A security breach notification process has been initiated by 7-Eleven as a result of a security incident where an outside party was able to gain access to their systems containing franchisers’ information. According to a breach notification filed with the state of Maine, the company discovered that threat actors accessed some of its internal systems on 8 April 2026. The company claims that there were just two cases involving individuals in the state of Maine, indicating that perhaps the effects of this breach were not very widespread. The compromised environment allegedly held documents related to franchising applications that contained personally identifiable information, such as applicants’ names and addresses. Additional data elements that may have been exposed…
Kirsten Doyle
OpenAI has confirmed that two employee devices were compromised in the recent TanStack npm supply chain attack, prompting the company to rotate code-signing certificates and require macOS users to update their applications by 12 June. In a security advisory published this week, the company said it found no evidence that customer data, production systems, or intellectual property were accessed or altered during the incident. The compromise is related to a larger campaign known as “Mini Shai-Hulud,” which is an example of a software supply chain attack targeting commonly used packages from npm and PyPI repositories. The TanStack web application development framework, one of the many frameworks impacted by the attack, was exploited…
Microsoft has disclosed a zero-day vulnerability that affects Exchange Server 2016, 2019, and Subscription Edition. This vulnerability would give bad actors an opportunity to run arbitrary code remotely on the Exchange server. Although Microsoft has not issued any patches for this security vulnerability, they suggested two possible mitigations until a solution becomes available. According to Microsoft, one preferred mitigation strategy is to activate the Exchange Emergency Mitigation (EM) Service, which provides protection for all customers whose EM Service remains enabled by default. The announcement was made at a time when Microsoft was releasing its May 2026 Patch Tuesday updates, which fixed more than 120 vulnerabilities across applications such…
West Pharmaceutical Services has disclosed a ransomware attack that disrupted manufacturing, shipping, and receiving operations across multiple global facilities after bad actors breached the company’s network on 4 May. The pharmaceutical packaging manufacturer said attackers exfiltrated data and encrypted systems, forcing the company to proactively shut down portions of its infrastructure to contain the incident. “We continue to make good progress in the restoration of our systems. Our outside counsel promptly engaged Palo Alto Networks Unit 42 to support the Company’s investigation, containment, and recovery efforts, in coordination with other external experts,” the company added.” It said it has restored its core enterprise systems, and critical processes for shipping, receiving, and manufacturing have restarted at…
A new report from Tenable is warning that organizations are creating what it describes as a growing “AI exposure gap,” as enterprises race to deploy AI tools and cloud-native services faster than security and governance teams can keep up. The “Cloud and AI Security Risk Report 2026” examined telemetry data gathered from public cloud and enterprise ecosystems from April to October 2025, while the AI-related data was taken until December 2025. The findings revealed that many organizations were unknowingly increasing their attack surface via overprivileged AI identities, vulnerable third-party libraries, and cloud credentials. In addition to those findings, 18% of enterprises had identities…
Microsoft is poised to set a new record for yearly patching by having released patches for over 130 vulnerabilities as part of its May Patch Tuesday release, pushing Microsoft’s total number of patched vulnerabilities to over 500 in just five months in 2026. Researchers at Microsoft and other organizations said that AI-enabled vulnerability discovery systems have greatly accelerated and amplified the process of discovering security flaws. There were about 137 to 138 security updates issued by Microsoft addressing 30 critical vulnerabilities, as well as various other vulnerabilities including those that could allow remote code execution and privileges elevation on Azure DevOps, DNS, Netlogon, Office, and Windows networking…
Foxconn has confirmed that several of its North American factories were hit by a cyberattack, after the Nitrogen ransomware group claimed to have stolen 8TB of data comprising more than 11 million files. According to the bad actor, the information supposedly obtained contains private directives, project details, technical drawings, and related project documents that pertain to companies such as Intel, Apple, Google, Dell, and Nvidia. These claims have not been independently verified yet. In a statement shared with media outlets, Foxconn acknowledged the breach and confirmed that attackers had stolen 8TB of data and more than 11 million documents. Some of the company’s factories in North America…
An attack on the popular Instructure Canvas learning management system has caused major disruptions for schools and universities in the US, just as students gear up for finals. This poses a serious threat to the personal data of millions of students and teachers. Multiple institutions reported outages affecting the web-based Canvas platform on Thursday, with users encountering ransom messages posted directly to school Canvas homepages. According to Instructure, Canvas serves more than 30 million active users worldwide. The company’s public status page showed that while most services had been restored by late Thursday, Canvas Beta and Canvas Test remained in maintenance mode. The…
Fashion retailer Inditex, the parent company of Zara, has confirmed unauthorized access to customer transaction databases hosted by a third-party provider. Data breach notification service Have I Been Pwned said approximately 197,400 unique email addresses were included in the leaked dataset. The company said it had launched security protocols and notified the relevant authorities following the incident, Reuters reports. It was reported that the data leak included customers’ email addresses, purchase history, order IDs, product information, and support ticket information. Inditex confirmed that passwords, payment card information, and physical addresses were not breached, and their internal operations and systems remained untouched. BleepingComputer reports linked…
A new report published by Internet Matters, reveals that the Online Safety Act (OSA) in the UK, although bringing visibility of online safety tools, does not seem to be living up to expectations of providing the much-needed “meaningful protection from harm.” In their report titled The Online Safety Act: Are Children Safer Online?, Internet Matters has highlighted a dual image of success and continued vulnerability. Age verification checks, reporting tools, warnings, and parental controls are being observed on social networking sites, games, and other online platforms. Approximately 68% of parents and children claim to have witnessed these changes Families embraced many of these changes. Kids especially appreciated…
