Chinese Hackers Exploited VMware ESXi Zero-Days a Year Before Disclosure
Huntress discovered a Chinese-linked exploit toolkit (MAESTRO) targeting VMware ESXi that was built in February 2024—a year before VMware disclosed CVE-2025-22224. Over 30,000 instances remain exposed.
Iranian MuddyWater APT Deploys New Rust-Based 'RustyWater' Implant
CloudSEK analysis reveals MuddyWater's upgraded toolkit targeting diplomatic, maritime, financial, and telecom entities across the Middle East with Rust-based malware featuring advanced evasion techniques.
Researchers Expose Industrial-Scale 'Pig Butchering' Fraud Infrastructure
Investigation reveals service providers fueling Southeast Asian scam compounds where trafficking victims are forced to conduct investment fraud. Losses exceed $53 billion since 2023, with $17 billion projected for 2025 alone.
National Public Data Breach: 2.9 Billion Records and the Dark Side of Data Brokers
A breach at obscure data broker National Public Data exposed 2.9 billion records containing Social Security numbers for an estimated 170 million Americans, highlighting the unregulated data broker industry and its security failures.
Critical n8n Workflow Automation Flaw Allows Remote Code Execution
CVE-2026-21858 'Ni8mare' (CVSS 10.0) enables unauthenticated attackers to read files, bypass authentication, and execute commands on n8n servers through a Content-Type confusion flaw.
Critical D-Link Router Vulnerability Actively Exploited for Remote Code Execution
CVE-2026-0625 enables unauthenticated remote code execution on legacy D-Link DSL, DIR, and DNS devices via command injection. Attacks observed since November 2025; no patch available for end-of-life devices.
European Space Agency Confirms Data Breach, Criminal Investigation Launched
A threat actor using the alias '888' exfiltrated 200GB+ from ESA systems including Bitbucket repositories, API tokens, and contractor data from SpaceX, Airbus, and Thales. Criminal probe initiated.
Ledger Customer Data Exposed After Third-Party Breach at Global-e
Crypto hardware wallet maker Ledger disclosed that customer names, addresses, and order data were exposed after hackers breached e-commerce partner Global-e. No wallet keys or recovery phrases were compromised.
CDK Global Ransomware Attack: How One Vendor Crippled 15,000 Auto Dealerships
A BlackSuit ransomware attack on CDK Global, the dominant dealer management system provider, shut down operations at 15,000 auto dealerships for nearly two weeks in June 2024, causing over $1 billion in losses and exposing critical supply chain risks.
Blue Shield of California Notifies Members of Healthcare Data Breach
A record merge error during a system enhancement exposed member PHI through Blue Shield's member portal. The October 2025 incident was disclosed in January 2026 under HIPAA requirements.
Claims Management Giant Sedgwick Hit by TridentLocker Ransomware
TridentLocker claims to have stolen 3.4GB from Sedgwick Government Solutions, which provides claims services to DHS, ICE, CBP, DOL, and CISA. The attack targeted an isolated file transfer system.
Brightspeed Investigating Breach Claims After Crimson Collective Posts Customer Data
Extortion group Crimson Collective claims to have stolen data on over 1 million Brightspeed customers, including PII, billing details, and payment information. A class-action lawsuit has been filed.