Coverage
Data Breaches
327 articles on breaches and ransomware
Advertisement

Microsoft Disrupts Fox Tempest Malware-Signing-as-a-Service Operation
Microsoft disrupts the Fox Tempest MSaaS operation which weaponized Artifact Signing to facilitate global ransomware attacks and compromise thousands of networks.

Grafana GitHub Breach: Source Code Exposed via TanStack npm Attack
Grafana Labs confirms a GitHub breach exposing internal source code following a TanStack npm supply chain attack. No customer production systems compromised.
GitHub Internal Repo Breach Claimed by TeamPCP – Code at Risk
GitHub investigates TeamPCP's claim of breaching internal repositories, potentially exposing 4,000 private codebases. Defenders must secure supply chains.

GitHub Investigates Claimed TeamPCP Breach of 4,000 Internal Repos
GitHub is investigating a potential breach of 4,000 internal repositories claimed by TeamPCP, highlighting the risk of source code leaks for enterprises.
DBIR 2026: Vulnerability Exploitation Now Top Breach Vector
Verizon's 2026 DBIR reveals vulnerability exploitation as the leading breach vector, surpassing credential theft. AI accelerates attacks, patching delays persist, and
Microsoft Disrupts MSaaS Operation Abusing Artifact Signing Service
Microsoft shuts down a malware-signing-as-a-service provider that leveraged fraudulent certificates to bypass security controls for ransomware groups.
Microsoft Disrupts Fox Tempest Malware Signing Service
Microsoft dismantled the Fox Tempest (Storm-1152) malware signing service, which issued over 10,000 fraudulent certificates to mask ransomware and other malware.
CISA Contractor Leaked AWS GovCloud Keys on GitHub: Critical Exposure
A CISA contractor publicly exposed highly privileged AWS GovCloud and internal system credentials on GitHub, detailing CISA's software development. This leak poses a
US Healthcare Data Breaches: Millions Impacted via Tracking Pixels
Millions of patient records were exposed in major healthcare breaches at Kaiser Permanente, City of Hope, and HealthEC due to tracking pixels and system access.
Grafana Labs Breach: Coinbase Cartel Claims Data Theft — Analysis
Grafana confirms a security breach after the Coinbase Cartel group claimed to have stolen sensitive data, including customer and infrastructure information.

Grafana GitHub Token Leak: Codebase Access and Extortion Attempt
Grafana discloses a security incident where an unauthorized party used a GitHub token to download source code, leading to a failed extortion attempt.
BlackFile: Analyzing UNC6671 Vishing & Cloud Data Extortion
Examines UNC6671's BlackFile vishing, AiTM, and cloud data exfiltration tactics against Microsoft 365 & Okta. Actionable mitigations included.