This 24-hour period saw urgent, out-of-band patches from major vendors to combat actively exploited zero-day vulnerabilities. Microsoft issued an emergency fix for a critical Office security bypass (CVE-2026-21509), while Fortinet scrambled to address a critical SSO authentication bypass (CVE-2026-24858), both of which were added to CISA's KEV catalog. In the data breach landscape, the ShinyHunters group claimed a massive breach of Match Group, allegedly compromising 10 million user records from Hinge and OkCupid. Additionally, SolarWinds disclosed five critical RCE and auth bypass flaws in its Web Help Desk, and the Illinois Department of Human Services confirmed a breach affecting 700,000 individuals.
Help others stay informed about cybersecurity threats
Curated and deduplicated every day from dozens of trusted sources — giving you one clean, consolidated view of what matters in cybersecurity.
Related stories are merged into a single evolving article rather than repeated as separate entries — cutting through noise so you only read what's new.
Every entry links to its full enriched article — complete with MITRE ATT&CK mappings, extracted IOCs, and actionable detection and mitigation guidance.