Carnival Data Breach Exposes Personal Data of Nearly 6 Million Customers
2026-05-29T02:51:44Z•8eb419d6e82ce0164de313f6c6fdd956285057365d80f83962ba0e4f68bbc5c8
CISA-KEVCVEactive-exploitationbotnet-takedowncloud-misconfigurationcode-signingcredential-exposuredata-breachdigital-crimes-unitinformation-stealerrcestate-linked-attackvulnerability
What happened
Collection of May 28, 2026 security incidents: Carnival disclosed a data breach affecting ~5.99M customers via social-engineered employee account access; a critical FortiClient EMS RCE (CVE-2026-35616, CVSS 9.1) is being actively exploited to deploy information-stealing malware; CISA added multiple flaws to its KEV list including LiteSpeed cPanel Plugin (CVE-2026-48172, CVSS 10.0) and Windows Shell/other entries (e.g., CVE-2026-8398); a third‑party UK visa site exposed ~100k passports on a public AWS server; researchers found 19.6 billion files exposed in misconfigured cloud buckets; Microsoft
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- securityaffairs
- Record identifier
- 8eb419d6e82ce0164de313f6c6fdd956285057365d80f83962ba0e4f68bbc5c8
- Enrichment time
- 2026-05-29T02:51:44Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.