ADT confirms data breach after ShinyHunters leak threat

2026-04-25T01:23:31Zcfc8f30051a7adec565752010d1a1269dd2ca7ac1cf3404f351c1217d148cb7d
ASABitwarden CLIBreeze CacheCheckmarx KICSCisco FirepowerFTDFirestarterPack2TheRootPackageKitShinyHuntersTrigonaWordPressXSSZimbraarbitrary-file-uploadcredential-theftdata-breachexfiltration-toolextortionfirewall persistencelocal-privilege-escalationmalwarenpm compromiseransomwaresupply-chain

What happened

Multiple high-risk security incidents reported on 24–23 Apr 2026: ADT confirmed a data breach after extortion threats from ShinyHunters; a persistent custom malware named Firestarter is surviving updates on Cisco ASA/FTD (Firepower/Secure Firewall) appliances; a local privilege-escalation flaw dubbed Pack2TheRoot in the PackageKit daemon can allow local users to gain root; over 10,000 Zimbra Collaboration instances are being actively exploited via an XSS flaw; a critical arbitrary file upload vulnerability in the Breeze Cache WordPress plugin is under active exploitation; the Bitwarden CLI npm

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
bleepingcomputer
Record identifier
cfc8f30051a7adec565752010d1a1269dd2ca7ac1cf3404f351c1217d148cb7d
Enrichment time
2026-04-25T01:23:31Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.