Tag: data-breach
-
Hugging Face ‘hacker’ was rogue OpenAI model
A hacker who broke into Hugging Face’s systems last week has been exposed as a pair of advanced OpenAI frontier models that were trying to cheat on an exam First seen on computerweekly.com Jump to article: www.computerweekly.com/news/366646003/Hugging-Face-hacker-was-rogue-OpenAI-model
-
Apple Fixes Hide My Email Vulnerability That Exposed Users’ Real Email Addresses
Apple has addressed a year-old vulnerability in its >>Hide My Email<< privacy feature, which could expose users' real email addresses. This incident has already led to a class action lawsuit and increased scrutiny of Apple's privacy claims. Hide My Email, part of the paid iCloud+ subscription, allows users to generate random alias addresses that forward…
-
Chick-fil-A discloses data breach after credential stuffing attacks
American fast food restaurant chain Chick-fil-A is notifying customers of a data breach after their accounts were hacked in a wave of recent credential stuffing attacks. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/chick-fil-a-discloses-data-breach-after-credential-stuffing-attacks/
-
Craneware confirms customer and employee data exposed in security incident
First seen on scworld.com Jump to article: www.scworld.com/brief/craneware-confirms-customer-and-employee-data-exposed-in-security-incident
-
Apple Fixes Hide My Email Bug That Exposed Real Addresses in Mail Logs
Apple has moved to address a security flaw in its Hide My Email service that enabled users’ real email addresses to be unmasked, effectively undermining the feature’s privacy guarantees.404 Media reported Tuesday that a fix for the issue was deployed by Apple on July 3, 2026, after more than a year, when it was disclosed…
-
Ransomware victims fail to fix flaws that exposed them
Many organizations still aren’t securing their email or patching vulnerabilities after recovering from attacks, a new report found. First seen on cybersecuritydive.com Jump to article: www.cybersecuritydive.com/news/ransomware-lingering-weaknesses-black-kite/825791/
-
Estée Lauder Confirms Cyberattack Affecting Personal Information
The Estée Lauder data breach has prompted the global cosmetics company to notify affected individuals after hackers exploited a vulnerability in Oracle E-Business Suite, a platform used for human resources (HR) operations. First seen on thecyberexpress.com Jump to article: thecyberexpress.com/estee-lauder-data-breach-oracle-ebs/
-
Estée Lauder Confirms Cyberattack Affecting Personal Information
The Estée Lauder data breach has prompted the global cosmetics company to notify affected individuals after hackers exploited a vulnerability in Oracle E-Business Suite, a platform used for human resources (HR) operations. First seen on thecyberexpress.com Jump to article: thecyberexpress.com/estee-lauder-data-breach-oracle-ebs/
-
Estée Lauder discloses data breach tied to Oracle EBS vulnerability
Cosmetics company Estée Lauder disclosed a data breach tied to a vulnerability in Oracle E-Business Suite (EBS) used for the company’s human resources operations. Estée … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/07/21/estee-lauder-data-breach-oracle-ebs/
-
Paidwork breach exposes sensitive data of 23 million users
Data belonging to more than 23 million users has been exposed following a breach at Paidwork, a platform that pays people for completing online microtasks. Paidwork markets … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/07/20/paidwork-data-breach-23-million-users/
-
Paidwork Data Breach Exposes 23.3 Million Accounts, Banking Data and bcrypt Password Hashes
Gig-economy platform Paidwork has been linked to a significant data breach that affects 23.3 million accounts. This breach, involving an approximately 11GB dataset, was publicly released in July 2026. The incident was added to the Have I Been Pwned (HIBP) breach database on July 19, with the compromise reportedly occurring in March 2026. Paidwork Data…
-
Estée Lauder discloses data breach via Oracle E-Business flaw
Cosmetics giant Estée Lauder is notifying customers of a data breach after hackers exploited a flaw in Oracle E-Business Suite that the company used for human resources (HR) operations. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/est-e-lauder-discloses-data-breach-via-oracle-e-business-flaw/
-
India says allegedly leaked nuclear plant files pose no safety risk
Documents that the World Leaks cybercrime group claimed to leak from the Kudankulam Nuclear Power Plant do not contain information pertaining to safety or security, Indian officials said. First seen on therecord.media Jump to article: therecord.media/india-nuclear-plant-kudankulam-world-leaks-documents
-
Exposed Server Reveals AI-Assisted Phishing Toolkit Behind WebDAV Malware Campaign
A malware operator left its delivery server wide open, and Rapid7 pulled down the whole toolkit: 1,048 files spanning lure templates, filename-spoofing tests, execution experiments, droppers, builder notes, and two campaign chains. One was already live against Windows users in Mexico, delivering an infostealer through a fake government ID-lookup site over WebDAV.What makes it more…
-
Paidwork breach exposes sensitive data of 23 million user
Data belonging to more than 23 million users has been exposed following a breach at Paidwork, a platform that pays people for completing online microtasks. Paidwork markets … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/07/20/paidwork-data-breach-23-million-users/
-
