ADT confirms data breach after ShinyHunters leak threat
2026-04-25T07:23:25Z•96b40fc3dbb4d3f81118d1eb920742f8130c084d9576df4482ebce31a3e5b94d
ASABlackFileCiscoFTDFirepowerFirestarterPack2TheRoot','PackageKit'ShinyHuntersTrigonabitwardenbreeze-cachecheckmarxdata-breachextortionfile-uploadfirewall-backdoorkicslocal-privilege-escalationnpmpersistenceransomwaresupply-chainwordpressxsszimbra
What happened
Multiple active threats and vulnerabilities were reported: ADT confirmed a data breach after extortion threats from ShinyHunters; a persistent custom malware named Firestarter is surviving updates on Cisco ASA/FTD (Firepower/Secure Firewall) appliances; over 10,000 Zimbra Collaboration servers are being actively exploited via an XSS flaw; and a critical unauthenticated file‑upload vulnerability in the Breeze Cache WordPress plugin is under active exploitation. Additional supply‑chain incidents include a malicious npm @bitwarden/cli package and compromised Checkmarx KICS Docker images and IDE/
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- bleepingcomputer
- Record identifier
- 96b40fc3dbb4d3f81118d1eb920742f8130c084d9576df4482ebce31a3e5b94d
- Enrichment time
- 2026-04-25T07:23:25Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.