Braintrust
May 4, 2026
•[ unauthorized access, API keys, cloud security ]
Braintrust confirmed unauthorized access to an internal AWS account on May 4, 2026 that likely exposed customer org-level AI-provider API keys used to access cloud-based AI models. Braintrust locked down the compromised account, audited and restricted related systems, rotated internal secrets, and instructed customers to rotate affected keys.
Oriental Diamond Co., Ltd.
May 4, 2026
•[ ransomware, cyberattack, data leak ]
Oriental Diamond Co., Ltd. confirmed that on May 4, 2026 a third party used ransomware in a cyberattack against a company-managed server, encrypting system data and causing business stoppage. The company reported possible leakage of names, addresses, and phone numbers, said bank account, credit card, and My Number information were not included, and stated that it would stop using the VPN path identified as the intrusion route. Public Japanese security reporting linked the confirmed incident to a The Gentlemen leak-site claim.
Cushman & Wakefield
May 3, 2026
•[ vishing, PII, data leak ]
Cushman & Wakefield confirmed a vishing-related security breach in May 2026 after ShinyHunters and Qilin separately listed the company. ShinyHunters claimed theft of more than 500,000 Salesforce records containing PII and internal corporate data and later reportedly published a 50GB Salesforce-linked dataset after negotiations failed. DataBreach indexed 2,198,033 rows associated with the breach. Public sources did not confirm encryption or operational disruption.
Red Radimagen
May 3, 2026
•[ data leak, health-sector, medical records ]
Red Radimagen was listed among the Panamanian health-sector entities directly affected by data exposure in a Vecert Analyzer intelligence report cited by La Estrella de Panam. The incident was dated May 3, 2026. Outside OSINT reporting attributed the Radimagen leak to ohmydays, linked the actor to Waxx Org., and referenced exposed medical or patient-related records from an unsecured server, but public reporting did not confirm encryption, data destruction, or operational disruption.
4VPS
May 2, 2026
•[ ransomware, infrastructure compromise, billing systems ]
4VPS disclosed on May 2, 2026 that an attack affected its website and billing systems. DataBreaches.net reported that The Gentlemen ransomware group later acknowledged that part of its own backend infrastructure had been compromised because some of it was hosted with 4VPS. Public reporting did not identify the attacker, the exact intrusion method, the total data volume, or the duration of service disruption.
Standard-Examiner
May 2, 2026
•[ ransomware, data leak, cyberattack ]
Qilin listed Standard-Examiner on its leak site on May 2, 2026 and claimed responsibility for a cyberattack, threatening to release sensitive data. Separate reporting noted earlier April production difficulties at the newspaper, but the Standard-Examiner had not publicly confirmed ransomware, data theft, or a connection between the printing disruption and Qilin's claim.
Government of Guam
May 2, 2026
•[ zero-day vulnerability, cyber incident response, website disruption ]
The Government of Guam activated its cyber incident response on May 2, 2026 after hackers exploited a critical zero-day vulnerability affecting globally used cPanel-hosted websites. Multiple GovGuam websites were disrupted, prompting a government-wide assessment and response. Officials said emergency services remained unaffected; public reporting did not identify the actor, confirm data theft, or quantify the disruption duration.
MiniMed Panamá
May 2, 2026
•[ data exposure, PII, plaintext credentials ]
MiniMed Panam was listed among the Panamanian health-sector platforms directly affected by data exposure in a Vecert Analyzer intelligence report cited by La Estrella de Panam. The incident was dated May 2, 2026, and outside OSINT reporting described roughly 400,000 exposed records associated with MiniMed, including a usersdata table with 74,233 records containing PII and plaintext credentials. Public reporting did not identify the threat actor, encryption, data destruction, or operational disruption.
Clínica Hospital Panamericano
May 2, 2026
•[ data leak, healthcare, patient database exposure ]
Ch-panamericana.com was listed among the Panamanian incidents in a Vecert Analyzer intelligence report cited by La Estrella de Panam. The domain appears to correspond to Clnica Hospital Panamericano, a healthcare provider in Panam Oeste, and outside monitoring referenced alleged patient database exposure from ch-panamericano.com. The incident was dated May 2, 2026. Outside OSINT reporting linked the leak to ohmydays and Waxx Org., but public reporting did not confirm encryption, data destruction, or operational disruption.
webhostingnz.com
May 1, 2026
•[ API token compromise, authentication bypass, unauthorized access ]
A fullaccess API token was added to a cPanel account for webhostingnz.com server rosie.whsl206.com, giving an attacker control of the account for several hours. The client area and server login were unavailable for ~6hours, and the provider did not shut down the server. The incident is linked to the cPanel authentication bypass vulnerability (CVE202641940).
