<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>CipherWatch — Asset Security</title><description>Security intelligence covering Asset Security: Data classification, ownership, privacy protection, retention policies, and data security standards.</description><link>https://cipherwatch.io/</link><language>en-gb</language><item><title>iRhythm Cardiac Monitoring Breach Exposes Patient PHI for 12 Million Zio Patch Wearers</title><link>https://cipherwatch.io/articles/2026-06-16-irhythm-cardiac-monitoring-data-breach-phi/</link><guid isPermaLink="true">https://cipherwatch.io/articles/2026-06-16-irhythm-cardiac-monitoring-data-breach-phi/</guid><description>iRhythm Holdings disclosed a data breach after social engineering granted attackers access to third-party systems hosting protected health information for approximately 12 million patients. A ransom demand was received on 9 June, and HIPAA breach notification timelines are now active for any covered entity whose patient data iRhythm processes.</description><pubDate>Tue, 16 Jun 2026 00:00:00 GMT</pubDate><category>healthcare</category><category>data-breach</category><category>phi</category><category>hipaa</category><category>social-engineering</category><category>ransomware</category></item><item><title>Novo Nordisk Discloses Breach of Clinical Trial Participant Data — Ozempic and GLP-1 Research Records Exposed</title><link>https://cipherwatch.io/articles/2026-06-15-novo-nordisk-clinical-trials-data-breach/</link><guid isPermaLink="true">https://cipherwatch.io/articles/2026-06-15-novo-nordisk-clinical-trials-data-breach/</guid><description>Danish pharmaceutical giant Novo Nordisk has disclosed a cybersecurity incident in which attackers gained unauthorised access to IT systems holding personal data of clinical trial participants, including individuals enrolled in GLP-1 receptor agonist trials for Ozempic and Wegovy. The breach raises significant regulatory concerns under EU clinical trial data protection requirements and the ICH GCP framework governing trial participant data handling.</description><pubDate>Mon, 15 Jun 2026 00:00:00 GMT</pubDate><category>pharmaceutical</category><category>clinical-trials</category><category>healthcare</category><category>data-breach</category><category>gdpr</category><category>novo-nordisk</category><category>gcp</category><category>trial-participant-data</category></item><item><title>Dell DSA-2026-239: CVE-2026-23856 Privilege Escalation in iDRAC9 Exposes PowerEdge Server Management Plane</title><link>https://cipherwatch.io/articles/2026-06-14-dell-idrac-dsa-2026-239-privilege-escalation-poweredge/</link><guid isPermaLink="true">https://cipherwatch.io/articles/2026-06-14-dell-idrac-dsa-2026-239-privilege-escalation-poweredge/</guid><description>Dell has patched a high-severity privilege escalation vulnerability in the iDRAC9 remote management controller affecting PowerEdge servers across multiple generations. CVE-2026-23856, rated CVSS 8.8, allows a low-privileged authenticated attacker to escalate to Administrator rights on the iDRAC management plane — granting control over server power, firmware, BIOS settings, and virtual console access outside the scope of the host operating system.</description><pubDate>Sun, 14 Jun 2026 00:00:00 GMT</pubDate><category>dell</category><category>idrac</category><category>cve-2026-23856</category><category>privilege-escalation</category><category>poweredge</category><category>server-management</category><category>hardware-security</category><category>bmc</category></item><item><title>Managing Chrome V8 Zero-Days in Enterprise Fleets: Browser Asset Inventory and Rapid Update Strategies</title><link>https://cipherwatch.io/articles/2026-06-13-chrome-enterprise-browser-management-zero-day/</link><guid isPermaLink="true">https://cipherwatch.io/articles/2026-06-13-chrome-enterprise-browser-management-zero-day/</guid><description>CVE-2026-11645&apos;s active exploitation before the patch highlights a persistent gap in enterprise browser management: many organisations do not maintain accurate browser version inventories or have the ability to push browser updates faster than the standard monthly patch cycle. This guide covers Chrome fleet management, version enforcement, and emergency update deployment.