A cybercrime crew claims to have breached MyPillow, the bedding company owned by Mike Lindell. The group has not yet disclosed details about the scope of the breach or what data was accessed.
The alleged hack adds MyPillow to a growing list of companies targeted by organized cybercriminal groups. The crew has not specified whether they obtained customer data, financial records, or other sensitive information.
MyPillow has not publicly confirmed the breach or commented on the claims. The company has faced increased scrutiny in recent years following various controversies involving its CEO.
In related security news, ransomware operators are adopting new tactics, including physical theft of data from company locations. Additionally, BusPatrol, which operates license plate recognition surveillance systems, is seeking to share its database with law enforcement agencies—raising privacy concerns among civil liberties advocates.
The incidents underscore ongoing vulnerabilities in corporate cybersecurity infrastructure and the evolving methods employed by criminal organizations to extract value from breached systems.
Forgejo, a self-hosted Git service, released version 16.0.4 to address a critical remote code execution vulnerability affecting all versions up to 16.0.3. Users should upgrade immediately.
Microsoft's September 2026 security patches are disabling Remote Desktop Services across Windows Server 2019, 2022, and 2025, leaving administrators unable to access systems and requiring hard resets in some cases.
Surfshark disclosed that hackers accessed internal testing and proxy servers following a configuration error that exposed systems to the internet. The VPN provider is investigating the scope of the breach.
Google has enabled Android users to securely migrate login credentials between password managers. The feature is currently available in a limited number of apps, with broader support expected soon.