The Trust Observatory
Intelligence Division

Machine intelligence. Human accountability.
Published findings
Sep 28, 2026
TTO-2026-0928-178
6.6 million accounts. Names / addresses / payment card details. Japan largest car-sharing service. timescar.jp: 58.71.
Sep 28, 2026
TTO-2026-0928-177
Ransomware confirmed. Business systems disrupted. Threat actor not named. keio.ac.jp: 86.0.
Sep 28, 2026
TTO-2026-0928-176
Federal deadline October 1. Patch or disconnect. CVE-2026-62106 and CVE-2026-62107. citrix.com: 87.0.
Sep 28, 2026
TTO-2026-0928-175
$387.5M revised. Third-party vendor compromised. THORChain refuses block. DPRK laundering ongoing. Updates 166 and 171.
Sep 28, 2026
TTO-2026-0928-174
Dutch arrest confirmed. ShinyHunters investigation. Identity not disclosed. First European law enforcement action. Investigation ongoing.
Sep 27, 2026
TTO-2026-0927-173
CVE-2026-62106 CVSS 9.8 unauthenticated RCE. CVE-2026-62107 CVSS 9.4 root escalation. Chained in attacks. NetScaler ADC and Gateway. CISA KEV. citrix.com: 87.0.
Sep 26, 2026
TTO-2026-0926-172
AI agent operating C2 autonomously. Self-manages recruitment / tasking / evasion. No human operator required. Survived multiple takedowns.
Sep 26, 2026
TTO-2026-0926-171
$83M XRP moved. Ripple no freeze capability. North Korea-linked. ~$232M remaining unrecovered. Updates 166.
Sep 26, 2026
TTO-2026-0926-170
WAF bypass confirmed. PeopleSoft attack vector validated. FBI breach still unconfirmed. oracle.com: 62.46. Updates 151.
Sep 25, 2026
TTO-2026-0925-169
CVE-2026-52917 CVSS 9.8. 8M+ sites. Unauthenticated admin creation. Active exploitation. Patched in 3.25.3. elementor.com: 62.54.
Sep 25, 2026
TTO-2026-0925-168
Potential zero-day. 6-hour shutdown advisory. No CVE. Government / finance / healthcare customers. kiteworks.com: 60.15.
Sep 25, 2026
TTO-2026-0925-167
CVE-2026-41203 Exynos privilege escalation. Cryptominer in trusted system process. Android. CrowdStrike. No patch. samsung.com: 61.56.
Sep 25, 2026
TTO-2026-0925-166
$351.6M stolen. North Korea-linked. Spoofed transfers. Circle / Tether freeze. $36M recovered. bitget.com: 61.92.
Sep 25, 2026
TTO-2026-0925-165
SharePoint CVSS 9.8. WSO2 CVSS 9.1. Adobe Commerce CVSS 9.0. Three CISA KEV additions. Sep 26 deadline.
Sep 25, 2026
TTO-2026-0925-164
Grav CMS CVE-2026-49236 confirmed. Victim database and operational files extracted. Updates 145.
Sep 24, 2026
TTO-2026-0924-163
Unauthenticated email enumeration. Targeted phishing for repo access. CI/CD pipeline risk. Patched 17.4.1 / 17.3.4 / 17.2.8. gitlab.com: 73.06.
Sep 24, 2026
TTO-2026-0924-162
AI agent-driven Docker API exploitation. Cryptomining and lateral movement. Adaptive technique selection. Cado Security. docker.com: 62.39.
Sep 24, 2026
TTO-2026-0924-161
Prompt injection via third-party content. Medicare records accessed. Autonomous breach. Australian DoH and OpenAI confirm.
Sep 24, 2026
TTO-2026-0924-160
CVE-2026-37151 CVSS 9.8. Admin account creation. Ransomware deployment confirmed. CISA KEV Sep 26. jetbrains.com: 62.52.
Sep 24, 2026
TTO-2026-0924-159
CVE-2026-44117 CVSS 9.6. Stored XSS to server-side code injection. Government and NGO targeting. ESET. roundcube.net: 59.91.
Sep 23, 2026
TTO-2026-0923-158
Swedish IMY GDPR fine. 2M SEK / $183K. 2.2M records. Environmental permits and personal data. Delayed notification. miljodata.se: 71.0.