</description><pubDate>Sat, 13 Jun 2026 00:00:00 GMT</pubDate><category>chrome</category><category>google</category><category>browser-security</category><category>asset-management</category><category>cve-2026-11645</category><category>enterprise-browser</category><category>fleet-management</category><category>group-policy</category><category>intune</category><category>cbcm</category></item><item><title>Windows Server Fleet Patching After June Patch Tuesday: Managing Velocity and Risk in Large Environments</title><link>https://cipherwatch.io/articles/2026-06-11-windows-server-patch-velocity-june-2026-enterprise/</link><guid isPermaLink="true">https://cipherwatch.io/articles/2026-06-11-windows-server-patch-velocity-june-2026-enterprise/</guid><description>After the largest Microsoft Patch Tuesday of 2026, enterprise teams face the challenge of patching Windows Server fleets at emergency speed while avoiding the outages that come with untested updates. This article addresses patch deployment sequencing, testing compression strategies, and rollback planning for the June 2026 emergency patch cycle.</description><pubDate>Thu, 11 Jun 2026 00:00:00 GMT</pubDate><category>windows-server</category><category>patch-management</category><category>asset-management</category><category>wsus</category><category>sccm</category><category>intune</category><category>vulnerability-management</category><category>patch-velocity</category><category>enterprise-operations</category></item><item><title>Free Apps Are Turning Smart TVs Into Residential Proxy Nodes — Without User Consent</title><link>https://cipherwatch.io/articles/2026-06-06-free-apps-smart-tvs-residential-proxy-nodes-ai-scraping/</link><guid isPermaLink="true">https://cipherwatch.io/articles/2026-06-06-free-apps-smart-tvs-residential-proxy-nodes-ai-scraping/</guid><description>Research published this week reveals that multiple free consumer applications are silently enrolling Android TV devices and Smart TV platforms as exit nodes for residential proxy networks, routing third-party AI web scraping and data harvesting traffic through household internet connections. Users receive free app access; their bandwidth and IP address are sold to commercial proxy operators without meaningful disclosure.</description><pubDate>Sat, 06 Jun 2026 00:00:00 GMT</pubDate><category>smart-tv</category><category>residential-proxy</category><category>android-tv</category><category>consumer-devices</category><category>privacy</category><category>unauthorized-access</category><category>iot-security</category><category>shadow-infrastructure</category></item><item><title>Magento and eCommerce Platform Security: Knowing What You Run and What You Owe Customers</title><link>https://cipherwatch.io/articles/2026-06-05-magento-ecommerce-platform-security-inventory/</link><guid isPermaLink="true">https://cipherwatch.io/articles/2026-06-05-magento-ecommerce-platform-security-inventory/</guid><description>CVE-2026-45247&apos;s CISA KEV status means organisations running Mirasvit Full Page Cache Warmer are now under a federal mandate to remediate — and should be asking whether their eCommerce platform inventory is accurate enough to comply. Magento deployments often span multiple versions, extension states, and customisation layers that make attack surface visibility a genuine challenge.</description><pubDate>Fri, 05 Jun 2026 00:00:00 GMT</pubDate><category>magento</category><category>ecommerce</category><category>cve-2026-45247</category><category>asset-inventory</category><category>pci-dss</category><category>platform-security</category><category>extension-management</category></item><item><title>Linux Kernel Patch Management as Asset Security: Why CVE-2026-46243 Exposes the Kernel Update Gap</title><link>https://cipherwatch.io/articles/2026-06-03-linux-kernel-patch-enterprise-asset-management/</link><guid isPermaLink="true">https://cipherwatch.io/articles/2026-06-03-linux-kernel-patch-enterprise-asset-management/</guid><description>The CVE-2026-46243 disclosure — a 19-year-old kernel flaw with a public root exploit and distribution patches already available — is a useful lens for examining how enterprises manage Linux kernel versions as security-relevant assets. Many organisations have robust patch management for applications but inconsistent processes for kernel updates, particularly on specialised infrastructure like database hosts and container nodes.</description><pubDate>Wed, 03 Jun 2026 00:00:00 GMT</pubDate><category>linux</category><category>kernel</category><category>patch-management</category><category>asset-management</category><category>cve-2026-46243</category><category>vulnerability-management</category><category>fleet-tracking</category></item><item><title>Android Enterprise Patch Management: Closing the Gap Between Google&apos;s Bulletin and Fleet-Wide Coverage</title><link>https://cipherwatch.io/articles/2026-06-02-android-enterprise-mobile-patch-management-emm/</link><guid isPermaLink="true">https://cipherwatch.io/articles/2026-06-02-android-enterprise-mobile-patch-management-emm/</guid><description>The June 2026 Android Security Bulletin — which includes an actively exploited zero-day — highlights a structural challenge for enterprise Android fleet management: Google publishes a patch, but enterprise coverage depends on OEM update timelines, carrier approval processes, and EMM deployment policies that can extend the effective exposure window by weeks. This guide covers a practical approach to managing the gap.