Xsolis Data Breach Affects 1.4 Million Individuals

2026-06-23T07:24:04Zd50bb6fa819c74d0f6e9e1e6b36eb9db5ae98398850278cffa12ab126f0f89fa
Texas-Parks-and-WildlifeXsolisai-regulationcredential-harvestingcryptocurrency-targetingdata-breachfortibleedfortinetgravity-smtphealthcareiphone-boot-exploitkluemastranpmplugin-exploitshinyhunterssquid-proxysquidbleedsupply-chainusbliter8wordpress

What happened

Multiple high-impact security stories: a data breach at healthcare vendor Xsolis exposed personal and protected health information for ~1.4M individuals, and a third‑party breach impacting Texas Parks & Wildlife exposed ~3M records. A decades‑old Squid proxy vulnerability dubbed “Squidbleed” can leak user data in a Heartbleed‑style flaw. Attackers are actively exploiting WordPress Gravity SMTP plugin flaws to harvest API keys, tokens and server data, while a Mastra NPM supply‑chain compromise (attributed to North Korean actors) injected malicious deps targeting crypto extensions. Researchers公開

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
securityweek
Record identifier
d50bb6fa819c74d0f6e9e1e6b36eb9db5ae98398850278cffa12ab126f0f89fa
Enrichment time
2026-06-23T07:24:04Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Xsolis Data Breach Affects 1.4 Million Individuals · Baitaphish