A curated dispatch from GajShield

The GajShield Gazette

Lead story

Sakura Internet hack exposes data of up to 1.36 million accounts

The Sakura Internet breach is significant not simply because of the potential number of affected accounts, but because of where the attackers gained access. According to the company’s disclosure, attackers accessed Sakura Internet’s internal sales management system, which stor…

Also today
Aug 19, 2026

Siemens Simcenter Nastran

CISA's ICSA-26-230-02 advisory covers a high-severity vulnerability in Siemens Simcenter Nastran, an engineering simulation platform used for structural analysis and com…

In brief

CISA Malcolm

CISA's ICSA-26-230-01 advisory covering Malcolm is particularly interesting because Malcolm is itself a defensive network traffic analysis …

Aug 19, 2026

CISA Adds Four Known Exploited Vulnerabilities to Catalog

CISA's addition of four vulnerabilities to the Known Exploited Vulnerabilities catalog on August 18, 2026 is particularly noteworthy becaus…

Aug 19, 2026

Clop created custom web shell for Windchill data theft attacks

The Clop campaign targeting PTC Windchill and FlexPLM is particularly significant because the attackers did not simply deploy a generic web…

Aug 19, 2026

Attackers Exploit MLflow SSRF Flaw to Steal Cloud Credentials and Secrets

The active exploitation of CVE-2026-64849 in MLflow is another reminder that AI infrastructure is quickly becoming part of the mainstream a…

Aug 19, 2026

Microsoft Copilot Personal Flaws Could Let One Click Exfiltrate Data From Connected Apps

The CoSnitch vulnerabilities disclosed in Microsoft Copilot Personal highlight a security challenge that will become increasingly important…

Aug 19, 2026

One Attacker Has Scraped Both Salesforce and ServiceNow Portals Since 2025

The City Forum campaign is a good example of how serious data exposure does not always require a sophisticated zero-day or even the comprom…

Aug 18, 2026

CISA Flags Actively Exploited Ray Flaw That Can Trigger Browser-Based RCE

This vulnerability is a strong reminder that internal or development services should never be considered safe simply because they are not d…

Aug 18, 2026

Forminator WordPress Flaw Can Enable Unauthenticated RCE via Malicious PHP Uploads

The Forminator vulnerability is another strong example of why WordPress security cannot be treated as simply keeping the core platform patc…

Aug 18, 2026

Pokémon Center data breach exposes customer info, cancels some orders

The reported Pokémon Center data breach is another reminder that retail cybersecurity is no longer limited to protecting payment systems. C…

Aug 18, 2026

Critical GitLab GraphQL Flaw Could Let Unauthenticated Attackers Delete Public Projects

The reported GitLab GraphQL vulnerability highlights an increasingly important security issue around powerful application APIs. GraphQL giv…

Aug 18, 2026

Massive Azure Exfiltration Campaign Exposes Millions of Enterprise Records via Compromised Credentials (Mcdonald's, Vodafone, Kyndryl & Others)

The reported Azure exfiltration campaign is a strong example of why compromised credentials remain one of the most dangerous paths into mod…

Aug 17, 2026