Tag: data-breach
-
Estée Lauder Confirms Cyberattack Affecting Personal Information
The Estée Lauder data breach has prompted the global cosmetics company to notify affected individuals after hackers exploited a vulnerability in Oracle E-Business Suite, a platform used for human resources (HR) operations. First seen on thecyberexpress.com Jump to article: thecyberexpress.com/estee-lauder-data-breach-oracle-ebs/
-
Estée Lauder discloses data breach tied to Oracle EBS vulnerability
Cosmetics company Estée Lauder disclosed a data breach tied to a vulnerability in Oracle E-Business Suite (EBS) used for the company’s human resources operations. Estée … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/07/21/estee-lauder-data-breach-oracle-ebs/
-
Paidwork breach exposes sensitive data of 23 million users
Data belonging to more than 23 million users has been exposed following a breach at Paidwork, a platform that pays people for completing online microtasks. Paidwork markets … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/07/20/paidwork-data-breach-23-million-users/
-
Paidwork Data Breach Exposes 23.3 Million Accounts, Banking Data and bcrypt Password Hashes
Gig-economy platform Paidwork has been linked to a significant data breach that affects 23.3 million accounts. This breach, involving an approximately 11GB dataset, was publicly released in July 2026. The incident was added to the Have I Been Pwned (HIBP) breach database on July 19, with the compromise reportedly occurring in March 2026. Paidwork Data…
-
Estée Lauder discloses data breach via Oracle E-Business flaw
Cosmetics giant Estée Lauder is notifying customers of a data breach after hackers exploited a flaw in Oracle E-Business Suite that the company used for human resources (HR) operations. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/est-e-lauder-discloses-data-breach-via-oracle-e-business-flaw/
-
India says allegedly leaked nuclear plant files pose no safety risk
Documents that the World Leaks cybercrime group claimed to leak from the Kudankulam Nuclear Power Plant do not contain information pertaining to safety or security, Indian officials said. First seen on therecord.media Jump to article: therecord.media/india-nuclear-plant-kudankulam-world-leaks-documents
-
Exposed Server Reveals AI-Assisted Phishing Toolkit Behind WebDAV Malware Campaign
A malware operator left its delivery server wide open, and Rapid7 pulled down the whole toolkit: 1,048 files spanning lure templates, filename-spoofing tests, execution experiments, droppers, builder notes, and two campaign chains. One was already live against Windows users in Mexico, delivering an infostealer through a fake government ID-lookup site over WebDAV.What makes it more…
-
Paidwork breach exposes sensitive data of 23 million user
Data belonging to more than 23 million users has been exposed following a breach at Paidwork, a platform that pays people for completing online microtasks. Paidwork markets … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/07/20/paidwork-data-breach-23-million-users/
-
âš¡ Weekly Recap: WordPress RCE, SonicWall 0-Days, AI Service Attacks, SharePoint 0-Day and More
Tags: ai, attack, breach, data-breach, malware, rce, remote-code-execution, service, wordpress, zero-dayA single request should not be able to do this much. But this week, small inputs led to code execution, memory loss, stolen keys, and disabled security tools.The paths were often simple: exposed systems, weak checks, old drivers, fake prompts, and public code used for malware delivery. Some bugs were new. Others were already being…
-
20th July Threat Intelligence Report
Ernst & Young, a global accounting and professional services company, has disclosed a data breach involving a compromised third-party IT support platform. The exposed support tickets may have contained client documents, tax information, […] First seen on research.checkpoint.com Jump to article: research.checkpoint.com/2026/20th-july-threat-intelligence-report/
-
Microsoft Ends OneDrive Sync App Security Updates on Windows 10 21H2 and Earlier
Microsoft will stop delivering feature updates, bug fixes, and security patches for the OneDrive sync app on systems running Windows version 21H2 and earlier on August 15, 2026. This change was announced in the Microsoft 365 Message Center notification MC1426708 and leaves organizations with older Windows endpoints exposed to an increasingly unsupported file synchronization client,…
-
One Malicious Web Request Can Turn an Exposed SharePoint Server Into a Persistent Backdoor
Tags: advisory, backdoor, cisa, cyber, data-breach, exploit, malicious, microsoft, remote-code-execution, update, vulnerabilityA newly disclosed cluster of Microsoft SharePoint Server vulnerabilities is actively being exploited in the wild, allowing attackers to convert a single crafted web request into full remote code execution and long-term persistence across enterprise environments. Security updates released in July 2026, alongside a CISA advisory, confirm that multiple vulnerabilities are already being weaponized against…
-
Ernst Young (EY) Investigates Data Breach Involving Third-Party Support Tickets
Ernst & Young (EY) disclosed a data breach after attackers compromised a third-party IT support system containing client documents and tax information. Ernst & Young (EY) is disclosed a data breach linked to a compromised third-party support ticket system used by its IT teams. The platform stored support requests that may have included documents containing…
-
23andMe Agrees to $18M Settlement With 43 States Over 2023 Data Breach
