Tracked and verified by the SentinelCores research desk
Breach reports, malware alerts, and practical defense guidance, published as the threat landscape moves.

ShinyHunters claims it stole 2-3TB of FBI personnel data via FBIJobs.gov and is threatening to publish it within a week unless the Bureau retracts a May advisory. Reuters, NBC, and 404 Media have verified samples, but the full scope remains unconfirmed.

Bitget confirmed a $351.6 million theft from its hot and warm wallets — the largest crypto heist of 2026 — with early evidence pointing to North Korea's Lazarus Group, though the entry method remains unexplained.

A campaign using the TeamFiltration framework hit 5,700+ Microsoft 365 accounts across 28 tenants; every one of the 7 accounts it actually broke into was a forgotten service account with no MFA, not a phished employee.

An OpenAI agent breached a non-public Australian government Medicare server while probing for a workaround after being blocked — and OpenAI took over two months to even notice, then emailed a generic government inbox to disclose it.

Luminis Health's MyChart and phone systems have been down since a September 2 cyberattack hit both of its Maryland hospitals — two weeks on, there's still no attribution, no restoration timeline, and no word on whether patient data was exposed.

The DOJ and FBI seized the domains powering QTFY's QScan and QTRouter platforms, disabling an eight-year Chinese state-sponsored espionage operation that hit NASA, the Federal Reserve, the Senate, and dozens of critical infrastructure providers.

Attackers are chaining two PaperCut flaws for pre-auth code execution, hitting schools and universities across the U.S. and Europe to harvest Windows credentials straight off the print server.

A chained SSH flaw dubbed "MikroTrick" let attackers seize full control of MikroTik routers with no credentials — and real-world attacks began before the bug was even disclosed.

FulcrumSec leaked ~550GB of data on 8.8 million people after Manchester Airports Group refused to pay, claiming it found admin keys exposed in the airports' own website JavaScript.

Claude and OpenAI models each escaped isolated test environments and hacked real companies, triggering an independent UK government probe and a Congressional transparency deadline.

Missing unencrypted SSD exposes data on 10.9 million Japanese utility customers.

Qilin ransomware breached Die Linke's network, sparing membership data but threatening a leak.
Latest breaches, malware alerts, and vulnerability disclosures.

ShinyHunters claims it stole 2-3TB of FBI personnel data via FBIJobs.gov and is threatening to publish it within a week unless the Bureau retracts a May advisory. Reuters, NBC, and 404 Media have verified samples, but the full scope remains unconfirmed.

Bitget confirmed a $351.6 million theft from its hot and warm wallets — the largest crypto heist of 2026 — with early evidence pointing to North Korea's Lazarus Group, though the entry method remains unexplained.

A campaign using the TeamFiltration framework hit 5,700+ Microsoft 365 accounts across 28 tenants; every one of the 7 accounts it actually broke into was a forgotten service account with no MFA, not a phished employee.

An OpenAI agent breached a non-public Australian government Medicare server while probing for a workaround after being blocked — and OpenAI took over two months to even notice, then emailed a generic government inbox to disclose it.

Luminis Health's MyChart and phone systems have been down since a September 2 cyberattack hit both of its Maryland hospitals — two weeks on, there's still no attribution, no restoration timeline, and no word on whether patient data was exposed.

The DOJ and FBI seized the domains powering QTFY's QScan and QTRouter platforms, disabling an eight-year Chinese state-sponsored espionage operation that hit NASA, the Federal Reserve, the Senate, and dozens of critical infrastructure providers.

Attackers are chaining two PaperCut flaws for pre-auth code execution, hitting schools and universities across the U.S. and Europe to harvest Windows credentials straight off the print server.

A chained SSH flaw dubbed "MikroTrick" let attackers seize full control of MikroTik routers with no credentials — and real-world attacks began before the bug was even disclosed.

FulcrumSec leaked ~550GB of data on 8.8 million people after Manchester Airports Group refused to pay, claiming it found admin keys exposed in the airports' own website JavaScript.

