US law enforcement and Google took down a phishing platform that operated more than 9,000 sites, allegedly stealing nearly 4 million credit cards and inflicting roughly $1.9 billion in losses. The operation shows the industrial scale of phishing-as-a-service and the value of cross-industry takedowns to disrupt criminal infrastructure.
Source: SecurityWeek
Palo Alto warns of active exploitation of GlobalProtect VPN flaw (CVE-2026-0257)
Palo Alto Networks reported in-the-wild exploitation of an authentication bypass (CVSS 7.8) impacting PAN-OS GlobalProtect portals and gateways. Successful abuse can grant unauthorized access, underscoring the urgency for administrators to apply vendor guidance, review access logs, and limit portal exposure where possible.
Source: TheHackerNews
Supply chain attack hits popular WordPress plugins via Awesome Motive CDN
Researchers at Sansec uncovered a live supply chain attack in which compromised CDN-hosted JavaScript backdoored sites using OptinMonster, TrustPulse, and PushEngage. Because the malicious code was delivered from the provider’s CDN—not the victim’s server—many traditional site checks would miss it, highlighting third-party script risk.
Source: Security Affairs
Critical Splunk Enterprise flaw (CVE-2026-20253) allows arbitrary file operations
Splunk urged immediate patching of a critical vulnerability (CVSS 9.8) that enables unauthenticated attackers to perform arbitrary file operations and potentially achieve remote code execution on affected versions. Environments relying on Splunk for security visibility should prioritize updates to avoid turning the platform into an attack vector.
Source: CyberExpress
French government’s Tchap breach exposes 73,467 users
A breach of Tchap, the French government’s messaging platform, is broader than initially disclosed, with 73,467 users exposed as a hacker claims access to government chats. The incident raises risks of targeted phishing, impersonation, and potential exploitation of sensitive communications metadata.
Source: CyberNews
ShinyHunters claims 297 GB breach of Council of Europe
The extortion group ShinyHunters says it stole 297 GB of data from the Council of Europe, including staff personal information, and is threatening to leak it. If confirmed, the exposure could fuel fraud, blackmail, and targeted social engineering against European officials and personnel.
Source: SecurityWeek
‘The Gentlemen’ ransomware leverages infostealers, AI, and generous affiliate cuts
Security researchers report that The Gentlemen ransomware operation has listed 483 victims across 66 countries since launching in September 2025, with rapid growth in 2026. The group’s model uses credentials harvested by infostealers, AI-enabled tooling, and a 90% affiliate revenue share to accelerate intrusions and scale impact.
Source: Security Affairs
You May Also Be Interested In... - A hardware neural network backdoor that hides in plain sight - Maine disables data breach portal due to fake submissions - Sniper Dz scams target MENA users via fake Facebook offers