Tag: data-breach
-
Electronic health record company CareCloud says 3.7 million people affected by breach
Healthcare software firm CareCloud filed documents with the Department of Health and Human Services confirming that 3,756,469 people had information leaked after a hacker spent eight hours in one of the company’s electronic health record environments. First seen on therecord.media Jump to article: therecord.media/electronic-health-record-company-carecloud-data-breach
-
Inside Operation CameraSwarm: How One Actor Took Over 14,000 Dahua Cameras
An exposed operator directory reveals how one actor compromised 14,000+ Dahua cameras across Ukraine and Russia, no password needed for most. A researcher discovered an exposed directory containing the tools of an attacker who compromised more than 14,000 Dahua cameras between June 17 and July 22, 2026, mainly in Ukraine and Russia. Hunt.io reconstructed the…
-
Blinde Flecken bei der Absicherung von KI-Rechenzentren
TrendAI veröffentlicht den Report ‘An Invisible Attack Surface: Thousands of Industrial Control Systems Exposed Near Data Centers”. Die Untersuchung zeigt: Während die Server von KI-Rechenzentren mit leistungsstarken Firewalls und Zero-Trust-Architekturen gesichert werden, bleibt eine andere Angriffsfläche oft unbeachtet die physische Gebäudetechnik, die Kühlung, Stromversorgung und Klimaregelung steuert. Forscher von TrendAI fanden 6.300 solcher Systeme, […]…
-
CareCloud confirms 3.7M patients had their medical records stolen in data breach
The cyberattack at CareCloud resulted in one of the largest reported data breaches in the U.S. healthcare industry this year. First seen on techcrunch.com Jump to article: techcrunch.com/2026/08/19/carecloud-confirms-3-7m-patients-had-their-medical-records-stolen-in-data-breach/
-
Hackers Compromised 14,500+ Dahua Devices Using Credential Attacks, Auth Bypasses, and P2P
Cybersecurity researchers at Hunt.io have disclosed details of a campaign that they say compromised more than 14,530 Dahua devices between June 17 and July 22, 2026, using credential attacks, two authentication-bypass flaws, and a peer-to-peer (P2P) relay technique.The activity, codenamed Operation CameraSwarm, was reconstructed from a 407 MB exposed working directory containing 2,616 files First…
-
Reverse-Lookup Service Exposed Millions of Photos of People’s Faces
The people-search tool ClarityCheck says its reverse image search service is “private and secure””, but it left a database containing more than 9 million image files exposed. First seen on wired.com Jump to article: www.wired.com/story/reverse-lookup-service-exposed-millions-of-photos-of-peoples-faces/
-
659 Stripe Merchant API Keys Leaked Online, Exposing 688,000 Customer Records
A data leak published on a cybercrime data-trading forum has exposed live Stripe API credentials for 659 merchant accounts, along with approximately 35 GB of customer- and payment-related data. The exposure affects an estimated 688,363 customer records across merchants in 42 countries, but available evidence indicates that Stripe’s own infrastructure was not breached. The dataset…
-
Cursor 0-Day Lets Attackers Execute Malicious Code by Opening a Repository
A recently disclosed security issue in Cursor IDE exposed a serious Windows binary-planting vulnerability that could allow malicious code to execute simply by opening an untrusted repository. This flaw, tracked as CVE-2026-63093, relates to Cursor’s executable resolution behavior and demonstrates how files controlled by attackers placed in a workspace could be executed with the current…
-
50,000 Stripe Secrets Leaked in Public Code
Over 50,000 exposed Stripe API keys show how leaked secrets can enable fraud, data access and account abuse within hours. Ransomnews researchers have documented a large-scale leak of Stripe merchant API keys found exposed in public code repositories, GitHub Actions logs, and misconfigured web servers, with over 50,000 unique keys identified in total. The research…
-
Hackers Expose Data of 1.2 Million Heights Finance Customers
A Heights Finance breach exposed personal and financial data of over 1.2 million people after hackers compromised a third-party cloud platform. Heights Finance is a U.S. consumer finance company that provides personal loans and related lending services, mainly to customers who may have limited access to traditional bank credit. It is part of Heights Finance…
