KDDI Data Breach Impacts up to 14.2 Million Email Accounts at Six ISPs

2026-06-29T08:51:50Z86d135b690f9032b61eef043244c7c1c4013a7c9d6b656d09f883e585afffd98
APTCISA KEVCL-STA-1062CVE-2026-12569CVE-2026-43503CellebriteCiscoDirtyCloneFBI advisoryFlexPLMKDDILinux kernel privilege escalationPTC WindchillPolymarketRussian intelligenceSignal recovery keysTinyRCTTonRATcrypto theftdata breachemail compromisehospitality sectorphishingsupply chain riskthird-party breach

What happened

A SecurityAffairs roundup covering multiple high-impact incidents and advisories: KDDI disclosed a third‑party software breach exposing up to 14.2 million email accounts across six Japanese ISPs; JFrog published a DirtyClone Linux kernel privilege escalation (CVE-2026-43503) with an 8.8 CVSS and working exploit; CISA added Cisco and PTC Windchill/FlexPLM flaws (including CVE-2026-12569) to its Known Exploited Vulnerabilities catalog; the FBI/CISA warned Russian intelligence actors are targeting Signal backup/recovery keys for message access and account takeover; Microsoft detailed a phishing/”

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
securityaffairs
Record identifier
86d135b690f9032b61eef043244c7c1c4013a7c9d6b656d09f883e585afffd98
Enrichment time
2026-06-29T08:51:50Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · KDDI Data Breach Impacts up to 14.2 Million Email Accounts at Six ISPs · Baitaphish