âš¡ Weekly Recap: WordPress RCE, SonicWall 0-Days, AI Service Attacks, SharePoint 0-Day and More
Tags: ai, attack, breach, data-breach, malware, rce, remote-code-execution, service, wordpress, zero-dayA single request should not be able to do this much. But this week, small inputs led to code execution, memory loss, stolen keys, and disabled security tools.The paths were often simple: exposed systems, weak checks, old drivers, fake prompts, and public code used for malware delivery. Some bugs were new. Others were already being…
-
20th July Threat Intelligence Report
Ernst & Young, a global accounting and professional services company, has disclosed a data breach involving a compromised third-party IT support platform. The exposed support tickets may have contained client documents, tax information, […] First seen on research.checkpoint.com Jump to article: research.checkpoint.com/2026/20th-july-threat-intelligence-report/
-
Microsoft Ends OneDrive Sync App Security Updates on Windows 10 21H2 and Earlier
Microsoft will stop delivering feature updates, bug fixes, and security patches for the OneDrive sync app on systems running Windows version 21H2 and earlier on August 15, 2026. This change was announced in the Microsoft 365 Message Center notification MC1426708 and leaves organizations with older Windows endpoints exposed to an increasingly unsupported file synchronization client,…
-
One Malicious Web Request Can Turn an Exposed SharePoint Server Into a Persistent Backdoor
Tags: advisory, backdoor, cisa, cyber, data-breach, exploit, malicious, microsoft, remote-code-execution, update, vulnerabilityA newly disclosed cluster of Microsoft SharePoint Server vulnerabilities is actively being exploited in the wild, allowing attackers to convert a single crafted web request into full remote code execution and long-term persistence across enterprise environments. Security updates released in July 2026, alongside a CISA advisory, confirm that multiple vulnerabilities are already being weaponized against…
-
Ernst Young (EY) Investigates Data Breach Involving Third-Party Support Tickets
Ernst & Young (EY) disclosed a data breach after attackers compromised a third-party IT support system containing client documents and tax information. Ernst & Young (EY) is disclosed a data breach linked to a compromised third-party support ticket system used by its IT teams. The platform stored support requests that may have included documents containing…
-
23andMe Agrees to $18M Settlement With 43 States Over 2023 Data Breach
23andMe will pay $18 million to settle claims from 43 states over its 2023 data breach, which exposed genetic information tied to nearly 7 million people. The post 23andMe Agrees to $18M Settlement With 43 States Over 2023 Data Breach appeared first on TechRepublic. First seen on techrepublic.com Jump to article: www.techrepublic.com/article/news-23andme-18-million-settlement-2023-genetic-data-breach/
-
New NadMesh Botnet Hunts Exposed AI Services for Cloud Keys and Kubernetes Tokens
A Go botnet called NadMesh turned up in early July hunting exposed AI services, and the operator’s own dashboard claims 3,811 unique AWS keys.A Shodan harvester keeps the scan queue stocked with ComfyUI, Ollama, n8n, Open WebUI, Langflow, and Gradio: the image generators, local model runners, and workflow builders that teams stand up fast and…
-
Lessons Learned: US Cybersecurity Agency Leaked Secrets
CISA Lauded for Fast Response, Transparency and Detailing Security Recommendations. Secure developers’ use of public code repositories, monitor them for secrets and if they get exposed, have a well-tested incident response playbook at the ready. The U.S. Cybersecurity and Infrastructure Security Agency has shared these and other lessons learned after suffering a data leak. First…
-
Ernst & Young discloses data breach after support system hack
Ernst & Young is notifying customers of a data breach caused by the compromise of a third-party support ticket system used by its IT personnel. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/ernst-and-young-discloses-data-breach-after-support-system-hack/
-
23andMe Faces New Security Mandates in $18m Data Breach Settlement
23andMe has agreed to an $18m settlement with 42 US attorneys general over its 2023 data breach, including enhanced data protection requirements First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/23andme-18m-data-breach-settlement/
-
The Cyber Express Weekly Roundup: TikTok Age Verification Probe, Healthcare Data Breach, Qantas Ruling, and Major Cyberattacks
Tags: breach, cyber, cyberattack, cybersecurity, data, data-breach, healthcare, risk, supply-chain, threat, vulnerabilityThis week’s cybersecurity roundup highlights growing concerns around online child safety, healthcare data protection, supply chain risks, and cyber threats affecting organizations worldwide. From regulatory scrutiny of digital platforms to large-scale vulnerabilities and operational disruptions, recent incidents show how cyber risks continue expanding across industries. First seen on thecyberexpress.com Jump to article: thecyberexpress.com/cybersecurity-weekly-roundup-tce/
-
The Biggest Data Breaches of 2026 So Far, Ranked by Impact
The biggest data breaches of 2026 so far, ranked by impact, with details on exposed data, affected users, and what readers should do next. The post The Biggest Data Breaches of 2026 So Far, Ranked by Impact appeared first on TechRepublic. First seen on techrepublic.com Jump to article: www.techrepublic.com/article/news-biggest-data-breaches-2026-ranked-impact/

