ADT confirms data breach after ShinyHunters leak threat

2026-04-25T07:23:25Z96b40fc3dbb4d3f81118d1eb920742f8130c084d9576df4482ebce31a3e5b94d
ASABlackFileCiscoFTDFirepowerFirestarterPack2TheRoot','PackageKit'ShinyHuntersTrigonabitwardenbreeze-cachecheckmarxdata-breachextortionfile-uploadfirewall-backdoorkicslocal-privilege-escalationnpmpersistenceransomwaresupply-chainwordpressxsszimbra

What happened

Multiple active threats and vulnerabilities were reported: ADT confirmed a data breach after extortion threats from ShinyHunters; a persistent custom malware named Firestarter is surviving updates on Cisco ASA/FTD (Firepower/Secure Firewall) appliances; over 10,000 Zimbra Collaboration servers are being actively exploited via an XSS flaw; and a critical unauthenticated file‑upload vulnerability in the Breeze Cache WordPress plugin is under active exploitation. Additional supply‑chain incidents include a malicious npm @bitwarden/cli package and compromised Checkmarx KICS Docker images and IDE/​

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
bleepingcomputer
Record identifier
96b40fc3dbb4d3f81118d1eb920742f8130c084d9576df4482ebce31a3e5b94d
Enrichment time
2026-04-25T07:23:25Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.