Tag: data-breach
-
Why Most Exposed Secrets Never Get Fixed
Our latest State of Secrets Sprawl 2025 research reveals a troubling reality: the majority of leaked corporate secrets found in public code repositories continue to provide access to systems for years after their discovery. First seen on securityboulevard.com Jump to article: securityboulevard.com/2025/06/why-most-exposed-secrets-never-get-fixed/
-
Millions of pilfered AT&T records exposed
First seen on scworld.com Jump to article: www.scworld.com/brief/millions-of-pilfered-att-records-exposed
-
Breach Roundup: Ukraine Hacks Russian Warplane Maker
Also, Crypter Takedown, Threat Intel Naming Accord and Regulators Ping CrowdStrike. This week, Ukraine hacked Tupelov, Russian hacking, crypter sites seized and the U.S. will seize North Korean IT worker crypto. Regulators probed CrowdStrike. A Rosetta Stone for intel. A Romanian man admitted to swatting, Lee Enterprises hack exposed data and an FBI vet joined…
-
AT&T Hit by Massive Reported Identity Data Leak – Again
Leaked Records Include Names, Decrypted Social Security Numbers and Addresses. Hackers have seemingly re-released a refined trove of 86 million AT&T records, including decrypted Social Security numbers and full identity data, heightening the risk of fraud and impersonation for tens of millions of users as researchers cite structural improvements in the dataset. First seen on…
-
Yet Another Exposed Database, This Time with 184 Million Records
I had hoped by now we’d be long past the discovery of exposed or misconfigured databases, considering how dangerous they can be to businesses, governments and individuals”, and given the heightened security measures that most organizations have implemented to secure sensitive data and prevent such exposure. But here we are again”, and this time the…
-
Banking groups urge SEC to rescind Biden-era cybersecurity rule
The rule has exposed companies to liability risks while failing to provide investors with;“decision-useful” information, the coalition said in a recent letter. First seen on cybersecuritydive.com Jump to article: www.cybersecuritydive.com/news/banking-groups-urge-sec-rescind-breach-reporting-rule/749928/
-
Odoo Employee Database Allegedly Exposed and Put Up for Sale on Dark Web
A data breach has reportedly struck Odoo, a leading Belgian provider of open-source business management software. On June 5, 2025, a 63.4MB employee database”, allegedly sourced through a “collaborative effort with a senior insider””, was advertised for sale on a dark web forum. The seller is demanding $25,000 in Monero (XMR) or Bitcoin (BTC) for…
-
Interlock ransomware claims Kettering Health breach, leaks stolen data
The Interlock ransomware gang has claimed a recent cyberattack on the Kettering Health healthcare network and leaked data allegedly stolen from breached systems. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/interlock-ransomware-claims-kettering-health-breach-leaks-stolen-data/
-
IBM Cloud login breaks for second time this week and Big Blue isn’t saying why
To make matters worse, IBM’s security software has a critical vuln caused by an exposed password First seen on theregister.com Jump to article: www.theregister.com/2025/06/05/ibm_cloud_outage_critical_vulnerability/
-
35K Solar Devices Vulnerable to Potential Hijacking
A little more than three-quarters of these exposed devices are located in Europe, followed by Asia, with 17%. First seen on darkreading.com Jump to article: www.darkreading.com/vulnerabilities-threats/35k-solar-devices-internet-exposure-hijacking
-
Millions of US patient data exposed by MongoDB misconfiguration
First seen on scworld.com Jump to article: www.scworld.com/brief/millions-of-us-patient-data-exposed-by-mongodb-misconfiguration
-
Newspaper giant Lee Enterprises says nearly 40,000 Social Security numbers leaked in ransomware attack
Lee Enterprises notified regulators in Maine of the impact on customer data after a ransomware attack in February that caused significant disruptions. First seen on therecord.media Jump to article: therecord.media/newspaper-lee-enterprises-cyberattack-ssn
-
Vast array of solar power equipment left exposed online
The most commonly exposed device has been discontinued and vulnerable for a decade, new research found. First seen on cybersecuritydive.com Jump to article: www.cybersecuritydive.com/news/solar-equipment-exposed-vulnerable-forescout/749806/
-
Data breach at newspaper giant Lee Enterprises affects 40,000 people
The ransomware attack paralyzed newspaper printing and disrupted operations at media outlets across the country for weeks. First seen on techcrunch.com Jump to article: techcrunch.com/2025/06/04/data-breach-at-newspaper-giant-lee-enterprises-affects-40000-people/
-
Media giant Lee Enterprises says data breach affects 39,000 people
Publishing giant Lee Enterprises is notifying over 39,000 people whose personal information was stolen in a February 2025 ransomware attack. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/media-giant-lee-enterprises-says-data-breach-affects-39-000-people/
-
Coinbase Aware of Data Breach Since January, Report Reveals
Major Coinbase breach involving a significant customer data leak. Stay informed and protect your assets. Read more! First seen on securityboulevard.com Jump to article: securityboulevard.com/2025/06/coinbase-aware-of-data-breach-since-january-report-reveals/
