Tag: data-breach
-
LiteLLM Supply-Chain Attack Exposed Credentials Across 2,500 Organizations
Malicious LiteLLM releases may have exposed credentials from more than 2,500 organizations and hundreds of thousands of CI/CD pipelines. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/cybersecurity-threats/news-litellm-supply-chain-attack-credential-theft/
-
CEVA Logistics Breach Triggers Customer Data Alerts Across Europe
CEVA Logistics’ data breach exposed customer and order information across European clients, raising phishing and third-party security concerns. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/cybersecurity/news-ceva-data-breach-emea-eu/
-
Mozilla updates GPG signing key for Firefox releases after exposure
Mozilla announced today that it updated the GPG key used to sign Firefox and Thunderbird releases after it was accidentally exposed on GitHub. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/mozilla-updates-gpg-key-for-signing-firefox-thunderbird-releases-after-exposure/
-
Logistics Giant Ceva Suffers Data Breach Impacting European Clients
Supply chain attack and data breach at Ceva Logistics appears to have a large blast radius First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/logistics-ceva-data-breach/
-
Locking your ssh-agent exposed local-only keys until OpenSSH 10.5
Tags: data-breachLock your ssh-agent and it should sit there refusing to sign anything until you unlock it. In OpenSSH 10.4, locking it also switched off the check that tells the agent whether … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/08/11/openssh-10-5-ssh-agent-flaw/
-
CISA Urges Organizations to Patch Exposed VPNs and Segment Networks Against Gunra Ransomware
Tags: advisory, breach, cisa, credentials, cyber, data, data-breach, encryption, exploit, firewall, infrastructure, international, law, network, organized, ransomware, service, theft, update, vpnCISA and international law-enforcement partners have issued a joint #StopRansomware advisory warning that Gunra ransomware affiliates are exploiting exposed edge infrastructure, including VPN gateways, firewall appliances and RDP-accessible systems, to breach enterprise networks. The advisory positions Gunra as an increasingly organized ransomware-as-a-service operation whose affiliates combine data theft, credential compromise and rapid encryption to pressure…
-
Multistate Water System Attacks Widen, Iran Suspected
Attacks targeting water systems just keep flowing across a dozen states, against ill-secured, Internet-exposed PLCs. First seen on darkreading.com Jump to article: www.darkreading.com/ics-ot-security/multistate-water-system-attacks-widen-iran-suspected
-
Klaviyo Sign-Up Bug May Have Exposed Passwords to Ad Trackers
Klaviyo says fewer than 200 people are known to be affected by a sign-up bug that may have exposed passwords to third-party trackers. The post Klaviyo Sign-Up Bug May Have Exposed Passwords to Ad Trackers appeared first on TechRepublic. First seen on techrepublic.com Jump to article: www.techrepublic.com/article/news-klaviyo-sign-up-password-tracker-exposure/
-
DEF CON 34: One Pyodide Flaw Exposed Seven Products
DEF CON 34 research exposed Pyodide sandbox flaws affecting seven products and potentially exposing sensitive host resources. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/threats/def-con-34-one-pyodide-flaw-exposed-seven-products/
-
Claude-Powered Agent Exploits Australian Gym API, Removes Waitlisted Member
A Claude-powered AI agent exploited an Australian gym API flaw, removed a member from a waitlist, and exposed new risks from autonomous agents. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/threats/news-claude-ai-agent-australian-gym-api-flaw-apac/
-
A data breach at shipping giant Ceva Logistics is rippling across banks, retailers, Steam gamers, and beyond
Companies that rely on Ceva Logistics for shipping their physical goods to customers say their personal data was taken during a recent cyberattack. First seen on techcrunch.com Jump to article: techcrunch.com/2026/08/10/a-data-breach-at-shipping-giant-ceva-logistics-is-rippling-across-banks-retailers-steam-gamers-and-beyond/
-
Cyberattack on Steam hardware shipper leaks names, addresses, and order data
