ADT confirms data breach after ShinyHunters leak threat
2026-04-25T01:23:31Z•cfc8f30051a7adec565752010d1a1269dd2ca7ac1cf3404f351c1217d148cb7d
ASABitwarden CLIBreeze CacheCheckmarx KICSCisco FirepowerFTDFirestarterPack2TheRootPackageKitShinyHuntersTrigonaWordPressXSSZimbraarbitrary-file-uploadcredential-theftdata-breachexfiltration-toolextortionfirewall persistencelocal-privilege-escalationmalwarenpm compromiseransomwaresupply-chain
What happened
Multiple high-risk security incidents reported on 24–23 Apr 2026: ADT confirmed a data breach after extortion threats from ShinyHunters; a persistent custom malware named Firestarter is surviving updates on Cisco ASA/FTD (Firepower/Secure Firewall) appliances; a local privilege-escalation flaw dubbed Pack2TheRoot in the PackageKit daemon can allow local users to gain root; over 10,000 Zimbra Collaboration instances are being actively exploited via an XSS flaw; a critical arbitrary file upload vulnerability in the Breeze Cache WordPress plugin is under active exploitation; the Bitwarden CLI npm
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- bleepingcomputer
- Record identifier
- cfc8f30051a7adec565752010d1a1269dd2ca7ac1cf3404f351c1217d148cb7d
- Enrichment time
- 2026-04-25T01:23:31Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.