KDDI Data Breach Impacts up to 14.2 Million Email Accounts at Six ISPs
2026-06-29T02:51:47Z•4c657d19ace5ea1c0473e205e6046b7659f27e89abc9ac8fe9d03a5adcc12265
APTcryptocurrency-theftdata-breachemail-compromiseespionageknown-exploited-vulnerabilitylinux-kernelmalwarephishingprivilege-escalationsignal-backupsupply-chain-compromisethird-party-breach
What happened
This feed covers multiple high-impact security incidents and advisories: KDDI disclosed a breach that exposed up to 14.2 million email accounts across six Japanese ISPs after attackers exploited a third‑party software vulnerability. CISA added critical/actively exploited flaws in Cisco and PTC Windchill/FlexPLM (including CVE-2026-12569) to its KEV catalog. JFrog published an exploit walkthrough for DirtyClone (CVE-2026-43503), a Linux kernel privilege escalation (CVSS 8.8) that can escalate to root without leaving disk traces. Additional notable items: FBI/CISA warnings that Russian actors ex
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- securityaffairs
- Record identifier
- 4c657d19ace5ea1c0473e205e6046b7659f27e89abc9ac8fe9d03a5adcc12265
- Enrichment time
- 2026-06-29T02:51:47Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.