Data Security

Application Security
Attackers Compile khunt Inside Oracle to Reach Windows SYSTEM
Huntress traced credential-theft alerts to attackers who compiled the khunt toolkit inside Oracle to reach SYSTEM-level code execution on a Windows server.
Cybersecurity
Snowflake Hacker Pleads Guilty Over Breaches Affecting 100 Million
Connor Riley Moucka pleaded guilty in Seattle federal court to intrusions into 165 Snowflake customers that exposed records of more than 100 million people.
Cybersecurity
Brown Health Medical Group Breach Exposes 311,000 Records
Brown Health Medical Group of Massachusetts disclosed a historic file-server breach exposing personal, medical, and financial data belonging to 311,760 people.
Application Security
ChainDrop npm Worm Poisons 440 Packages, Steals Cloud Credentials
The ChainDrop npm worm, a new Shai-Hulud variant, poisoned over 440 registry packages and uses stolen tokens to republish malware and reach cloud credentials.
Application Security
tl;dv AI Notetaker Flaw Exposes Government, Corporate Calls
A Google Firebase misconfiguration in the tl;dv AI meeting tool lets users query others' meeting data and potentially join calls, exposing sensitive briefings.
Application Security
Poisoned Xanadu mrmustard Package Steals SSH Keys and AWS Credentials
Threat actors poisoned Xanadu's mrmustard 0.7.4 on PyPI with an info-stealer that exfiltrates SSH keys and AWS credentials from research and HPC systems.
Cybersecurity
ExfilSquad Leaks Contact Data of 100,000 UK Police Officers
ExfilSquad leaked contact data of over 100,000 UK police and staff in a Police National Legal Database breach, enabling phishing against named officers.
Cybersecurity
Liechtenstein Register Breach Exposes Data of 31,000 People
A cyberattack accessed Liechtenstein's beneficial-ownership register, exposing data on about 31,000 people behind companies and foundations, officials said.
Cybersecurity
UKGI Left Officials’ Contact Details Exposed for 40 Hours
UK Government Investments admitted an employee left a file with 51 government officials' names and work email addresses publicly accessible for 40 hours.
CVE Vulnerability Alerts
Thermo Fisher Patches DNA File Tampering Flaw CVE-2026-17583
Thermo Fisher patched CVE-2026-17583 in Applied Biosystems DNA-testing software, allowing forensic evidence file alterations to pass with little detection.