VPN Breach Exposes 58 Million Connection Logs Despite “No-Logs” Claims

2026-07-29T08:51:36Zf36981c27ca89ab5b2b7608c41c33b5b9679fcbf887653bbe176dcf99bbf7ac7
CVE-2025-68686CVE-2026-63077AI securityCISA KEVFortinet FortiOSGitLabHugging FaceOj parserRATTeamCityVPNVeloCloud Orchestratorblockchain domainsbotnetbrowser hijackingcommand and controlcredential and user data exposurecrypter-as-a-servicedata breachexploit chainhealthcare datamalware deliveryprivacyremote code executionwearable privacy

What happened

Security news covering a major VPN data breach exposing 58 million connection logs and user records; the 200,000-device Dysphoria botnet using blockchain domains for command-and-control concealment; critical unauthenticated RCE in JetBrains TeamCity (CVE-2026-63077); the Cruciferra crypter-as-a-service malware delivery ecosystem; actively exploited Arista VeloCloud Orchestrator and Fortinet FortiOS vulnerabilities added to CISA KEV; an AI agent-related Hugging Face breach; MedusaHVNC browser and data theft; a DentaQuest breach affecting over 23 million people; a critical GitLab RCE exploit;and

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
securityaffairs
Record identifier
f36981c27ca89ab5b2b7608c41c33b5b9679fcbf887653bbe176dcf99bbf7ac7
Enrichment time
2026-07-29T08:51:36Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.