Mount Royal University confirms breach as hackers claim attack
2026-07-09T01:23:31Z•7c4d37d1183f64153570894df9c42e5fbc85c513f07a16b3aa40d6daefc12b63
AI-powered-attacksAPTCI/CD-securityCISAChina-linked-actorColdFusionEntra-passkeyGitHub-ActionsLONGLEASHLangflowMicrosoft-365ORB-networkRoundcubeRuckus-routersTenda-backdoorUbiquitiUniFi-OScredential-theftdata-breachmalicious-packagesnpmpypiservice-desk-impersonationsupply-chainvishing
What happened
Batch of security alerts (07 Jul–08 Jul 2026): multiple confirmed data breaches (Mount Royal University, Accenture, KDDI), malicious SDK/packages on npm and PyPI distributing credential-stealer malware targeting payment apps, active exploitation of Roundcube servers by a China-linked cluster to harvest credentials and deploy backdoors, and a hidden backdoor in Tenda router firmware. U.S. CISA ordered emergency patching for actively exploited flaws (Langflow auth-bypass and a max-severity Adobe ColdFusion bug); Ubiquiti published fixes for multiple critical UniFi OS vulnerabilities including a
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- bleepingcomputer
- Record identifier
- 7c4d37d1183f64153570894df9c42e5fbc85c513f07a16b3aa40d6daefc12b63
- Enrichment time
- 2026-07-09T01:23:31Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.