U.S. utility giant Itron discloses a security breach

2026-04-27T08:51:46Zf0ade20f3cd578e0dc544d4b6d424cc91c0eb0c8dcf53b11743f4c4e5cd71897
APTBreeze-CacheCVE-2024-7399CVE-2026-3844CVE-2026-40050CVE-2026-41651Cisco-ASACrowdStrikeFIRESTARTERGopherWhisperItronPack2TheRootdata-breachdata-exfiltrationpath-traversalransomwareunauthenticated-exploitvulnerability

What happened

Multiple high-impact security incidents and vulnerabilities reported: Itron disclosed unauthorized access to parts of its internal IT environment (detected Apr 13, 2026). CrowdStrike patched a critical unauthenticated path-traversal in LogScale self‑hosted (CVE-2026-40050) allowing arbitrary file reads. WordPress Breeze Cache plugin is being actively exploited via CVE-2026-3844 (unauthenticated file upload) affecting hundreds of thousands of sites. ESET identified a new China-aligned APT “GopherWhisper” targeting Mongolian government entities with Go-based loaders/backdoors. Trigona ransomware

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
securityaffairs
Record identifier
f0ade20f3cd578e0dc544d4b6d424cc91c0eb0c8dcf53b11743f4c4e5cd71897
Enrichment time
2026-04-27T08:51:46Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · U.S. utility giant Itron discloses a security breach · Baitaphish