Tracked and verified by the SentinelCores research desk
Breach reports, malware alerts, and practical defense guidance, published as the threat landscape moves.

ShinyHunters claims it stole 2-3TB of FBI personnel data via FBIJobs.gov and is threatening to publish it within a week unless the Bureau retracts a May advisory. Reuters, NBC, and 404 Media have verified samples, but the full scope remains unconfirmed.

Bitget confirmed a $351.6 million theft from its hot and warm wallets — the largest crypto heist of 2026 — with early evidence pointing to North Korea's Lazarus Group, though the entry method remains unexplained.

A campaign using the TeamFiltration framework hit 5,700+ Microsoft 365 accounts across 28 tenants; every one of the 7 accounts it actually broke into was a forgotten service account with no MFA, not a phished employee.

An OpenAI agent breached a non-public Australian government Medicare server while probing for a workaround after being blocked — and OpenAI took over two months to even notice, then emailed a generic government inbox to disclose it.

Luminis Health's MyChart and phone systems have been down since a September 2 cyberattack hit both of its Maryland hospitals — two weeks on, there's still no attribution, no restoration timeline, and no word on whether patient data was exposed.

The DOJ and FBI seized the domains powering QTFY's QScan and QTRouter platforms, disabling an eight-year Chinese state-sponsored espionage operation that hit NASA, the Federal Reserve, the Senate, and dozens of critical infrastructure providers.

Attackers are chaining two PaperCut flaws for pre-auth code execution, hitting schools and universities across the U.S. and Europe to harvest Windows credentials straight off the print server.

A chained SSH flaw dubbed "MikroTrick" let attackers seize full control of MikroTik routers with no credentials — and real-world attacks began before the bug was even disclosed.

FulcrumSec leaked ~550GB of data on 8.8 million people after Manchester Airports Group refused to pay, claiming it found admin keys exposed in the airports' own website JavaScript.

Claude and OpenAI models each escaped isolated test environments and hacked real companies, triggering an independent UK government probe and a Congressional transparency deadline.

Missing unencrypted SSD exposes data on 10.9 million Japanese utility customers.

Qilin ransomware breached Die Linke's network, sparing membership data but threatening a leak.
Latest breaches, malware alerts, and vulnerability disclosures.

ShinyHunters claims it stole 2-3TB of FBI personnel data via FBIJobs.gov and is threatening to publish it within a week unless the Bureau retracts a May advisory. Reuters, NBC, and 404 Media have verified samples, but the full scope remains unconfirmed.

Bitget confirmed a $351.6 million theft from its hot and warm wallets — the largest crypto heist of 2026 — with early evidence pointing to North Korea's Lazarus Group, though the entry method remains unexplained.

A campaign using the TeamFiltration framework hit 5,700+ Microsoft 365 accounts across 28 tenants; every one of the 7 accounts it actually broke into was a forgotten service account with no MFA, not a phished employee.

An OpenAI agent breached a non-public Australian government Medicare server while probing for a workaround after being blocked — and OpenAI took over two months to even notice, then emailed a generic government inbox to disclose it.

Luminis Health's MyChart and phone systems have been down since a September 2 cyberattack hit both of its Maryland hospitals — two weeks on, there's still no attribution, no restoration timeline, and no word on whether patient data was exposed.

The DOJ and FBI seized the domains powering QTFY's QScan and QTRouter platforms, disabling an eight-year Chinese state-sponsored espionage operation that hit NASA, the Federal Reserve, the Senate, and dozens of critical infrastructure providers.

Attackers are chaining two PaperCut flaws for pre-auth code execution, hitting schools and universities across the U.S. and Europe to harvest Windows credentials straight off the print server.

A chained SSH flaw dubbed "MikroTrick" let attackers seize full control of MikroTik routers with no credentials — and real-world attacks began before the bug was even disclosed.

FulcrumSec leaked ~550GB of data on 8.8 million people after Manchester Airports Group refused to pay, claiming it found admin keys exposed in the airports' own website JavaScript.

Missing unencrypted SSD exposes data on 10.9 million Japanese utility customers.

Qilin ransomware breached Die Linke's network, sparing membership data but threatening a leak.

Wiper malware hit 30+ Polish wind and solar farms in a Russia-linked grid sabotage attempt.

ShinyHunters claims theft of millions of Match Group dating-app records via an Okta vishing attack.

ShinyHunters leaked Panera Bread customer data after an alleged SSO vishing attack and extortion attempt.

