Tag: data-breach
-
295 Malicious IPs Launch Coordinated Brute-Force Attacks on Apache Tomcat Manager
Threat intelligence firm GreyNoise has warned of a “coordinated brute-force activity” targeting Apache Tomcat Manager interfaces.The company said it observed a surge in brute-force and login attempts on June 5, 2025, an indication that they could be deliberate efforts to “identify and access exposed Tomcat services at scale.”To that end, 295 unique IP addresses have…
-
Brute-force attacks target Apache Tomcat management panels
A coordinated campaign of brute-force attacks using hundreds of unique IP addresses targets Apache Tomcat Manager interfaces exposed online. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/brute-force-attacks-target-apache-tomcat-management-panels/
-
Half of Mobile Users Now Face Daily Scams
Malwarebytes claims 44% of mobile users are exposed to scams every day First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/half-of-mobile-users-now-face/
-
DanaBot malware operators exposed via C2 bug added in 2022
A vulnerability in the DanaBot malware operation introduced in June 2022 update led to the identification, indictment, and dismantling of their operations in a recent law enforcement action. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/danabot-malware-operators-exposed-via-c2-bug-added-in-2022/
-
300K Crash Reports Stolen in Texas DOT Hack
Crash Records and Driver Data Exposed in Texas Transportation Hack. Hackers accessed the Texas Department of Transportation’s crash records system using a compromised account, stealing nearly 300,000 reports containing personal and vehicle information that could be used for fraud, the department warned in a letter to impacted individuals. First seen on govinfosecurity.com Jump to article:…
-
Texas Department of Transportation (TxDOT) data breach exposes 300,000 crash reports
Hackers breached Texas DOT (TxDOT), stealing 300,000 crash reports with personal data from its Crash Records Information System (CRIS). Threat actors compromised the Crash Records Information System (CRIS) from the Texas Department of Transportation (TxDOT) and stole 300,000 Crash Reports. The Texas Department of Transportation is a state agency that manages Texas’s transportation systems. It…
-
Ticketmaster data obtained from Snowflake hack momentarily leaked
First seen on scworld.com Jump to article: www.scworld.com/brief/ticketmaster-data-obtained-from-snowflake-hack-momentarily-leaked
-
Sensata warns of ransomware-related data breach
First seen on scworld.com Jump to article: www.scworld.com/brief/sensata-warns-of-ransomware-related-data-breach
-
Texas Dept. of Transportation breached, 300k crash records stolen
The Texas Department of Transportation (TxDOT) is warning that it suffered a data breach after a threat actor downloaded 300,000 crash records from its database. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/texas-dept-of-transportation-breached-300k-crash-records-stolen/
-
AI is a data-breach time bomb, reveals new report
AI acts like Pac-Man”, devouring sensitive data across clouds, apps, and copilots. Varonis analyzed 1,000 orgs and found 99% have exposed data AI can access, exposing them to data risks. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/ai-is-a-data-breach-time-bomb-reveals-new-report/
-
Mastery Schools Notifies 37,031 of Major Data Breach
A ransomware attack on Mastery Schools, Philadelphia, has compromised personal information of 37,031 individuals, exposing sensitive data First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/mastery-schools-data-breach/
-
Over 84,000 Roundcube Webmail Installations Exposed to Remote Code Vulnerabilities
Security researchers have identified a critical vulnerability in Roundcube Webmail that affects over 84,000 unpatched installations worldwide, according to data from The Shadowserver Foundation. The vulnerability, designated CVE-2025-49113, enables authenticated attackers to execute arbitrary code remotely and has already been exploited in targeted attacks potentially conducted by state actors. The vulnerability affects all Roundcube versions…
-
AI threats leave SecOps teams burned out and exposed
Security teams are leaning hard into AI, and fast. A recent survey of 500 senior cybersecurity pros at big U.S. companies found that 86% have ramped up their AI use in the … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2025/06/10/ai-powered-attacks-secops-teams/
-
Connected and exposed: Building a cyber future America can trust
First seen on scworld.com Jump to article: www.scworld.com/perspective/connected-and-exposed-building-a-cyber-future-america-can-trust
-
Data breach impacts Pennsylvanian law firm CML
First seen on scworld.com Jump to article: www.scworld.com/brief/data-breach-impacts-pennsylvanian-law-firm-cml
-
Optima Tax Relief data exposed by Chaos ransomware
First seen on scworld.com Jump to article: www.scworld.com/brief/optima-tax-relief-data-exposed-by-chaos-ransomware
-
Can Online Casino Accounts Be Hacked?
