Lead Story · Breaking News The J. Edgar Hoover Building in Washington, D.C., headquarters of the Federal Bureau of Investigation.

FBI Arrests Canadian Cyber Executive Edward Dubrovsky in ShinyHunters Probe

Director Kash Patel announced the arrest of a suspected ShinyHunters co-conspirator on Oct. 9; sources identify the suspect as Edward Dubrovsky, co-founder of Canadian cybersecurity firm CYPFER. The FBI has not publicly confirmed the link.

Desk: Threats — Breaking News By Owen Barrett October 10, 2026

Read the story

Incident Reports

Latest incident reports

A running file of verified security incidents — confirmed against primary sources before publication.

Greater London House in Camden Town, London — ASOS's headquarters. Breaches

ASOS Confirms Data Breach Stemmed From Social Engineering Attack on Employee

The retailer says an attacker impersonated a trusted contact to steal employee login credentials, then accessed information on third-party platforms. Customer names and contact details were exposed — but not passwords or payment data. This is distinct from an earlier August breach.

Vulnerability Watch

Critical vulnerabilities

High-severity flaws that defenders need to act on — verified identifiers, affected versions, and remediation status.

Oracle's Riverside Campus in Austin, Texas, the company's headquarters. Vulnerabilities

ShinyHunters Uses Encoding Trick to Re-Exploit Oracle PeopleSoft Flaw Past WAFs

One URL-encoded letter lets ShinyHunters walk around web application firewall rules blocking its favorite attack path — re-targeting servers that blocked the endpoint with WAFs instead of patching. Mandiant confirmed the flaw was exploited as a zero-day in May and June.

The near-complete Atlassian Central tower, Atlassian's Sydney headquarters, at Railway Square, photographed October 2026. Vulnerabilities

Attackers Probe Critical Atlassian File-Read Flaw Within Hours of Public PoC

CVE-2026-21589 lets unauthenticated attackers read files in an Atlassian application’s web root — including plaintext credentials in Crowd-integrated Jira deployments. Honeypot operators saw exploitation attempts begin within about two hours of a public proof-of-concept.

Threat Research

Threat research

Campaign analysis, malware and tooling coverage, and threat-actor tracking — built on verifiable technical evidence.

Industry

Security industry business

Funding, M&A, executive moves, and the economics of the security market — reported with numbers you can check.

A TP-Link Archer A6 router, front side, powered on with its status LEDs lit. Industry

Four More States Sue TP-Link Over Router Security and China Ties

Florida, Iowa, Montana, and Nebraska filed consumer-protection suits on Oct. 6, joining Texas in alleging the router maker misled buyers about security and its separation from China. TP-Link denies the claims — and a day later, 21 attorneys general wrote to the FCC.

Featured Investigation

Long-form investigations, filed with evidence.

HackedWire’s investigations desk will pursue deep, document-backed reporting on the security industry. The first file is in production — nothing is listed here until the reporting is verified and ready to publish.

Desk: Investigations Status: In production First file: At launch

Company Profiles

Company profiles

Independent profiles of the companies shaping security — what they build, what they claim, and what the record says. No pay-to-play placements, no sponsored rankings.

Browse the company directory

Conversations

Original interviews

On-the-record conversations with the people who build, break, and defend systems — published in full, in their own words. The first conversations are in production; nothing is listed here until a conversation has actually been recorded.

About HackedWire Conversations

Intelligence

Security resources

Reference material for practitioners — maintained, dated, and corrected when the facts change.

Sponsored

Clearly labeled, plainly separated from the newsroom. Sponsors never influence reporting.