April 2026
5 pieces, newest first.
- The most important door had no lock
April 28, 2026 · 4 sources
An authentication bypass in cPanel & WHM let unauthenticated attackers into the panel that runs every site on the server. CISA lists it as used in ransomware.
- They paid, and received a receipt for a deletion nobody can check
April 28, 2026 · 3 sources
Breached twice in a fortnight, then paid for shred logs. Deletion is a negative, and negatives cannot be demonstrated.
- Their staff, your access, nobody's joiner-leaver process
April 22, 2026 · 3 sources
Contractor staff hold the client's access while sitting outside its directory. Each party owns half of what revocation needs.
- Two banks, one supplier, and a leak site that gave it away
April 20, 2026 · 3 sources
Two competitors posted the same day with the same data. The shared dependency was revealed by the attackers' schedule.
- The consent granted once, and never looked at again
April 15, 2026 · 3 sources
A month dominated by OAuth abuse. A standing grant is implicit trust with a permanent credential, issued by whoever clicked.