Summary
Week 38 of 2026 saw 19 advisories and 28 incidents. Advisories are up, incidents slightly down from the prior week, and known impacted individuals jumped from 6 million to over 31 million, driven largely by the Gyazo/Helpfeel breach exposing 23.6 million user records. Malware/ransomware and software vulnerability exploits tied as the leading causes (7 each). Government, healthcare, and IT/software are the hardest-hit industries, alongside a heavy wave of actively exploited flaws in Cisco, Apple, Oracle, and WordPress plugin products.
Take Action:
If it's internet-facing, patch it today. Attackers are already exploiting this week's Cisco, Linux kernel, ScreenConnect and WordPress flaws, and several have no workaround. Everything else comes down to one habit: keep admin and management interfaces off the public internet, and rotate any secrets that sat on an exposed system.
Read the full article on BeyondMachines
This article was originally published on BeyondMachines
Top comments (0)