Tag: data-breach
-
Lidl Notifies Customers of Third-Party Data Breach
Supermarket giant Lidl has revealed details of a supplier breach impacting customer data First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/lidl-notifies-customers-of/
-
Lidl Notified Online Shop Customers in Germany, Belgium, and the Netherlands of a Data Breach
Lidl disclosed a third-party data breach affecting online shop customers in Germany, Belgium, and the Netherlands. Payment data was not exposed. Lidl contacted customers of its online shop in Germany, Belgium, and the Netherlands last week to inform them that their personal data had been stolen in an attack on an external IT service provider.…
-
Open Directory Exposes Three Evilginx Phishing Operators
Misconfigured server exposed three phishing operators running Evilginx forks to bypass MFA First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/open-directory-exposes-evilginx/
-
13th July Threat Intelligence Report
U.S. auto insurer AssuranceAmerica has disclosed a data breach affecting approximately 7 million people. Attackers targeted an employee and used compromised credentials to access company systems, stealing names, contact information, driver’s license […] First seen on research.checkpoint.com Jump to article: research.checkpoint.com/2026/13th-july-threat-intelligence-report/
-
Attackers Combine MCP Recon With Cloud Metadata SSRF to Steal Service Account Tokens
Internet-wide reconnaissance is expanding beyond conventional application targets to include Model Context Protocol (MCP) services, AI assistant configuration files, and locally exposed LLM endpoints. A 14-day review of Apache and ModSecurity logs from a small, low-traffic shared host found roughly 200 requests tied to AI-agent reconnaissance, alongside routine WordPress, .env, Git, and Spring Boot Actuator…
-
Dutch Nationals Suspected in Odido Hack That Exposed Six Million Customers
Dutch police suspect local hackers behind the Odido breach that exposed 6M customers after a phishing attack and seek public help identifying them. Dutch police have identified strong indications that Dutch nationals were involved in the February 2026 cyberattack on telecom provider Odido, which resulted in data from more than six million customers being stolen…
-
Exposed Server Unmasks Evilginx Operators Stealing Microsoft 365 Sessions and OAuth Tokens
A misconfigured server in Budapest exposed a live phishing operation built to bypass Microsoft 365 multi-factor authentication and retain access to compromised accounts. The server, hosted at 185.163.204[.]7185.163.204[.]7185.163.204[.]7, was running python3 -m http.server 8080 with directory listing enabled, making its operational files publicly accessible. Researchers found phishing configurations, Telegram session artifacts, credential logs, RMM installers,…
-
Exposed Server Unmasks Evilginx Operators Stealing Microsoft 365 Sessions and OAuth Tokens
A misconfigured server in Budapest exposed a live phishing operation built to bypass Microsoft 365 multi-factor authentication and retain access to compromised accounts. The server, hosted at 185.163.204[.]7185.163.204[.]7185.163.204[.]7, was running python3 -m http.server 8080 with directory listing enabled, making its operational files publicly accessible. Researchers found phishing configurations, Telegram session artifacts, credential logs, RMM installers,…
-
IT-Vorfall bei Dienstleister: Lidl informiert Kunden über Datenleck
Unbekannte Angreifer sind über einen IT-Dienstleister an Kundendaten des Lidl-Shops gelangt. Betroffene wurden per E-Mail informiert. First seen on golem.de Jump to article: www.golem.de/news/it-vorfall-bei-dienstleister-lidl-informiert-kunden-ueber-datenleck-2607-210785.html
-
Dutch police suspect Dutch hackers in Odido data breach
First seen on scworld.com Jump to article: www.scworld.com/brief/dutch-police-suspect-dutch-hackers-in-odido-data-breach
-
Data breach hits car insurance provider
Hackers gained access to more than 6.9 million records at AssuranceAmerica by targeting a company employee. First seen on cybersecuritydive.com Jump to article: www.cybersecuritydive.com/news/data-breach-car-insurance-provider/824835/
-
AssuranceAmerica Breach Exposes 7 Million Driver’s Licenses After Employee Account Hack
AssuranceAmerica confirmed a breach exposing nearly 7 million driver’s licenses after hackers compromised an employee account and stole customer data. U.S. auto insurer AssuranceAmerica has confirmed a data breach affecting nearly 7 million people, making it the largest known theft of Americans’ driver’s license information in 2026. >>In a data breach notice sent to customers…
-
AssuranceAmerica Confirms Massive Data Breach Exposing Driver’s License and Insurance Data
AssuranceAmerica, a U.S. provider of auto and renters insurance, has confirmed a significant data breach that exposed the personal information and driver’s license data of approximately 6.99 million people. This incident marks the largest known leak of Americans’ driver’s license information this year. Founded in 1998, the Atlanta-based insurer operates in more than a dozen…
-
AssuranceAmerica data breach exposes records of 6.9 million drivers
American insurance company AssuranceAmerica has disclosed a data breach impacting nearly 7 million drivers after attackers gained access to its systems earlier this year. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/assuranceamerica-data-breach-exposes-records-of-69-million-drivers/
-
AssuranceAmerica data breach exposes records of 6.9 million drivers
American insurance company AssuranceAmerica has disclosed a data breach impacting nearly 7 million drivers after attackers gained access to its systems earlier this year. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/assuranceamerica-data-breach-exposes-records-of-69-million-drivers/
-
UK’s largest businesses dangerously exposed to cloud outages