-
Nearly 3,000 North Face website customer accounts breached as retail incidents continue
The parent company of apparel brand The North Face sent data breach notification letters to about 3,000 customer accounts, saying attackers used the technique known as credential stuffing. First seen on therecord.media Jump to article: therecord.media/north-face-customer-accounts-data-breach-notification
-
Malicious PyPI, npm, and Ruby Packages Exposed in Ongoing Open-Source Supply Chain Attacks
Several malicious packages have been uncovered across the npm, Python, and Ruby package repositories that drain funds from cryptocurrency wallets, erase entire codebases after installation, and exfiltrate Telegram API tokens, once again demonstrating the variety of supply chain threats lurking in open-source ecosystems.The findings come from multiple reports published by Checkmarx, First seen on thehackernews.com…
-
35,000 Internet-Connected Solar Power Systems Vulnerable to Cyberattacks
Forescout Research Vedere Labs has uncovered that nearly 35,000 solar power devices, including inverters, data loggers, and gateways from 42 vendors, are exposed on the internet with vulnerable management interfaces. Identified using the Shodan search engine, these devices represent a critical cybersecurity risk to global power grids, especially as renewable energy sources like solar power…
-
Threat Actor Bribes Overseas Support Agents to Steal Coinbase Customer Data
On May 15, 2025, Coinbase, the largest U.S. cryptocurrency exchange, publicly disclosed a major security breach that exposed the sensitive personal data of 69,461 users”, less than 1% of its monthly transacting base, but a significant figure given the depth of information compromised. This incident was not a typical crypto hack exploiting blockchain vulnerabilities; instead,…
-
Cartier disclosed a data breach following a cyber attack
Luxury-goods conglomerate Cartier disclosed a data breach that exposed customer information after a cyberattack. Cartier has disclosed a data breach following a cyberattack that compromised its systems, exposing customers’ personal information. The incident comes amid a wave of cyberattacks targeting luxury fashion brands. The luxury firm states that the threat actors gained access to >>limited…
-
Datenleck bei Unterwegs: Großer Outdoor-Shop bestätigt Cyberangriff
Ein Cyberangriff auf den Unterwegs Outdoor Shop betrifft die Daten zahlreicher Kunden. Passwörter für den Onlineshop sind vorsorglich zurückgesetzt worden. First seen on golem.de Jump to article: www.golem.de/news/datenleck-bei-unterwegs-grosser-outdoor-shop-bestaetigt-cyberangriff-2506-196821.html
-
Bevor es ‘knallt”: Wie DataContainment Angriffe stoppt, bevor sie eskalieren
Ransomware-Angriffe verdoppeln sich, Erkennungszeiten bleiben erschreckend lang und trotzdem setzen viele Unternehmen noch immer auf reaktive Sicherheit. Dabei liegt der Schlüssel zur Cyber-Resilienz längst in der proaktiven Eindämmung. Wie Data-Breach-Containment zur tragenden Säule moderner IT-Sicherheitsarchitekturen wird durch Mikrosegmentierung, automatische Isolierung und eine kompromisslose Zero-Trust-Strategie. First seen on itsicherheit-online.com Jump to article: www.itsicherheit-online.com/news/security-management/bevor-es-knallt-wie-data-breach-containment-angriffe-stoppt-bevor-sie-eskalieren/
-
Datenschutzvorfall bei Unterwegs Outdoor Shop GmbH (Mai 2025)
Kurze Information für Blog-Leser, die Kunden der Unterwegs Outdoor Shop GmbH sind. Diese informiert gerade, dass man im Mai 2025 einen Datenabfluss hatte. Bei einem Cyberangriff auf die IT-Systeme des Unternehmens kam es zu einem Datenschutzvorfall nach Art. 34 DSGVO, … First seen on borncity.com Jump to article: www.borncity.com/blog/2025/06/04/datenschutzvorfall-bei-unterwegs-outdoor-shop-gmbh/
-
Code Bug at Compliance Firm Vanta Leaks Customer Data to Other Clients
Compliance automation provider Vanta confirms a software bug exposed private customer data to other users, impacting hundreds of… First seen on hackread.com Jump to article: hackread.com/code-bug-compliance-vanta-data-leak-customer-clients/
-
Coinbase breach tied to bribed TaskUs support agents in India
A recently disclosed data breach at Coinbase has been linked to India-based customer support representatives from outsourcing firm TaskUs, who threat actors bribed to steal data from the crypto exchange. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/coinbase-breach-tied-to-bribed-taskus-support-agents-in-india/
-
What Tackling the SaaS Security Problem Means to Me
By Kevin Hanes, CEO of Reveal Security When I reflect on the years I spent leading one of the world’s largest Security Operations Centers (SOCs) and incident response teams, the lessons learned aren’t just war stories”¦they’re a playbook for how we should rethink our responsibilities in the face of today’s fast-evolving attack surfaces. Back then,…
-
Posture ≠Protection
CSPM, DSPM, ASPM, SSPM, ESPM, the alphabet soup of Security Posture Management (SPM) tools promises visibility into risk. They map misconfigurations, surface exposure paths and highlight policy gaps. That can be useful. But let’s not confuse awareness with action. They don’t block threats.They don’t enforce controls.They don’t prevent breaches. SPMs detect, then delegate. A ticket.…

