A curated dispatch from GajShield

The GajShield Gazette

Lead story

Hospital operator Nutex Health says data stolen in cyberattack

The Nutex Health cyberattack is concerning primarily because the company has already confirmed data exfiltration, even though the investigation has not yet established exactly what was taken or whose information was affected. Nutex disclosed the incident in an SEC filing after…

Also today
In brief

Hackers target WordPress sites in miniOrange auth bypass attacks

The active exploitation of vulnerabilities in the miniOrange SAML 2.0 Single Sign On plugin for WordPress is particularly serious because t…

Aug 25, 2026

Unpatched Calix flaw lets hackers bypass NAT to expose internal devices

The disclosure of CVE-2026-75501 in the Calix GS7 XGS GS5239XG residential gateway is particularly serious because it breaks one of the mos…

Aug 25, 2026

ReliaQuest confirms failed data-theft attack after ShinyHunters breach

The ReliaQuest incident is a useful example of why modern identity attacks cannot be judged simply by whether an attacker obtained a userna…

Aug 24, 2026

South Korean startup platform breach exposes key management failures

The breach involving South Korea’s government-backed startup platform Modu-ui Changup is a particularly good example of why encryption alon…

Aug 24, 2026

Critical Keycloak Password Reset Flaw Could Let Unauthenticated Attackers Take Over Any Account

The disclosure of CVE-2026-18963 in Keycloak deserves immediate attention because it affects one of the most sensitive workflows in any ide…

Aug 24, 2026

Latvia CSDD Cyberattack Exposes Data of 1.2 Million People

The cyberattack on Latvia’s Road Traffic Safety Directorate, CSDD, is particularly significant because the attackers did not merely obtain …

Aug 24, 2026

CISA Adds One Known Exploited Vulnerability to Catalog

CISA’s August 21, 2026 addition of CVE-2026-73570 to the Known Exploited Vulnerabilities catalog materially increases the urgency around th…

Aug 24, 2026

Oz Hair & Beauty hit by data breach, customer names and contact details exposed

The Oz Hair and Beauty data breach is another useful reminder that the absence of stolen payment-card details does not make a customer-data…

Aug 24, 2026

SickKids data breach exposes employee and job applicant info

The SickKids cybersecurity incident is a useful reminder that an organisation’s security posture increasingly depends on software it does n…

Aug 22, 2026

Hundreds of leaked AWS keys give full control over corporate accounts

The discovery of more than 9,300 still-valid AWS access keys exposed publicly over the past four years is a striking reminder that cloud co…

Aug 22, 2026

New SynkLoader malware pushed in Microsoft Teams phishing campaign

The SynkLoader campaign is an important example of how phishing is moving beyond email and into collaboration platforms that employees natu…

Aug 22, 2026