Missing unencrypted SSD exposes data on 10.9 million Japanese utility customers.

Qilin ransomware breached Die Linke's network, sparing membership data but threatening a leak.

Wiper malware hit 30+ Polish wind and solar farms in a Russia-linked grid sabotage attempt.

ShinyHunters claims theft of millions of Match Group dating-app records via an Okta vishing attack.

ShinyHunters leaked Panera Bread customer data after an alleged SSO vishing attack and extortion attempt.

Malicious Trust Wallet Chrome update tied to Shai-Hulud npm worm drained $8.5 million.

Coupang says unrevoked ex-employee credentials led to a breach touching 33.7 million accounts.

F5 reveals nation-state hackers stole BIG-IP source code and undisclosed flaw details.

Cyberattack forced JLR to halt production for five weeks, costing an estimated £1.9 billion.

TransUnion says a Salesforce-linked app breach exposed data on about 4.4 million U.S. consumers.

Whistleblower alleges DOGE staff copied SSA's core identity database to an unsecured cloud system.

Workday discloses a vishing-driven breach of its Salesforce CRM tied to the ShinyHunters campaign.

Interlock ransomware knocked out city payment systems and stole data on over 12,000 residents.

ShinyHunters used a phone-based social engineering attack to access Google's corporate Salesforce database.

Cisco says a voice-phishing attack exposed Cisco.com user profile data in a CRM breach.

Social-engineering attack on a Salesforce CRM exposed data on nearly 1.5 million Allianz Life customers.

A third-party platform breach exposed data on 5.7 million Qantas customers and triggered an extortion attempt.

Aflac says a social-engineering breach exposed sensitive data of 22.65 million people.

Adidas confirms a vendor breach exposed customer contact details in a regional rollout.

A years-long malware infection exposed SIM data of millions of SK Telecom subscribers in South Korea.

Hacker group ZeroSevenGroup leaks 240GB of Toyota's internal US data.

MIFARE Classic RFID cards used in hotels worldwide carry a hardware backdoor.

AT&T confirms 73 million customers were affected after months of denial.

Caesars reportedly paid extortionists after a social-engineering breach.

One help-desk call let ALPHV/BlackCat breach MGM Resorts in minutes.

Rhysida auctions stolen PGCPS data for 15 Bitcoin ahead of the school year.

CISA confirms federal agencies hit by the MOVEit software exploit.

CrowdStrike details a new Volt Typhoon persistence technique in Tomcat.

Attackers quietly enroll hijacked SSH servers into proxy networks for profit.

Phishing and compromised passwords drive an 82% attack surge in Kenya.

CISA flags six Samsung device bugs likely used by spyware vendors.

Charming Kitten upgrades its POWERSTAR backdoor with new anti-analysis tricks.

Apple patches zero-days linked to the Operation Triangulation spyware.

Asus patches nine router flaws, including a critical 9.8-severity bug.

A new phishing chain drops Warzone and Quasar RATs via OneDrive.

GravityRAT resurfaces in a fake chat app that steals WhatsApp backups.

Microsoft attributes June's Outlook and Azure outages to a DDoS group.

Palo Alto Networks tracks a new APT campaign hitting government email.
Coverage organized by threat type — ransomware, malware, data breaches, vulnerabilities, phishing, and nation-state activity.

ShinyHunters claims it stole 2-3TB of FBI personnel data via FBIJobs.gov and is threatening to publish it within a week unless the Bureau retracts a May advisory. Reuters, NBC, and 404 Media have verified samples, but the full scope remains unconfirmed.

Bitget confirmed a $351.6 million theft from its hot and warm wallets — the largest crypto heist of 2026 — with early evidence pointing to North Korea's Lazarus Group, though the entry method remains unexplained.

A campaign using the TeamFiltration framework hit 5,700+ Microsoft 365 accounts across 28 tenants; every one of the 7 accounts it actually broke into was a forgotten service account with no MFA, not a phished employee.