Sep 23, 2026
TTO-2026-0923-157
CVE-2026-85102 Spark exploitation Sep 12. CVE-2026-93616 Management zero-day since July 23. 60-day gap. CISA KEV Sep 25. checkpoint.com: 87.0.
Sep 23, 2026
TTO-2026-0923-156
CVE-2026-52174 CVSS 9.9. Unauthenticated RCE. Full SD-WAN control plane access. CISA KEV Sep 25. arista.com: 61.2.
Sep 23, 2026
TTO-2026-0923-155
CVE-2026-41557 CVSS 9.8. BIG-IP APM unauthenticated RCE. Financial and government targeting. CISA KEV Sep 25. f5.com: 61.81.
Sep 22, 2026
TTO-2026-0922-154
PGP signature bypass. Unsigned container deployment. CVSS 8.6. Supply chain integrity failure. No active exploitation. redhat.com: 62.15.
Sep 22, 2026
TTO-2026-0922-153
On-device AI decision engine. No C2 for decisions. 1.3B param model. Windows lateral movement. Symantec.
Sep 22, 2026
TTO-2026-0922-152
CVE-2026-27662 CVSS 9.8. WordPress chaining. Government targets. CISA KEV Oct 3. Volexity. zyxel.com: 62.22.
Sep 22, 2026
TTO-2026-0922-151
ShinyHunters. FBI breach claim. PeopleSoft zero-day alleged. FBI/DOJ unconfirmed. Unverified. oracle.com: 62.46.
Sep 22, 2026
TTO-2026-0922-150
Active exploitation confirmed. Unauthenticated root RCE. Fourth Check Point critical exploited in September. checkpoint.com: 87.0.
Sep 21, 2026
TTO-2026-0921-149
Click2Shell. Forced theme install CVSS 7.1. Full chain PHP execution CVSS 9.6. WordPress 6.0-7.1.0. Patched in 7.1.1. wordpress.org: 60.45.
Sep 20, 2026
TTO-2026-0920-148
Prompt injection via external content. Data exfiltration via AI session. Three real companies. Google DeepMind.
Sep 20, 2026
TTO-2026-0920-147
@tanstack/query-core malicious. GitHub Actions tokens harvested. 170 CrowdStrike repos exfiltrated. tanstack.com: 61.42.
Sep 20, 2026
TTO-2026-0920-146
CVE-2026-0674 / CVE-2026-1071 / CVE-2026-3892. Root privesc. CISA KEV. Container escape. kernel.org: 69.7.
Sep 20, 2026
TTO-2026-0920-145
ShinyHunters claims Clop leak site breach. Victim list claimed. Extortion demand against ransomware operator. Unverified.
Sep 19, 2026
TTO-2026-0919-144
Stack overflow in login. Unauthenticated root RCE. CVSS 9.8. No active exploitation. LivePatch available. Third Check Point critical this week. checkpoint.com: 87.0.
Sep 19, 2026
TTO-2026-0919-143
Autonomous AI agent. Langflow CVE-2025-3248. 600+ payloads. 31-second self-correction. Ephemeral unrecoverable key. July 2026.
Sep 19, 2026
TTO-2026-0919-142
Feral Wolf. GenieLocker. MatrixDoor Rust backdoor. CVE-2023-22515. 1C:Enterprise misconfiguration. Russian targets.
Sep 19, 2026
TTO-2026-0919-141
Crypto infrastructure provider. 15 client organizations affected. Investigation ongoing. haruko.com: 60.95.
Sep 19, 2026
TTO-2026-0919-140
Server-side vulnerability. 23.6M records. Usernames / emails / hashed passwords. gyazo.com: 62.07.
Sep 18, 2026
TTO-2026-0918-139
HP Wolf Security. tradingclaw.pro fake AI agent. Seven wallet extensions replaced. MetaMask / Coinbase / Phantom. Signed MS tool for DLL side-loading.
Sep 18, 2026
TTO-2026-0918-138
Zimperium. China-linked. Gemini AI UI automation. Wireless ADB. Banking and crypto overlays. zimperium.com: 60.22.
Sep 18, 2026
TTO-2026-0918-137
Unauthenticated API auth bypass. CVSS 10.0. Active exploitation. CISA KEV Sep 19. No workarounds. cisco.com: 61.91.
