U.S. utility giant Itron discloses a security breach
2026-04-27T08:51:46Z•f0ade20f3cd578e0dc544d4b6d424cc91c0eb0c8dcf53b11743f4c4e5cd71897
APTBreeze-CacheCVE-2024-7399CVE-2026-3844CVE-2026-40050CVE-2026-41651Cisco-ASACrowdStrikeFIRESTARTERGopherWhisperItronPack2TheRootdata-breachdata-exfiltrationpath-traversalransomwareunauthenticated-exploitvulnerability
What happened
Multiple high-impact security incidents and vulnerabilities reported: Itron disclosed unauthorized access to parts of its internal IT environment (detected Apr 13, 2026). CrowdStrike patched a critical unauthenticated path-traversal in LogScale self‑hosted (CVE-2026-40050) allowing arbitrary file reads. WordPress Breeze Cache plugin is being actively exploited via CVE-2026-3844 (unauthenticated file upload) affecting hundreds of thousands of sites. ESET identified a new China-aligned APT “GopherWhisper” targeting Mongolian government entities with Go-based loaders/backdoors. Trigona ransomware
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- securityaffairs
- Record identifier
- f0ade20f3cd578e0dc544d4b6d424cc91c0eb0c8dcf53b11743f4c4e5cd71897
- Enrichment time
- 2026-04-27T08:51:46Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.