</description><pubDate>Tue, 02 Jun 2026 00:00:00 GMT</pubDate><category>android</category><category>mobile-security</category><category>emm</category><category>enterprise-mobility</category><category>patch-management</category><category>mdm</category><category>intune</category><category>asset-management</category><category>samsung-knox</category></item><item><title>AMD Zen 2 Firmware Update Strategy: Managing CPU Microcode Patches Across Enterprise Hardware</title><link>https://cipherwatch.io/articles/2026-05-28-amd-cpu-firmware-enterprise-asset-management/</link><guid isPermaLink="true">https://cipherwatch.io/articles/2026-05-28-amd-cpu-firmware-enterprise-asset-management/</guid><description>CVE-2026-46174 requires a PI firmware (BIOS/UEFI) update to deliver the AMD Zen 2 microcode fix — not a software patch. For enterprises running AMD EPYC Rome servers or Zen 2-based workstations, this means a separate patch track from OS-level vulnerability management. An asset-based approach to CPU generation inventory is the prerequisite.</description><pubDate>Thu, 28 May 2026 00:00:00 GMT</pubDate><category>amd</category><category>zen2</category><category>firmware</category><category>asset-management</category><category>microcode</category><category>epyc</category><category>bios-update</category><category>hardware-security</category></item><item><title>Apple Retroactively Publishes CVE Details for macOS, iOS, and visionOS — Including Root Escalation and Siri Privacy Bypass</title><link>https://cipherwatch.io/articles/2026-05-26-apple-retroactive-cve-disclosures-macos-ios-transparency/</link><guid isPermaLink="true">https://cipherwatch.io/articles/2026-05-26-apple-retroactive-cve-disclosures-macos-ios-transparency/</guid><description>Apple updated multiple security pages on 26 May to add CVE identifiers and technical details for vulnerabilities that were patched weeks or months earlier with minimal public disclosure. The retroactively disclosed issues include a CoreServices root escalation via malicious app, a Siri Private Browsing bypass, and a call history fingerprinting flaw — none were disclosed as separate security updates at the time of patching.</description><pubDate>Tue, 26 May 2026 00:00:00 GMT</pubDate><category>apple</category><category>macos</category><category>ios</category><category>cve-disclosure</category><category>transparency</category><category>privacy</category><category>root-escalation</category><category>patch-management</category></item><item><title>SonicWall EoL Highlights an Asset Management Gap: Network Equipment Lifecycle Tracking in Enterprise Environments</title><link>https://cipherwatch.io/articles/2026-05-19-eolife-network-equipment-asset-management-lifecycle/</link><guid isPermaLink="true">https://cipherwatch.io/articles/2026-05-19-eolife-network-equipment-asset-management-lifecycle/</guid><description>The SonicWall Generation 6 end-of-life situation reveals a consistent gap in enterprise asset management: network equipment EoL dates are not tracked with the same rigour as software licence renewals or server hardware refresh cycles. Organisations with accurate, proactively managed network equipment lifecycle records have a weeks-to-months advantage in responding to EoL-driven security risks.</description><pubDate>Tue, 19 May 2026 00:00:00 GMT</pubDate><category>asset-management</category><category>end-of-life</category><category>network-equipment</category><category>sonicwall</category><category>vpn</category><category>lifecycle</category><category>cmdb</category></item><item><title>TeamPCP Gang Advertising Stolen Mistral AI Source Code Repositories for Sale — Part of Shai-Hulud Supply Chain Campaign</title><link>https://cipherwatch.io/articles/2026-05-15-teampcp-mistral-ai-code-repository-theft/</link><guid isPermaLink="true">https://cipherwatch.io/articles/2026-05-15-teampcp-mistral-ai-code-repository-theft/</guid><description>The TeamPCP extortion group is advertising stolen Mistral AI source code repositories on dark web forums, claiming access was obtained as a side effect of the Shai-Hulud npm supply chain campaign targeting AI development infrastructure. The breach potentially exposes Mistral&apos;s proprietary model training code, API infrastructure, and internal tooling to competitors and nation-state actors.