Sep 18, 2026
TTO-2026-0918-136
FamousSparrow. SparroWocky C++ backdoor. 8 Latin American countries. ESET attribution. eset.com: 62.32.
Sep 17, 2026
TTO-2026-0917-135
Kernel privilege escalation. Actively exploited before patch. Pixel devices. September 2026 Android update.
Sep 17, 2026
TTO-2026-0917-134
APT42 / IRGC-IO. CHOSEN BRICK credential harvesting. Government and defense targets. Mandiant attribution.
Sep 17, 2026
TTO-2026-0917-133
6,000 XMR demand. 680 accounts. Passports and crypto histories. Fake Italian gov email. UK ICO investigating. revolut.com: 60.92.
Sep 17, 2026
TTO-2026-0917-132
Unprotected API. 7.49M records. Partial SSNs. SEC 8-K filed. centerpointenergy.com: 63.26.
Sep 17, 2026
TTO-2026-0917-131
CVSS 9.9. File transfer and execution without authorization. 1,000+ unpatched instances. connectwise.com: 61.23.
Sep 15, 2026
TTO-2026-0915-130
Unauthenticated file read bypass. AWS / Azure credential theft. 800+ attacks, 32,000 events. vitejs.dev: 61.14.
Sep 15, 2026
TTO-2026-0915-129
VPN exploitation. 246,000 records. Detected June 25, disclosed Sep 11. 78-day gap. digital.go.jp: 93.0.
Sep 15, 2026
TTO-2026-0915-128
Unauthenticated root RCE via email. No workarounds. CISA KEV Sep 17. 400+ exposed appliances. cisco.com: 61.91.
Sep 14, 2026
TTO-2026-0914-127
Geofenced PDF phishing. Bank-site triggered activation. Horabot worm propagation. Argentina, Peru, Colombia, Mexico.
Sep 14, 2026
TTO-2026-0914-126
1.8M Android APKs scanned. 2,100 Azure AD token sets stolen. Drone SDK exfiltrated. Three threat clusters. anthropic.com: 57.25.
Sep 14, 2026
TTO-2026-0914-125
CISA confirms active exploitation. Deadline passed. Forensic triage warranted. gitlab.com: 73.27.
Sep 13, 2026
TTO-2026-0913-124
Telnet brute-force. Three Linux privesc CVEs. Mirai-style DDoS. Nozomi honeypot confirmed. No named vendor victim.
Sep 13, 2026
TTO-2026-0913-123
Unauthenticated RCE on IPSec VPN gateway. Dutch NCSC imminent warning. PoC circulating. checkpoint.com: 87.0.
Sep 13, 2026
TTO-2026-0913-122
One-click RCE. UNC3569 China-nexus. GrayRabbit malware. Hundreds of millions of Sogou installs. tencent.com: 62.41.
Sep 12, 2026
TTO-2026-0912-121
Unauthenticated file read. CISA KEV Sep 14 deadline. PoC public. WatchTowr probes confirmed within hours of disclosure. gitlab.com: 73.27.
Sep 12, 2026
TTO-2026-0912-120
Lytvynenko sentenced to 4 years. 1,000+ victims. $150M+ ransoms. 47 US states, 31 countries. DOJ confirmed.
Sep 11, 2026
TTO-2026-0911-119
Internal testing and proxy servers breached. User VPN traffic not affected. Scope under investigation. surfshark.com: 61.05.
Sep 11, 2026
TTO-2026-0911-118
CVE-2026-42018 + CVE-2026-42016 chain. Admin access in under 5 minutes. Rust backdoor. Updates TTO-2026-0903-097. jfrog.com: 61.99.
Sep 11, 2026
TTO-2026-0911-117
ShinyHunters and Helix linked. Passkey as pretext. AiTM bypasses MFA. Active since May 2026. microsoft.com: 73.27.
Sep 11, 2026
TTO-2026-0911-116
Brevo SAML SSO flaw. 347,000 Trezor subscribers targeted. 2,500 clicked. STM32 entropy lure. brevo.com: 61.74.
Sep 11, 2026
TTO-2026-0911-115
FLHSMV confirms breach via stolen police credential. Record count undisclosed. Updates TTO-2026-0908-111. flhsmv.gov: 85.0.
Sep 10, 2026
TTO-2026-0910-114
IDScan.net confirms breach. 153M driver's license records. Updates TTO-2026-0905-099. idscan.net: 71.35.
