BREAKING Singapore Cyber Security Agency confirms UNC3886 breach across all four major telcos RANSOMWARE Jaguar Land Rover production paused for sixth consecutive month — UK auto sector impact estimated at £1.9B SUPPLY CHAIN SalesLoft Drift OAuth abuse confirmed at TransUnion, Workday, Qantas, Chanel and Farmers BREACH Coupang reports 33.7M South Korean customer accounts exposed; former employee identified as suspect VULNERABILITY SharePoint ToolShell zero-days CVE-2025-53770/53771 still being exploited months after patch CRYPTO Bybit's $1.46B Ethereum heist marked one year — Lazarus laundering trail finally going cold BREAKING Singapore Cyber Security Agency confirms UNC3886 breach across all four major telcos RANSOMWARE Jaguar Land Rover production paused for sixth consecutive month — UK auto sector impact estimated at £1.9B SUPPLY CHAIN SalesLoft Drift OAuth abuse confirmed at TransUnion, Workday, Qantas, Chanel and Farmers BREACH Coupang reports 33.7M South Korean customer accounts exposed; former employee identified as suspect VULNERABILITY SharePoint ToolShell zero-days CVE-2025-53770/53771 still being exploited months after patch CRYPTO Bybit's $1.46B Ethereum heist marked one year — Lazarus laundering trail finally going cold
Live // Tracking 135 catalogued incidents worldwide Inside the mind
atthacked
// reading: attacked // reading: hacked

Learn from every major cyber attack. Breaches, ransomware, nation-state operations — catalogued the day they break, decoded so you understand the incident, the technique, and the adversary behind it.

// Independent. No vendor sponsorship. No paywall.
135
Incidents catalogued // 2007–26
$1.46B
Largest single theft tracked
16B
Credentials in tracked exposures
11mo
Longest counter-intrusion logged
01 //

Top stories

02 //

Inside the mind of a hacker

Profiles and interviews with the people behind the keyboard. Some made the news. Some made the millions. Some did the time. Some came back with something to say.

Open the profiles →
03 //

More from the desk

Re-sign

OpenAI — two employee devices compromised in TanStack npm supply-chain attack

Two OpenAI staff devices compromised by poisoned @tanstack npm packages; limited credentials exfiltrated and OpenAI is re-signing all desktop and mobile applications.

KEV

Palo Alto Networks PAN-OS GlobalProtect — CVE-2026-0257

Authentication-override flaw in PAN-OS GlobalProtect lets unauthenticated attackers forge cookies and establish VPN tunnels; CISA added it to KEV with a 1 June deadline.

744

DentaQuest — ShinyHunters leak-site listing, US dental insurer

ShinyHunters listed US dental-insurance provider DentaQuest on its leak site, claiming 744 user records and threatening publication after the extortion deadline lapsed.

AKIRA

GS Yuasa Lithium Power — Akira leak-site listing, US aerospace battery supplier

Akira listed US aerospace battery supplier GS Yuasa Lithium Power on its leak site, naming Boeing satellite project data among the allegedly stolen material.

185K

7-Eleven — misconfigured Salesforce Experience Cloud, ShinyHunters dump

ShinyHunters dumped a 9.4 GB archive of 7-Eleven franchise applicant data after exploiting a misconfigured Salesforce Experience Cloud instance with the AuraInspector audit tool.

04 //

Go deeper