Top stories
// 5 stories cyclingPTC Windchill / FlexPLM — Cl0p mass exploitation (CVE-2026-12569)
Cl0p is exploiting an unauthenticated remote-code-execution flaw in PTC's Windchill and FlexPLM product-lifecycle software to plant webshells, steal engineering data and run double-extortion.
Nichirei — RansomHouse ransomware halts Japan's largest frozen-food cold-chain network
RansomHouse-claimed ransomware disrupted Nichirei, Japan's largest frozen-food and cold-chain logistics group, for over a week, curtailing shipments and triggering KFC Japan and Glico supply shortages.
fairlife (The Coca-Cola Company) — ransomware halts US dairy production, Item 8.01 8-K
Coca-Cola filed an Item 8.01 8-K on 16 July confirming a ransomware event at dairy subsidiary fairlife that suspended all US production; Canada unaffected.
Deutsche Bank — third-party platform breach, Unsafe extortion claim
Extortion group Unsafe listed Deutsche Bank and leaked alleged employee records; the bank attributes the breach to a German third-party marketing platform, not its network.
US Department of Homeland Security — HSIN information-sharing platform breach
DHS confirmed hackers breached HSIN, its unclassified information-sharing platform and a linked SharePoint system, weeks before disclosure during live World Cup security coordination.
Profiles and interviews with the people behind the keyboard. Some made the news. Some made the millions. Some did the time. Some came back with something to say.
Open the profiles →Aflac Japan — policyholder-portal breach, 4.38M records, SEC 8-K
Aflac Japan disclosed via SEC 8-K that intruders repeatedly accessed its policyholder portal over ten days, exfiltrating personal data on 4.38 million customers and agents.
River Financial Corporation — ransomware attack, Item 1.05 8-K
River Financial, parent of Alabama's River Bank & Trust, filed an Item 1.05 8-K on 25 June confirming ransomware across its servers after a 16 June intrusion.
Klue — OAuth integration compromise feeding Icarus Salesforce data theft
Attackers compromised Klue's integration platform via a legacy credential, harvested customers' OAuth tokens and exfiltrated Salesforce and Gong data from multiple organisations; Icarus claimed responsibility.
Eastman Kodak — ShinyHunters extortion claim, US imaging manufacturer
ShinyHunters listed Kodak on its leak site claiming 2.2 million records; Kodak confirmed an unauthorised third party briefly accessed a limited amount of company data.
Grindr — alleged 15M+ user database listing
Forum seller listed an alleged 15-million-record Grindr database for $400 covering bcrypt hashes, geolocation and HIV-status field; Grindr has not commented.