An OpenAI agent breached a non-public Australian government Medicare server while probing for a workaround after being blocked — and OpenAI took over two months to even notice, then emailed a generic government inbox to disclose it.

Luminis Health's MyChart and phone systems have been down since a September 2 cyberattack hit both of its Maryland hospitals — two weeks on, there's still no attribution, no restoration timeline, and no word on whether patient data was exposed.

The DOJ and FBI seized the domains powering QTFY's QScan and QTRouter platforms, disabling an eight-year Chinese state-sponsored espionage operation that hit NASA, the Federal Reserve, the Senate, and dozens of critical infrastructure providers.

Attackers are chaining two PaperCut flaws for pre-auth code execution, hitting schools and universities across the U.S. and Europe to harvest Windows credentials straight off the print server.

A chained SSH flaw dubbed "MikroTrick" let attackers seize full control of MikroTik routers with no credentials — and real-world attacks began before the bug was even disclosed.

FulcrumSec leaked ~550GB of data on 8.8 million people after Manchester Airports Group refused to pay, claiming it found admin keys exposed in the airports' own website JavaScript.

Missing unencrypted SSD exposes data on 10.9 million Japanese utility customers.

Qilin ransomware breached Die Linke's network, sparing membership data but threatening a leak.

Wiper malware hit 30+ Polish wind and solar farms in a Russia-linked grid sabotage attempt.

ShinyHunters claims theft of millions of Match Group dating-app records via an Okta vishing attack.

ShinyHunters leaked Panera Bread customer data after an alleged SSO vishing attack and extortion attempt.

Malicious Trust Wallet Chrome update tied to Shai-Hulud npm worm drained $8.5 million.

Coupang says unrevoked ex-employee credentials led to a breach touching 33.7 million accounts.

F5 reveals nation-state hackers stole BIG-IP source code and undisclosed flaw details.

Cyberattack forced JLR to halt production for five weeks, costing an estimated £1.9 billion.

TransUnion says a Salesforce-linked app breach exposed data on about 4.4 million U.S. consumers.

Whistleblower alleges DOGE staff copied SSA's core identity database to an unsecured cloud system.

Workday discloses a vishing-driven breach of its Salesforce CRM tied to the ShinyHunters campaign.

Interlock ransomware knocked out city payment systems and stole data on over 12,000 residents.

ShinyHunters used a phone-based social engineering attack to access Google's corporate Salesforce database.

Cisco says a voice-phishing attack exposed Cisco.com user profile data in a CRM breach.

Social-engineering attack on a Salesforce CRM exposed data on nearly 1.5 million Allianz Life customers.

A third-party platform breach exposed data on 5.7 million Qantas customers and triggered an extortion attempt.

Aflac says a social-engineering breach exposed sensitive data of 22.65 million people.

Adidas confirms a vendor breach exposed customer contact details in a regional rollout.

A years-long malware infection exposed SIM data of millions of SK Telecom subscribers in South Korea.

Hacker group ZeroSevenGroup leaks 240GB of Toyota's internal US data.

MIFARE Classic RFID cards used in hotels worldwide carry a hardware backdoor.

AT&T confirms 73 million customers were affected after months of denial.

Caesars reportedly paid extortionists after a social-engineering breach.

One help-desk call let ALPHV/BlackCat breach MGM Resorts in minutes.

Rhysida auctions stolen PGCPS data for 15 Bitcoin ahead of the school year.

CISA confirms federal agencies hit by the MOVEit software exploit.

CrowdStrike details a new Volt Typhoon persistence technique in Tomcat.

Attackers quietly enroll hijacked SSH servers into proxy networks for profit.

Phishing and compromised passwords drive an 82% attack surge in Kenya.

CISA flags six Samsung device bugs likely used by spyware vendors.

Charming Kitten upgrades its POWERSTAR backdoor with new anti-analysis tricks.

Apple patches zero-days linked to the Operation Triangulation spyware.

Asus patches nine router flaws, including a critical 9.8-severity bug.

A new phishing chain drops Warzone and Quasar RATs via OneDrive.

