Krispy Kreme, the popular doughnut chain, recently suffered a cybersecurity incident that disrupted its online ordering system but left retail operations unaffected. In a Securities and Exchange Commission (SEC) filing, the company reported "unauthorized activity" affecting parts of its IT systems in late November. According to the filing, Krispy Kreme is collaborating with external cybersecurity experts to address the incident and restore online ordering. Federal law enforcement has also been notified. While the full scope and impact of the breach are still under investigation, the company anticipates the incident will have a "material impact" on operations until recovery is complete. Fortunately, expected losses are likely to be mitigated by cyber insurance. The company has not confirmed whether customer data was compromised. However, Paul Bischoff, a consumer privacy advocate at Comparitech, warned that customers who have ordered online should assume their information may have been exposed, as most breaches of this nature often involve data theft. Despite the challenges, Krispy Kreme’s cybersecurity team acted quickly to prevent further damage, ensuring retail stores and delivery operations remained unaffected. Security expert Ilia Sotnikov noted the team’s rapid response likely minimized disruptions. However, Ryan Sherstobitoff of Security Scorecard raised concerns about potential vulnerabilities in Krispy Kreme’s supply chain, given its size and scale. With over 400 U.S. locations, the breach underscores the importance of vigilance, especially during the holiday season when cybercriminals exploit distractions.
A critical security flaw in Oracle WebLogic Server has rapidly become a prime target for attackers worldwide. Identified as CVE-2026-21962, the issue carries the highest possible s...
A new Windows malware called ResokerRAT has been discovered, which allows attackers to secretly control infected systems. This malware uses Telegram instead of traditional servers ...
A vulnerability has been identified in Google Cloud’s Vertex AI platform that could allow unauthorized users to access sensitive data associated with machine learning workloads. ...