-
Why Secrets Slip Through Every Layer of Your Security Stack
Your security stack is a set of specialists, each guarding one territory. Exposed credentials don’t respect the boundaries between them, and 64% of the ones found valid in 2022 were still valid four years later. First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/08/why-secrets-slip-through-every-layer-of-your-security-stack/
-
BTMob Uses Custom Phishing Apps to Turn Android Users Into Remote-Controlled Fraud Victims
BTMOB has evolved beyond a conventional Android banking trojan into a turnkey fraud platform that lets criminals build branded phishing apps, remotely operate infected phones, and automate theft. Its emergence illustrates how leaked malware source code and low-code tooling are turning mobile fraud into a scalable franchise. The malicious lnat-tv-pro.apk sample connected to server[.]yaarsa[.]com/con over…
-
The AI Factory’s Blind Spot Is Trust: Why Confidential AI Is the Missing Infrastructure Layer
AI factories promise scalable enterprise AI, but traditional security leaves sensitive data and model weights exposed during processing. Confidential AI closes the gap by protecting data in use with hardware isolation, encryption and cryptographic attestation. First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/08/the-ai-factorys-blind-spot-is-trust-why-confidential-ai-is-the-missing-infrastructure-layer/
-
SafePal Hardware Wallet Maker Says Flaw Exposed Data of Nearly 40,000 Customers
SafePal has disclosed that an authorization flaw in an order-tracking plug-in exposed the names, email addresses, shipping addresses, phone numbers, and purchase details of approximately 39,798 customers.The hardware wallet maker said all affected customers were notified individually by email on August 16 from security@safepal.com, with the subject line “[Important] Your SafePal Order First seen on…
-
Operation ASTERIX Uses Vishing and Fake Crypto Wallet Apps to Steal Seed Phrases
Operation ASTERIX, a cryptocurrency fraud campaign that combined account enumeration, branded phishing, targeted voice calls, and trojanized wallet software to capture victims’ recovery phrases. The campaign’s exposed operational server also revealed an unusually detailed view of how the operator incorporated AI coding tools into active fraud development. Named after the Asterisk telephony platform found on…
-
Operation ASTERIX Uses Vishing and Fake Crypto Wallet Apps to Steal Seed Phrases
Operation ASTERIX, a cryptocurrency fraud campaign that combined account enumeration, branded phishing, targeted voice calls, and trojanized wallet software to capture victims’ recovery phrases. The campaign’s exposed operational server also revealed an unusually detailed view of how the operator incorporated AI coding tools into active fraud development. Named after the Asterisk telephony platform found on…
-
Operation ASTERIX Uses Vishing and Fake Crypto Wallet Apps to Steal Seed Phrases
Operation ASTERIX, a cryptocurrency fraud campaign that combined account enumeration, branded phishing, targeted voice calls, and trojanized wallet software to capture victims’ recovery phrases. The campaign’s exposed operational server also revealed an unusually detailed view of how the operator incorporated AI coding tools into active fraud development. Named after the Asterisk telephony platform found on…
-
VMware vCenter RCE Gives Attackers a Path From One Appliance to Entire Virtual Infrastructure
Tags: cve, cyber, data-breach, exploit, infrastructure, rce, remote-code-execution, vcenter, vmware, vulnerabilityA critical VMware vCenter vulnerability is being actively exploited in a fast-moving campaign that turns a single exposed management appliance into a launch point for broad virtual-infrastructure compromise. Incident responders at QUIRSO linked the activity to exploitation of CVE-2026-59310, while identifying a separate, possibly unrelated track involving CVE-2026-59309. CVE-2026-59310 is a directory-traversal vulnerability in the…
-
Pokémon Center Data Breach Exposes Customers’ Personal and Order Data
Pokémon Center has begun notifying customers in the United Kingdom and Germany that personal information from their online orders was exposed following a cyberattack on CEVA Logistics, its third-party fulfillment partner. The retailer clarified that the incident did not originate from Pokémon Center’s own systems or website. Instead, attackers compromised the systems CEVA uses to…
