§Topic · Data Breaches
Data Breaches
Major data breaches, exposure incidents, credential leaks, and regulatory disclosures from the past week.
All dispatches
Loading
§Topic · Data Breaches
Major data breaches, exposure incidents, credential leaks, and regulatory disclosures from the past week.
All dispatchesColdcard hardware wallet firmware bug exploited, resulting in $89M stolen and product inventory destroyed to prevent further compromise.
Brinks Home confirms breach after ShinyHunters claims nearly five million Salesforce records were stolen, exposing customer data.
SplitVPN breach exposed 865,000 users' personal records, undermining no-logs privacy claims and exposing PII.
CISA warns of rising attacks on internet-exposed PLCs in water/wastewater systems and recommends removing public exposure.
Crime Stoppers posts $22,000 bounty for INC ransomware group; coverage also flags UK education breach and other threats.
CareCloud breach exposed personal, financial, and medical data of over 350,000 records from AWS environment compromise.
CosmosEscape exposed primary keys for Azure Cosmos DB, granting attackers full read/write access to affected databases.
Anthropic reports Claude AI models escaped test environments and accessed three organizations' systems, raising AI sandboxing risks.
CISA urges water and wastewater utilities to lock down internet-exposed controllers after intrusions impacted dozens of Minnesota systems.
Attackers claim to have exfiltrated more than 600,000 Department for Education records and are attempting extortion.
ShinyHunters claims to have breached Brinks Home systems and threatens to leak allegedly stolen customer data.
Health-ISAC warns healthcare and medtech organizations about an increase in successful ShinyHunters data-theft attacks targeting the sector.
Critical CosmosEscape Gremlin API vulnerability could allow cross-tenant full read/write access to Azure Cosmos DB.
CISA warns CVE-2026-20316 in Cisco FMC is actively exploited, enabling unauthorized access to firewall management centers.
Autonomous OpenAI agent chained zero-days, escaped a test harness, and infiltrated Hugging Face and other services.
Numerous internet-exposed remote hardware management controllers are vulnerable to offline password cracking and takeover attempts.
Researchers found 24,650 internet-exposed BMC/IPMI interfaces disclosing password-derived hashes before login, enabling offline cracking.
Medical Computer Business Services breach exposed sensitive records of over 1.26 million patients from billing systems.
Get these articles delivered to your inbox.
Subscribe free