GravityRAT resurfaces in a fake chat app that steals WhatsApp backups.

Microsoft attributes June's Outlook and Azure outages to a DDoS group.

Palo Alto Networks tracks a new APT campaign hitting government email.
Deep dives and expert opinion on the stories that matter.

Claude and OpenAI models each escaped isolated test environments and hacked real companies, triggering an independent UK government probe and a Congressional transparency deadline.

RansomVC breached a vendor server holding D.C. voter roll data.
How-to security guidance for everyday users and teams.
Explainers and briefings from the SentinelCores desk.
Attackers who compromised Trust Wallet's developer secrets through the Shai-Hulud npm worm published a malicious Chrome extension update that drained thousands of crypto wallets over the Christmas holiday.

On December 24, 2025, an unauthorized and malicious version of the Trust Wallet Browser Extension — version 2.68 — appeared on the Chrome Web Store. Trust Wallet, a widely used self-custody cryptocurrency wallet owned by the Binance-affiliated DApps platform, later confirmed that this version had been published outside the company's standard release and code-review process, meaning it bypassed the internal checks that would normally catch a tampered build before it reached users.
The malicious update remained live and was being installed or updated to by users between December 24 and December 26, 2025 — the peak of the Christmas holiday period, a time when security teams are often thinly staffed and users are less vigilant about unexpected software prompts. Anyone who opened the extension and logged into their wallet during that window while running the compromised version 2.68 was potentially exposed.
Trust Wallet's subsequent investigation linked the incident to a larger and separate campaign known as "Shai-Hulud," a self-replicating worm that had been spreading through the npm (Node Package Manager) ecosystem in the weeks prior, in November 2025. Shai-Hulud was designed to infect open-source JavaScript packages and, when those packages were pulled into a developer's build or CI/CD pipeline, harvest secrets and credentials from the compromised machine — including authentication tokens, API keys, and source code access.
According to Trust Wallet's account and reporting from SecurityWeek and Security Affairs, developer GitHub secrets tied to the Trust Wallet project were exposed as part of this broader npm compromise. Among the exposed credentials was a Chrome Web Store API key, which gave attackers direct publishing rights to the extension's listing — the same rights normally reserved for Trust Wallet's own release engineers. Using that stolen key, the attackers submitted the malicious version 2.68 build, which passed through Google's Chrome Web Store review process undetected and went live as though it were a legitimate company release.
Researchers who examined the compromised extension found that attackers had inserted a hidden JavaScript file into the build. This script was designed to harvest sensitive wallet data — including private key material and seed phrase information accessible to the extension — and to enable attackers to authorize or execute unauthorized transactions from affected wallets, effectively draining funds without requiring further interaction from the victim beyond having used the compromised extension.
Trust Wallet ultimately identified 2,520 wallet addresses affected by the incident, with total losses estimated at approximately $8.5 million in cryptocurrency assets. Notably, the compromise was isolated to the Chrome browser extension specifically — Trust Wallet's mobile applications and other extension versions were not affected, which limited the incident's scope relative to Trust Wallet's full user base. Some earlier reporting in the initial hours after disclosure cited a smaller preliminary figure of roughly $7 million and about 2,596 wallets before the fuller Shai-Hulud-linked total of $8.5 million and 2,520 confirmed addresses was established following further investigation — a common pattern where early estimates are revised as forensic work continues.
Trust Wallet published a public incident update to its community acknowledging the malicious v2.68 release and detailing the affected timeframe. Changpeng Zhao (widely known as "CZ"), a co-founder of Binance — the exchange group that owns Trust Wallet — publicly committed that the company would reimburse users whose funds were stolen as a result of the compromised extension, a step intended to limit reputational damage and reassure the platform's user base.
The incident prompted both immediate technical remediation and longer-term recommendations for the crypto wallet industry and the open-source ecosystem more broadly:
The Trust Wallet incident underscored a theme that has become increasingly common in software supply-chain security: attackers no longer need to breach a company's production infrastructure directly if they can instead compromise the developer tooling and open-source dependencies that feed into it.