§Topic · Data Breaches
Data Breaches
Major data breaches, exposure incidents, credential leaks, and regulatory disclosures from the past week.
All dispatches
Loading
§Topic · Data Breaches
Major data breaches, exposure incidents, credential leaks, and regulatory disclosures from the past week.
All dispatchesOrigin Energy confirms a breach affecting roughly 2 million customers, with threat actor claiming stolen customer data.
Qilin ransomware exploits critical Palo Alto PAN-OS GlobalProtect authentication bypass to breach networks and deploy ransomware.
Unknown attackers compromised South Korea's diplomatic academy training system for nine months, exfiltrating personal data of ministry staff.
Attackers exploited Oracle E-Business Suite zero-day to exfiltrate personal, financial and health information from Este9e Lauder systems.
Social-engineering attack compromised employee accounts exposing personal and health information at Clover Health Investments.
Autonomous agent breached Hugging Face, accessing internal datasets and some credentials, signaling new AI-agent threat vectors.
Newsletter aggregates multiple incidents including EY breach, wp2shell exploit, and numerous high-impact patches and breaches.
NadMesh botnet scans Shodan for exposed AI services, harvesting cloud keys and Kubernetes tokens to hijack model-serving infrastructure.
EY discloses breach of a third-party support ticket system, with client tax documents accessed and downloaded.
Directory listing on misconfigured server exposed three Evilginx phishing operations that bypass MFA to target Microsoft 365 users.
AsyncAPI packages were trojanized after attacker stole an npm publishing token via GitHub Actions, risking developer and CI compromise.
Miasma v3 delivered via trojanized AsyncAPI packages creates persistent backdoors on developer machines and build servers.
Retailer Lidl notifies customers after a third-party supplier breach exposed stored customer data hosted externally.
Finnish authorities issue wanted notice for suspect in massive psychotherapy provider Vastaamo breach that exposed sensitive patient records.
Investigation reveals ransomware negotiation firm leaked victims' insurance and strategy to attackers, undermining incident response trust and outcomes.
Threat group O UNC 066 uses phone-based phishing to trick employees into registering attacker-controlled Entra passkeys to hijack accounts.
Vulnerabilities in cloud-connected baby monitors and cameras exposed nearly one million devices and private video data.
Get these articles delivered to your inbox.
Subscribe free