Curated Cyber Threat Intelligence

Threat Feed

Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.

scheduleUpdated 2026-09-04 · 02:17 UTC
articleTotal: 1172 reports

Filtered Reports

10 / 10 results
Active filter:tag: #retail✕ clear
ShinyHunters Publishes 12.9M Carhartt Customer Records After Breachhighperson_alertThreat Actor
person_alertThreat Actor

ShinyHunters Publishes 12.9M Carhartt Customer Records After Breach

ShinyHunters is a financially motivated extortion group known for large-scale data theft and public leak operations. The group operates by exfiltrating sensitive data from compromised organizations, demanding ransom payments, and publishing stolen re…

Carhartt27 Aug · 09:10 UTC
Zombie Card attack revives expired Visa contactless cards via NFC relayhighbug_reportVulnerability
bug_reportVulnerability

Zombie Card attack revives expired Visa contactless cards via NFC relay

Visa contactless credit cards using Kernel 3 specification. Attack requires physical card access or sustained NFC proximity, plus relay device between card and terminal. Five major US banks tested; three confirmed vulnerable with varying policies.

Visa20 Aug · 10:01 UTC
Adobe Commerce critical vulnerability under active exploitationcriticalbug_reportVulnerability
bug_reportVulnerability

Adobe Commerce critical vulnerability under active exploitation

Adobe Commerce (formerly Magento). Specific affected versions not disclosed in advisory. All unpatched instances should be considered at risk.

Adobe17 Aug · 07:14 UTC
SAP Commerce Cloud RCE flaw (CVE-2026-58231) exploited 3 days post-patchcriticalbug_reportVulnerability
bug_reportVulnerability

SAP Commerce Cloud RCE flaw (CVE-2026-58231) exploited 3 days post-patch

SAP Commerce Cloud (formerly Hybris), specifically the core Data Hub Adapter extension. All unpatched instances are vulnerable. Shadowserver tracks 4,200+ internet-exposed instances, primarily in Europe and North America.

SAP14 Aug · 11:45 UTC
Adobe Commerce/Magento flaw CVE-2026-71362 exploited to hijack accountscriticalbug_reportVulnerability
bug_reportVulnerability

Adobe Commerce/Magento flaw CVE-2026-71362 exploited to hijack accounts

Adobe Commerce and Magento Open Source e-commerce platforms, all currently supported release lines. The vulnerability affects customer account session handling and requires no authentication to exploit.

CVE-2026-7136212 Aug · 18:54 UTC
Levi Strauss discloses social engineering breach targeting employeeshighpublicGeopolitical
publicGeopolitical

Levi Strauss discloses social engineering breach targeting employees

The incident reflects the persistent threat of social engineering attacks against major U.S. corporations, particularly within the retail and apparel sectors.

Levi Strauss & Co.7 Aug · 13:48 UTC
Scattered Spider Linked to U.S. Luxury Retail Breach via Device IDhighperson_alertThreat Actor
person_alertThreat Actor

Scattered Spider Linked to U.S. Luxury Retail Breach via Device ID

Scattered Spider (also tracked as Roasted 0ktapus, Octo Tempest, Storm-0875, and UNC3944) is a financially motivated threat actor known for sophisticated social engineering and identity-focused attacks.

The Hacker News7 Jul · 11:27 UTC
Shopify Shop app abused for callback phishing via fake order receiptshighbug_reportVulnerability
bug_reportVulnerability

Shopify Shop app abused for callback phishing via fake order receipts

Shopify Shop order-tracking app users. Threat actors inject fraudulent purchase receipts into legitimate user order histories, leveraging Shopify's trusted platform to deliver phishing lures.

Shopify25 Jun · 17:45 UTC
Toshiba, Muji sites show credential-stealing prompts via polyfill supply chainhighbug_reportVulnerability
bug_reportVulnerability

Toshiba, Muji sites show credential-stealing prompts via polyfill supply chain

Toshiba and Muji public websites, potentially other sites using the compromised third-party polyfill library. Scope of affected sites and specific polyfill service not yet confirmed.

Toshiba5 Jun · 19:54 UTC
ShinyHunters Breaches 7-Eleven, Exfiltrates 183K Recordshighperson_alertThreat Actor
person_alertThreat Actor

ShinyHunters Breaches 7-Eleven, Exfiltrates 183K Records

ShinyHunters is a financially motivated cybercrime group known for large-scale data breaches and extortion operations targeting organizations across multiple sectors.

7-Eleven26 May · 05:01 UTC