DEV Community

Cover image for State of (in)security - Week 36, 2026
BeyondMachines for BeyondMachines

Posted on Originally published at beyondmachines.net

State of (in)security - Week 36, 2026

Summary

Week 36 of 2026 saw 15 advisories and 27 incidents, with breaches up sharply and known impacted individuals jumping from 22 million to roughly 210 million. The impact count is driven largely by the IDScan.net driver's license breach, alongside a 40-million-account leak at Tving. Ransomware and malware led the causes (6 incidents), followed by software vulnerability exploits (4), with healthcare and IT/software the hardest-hit sectors. Actively exploited flaws are in JFrog Artifactory, Ruby on Rails, Citrix NetScaler, MikroTik, Langflow, and a Chrome V8 zero-day.

Take Action:

Patch the things already under attack this week: Chrome and other Chromium browsers, Firefox/Thunderbird, Rails image handling, JFrog Artifactory, Switchvox, SonicWall SMA 1000, and NetScaler. For everything else, get admin and management interfaces off the public internet (Cisco, MikroTik, Aruba CX, Langflow, Switchvox).


Read the full article on BeyondMachines


This article was originally published on BeyondMachines

Top comments (0)