ShinyHunters Breach Amtrak via Salesforce Social Engineering — Up to 9.4 Million Records Compromised
Summary The prolific cybercrime group ShinyHunters has claimed responsibility for a massive data breach targeting Amtrak, alleging the theft of 9.4 million customer records through unauthorized access to the rail…
Microsoft April 2026 Patch Tuesday Fixes 167 Vulnerabilities Including Two Actively Exploited Zero-Days
Summary Microsoft’s April 2026 Patch Tuesday, released on April 14, addressed a massive 167 vulnerabilities across Windows and other Microsoft products — one of the largest monthly patch drops in…
Anthropic Withholds Claude Mythos Preview After It Autonomously Discovered Thousands of Zero-Day Vulnerabilities
Summary Anthropic has made the unprecedented decision to withhold its most advanced AI model, Claude Mythos Preview, from public release after internal testing revealed it could autonomously discover and exploit…
Critical GitHub Vulnerability Exposes Millions of Repositories to Remote Code Execution
What Happened A critical vulnerability (CVE-2026-3854) in GitHub’s infrastructure has been disclosed that could expose millions of repositories and potentially enable remote code execution. The flaw affects core GitHub functionality,…
ShinyHunters Ransomware Blitz Hits 40+ Organizations — Carnival Corp Leaks 8.7 Million Records
What Happened The notorious ShinyHunters group has launched a massive ransomware campaign impacting over 40 organizations across retail, insurance, hospitality, and other sectors. Among the most significant casualties is Carnival…
Critical LiteLLM SQL Injection (CVSS 9.3) Exploited Within Hours of Disclosure
What Happened A critical SQL injection vulnerability (CVE-2026-42208) in LiteLLM, the popular open-source AI gateway proxy, was exploited almost immediately after public disclosure. Rated at CVSS 9.3, the flaw allows…
CISA Orders Emergency Patches for Windows Zero-Day Exploited by Russian APT28
What Happened The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical Microsoft Windows Shell vulnerability (CVE-2026-32202) to its Known Exploited Vulnerabilities catalog, ordering federal agencies to patch…
IBM Releases Granite 4.1 — Its Most Extensive Open Model Family Yet
What Happened IBM released its Granite 4.1 collection on April 29, 2026, marking the company’s most extensive model release to date. The family spans language models, vision models, speech models,…
Rituals Cosmetics Confirms Massive Breach — 41 Million Customer Records Exposed
What Happened Netherlands-based cosmetics giant Rituals has confirmed a significant data breach after hackers compromised its membership database. The breach potentially affects 41 million customers worldwide — making it one…
China Drafts Sweeping Rules for AI “Digital Humans” — Bans Virtual Relationships for Minors
Summary China’s Cyberspace Administration (CAC) has released draft regulations titled “Provisional Measures on the Administration of Human-like Interactive AI Services,” targeting the rapidly growing market of AI-powered digital humans. The…
