§Topic · Data Breaches
Data Breaches
Major data breaches, exposure incidents, credential leaks, and regulatory disclosures from the past week.
All dispatches
Loading
§Topic · Data Breaches
Major data breaches, exposure incidents, credential leaks, and regulatory disclosures from the past week.
All dispatchesShell is investigating Cl0p's claim of exfiltrating 89GB of internal data amid an ongoing potential incident and extortion demand.
Gunra actors exploit Fortinet vulnerabilities to exfiltrate large volumes of Microsoft service data, targeting critical infrastructure.
Malicious LiteLLM PyPI releases contained credential-stealing code that may have exposed secrets for 2,100+ organizations.
CERT.PL reports Russian-linked hackers accessed a Polish power plant OT network via a private APN, impacting critical infrastructure.
BdThemes supply-chain compromise poisoned JSON feeds to create rogue WordPress admin accounts, backdooring sites without modifying plugin files.
Widening attacks against US water systems continue, targeting Internet-exposed PLCs; attribution reports suggest Iran-linked activity in some cases.
Critical vulnerabilities discovered in Belgian eID software put two million users at risk of identity compromise.
Ceva Logistics suffers supply-chain data breach, disrupting warehouse operations and impacting multiple European retail customers.
Levi Strauss suffered a breach after social-engineering of three employees gave attackers access to internal systems and data.
IEH Corporation disclosed a cyberattack affecting systems tied to military device manufacturing in an SEC filing.
SANS NewsBites flags exposed OT controllers after water attacks, Chinese telecoms' US presence, and OSAA's SAFE proposal for AI findings sharing.
Unlimited Technology Systems breach exposed personal, medical and health insurance information for about 3.8 million people.
Critical Metabase SQLi zero-day allows unauthenticated admin access and active data-theft; immediate mitigation required.
QuickFox supply-chain compromise trojanized Windows installer to deliver FDMTP backdoor in deployments since at least August 2025.
Forescout found 4,407 internet-exposed Rockwell PLCs worldwide, including 22 in cities impacted by recent water utility attacks.
Researchers disclosed factory-installed backdoor in Zbtlink routers enabling unauthenticated root shells and persistent beaconing.
Connor Riley Moucka admitted to compromising 165 Snowflake customer accounts and exposing data for over 100 million people.
Get these articles delivered to your inbox.
Subscribe free