ASOS breached and more - October 11, 2026

Featured

ASOS has confirmed they were victim of a data breach

Hackers accessed some customer personal data and links the breach to a social engineering attack and credential theft

This Week’s Updates

Breaches

South Korea's Financial Services Commission confirms a data breach at Shinhan Bank that leaked data on roughly 25,000 customers amid a wave of bank breaches

Denmark's Central Population Register confirms a data breach exposing personal information of roughly 8.8 million registered individuals

Japanese publisher Nikkei discloses breaches of two employee email accounts that were used to send thousands of phishing emails

Japanese chipmaker Advantest confirms personal information was stolen in a ransomware attack earlier this year

Google confirms hackers hijacked domains in Ghana, Sierra Leone, and American Samoa's ccTLDs and obtained unauthorized HTTPS certificates after breaching third-party registry operators

ASOS confirms hackers accessed some customer personal data and links the breach to a social engineering attack and credential theft

Japanese cloud provider IDC Frontier confirms a ransomware attack disrupted its IDCF Cloud data center cluster, affecting 495 companies and government clients

Vulnerabilities

Citrix patches a NetScaler SAML zero-day, CVE-2026-88779, exploited in denial-of-service attacks

Dell patches a critical path traversal flaw, CVE-2026-86360, in its System Update tool that let attackers gain root privileges

Rejetto patches a critical weak signing key flaw, CVE-2026-61500, in HFS after hackers began scanning for vulnerable servers

Atlassian warns of a critical unauthenticated file-access flaw, CVE-2026-21589, affecting Jira, Confluence, and Bitbucket Data Center products

Ninja Forms and WPC Product Bundles WordPress plugins patch exploited cross-site scripting flaws used to install backdoors and rogue admin accounts

SonicWall releases hotfixes for a maximum-severity SSRF flaw in SMA1000 series gateway appliances

Hackers begin exploiting the critical Atlassian flaw, CVE-2026-21589, after a public proof-of-concept is released

Cisco patches five critical NX-OS vulnerabilities that could let attackers take over Nexus switches with root privileges

Citrix warns admins to immediately patch a new NetScaler RCE flaw, CVE-2026-107406, affecting SAML-configured appliances

Hackers exploit the maximum-severity SonicWall SMA1000 flaw, CVE-2026-102255, just three days after it was patched

Threat actors exploit unpatched AhsayCBS backup platform flaws, CVE-2026-105133 and CVE-2026-105134, to deploy webshells and cryptocurrency miners

Next
Next

Microsoft’s X account breached and more - October 4, 2026