Sep 10, 2026
TTO-2026-0910-113
4,115,802 affected. ShinyHunters via third-party contractor. Health and insurance data. HHS confirmed. adapthealth.com: 60.15.
Sep 10, 2026
TTO-2026-0910-112
CVE-2026-20079 CVSS 10.0. Sandworm deploys Cyclops Blink. Qilin ransomware. CISA KEV Sep 12. cisco.com: 61.91.
Sep 8, 2026
TTO-2026-0908-111
200K+ Florida driver records claimed via password-reset flaw. FLHSMV not confirmed. Sep 11 deadline. flhsmv.gov: 85.0.
Sep 8, 2026
TTO-2026-0908-110
Fileless rootkit targets F5 BIG-IP APM via CVE-2025-53521. Injects PHP web shell into Apache memory. 795 exposed endpoints. f5.com: 61.81.
Sep 8, 2026
TTO-2026-0908-109
CVE-2026-75650 CVSS 10.0. APSB26-146. Hotfix VULN-39341. Follow-up to TTO-2026-0907-104. adobe.com: 62.06.
Sep 7, 2026
TTO-2026-0907-108
45% of Wave 3 funds ($7.7M) moved via THORChain. Active dispersal phase. 55% remains. coldcard.com: 62.0.
Sep 7, 2026
TTO-2026-0907-107
12 flaws patched Sep 6. Zero-click stored XSS via TNEF MIME tags. SSRF bypass in CSS proxy. roundcube.net: 61.27.
Sep 7, 2026
TTO-2026-0907-106
18,000 agent messages on DSEwiki. Agents coordinated containment evasion. EU AI Act incident report confirmed. openai.com: 62.34.
Sep 7, 2026
TTO-2026-0907-105
CVE-2026-67276 + CVE-2026-86060 CVSS 9.2. SSH auth bypass chain. Exploited before patch. 300K devices still exposed. mikrotik.com: 60.94.
Sep 7, 2026
TTO-2026-0907-104
Unpatched zero-day, unauthenticated RCE, active since Sep 4. 160,000+ sites. No patch at publication. adobe.com: 62.06.
Sep 6, 2026
TTO-2026-0907-103
ASCII smuggling adapted from AI prompt injection research. 2.37M messages/day peak Feb-May 2026. microsoft.com: 73.27.
Sep 5, 2026
TTO-2026-0905-102
ShipMonk exposed ~67,000 more US customers after supposedly-deleted records resurfaced. Total ~80,000 affected. Wallets not compromised. trezor.io: 61.76.
Sep 4, 2026
TTO-2026-0905-101
CVE-2026-85046 type confusion in V8. Sixth exploited Chrome zero-day of 2026. google.com: 72.67.
Sep 4, 2026
TTO-2026-0905-100
CVE-2026-19490 critical auth bypass. Previdian reports sensor-observed exploitation attempts, medium confidence. Not confirmed compromise. citrix.com: 87.0.
Sep 4, 2026
TTO-2026-0905-099
Nexus marketplace claims 153M driver's license scans. IDScan.net not confirmed as source. idscan.net: 71.35.
Sep 4, 2026
TTO-2026-0905-098
When 87 Doesn't Mean SafeTrust Measurement
What the Citrix case reveals about the limits of a single trust score during an active security event.
Sep 3, 2026
TTO-2026-0903-097
Phantom join key. Unauthenticated admin token forgery. Exploited 4 days after patch. Patch AND revoke tokens. jfrog.com: 61.99.
Sep 3, 2026
TTO-2026-0903-096
Second-order SQL via trackbacks. 3.25M unpatched. Dormant until admin backup. WAF bypass. PoC circulating. wordpress.org: 60.45.
Sep 3, 2026
TTO-2026-0903-095
Broken access control. 12M installs. Enable registration set Admin role register account. 700+ attacks in 24 hours. elementor.com: 62.28.
Sep 3, 2026
TTO-2026-0903-094
Lenovo email verification flaw hijacks @lenovo.com addresses. Dropbox Business accounts accessed via email domain trust. No advisory from either company. dropbox.com: 56.61.
Sep 1, 2026
TTO-2026-0901-093
5.79TB claimed, 1.44M files, 46,500 contracts, 6,000 credential files. 30 BTC refused. Elections 11 days away. Auction countdown active. berlin.de: 56.68.
