Incident 2026() 2025() 2024() 2020 2019 2018 2017 2016 2015 2014 2013 2012 2011 2010 2009 2008 2007 2006 2005 2004 | Group Incident Response
DATE |
NAME |
INFO |
CATEGORY |
SUBCATE |
|
29.9.26 |
Bitget Security Incident | Bitget Security Incident Explained: Timeline, Impact and Security Response | INCIDENT | INCIDENT |
|
23.9.26 |
Berlin Data Leak | In August 2026, the Rhysida extortion group breached Berlin’s state network and copied roughly 1.44 million files from two of the city-state’s Senate administrations. Berlin disconnected the affected departments on August 14, refused a ransom demand of 30 BTC, and on September 4 the group released the archive to public access on its Dark Web leak site. | INCIDENT | INCIDENT |
|
21.9.26 |
KelpDAO Incident PDF | Tl;dr On April 18, 2026, KelpDAO was exploited for approximately $290M. Preliminary indicators suggest attribution to a highly-sophisticated state actor, likely DPRK’s Lazarus Group, more specifically TraderTraitor. This incident was isolated to KelpDAO’s rsETH configuration as a direct consequence of their single-DVN setup. There is zero contagion to any other cross-chain assets or applications. | INCIDENT | INCIDENT |
|
12.9.26 |
DoppelCart | DoppelCart: 119,000 Domains in What May Be the Largest Documented Fake-Shop Network | INCIDENT | INCIDENT |
|
2.9.26 |
Virtualizor INCIDENT | BGP Hijack Delivers Malicious Virtualizor Update That Establishes Persistent Root Access | INCIDENT | INCIDENT |
| 26.8.26 | Anatomy of a Frontier Lab Agent Intrusion: A Technical Timeline of the July 2026 Incident | A companion technical writeup to our incident disclosure. This post walks through how the intrusion actually worked: the two initial-access vectors, how the agent pivoted and moved laterally, representative examples of the commands that were run and how we investigated with GLM 5.2 (an open-source model). Live credentials, internal hostnames, and specific indicators have been redacted or genericized, while the techniques are described exactly as observed by Hugging Face. | INCIDENT | INCIDENT |
|
20.8.26 |
Zero-click Grok data theft | Zero-click Grok data theft: Cryptographic Context Injection attack leaks chat histories | INCIDENT | INCIDENT |
|
29.7.26 |
Anatomy of a Frontier Lab Agent Intrusion: A Technical Timeline of the July 2026 Incident | A companion technical writeup to our incident disclosure. This post walks through how the intrusion actually worked: the two initial-access vectors, how the agent pivoted and moved laterally, representative examples of the commands that were run and how we investigated with GLM 5.2 (an open-source model). Live credentials, internal hostnames, and specific indicators have been redacted or genericized, while the techniques are described exactly as observed by Hugging Face. | INCIDENT | AI |
| 12.7.26 | Official jscrambler npm Package Compromised | Official jscrambler npm Package Compromised Across Multiple Releases | INCIDENT | INCIDENT |
| 29.6.26 | Klue Supply Chain Incident & LastPass Response | We want to inform our customers of a security incident which recently occurred at one of our third-party suppliers and how that incident impacts LastPass and our customers. | INCIDENT | INCIDENT |
| 7.6.26 | VerdantBamboo | VerdantBamboo: Just Another BRICKSTORM in the Firewall | INCIDENT | INCIDENT |
| 23.5.26 | Laravel Lang Compromised | Laravel Lang Compromised with RCE Backdoor Across 700+ Versions | INCIDENT | INCIDENT |
| 6.5.26 | DAEMON Tools software infected | DAEMON Tools software infected – supply chain attack ongoing since April 8, 2026 | INCIDENT | INCIDENT |
| 5.5.26 | ScarCruft compromises | A rigged game: ScarCruft compromises gaming platform in a supply-chain attack | INCIDENT | APT |
| 30.4.26 | Shai-Hulud Hits SAP | Shai-Hulud Hits SAP: Stolen Credentials Found in 1,200 GitHub Repos | INCIDENT | INCIDENT |
| 23.4.26 | Bitwarden CLI 2026.4.0 | Bitwarden CLI Compromised in Ongoing Checkmarx Supply Chain Campaign | INCIDENT | INCIDENT |
| 13.4.26 | CPU-Z / HWMonitor watering hole infection – a copy-pasted attack | On April 9, 2026, the website cpuid[.]com, hosting installers for popular system administration software CPU-Z, HWMonitor (HWMonitor Pro) and Perfmonitor 2, was compromised. | INCIDENT | INCIDENT |
| 8.4.26 | SOHO router compromise | SOHO router compromise leads to DNS hijacking and adversary-in-the-middle attacks | INCIDENT | INCIDENT |
| 31.3.26 | axios Compromised | axios Compromised: npm Supply Chain Attack via Dependency Injection | INCIDENT | INCIDENT |
| 2.2.26 | Critical eScan Supply Chain Compromise | On January 20, 2026, Morphisec identified an active supply chain compromise affecting MicroWorld Technologies’ eScan antivirus product. | INCIDENT | INCIDENT |