DEV Community

Cover image for State of (in)security - Week 35, 2026
BeyondMachines for BeyondMachines

Posted on Originally published at beyondmachines.net

State of (in)security - Week 35, 2026

Summary

Week 35 of 2026 saw 21 advisories and 20 incidents, with breaches affecting roughly 21.7 million people. The largest incident is being ShinyHunters' leak of 12.9 million Carhartt accounts, part of a broader ShinyHunters campaign also hitting McKesson and Baxter. Attacks were driven mainly by unauthorized access, ransomware, phishing, and third-party compromise (mostly in manufacturing, government, and healthcare). Critical vulnerabilities were patched in widely used software like Chrome, Next.js, Apache Tomcat, ServiceNow, Keycloak, and several WordPress plugins.

Take Action:

Update Chrome/Chromium browsers and start patching WordPress plugins. This week is heavy on WordPress issues.


Read the full article on BeyondMachines


This article was originally published on BeyondMachines

Top comments (0)