Tag: leak
-
RabbitMQ Flaws Could Leak OAuth Secrets and Expose Cross-Tenant Queue Metadata
Cybersecurity researchers have disclosed details of two access control-related flaws impacting the RabbitMQ message broker service that could allow attackers to leak OAuth client secrets, expose enterprise messaging infrastructure to takeover risks, and bypass tenant boundaries.Miggo’s security team, which discovered and reported the flaws, said one “leaks the broker’s confidential OAuth First seen on thehackernews.com…
-
Study of 85 Crypto Wallet Extensions Finds Address Leaks and Cross-Site Tracking Risks
Researchers at KU Leuven tested 85 of the most popular crypto wallets that run as browser extensions and found that the wallets themselves leak enough to link and track the people using them.The way these wallets talk to websites and blockchain servers can tie a person’s separate addresses together and let outsiders follow them from…
-
Pro-Iran Hacktivist Groups Launch DDoS and Hack-and-Leak Attacks Against Critical Infrastructure
Tags: attack, credentials, cyber, data, ddos, government, group, infrastructure, iran, leak, network, service, technologyA decentralized network of pro-Iran hacktivist groups is intensifying cyber operations against critical infrastructure, government entities, technology providers, and organizations perceived as aligned with U.S., Israeli, or Western interests. The activity is dominated by distributed denial-of-service attacks, defacements, credential-focused operations, data-leak claims, and propaganda designed to convert limited technical disruption into outsized psychological and reputational…
-
Pro-Iran Hacktivist Groups Launch DDoS and Hack-and-Leak Attacks Against Critical Infrastructure
Tags: attack, credentials, cyber, data, ddos, government, group, infrastructure, iran, leak, network, service, technologyA decentralized network of pro-Iran hacktivist groups is intensifying cyber operations against critical infrastructure, government entities, technology providers, and organizations perceived as aligned with U.S., Israeli, or Western interests. The activity is dominated by distributed denial-of-service attacks, defacements, credential-focused operations, data-leak claims, and propaganda designed to convert limited technical disruption into outsized psychological and reputational…
-
A Leak of San Francisco Police Drone Footage Exposes the New Reality of Urban Surveillance
Tags: leakThe SFPD’s exposure of hours of videos from drone platform Skydio reveals how broadly it’s watching the city from above”, and how the results can spill online. First seen on wired.com Jump to article: www.wired.com/story/sfpd-drone-video-leak-surveillance/
-
AssuranceAmerica Confirms Massive Data Breach Exposing Driver’s License and Insurance Data
AssuranceAmerica, a U.S. provider of auto and renters insurance, has confirmed a significant data breach that exposed the personal information and driver’s license data of approximately 6.99 million people. This incident marks the largest known leak of Americans’ driver’s license information this year. Founded in 1998, the Atlanta-based insurer operates in more than a dozen…
-
Nike Alleged Breach: Threat Actors Claim Leak of Millions of Customer Records
A threat actor on a prominent cybercrime forum has claimed responsibility for leaking data allegedly belonging to Nike and Alcon, posting the purported datasets for download. The claims, currently unverified, suggest a significant breach affecting millions of records across both organizations. Nike Alleged Breach According to the forum post, the threat actor alleges the Nike-related…
-
GitLost Vulnerability Lets Attackers Trick GitHub AI Agent Into Leaking Private Repos
A critical vulnerability known as >>GitLost<< has been discovered in GitHub's newly introduced Agentic Workflows by Noma Labs. This flaw allows unauthenticated attackers to exfiltrate sensitive data from private repositories. It demonstrates how AI-driven automation within development pipelines can be manipulated to bypass conventional access controls and leak confidential information across repository boundaries. GitLost Vulnerability…
-
‘GitLost’ Flaw Leaks Private Data From GitHub’s Agentic Workflows
The flaw allows an unauthenticated attacker to craft a GitHub Issue in an org’s public repository and then silently pull data from its private repos, too. First seen on darkreading.com Jump to article: www.darkreading.com/cyber-risk/gitlost-leaks-private-data-github-agentic-workflows
-
Writer AI Flaw Could Let Agent Previews Leak Session Tokens Across Tenants
