KDDI Data Breach Impacts up to 14.2 Million Email Accounts at Six ISPs
2026-06-29T08:51:50Z•86d135b690f9032b61eef043244c7c1c4013a7c9d6b656d09f883e585afffd98
APTCISA KEVCL-STA-1062CVE-2026-12569CVE-2026-43503CellebriteCiscoDirtyCloneFBI advisoryFlexPLMKDDILinux kernel privilege escalationPTC WindchillPolymarketRussian intelligenceSignal recovery keysTinyRCTTonRATcrypto theftdata breachemail compromisehospitality sectorphishingsupply chain riskthird-party breach
What happened
A SecurityAffairs roundup covering multiple high-impact incidents and advisories: KDDI disclosed a third‑party software breach exposing up to 14.2 million email accounts across six Japanese ISPs; JFrog published a DirtyClone Linux kernel privilege escalation (CVE-2026-43503) with an 8.8 CVSS and working exploit; CISA added Cisco and PTC Windchill/FlexPLM flaws (including CVE-2026-12569) to its Known Exploited Vulnerabilities catalog; the FBI/CISA warned Russian intelligence actors are targeting Signal backup/recovery keys for message access and account takeover; Microsoft detailed a phishing/”
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- securityaffairs
- Record identifier
- 86d135b690f9032b61eef043244c7c1c4013a7c9d6b656d09f883e585afffd98
- Enrichment time
- 2026-06-29T08:51:50Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.