</description><pubDate>Fri, 15 May 2026 00:00:00 GMT</pubDate><category>mistral-ai</category><category>source-code-theft</category><category>teampcp</category><category>supply-chain</category><category>intellectual-property</category></item><item><title>Zara Confirms Data Breach Affecting 197,000 Customers — ShinyHunters&apos; April Extortion Claim Now Substantiated</title><link>https://cipherwatch.io/articles/2026-05-11-zara-inditex-data-breach-197k-confirmed/</link><guid isPermaLink="true">https://cipherwatch.io/articles/2026-05-11-zara-inditex-data-breach-197k-confirmed/</guid><description>Inditex has confirmed that a breach of Zara customer data exposed the personal information of approximately 197,000 people, substantiating the ShinyHunters extortion claim from late April 2026. Exposed data includes names, email addresses, postal addresses, phone numbers, and purchase history. European GDPR notification has been filed and affected customers are being contacted.</description><pubDate>Mon, 11 May 2026 00:00:00 GMT</pubDate><category>zara</category><category>inditex</category><category>data-breach</category><category>shinyhunters</category><category>gdpr</category><category>retail</category><category>customer-data</category><category>pii</category></item><item><title>OpenEMR: Three Critical Vulnerabilities Expose Patient Records Across 100,000 Healthcare Providers</title><link>https://cipherwatch.io/articles/2026-05-07-openemr-critical-cves-100k-healthcare-providers/</link><guid isPermaLink="true">https://cipherwatch.io/articles/2026-05-07-openemr-critical-cves-100k-healthcare-providers/</guid><description>Aisle security researchers have disclosed 38 vulnerabilities in OpenEMR — the world&apos;s most widely deployed open-source electronic medical records and practice management system, used by over 100,000 healthcare providers globally. Three of the vulnerabilities are critical, allowing unauthenticated remote code execution and patient record exfiltration. OpenEMR 7.0.2 patch 2 addresses all reported issues; unpatched instances are a direct patient data and regulatory liability.</description><pubDate>Thu, 07 May 2026 00:00:00 GMT</pubDate><category>openemr</category><category>healthcare</category><category>emr</category><category>patient-data</category><category>critical-vulnerability</category><category>rce</category><category>hipaa</category><category>gdpr</category><category>medical-records</category></item><item><title>Salesforce Marketing Cloud Server-Side Template Injection Exposed Entire Customer Contact Database</title><link>https://cipherwatch.io/articles/2026-05-06-salesforce-marketing-cloud-ssti-contacts-db-exposure/</link><guid isPermaLink="true">https://cipherwatch.io/articles/2026-05-06-salesforce-marketing-cloud-ssti-contacts-db-exposure/</guid><description>SL Cyber researchers have disclosed five patched vulnerabilities in Salesforce Marketing Cloud (ExactTarget), the most critical of which — a server-side template injection flaw — allowed an authenticated marketing user to exfiltrate the complete contacts database and historical email campaign content of any Salesforce Marketing Cloud instance. The vulnerabilities were patched by Salesforce; organisations should verify which contact data and historical communications were accessible to marketing team members.</description><pubDate>Wed, 06 May 2026 00:00:00 GMT</pubDate><category>salesforce</category><category>marketing-cloud</category><category>template-injection</category><category>data-exposure</category><category>ssti</category><category>crm</category><category>contact-data</category><category>gdpr</category></item><item><title>Instructure (Canvas LMS) Discloses Cybersecurity Incident — Scope of Student and Faculty Data Exposure Under Investigation</title><link>https://cipherwatch.io/articles/2026-05-03-instructure-canvas-lms-data-breach/</link><guid isPermaLink="true">https://cipherwatch.io/articles/2026-05-03-instructure-canvas-lms-data-breach/</guid><description>Instructure, the company behind Canvas Learning Management System used by thousands of universities and K-12 school districts globally, has disclosed a cybersecurity incident affecting an internal infrastructure component. The scope of student, faculty, and institutional data potentially exposed is under forensic investigation. Institutions running Canvas should activate their incident response contact with Instructure and review data sharing scope.</description><pubDate>Sun, 03 May 2026 00:00:00 GMT</pubDate><category>data-breach</category><category>education</category><category>lms</category><category>student-data</category><category>ferpa</category><category>privacy</category></item><item><title>Trellix Confirms Source Code Repository Breach — Forensic Investigation Underway</title><link>https://cipherwatch.io/articles/2026-05-02-trellix-source-code-repository-breach/</link><guid isPermaLink="true">https://cipherwatch.io/articles/2026-05-02-trellix-source-code-repository-breach/</guid><description>Cybersecurity vendor Trellix has confirmed unauthorised access to an internal source code repository, with law enforcement notified and a forensic investigation ongoing. The breach raises concerns about potential weaponisation of security product internals against Trellix&apos;s enterprise customer base.