PrivacySignal
Breach

BdThemes plugins supply-chain hack creates rogue WordPress admins

BleepingComputer · · International · Data Breaches

A threat actor compromised the upstream infrastructure of BdThemes, a developer of premium WordPress web-design tools, and modified a remote JSON feed delivered to administrators' browsers to create rogue admin accounts. [...]

Who should care: Cybersecurity · Privacy officers · Administrators

This summary is AI-assisted and may contain errors. It is an original briefing to help you gauge significance quickly — not a reproduction of the source. Always read the linked original before relying on it. See our methodology.

Analysis

All analysis →

Weekly Editorial Analysis from Experts and Editors

Related stories

Breach
DataBreaches.net · · International

CISA Advisory: #StopRansomware: Gunra Ransomware

Gunra is a ransomware-as-a-service (RaaS) used by affiliates to target government, critical infrastructure, and other organizations. The Gunra ransomware variant first appeared in 2025 and expanded to RaaS operations in 2026. The actors leverage a double-extortion model, both encrypting data and threatening to publish exfiltrated data to a dedicated leak site (DLS) if the ransom... Source

Who should care: Cybersecurity · Privacy officers · Administrators

#breach#security Read original →
Breach
BleepingComputer · · International

New StormEncryptor ransomware used by former Medusa affiliate

A financially motivated threat actor previously associated with the Medusa ransomware operation is now deploying a new ransomware strain called StormEncryptor. [...]

Who should care: Cybersecurity · Privacy officers · Administrators

#breach#security Read original →
Breach
HIPAA Journal · · US Federal

California Child Care Company Discovers 9-Year Employee Data Leak

Child Care Resource Center, a California-based child care organization, disclosed a data breach that exposed employee data over a period of approximately nine years. The breach was attributed to internal employee practices rather than an outside attack.

Who should care: Cybersecurity · Privacy officers · Administrators · Healthcare professionals · Compliance

#breach#healthcare Read original →
Breach
Nextgov/FCW · · US Federal

Federal systems increasingly likely to face accidental AI breach after Hugging Face, experts say

Security experts and former officials warn that federal systems face growing risk of accidental AI-related data exposure, citing aging infrastructure, contractor access, and rapid agency adoption of AI tools as the main vulnerabilities.

Who should care: Cybersecurity · Privacy officers · Administrators · General readers · AI governance · Policy

#breach#ai Read original →