ASOS breached and more - October 11, 2026 Weekly Roundup Oct 11 Written By RF Wave Featured ASOS has confirmed they were victim of a data breach Hackers accessed some customer personal data and links the breach to a social engineering attack and credential theft This Week’s Updates Breaches South Korea's Financial Services Commission confirms a data breach at Shinhan Bank that leaked data on roughly 25,000 customers amid a wave of bank breaches Denmark's Central Population Register confirms a data breach exposing personal information of roughly 8.8 million registered individuals Japanese publisher Nikkei discloses breaches of two employee email accounts that were used to send thousands of phishing emails Japanese chipmaker Advantest confirms personal information was stolen in a ransomware attack earlier this year Google confirms hackers hijacked domains in Ghana, Sierra Leone, and American Samoa's ccTLDs and obtained unauthorized HTTPS certificates after breaching third-party registry operators ASOS confirms hackers accessed some customer personal data and links the breach to a social engineering attack and credential theft Japanese cloud provider IDC Frontier confirms a ransomware attack disrupted its IDCF Cloud data center cluster, affecting 495 companies and government clients Vulnerabilities Citrix patches a NetScaler SAML zero-day, CVE-2026-88779, exploited in denial-of-service attacks Dell patches a critical path traversal flaw, CVE-2026-86360, in its System Update tool that let attackers gain root privileges Rejetto patches a critical weak signing key flaw, CVE-2026-61500, in HFS after hackers began scanning for vulnerable servers Atlassian warns of a critical unauthenticated file-access flaw, CVE-2026-21589, affecting Jira, Confluence, and Bitbucket Data Center products Ninja Forms and WPC Product Bundles WordPress plugins patch exploited cross-site scripting flaws used to install backdoors and rogue admin accounts SonicWall releases hotfixes for a maximum-severity SSRF flaw in SMA1000 series gateway appliances Hackers begin exploiting the critical Atlassian flaw, CVE-2026-21589, after a public proof-of-concept is released Cisco patches five critical NX-OS vulnerabilities that could let attackers take over Nexus switches with root privileges Citrix warns admins to immediately patch a new NetScaler RCE flaw, CVE-2026-107406, affecting SAML-configured appliances Hackers exploit the maximum-severity SonicWall SMA1000 flaw, CVE-2026-102255, just three days after it was patched Threat actors exploit unpatched AhsayCBS backup platform flaws, CVE-2026-105133 and CVE-2026-105134, to deploy webshells and cryptocurrency miners vulnerabilitydata breach RF Wave
ASOS breached and more - October 11, 2026 Weekly Roundup Oct 11 Written By RF Wave Featured ASOS has confirmed they were victim of a data breach Hackers accessed some customer personal data and links the breach to a social engineering attack and credential theft This Week’s Updates Breaches South Korea's Financial Services Commission confirms a data breach at Shinhan Bank that leaked data on roughly 25,000 customers amid a wave of bank breaches Denmark's Central Population Register confirms a data breach exposing personal information of roughly 8.8 million registered individuals Japanese publisher Nikkei discloses breaches of two employee email accounts that were used to send thousands of phishing emails Japanese chipmaker Advantest confirms personal information was stolen in a ransomware attack earlier this year Google confirms hackers hijacked domains in Ghana, Sierra Leone, and American Samoa's ccTLDs and obtained unauthorized HTTPS certificates after breaching third-party registry operators ASOS confirms hackers accessed some customer personal data and links the breach to a social engineering attack and credential theft Japanese cloud provider IDC Frontier confirms a ransomware attack disrupted its IDCF Cloud data center cluster, affecting 495 companies and government clients Vulnerabilities Citrix patches a NetScaler SAML zero-day, CVE-2026-88779, exploited in denial-of-service attacks Dell patches a critical path traversal flaw, CVE-2026-86360, in its System Update tool that let attackers gain root privileges Rejetto patches a critical weak signing key flaw, CVE-2026-61500, in HFS after hackers began scanning for vulnerable servers Atlassian warns of a critical unauthenticated file-access flaw, CVE-2026-21589, affecting Jira, Confluence, and Bitbucket Data Center products Ninja Forms and WPC Product Bundles WordPress plugins patch exploited cross-site scripting flaws used to install backdoors and rogue admin accounts SonicWall releases hotfixes for a maximum-severity SSRF flaw in SMA1000 series gateway appliances Hackers begin exploiting the critical Atlassian flaw, CVE-2026-21589, after a public proof-of-concept is released Cisco patches five critical NX-OS vulnerabilities that could let attackers take over Nexus switches with root privileges Citrix warns admins to immediately patch a new NetScaler RCE flaw, CVE-2026-107406, affecting SAML-configured appliances Hackers exploit the maximum-severity SonicWall SMA1000 flaw, CVE-2026-102255, just three days after it was patched Threat actors exploit unpatched AhsayCBS backup platform flaws, CVE-2026-105133 and CVE-2026-105134, to deploy webshells and cryptocurrency miners vulnerabilitydata breach RF Wave