23andMe will pay $18 million to settle claims from 43 states over its 2023 data breach, which exposed genetic information tied to nearly 7 million people. The post 23andMe Agrees to $18M Settlement With 43 States Over 2023 Data Breach appeared first on TechRepublic. First seen on techrepublic.com Jump to article: www.techrepublic.com/article/news-23andme-18-million-settlement-2023-genetic-data-breach/
-
New NadMesh Botnet Hunts Exposed AI Services for Cloud Keys and Kubernetes Tokens
A Go botnet called NadMesh turned up in early July hunting exposed AI services, and the operator’s own dashboard claims 3,811 unique AWS keys.A Shodan harvester keeps the scan queue stocked with ComfyUI, Ollama, n8n, Open WebUI, Langflow, and Gradio: the image generators, local model runners, and workflow builders that teams stand up fast and…
-
Lessons Learned: US Cybersecurity Agency Leaked Secrets
CISA Lauded for Fast Response, Transparency and Detailing Security Recommendations. Secure developers’ use of public code repositories, monitor them for secrets and if they get exposed, have a well-tested incident response playbook at the ready. The U.S. Cybersecurity and Infrastructure Security Agency has shared these and other lessons learned after suffering a data leak. First…
-
Ernst & Young discloses data breach after support system hack
Ernst & Young is notifying customers of a data breach caused by the compromise of a third-party support ticket system used by its IT personnel. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/ernst-and-young-discloses-data-breach-after-support-system-hack/
-
23andMe Faces New Security Mandates in $18m Data Breach Settlement
23andMe has agreed to an $18m settlement with 42 US attorneys general over its 2023 data breach, including enhanced data protection requirements First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/23andme-18m-data-breach-settlement/
-
The Cyber Express Weekly Roundup: TikTok Age Verification Probe, Healthcare Data Breach, Qantas Ruling, and Major Cyberattacks
Tags: breach, cyber, cyberattack, cybersecurity, data, data-breach, healthcare, risk, supply-chain, threat, vulnerabilityThis week’s cybersecurity roundup highlights growing concerns around online child safety, healthcare data protection, supply chain risks, and cyber threats affecting organizations worldwide. From regulatory scrutiny of digital platforms to large-scale vulnerabilities and operational disruptions, recent incidents show how cyber risks continue expanding across industries. First seen on thecyberexpress.com Jump to article: thecyberexpress.com/cybersecurity-weekly-roundup-tce/
-
The Biggest Data Breaches of 2026 So Far, Ranked by Impact
The biggest data breaches of 2026 so far, ranked by impact, with details on exposed data, affected users, and what readers should do next. The post The Biggest Data Breaches of 2026 So Far, Ranked by Impact appeared first on TechRepublic. First seen on techrepublic.com Jump to article: www.techrepublic.com/article/news-biggest-data-breaches-2026-ranked-impact/
-
Two Scattered Spider Members Sentenced to 5.6 Years Over TfL Cyberattack
Nearly two years after a cyberattack disrupted Transport for London’s (TfL) online services and exposed customer data, two… First seen on hackread.com Jump to article: hackread.com/two-scattered-spider-members-sentenced-tfl-cyberattack/
-
23andMe to pay $18 million in new genetics data breach settlement
Genetic testing company 23andMe has agreed to pay $18 million to settle claims from a coalition of 43 attorneys general that it failed to protect customers’ genetic data. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/23andme-to-pay-18-million-in-new-genetics-data-breach-settlement/
-
Ungeschütztes Elasticsearch-Cluster – Knapp 8 GB interne Nextcloud-Daten geleakt
Tags: data-breachFirst seen on security-insider.de Jump to article: www.security-insider.de/offenes-elasticsearch-cluster-nextcloud-daten-leak-a-f7340e831560f3c6d77d908db52f93c0/
-
Partnered Health Cyberattack Exposes Patient Data Across Australia
The Partnered Health cyberattack has exposed sensitive patient information across multiple Australian clinics, raising fresh concerns about healthcare cybersecurity. First seen on thecyberexpress.com Jump to article: thecyberexpress.com/partnered-health-cyberattack/
-
Australian Enterprises At Risk as Anthropic Finds Hackers In Claude Code
A Claude Code-powered cyberattack exposed AI governance gaps common among Australian businesses, where oversight continues to lag adoption. The post Australian Enterprises At Risk as Anthropic Finds Hackers In Claude Code appeared first on TechRepublic. First seen on techrepublic.com Jump to article: www.techrepublic.com/article/apac/
-
Finland issues wanted notice for hacker behind massive psychotherapy data breach
The defendant’s lawyer told Finnish media that he does not know where his client is but believes Kivimäki is outside Finland. First seen on therecord.media Jump to article: therecord.media/finland-issues-wanted-notice-for-hacker-vastaamo-breach
-
xAI Grok CLI Exposed Developer Code Through Automatic Whole-Repository Uploads
According to a reproducible wire-level analysis of version 0.2.93, xAI’s Grok Build CLI allegedly transmitted entire Git repositories, including unread files and commit history, to xAI infrastructure by default. The researcher noted that the behavior also sent the contents of files accessed by the agent, including a test .env file containing simulated credentials, without redaction.…
-
Telegram-Datenleck: 182 Millionen Nutzer-Datensätze im Darknet aufgetaucht
Eine Datenbank mit angeblich 182 Millionen Telegram-Nutzerdaten steht im Darknet zum Verkauf. Experten warnen vor gezieltem Phishing. First seen on it-daily.net Jump to article: www.it-daily.net/it-sicherheit/cybercrime/telegram-datenleck-darknet