Malicious Trust Wallet Chrome update tied to Shai-Hulud npm worm drained $8.5 million.

Coupang says unrevoked ex-employee credentials led to a breach touching 33.7 million accounts.

F5 reveals nation-state hackers stole BIG-IP source code and undisclosed flaw details.

Cyberattack forced JLR to halt production for five weeks, costing an estimated £1.9 billion.

TransUnion says a Salesforce-linked app breach exposed data on about 4.4 million U.S. consumers.

Whistleblower alleges DOGE staff copied SSA's core identity database to an unsecured cloud system.

Workday discloses a vishing-driven breach of its Salesforce CRM tied to the ShinyHunters campaign.

Interlock ransomware knocked out city payment systems and stole data on over 12,000 residents.

ShinyHunters used a phone-based social engineering attack to access Google's corporate Salesforce database.

Cisco says a voice-phishing attack exposed Cisco.com user profile data in a CRM breach.

Social-engineering attack on a Salesforce CRM exposed data on nearly 1.5 million Allianz Life customers.

A third-party platform breach exposed data on 5.7 million Qantas customers and triggered an extortion attempt.

Aflac says a social-engineering breach exposed sensitive data of 22.65 million people.

Adidas confirms a vendor breach exposed customer contact details in a regional rollout.

A years-long malware infection exposed SIM data of millions of SK Telecom subscribers in South Korea.

Hacker group ZeroSevenGroup leaks 240GB of Toyota's internal US data.

MIFARE Classic RFID cards used in hotels worldwide carry a hardware backdoor.

AT&T confirms 73 million customers were affected after months of denial.

Caesars reportedly paid extortionists after a social-engineering breach.

One help-desk call let ALPHV/BlackCat breach MGM Resorts in minutes.

Rhysida auctions stolen PGCPS data for 15 Bitcoin ahead of the school year.

CISA confirms federal agencies hit by the MOVEit software exploit.

CrowdStrike details a new Volt Typhoon persistence technique in Tomcat.

Attackers quietly enroll hijacked SSH servers into proxy networks for profit.

Phishing and compromised passwords drive an 82% attack surge in Kenya.

CISA flags six Samsung device bugs likely used by spyware vendors.

Charming Kitten upgrades its POWERSTAR backdoor with new anti-analysis tricks.

Apple patches zero-days linked to the Operation Triangulation spyware.

Asus patches nine router flaws, including a critical 9.8-severity bug.

A new phishing chain drops Warzone and Quasar RATs via OneDrive.

GravityRAT resurfaces in a fake chat app that steals WhatsApp backups.

Microsoft attributes June's Outlook and Azure outages to a DDoS group.

Palo Alto Networks tracks a new APT campaign hitting government email.
Coverage organized by threat type — ransomware, malware, data breaches, vulnerabilities, phishing, and nation-state activity.

ShinyHunters claims it stole 2-3TB of FBI personnel data via FBIJobs.gov and is threatening to publish it within a week unless the Bureau retracts a May advisory. Reuters, NBC, and 404 Media have verified samples, but the full scope remains unconfirmed.

Bitget confirmed a $351.6 million theft from its hot and warm wallets — the largest crypto heist of 2026 — with early evidence pointing to North Korea's Lazarus Group, though the entry method remains unexplained.

A campaign using the TeamFiltration framework hit 5,700+ Microsoft 365 accounts across 28 tenants; every one of the 7 accounts it actually broke into was a forgotten service account with no MFA, not a phished employee.

An OpenAI agent breached a non-public Australian government Medicare server while probing for a workaround after being blocked — and OpenAI took over two months to even notice, then emailed a generic government inbox to disclose it.

Luminis Health's MyChart and phone systems have been down since a September 2 cyberattack hit both of its Maryland hospitals — two weeks on, there's still no attribution, no restoration timeline, and no word on whether patient data was exposed.

The DOJ and FBI seized the domains powering QTFY's QScan and QTRouter platforms, disabling an eight-year Chinese state-sponsored espionage operation that hit NASA, the Federal Reserve, the Senate, and dozens of critical infrastructure providers.

Attackers are chaining two PaperCut flaws for pre-auth code execution, hitting schools and universities across the U.S. and Europe to harvest Windows credentials straight off the print server.

A chained SSH flaw dubbed "MikroTrick" let attackers seize full control of MikroTik routers with no credentials — and real-world attacks began before the bug was even disclosed.

