12 Million Impacted by Data Breach at Japanese Telco KDDI

2026-07-09T13:24:20Z791452bc1cf7fbf4cb990a215f3c58d32e6945deca3ebbb584a02f1d50f80115
CVE-2026-11405CVE-2026-50656GhostLockai-securityaptbackdoorbackdoor-toolingbrowser-securitychromedata-breachdata-theftdefenderemail-system-compromiseghostapprovallapdogslinux-kernelprivilege-escalationransomwaresoho-routertelcotendathird-partyuse-after-freezero-day

What happened

Multiple high-impact incidents and vulnerabilities reported: Japanese telco KDDI suffered a data breach affecting ~12 million users after attackers exploited a zero‑day in a third‑party ISP email system; a 15‑year‑old Linux kernel privilege‑escalation flaw dubbed “GhostLock” enables local root on major distributions; Microsoft patched a Defender privilege‑escalation flaw (CVE-2026-50656); an unpatched backdoor in Tenda firmware (CVE-2026-11405) grants unauthenticated admin access to devices; Chrome 150 fixes 27 vulnerabilities including critical use‑after‑free bugs; Mount Royal University and

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
securityweek
Record identifier
791452bc1cf7fbf4cb990a215f3c58d32e6945deca3ebbb584a02f1d50f80115
Enrichment time
2026-07-09T13:24:20Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.