IDScan breached and more - Sept 13, 2026
Featured
This Week’s Updates
Breaches
Trezor confirms a breach at shipping partner ShipMonk now affects 81,000 customers total
AdaptHealth confirms a ShinyHunters cyberattack exposed data on 4.1 million people
Surfshark discloses hackers breached an internal test server left exposed by a misconfiguration
Trezor says a Brevo email provider breach fueled phishing attacks on 347,000 users, affecting 2,500
Florida confirms its DAVID driver database was breached using a stolen police employee's credentials
Vulnerabilities
N-able releases an emergency hotfix for a maximum-severity N-central RCE flaw amid ongoing attacks
MikroTik patches two chained RouterOS flaws being exploited to hijack routers with exposed SSH
SAP patches a maximum-severity SAP Kernel flaw among 20 vulnerabilities fixed this month
Google patches its seventh actively exploited Chrome zero-day of the year
Over 36,000 Plex servers remain unpatched against previously disclosed vulnerabilities
Skullcandy patches a Bluetooth flaw in Dime 3 earbuds that let attackers hijack audio and mic access
Cisco confirms CVE-2026-20079, a maximum-severity Secure FMC flaw, is being actively exploited
CISA confirms ransomware gangs are now exploiting a patched critical WatchGuard Firebox flaw
Cisco Talos ties two patched Secure FMC flaws to ransomware and state-sponsored exploitation
GitLab urges immediate patching of a maximum-severity path traversal flaw, CVE-2026-85706
Attackers chain critical JFrog Artifactory flaws to deploy a Rust backdoor
