/2026-05-23-panasonic-avionics-coinbasecartel-data-breach-2026.webp" medium="image"/><enclosure url="https://breached.company/images/2026-05-23-panasonic-avionics-coinbasecartel-data-breach-2026.webp" length="0" type="image/webp"/></item></channel></rss>