Online casino platforms are not immune to compromise, but the most successful breaches don’t happen through the front door. They happen when users bring bad habits to high-risk environments. For hackers, it’s rarely about breaking encryption, it’s about exploiting behavior. Exposed Credentials Still Drive Most Attacks The majority of online casino account breaches don’t start…
-
Limited Canva Creator Data Exposed Via AI Chatbot Database
A Chroma database operated by Russian AI chatbot startup My Jedai was found exposed online, leaking survey responses… First seen on hackread.com Jump to article: hackread.com/limited-canva-creator-data-expose-ai-chatbot-database/
-
Boards Leave CISOs Exposed to Legal Risks
Attorney Jonathan Armstrong Says Board Diversity Must Include Cybersecurity Skills. Many boards lack cybersecurity expertise, leaving CISOs exposed to legal risks. New fraud laws and AI regulations compound the challenge as security leaders struggle for boardroom support, said Jonathan Armstrong, partner at Punter Southall Law. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/boards-leave-cisos-exposed-to-legal-risks-a-28621
-
Sensata Technologies says personal data stolen by ransomware gang
Sensata Technologies is warning former and current employees it suffered a data breach after concluding an investigation into an April ransomware attack. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/sensata-technologies-says-personal-data-stolen-by-ransomware-gang/
-
Chrome extension privacy promises undone by hardcoded secrets, leaky HTTP
Extension code uses hardcoded credentials: Guo added that hardcoded credentials, such as API keys, secrets, and tokens, are exposed within popular extensions’ JavaScript, making them accessible to anyone who inspects the extension’s source code. For instance, Avast Online Security and Privacy and AVG Online Security extensions, aimed at browsing privacy and security, both contain hardcoded Google…
-
Cloud assets have 115 vulnerabilities on average, some several years old
Tags: access, ai, api, attack, cloud, credentials, data, data-breach, github, gitlab, iam, infrastructure, risk, service, strategy, threat, vulnerabilityIsolated risks lead to bigger issues: Orca also warns that half of organizations have assets exposing attack paths that can lead to sensitive data exposure, as well as 23% with paths that lead to broad permission access and compromised hosts. Attack paths are the combination of risks that appear isolated but can be combined to…
-
Ein pragmatischer Ansatz – Bereit sein fürs Worst-Case-Szenario bei sensiblen Datenlecks
Tags: data-breachFirst seen on security-insider.de Jump to article: www.security-insider.de/datenlecks-worst-case-a-b9140657beda574ae166803d67adf036/
-
Experts found 4 billion user records online, the largest known leak of Chinese personal data from a single source
Over 4 billion user records were found exposed online in a massive breach, possibly linked to the surveillance of Chinese citizens. Cybersecurity researcher Bob Dyachenko and the Cybernews team discovered a massive data leak in China that exposed billions of documents, including financial, WeChat, and Alipay data, likely affecting hundreds of millions. Researchers speculate data…
-
Expanding Bitter APT operation exposed
First seen on scworld.com Jump to article: www.scworld.com/brief/expanding-bitter-apt-operation-exposed
-
Popular Chrome Extensions Found Leaking Data via Unencrypted Connections
Popular Chrome extensions exposed user data by sending it over unencrypted HTTP, raising privacy concerns. Symantec urges caution for users. First seen on hackread.com Jump to article: hackread.com/popular-chrome-extensions-data-leak-unencrypted-connection/
-
Tax resolution firm Optima Tax Relief hit by ransomware, data leaked
U.S. tax resolution firm Optima Tax Relief suffered a Chaos ransomware attack, with the threat actors now leaking data stolen from the company. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/tax-resolution-firm-optima-tax-relief-hit-by-ransomware-data-leaked/
-
Colossal breach exposes 4B Chinese user records in surveillance-grade database
Tags: breach, china, cybercrime, cybersecurity, data, data-breach, disinformation, exploit, finance, fraud, group, identity, infrastructure, insurance, intelligence, iphone, leak, mobile, organized, phishing, phone, threataccording to cybersecurity firm Cybernews, which reported its findings based on its own research.What makes this breach particularly alarming isn’t just its size, though at four billion records, it’s believed to be the largest single-source leak of Chinese personal data ever found, it’s the breadth and depth of information that was exposed.According to the report, the researchers stumbled…
-
Why Most Exposed Secrets Never Get Fixed
Our latest State of Secrets Sprawl 2025 research reveals a troubling reality: the majority of leaked corporate secrets found in public code repositories continue to provide access to systems for years after their discovery. First seen on securityboulevard.com Jump to article: securityboulevard.com/2025/06/why-most-exposed-secrets-never-get-fixed/
-
Millions of pilfered AT&T records exposed
First seen on scworld.com Jump to article: www.scworld.com/brief/millions-of-pilfered-att-records-exposed

