KDDI Data Breach Impacts up to 14.2 Million Email Accounts at Six ISPs
2026-06-28T20:51:47Z•2409d2b9a5179968b9c506a62508becf65fa1314865268decac41f6aa9ff9e14
APTCISA-KEVDirtyCloneKDDILinux-kernelcryptocurrency-theftdata-breachemail-compromisephishingsignal-recovery-keysthird-party-breachvulnerability-management
What happened
Multiple high-impact security incidents and research items: KDDI disclosed a breach that exposed up to 14.2 million email accounts across six Japanese ISPs after attackers exploited a third‑party software vulnerability. Polymarket suffered a third‑party compromise that enabled malicious code injection and ~$2.94M in crypto theft. JFrog published a working exploit for DirtyClone (Linux kernel privilege escalation, CVE-2026-43503, CVSS 8.8). CISA added Cisco/PTC flaws (including CVE-2026-12569) to its Known Exploited Vulnerabilities catalog. Additional coverage includes FBI/CISA warnings about S
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- securityaffairs
- Record identifier
- 2409d2b9a5179968b9c506a62508becf65fa1314865268decac41f6aa9ff9e14
- Enrichment time
- 2026-06-28T20:51:47Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.