BigCommerce Data Stolen via Ribon Apps Hack

2026-09-22T19:24:01Z•c90b2c74fe47af4e57b2dc80c2f54fa8a8f82a54a0cb3fa18e6b42713efcdf80
BigCommerceChinese threat actorClick2ShellGDPRMicrosoft DefenderNorth KoreaOT securityRibonWaterPlumWordPressZyXEL switchescompromised application keycredential compromisedata breachexploitation in the wildindexed-btreeindustrial control systemslaptop farmmalicious packagenetwork segmentationnpm supply-chain attackprivacy regulationremote code executionsensitive data exfiltration

What happened

SecurityWeek RSS roundup covering a BigCommerce customer-data breach through a compromised Ribon application key, exploitation of a ZyXEL switch vulnerability by a Chinese threat actor, a malicious npm package, a WordPress remote-code-execution vulnerability, North Korean laptop-farm activity, Microsoft Defender exploit disclosure, and broader OT network-segmentation and privacy developments.

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
securityweek
Record identifier
c90b2c74fe47af4e57b2dc80c2f54fa8a8f82a54a0cb3fa18e6b42713efcdf80
Enrichment time
2026-09-22T19:24:01Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.