Related Threat Clusters
-
Critical OS Command Injection Vulnerability in Atlassian Bamboo Disclosed
Atlassian has announced two critical vulnerabilities in its Bamboo Data Center and Server product, including a severe OS command injection flaw (CVE-2026-21571) and a high-severity denial-of-service issue. The command…
2 articles · Updated April 22, 2026 -
Critical Zero-Day Vulnerabilities in Atlassian Confluence Exploited
Atlassian Confluence has faced multiple critical vulnerabilities, including CVE-2022-26134 and CVE-2023-22515. CVE-2022-26134, published on June 3, 2022, is an unauthenticated remote code execution vulnerability that…
3 articles · Updated June 17, 2026 -
Megalodon Campaign Infects Over 5,500 GitHub Repositories with Malware
On May 18, 2026, an automated cyber campaign named Megalodon pushed 5,718 malicious commits to 5,561 GitHub repositories within six hours. The attackers used forged identities and dummy accounts to inject malicious…
7 articles · Updated May 26, 2026 -
RovoBlast Vulnerability Exposes Enterprise Data via One-Click Attack
Atlassian's Rovo AI assistant was found vulnerable to a one-click prompt injection attack, dubbed RovoBlast, which allows attackers to inject malicious instructions into authenticated user sessions. This vulnerability…
4 articles · Updated August 10, 2026 -
AI-Powered Phishing Campaigns Render Blocklists Ineffective
AI has significantly enhanced phishing tactics, making traditional blocklists obsolete. Attackers utilize AI to generate phishing pages from screenshots in mere minutes, leading to a rapid turnover of phishing domains.…
2 articles · Updated August 5, 2026 -
Telus Digital Confirms Massive Data Breach by ShinyHunters Group
Telus Digital, a Canadian telecommunications and BPO provider, has confirmed a significant data breach involving the ShinyHunters hacking group. The attackers claim to have stolen approximately 1 petabyte of data,…
18 articles · Updated March 12, 2026 -
Zara Data Breach Exposes Information of 197,000 Customers
Zara experienced a data breach affecting over 197,000 customers, attributed to the ShinyHunters extortion group. The breach involved a compromise of the Anodot analytics platform, leading to the theft of unique email…
6 articles · Updated May 8, 2026 -
AI-Driven Email Fraud Threatens Banks in Australia and India
Proofpoint's analysis reveals that a significant number of banks in Australia and major companies in India are not enforcing the strongest DMARC email authentication protocols, leaving them vulnerable to AI-enhanced…
9 articles · Updated July 1, 2026 -
Gainsight Apps Breach Exposes Data of Over 200 Salesforce Customers
A significant supply chain attack has compromised Salesforce-stored data from more than 200 companies through applications published by Gainsight. Salesforce confirmed unauthorized access to customer data and is…
30 articles · Updated November 23, 2025 -
Abbott Laboratories Investigates Cyber Incidents in Cancer Diagnostics and LabCentral Portal
Abbott Laboratories is probing two cyber incidents involving unauthorized access to its Cancer Diagnostics business and LabCentral portal. The company confirmed that the incidents did not affect operations or other…
20 articles · Updated July 17, 2026
Recent Intelligence Reports
- Atlassian Rovo AI Vulnerability Lets Attackers Steal Enterprise Data With a Single Click — Gbhackers · August 10, 2026
- Atlassian Rovo Prompt Injection Exfiltrates Jira and Confluence Data Without User Approval — Cybersecuritynews · August 10, 2026
- How AI — Bleepingcomputer · August 5, 2026
- How AI — Bleepingcomputer · August 5, 2026
- Abbott Laboratories probes two cyber incidents amid extortion claims — Bleepingcomputer · July 17, 2026
- Otelier Data Breach Exposes Info Hotel Reservations Of Millions — www.bleepingcomputer.com · June 27, 2026
- Rapid7 Analysis: CVE-2022 — Rapid7 · June 17, 2026
- Megalodon Mass Github Repo Backdooring Ci Workflows — safedep.io · May 26, 2026