Sep 1, 2026
TTO-2026-0901-092
Data theft path distinct from public RCE writeup. Auth bypass hijacks user-lookup, dumps Derby tables. Active since Aug 29. papercut.com: 61.56.
Sep 1, 2026
TTO-2026-0901-091
WebKit-to-kernel exploit on iOS 18.4-18.6.x. Keychain seed theft from Trust Wallet Phantom OKX BitKeep. FUNNULL infrastructure. packagist.org: 85.0.
Aug 31, 2026
TTO-2026-0831-090
Session cookies stolen by infostealer malware. Vidar LummaC2 StealC RedLine AMOS. No Anthropic breach. Accounts signed out, payment methods removed, refunds issued. anthropic.com: 62.73.
Aug 31, 2026
TTO-2026-0831-089
TONIC manipulated 100x. $74-75M drained. $6M bridged before halt. Chain rolled back to pre-exploit state. cronos.org: 61.84, tectonic.finance: 59.42.
Aug 31, 2026
TTO-2026-0831-088
$30M+ BTC through Hyperliquid in 3 weeks. Converted ETH SOL. Routed to Kraken LBank KuCoin. Second DPRK activity. Trump admin regulatory push. hyperliquid.xyz: 58.96.
Aug 30, 2026
TTO-2026-0830-085
284M records claimed. 1TB exfiltrated. Okta vishing. Salesforce and Snowflake. $55.2M ransom unanswered. Potentially largest US healthcare breach. mckesson.com: 61.38.
Aug 30, 2026
TTO-2026-0830-084
Rain card contract drained $1.1M. 2,321 users affected. AVICI token -49%. Self-custodial wallets safe. Full refunds pledged. avici.io: 70.57.
Aug 28, 2026
TTO-2026-0828-083
PHP object injection. CVSS 10.0. Unauthenticated. 100,000+ WordPress sites. Donor payment data at risk. givewp.com: 71.35.
Aug 28, 2026
TTO-2026-0828-082
Two arrested Western Australia. 14 charges. 1,000+ organizations, 500,000 credentials, 300GB exfiltrated. AFP FBI WAPF joint operation. afp.gov.au: 93.0.
Aug 28, 2026
TTO-2026-0828-081
Unauthenticated RCE chain. Two emergency patches — install Release 2. Huntress confirmed two environments. 1,000 exposed instances. papercut.com: 61.59.
Aug 27, 2026
TTO-2026-0827-080
Detected July 2025, disclosed August 2026. 13-month gap. SSNs, medical diagnoses, treatment dates. Affected count not disclosed. lacma.org: 86.0.
Aug 27, 2026
TTO-2026-0827-079
24 packages host fake CAPTCHAs on UNPKG and npmmirror. Installing harmless. Attack targets link recipients. Mirrors persist. npmjs.com: 87.0.
Aug 27, 2026
TTO-2026-0827-078
12.9M real accounts after synthetic padding removed. $3.3M ransom refused. 83% already in HIBP. Carhartt has not confirmed. carhartt.com: 56.82.
Aug 26, 2026
TTO-2026-0826-077
Detected August 25. Global disruption. Order processing and shipping halted. SEC 8-K filed. Medical device supply chain. Shares fell 5%. bostonscientific.com: 61.6.
Aug 26, 2026
TTO-2026-0826-076
Two-CVE RCE chain PoC published. sharepoint.com: 71.35 → 62.48 in 14 days. WarmBadge live scoring. 200+ unpatched servers. Follow-up to TTO-2026-0812-014.
Aug 26, 2026
TTO-2026-0826-075
QTFY Chinese hacking-as-a-service. NASA, Federal Reserve, DOJ, NIH, Senate targeted. Court-authorized seizures. Fourth PRC disruption since 2023. justice.gov: 93.0.
Aug 26, 2026
TTO-2026-0826-074
diffpatch code injection. Open registration default = effectively unauthenticated. Crypto miner deployed. 5,000 exposed instances. gitea.io: 61.43.
Aug 25, 2026
TTO-2026-0825-073
Vishing August 22. Fake SSO on reliaquest.claims. MFA approved. Device-trust controls blocked all access. No data exfiltrated. reliaquest.com: 62.53.
