Industry news, vulnerability disclosures, compliance updates, and threat intelligence—handpicked for relevance to your environment.
Each item includes our perspective on why it matters to your security posture.
Medtronic confirms attackers accessed sensitive customer personal and medical data. ShinyHunters has since removed its listing, a pattern usually indicating a ransom was paid.
Why it matters: A removed leak-site listing is not confirmation the data is gone — treat exposed personal and medical data as compromised regardless of payment status, and verify your own breach notification and monitoring obligations don't hinge on an attacker's word.
Read source →Japanese telecom KDDI reports a data leak affecting roughly 14.2 million customers after attackers gained partial access to its email system through a third-party software flaw.
Why it matters: Email infrastructure is a high-value target precisely because it aggregates customer data and internal correspondence in one place — confirm your own mail platform's third-party plugins and integrations are patched and that access to them is logged and monitored.
Read source →SOC Radar ties the FortiBleed attack campaign, which scanned 11,250 Fortinet devices and gained domain admin access at 354 organizations, to the Lynx and INC ransomware groups.
Why it matters: If you run Fortinet devices, don't wait for a ransomware deployment to find out you were part of the 354 domain-admin-compromised organizations — audit device patch status and admin account activity against this campaign's timeline now.
Read source →CISA directs federal agencies to urgently update Cisco Unified Communications Manager over a critical vulnerability (CVE-2026-20230) being exploited in the wild.
Why it matters: A CISA binding directive is a strong signal of active, real-world exploitation — if you run Cisco Unified Communications Manager anywhere in your environment, treat CVE-2026-20230 as a same-week patch, not a next-cycle one, regardless of whether you're a federal agency.
Read source →Push Security details a campaign where attackers create legitimate-looking OpenAI tenants impersonating a target company to intercept sensitive employee conversations with ChatGPT.
Why it matters: Employees increasingly treat their org's ChatGPT workspace as trusted internal infrastructure and paste sensitive data into it — if you can't verify tenant legitimacy at invite time, assume some fraction of your team is one convincing invite email away from leaking data to an attacker-controlled tenant.
Read source →Insurance company Aflac reports a data breach after attackers compromised its Japan subsidiary, exposing data belonging to millions of customers.
Why it matters: A breach at a regional subsidiary of a multinational insurer is a reminder that global companies are only as strong as their weakest regional entity — if your organization operates through subsidiaries or regional offices, verify security controls and monitoring are consistent across all of them, not just headquarters.
Read source →The US State Department is offering up to $10 million for information on two Russian-linked threat groups that ran phishing campaigns stealing WhatsApp and Signal accounts from government officials.
Why it matters: Phishing campaigns targeting messaging apps like WhatsApp and Signal represent a direct threat to out-of-band communication channels that security teams often treat as safe. If your organization uses consumer messaging apps for any sensitive coordination, this is a reminder to enforce mobile device policies and monitor for account compromise signals.
Read source →CISA confirmed active exploitation of a CVSS 8.8 deserialization flaw in on-prem SharePoint Server, exploitable by any authenticated user with minimal Site Member permissions.
Why it matters: Low privilege requirement plus low attack complexity is a bad combination — any authenticated Site Member is enough to trigger this. If you run on-prem SharePoint Server (Subscription Edition, 2019, or Enterprise 2016), confirm the May 2026 patch is actually installed, not just scheduled.
Read source →Wiz's autonomous red-team agent discovered a BOLA flaw in an airline booking API, exposing customer data and write access to flights, refunds, and cancellations.
Why it matters: Autonomous AI agents are compressing the time from 'API exists' to 'API is fully compromised' down to minutes. If you expose customer-facing APIs, assume both attackers and automated red-teaming tools can now find authorization flaws faster than your manual review cycle catches them.
Read source →Attackers planted malicious code on the Polymarket betting platform via a compromised third-party vendor, stealing approximately $3 million from users.
Why it matters: This is a textbook third-party supply chain attack — the platform itself wasn't breached directly, but a vendor it trusted was. If you don't have visibility into scripts and dependencies loaded from third parties, you won't see this kind of attack until users start losing money.
Read source →