Mount Royal University confirms breach as hackers claim attack

2026-07-09T01:23:31Z7c4d37d1183f64153570894df9c42e5fbc85c513f07a16b3aa40d6daefc12b63
AI-powered-attacksAPTCI/CD-securityCISAChina-linked-actorColdFusionEntra-passkeyGitHub-ActionsLONGLEASHLangflowMicrosoft-365ORB-networkRoundcubeRuckus-routersTenda-backdoorUbiquitiUniFi-OScredential-theftdata-breachmalicious-packagesnpmpypiservice-desk-impersonationsupply-chainvishing

What happened

Batch of security alerts (07 Jul–08 Jul 2026): multiple confirmed data breaches (Mount Royal University, Accenture, KDDI), malicious SDK/packages on npm and PyPI distributing credential-stealer malware targeting payment apps, active exploitation of Roundcube servers by a China-linked cluster to harvest credentials and deploy backdoors, and a hidden backdoor in Tenda router firmware. U.S. CISA ordered emergency patching for actively exploited flaws (Langflow auth-bypass and a max-severity Adobe ColdFusion bug); Ubiquiti published fixes for multiple critical UniFi OS vulnerabilities including a

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
bleepingcomputer
Record identifier
7c4d37d1183f64153570894df9c42e5fbc85c513f07a16b3aa40d6daefc12b63
Enrichment time
2026-07-09T01:23:31Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Mount Royal University confirms breach as hackers claim attack · Baitaphish