Reborn Gaming
April 30, 2026
•[ data breach, gaming, vulnerability ]
In April 2026, the gaming community Reborn Gaming suffered a data breach due to a vulnerability in cPanel and WebHost Manager (WHM). The breach exposed 126 unique email addresses along with IP addresses and Steam IDs. Reborn Gaming self-submitted the data to Have I Been Pwned.
Canonical
April 30, 2026
•[ DDoS, hacktivism, service outage ]
A hacktivist group claimed responsibility for a distributed denialofservice attack that flooded Canonicals publicfacing infrastructure on 1May2026, causing Ubuntu website, package repositories and security API to become unavailable for over 24hours.
Kentwood Public Schools
April 30, 2026
•[ malware, insider threat, network disruption ]
A student deployed malicious software that interfered with Kentwood Public Schools network, causing districtwide WiFi connectivity loss, which was later isolated and restored with help from external experts.
Advanced Diagnostic Imaging
April 30, 2026
•[ ransomware, electronic medical records, healthcare ]
Columbia Surgical Partners said it was unable to access electronic medical records after its parent company, Advanced Diagnostic Imaging, was hit by a reported ransomware attack. Available reporting confirms EHR-access disruption at Columbia Surgical Partners, but does not publicly confirm a responsible ransomware group, data theft, ransom demand, restoration timeline, or whether other ADI systems or sites were affected.
At least one Claude Code user
April 30, 2026
•[ malware, fake installer, credential harvesting ]
A fake Claude Code installer campaign likely affected many users searching for Anthropic's Claude Code tool, though public reporting did not identify specific victims or quantify the total number infected. The campaign delivered a PowerShell payload that extracted decrypted cookies, saved passwords, and payment data from Chromium-based browsers on infected machines. Public reporting did not identify the specific actor, country, volume of stolen data, or any operational disruption.
Undisclosed Pakistani government entity
April 30, 2026
•[ cyber espionage, Shadow-Earth-053, Microsoft Exchange ]
Shadow-Earth-053, a China-aligned espionage cluster, was reported to have compromised an undisclosed Pakistani government environment by exploiting unpatched Microsoft Exchange and IIS servers, deploying web shells and ShadowPad, collecting credentials, and exporting mailbox contents.
Undisclosed Thai government entity
April 30, 2026
•[ espionage, vulnerability exploitation, web shells ]
Shadow-Earth-053, a China-aligned espionage cluster, was reported to have compromised an undisclosed Thai government environment by exploiting unpatched Microsoft Exchange and IIS servers, deploying web shells and ShadowPad, collecting credentials, and exporting mailbox contents.
Undisclosed Indian government entity
April 30, 2026
•[ espionage, web shell, ShadowPad ]
Shadow-Earth-053, a China-aligned espionage cluster, was reported to have compromised an undisclosed Indian government environment by exploiting unpatched Microsoft Exchange and IIS servers, deploying web shells and ShadowPad, collecting credentials, and exporting mailbox contents.
Undisclosed Myanmar government entity
April 30, 2026
•[ cyber espionage, vulnerability exploitation, web shells ]
Shadow-Earth-053, a China-aligned espionage cluster, was reported to have compromised an undisclosed Myanmar government environment by exploiting unpatched Microsoft Exchange and IIS servers, deploying web shells and ShadowPad, collecting credentials, and exporting mailbox contents.
Undisclosed Malaysian government entity
April 30, 2026
•[ espionage, vulnerability exploitation, unpatched software ]
Shadow-Earth-053, a China-aligned espionage cluster, was reported to have compromised an undisclosed Malaysian government environment by exploiting unpatched Microsoft Exchange and IIS servers, deploying web shells and ShadowPad, collecting credentials, and exporting mailbox contents.