Data Breach

ASOS Push Notification Security Breach Concept

News

ASOS Global Push Notification Breach: Xuanye Group Hijacks Customer Engagement Pipeline

📌Security Roundup Series: Week of October 9, 2026 • 4 min read deep dive🏛️Incident Overview: Target / Organization: ASOS.com (Global Online Fashion & Retail) Threat Actor / Attribution: Xuanye Group (Cyber Extortion Collective) Impact / Records Compromised: Customer names, email addresses, phone numbers, delivery addresses, search histories Initial Attack Vector: Social engineering

By James Luther
Photon Health Healthcare Data Breach Concept

News

Photon Health Data Breach: Zero-Day SQL Injection in Self-Hosted Metabase Exposes Patient Prescriptions

📌Security Roundup Series: Week of October 9, 2026 • 4 min read deep dive🏛️Incident Overview: Target / Organization: Photon Health, Inc. (Digital E-Prescription SaaS Infrastructure) Threat Actor / Attribution: Unidentified Threat Actor (Financial / Data Extortion) Impact / Records Compromised: Patient names, street addresses, phone numbers, dates of birth, sensitive prescription medications Initial Attack

By James Luther
ColibriSec Weekend Security Roundup October 5 2026

News

Security Roundup: Citrix NetScaler SAML Zero-Day, Denmark 8.8M Registry Breach, Rejetto AI RCE, Asian Financial Infiltrations (Weekend of October 5, 2026)

Executive Summary: The weekend of October 3–5, 2026, delivered an unprecedented surge of critical perimeter exploits, monumental government and enterprise data leaks, and AI-driven intrusion vectors. Headlining the emergency alerts, Citrix confirmed active targeted exploitation of CVE-2026-88779—a high-severity memory overflow zero-day in NetScaler ADC and Gateway configured as

By ColibriSec
Denmark National Central Person Register CPR Cyber Breach

News

Denmark Central Person Register Breach: 8.8 Million Citizen Records Exposed via Authorized Partner Misuse

📌Security Roundup Series: Weekend of October 5, 2026 • 4 min read deep dive🏛️Incident Overview: Target / Organization: Kingdom of Denmark: Det Centrale Personregister (CPR) Threat Actor / Attribution: Unattributed Threat Syndicate / Compromised Private Partner Access Impact / Records Compromised: 8.8 Million Citizen Records (Current Residents, Expatriates & Historical Records) Initial Attack

By ColibriSec
Monogatari Corporation Yakiniku King Data Leak Tokyo Japan

News

Monogatari Corporation Breach: 10.79 Million Customer Records Leaked in Japanese Hospitality Incident

📌Security Roundup Series: Weekend of October 5, 2026 • 4 min read deep dive🏛️Incident Overview: Target / Organization: Monogatari Corporation (Yakiniku King, Marugen Ramen, Syabu-no-Sato) Threat Actor / Attribution: Unattributed Threat Actor / External Cloud Intrusion Impact / Records Compromised: 10,790,000 Customer Member Records Compromised Initial Attack Vector: Unauthorized Ingress into Cloud

By ColibriSec
Daiwa Securities and Scala Communications Supply Chain Cyber Incident

News

Daiwa Securities Supply Chain Breach: Vendor Server Compromise Exposes 110,000 Client Accounts

📌Security Roundup Series: Weekend of October 5, 2026 • 4 min read deep dive🏛️Incident Overview: Target / Organization: Daiwa Securities Group Inc. / Scala Communications Inc. Threat Actor / Attribution: External Threat Actors / Third-Party Vendor Compromise Impact / Records Compromised: 110,000 Wealth Management & Brokerage Client Accounts Initial Attack Vector: Server Infiltration at

By ColibriSec
Technical University of Denmark DTU DTUBasen Identity Management Breach

News

Technical University of Denmark (DTU) Breach: 200,000 Identities Exposed via DTUBasen IAM

📌Security Roundup Series: Weekend of October 5, 2026 • 4 min read deep dive🏛️Incident Overview: Target / Organization: Technical University of Denmark (Danmarks Tekniske Universitet - DTU) Threat Actor / Attribution: Unauthenticated Cyber Threat Actor / Credential Abuse Impact / Records Compromised: Up to 200,000 Current and Former Students, Faculty, and Researchers Initial

By ColibriSec
Bitget $387.5M Cryptocurrency Exchange Hot Wallet Breach

News

Bitget $387.5M Security Breach: Third-Party Zero-Day and Hot Wallet Risk Analysis

📌Security Roundup Series: Week of October 2, 2026 • 4 min read deep dive🏛️Incident Overview: Target / Organization: Bitget Global Cryptocurrency Exchange Threat Actor / Attribution: Suspected State-Sponsored Syndicate (Lazarus Group / DPRK) Impact / Records Compromised: $387.5 Million in Digital Assets (ETH, XRP, USDT, USDC across 11 Blockchains) Initial Attack Vector: Zero-Day

By James Luther
Adif and Renfe Spanish Railway Cyberattack Deep Dive

News

Adif & Renfe Railway Cyberattack: First Documented AI-Augmented Intrusion on Spanish Critical Infrastructure

📌Security Roundup Series: Weekend of September 28, 2026 • 4 min read deep dive🏛️Incident Overview: Target / Organization: Adif (Infrastructure Manager) & Renfe (National Railway) - Spain Threat Actor / Attribution: Unattributed Cyber Threat Actor / AI-Assisted Reconnaissance Unit Impact / Records Compromised: ~500GB Exfiltrated (Passenger Telemetry, Route Scheduling, System Logs) Initial Attack Vector:

By James Luther
ShinyHunters Syndicate Amsterdam Arrest and Retaliation Analysis

News

ShinyHunters Syndicate Retaliation: Amsterdam Arrest Sparks Extortion Surge and Federal Contractor Leaks

📌Security Roundup Series: Weekend of September 28, 2026 • 4 min read deep dive🏛️Incident Overview: Target / Organization: ShinyHunters Syndicate Infrastructure / Odido / FBI Job Portal Threat Actor / Attribution: Pepijn van der Stap (Arrested) & ShinyHunters Retaliatory Affiliates Impact / Records Compromised: Terabytes of Historical & Retaliatory Extortion Data Initial Attack Vector: Offensive

By James Luther