12 Million Impacted by Data Breach at Japanese Telco KDDI
2026-07-09T13:24:20Z•791452bc1cf7fbf4cb990a215f3c58d32e6945deca3ebbb584a02f1d50f80115
CVE-2026-11405CVE-2026-50656GhostLockai-securityaptbackdoorbackdoor-toolingbrowser-securitychromedata-breachdata-theftdefenderemail-system-compromiseghostapprovallapdogslinux-kernelprivilege-escalationransomwaresoho-routertelcotendathird-partyuse-after-freezero-day
What happened
Multiple high-impact incidents and vulnerabilities reported: Japanese telco KDDI suffered a data breach affecting ~12 million users after attackers exploited a zero‑day in a third‑party ISP email system; a 15‑year‑old Linux kernel privilege‑escalation flaw dubbed “GhostLock” enables local root on major distributions; Microsoft patched a Defender privilege‑escalation flaw (CVE-2026-50656); an unpatched backdoor in Tenda firmware (CVE-2026-11405) grants unauthenticated admin access to devices; Chrome 150 fixes 27 vulnerabilities including critical use‑after‑free bugs; Mount Royal University and
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- securityweek
- Record identifier
- 791452bc1cf7fbf4cb990a215f3c58d32e6945deca3ebbb584a02f1d50f80115
- Enrichment time
- 2026-07-09T13:24:20Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.