Shopify — Cyber Attacks, Breaches & Threat Activity

Threat entity extracted from intelligence sources

Frequency
10
occurrences
First Seen
November 19, 2025
Last Seen
July 14, 2026

Related Threat Clusters

  • CVE-2026-2441: Zero-Day CSS Vulnerability in Chromium-Based Browsers

    CVE-2026-2441 is a zero-day CSS vulnerability affecting all Chromium-based browsers, allowing attackers to exploit a use-after-free condition in the Blink rendering engine. This vulnerability enables the theft of…

    3 articles · Updated February 21, 2026
  • Critical SSTI Vulnerability in FOSSBilling Exposes Databases to RCE Attacks

    A critical server-side template injection (SSTI) vulnerability in FOSSBilling, tracked as CVE-2026-28496, was disclosed on June 23, 2026. This flaw affects all versions up to 0.7.2 and allows attackers to exploit unsafe…

    2 articles · Updated June 26, 2026
  • State Actors Target Water Systems Amid Weak Cyber Defenses

    Water and wastewater systems are increasingly targeted by Russia, China, and Iran due to poor operational technology defenses. Exposed human-machine interfaces and programmable logic controllers create vulnerabilities…

    2 articles · Updated June 26, 2026
  • FBI Warns of Kali365 Phishing Kit Targeting Microsoft 365 Users

    The FBI has issued a warning regarding the Kali365 phishing kit, which is actively stealing Microsoft OAuth tokens and bypassing multi-factor authentication (MFA) protocols. First identified in April 2026, Kali365 is…

    135 articles · Updated May 22, 2026
  • Google Sues Chinese Cybercrime Network for AI-Powered Phishing Operations

    Google has filed a lawsuit against the 'Outsider Enterprise', a China-based cybercrime network, for allegedly using AI tools, including its Gemini platform, to conduct large-scale phishing operations. The operation has…

    57 articles · Updated June 12, 2026
  • Malicious LLM Proxy Routers Compromise AI Security

    A recent study identified 28 malicious LLM proxy routers that can modify AI service responses and access sensitive credentials. The research tested 28 paid routers and 400 free routers, revealing that nine injected…

    2 articles · Updated April 15, 2026
  • Celine Dion Concert Ticket Scam: Fans Targeted by Fraudsters

    Scammers are exploiting the excitement around Celine Dion's concert comeback, targeting fans with fraudulent ticket sales. Group-IB has identified multiple scam campaigns operating on social media and fake websites that…

    2 articles · Updated July 16, 2026
  • Ledger Faces Data Breach via Global-e Payment Processor

    Ledger, a crypto wallet firm, is experiencing a data breach linked to its third-party payment processor, Global-e. Customer data may have been exposed during this incident, which raises concerns about the security of…

    17 articles · Updated January 5, 2026
  • Cloudflare Outage Disrupts Major Websites and Apps

    A significant outage at Cloudflare has resulted in numerous major websites and applications going offline. The incident has particularly impacted financial services firms that rely on Cloudflare's network and security…

    36 articles · Updated November 18, 2025
  • Cloudflare Outage Disrupts Major Internet Services

    On November 18, 2025, Cloudflare experienced a significant outage that affected access to numerous major websites, including ChatGPT and X. The disruption was caused by a change to database access controls, which led to…

    39 articles · Updated November 26, 2025

Recent Intelligence Reports

  • The Scam Will Go On: Beware of Fake Offers for Celine Dion Concert Tickets | Group — Group-Ib · July 14, 2026
  • Water and Wastewater Systems Become Strategic Targets for Russia, China, and Iran — Gbhackers · June 26, 2026
  • FOSSBilling Flaw Lets Admin Attackers Abuse DI Container for SQL Access and RCE — Gbhackers · June 26, 2026
  • FBI takes down Phishing-as-a-Service platform "Outsider" — Heise.De · June 16, 2026
  • Google sues Chinese AI phishing ring as FBI seizes domains and $100000 in Operation Ghost Hook — Cryptopolitan · June 13, 2026
  • Chinese cybercrime operation that used AI to scam ‘hundreds of thousands of victims’ sued by Google — Techcrunch · June 12, 2026
  • Malicious LLM proxy routers found in the wild — News.Risky.Biz · April 15, 2026
  • CVE-2026-2441 Explained: CSS Zero-Day Browser Security — Sitepoint · February 19, 2026

CVSS v3.1 Breakdown