INCIDENT EVIDENCE GRAPH

Security incident evidence

Public security incidents grouped by event, with evidence, corroboration, and conflicting claims.

P0
3 sources

Ostium hacked — $18.00M lost

Ostium, an RWA-focused perpetuals DEX on Arbitrum, suffered an oracle manipulation exploit. The attacker used a compromised oracle signer key to submit fraudulent future-dated price reports, generating artificial trading profits and draini…

P0
1 sources

AFX Bridge hacked — $24.15M lost

The AFX-operated cross-chain/USDC custody bridge on Arbitrum was exploited. The attacker used compromised validator hot keys to meet the quorum and drain approximately $24.15 million USDC. The funds were bridged to Ethereum and swapped for…

P0
2 sources

BonkDAO hacked — $20.00M lost

BonkDAO suffered a governance attack. The attacker spent ~$4M to buy BONK tokens for sufficient voting power and passed a malicious governance proposal (BIP-76) to transfer ~$20M BONK from the treasury to controlled wallets. No smart contr…

P0
1 sources

Wanchain Cardano-BNB Chain Bridge hacked — $10.00M lost

Wanchain’s Cardano-to-BNB Chain cross-chain bridge was exploited. The attacker drained approximately 515 million NIGHT tokens from the Cardano-side lock address. The incident may involve signature validation or replay flaws. Wanchain suspe…

P0
1 sources

Triple-A hacked — $11.80M lost

Singapore-based stablecoin payments firm Triple-A suffered unauthorized access to its hot wallets across multiple chains, with attackers draining approximately $9.7M–$11.8M in company-owned digital assets that were swapped and bridged/cons…

P0
1 sources

CVE-2025-61882: Oracle E-Business Suite Unspecified Vulnerability

Oracle E-Business Suite contains an unspecified vulnerability in the BI Publisher Integration component. The vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Concurrent Processing. Successful…

P0
1 sources

CVE-2023-27351: PaperCut NG/MF Improper Authentication Vulnerability

PaperCut NG/MF contains an improper authentication vulnerability that could allow remote attackers to bypass authentication on affected installations via the SecurityRequestFilter class.;Required action: Apply mitigations per vendor instru…

P0
1 sources

CVE-2024-57728: SimpleHelp Path Traversal Vulnerability

SimpleHelp contains a path traversal vulnerability that allows admin users to upload arbitrary files anywhere on the file system by uploading a crafted zip file (i.e. zip slip). This can be exploited to execute arbitrary code on the host i…

P0
1 sources

CVE-2024-57726: SimpleHelp Missing Authorization Vulnerability

SimpleHelp contains a missing authorization vulnerability that could allow low-privileged technicians to create API keys with excessive permissions. These API keys can be used to escalate privileges to the server admin role.;Required actio…

P0
1 sources

CVE-2026-48027: Nx Console Embedded Malicious Code Vulnerability

Nx Console contains an embedded malicious code vulnerability that allowed a malicious version of Nx Console to be published. The compromised extension fetched an obfuscated payload that could harvested credentials from multiple sources on…

P0
1 sources

CVE-2026-45321: TanStack Unspecified Vulnerability

TanStack contains an unspecified vulnerability that allowed malicious versions of the product to be published to the npm registry to publish credential-stealing malware under a trusted identity.;Required action: Apply mitigations per vendo…

P1
2 sources

Bonzo Lend hacked — $9.05M lost

Bonzo Lend on Hedera was exploited through a third-party oracle (Supra) vulnerability. An attacker submitted a massively manipulated SAUCE price, allowing them to borrow approximately $9.05 million in assets with minimal collateral. The bo…

P1
1 sources

WEMIX hacked — $6.25M lost

The owner privileges of a WEMIX$-related smart contract were compromised, allowing the attacker to illegally mint approximately 5.23 million WEMIX$ stablecoins (worth about $6.25 million), which were swapped into WEMIX and USDC.e before be…

P1
1 sources

Verus Ethereum Bridge hacked — $7.54M lost

The Verus Ethereum Bridge was exploited again. The attacker abused the bridge’s import path to trigger unbacked payouts on the Ethereum side, draining approximately $7.54 million in assets (ETH, tBTC, USDC, etc.) from the bridge reserves.…

P1
2 sources

Summer Finance - Rekt

$6.04 million stolen from Summer Finance's Lazy Summer depositors when a capped-for-removal Ark was still counted in the vault’s value, letting a donated stale asset inflate the share price and drain real liquidity.