</description><pubDate>Sat, 02 May 2026 00:00:00 GMT</pubDate><category>data-breach</category><category>source-code-theft</category><category>security-vendor</category><category>threat-intelligence</category><category>supply-chain</category></item><item><title>DPRK Scales npm Malware Campaign With AI-Generated Code, Fake Tech Firms, and Remote RAT Deployment</title><link>https://cipherwatch.io/articles/2026-05-01-dprk-ai-npm-malware-fake-firms/</link><guid isPermaLink="true">https://cipherwatch.io/articles/2026-05-01-dprk-ai-npm-malware-fake-firms/</guid><description>North Korean threat actors have launched a new wave of npm supply chain attacks using AI-generated malicious package code that bypasses static analysis tools, fake software development firms as cover identities, and a multi-stage RAT that exfiltrates source code, cryptographic keys, and credentials from developer workstations. The campaign targets blockchain, DeFi, and fintech developers — organisations in these sectors should audit npm dependencies and developer machine security.</description><pubDate>Fri, 01 May 2026 00:00:00 GMT</pubDate><category>dprk</category><category>north-korea</category><category>npm</category><category>supply-chain</category><category>ai-generated-malware</category><category>source-code-theft</category><category>crypto-theft</category><category>rat</category></item><item><title>Medtronic Confirms Data Breach — ShinyHunters Claims 9 Million Medical Device Patient Records Stolen</title><link>https://cipherwatch.io/articles/2026-04-28-medtronic-breach-shinyhunters-9-million-medical-records/</link><guid isPermaLink="true">https://cipherwatch.io/articles/2026-04-28-medtronic-breach-shinyhunters-9-million-medical-records/</guid><description>Medtronic, the world&apos;s largest medical device manufacturer, has confirmed a data breach after the ShinyHunters threat actor claimed to have stolen nine million patient records. The breach includes patient names, device serial numbers, implant dates, clinic details, and in some cases diagnostic data from cardiac, diabetes, and spinal device programmes across 150 countries. Regulatory notifications under HIPAA, GDPR, and MDR are expected.</description><pubDate>Tue, 28 Apr 2026 00:00:00 GMT</pubDate><category>breach</category><category>healthcare</category><category>medical-devices</category><category>shinyhunters</category><category>gdpr</category><category>hipaa</category><category>patient-data</category></item><item><title>Rituals Cosmetics Discloses Data Breach — Up to 40 Million My Rituals Members&apos; PII Potentially Exposed</title><link>https://cipherwatch.io/articles/2026-04-28-rituals-cosmetics-data-breach-40-million/</link><guid isPermaLink="true">https://cipherwatch.io/articles/2026-04-28-rituals-cosmetics-data-breach-40-million/</guid><description>Amsterdam-based luxury cosmetics brand Rituals has disclosed a breach of its My Rituals membership platform affecting potentially up to 40 million registered members across its 1,170-plus retail locations in 37 countries. Exposed data includes names, contact details, date of birth, gender, and purchase history. The breach carries significant GDPR obligations as Rituals is headquartered in the EU.</description><pubDate>Tue, 28 Apr 2026 00:00:00 GMT</pubDate><category>breach</category><category>gdpr</category><category>retail</category><category>pii</category><category>membership-data</category><category>eu-data-protection</category></item><item><title>France Titres (ANTS) Breach Exposes 11.7 Million Citizens&apos; Identity Records</title><link>https://cipherwatch.io/articles/2026-04-26-france-titres-ants-breach-11m-identity-records/</link><guid isPermaLink="true">https://cipherwatch.io/articles/2026-04-26-france-titres-ants-breach-11m-identity-records/</guid><description>France&apos;s national secure-ID document agency confirmed a breach affecting 11.7 million citizens — roughly one in five residents — after threat actor &apos;breach3d&apos; claimed to have exfiltrated records including names, dates of birth, addresses, email addresses, and phone numbers. CNIL, ANSSI, and the Paris Public Prosecutor have been notified. Organisations operating in France face elevated customer account fraud and social engineering risk from the compromised data.