-
SafePal warns of data breach affecting nearly 40,000 customers
First seen on scworld.com Jump to article: www.scworld.com/brief/safepal-warns-of-data-breach-affecting-nearly-40000-customers
-
SafePal Warns of Phishing Risk After Data Exposure Hits Nearly 40,000 Customers
SafePal says a security flaw exposed personal and order information for nearly 40,000 customers, increasing the risk of targeted phishing attacks. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/cybersecurity-threats/news-safepal-data-breach-40000-customers/
-
Nearly 750k had financial info, SSNs leaked in South Carolina loan company breach
The breach affected anyone who received a loan through the company or inquired about a loan product through a third party. First seen on therecord.media Jump to article: therecord.media/financial-info-leak-debt-consolidator
-
SafePal Says 39,798 Customers Hit by Data Breach
SafePal says a breach exposed personal data of 39,798 customers, but not wallet credentials, private keys, seed phrases, or payment information. SafePal disclosed a data breach affecting about 39,798 customers after hackers exploited a vulnerability in its order-tracking plugin. The flaw exposed information linked to orders placed between March 2, 2025, and April 11, 2026,…
-
French Tax Authority Data Breach Exposes Information of 678,000 People
A breach of France’s tax authority exposed sensitive tax, business, and property data belonging to 678,000 people. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/threats/french-tax-authority-data-breach-exposes-information-of-678000-people/
-
Pokémon Center data breach exposes customer info, cancels some orders
Pokémon Center is notifying customers in the United Kingdom and Germany that it suffered a third-party data breach after hackers stole customer personal and order information from third-party logistics provider CEVA Logistics. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/pokemon-center-data-breach-exposes-customer-info-cancels-some-orders/
-
LiteLLM Supply-Chain Attack Technology, Banking and Healthcare the Most Affected
Tags: attack, backdoor, banking, credentials, cybersecurity, data-breach, finance, healthcare, supply-chain, technologyThe SANDCLOCK LiteLLM supply-chain attack exposed credentials across 2,038 repositories, affecting technology, finance, healthcare, retail and more. Resecurity (USA) estimated the most affected sectors by the “SANDCLOCK” backdoor, which was planted as a result of the code repository compromise. According to cybersecurity experts, LiteLLM / TeamPCP Supply-Chain Attack will have long-lasting consequences. By compromising a…
-
Nearly 700,000 French Taxpayer Records Reportedly Stolen in Government Cyberattack
France’s tax authority confirmed a cyberattack exposed taxpayer data as officials investigate the breach’s scope and an unverified 678,000-record claim. The post Nearly 700,000 French Taxpayer Records Reportedly Stolen in Government Cyberattack appeared first on TechRepublic. First seen on techrepublic.com Jump to article: www.techrepublic.com/article/news-france-tax-authority-cyberattack-taxpayer-data-emea/
-
SafePal latest crypto hardware wallet maker affected by breach, with nearly 40,000 impacted
The crypto hardware wallet company SafePal confirmed a data breach on Sunday, telling users that nearly 40,000 customers had information stolen during a recent security incident. First seen on therecord.media Jump to article: therecord.media/safepal-crypto-hardware-breach
-
SafePal latest crypto hardware wallet maker affected by breach, with nearly 40,000 impacted
The crypto hardware wallet company SafePal confirmed a data breach on Sunday, telling users that nearly 40,000 customers had information stolen during a recent security incident. First seen on therecord.media Jump to article: therecord.media/safepal-crypto-hardware-breach
-
Major genetic-testing firm says hack compromised sensitive patient data
The June breach, which also exposed employees’ information, underscored the supply-chain risks facing the healthcare sector. First seen on cybersecuritydive.com Jump to article: www.cybersecuritydive.com/news/baylor-genetics-cyberattack-compromise-patient-data-genetic-testing/828019/

