Denmark CPR Data Breach: 8.8 Million Records

Denmark CPR data breach: 8.8 million records pulled through one company's lawful registry access. An oversized invoice exposed it after ten days.

The Denmark CPR data breach exposed the names, addresses and personal ID numbers of about 8.8 million people, roughly four in five records in the country’s Central Person Register. Unauthorized parties reached it through a smaller company’s lawful lookup access, ran more than 14 million queries over about ten days in September, and were noticed…

Read More

Atlassian File Access Vulnerability in Data Center

Atlassian Data Center file access vulnerability CVE-2026-21589 (CVSS 9.3) hits eight products with no login. No exploitation reported yet. Patch now.

The Atlassian file access vulnerability CVE-2026-21589 (CVSS 9.3) lets an unauthenticated attacker read files from the web root of eight self-hosted products: Jira Software, Jira Service Management, Confluence, Bitbucket, Bamboo, Crowd, Crucible and Fisheye. Every version is affected until it is upgraded. No exploitation has been reported so far, and the patched releases are out.…

Read More

Warlock Ransomware SharePoint Attacks

Warlock ransomware SharePoint attacks hit a water utility and a telecom provider. Symantec saw an EDR killer on 40 hosts in two hours. Patch and hunt.

Warlock ransomware SharePoint attacks have reached a water utility, a telecom provider, a regional government body and a university, according to Symantec and Carbon Black. The China-linked group still gets in through on-premises SharePoint, switches off endpoint protection on dozens of machines within about two hours, and then launches ransomware from a share that every…

Read More

Zammad Zero-Day Vulnerabilities Exploited

Two Zammad zero-day vulnerabilities give attackers root on helpdesk servers. Used against DIVD, on CISA KEV, one flaw had no fix at disclosure.

Two Zammad zero-day vulnerabilities, CVE-2026-102489 and CVE-2026-102490, let an attacker take over the open-source helpdesk and reach root on its server. The Dutch Institute for Vulnerability Disclosure (DIVD) says an automated AI agent chained them against its own network on September 21. CISA has added the first flaw to its Known Exploited Vulnerabilities catalog, and…

Read More

FortiMail Zero-Day Vulnerability Exploited in the Wild

A FortiMail zero-day vulnerability lets attackers write files with no login. Exploited now; fixes for 7.4, 7.6 and 8.0 were pending at disclosure.

A FortiMail zero-day vulnerability, CVE-2026-104286 (CVSS 9.8), lets an unauthenticated attacker write arbitrary files onto Fortinet’s email security appliance with nothing more than crafted web requests. Fortinet confirmed active exploitation on October 1, CISA added the flaw to its Known Exploited Vulnerabilities catalog the same day, and fixed releases for the 7.4, 7.6 and 8.0…

Read More