LIVE · cybersecurity feed
Live wire
CVE-2026-20245high

Texas Parks and Wildlife, WordPress Plugin Vendor Hit by Data Breaches

Several organizations experienced significant security incidents this week. The Texas Parks and Wildlife Department suffered a data breach affecting over 3 million customers due to a vendor compromise, exposing personal information but not financial or social security data. Additionally, a supply chain attack on WordPress plugin vendor ShapedPlugin delivered malicious updates, leading to credential theft and website modifications. AI-powered threats are also on the rise, with a new phishing service called EvilTokens exploiting device-code authentication to steal Microsoft 365 tokens.

zeroday.news · 31d ago

The Texas Parks and Wildlife Department has confirmed a data breach affecting its hunting and fishing license system vendor, exposing personal information for over 3 million customers. Separately, ShapedPlugin, a vendor of WordPress plugins, suffered a supply chain attack that delivered malicious updates to its paid plugins.

The incident impacting the Texas Parks and Wildlife Department involved a third-party vendor and resulted in the exposure of driver’s license information, passport numbers, email addresses, phone numbers, and residential addresses for 3,087,721 hunting and fishing license customers. The department confirmed that Social Security numbers and payment data were not compromised in the breach.

In the ShapedPlugin incident, a supply chain attack leveraged the vendor's official updater to distribute malicious updates for three of its paid WordPress plugins. The malware installed a hidden, fake WooCommerce plugin designed to steal administrative, database, and two-factor authentication credentials. It also modified affected websites. Analysis of the incident indicated that the compromise originated within the vendor's release infrastructure.

In other cybersecurity news, iRhythm Technologies, a US digital health company, confirmed a cyberattack on its third-party-hosted business applications. The company stated that protected health information, proprietary data, and other personal data were stolen via a social engineering attack, though clinical systems remained unaffected.

Market intelligence platform Klue also confirmed a breach. Attackers utilized compromised legacy integration credentials to steal OAuth tokens linked to customer Salesforce environments. These tokens were then used to exfiltrate sales and customer data from several clients, including Huntress, Recorded Future, Tanium, and Jamf. The Icarus extortion group has claimed responsibility for this attack.

data breachsupply chain attackphishingaicredential theft
ShareXLinkedInWhatsAppFacebook

More News

view all →
vulnerabilitycritical

Rails patches critical Active Storage flaw with RCE potential

A critical vulnerability in the Active Storage framework can allow an unauthenticated attacker to read arbitrary files from a Rails application, and potentially escalate to remote code execution (RCE). [...]

malware

Russian Hackers Hijack Hotel Wi-Fi to Steal Microsoft 365 Tokens

Microsoft says Russian hackers hijacked hotel Wi-Fi portals to spread malware and steal Microsoft 365 tokens from travelers. Microsoft Threat Intelligence disclosed CaptiveCrunch, a campaign it attributes to Storm-2945, an operational sub-cluster of Midnight Blizzard, the Russian SVR-linked group also known as APT29 and Cozy Bear. Since early May 2026, Storm-2945 has been manipulating DNS […]

CVE-2026-48449critical

Adobe fixed a maximum-severity vulnerability flaw in Campaign Classic

Adobe fixed a maximum severity vulnerability in Campaign Classic that could let attackers run code remotely without user interaction. Adobe has addressed a critical vulnerability, tracked as CVE-2026-48449 (CVSS score of 10.0), in Adobe Campaign Classic, the company’s enterprise marketing automation platform. The flaw is caused by incorrect authorization and could allow attackers to execute […]

security

Balance Theory Raises $19 Million to Help Enterprises Manage Cybersecurity Investments

The funding round was led by SYN Ventures, with participation from existing investors DataTribe and TEDCO. The post Balance Theory Raises $19 Million to Help Enterprises Manage Cybersecurity Investments appeared first on SecurityWeek.

vulnerabilitycritical

Ruby on Rails Patches Critical Vulnerability

The flaw can be exploited by unauthenticated attackers to read arbitrary files and potentially achieve remote code execution (RCE). The post Ruby on Rails Patches Critical Vulnerability appeared first on SecurityWeek.

ai

7 States’ Water Systems Hit by Cyberattacks Likely Tied to Iran

Plus: The FBI eyes AI-powered tech to detect future crimes, Russia charges Telegram’s founder, xAI sues to stop a state’s “nudification” ban, and the Democrats learn a lesson about getting scammed.