</description><pubDate>Sun, 26 Apr 2026 00:00:00 GMT</pubDate><category>data-breach</category><category>pii</category><category>government</category><category>identity</category><category>gdpr</category><category>france</category></item><item><title>ADT Confirms Customer Data Breach After ShinyHunters Vishing Attack on Help Desk</title><link>https://cipherwatch.io/articles/2026-04-25-adt-breach-shinyhunters-vishing-customer-pii/</link><guid isPermaLink="true">https://cipherwatch.io/articles/2026-04-25-adt-breach-shinyhunters-vishing-customer-pii/</guid><description>ADT, the US home and business security monitoring provider, has confirmed a data breach after ShinyHunters used voice phishing to social-engineer a support employee into granting access to customer management systems. Names, phone numbers, and account data were exfiltrated. The incident underlines how thoroughly attackers have made help desk social engineering a standard tool.</description><pubDate>Sat, 25 Apr 2026 00:00:00 GMT</pubDate><category>data-breach</category><category>vishing</category><category>shinyhunters</category><category>social-engineering</category><category>pii</category><category>help-desk</category></item><item><title>26 Fake Crypto Wallet Apps Found on Apple App Store Harvesting Mnemonic Seed Phrases</title><link>https://cipherwatch.io/articles/2026-04-24-fake-crypto-wallet-apps-apple-app-store-seed-phrase-theft/</link><guid isPermaLink="true">https://cipherwatch.io/articles/2026-04-24-fake-crypto-wallet-apps-apple-app-store-seed-phrase-theft/</guid><description>Researchers have discovered 26 malicious applications that bypassed Apple&apos;s App Store review and actively harvest cryptocurrency wallet seed phrases from victims. Users who installed any suspect app should rotate all wallet credentials immediately — mnemonic phrase compromise results in permanent, irreversible asset loss.</description><pubDate>Fri, 24 Apr 2026 00:00:00 GMT</pubDate><category>mobile-security</category><category>cryptocurrency</category><category>malware</category><category>apple</category><category>data-theft</category></item><item><title>Sanctioned Russian Crypto Exchange Grinex Shut Down After $13.74M Hack — Blames Western Intelligence</title><link>https://cipherwatch.io/articles/2026-04-23-grinex-sanctioned-crypto-exchange-13m-hack/</link><guid isPermaLink="true">https://cipherwatch.io/articles/2026-04-23-grinex-sanctioned-crypto-exchange-13m-hack/</guid><description>Grinex, a cryptocurrency exchange linked to the sanctioned Garantex operation, suspended all services after attackers drained $13.74 million in a targeted April 15 incident. The exchange blamed &apos;hostile state intelligence agencies,&apos; pointing to the attack&apos;s technical sophistication. Elliptic and Chainalysis analysts have traced the funds but stop short of confirming attribution. The shutdown removes a significant node in Russia&apos;s sanctions-evasion infrastructure.</description><pubDate>Thu, 23 Apr 2026 00:00:00 GMT</pubDate><category>crypto-theft</category><category>sanctions-evasion</category><category>russia</category><category>grinex</category><category>garantex</category><category>state-sponsored</category><category>financial-crime</category></item><item><title>Everest Ransomware Claims Citizens Bank Breach — 380 GB Including 250,000 SSNs and 3.4 Million Records</title><link>https://cipherwatch.io/articles/2026-04-22-everest-ransomware-citizens-bank-data-breach/</link><guid isPermaLink="true">https://cipherwatch.io/articles/2026-04-22-everest-ransomware-citizens-bank-data-breach/</guid><description>The Everest ransomware group claims to have stolen 380 GB of Citizens Bank customer data via a third-party vendor, including 250,000 Social Security Numbers and 3.4 million banking records. Citizens attributes the breach to a vendor, not its core systems — but regulatory notification obligations apply regardless.</description><pubDate>Wed, 22 Apr 2026 00:00:00 GMT</pubDate><category>ransomware</category><category>everest</category><category>data-breach</category><category>financial-sector</category><category>third-party-risk</category><category>pii-exposure</category></item><item><title>ShinyHunters Claims Breaches at Zara, Carnival, and 7-Eleven — Extortion Deadline Set</title><link>https://cipherwatch.io/articles/2026-04-22-shinyhunters-zara-carnival-7-eleven-extortion/</link><guid isPermaLink="true">https://cipherwatch.io/articles/2026-04-22-shinyhunters-zara-carnival-7-eleven-extortion/</guid><description>Prolific threat actor ShinyHunters posted simultaneous claims of data theft from Inditex/Zara, Carnival Corporation, and 7-Eleven on dark web forums on 21 April, threatening to publish stolen datasets. None of the companies has confirmed the breaches. Given ShinyHunters&apos; track record, claims should be treated as credible pending investigation.