Advertisement
Manchester Airports Group Data Leak Exposed by FulcrumSec Extortion
FulcrumSec leaks 550GB of data on 8.8 million individuals after Manchester Airports Group refused to pay a ransom demand following a breach.
Philippines Nuclear Agency Breached via Unpatched ownCloud Flaws
Threat actors exploit unpatched ownCloud vulnerabilities to breach the Philippines nuclear agency, stealing sensitive databases and credentials.
Dark Web Service Nexus Sells 153M+ Driver Licenses
A new dark web service, Nexus, is selling over 153 million drivers' licenses from North America, likely sourced from an identity verification company.
Nutex Health Suffers Data Breach, Sensitive Data Exfiltrated
Nutex Health experienced a data breach exposing patient, employee, and operational data. The company is assessing the full impact.
Encrypted Prompts Bypass AI Safety Guardrails in Grok and Gemini
Researchers discover cryptographic context injection, a novel technique bypassing AI safety filters in xAI Grok and Google Gemini using encryption.
Hundreds of Leaked AWS Keys Expose Corporate Cloud Accounts
Research reveals over 9,000 publicly exposed Amazon Web Services access keys remain active, including hundreds of root and administrator credentials.
Advertisement
Sakura Internet Breach Exposes 1.36 Million Accounts
Japanese cloud provider Sakura Internet discloses a data breach exposing customer contract and membership data for up to 1.36 million accounts.
Threat Actor Claims 3.6 Million Azure Account Records Stolen
A threat actor named TheHatman is selling 3.6 million employee records allegedly stolen from major corporate Azure tenants using compromised credentials.
DGFiP Data Breach Exposes 680,000 Individuals' Tax Data
France's DGFiP disclosed a data breach exposing tax income, withholding rates, and cadastral data for 680,000 individuals via compromised credentials.
SafePal Data Breach Exposes 39,798 Customer Order Details
SafePal confirms a data breach impacting 39,798 customers, exposing names, emails, and shipping info. Stolen data is for sale, increasing phishing risks.
Beacon CRM Data Breach Exposes Over 1,000 Charity Databases
Beacon CRM data breach exposed personal details of supporters across 1,000+ charities due to a compromised AWS access key.
Scottish Government Data Breach at Prosecutor's Office via Third Party
The Scottish Crown Office and Procurator Fiscal Service (COPFS) suffered a data breach linked to a third-party supplier, risking sensitive personal data.
RingCentral Data Breach Exposes 1.6M Users to ShinyHunters
RingCentral data breach impacts 1.6 million users after a sophisticated social engineering attack by ShinyHunters. Names, emails, addresses, and phone numbers exposed.
ShinyHunters Breaches ShipMonk: 14,000 Trezor Customers' Data Exposed
ShinyHunters group breached shipping provider ShipMonk, exposing personal data of 14,000 Trezor customers via a Metabase SQL injection vulnerability.
Data Analyst Sentenced to Prison for Extorting Brightly Software
A former data analyst contractor was sentenced to two years in prison for orchestrating a $2.5 million cryptocurrency extortion scheme against Brightly.
City-Forum Data Theft Targets Salesforce and ServiceNow Portals
City-Forum data theft attacks target misconfigured Salesforce and ServiceNow portals, exploiting overly permissive guest access rules.
Wesco Confirms Cloud CRM Incident After ExfilSquad Data Leak
Wesco confirms a cloud CRM security incident as ExfilSquad claims theft of 2.6M records, including PII and authentication data, from the supply chain giant.
Swiss Government SharePoint Breach: 200 Accounts Compromised
Switzerland's federal IT office confirms a Microsoft SharePoint breach compromised approximately 200 accounts, leading to a swift remediation.
Metabase Zero-Day Exploited: Unauthenticated Admin Access
Metabase zero-day vulnerability (CVSS 10.0) actively exploited, allowing unauthenticated remote attackers to gain admin access and steal data.
Metabase SQLi Zero-Day Exploited: Data Theft Attacks Confirmed
A critical Metabase SQL injection zero-day vulnerability (versions 1.58+) has been exploited in data theft attacks affecting customers like Framework and Tally.
Unlimited Technology Systems Data Breach Exposes 3.8M Records
Unlimited Technology Systems disclosed a data breach exposing PII and PHI of 3.8 million individuals, including Social Security numbers.
Canadian Threat Actor Pleads Guilty in Snowflake Extortions
Connor Riley Moucka pleaded guilty to computer fraud and extortion involving 165 Snowflake client organizations and AT&T customer records.
Snowflake Hacker Pleads Guilty: Analyzing the UNC5537 Data Breach
Hacker pleads guilty in UNC5537 Snowflake data breach, compromising 165 organizations and millions of records via stolen credentials.
Amgen Cloud Data Breach: Patient Health and Proprietary Data Exposed
Amgen confirms a data breach exposed patient health and corporate data stored in third-party cloud systems. Understand the impact and mitigation.