Supply Chain
Data Extortion
OAuth Abuse
Icarus: The Extortion Group Behind the Klue–Salesforce Supply Chain Breach
A new extortion group called Icarus breached Klue's SaaS platform and harvested OAuth tokens to extract Salesforce CRM data from Huntress, Recorded Future, LastPass, BeyondTrust, and 15+ other organisations.
Credential Stuffing
Data Breach
Active Campaign
FortiBleed — The 73,000+ Fortinet Firewall Credential Dump
A Russian-speaking threat group has compromised administrator credentials on over 73,000 internet-facing Fortinet FortiGate firewalls across 194 countries — using previously leaked passwords, no new vulnerability required.
Zero-Day Exploit
Data Breach
Extortion
ShinyHunters — Enterprise Resource Planning Under Attack
ShinyHunters is actively exploiting a zero-day in Oracle PeopleSoft servers worldwide. An emergency patch has been issued for CVE-2026-35273. If your organisation uses PeopleSoft PeopleTools 8.61 or 8.62, act immediately.
AI
Vulnerability Management
Threat Intelligence
AI — Rewriting the Rules of Vulnerability Management
AI has compressed the average time-to-exploit from 700 days to 44. Published CVEs hit 48,244 in 2025. Prompt injection rose 540%. Here's what the AI-driven shift in vulnerability management means for your organisation.
Hacktivism
Data Leak
Government
South Africa Actively Targeted by Nullsec Nigeria
Nigerian hacktivist group Nullsec Nigeria claimed to compromise SARS, SITA, and ProWellness as part of OpSouthAfrica. BreachWatcher analysed the leaked data — here's what it means for you.