BigCommerce Data Stolen via Ribon Apps Hack
2026-09-22T19:24:01Z•c90b2c74fe47af4e57b2dc80c2f54fa8a8f82a54a0cb3fa18e6b42713efcdf80
BigCommerceChinese threat actorClick2ShellGDPRMicrosoft DefenderNorth KoreaOT securityRibonWaterPlumWordPressZyXEL switchescompromised application keycredential compromisedata breachexploitation in the wildindexed-btreeindustrial control systemslaptop farmmalicious packagenetwork segmentationnpm supply-chain attackprivacy regulationremote code executionsensitive data exfiltration
What happened
SecurityWeek RSS roundup covering a BigCommerce customer-data breach through a compromised Ribon application key, exploitation of a ZyXEL switch vulnerability by a Chinese threat actor, a malicious npm package, a WordPress remote-code-execution vulnerability, North Korean laptop-farm activity, Microsoft Defender exploit disclosure, and broader OT network-segmentation and privacy developments.
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- securityweek
- Record identifier
- c90b2c74fe47af4e57b2dc80c2f54fa8a8f82a54a0cb3fa18e6b42713efcdf80
- Enrichment time
- 2026-09-22T19:24:01Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.