</description><pubDate>Wed, 22 Apr 2026 00:00:00 GMT</pubDate><category>data-breach</category><category>shinyhunters</category><category>extortion</category><category>retail</category><category>dark-web</category><category>pii-exposure</category><category>data-broker</category></item><item><title>McGraw Hill Confirms 13.5 Million Account Breach After ShinyHunters Exploits Salesforce Misconfiguration</title><link>https://cipherwatch.io/articles/2026-04-19-mcgraw-hill-shinyhunters-salesforce-breach/</link><guid isPermaLink="true">https://cipherwatch.io/articles/2026-04-19-mcgraw-hill-shinyhunters-salesforce-breach/</guid><description>Education publisher McGraw Hill has confirmed a data breach affecting 13.5 million accounts after the ShinyHunters cybercriminal group threatened to publish 45 million Salesforce records. The breach stemmed from a misconfiguration within Salesforce&apos;s environment — one McGraw Hill acknowledges is part of a broader issue affecting multiple organisations. Over 100GB of data has been publicly released.</description><pubDate>Sun, 19 Apr 2026 00:00:00 GMT</pubDate><category>data-breach</category><category>shinyhunters</category><category>salesforce</category><category>misconfiguration</category><category>cloud-security</category><category>edtech</category><category>extortion</category><category>third-party-risk</category></item><item><title>Standard Bank Breach: 1.2TB of Client Data — Including Credit Card Details — Published Online</title><link>https://cipherwatch.io/articles/2026-04-17-standard-bank-breach-1-2tb-client-data-leaked/</link><guid isPermaLink="true">https://cipherwatch.io/articles/2026-04-17-standard-bank-breach-1-2tb-client-data-leaked/</guid><description>A threat actor claiming to have spent three weeks inside Standard Bank&apos;s network has published approximately 1.2TB of stolen data online, including client names, national identity numbers, account details, and a subset of credit card numbers. One of Africa&apos;s largest banks, Standard Bank operates across more than 20 countries and holds significant international exposure. The double-extortion attack pattern and lessons for database-layer monitoring are directly relevant to financial services defenders globally.</description><pubDate>Fri, 17 Apr 2026 00:00:00 GMT</pubDate><category>data-breach</category><category>financial-services</category><category>double-extortion</category><category>credit-card</category><category>database-security</category><category>incident-response</category></item><item><title>Basic-Fit Breach Exposes Personal and Bank Data of One Million European Gym Members</title><link>https://cipherwatch.io/articles/2026-04-14-basic-fit-breach-one-million-european-members/</link><guid isPermaLink="true">https://cipherwatch.io/articles/2026-04-14-basic-fit-breach-one-million-european-members/</guid><description>Dutch fitness chain Basic-Fit has disclosed a data breach affecting approximately one million members across six European countries, with bank account details among the compromised data. The breach targeted the company&apos;s visit-tracking system, exposing names, contact details, dates of birth, and banking information. GDPR notifications have been filed.</description><pubDate>Tue, 14 Apr 2026 00:00:00 GMT</pubDate><category>breach</category><category>basic-fit</category><category>gdpr</category><category>europe</category><category>personal-data</category><category>banking-data</category><category>netherlands</category><category>data-classification</category></item><item><title>Booking.com Breach Exposes Reservation Data — Phishing Wave Follows</title><link>https://cipherwatch.io/articles/2026-04-12-booking-com-reservation-data-breach-phishing-risk/</link><guid isPermaLink="true">https://cipherwatch.io/articles/2026-04-12-booking-com-reservation-data-breach-phishing-risk/</guid><description>Booking.com has disclosed unauthorised access to customer reservation data including names, contact details, and booking information. No payment data was taken, but the exposed reservation details create a high-quality dataset for targeted travel-themed phishing campaigns. Reservation PINs have been reset across affected bookings.</description><pubDate>Sun, 12 Apr 2026 00:00:00 GMT</pubDate><category>breach</category><category>booking-com</category><category>phishing</category><category>travel</category><category>data-exposure</category><category>gdpr</category><category>personal-data</category></item><item><title>World Leaks Exposes 7.7TB of LAPD Records After City Attorney&apos;s Discovery Tool Breach</title><link>https://cipherwatch.io/articles/2026-04-10-lapd-world-leaks-city-attorney-breach/</link><guid isPermaLink="true">https://cipherwatch.io/articles/2026-04-10-lapd-world-leaks-city-attorney-breach/</guid><description>Extortion group World Leaks has published more than 337,000 sensitive LAPD files — including officer personnel records, Internal Affairs investigations, and witness medical information — after breaching a third-party legal discovery transfer tool used by the Los Angeles City Attorney&apos;s Office. The incident illustrates how legal and compliance workflows that touch sensitive data are increasingly targeted as a softer entry point than agency systems themselves.