The biggest stories in cybersecurity
Cyber Security News
The breaches, vulnerabilities and nation-state activity that matter to everyone — ranked by impact, with unverified claims labelled as unverified and every item linked to its primary source.
New critical
Coding-agent harness flaws disclosed: RCE from a single GitHub issue
Novee researcher Elad Meged demonstrated that an unprivileged GitHub issue could reach code execution on CI runners behind Claude Code, Gemini CLI and Codex in each vendor's default configuration. Anthropic assigned CVE-2026-54316; Google rated its issue CVSS 10.0.
Source: Novee · Our coverage
More, ranked by impact
Straight from the incident ledger, biggest first. See the full ledger →
critical
Conduent breach notifications pass 62.2 million people
The business services provider expanded the incident's reported scope to more than 62.2 million individuals. Social Security numbers, medical information and health insurance data were among the exposed records. Largest US breach disclosed in 2026 by affected population. Date is approximate — reflects July filings.
Source: TechCrunch
critical
Stryker hit by destructive wiper attack; global Microsoft environment disrupted
The medical device maker suffered a cyberattack causing global disruption to its Microsoft environment. Attributed in reporting to Iran-linked group Handala, and characterised as data theft plus a wipe rather than ransomware. The group claimed more than 200,000 systems impacted and roughly 50TB exfiltrated — attacker claims, not confirmed figures. Stryker reported most manufacturing sites restored by 30 March, and the attack affected Q1 earnings.
Source: Stryker
high unverified
Ransomware group claims 21 million Salesforce records
A ransomware group claimed theft of more than 21 million Salesforce records and 147GB of internal corporate data. Not corroborated by the named parties. Leak-site victim counts are an extortion marketing tactic and should not be planned around.
Source: SharkStriker breach tracker
high
Carnival breach affects roughly 6 million people
Nearly six million people were affected, some records containing government identification. The attacker gained access through social engineering rather than a technical exploit.
Source: TechRepublic
high unverified
ShinyHunters claims theft of EY client tax data
The extortion group ShinyHunters said it stole client tax data from EY and threatened to leak it. Reported as a claim by the group.
Source: DuoCircle
high
AssuranceAmerica confirms 6.9 million affected
The insurer confirmed exposure of personal information and driver's licence numbers for 6.9 million people — reported as the largest known exposure of US driver's licence data this year.
Source: TechCrunch
high
CISA announces initiative to harden critical infrastructure against nation-state attacks
CISA announced an initiative to provide guidance to critical infrastructure operators, urging entities to assume third-party dependencies are unreliable, prepare to restore vital systems while isolated, and practise local manual operation.
Source: AHA News
high
Joint advisory: Iranian-affiliated actors targeting PLCs and industrial control systems
US federal agencies warned that Iranian-affiliated actors were targeting programmable logic controllers and ICS in water, energy and municipal infrastructure, with campaigns linked to CyberAv3ngers focused on operational disruption rather than espionage. Date approximate.
Source: CISA
medium unverified
CRPx0 lists Hyundai Türkiye on its leak site
The double-extortion group CRPx0 claimed 1.5GB of exfiltrated assessment data from Hyundai's Turkish operations. Claim not confirmed by Hyundai.
Source: DuoCircle