P1
2 sources

SecondFi - Rekt

A single missing secret in SecondFi's signing code made every on-chain transaction a private key disclosure. Attackers drained $2.4 million from 374 wallets on Cardano. One line of missing code, nothing more. Just reading what was already…

P1
1 sources

Allbridge Core hacked — $1.65M lost

Cross-chain bridge protocol Allbridge Core was exploited on July 19-20, 2026. The attacker used a ~$1.12M USDC flash loan from Kamino to rapidly swap in the Solana USDC/USDT liquidity pools, manipulating ratios and draining approximately $…

P1
1 sources

Taiko Bridge hacked — $1.70M lost

On June 21-22, 2026, Taiko (an Ethereum L2) suffered a bridge exploit targeting its ERC20 Vault. Attackers exploited a compromise in the chain state verification mechanism by forging SGX proofs to register a malicious prover, bypassing ver…

P1
1 sources

MEV Bot hacked — $7.50M lost

The MEV bot operated by JaredFromSubway.eth was drained of approximately $7.5 million. Attackers deployed fake token wrappers and liquidity pools to trick the bot’s automated MEV execution system into granting token approvals to attacker-c…

P1
1 sources

Secret Network - Rekt

$4.67 million lost from Secret Network’s bridge connection to Axelar Network after a forked Secret-side IBC contract minted unbacked tokens from thin air. 2 missing validation checks let an attacker forge deposits with a fake Cosmos chain.…

P1
1 sources

Polymarket hacked — $3.10M lost

Polymarket suffered a third-party supply chain attack where hackers injected a malicious script into the platform's frontend, draining approximately $3.1 million in PUSD from 11 user wallets. Funds were moved from Polygon to Ethereum. Poly…

P1
1 sources

AFX Trade - Rekt

Five compromised validator signatures cleared the two-thirds threshold guarding a bridge, draining $24.15 million from AFX Trade's USDC custody bridge contract on Arbitrum and moving it out through the same public rails everyone else uses.

P1
1 sources

Aztec Connect - Rekt

$2.28 million drained from Aztec Connect on June 14th, a deprecated ZK-rollup built by Aztec Labs, across two consecutive days. The ZK proof and settlement layer processed different transaction sets, attackers exploited the gap to mint unb…

P1
1 sources

PTC Windchill Vulnerability Exploited in Ransomware Campaign

The critical unsafe deserialization flaw allows attackers to execute arbitrary code remotely, without authentication. The post PTC Windchill Vulnerability Exploited in Ransomware Campaign appeared first on SecurityWeek .

P1
1 sources

Aztec Bridge - Rekt

One deprecated contract, one flawed escape hatch circuit, and a verifier that should have been retired years earlier. Aztec’s legacy rollup contract lost roughly $2.198 million after a ZK proof passed a broken root-binding check.

P1
1 sources

South Korea discloses data breach impacting diplomats worldwide

South Korea disclosed that hackers breached the National Diplomatic Academy's online education system for ten months and stole personal information belonging to current and former employees of the Ministry of Foreign Affairs (MFA), includi…

P1
2 sources

CVE-2026-63030: WordPress Core Interpretation Conflict Vulnerability

WordPress Core contains an interpretation conflict vulnerability that could allow an attacker to perform SQL Injection and achieve Remote Code Execution. This vulnerability can be chained with CVE-2026-60137.;Required action: Apply mitigat…

P1
3 sources

Hugging Face warns an autonomous AI agent hacked its network

The Hugging Face artificial intelligence repository disclosed that attackers gained access to internal datasets and credentials after breaching its production infrastructure using an autonomous AI agent system. [...]

P1
1 sources

MCBS Data Breach Affects 1.2 Million Individuals

The PEAR ransomware group claimed to have stolen 3 TB of information from the medical business management company. The post MCBS Data Breach Affects 1.2 Million Individuals appeared first on SecurityWeek .