Video game publisher Valve is alerting customers in Europe to a data breach at CEVA Logistics, its Steam hardware shipping partner. Reports from affected customers began … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/08/10/valve-data-breach-ceva-logistics-steam-hardware/
-
Metabase zero-day exploited to access Framework customer data
Framework, the San Francisco-based company that designs repairable and upgradeable laptops, has suffered a data breach after attackers managed to exploit a zero-day … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/08/10/metabase-zero-day-framework-tally-kilo-code/
-
New Passkey Attacks Can Recover Synced Private Keys or Bypass Phishing-Resistant MFA
Tags: attack, authentication, cloud, cryptography, data-breach, malware, mfa, passkey, password, phishing, windowsThree separate research efforts last week demonstrated ways to defeat passkey protections without breaking the cryptography they rest on.Passkeys are designed to replace reusable passwords and resist phishing. The attacks instead reused signed authentication material that Windows had exposed, abused a cloud-synced passkey system from malware already on the victim’s machine, and used a First…
-
Valve notifies Steam hardware customers of a data breach
Video game publisher and digital distribution giant Valve is notifying Steam hardware customers in Europe that hackers stole their data after hacking its shipping partner, CEVA Logistics. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/valve-notifies-steam-hardware-customers-of-a-data-breach/
-
U.S. Defense Manufacturer IEH Hit by Phishing Attack, Exposing Potentially Export-Controlled Data
IEH was breached by a phishing attack that exposed its Microsoft 365 inbox, including emails and potentially export-controlled military data. IEH Corporation is a U.S. defense and aerospace manufacturer based in Brooklyn, New York. The company specializes in high-reliability electrical connectors, particularly hyperboloid connectors used in demanding military and aerospace environments. Its connectors are used…
-
Unlimited Technology Systems Data Breach Exposes Data of 3.8 Million Healthcare Patients
Hackers stole personal, medical, and insurance data of 3.8 million people from Unlimited Technology Systems’ data center. Unlimited Technology Systems disclosed a data breach affecting more than 3.8 million people after hackers accessed one of its commercial data centers between October 5 and 10, 2025. Unlimited Technology Systems is a U.S.-based healthcare technology company headquartered…
-
Critical macOS RCE Vulnerability Allows Attackers to Gain Root Access Without Password
Tags: access, apple, cve, cyber, data-breach, flaw, macOS, password, rce, remote-code-execution, update, vulnerabilityApple has shipped emergency macOS updates to close a critical vulnerability in Screen Sharing, tracked as CVE-2026-65400, which allows unauthenticated remote attackers to execute arbitrary code and access files with root-level privileges. The flaw is especially severe on systems where Screen Sharing is exposed to the public internet. Apple’s August 6 releases macOS Tahoe 26.6.1,…
-
Practice Management Firm Notifies 3.8M of 2025 Breach
Ohio-Based Unlimited Technology Systems Serves Thousands of Medical Practices. Practice management and financial software firm Unlimited Technology Systems is notifying 3.8 million people of an October 2025 data theft. The third-party vendor hack currently ranks as the largest health data breach reported to federal regulators so far in 2026. First seen on govinfosecurity.com Jump to…
-
Snowflake Hacker Pleads Guilty After Breaches Exposed Data of at Least 100 Million People
A hacker tied to the 2024 Snowflake customer breaches pleaded guilty after attacks exposed data tied to at least 100 million people. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/threats/news-snowflake-hacker-guilty-data-breach/
-
Unlimited Technology Systems breach impacts 3.8 million people
Healthcare software company Unlimited Technology Systems reported that more than 3.8 million people were impacted by a data breach incident that occurred in October 2025. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/unlimited-technology-systems-breach-impacts-38-million-people/
-
ThreatLabz 2026 Report: Frontier AI and Enterprise Readiness
