Exposed API Endpoint
A misconfigured API endpoint allowed unauthorized users to access data stored in ServiceNow instances. The company did not release a fix until several weeks after receiving a bug bounty report.
Attack on Global Exchange
A major global stock exchange operator has fallen victim to a cyber-espionage campaign after attackers maintained covert access to a senior executive’s email account for five months.
Ransomware Attack on Marks & Spencer
A cyberattack carried out by the Scattered Spider group has cost Marks & Spencer (M&S) CEO Stuart Machin his annual bonus for the 2025/26 financial year.
Lapsus$ Dumps 180GB of Vodafone Data
After a reportedly failed extortion attempt, the cybercrime group Lapsus$ has published around 180 GB of data from Vodafone, including software source code and network plans. According to the company, no customer data appears to be affected.
Unencrypted Protocols
A look at the evolution of cybersecurity suggests that the nature of hacking in the early days of digitalization followed fundamentally different rules than it does in 2026.
Strategy Shift in Iranian Cyberespionage
The hacking group MuddyWater is infiltrating industrial and financial companies across nine countries by smuggling malicious code in through legitimate system files.
Security Nightmare YellowKey
The zero-day exploit known as YellowKey bypasses BitLocker protection on Windows 11. Physical access alone is enough to instantly unlock encrypted drives.
Access to GitHub Infrastructure
Following extortion attempts by the Coinbase Cartel, Grafana Labs has confirmed a cyberattack on its GitHub environment and the theft of source code.
Ransom paid?
The cybercrime group ShinyHunters claims to have stolen nine million records and several terabytes of internal information. Medical technology company Medtronic confirms unauthorized system access, but remains silent on the ransom question.
Insurance company will likely cover the costs
Itron supplies utilities and municipalities worldwide with technology for power, gas and water grids. In mid-April, the company detected unauthorized access to its internal systems.