The KDDI Breach: One Vulnerable Component, Six ISPs, 12 Million Exposed Inboxes
A zero-day in unnamed third-party software let attackers sit inside KDDI's shared ISP email platform for a month, exposing email addresses and passwords used by @nifty, BIGLOBE, J:COM, and three other providers. Here's what's confirmed and what isn't.