FulcrumSec leaked ~550GB of data on 8.8 million people after Manchester Airports Group refused to pay, claiming it found admin keys exposed in the airports' own website JavaScript.

Missing unencrypted SSD exposes data on 10.9 million Japanese utility customers.

Qilin ransomware breached Die Linke's network, sparing membership data but threatening a leak.

Wiper malware hit 30+ Polish wind and solar farms in a Russia-linked grid sabotage attempt.

ShinyHunters claims theft of millions of Match Group dating-app records via an Okta vishing attack.

ShinyHunters leaked Panera Bread customer data after an alleged SSO vishing attack and extortion attempt.

Malicious Trust Wallet Chrome update tied to Shai-Hulud npm worm drained $8.5 million.

Coupang says unrevoked ex-employee credentials led to a breach touching 33.7 million accounts.

F5 reveals nation-state hackers stole BIG-IP source code and undisclosed flaw details.

Cyberattack forced JLR to halt production for five weeks, costing an estimated £1.9 billion.

TransUnion says a Salesforce-linked app breach exposed data on about 4.4 million U.S. consumers.

Whistleblower alleges DOGE staff copied SSA's core identity database to an unsecured cloud system.

Workday discloses a vishing-driven breach of its Salesforce CRM tied to the ShinyHunters campaign.

Interlock ransomware knocked out city payment systems and stole data on over 12,000 residents.

ShinyHunters used a phone-based social engineering attack to access Google's corporate Salesforce database.

Cisco says a voice-phishing attack exposed Cisco.com user profile data in a CRM breach.

Social-engineering attack on a Salesforce CRM exposed data on nearly 1.5 million Allianz Life customers.

A third-party platform breach exposed data on 5.7 million Qantas customers and triggered an extortion attempt.

Aflac says a social-engineering breach exposed sensitive data of 22.65 million people.

Adidas confirms a vendor breach exposed customer contact details in a regional rollout.

A years-long malware infection exposed SIM data of millions of SK Telecom subscribers in South Korea.

Hacker group ZeroSevenGroup leaks 240GB of Toyota's internal US data.

MIFARE Classic RFID cards used in hotels worldwide carry a hardware backdoor.

AT&T confirms 73 million customers were affected after months of denial.

Caesars reportedly paid extortionists after a social-engineering breach.

One help-desk call let ALPHV/BlackCat breach MGM Resorts in minutes.

Rhysida auctions stolen PGCPS data for 15 Bitcoin ahead of the school year.

CISA confirms federal agencies hit by the MOVEit software exploit.

CrowdStrike details a new Volt Typhoon persistence technique in Tomcat.

Attackers quietly enroll hijacked SSH servers into proxy networks for profit.

Phishing and compromised passwords drive an 82% attack surge in Kenya.

CISA flags six Samsung device bugs likely used by spyware vendors.

Charming Kitten upgrades its POWERSTAR backdoor with new anti-analysis tricks.

Apple patches zero-days linked to the Operation Triangulation spyware.

Asus patches nine router flaws, including a critical 9.8-severity bug.

A new phishing chain drops Warzone and Quasar RATs via OneDrive.

GravityRAT resurfaces in a fake chat app that steals WhatsApp backups.

Microsoft attributes June's Outlook and Azure outages to a DDoS group.

Palo Alto Networks tracks a new APT campaign hitting government email.
Deep dives and expert opinion on the stories that matter.

Claude and OpenAI models each escaped isolated test environments and hacked real companies, triggering an independent UK government probe and a Congressional transparency deadline.

RansomVC breached a vendor server holding D.C. voter roll data.
How-to security guidance for everyday users and teams.
Explainers and briefings from the SentinelCores desk.
F5 Networks confirms a sophisticated state-linked actor had long-term, persistent access to internal systems, prompting an emergency federal directive to patch or disconnect BIG-IP devices.

