Security News

Curated cybersecurity news and emerging threats relevant to startups, SMBs, and growing teams.

Industry news, vulnerability disclosures, compliance updates, and threat intelligence—handpicked for relevance to your environment.

Each item includes our perspective on why it matters to your security posture.

Polymarket Discloses Third-Party Supply Chain Breach, $3M Stolen

Incident Response Threat Intelligence

Attackers planted malicious code on Polymarket via a third-party vendor, stealing roughly $3M from users. Polymarket has pledged to reimburse affected accounts.

Why it matters: Third-party JavaScript and vendor scripts running on customer-facing pages are a direct path to account and fund theft — review what third-party code executes in your own web properties and whether you'd detect it injecting or exfiltrating data.
Read source →

OpenAI Ships GPT-5.6 With New Flagship Model Sol

AI Threat Intelligence Tools

OpenAI releases three new models under GPT-5.6, with flagship model Sol matching rival Mythos on benchmarks using a third of the output tokens.

Why it matters: Sol's stated focus on both offensive research assistance and model self-defense means attacker tooling and AI-assisted vulnerability discovery are about to get faster — factor that into your threat model and detection priorities, not just your engineering roadmap.
Read source →

Nissan and NAIC Disclose Data Breaches Tied to Oracle PeopleSoft Flaw

Vulnerability Incident Response

More organizations report data leaks from the Oracle PeopleSoft vulnerability, including Nissan factory workers and insurance regulator NAIC.

Why it matters: When a single vendor vulnerability produces a wave of unrelated victims over weeks, assume your own PeopleSoft instances are still exposed until you've confirmed patching and reviewed logs for the exploitation window, not just applied the fix.
Read source →

Nidec Hit by Ransomware, Blackfield Group Demands $2M

Incident Response Threat Intelligence

Japanese auto parts manufacturer Nidec Corporation, with roughly $17B in annual revenue, falls victim to a ransomware attack claimed by the Blackfield group.

Why it matters: A $2M demand against a $17B-revenue manufacturer is a rounding error for the attacker to price low and for the victim to consider paying — ransomware groups increasingly calibrate demands to maximize the odds of a quick payout rather than to match victim size, which should factor into your own incident response cost-benefit planning.
Read source →

Medtronic Update: Stolen Data Pulled From Leak Site, Signaling Possible Ransom Payment

Incident Response Compliance

Medtronic confirms attackers accessed sensitive customer personal and medical data. ShinyHunters has since removed its listing, a pattern usually indicating a ransom was paid.

Why it matters: A removed leak-site listing is not confirmation the data is gone — treat exposed personal and medical data as compromised regardless of payment status, and verify your own breach notification and monitoring obligations don't hinge on an attacker's word.
Read source →

KDDI Discloses Breach Affecting 14.2 Million Customers via Email System

Incident Response Vulnerability

Japanese telecom KDDI reports a data leak affecting roughly 14.2 million customers after attackers gained partial access to its email system through a third-party software flaw.

Why it matters: Email infrastructure is a high-value target precisely because it aggregates customer data and internal correspondence in one place — confirm your own mail platform's third-party plugins and integrations are patched and that access to them is logged and monitored.
Read source →

FortiBleed Campaign Linked to Lynx and INC Ransomware Groups

Vulnerability Threat Intelligence

SOC Radar ties the FortiBleed attack campaign, which scanned 11,250 Fortinet devices and gained domain admin access at 354 organizations, to the Lynx and INC ransomware groups.

Why it matters: If you run Fortinet devices, don't wait for a ransomware deployment to find out you were part of the 354 domain-admin-compromised organizations — audit device patch status and admin account activity against this campaign's timeline now.
Read source →

CISA Orders Agencies to Patch Actively Exploited Cisco UCM Flaw

Vulnerability Regulations

CISA directs federal agencies to urgently update Cisco Unified Communications Manager over a critical vulnerability (CVE-2026-20230) being exploited in the wild.

Why it matters: A CISA binding directive is a strong signal of active, real-world exploitation — if you run Cisco Unified Communications Manager anywhere in your environment, treat CVE-2026-20230 as a same-week patch, not a next-cycle one, regardless of whether you're a federal agency.
Read source →

Attackers Set Up Fake OpenAI Tenants to Harvest Corporate ChatGPT Data

Identity & Access Threat Intelligence Tools

Push Security details a campaign where attackers create legitimate-looking OpenAI tenants impersonating a target company to intercept sensitive employee conversations with ChatGPT.

Why it matters: Employees increasingly treat their org's ChatGPT workspace as trusted internal infrastructure and paste sensitive data into it — if you can't verify tenant legitimacy at invite time, assume some fraction of your team is one convincing invite email away from leaking data to an attacker-controlled tenant.
Read source →

Aflac Discloses Breach at Japan Subsidiary Affecting Millions of Customers

Incident Response Compliance

Insurance company Aflac reports a data breach after attackers compromised its Japan subsidiary, exposing data belonging to millions of customers.

Why it matters: A breach at a regional subsidiary of a multinational insurer is a reminder that global companies are only as strong as their weakest regional entity — if your organization operates through subsidiaries or regional offices, verify security controls and monitoring are consistent across all of them, not just headquarters.
Read source →