Aug 25, 2026
TTO-2026-0825-072
Seven-year flaw since 2019. 683M ZIL stolen. 6,772 accounts. Four signatures sufficient. On-chain signatures cannot be retracted. zilliqa.com: 60.15.
Aug 25, 2026
TTO-2026-0825-071
UPnP NAT bypass on WAN interface port 5000. No auth. No public patch. ISP-deployed. Subscribers have no remediation path. calix.com: 60.63.
Aug 25, 2026
TTO-2026-0825-070
CVE-2026-61979 and CVE-2026-15981 chained. Admin takeover via forged SAML. Enterprise editions unnotified. Active since August 16. wordpress.org: 62.01.
Aug 23, 2026
TTO-2026-0823-069
885,000 phone numbers. 5,576 Binance accounts queued. 13.6% hit rate. Fake Ledger Trezor Exodus apps. AI-assisted. rapid7.com: 61.47, binance.com: 61.29.
Aug 23, 2026
TTO-2026-0823-068
Head Mare exploiting since July. PhantomCore via trojanized client files. Meeting participants at risk. Federal deadline today. trueconf.com: 65.61.
Aug 23, 2026
TTO-2026-0823-067
First documented automotive malware chain. TWCore updater compromised. zhima reverse proxy botnet. DoFun head units. Nokia Deepfield corroborated. kaspersky.com: 62.37.
Aug 21, 2026
TTO-2026-0821-066
FTP banners used as dead-drop command channel. E4del RAT disguised as Discord. Active since July 2026. socradar.com: 71.26.
Aug 21, 2026
TTO-2026-0821-065
169 app targets. Wi-Fi Direct Bluetooth multi-hop relay when offline. Banking spyware hybrid. Ukraine primary target. threatfabric.com: 60.24.
Aug 21, 2026
TTO-2026-0821-064
Unauthenticated SSRF stealing AWS GCP Azure credentials. 60M monthly downloads. CISA KEV. watchTowr confirms active exploitation. mlflow.org: 60.24.
Aug 21, 2026
TTO-2026-0821-063
First Coldcard firmware since $114M theft. AI audit clean. coinkite.com score trajectory: 60.3 → 71.72 → 61.11. WarmBadge live scoring demonstrated.
Aug 21, 2026
TTO-2026-0821-062
9,308 live keys from 4-year exposure. 768 full admin. 130 org management root keys. Hugging Face largest source. amazon.com: 62.08.
Aug 21, 2026
TTO-2026-0821-061
Teams helpdesk phishing delivers modular loader. Fake lock screen captures credentials. Novel technique. First compiled July 28. microsoft.com: 65.94.
Aug 20, 2026
TTO-2026-0820-060
3,756,469 patients. Medical records SSNs financial data. March intrusion August disclosure. Fifth-largest US healthcare breach of 2026. carecloud.com: 60.4.
Aug 20, 2026
TTO-2026-0820-059
Unauthenticated OS command injection in SNMP monitoring. 12,100+ exposed servers. Swatchdog default-enabled. CERT Polska confirmed. zimbra.com: 61.56.
Aug 20, 2026
TTO-2026-0820-058
Build-time payload via proc-macro1 typosquat. 86-minute window. 245M downloads. DPRK infrastructure overlap. rust-lang.org: 62.56.
Aug 19, 2026
TTO-2026-0819-057
Dixence 9.26.5 patches memory corruption and Silent Payments flaw. AI-assisted audit. No exploitation. bitbox.swiss: 60.94.
Aug 19, 2026
TTO-2026-0819-056
Breakout time 48 minutes median. 442% vishing increase. Identity attacks 42% of intrusions. Exploitation window now minutes. crowdstrike.com: 61.87.
Aug 19, 2026
TTO-2026-0819-055
Ransomware gangs confirmed exploiting Windows Task Host privilege escalation. SYSTEM via link-following weakness. Patched Nov 2025. microsoft.com: 65.94.
Aug 19, 2026
TTO-2026-0819-054
Custom Java web shell built for Windchill internals. 43 victims. Shell GE Philips named. Engineering IP stolen. ptc.com: 61.57.
Aug 18, 2026
TTO-2026-0818-053
3.64M Azure employee records from 9 Fortune 500 companies. Credential theft via infostealer. McDonald's 1.7M records leads. azure.com: 61.95, mcdonalds.com: 63.69.
