Golf Canada Data Breach May 2026 - What Was Exposed and What To Do
Golf Canada breach exposed 568,972 records including Dates of birth, Email addresses, Genders, Geographic locations, Names. Check if you were affected.
Intelligence Feed
The Sherlock Forensics Intelligence Feed provides expert analysis of AI code security, vibe coding vulnerabilities, CVE advisories and digital forensics methodologies from certified examiners with over 20 years of field experience in Vancouver, BC.
Editor Picks
The most-read pieces our team is shipping right now.
Golf Canada breach exposed 568,972 records including Dates of birth, Email addresses, Genders, Geographic locations, Names. Check if you were affected.
CVE-2024-50125 (Security, CVSS 8.0 HIGH, CWE-416 and CWE-416) affecting linux kernel. Full forensic analysis and public exploit availability inventory and Sigma detection signature and mitigation guidance.
CVE-2025-46291 (Security, CVSS 7.8 HIGH, CWE-693) affecting apple macos. Full forensic analysis and public exploit availability inventory and Sigma detection signature and mitigation guidance.
CVE-2025-66824 (Security, CVSS 8.7 HIGH, CWE-79) affecting trueconf server. Full forensic analysis and public exploit availability inventory and Sigma detection signature and mitigation guidance.
CVE-2026-74944 (Security, CVSS 9.8 CRITICAL, CWE-416 and CWE-416) affecting mozilla firefox. Full forensic analysis and public exploit availability inventory and Sigma detection signature and mitigation guidance.
CVE-2026-76259 (Security, CVSS 8.8 HIGH, CWE-269) affecting splunk. Full forensic analysis and public exploit availability inventory and Sigma detection signature and mitigation guidance.
CVE-2026-74943 (Security, CVSS 9.8 CRITICAL, CWE-416) affecting mozilla firefox. Full forensic analysis and public exploit availability inventory and Sigma...
CVE-2026-74940 (Security, CVSS 9.8 CRITICAL, CWE-416) affecting mozilla firefox. Full forensic analysis and public exploit availability inventory and Sigma...
CVE-2026-74936 (Security, CVSS 9.8 CRITICAL, CWE-416) affecting mozilla firefox. Full forensic analysis and public exploit availability inventory and Sigma...
CVE-2025-62718 (Security, CVSS 9.9 CRITICAL, CWE-441 and CWE-918 and CWE-1289) affecting axios. Full forensic analysis and public exploit availability...
CVE-2024-58240 (Security, CVSS 9.8 CRITICAL, CWE-416) affecting linux kernel. Full forensic analysis and public exploit availability inventory and Sigma...
CVE-2026-11718 (Security, CVSS 9.1 CRITICAL, CWE-287) affecting google mcp toolbox for databases. Full forensic analysis and public exploit availability...
CVE-2026-11717 (Security, CVSS 9.1 CRITICAL, CWE-287) affecting google mcp toolbox for databases. Full forensic analysis and public exploit availability...
CVE-2025-62593 (Code Injection, CVSS 8.8 HIGH, CWE-94 and CWE-352) affecting anyscale ray. Full forensic analysis and public exploit availability inventory and...
CVE-2026-65767 (Security, CVSS 8.8 HIGH, CWE-79) affecting microsoft teams. Full forensic analysis and public exploit availability inventory and Sigma...
A neutral guide to choosing a digital forensics firm: credentials to demand, chain-of-custody discipline, tooling transparency and red flags to watch.
After a breach, the forensic evidence a cyber insurer needs to pay the claim: IR report, chain of custody, exposure scope and timeline. Post-incident.
The signs you need a forensic investigation: suspected breach, insider threat, litigation hold or insurer requirement. Why waiting destroys the evidence.
An operational PIPEDA breach-reporting playbook: the RROSH decision, as-soon-as-feasible OPC timelines and what the report must contain.
38 vulnerabilities analyzed the week of August 16, 2026. 29 critical, 9 high. Grouped by vendor with patching priorities.
How a forensic examiner reconstructs a business email compromise: mailbox rule abuse, token theft, the wire-fraud timeline and what logs survive.
The real line items behind a mid-market data breach: incident response, legal, notification, downtime, churn and premium hikes.
The pre-incident posture that makes response fast and evidence admissible: logging, retention, chain-of-custody discipline and tabletop rehearsal.
What a right-sized incident response engagement looks like for a 50 to 500 person company: when to call, what the first 48 hours deliver.
CVE-2026-13368 (Security, CVSS 8.1 HIGH, CWE-416) affecting watchguard fireware. Full forensic analysis and public exploit availability inventory and Sigma detection signature and mitigation guidance.
CVE-2026-63797 (Security, CVSS 8.4 HIGH, CWE-416) affecting linux kernel. Full forensic analysis and public exploit availability inventory and Sigma detection signature and mitigation guidance.
