Incident  2026()  2025()  2024()  2020  2019  2018  2017  2016  2015  2014  2013  2012  2011  2010  2009  2008  2007  2006  2005  2004 |  Group  Incident Response 

DATE

NAME

INFO

CATEGORY

SUBCATE

29.9.26

Bitget Security Incident Bitget Security Incident Explained: Timeline, Impact and Security Response INCIDENT INCIDENT

23.9.26

Berlin Data Leak In August 2026, the Rhysida extortion group breached Berlin’s state network and copied roughly 1.44 million files from two of the city-state’s Senate administrations. Berlin disconnected the affected departments on August 14, refused a ransom demand of 30 BTC, and on September 4 the group released the archive to public access on its Dark Web leak site. INCIDENT INCIDENT

21.9.26

KelpDAO Incident  PDF Tl;dr On April 18, 2026, KelpDAO was exploited for approximately $290M. Preliminary indicators suggest attribution to a highly-sophisticated state actor, likely DPRK’s Lazarus Group, more specifically TraderTraitor. This incident was isolated to KelpDAO’s rsETH configuration as a direct consequence of their single-DVN setup. There is zero contagion to any other cross-chain assets or applications. INCIDENT INCIDENT

12.9.26

DoppelCart DoppelCart: 119,000 Domains in What May Be the Largest Documented Fake-Shop Network INCIDENT INCIDENT

2.9.26

Virtualizor INCIDENT BGP Hijack Delivers Malicious Virtualizor Update That Establishes Persistent Root Access INCIDENT INCIDENT
26.8.26 Anatomy of a Frontier Lab Agent Intrusion: A Technical Timeline of the July 2026 Incident A companion technical writeup to our incident disclosure. This post walks through how the intrusion actually worked: the two initial-access vectors, how the agent pivoted and moved laterally, representative examples of the commands that were run and how we investigated with GLM 5.2 (an open-source model). Live credentials, internal hostnames, and specific indicators have been redacted or genericized, while the techniques are described exactly as observed by Hugging Face. INCIDENT INCIDENT

20.8.26

Zero-click Grok data theft Zero-click Grok data theft: Cryptographic Context Injection attack leaks chat histories INCIDENT INCIDENT

29.7.26

Anatomy of a Frontier Lab Agent Intrusion: A Technical Timeline of the July 2026 Incident A companion technical writeup to our incident disclosure. This post walks through how the intrusion actually worked: the two initial-access vectors, how the agent pivoted and moved laterally, representative examples of the commands that were run and how we investigated with GLM 5.2 (an open-source model). Live credentials, internal hostnames, and specific indicators have been redacted or genericized, while the techniques are described exactly as observed by Hugging Face. INCIDENT AI
12.7.26 Official jscrambler npm Package Compromised Official jscrambler npm Package Compromised Across Multiple Releases INCIDENT INCIDENT
29.6.26 Klue Supply Chain Incident & LastPass Response We want to inform our customers of a security incident which recently occurred at one of our third-party suppliers and how that incident impacts LastPass and our customers. INCIDENT INCIDENT
7.6.26 VerdantBamboo VerdantBamboo: Just Another BRICKSTORM in the Firewall INCIDENT INCIDENT
23.5.26 Laravel Lang Compromised Laravel Lang Compromised with RCE Backdoor Across 700+ Versions INCIDENT INCIDENT
6.5.26 DAEMON Tools software infected DAEMON Tools software infected – supply chain attack ongoing since April 8, 2026 INCIDENT INCIDENT
5.5.26 ScarCruft compromises A rigged game: ScarCruft compromises gaming platform in a supply-chain attack INCIDENT APT
30.4.26 Shai-Hulud Hits SAP Shai-Hulud Hits SAP: Stolen Credentials Found in 1,200 GitHub Repos INCIDENT INCIDENT
23.4.26 Bitwarden CLI 2026.4.0 Bitwarden CLI Compromised in Ongoing Checkmarx Supply Chain Campaign INCIDENT INCIDENT
13.4.26 CPU-Z / HWMonitor watering hole infection – a copy-pasted attack On April 9, 2026, the website cpuid[.]com, hosting installers for popular system administration software CPU-Z, HWMonitor (HWMonitor Pro) and Perfmonitor 2, was compromised. INCIDENT INCIDENT
8.4.26 SOHO router compromise SOHO router compromise leads to DNS hijacking and adversary-in-the-middle attacks INCIDENT INCIDENT
31.3.26 axios Compromised axios Compromised: npm Supply Chain Attack via Dependency Injection INCIDENT INCIDENT
2.2.26 Critical eScan Supply Chain Compromise On January 20, 2026, Morphisec identified an active supply chain compromise affecting MicroWorld Technologies’ eScan antivirus product. INCIDENT INCIDENT