Data Security

Application Security
Poisoned Xanadu mrmustard Package Steals SSH Keys and AWS Credentials
Threat actors poisoned Xanadu's mrmustard 0.7.4 on PyPI with an info-stealer that exfiltrates SSH keys and AWS credentials from research and HPC systems.
Cybersecurity
ExfilSquad Leaks Contact Data of 100,000 UK Police Officers
ExfilSquad leaked contact data of over 100,000 UK police and staff in a Police National Legal Database breach, enabling phishing against named officers.
Cybersecurity
Liechtenstein Register Breach Exposes Data of 31,000 People
A cyberattack accessed Liechtenstein's beneficial-ownership register, exposing data on about 31,000 people behind companies and foundations, officials said.
Cybersecurity
UKGI Left Officials’ Contact Details Exposed for 40 Hours
UK Government Investments admitted an employee left a file with 51 government officials' names and work email addresses publicly accessible for 40 hours.
CVE Vulnerability Alerts
Thermo Fisher Patches DNA File Tampering Flaw CVE-2026-17583
Thermo Fisher patched CVE-2026-17583 in Applied Biosystems DNA-testing software, allowing forensic evidence file alterations to pass with little detection.
Application Security
Hackers Poison Adform Script to Rewrite Crypto Wallet Addresses
Attackers tampered with Adform's trackpoint script, rewriting crypto wallet addresses across customer pages to divert payments to attacker-controlled wallets.
Application Security
Wiz CosmosEscape Chain Exposed Azure Cosmos DB Tenant Keys
Wiz researchers showed an Azure Cosmos DB Gremlin sandbox escape could expose a platform-wide signing key that unlocks any tenant account's primary keys.
Application Security
Claude Models Breached 3 Real Firms During Anthropic Cyber Tests
Anthropic said Claude models breached three real organizations during evaluations, including publishing PyPI malware that stole a security vendor's credentials.
Cybersecurity
South Korea Fines KT $39 Million Over 11-Month Breach
South Korea's data regulator fined telecom giant KT KRW 53.979 billion after an 11-month breach exposed 16,647 subscribers' data through a rogue femtocell.
Cybersecurity
ShinyHunters Claims Brinks Home Breach of Up to 4.9 Million Records
ShinyHunters claims it breached Brinks Home in a Microsoft Entra vishing attack and stole up to 4.9 million Salesforce records and 3.8 million support chats.