The Texas Parks and Wildlife Department has confirmed a data breach affecting its hunting and fishing license system vendor, exposing personal information for over 3 million customers. Separately, ShapedPlugin, a vendor of WordPress plugins, suffered a supply chain attack that delivered malicious updates to its paid plugins.
The incident impacting the Texas Parks and Wildlife Department involved a third-party vendor and resulted in the exposure of driver’s license information, passport numbers, email addresses, phone numbers, and residential addresses for 3,087,721 hunting and fishing license customers. The department confirmed that Social Security numbers and payment data were not compromised in the breach.
In the ShapedPlugin incident, a supply chain attack leveraged the vendor's official updater to distribute malicious updates for three of its paid WordPress plugins. The malware installed a hidden, fake WooCommerce plugin designed to steal administrative, database, and two-factor authentication credentials. It also modified affected websites. Analysis of the incident indicated that the compromise originated within the vendor's release infrastructure.
In other cybersecurity news, iRhythm Technologies, a US digital health company, confirmed a cyberattack on its third-party-hosted business applications. The company stated that protected health information, proprietary data, and other personal data were stolen via a social engineering attack, though clinical systems remained unaffected.
Market intelligence platform Klue also confirmed a breach. Attackers utilized compromised legacy integration credentials to steal OAuth tokens linked to customer Salesforce environments. These tokens were then used to exfiltrate sales and customer data from several clients, including Huntress, Recorded Future, Tanium, and Jamf. The Icarus extortion group has claimed responsibility for this attack.






