π₯ BREACHES & INCIDENTS
- Ernst & Young Data Breach Exposes Personal and Financial Client Information β SecurityWeek
Ernst & Young disclosed a data breach involving client personal and financial data from a third-party platform.- Applies to Ernst & Young clients using a third-party IT support platform for tax-related services
- Compromised data includes names, addresses, Social Security numbers, credit/debit card numbers, and tax documents
- Attack occurred between March 28 and April 12, 2026, with unauthorized access to support tickets and documents
- Breach discovered April 23, 2026; EY engaged cybersecurity firm for investigation and began remediation
- No ransomware/extortion claims or attack method details disclosed by EY
π ADVISORIES
- OpenSSL silently fixes HollowByte DoS vulnerability causing memory exhaustion β SecurityWeek
OpenSSL patched a denial-of-service bug that exhausts server memory via crafted payloads.- Applies to OpenSSL versions before 4.0.1, including 3.6.3, 3.5.7, 3.4.6, and 3.0.21
- Vulnerability triggers buffer pre-allocations based on handshake header, not actual data
- Attack uses 11-byte malicious payloads declaring large message sizes to exhaust memory
- Multiple successive connections cause memory fragmentation and exhaustion without freeing
- Impacts servers and applications using OpenSSL like Apache, NGINX, Node.js, Python, Ruby, PHP, MySQL, PostgreSQL
π CVEs & KEV
- CVE-2026-14440 β CVSS 6.8 β Cloudflareβs CAA flaw looks impractical for criminals β but what about actors who control the network?
- CVE-2026-15813 β CVSS 6.5 β Kronosnet: memory corruption and out-of-bounds access via malformed input
- CVE-2026-16254 β CVSS 4.3 β Claircore: denial of service via out-of-bounds slice in claircore component