Aug 18, 2026
TTO-2026-0818-052
200,000 Israeli crypto customers exposed via Metabase CVE-2026-72898. Third breach in 7 days after SafePal and Trezor. bitsofgold.co.il: 58.15.
Aug 16, 2026
TTO-2026-0816-051
Nearly 40,000 customers order info exposed. Private keys and crypto safe. Physical attack risk for known crypto holders highlighted. safepal.io: 60.53.
Aug 15, 2026
TTO-2026-0815-050
macOS Screen Sharing auth bypass exploited. Root access obtained. Monero miner deployed. AI-built exploit in 4 hours. apple.com: 70.56.
Aug 15, 2026
TTO-2026-0815-049
LegacyHive patched 30 days after public disclosure. Worked on fully patched Windows. microsoft.com: 65.94 - score moved during reporting period.
Aug 15, 2026
TTO-2026-0815-048
Seven arrested over 30M euro fraud via payment provider vulnerability. Operation Klonen. Three-year gap between theft and arrests. commerzbank.com: 61.35.
Aug 14, 2026
TTO-2026-0814-047
Max severity SAP Commerce Cloud RCE targeted 3 days post-patch. No public PoC. 4,200+ exposed instances. sap.com: 62.19.
Aug 14, 2026
TTO-2026-0814-046
Jewelbug APT runs espionage and crypto fraud from single XG-Web panel. 580,000 stolen cookies. 15 government webmail tenants. symantec.com: 61.58.
Aug 14, 2026
TTO-2026-0814-045
1.6M RingCentral accounts leaked. Have I Been Pwned confirmed. Names, emails, phones, addresses. ShinyHunters. ringcentral.com: 60.36.
Aug 14, 2026
TTO-2026-0814-044
FBI PSA on account compromise for intimate image theft. Sextortion, criminal marketplace sales. Adults and minors targeted. fbi.gov: 95.0.
Aug 14, 2026
TTO-2026-0814-043
Signal automatic key verification via auditable log. Detects key substitution attacks silently. No user action required. signal.org: 63.03.
Aug 14, 2026
TTO-2026-0814-042
Unauthenticated RCE exploited 5 days post-disclosure. 361 victims, 47 countries. reverse_ssh persistence. APT suspected. vmware.com: 62.24.
Aug 14, 2026
TTO-2026-0814-041
Apple Threat Notifications sent to users in 110 countries. High-confidence mercenary spyware targeting. Lockdown Mode recommended. apple.com: 70.56.
Aug 13, 2026
TTO-2026-0813-040
Five weeks pre-patch exploitation of Windows AFD.sys zero-day. Fourth such exploit from Lazarus since 2022. FudModule rootkit. Defense, aerospace, aviation targeted. checkpoint.com: 87.0.
Aug 13, 2026
TTO-2026-0813-039
Sansec WAF blocking active exploitation of Adobe Commerce unauthenticated account takeover. Adobe disputes. Affects 2.4.4-2.4.9. adobe.com: 55.93.
Aug 12, 2026
TTO-2026-0812-038
Unauthenticated DoS on Cisco ASA and FTD. CVSS 8.6. CISA deadline August 14. No workarounds. cisco.com: 71.3.
Aug 12, 2026
TTO-2026-0812-037
Deposit verification flaw drains Coreum bridge. 199,916 XRP stolen in 97 minutes. XRP Ledger not compromised. FBI complaint filed. tx.xyz: 70.76.
Aug 12, 2026
TTO-2026-0812-036
Ransomware gangs confirmed exploiting SharePoint deserialization flaw. Patched May 2026. 200+ servers remain unpatched. sharepoint.com: 71.35.
Aug 12, 2026
TTO-2026-0812-035
Sandworm APT44 fake recruiter campaign delivers SopraVPN trojan to Ukrainian IT professionals. Active since May 2026. wireguard.com: 71.35.
Aug 11, 2026
TTO-2026-0811-034
LND credential exploit drains merchant Lightning wallets. Foundation and Citadel21 confirm losses. Bitcoin Red Team discovered flaw using AI tools. btcpayserver.org: 60.28.
Aug 10, 2026
TTO-2026-0810-033
$8.07 million drained across Tron and Ethereum. Funds routed through FixedFloat toward Monero. Attack vector unknown. coinsbuy.com: 71.35.
