California-based marijuana delivery service Three Trees had data from at least 40,000 individuals leaked as a result of a misconfigured MongoDB database, Cybernews reports.
Security researchers at SonicWall reported that ransomware actors have moved away from broad, untargeted attacks to more human-operated, "big game hunting" methodologies.
The UK National Cyber Security Centre's report highlights an increase to 100 nations having access to these hacking tools, up from 80 countries estimated last year.
Hackers gained access to Rituals' membership database, stealing data that includes customers' full names, dates of birth, gender, postal and email addresses, and phone numbers.
The vulnerability, identified as CVE-2026-28950, was patched on April 22, 2026, in iOS 26.4.2 and iPadOS 26.4.2, as well as in iOS 18.7.8 and iPadOS 18.7.8.
The Harvester group, believed to be state-sponsored, has been active since at least 2021, targeting telecommunications, government, and IT organizations in South Asia with custom tools.
Fast Five
Selected by the SC Media Editorial team every Tuesday.
Sign up now for the top five issues cybersecurity pros need to know this week.