British businesses, particularly those in the FTSE 100, are dangerously dependent on large cloud providers, with hypothetical large-scale outages at AWS or Azure regions likely to cause major economic damage, according to the Cyber Monitoring Centre First seen on computerweekly.com Jump to article: www.computerweekly.com/news/366645540/UKs-largest-businesses-dangerously-exposed-to-cloud-outages
-
Accenture Confirms Security Incident After Hacker Claims Data Haul
Accenture acknowledged that it suffered a data breach, but said it has remediated it with no impact on operations or service delivery. First seen on crn.com Jump to article: www.crn.com/news/security/2026/accenture-confirms-security-incident-after-hacker-claims-data-haul
-
A Hacker Claims 35 GB of Accenture Source Code. The Company discloses the data breach
Accenture confirmed a breach after a hacker claimed to steal 35 GB of source code, keys, and Azure credentials now offered for sale. A threat actor using the handle >>888<>Today […] First seen on securityaffairs.com Jump to article: securityaffairs.com/194962/data-breach/a-hacker-claims-35-gb-of-accenture-source-code-the-company-discloses-the-data-breach.html
-
Hacker Claims Accenture Breach Exposed Source Code, SSH Keys, and Azure Tokens
Accenture confirmed a breach after a hacker claimed 35GB of source code and cloud keys were stolen, raising questions for cloud and security teams. The post Hacker Claims Accenture Breach Exposed Source Code, SSH Keys, and Azure Tokens appeared first on TechRepublic. First seen on techrepublic.com Jump to article: www.techrepublic.com/article/news-accenture-breach-cloud-keys/
-
Wireless Pentesting with Claude Using the Aircrack MCP Server
Overview Wireless networks remain one of the most exposed and frequently overlooked attack surfaces across enterprise and consumer environments. This article introduces the Aircrack-ng MCP First seen on hackingarticles.in Jump to article: www.hackingarticles.in/wireless-pentesting-with-claude-using-the-aircrack-mcp-server/
-
Another massive data breach exposed millions of driver’s license numbers
The cyberattack targeting a U.S. insurance giant is the largest known breach of driver’s license numbers so far in 2026. First seen on techcrunch.com Jump to article: techcrunch.com/2026/07/08/another-massive-data-breach-exposed-millions-of-drivers-license-numbers/
-
Accenture faces massive data breach that could put clients at risk
The threat actor claiming responsibility says it stole source code, encryption keys and more. First seen on cybersecuritydive.com Jump to article: www.cybersecuritydive.com/news/accenture-data-breach-access-keys-source-code/824694/
-
Großes Datenleck bei Nextcloud: Kundenskripte und Rechnungen standen offen im Netz
Neben internen Unternehmensdaten ließen sich durch die Sicherheitslücke bei Nextcloud auch für Kunden angefertigte Skripte einsehen. First seen on golem.de Jump to article: www.golem.de/news/grosses-datenleck-bei-nextcloud-kundenskripte-und-rechnungen-standen-offen-im-netz-2607-210659.html
-
Accenture acknowledges security incident following 35GB data theft claim
Accenture appears to have suffered a data breach, the extent of which is currently unknown. On Monday, a threat actor going by the handle >>888<< posted on the … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/07/08/accenture-data-breach-2026/
-
Telco giant KDDI says data breach affects over 12 million people
Japanese telecommunications giant KDDI says that millions of people had their email addresses and passwords exposed after attackers breached an email platform used by five internet service providers (ISPs) in the country. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/japanese-telecom-giant-kddi-says-data-breach-affects-12-million-people/
-
Exposed Banana RAT Infrastructure Reveals Payload Generator and Obfuscator Tooling
A publicly indexed server at 198[.]245[.]53[.]26, discovered via Shodan, exposed more than simple staging files it revealed an active payload-generation backend and obfuscation tooling tied to two distinct Banana RAT branches. The host served static stages (st.txt, payload.php) and a FastAPI-based builder (servidor_completo_pool.py) plus an ofuscador.py helper. Enabling researchers to compare an older ETW-themed branch…
-
Over 70% of Public WordPress Sites Running Outdated PHP Exposed to Cyberattacks
A new analysis has revealed a significant security gap within the global web ecosystem. Over 70% of publicly accessible WordPress sites are running outdated, end-of-life (EOL) PHP versions, significantly increasing their vulnerability to cyberattacks. These findings highlight a systemic issue in how organizations manage their backend infrastructure, particularly given that WordPress remains the leading content…
-
Januscape Flaw in Linux KVM’s MMU Code Enables VM Escape on Intel and AMD
A newly disclosed Linux kernel vulnerability, CVE-2026-53359, dubbed Januscape, has exposed a critical weakness in the Linux Kernel-based Virtual Machine (KVM) hypervisor. The flaw resides in the shadow MMU code and allows attackers to escape a virtual machine (VM), compromise the underlying host, and potentially execute arbitrary code. First seen on thecyberexpress.com Jump to article: thecyberexpress.com/cve-2026-53359-januscape/
-
Google Dialogflow CX Flaw Lets Attackers Bypass VPC-SC and Steal Sensitive Chatbot Data
A critical vulnerability in Google Cloud’s Dialogflow CX platform allowed attackers to bypass VPC Service Controls (VPC-SC) and silently exfiltrate sensitive chatbot data, raising significant concerns about the security of enterprise AI deployments. Discovered by Varonis Threat Labs and dubbed “Rogue Agent,” the flaw exposed a serious design gap in how Dialogflow CX executes custom…
-
Accenture Data Breach Exposes 35GB Source Code and Azure DevOps Credentials
Accenture is currently investigating a potential data breach after a threat actor using the alias “888” claimed to be selling approximately 35GB of stolen data, including source code and sensitive credentials, on a cybercrime forum. This listing, posted on July 6, 2026, alleges that the breach resulted in the exfiltration of proprietary assets, including source…