Tags: access, ai, attack, authentication, breach, cisa, ciso, control, credentials, cyberattack, data, data-breach, endpoint, exploit, flaw, governance, identity, Internet, kev, login, malicious, privacy, radius, resilience, strategy, switch, threat, update, vpn, vulnerability, zero-trustThe BreachIt was 9:14 AM when the CISO’s VPN connection momentarily dropped, something that normally wouldn’t cause any concern. What he couldn’t see was that attackers had already exploited a pre-authentication flaw in the VPN appliance itself, gaining access before any login ever occurred. From there, they extracted stored credentials, forged an identity as his…
-
ThreatLabz 2026 Report: Frontier AI and Enterprise Readiness
Tags: access, ai, attack, authentication, breach, cisa, ciso, control, credentials, cyberattack, data, data-breach, endpoint, exploit, flaw, governance, identity, Internet, kev, login, malicious, privacy, radius, resilience, strategy, switch, threat, update, vpn, vulnerability, zero-trustThe BreachIt was 9:14 AM when the CISO’s VPN connection momentarily dropped, something that normally wouldn’t cause any concern. What he couldn’t see was that attackers had already exploited a pre-authentication flaw in the VPN appliance itself, gaining access before any login ever occurred. From there, they extracted stored credentials, forged an identity as his…
-
Computer maker Framework notifies ‘all customers’ of a data breach
Framework told “all” of its customers that hackers accessed their names, email addresses, phone numbers, and physical addresses in a data breach. First seen on techcrunch.com Jump to article: techcrunch.com/2026/08/07/computer-maker-framework-notifies-all-customers-of-a-data-breach/
-
Agentic AI for Cyber Defenders: What Security Teams Built at Black Hat USA 2026
Tags: ai, automation, conference, control, credentials, cve, cyber, cybersecurity, data, data-breach, defense, detection, exploit, flaw, group, iam, intelligence, ISO-27001, mitigation, network, nvidia, offense, open-source, RedTeam, risk, skills, soc, technology, threat, tool, usa, vulnerabilityAgentic AI armed attackers first, but it also put real building power in defenders’ hands. Here’s what security practitioners built in two days at Black Hat USA 2026, and how the CyberAgents Exchange keeps that work compounding long after the event. Key takeaways Building defensive cybersecurity tooling no longer requires a developer. Agentic tooling drove…
-
AI-Assisted HTTP Terminator Finds Novel HTTP Desync Techniques and Apache Zero-Day
PortSwigger says HTTP Terminator, an artificial intelligence (AI)-assisted research system built by James Kettle, generated and proved new HTTP desynchronization techniques after exploring 30,000 candidate attack vectors.PortSwigger said a separate human-guided discovery cascade also exposed a zero-day in Apache Traffic Server. Kettle said HTTP Terminator tested 30,000 websites where scanning First seen on thehackernews.com Jump…
-
Updoc Data Breach Exposes Patient Contact Information Following Third-Party Security Incident
The Updoc data breach has raised fresh concerns about cybersecurity in Australia’s healthcare sector after the telehealth provider confirmed that an unauthorized third party may have accessed customer contact information through an external system. First seen on thecyberexpress.com Jump to article: thecyberexpress.com/updoc-data-breach/
-
1000 Best Google Dorks List (Google Hacking Guide) 2026
A Google dork is an advanced search query that combines Google’s search operators (such as site:, intitle:, inurl:, and filetype:) to surface information that is publicly indexed but hard to find through normal searching. Security professionals use Google dorking (also called Google hacking) for OSINT, reconnaissance, and to discover”, and fix”, their own exposed files,…
-
Hackers Target Internet-Exposed Rockwell PLCs in U.S. Water Systems
A coordinated cyber campaign targeting internet-facing programmable logic controllers (PLCs) has disrupted water and wastewater operations across the United States, raising concerns about the vulnerabilities in exposed operational technology (OT). These incidents highlight how publicly accessible industrial controllers can enable attackers to alter configurations, disrupt system visibility, and affect essential services. Hackers Target Internet-Exposed Rockwell…

