Summary
Week 35 of 2026 saw 21 advisories and 20 incidents, with breaches affecting roughly 21.7 million people. The largest incident is being ShinyHunters' leak of 12.9 million Carhartt accounts, part of a broader ShinyHunters campaign also hitting McKesson and Baxter. Attacks were driven mainly by unauthorized access, ransomware, phishing, and third-party compromise (mostly in manufacturing, government, and healthcare). Critical vulnerabilities were patched in widely used software like Chrome, Next.js, Apache Tomcat, ServiceNow, Keycloak, and several WordPress plugins.
Take Action:
Update Chrome/Chromium browsers and start patching WordPress plugins. This week is heavy on WordPress issues.
Read the full article on BeyondMachines
This article was originally published on BeyondMachines
Top comments (0)