900+ Certificates Used by Fortune 500, Governments Exposed by Key Leaks
2026-03-06T20:51:47Z•e63adbab209dcafc82116dba3e6d9574f82e4c576454b8d72e4a47d2c73f61b3
1Password credential theftAPT36CVSS 10Cisco Secure FirewallComet AIDocker HubEuropol takedownGitGuardianGitHubGoogleGoogle Sheets abuseLeakBase seizureMFA bypassPerplexityPleaseFixTLS certificate leaksTycoon phishing shutdownauthentication bypassprivate key exposureremote code executionsupply chain riskvibewarevulnerability patchingzero-click attack
What happened
Multiple high-impact cyber incidents and disclosures reported: a Google/GitGuardian study found over 2,600 valid TLS certificates (protecting Fortune 500 firms and government agencies) compromised by private key leaks on GitHub and Docker Hub; Cisco released patches for 48 Secure Firewall vulnerabilities, including two CVSS 10 flaws enabling authentication bypass and remote code execution; researchers disclosed PleaseFix flaws in the Comet AI (Perplexity) browser that enable zero-click calendar invites to exfiltrate 1Password vault data; Pakistan-linked APT36 is using AI-generated ‘vibeware’ &
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- hackread
- Record identifier
- e63adbab209dcafc82116dba3e6d9574f82e4c576454b8d72e4a47d2c73f61b3
- Enrichment time
- 2026-03-06T20:51:47Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.