CVE-2026-65768 (Path Traversal, CVSS 8.8 HIGH, CWE-22) affecting microsoft teams. Full forensic analysis and public exploit availability inventory and Sigma detection signature and mitigation guidance.
CVE-2025-71390 (Security, CVSS 8.8 HIGH, CWE-863) affecting surrealdb. Full forensic analysis and public exploit availability inventory and Sigma detection signature and mitigation guidance.
CVE-2026-8984 (Code Injection, CVSS 9.8 CRITICAL, CWE-94) affecting autel maxicharger single charger firmware. Full forensic analysis and public exploit availability inventory and Sigma detection signature and mitigation guidance.
CVE-2026-8985 (OS Command Injection, CVSS 9.8 CRITICAL, CWE-78) affecting autel maxicharger single charger firmware. Full forensic analysis and public exploit availability inventory and Sigma detection signature and mitigation guidance.
Oz Hair and Beauty breach exposed 1,988,331 records including Email addresses, Geographic locations, Names, Phone numbers. Check if you were affected.
CVE-2026-8983 (Security, CVSS 9.8 CRITICAL, CWE-798) affecting autel maxicharger single charger firmware. Full forensic analysis and public exploit...
CVE-2025-14733 (Security, CVSS 9.8 CRITICAL, CWE-787) affecting watchguard fireware. Full forensic analysis and public exploit availability inventory and Sigma...
CVE-2026-8037 (Security, CVSS 9.6 CRITICAL, CWE-77) affecting progress connection manager for objectscale. Full forensic analysis and public exploit...
CVE-2026-16232 (Security, CVSS 9.8 CRITICAL, CWE-287) affecting checkpoint multi-domain security management. Full forensic analysis and public exploit...
CVE-2025-9242 (Security, CVSS 9.8 CRITICAL, CWE-787) affecting watchguard fireware. Full forensic analysis and public exploit availability inventory and Sigma...
CVE-2024-23692 (Code Injection, CVSS 9.8 CRITICAL, CWE-1336 and CWE-94) affecting rejetto http file server. Full forensic analysis and public exploit...
3 vulnerabilities analyzed this week. 2 critical, 1 high. Grouped by vendor with patching priorities.
16 new Code/Command Injection CVEs this week including CVE-2026-58275 (CVSS 10.0). What Startup Security teams need to know.
CVE-2026-49875 (Security, CVSS 9.8 CRITICAL, CWE-611 and CWE-611) affecting apache cxf. Full forensic analysis and public exploit availability inventory and...
CVE Intelligence
High and critical vulnerabilities relevant to cloud, web and AI infrastructure. Updated daily from the National Vulnerability Database.
| CVE | Severity | CVSS | Affected Product | Vulnerability |
|---|---|---|---|---|
| CVE-2026-23696 | CRITICAL | 9.9 | Windmill CE/EE | SQL injection in folder ownership management |
| CVE-2021-4473 | CRITICAL | 9.8 | Tianxin Management System | Command injection in Reporter component |
| CVE-2026-22679 | CRITICAL | 9.8 | Weaver E-cology 10.0 | Unauthenticated RCE via debug endpoint |
| CVE-2026-3296 | CRITICAL | 9.8 | Everest Forms (WordPress) | PHP Object Injection via deserialization |
| CVE-2026-4631 | CRITICAL | 9.8 | Cockpit (Linux) | SSH command injection via login endpoint |
| CVE-2026-1346 | CRITICAL | 9.3 | IBM Verify Identity Access | Privilege escalation for local users |
| CVE-2026-22683 | HIGH | 8.8 | Windmill | Missing authorization bypasses operator restrictions |
| CVE-2026-3357 | HIGH | 8.8 | IBM Langflow Desktop | Insecure FAISS deserialization enables code execution |
| CVE-2026-1342 | HIGH | 8.5 | IBM Verify Identity Access | Local users can execute malicious scripts |
| CVE-2026-4788 | HIGH | 8.4 | IBM Tivoli Netcool Impact | Sensitive data exposure in log files |
| CVE-2026-4740 | HIGH | 8.2 | Red Hat ACM / Open Cluster Mgmt | Certificate forgery via improper validation |
| CVE-2026-5736 | HIGH | 7.3 | PowerJob | detailPlus endpoint manipulation |
| CVE-2026-5739 | HIGH | 7.3 | PowerJob | Code injection via OpenAPI workflow endpoint |
| CVE-2026-5741 | HIGH | 7.3 | docker-mcp-server | OS command injection via HTTP interface |
| CVE-2026-1343 | HIGH | 7.2 | IBM Verify Identity Access | SSRF exposes internal auth endpoints |
| CVE-2026-22682 | HIGH | 7.1 | OpenHarness | Improper access control exposes local files |