</description><pubDate>Fri, 10 Apr 2026 00:00:00 GMT</pubDate><category>data-breach</category><category>extortion</category><category>third-party-risk</category><category>police-records</category><category>discovery-data</category><category>world-leaks</category><category>sensitive-data</category></item><item><title>ShinyHunters Breach Anodot SaaS Integrator, Steal Snowflake Customer Data via Harvested Tokens</title><link>https://cipherwatch.io/articles/2026-04-09-anodot-snowflake-saas-integrator-breach/</link><guid isPermaLink="true">https://cipherwatch.io/articles/2026-04-09-anodot-snowflake-saas-integrator-breach/</guid><description>The ShinyHunters threat group breached Anodot, an AI analytics platform used to integrate with Snowflake cloud data warehouses, and stole authentication tokens that enabled downstream data theft from over a dozen Snowflake customer environments. The attack is a textbook fourth-party risk incident: the direct target was not the victim organisations&apos; systems but a trusted third-party integration layer.</description><pubDate>Thu, 09 Apr 2026 00:00:00 GMT</pubDate><category>snowflake</category><category>anodot</category><category>saas</category><category>supply-chain</category><category>shinyhunters</category><category>data-theft</category><category>token-theft</category><category>third-party-risk</category><category>cloud-security</category></item><item><title>ChipSoft Ransomware Attack Takes Down Patient Records Across 80% of Dutch Hospitals</title><link>https://cipherwatch.io/articles/2026-04-08-chipsoft-ransomware-dutch-healthcare/</link><guid isPermaLink="true">https://cipherwatch.io/articles/2026-04-08-chipsoft-ransomware-dutch-healthcare/</guid><description>Dutch healthcare IT vendor ChipSoft, whose HiX electronic patient record system is used by approximately 80% of hospitals in the Netherlands, was struck by a ransomware attack on 7 April. Eleven hospitals have disconnected from ChipSoft systems and reverted to emergency paper procedures. ChipSoft has confirmed a &apos;data incident&apos; with possible unauthorised access to patient records, and Z-CERT has advised all connected healthcare institutions to disconnect VPN links to the vendor.</description><pubDate>Wed, 08 Apr 2026 00:00:00 GMT</pubDate><category>ransomware</category><category>chipsoft</category><category>healthcare</category><category>patient-data</category><category>netherlands</category><category>third-party-risk</category><category>z-cert</category><category>ehr</category></item><item><title>Dell iDRAC Service Module CVE-2026-23856 Allows Local Privilege Escalation on PowerEdge Servers</title><link>https://cipherwatch.io/articles/2026-04-03-dell-idrac-cve-2026-23856-privilege-escalation/</link><guid isPermaLink="true">https://cipherwatch.io/articles/2026-04-03-dell-idrac-cve-2026-23856-privilege-escalation/</guid><description>Dell has patched CVE-2026-23856, a privilege escalation vulnerability in the iDRAC Service Module (iSM) shipped with PowerEdge servers. A local attacker with standard user privileges can exploit improper access controls in the iSM — which runs with elevated system privileges to communicate with the hardware management interface — to elevate to SYSTEM or root. Updated iSM packages are available for both Windows and Linux.</description><pubDate>Fri, 03 Apr 2026 00:00:00 GMT</pubDate><category>dell</category><category>idrac</category><category>poweredge</category><category>cve-2026-23856</category><category>privilege-escalation</category><category>firmware</category><category>server-security</category></item><item><title>ShinyHunters Claims Infinite Campus Breach — 11 Million Student Records at Risk</title><link>https://cipherwatch.io/articles/2026-03-25-infinite-campus-shinyhunters-k12-breach/</link><guid isPermaLink="true">https://cipherwatch.io/articles/2026-03-25-infinite-campus-shinyhunters-k12-breach/</guid><description>Infinite Campus, the K-12 student information system used by over 3,200 school districts across 46 US states, has warned customers of a security incident after ShinyHunters claimed to have stolen data via a Salesforce ticketing system compromise on 18 March. The company confirmed the attack lasted 38 minutes and primarily exposed school staff contact details, asserting no student database access occurred — but the threat actor&apos;s extortion deadline has passed without resolution.</description><pubDate>Wed, 25 Mar 2026 00:00:00 GMT</pubDate><category>data-breach</category><category>shinyhunters</category><category>education</category><category>salesforce</category><category>k12</category><category>student-data</category><category>extortion</category><category>social-engineering</category></item></channel></rss>