SplitVPN breach exposes 865K accounts including emails and partial card data
Russian VPN service SplitVPN (formerly NotVPN) suffered a July 2026 breach exposing 865K email addresses, IPs, and partial payment card details.
A running digest of identity-related exploit and breach news — new zero-days, exposed credential dumps, and directory-security advisories — each summarized in our own words with a link to the primary source.
Russian VPN service SplitVPN (formerly NotVPN) suffered a July 2026 breach exposing 865K email addresses, IPs, and partial payment card details.
CISA warns of a missing-authentication flaw (CVE-2026-12562) giving unauthenticated attackers full root access to Toptech energy-sector devices.
CVE-2026-20316, a hard-coded password flaw in Cisco Secure FMC, is under active exploitation and added to CISA's KEV Catalog.
A ShinyHunters extortion campaign leaked 832k email addresses plus names, addresses, phone numbers, and academic records from Houston City College.
CISA warns MikroTik RouterOS and Cloud Hosted Router lack effective brute-force protections, letting attackers rapidly guess credentials for unauthorized access.
A CISA advisory flags CVE-2026-16581 in the igloohome Smart Lock Android app, where hardcoded sensitive data let attackers reach insufficiently protected backend services.
A documentation gap around the System.User entity in Siemens Mendix leads to overly permissive access rules, risking data exposure and privilege escalation.
CISA advisory flags multiple IntraVUE vulnerabilities, including plaintext password storage that leaks cleartext credentials through the API.
CISA warns that Russian state-backed actors are targeting Zimbra Collaboration Suite users via phishing and a novel zero-day to steal email data.
CISA advisory details vulnerabilities in Weintek cMT3092X HMI that let low-privileged users escalate privileges and view other users' credentials.
CISA added two actively exploited flaws to its KEV Catalog, including a Check Point SmartConsole improper authentication bug directly relevant to identity security.
CISA advisory warns a CVSS 9.8 auth bypass lets unauthenticated attackers gain admin sessions and access stored credentials on Tycon monitoring devices.
CVE-2026-10714 in FactoryTalk Services Platform allows JWT signature bypass, enabling low-privilege users to impersonate authorized accounts.
An unquoted search path vulnerability in Siemens IAM Client lets an authenticated local attacker escalate privileges across many Siemens engineering products.
A critical flaw in Siemens Opcenter X before V2604 lets unauthenticated attackers forge JWTs and impersonate any user, including admins.
A November 2025 breach at AI music tool Suno leaked over 55M unique emails, phone numbers, and tens of thousands of partial Stripe payment records.
A gig economy platform breach leaked over 23M email addresses along with bcrypt password hashes, banking data, and payout history.
CVE-2026-11889 allows an authenticated operator to bypass partition boundaries and access spaces outside their assigned tenancy in SALTO ProAccess Space <6.13.
CISA advisory covers multiple SICAM 8 vulnerabilities, including an unverified password change weakness and insecure default initialization affecting ICS devices.
CISA advisory warns of a stored XSS flaw (CVE-2026-9292) in FactoryTalk DataMosaix that can lead to credential theft and account takeover.
ShinyHunters published 100GB+ of data from test equipment maker Fluke, exposing 800k+ email addresses, names, phone numbers and addresses.
A breach of Goose Creek's Shopify instance leaked 6.6M email addresses along with names, phone numbers, addresses, and order details.
CISA flagged four actively exploited CVEs, including a Microsoft AD FS access-control flaw and SonicWall SMA1000 gateway bugs, mandating federal remediation.
A missing-authentication flaw in Rockwell's 1715-AENTR adapter lets unauthenticated remote attackers run intrusive CLI commands via an exposed debug port.
Three actively exploited SharePoint Server flaws allow unauthorized access, RCE, and IIS machine key theft for persistence across all supported on-prem versions.
Joint advisory details FSB Center 16 opportunistically compromising poorly configured networking devices, including via weak SNMP and default credentials, across critical sectors.
A ShinyHunters 'pay or leak' campaign hit Glendale Community College, leaking nearly 800k emails plus SSNs, names and enrollment data.
CISA advisory flags multiple vulnerabilities in Schneider PowerChute Serial Shutdown <=1.4 that could allow unauthorized account access and credential resets.
CVSS 9.8 access control and session flaws in Hydro-Québec's Le Circuit Electrique charging backend could enable privilege escalation and DoS.
CISA advisory warns of authentication bypass and XSS flaws in Digi International serial device servers that could expose credentials.
A cleartext HTTP transmission flaw (CVE-2026-10763) in PROMOD V could let attackers intercept credentials, hijack sessions, or gain unauthorized access.
A ShinyHunters 'pay or leak' campaign led to 2.3M email addresses and personal details of donors, students and alumni being published publicly.
Satellite terminals expose REST API endpoints without authentication, letting remote attackers pull sensitive device identity data or trigger DoS.
CISA advisory details critical Gardyn IoT Hub vulnerabilities, including a hard-coded privileged key allowing unauthenticated attackers to control managed devices.
CISA warns Delta Electronics DVP12SE PLCs allow unauthenticated Modbus TCP commands, letting remote attackers control device logic without credentials.
CVE-2026-13207 lets remote attackers bypass authentication via dot-segment path tricks to enumerate all users and role assignments in FUXA SCADA/HMI.
CISA advisory warns unauthenticated attackers can access credentials stored in firmware or system files of Schneider Electric RTUs.
CISA warns of critical StoneFly Storage Concentrator vulnerabilities, including hard-coded credentials enabling root-level unauthorized access.
CISA added a SimpleHelp authentication bypass flaw to its KEV Catalog citing active exploitation, requiring rapid federal remediation.
A ShinyHunters extortion attack on Sysco leaked 2.7M email addresses plus names, phone numbers, addresses, and internal job titles.
ShinyHunters published data on 200k+ individuals tied to American Tower after a pay-or-leak extortion attempt, exposing emails, names, addresses, and phone numbers.
CISA warns of path traversal, unrestricted file upload, and hard-coded credential flaws in Daktronics Controller Firmware enabling unauthenticated root-level takeover.
CISA advisory details missing authentication, weak session handling, and exposed credentials in EVoke CSMS, enabling unauthorized admin control of charging stations.
A SSRF flaw in OHIF DICOM Web Viewer (<=v3.12.0) can leak an authenticated clinician's OIDC Bearer token to an attacker-controlled server.
UNC6395 stole OAuth tokens tied to the Salesloft Drift integration and used them to export data — and hunt for cloud credentials — from over 700 organizations' Salesforce instances.
UNC5537 used credentials harvested by infostealer malware — some years old and never rotated — to loot 100+ Snowflake customer databases, including AT&T and Ticketmaster.
BlackCat ransomware actors logged into Change Healthcare's Citrix remote-access portal with stolen credentials and no MFA — the largest healthcare data breach in U.S. history.
A legacy, non-production tenant account with no MFA was compromised by password spray, then abused through OAuth to read senior Microsoft executives' email.
Attackers reused passwords leaked on other sites to break into ~14,000 23andMe accounts, then scraped the DNA Relatives feature to reach 6.9 million users.
Attackers accessed Okta's customer support case-management system and obtained HAR files containing session tokens, which were then used against several downstream customers.
A zero-click Outlook vulnerability (CVE-2023-23397) let attackers capture Net-NTLMv2 authentication hashes simply by sending a crafted email — exploited in the wild before patch.
CVE-2020-1472 let an unauthenticated attacker with network access to a domain controller reset its machine-account password and seize the entire Active Directory domain.