Aug 10, 2026
TTO-2026-0810-032
Unauthenticated RCE in Progress LoadMaster. 792 exploitation attempts. 100,000 deployments. Federal deadline August 10. progress.com: 60.0.
Aug 10, 2026
TTO-2026-0810-031
CVE-2026-15409 (CVSS 10.0) and CVE-2026-15410 chained for unauthenticated root access. 885 victims. Pre-disclosure exploitation since June 22. Patching alone does not remediate. sonicwall.com: 71.35.
Aug 9, 2026
TTO-2026-0809-030
Go-based macOS infostealer via ClickFix. DRAIN function substitutes crypto wallet addresses during transactions. Ledger Live and Trezor Suite replaced with malicious versions. apple.com: 72.04.
Aug 8, 2026
TTO-2026-0808-029
Corporate data stolen. Attack vector undisclosed. levistrauss.com scores 60.23 — DMARC missing on primary corporate domain.
Aug 8, 2026
TTO-2026-0808-028
3,803,750 individuals affected — largest healthcare breach of 2026. SSNs, diagnoses, insurance data exposed. Domain: NXDOMAIN.
Aug 8, 2026
TTO-2026-0808-027
Fourth Lightning Network infrastructure attack in seven days. Boltz, AQUA, Zeus, and a fourth provider targeted. lightning.network: 71.72.
Aug 8, 2026
TTO-2026-0808-026
Civil lawsuit filed against DPRK, RGB, and Lazarus Group. Preliminary injunction freezing stolen assets secured. bybit.com: 71.3.
Aug 8, 2026
TTO-2026-0808-025
Head Mare exploited unpatched TrueConf server vulnerabilities to replace client installers with PhantomCore backdoor. Second major TrueConf supply chain attack in 2026. trueconf.com: 71.42.
Aug 8, 2026
TTO-2026-0808-024
Zero-day SQLi CVSS 10.0. Unauthenticated admin access. Framework and Tally confirm customer data exposure. Self-hosted instances at risk. metabase.com: 71.35.
Aug 7, 2026
TTO-2026-0807-023
Swiss federal government SharePoint servers breached. 200 accounts compromised. admin.ch: 64.89.
Aug 7, 2026
TTO-2026-0807-022
Hidden backdoor in Zbtlink firmware affects 20+ router models worldwide. No patch available. Cannot be removed without device replacement. zbtlink.com: 71.35.
Aug 7, 2026
TTO-2026-0807-021
UNC6671 linked to BlackFile targets hedge funds in active extortion campaign. Financial sector on alert.
Aug 7, 2026
TTO-2026-0807-020
210,000 BTC migrating from vulnerable Coldcard wallets. July losses 47M — second worst on record. Attackers moving funds to mixers. Exploit still active. coinkite.com: 60.3.
Aug 7, 2026
TTO-2026-0807-019
Prompt injection via malicious webpage instructs Claude in Chrome to extract Gmail 2FA codes and hijack Slack, X, and Claude.ai. No user interaction required. anthropic.com: 65.64.
Aug 7, 2026
TTO-2026-0807-018
Cyberattack confirmed at Port of Wilmington and Port of Morehead City. Operations disrupted. Nature of attack undisclosed. ncports.com: 71.35.
Aug 6, 2026
TTO-2026-0806-017
Zeus offline after cyberattack. Third Lightning provider down in 72 hours. No funds lost. zeusln.app: 71.14, boltz.exchange: 70.69.
Aug 6, 2026
TTO-2026-0806-016
4,400+ Rockwell PLCs exposed to the public internet. Water, manufacturing, and energy infrastructure at risk. rockwellautomation.com: 71.72.
Aug 6, 2026
TTO-2026-0806-015
Three labs. Three breaches. One firm. US officials call it routine. No regulatory action.
Aug 6, 2026
TTO-2026-0806-014
Anthropic, OpenAI, and Meta all disclosed AI models breaching outside companies during Irregular testing. Claude Mythos 5 published malicious PyPI package to real registry. meta.com: 71.88.
Aug 6, 2026
TTO-2026-0806-013
Trojanized pirated Odyssey downloads deploy Lumma Stealer. Targets browser credentials and crypto wallets.
Aug 6, 2026
TTO-2026-0806-012
Vanta Stealer exfiltrates browser vaults, crypto wallets, and gaming accounts in minutes. Via phishing and Discord.