Cyberattack
Critical Infrastructure
South Africa
Cyberattack Allegedly Cripples South Africa's Largest Water Utility
Rand Water, the utility supplying bulk water to more than 11 million people across Gauteng, has allegedly been hit by a cyberattack that crippled its payments system and GIS infrastructure database. An official statement is pending.
Ransomware
Mass Exploitation
Data Extortion
Inside Cl0p's Latest Extortion Wave: The PTC Windchill Campaign
Cl0p is mass-exploiting CVE-2026-12569, a critical RCE flaw in PTC Windchill and FlexPLM. 44+ organisations are now named on its leak site with over 20TB of engineering and product data claimed stolen.
Supply Chain
Data Extortion
OAuth Abuse
Icarus: The Extortion Group Behind the Klue–Salesforce Supply Chain Breach
A new extortion group called Icarus breached Klue's SaaS platform and harvested OAuth tokens to extract Salesforce CRM data from Huntress, Recorded Future, LastPass, BeyondTrust, and 15+ other organisations.
Credential Stuffing
Data Breach
Active Campaign
FortiBleed — The 73,000+ Fortinet Firewall Credential Dump
A Russian-speaking threat group has compromised administrator credentials on over 73,000 internet-facing Fortinet FortiGate firewalls across 194 countries — using previously leaked passwords, no new vulnerability required.
Zero-Day Exploit
Data Breach
Extortion
ShinyHunters — Enterprise Resource Planning Under Attack
ShinyHunters is actively exploiting a zero-day in Oracle PeopleSoft servers worldwide. An emergency patch has been issued for CVE-2026-35273. If your organisation uses PeopleSoft PeopleTools 8.61 or 8.62, act immediately.
AI
Vulnerability Management
Threat Intelligence
AI — Rewriting the Rules of Vulnerability Management
AI has compressed the average time-to-exploit from 700 days to 44. Published CVEs hit 48,244 in 2025. Prompt injection rose 540%. Here's what the AI-driven shift in vulnerability management means for your organisation.
Hacktivism
Data Leak
Government
South Africa Actively Targeted by Nullsec Nigeria
Nigerian hacktivist group Nullsec Nigeria claimed to compromise SARS, SITA, and ProWellness as part of OpSouthAfrica. BreachWatcher analysed the leaked data — here's what it means for you.