The breaches, vulnerabilities and nation-state activity that matter to everyone — ranked by impact, with unverified claims labelled as unverified and every item linked to its primary source.
Cyber security
GitHub
Newcritical
Coding-agent harness flaws disclosed: RCE from a single GitHub issue
Novee researcher Elad Meged demonstrated that an unprivileged GitHub issue could reach code execution on CI runners behind Claude Code, Gemini CLI and Codex in each vendor's default configuration. Anthropic assigned CVE-2026-54316; Google rated its issue CVSS 10.0.
Conduent breach notifications pass 62.2 million people
The business services provider expanded the incident's reported scope to more than 62.2 million individuals. Social Security numbers, medical information and health insurance data were among the exposed records. Largest US breach disclosed in 2026 by affected population. Date is approximate — reflects July filings.
Stryker hit by destructive wiper attack; global Microsoft environment disrupted
The medical device maker suffered a cyberattack causing global disruption to its Microsoft environment. Attributed in reporting to Iran-linked group Handala, and characterised as data theft plus a wipe rather than ransomware. The group claimed more than 200,000 systems impacted and roughly 50TB exfiltrated — attacker claims, not confirmed figures. Stryker reported most manufacturing sites restored by 30 March, and the attack affected Q1 earnings.
Ransomware group claims 21 million Salesforce records
A ransomware group claimed theft of more than 21 million Salesforce records and 147GB of internal corporate data. Not corroborated by the named parties. Leak-site victim counts are an extortion marketing tactic and should not be planned around.
Nearly six million people were affected, some records containing government identification. The attacker gained access through social engineering rather than a technical exploit.
The insurer confirmed exposure of personal information and driver's licence numbers for 6.9 million people — reported as the largest known exposure of US driver's licence data this year.
CISA announces initiative to harden critical infrastructure against nation-state attacks
CISA announced an initiative to provide guidance to critical infrastructure operators, urging entities to assume third-party dependencies are unreliable, prepare to restore vital systems while isolated, and practise local manual operation.
Joint advisory: Iranian-affiliated actors targeting PLCs and industrial control systems
US federal agencies warned that Iranian-affiliated actors were targeting programmable logic controllers and ICS in water, energy and municipal infrastructure, with campaigns linked to CyberAv3ngers focused on operational disruption rather than espionage. Date approximate.
A free 5-minute morning brief — the day's AI and cybersecurity in five items,
each linked to its source. Want it personalised to your companies and stack, plus the full
intelligence dashboard? See the plans — free to start,
Pro from €39/mo.