Advertisement
Mathspace Breach: Over 1 Million Impacted by Metabase Zero-Day
Mathspace disclosed a data breach affecting over 1 million students, staff, and parents due to a Metabase vulnerability.
CVE-2026-63077: JetBrains Cadence Breach Exposes Credentials
JetBrains Cadence suffered a data breach via unpatched TeamCity (CVE-2026-63077), exposing AWS credentials, source code, and user data. Immediate action required.
IDScan Sued Over Alleged Breach Impacting 153 Million Drivers
IDScan faces lawsuits after a dark-web service allegedly offered to sell 153 million driver's licenses and millions of other identity documents.
French Hospital Fined €500K for GDPR Data Breach
France's CNIL fined Hôpital privé de la Loire €500,000 after a data breach exposed sensitive medical data of 727,000 patients.
Manchester Airports Group Data Leak Exposed by FulcrumSec Extortion
FulcrumSec leaks 550GB of data on 8.8 million individuals after Manchester Airports Group refused to pay a ransom demand following a breach.
Philippines Nuclear Agency Breached via Unpatched ownCloud Flaws
Threat actors exploit unpatched ownCloud vulnerabilities to breach the Philippines nuclear agency, stealing sensitive databases and credentials.
Advertisement
Dark Web Service Nexus Sells 153M+ Driver Licenses
A new dark web service, Nexus, is selling over 153 million drivers' licenses from North America, likely sourced from an identity verification company.
Infostealers Target Anthropic Claude Users via Session Theft
Threat actors are employing various infostealers to compromise Anthropic Claude user accounts via session theft, posing significant risks.
Cronos Blockchain Halted After $6M Tectonic DeFi Exploit
A price manipulation attack on Tectonic’s TONIC token led to a $6M Ethereum theft from the Cronos blockchain, forcing an emergency network restart.
Nutex Health Suffers Data Breach, Sensitive Data Exfiltrated
Nutex Health experienced a data breach exposing patient, employee, and operational data. The company is assessing the full impact.
ReliaQuest Thwarts ShinyHunters Social Engineering Attack on Okta SSO
ReliaQuest confirms a social engineering attack by ShinyHunters targeting an employee's Okta SSO, blocked from accessing applications or customer data.
Sakura Internet Breach Exposes 1.36 Million Accounts
Japanese cloud provider Sakura Internet discloses a data breach exposing customer contract and membership data for up to 1.36 million accounts.
Threat Actor Claims 3.6 Million Azure Account Records Stolen
A threat actor named TheHatman is selling 3.6 million employee records allegedly stolen from major corporate Azure tenants using compromised credentials.
DGFiP Data Breach Exposes 680,000 Individuals' Tax Data
France's DGFiP disclosed a data breach exposing tax income, withholding rates, and cadastral data for 680,000 individuals via compromised credentials.
SafePal Data Breach Exposes 39,798 Customer Order Details
SafePal confirms a data breach impacting 39,798 customers, exposing names, emails, and shipping info. Stolen data is for sale, increasing phishing risks.
Clop Ransomware Exploits CVE-2026-12569 in PTC Products
Shell investigates potential data theft by Clop gang after exploitation of critical CVE-2026-12569 in PTC Windchill and FlexPLM instances.
Beacon CRM Data Breach Exposes Over 1,000 Charity Databases
Beacon CRM data breach exposed personal details of supporters across 1,000+ charities due to a compromised AWS access key.
Scottish Government Data Breach at Prosecutor's Office via Third Party
The Scottish Crown Office and Procurator Fiscal Service (COPFS) suffered a data breach linked to a third-party supplier, risking sensitive personal data.
RingCentral Data Breach Exposes 1.6M Users to ShinyHunters
RingCentral data breach impacts 1.6 million users after a sophisticated social engineering attack by ShinyHunters. Names, emails, addresses, and phone numbers exposed.
Hackers Arrested Over €30M Bank Fraud via Service Provider Flaw
Brazilian and German authorities arrested cybercriminals for €30M bank fraud exploiting a service provider flaw, impacting Commerzbank customers.
ShinyHunters Breaches ShipMonk: 14,000 Trezor Customers' Data Exposed
ShinyHunters group breached shipping provider ShipMonk, exposing personal data of 14,000 Trezor customers via a Metabase SQL injection vulnerability.
Data Analyst Sentenced to Prison for Extorting Brightly Software
A former data analyst contractor was sentenced to two years in prison for orchestrating a $2.5 million cryptocurrency extortion scheme against Brightly.
City-Forum Data Theft Targets Salesforce and ServiceNow Portals
City-Forum data theft attacks target misconfigured Salesforce and ServiceNow portals, exploiting overly permissive guest access rules.
Wesco Confirms Cloud CRM Incident After ExfilSquad Data Leak
Wesco confirms a cloud CRM security incident as ExfilSquad claims theft of 2.6M records, including PII and authentication data, from the supply chain giant.