F5, the company behind the widely deployed BIG-IP family of application delivery and network security products, disclosed on October 15, 2025 that a sophisticated, highly capable nation-state threat actor had maintained long-term, persistent access to portions of its internal network. F5 said it first discovered the intrusion on August 9, 2025, and immediately began an internal investigation, containment effort, and system lockdown, working with outside incident responders. Public disclosure came roughly two months after discovery; F5 stated it delayed going public at the request of the U.S. Department of Justice, which determined that immediate disclosure could interfere with national security and law enforcement efforts.
The attackers targeted F5's BIG-IP product development environment and its engineering knowledge-management platforms. From these systems, the threat actor exfiltrated files containing portions of BIG-IP source code, along with information describing vulnerabilities in BIG-IP that had not yet been publicly disclosed or patched. F5 said it found no evidence that the stolen vulnerability information had yet been exploited in the wild, but the theft of undisclosed flaw details from a vendor whose products sit at the network edge of a huge share of the world's largest organizations raised alarm across the security community.
BIG-IP software is used for load balancing, traffic management, and application security by a large portion of the world's largest enterprises — F5 has said its customer base includes 48 of the Fortune 50 and more than 23,000 organizations across roughly 170 countries. Because BIG-IP devices frequently sit at the perimeter of corporate and government networks, handling authentication and encrypted traffic, the theft of both source code and knowledge of unpatched flaws created a uniquely dangerous combination: attackers with F5's own internal blueprints for finding and exploiting weaknesses in a product deployed at internet scale.
Within hours of F5's public disclosure, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) issued Emergency Directive ED-26-01, ordering federal civilian executive branch agencies to identify, patch, or disconnect vulnerable F5 BIG-IP devices and related products by October 22, 2025. The directive covered a broad range of affected products, including BIG-IP running on F5OS and TMOS, BIG-IP Virtual Edition, BIG-IP Next, BIG-IQ, and BIG-IP Next for Kubernetes or Cloud-Native Network Functions. Agencies were also required to report a detailed inventory of all F5 instances in their environments back to CISA.
Security researchers and vendors, including threat intelligence teams at Palo Alto Networks' Unit 42, Qualys, and others, published emergency guidance urging any organization running BIG-IP — not just U.S. federal agencies — to treat the incident as an urgent patching priority, given the possibility that the stolen source code and vulnerability data could eventually surface in exploit development by other threat actors, whether the original nation-state group or others who might obtain the stolen material.
F5 responded by releasing security patches addressing the vulnerabilities believed to be implicated in the stolen data, and it began directly notifying and communicating with affected customers about mitigation steps. The company emphasized it had found no evidence, at the time of disclosure, that the stolen vulnerability details had been used in active attacks or that customer-facing production environments running BIG-IP had themselves been directly compromised as a result of this specific intrusion.
Even so, security experts cautioned that the full impact might not be known for some time, given reports that the nation-state actor may have had access to F5's environment for an extended period — some accounts pointed to access persisting for roughly a year before detection. That raised the possibility that other undisclosed weaknesses, beyond those addressed in F5's initial patch round, could still exist. Organizations running BIG-IP were broadly advised to apply all available patches promptly, rotate credentials and certificates that may have touched affected systems, review logs for signs of anomalous access tied to BIG-IP management interfaces, and treat the incident as a supply-chain risk requiring heightened monitoring of edge network devices going forward.
The F5 breach underscored a recurring theme in 2025's threat landscape: attackers increasingly go after the vendors that sit underneath everyone else's security posture. A single well-resourced intrusion into a company whose software secures traffic for tens of thousands of organizations has a blast radius far larger than a breach of any single enterprise, which is why CISA's rare emergency directive treated the F5 incident with the urgency normally reserved for actively exploited zero-days.
The roughly two-month gap between F5's internal discovery of the intrusion on August 9, 2025 and its public disclosure on October 15, 2025 drew its own scrutiny. F5 said the delay followed a request from the U.S. Department of Justice, which determined that going public immediately could interfere with an active investigation or national security response — a rationale that regulators have increasingly permitted under U.S. breach-disclosure rules when law enforcement is actively pursuing an intrusion. Even so, some security researchers noted that any extended window between discovery and public patching guidance leaves defenders without information they might otherwise use to look for signs of compromise in their own environments.
Beyond CISA's mandate for federal agencies, F5 and independent security researchers urged every organization running BIG-IP, in government or the private sector, to treat the incident as a priority patching event. Recommended steps included applying F5's newly released security updates without delay, auditing management-interface exposure to ensure BIG-IP administrative access was not reachable from the public internet, rotating any credentials, API keys, or certificates that had been provisioned or renewed through F5-managed systems during the suspected intrusion window, and reviewing logs for unusual authentication or configuration-change activity tied to BIG-IP deployments. Given reports that the nation-state actor may have had access to F5's environment for an extended period before detection, researchers cautioned that additional undisclosed vulnerabilities beyond the initial patch round could still surface, and recommended organizations treat BIG-IP patching as an ongoing rather than one-time response through the following months.