P1
1 sources

Hacked Public Wi-Fi Gateways Used to Harvest Corporate Credentials

A threat actor has been using the compromised appliances to target the Microsoft 365 accounts of traveling corporate employees. The post Hacked Public Wi-Fi Gateways Used to Harvest Corporate Credentials appeared first on SecurityWeek .

P1
1 sources

Origin Energy Data Breach Affects 900,000 Australians

The hacker claimed to have stolen the information of 2 million Origin Energy customers after breaching its systems. The post Origin Energy Data Breach Affects 900,000 Australians appeared first on SecurityWeek .

P1
1 sources

Unpatched Fastjson Vulnerability Exploited in Attacks

The critical remote code execution bug can be exploited without authentication, under the library’s stock default configurations. The post Unpatched Fastjson Vulnerability Exploited in Attacks appeared first on SecurityWeek .

P1
1 sources

LABUBU/OLPC hacked — $1.10M lost

The OLPC/LABUBU liquidity pool on PancakeSwap V2 (BNB Chain) was exploited, resulting in approximately $1.1 million in losses. The attacker exploited a logic vulnerability in the OLPC token contract’s _update function. Approximately 46 day…

P1
1 sources

MedusaHVNC Malware Uses Hidden Windows Desktops to Evade Detection

The malware-as-a-service operation launches legitimate browsers on an invisible desktop, giving attackers persistent and covert remote access to compromised Windows systems. The post MedusaHVNC Malware Uses Hidden Windows Desktops to Evade…

P1
1 sources

Russian Global Webmail Espionage

Unit 42 details a Russian cyberespionage campaign targeting Zimbra webmail servers using JavaScript injection to steal credentials. The post Russian Global Webmail Espionage appeared first on Unit 42 .

P1
1 sources

Suno, Paidwork Data Breaches Affect Tens of Millions of Accounts

Hackers leaked names, email addresses, phone numbers, passwords, and financial information stolen from the two platforms. The post Suno, Paidwork Data Breaches Affect Tens of Millions of Accounts appeared first on SecurityWeek .

P1
1 sources

Russian hackers exploit Zimbra zero-click flaw for email theft

CISA is warning that the Russian state-sponsored hacking group Laundry Bear, also known as Void Blizzard, is targeting organizations using Zimbra Collaboration email servers by combining phishing attacks with the exploitation of a now-patc…

P1
2 sources

Ernst & Young Data Breach Affects Personal, Financial Information

Hackers stole names, addresses, Social Security numbers, credit/debit card numbers, and other information from a third-party management platform. The post Ernst & Young Data Breach Affects Personal, Financial Information appeared first on…

P1
1 sources

CVE-2026-48558: SimpleHelp Authentication Bypass Vulnerability

SimpleHelp contains an authentication bypass vulnerability in the OIDC authentication flow. When OIDC authentication is configured, identity tokens submitted during login are accepted without verifying their cryptographic signature. In a v…

P1
1 sources

CVE-2026-48282: Adobe ColdFusion Path Traversal Vulnerability

Adobe ColdFusion contains a path traversal vulnerability that could lead to arbitrary code execution in the context of the current user.;Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CI…

P1
1 sources

CVE-2008-4128: Cisco IOS Cross-Site Request Forgery Vulnerability

Cisco IOS 12.4 contains multiple cross-site forgery vulnerabilities that allows remote attackers to execute arbitrary commands via (1) a certain "show privilege" command to the /level/15/exec/- URI, and (2) a certain "alias exec" command t…

P1
1 sources

CVE-2021-27137: DD-WRT Stack-Based Buffer Overflow Vulnerability

DD-WRT contains a stack-based buffer overflow vulnerability that could allow an unauthenticated attacker to overflow an internal buffer used by UPnP and trigger a code execution vulnerability.;Required action: Apply mitigations in accordan…

P1
1 sources

Zunami Protocol - Case File

Four exploits, $2.97 million gone, and a deployer wallet that shouldn't have known the attacker existed. Three years later, a forensic investigator pulled the thread on Zunami Protocol. Five exchanges, an FBI filing, and wallets still movi…

P1
1 sources

No Manners Here: The Ruthless Rise of The Gentlemen Ransomware

Unit 42 explores The Gentlemen ransomware operations, revealing the affiliate model driving its rapid growth. Learn more here. The post No Manners Here: The Ruthless Rise of The Gentlemen Ransomware appeared first on Unit 42 .