Cybersecurity researchers have disclosed details of a now-patched critical session isolation vulnerability in Writer, an enterprise generative artificial intelligence (AI) platform, that could result in cross-tenant compromise.The one-click vulnerability has been codenamed WriteOut by the Sand Security Research team.”An outsider could go from having no access to taking over any Writer AI First seen on…
-
Vect and TeamPCP Cybercrime Groups Link for Ransomware Hits
Supply-Chain Victims Also at Risk From Poorly Coded, Data-Shredding Crypto-Locker. Recently announced tie-ups between ransomware group Vect, supply-chain attack specialists TeamPCP and data-leak stalwart Lapsus$ show cybercriminals continuing their quest to monetize their attacks and develop new profit streams. But not all has been smooth sailing. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/vect-teampcp-cybercrime-groups-link-for-ransomware-hits-a-32159
-
Seven Bugs in FatFs Put IoT and Embedded Devices at Risk
runZero found 7 flaws in FatFs, a filesystem used in IoT and embedded devices. Bugs can cause memory corruption, crashes, or data leaks via crafted storage. Cybersecurity firm runZero has disclosed seven vulnerabilities in FatFs, a compact open-source library that lets embedded devices read and write FAT and exFAT formatted storage, the same formats used…
-
New TrojPix Attack Leaks Data From Air-Gapped Systems via Video Cable Emissions
Researchers at Shandong University have shown a fast new way to pull data off computers that are cut off from every network. The technique, called TrojPix, tweaks on-screen pixels in ways the eye cannot see, so that the video cable carrying them radiates a faint radio signal a nearby receiver can decode.But TrojPix works only…
-
The Gentlemen Ransomware Targets Large Corporations and Critical Infrastructure Worldwide
The Gentlemen ransomware group has emerged in 2026 as a highly adaptive and technically sophisticated ransomware-as-a-service (RaaS) operation targeting large corporations and critical infrastructure across multiple regions. Public reporting places The Gentlemen among the top 10 ransomware actors by victim announcements on its data leak site during the first half of 2026 (see ransomware.live/stats/2026), and…
-
Indian bank domain registrar allegedly leaks sensitive data
First seen on scworld.com Jump to article: www.scworld.com/brief/indian-bank-domain-registrar-allegedly-leaks-sensitive-data
-
CVE-2026-8451: Citrix NetScaler Vulnerability Leaks Memory
CVE-2026-8451 is a Citrix NetScaler vulnerability that can leak process memory through specially crafted SAML requests. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/threats/cve-2026-8451-citrix-netscaler-vulnerability-leaks-memory/
-
Microsoft Warns Poisoned MCP Tool Descriptions Can Make AI Agents Leak Data
New Microsoft research shows how attackers can hijack AI agents that act on a user’s behalf, using nothing more than a poisoned tool description to make the agent quietly hand over company data to an outsider.The trick is that the agent never breaks a rule. Every step looks routine, so in a default setup no…
-
iPhone 18 Leak: Apple’s Next Pro Design May Have Appeared Online
Leaked Tata files reportedly show possible iPhone 18 Pro design details, factory images, and supplier records ahead of Apple’s expected September launch. The post iPhone 18 Leak: Apple’s Next Pro Design May Have Appeared Online appeared first on TechRepublic. First seen on techrepublic.com Jump to article: www.techrepublic.com/article/news-iphone-18-pro-design-leak-tata-breach/
-
282 iOS AI Apps Leak API Keys and Open AI Proxy Access in Network Traffic Study
Researchers tested 444 AI chatbot apps for iPhone and found that 282 of them, nearly two-thirds, exposed paid AI access through their network traffic.In many cases, the path in was visible just by watching what the app sent: a plaintext API key, a reusable token, or a backend server that accepted requests with no key…
-
Hackers Claim French Employment Leak Exposes Over 1M Records, Health Data
Hackers claim 1M+ records tied to French employment apps were exposed, including HR files, health data, worker details, and plaintext passwords. The post Hackers Claim French Employment Leak Exposes Over 1M Records, Health Data appeared first on TechRepublic. First seen on techrepublic.com Jump to article: www.techrepublic.com/article/news-akaolife-data-claim-emea-france/
-
Tata Electronics Confirms Data Breach After 630GB Leak Claim Targets Apple and Tesla
Tata Electronics confirmed a data breach after hackers claimed to steal 630GB of data, including alleged Apple supplier and Tesla documents. Tata Electronics, a major supplier to Apple and Tesla, has confirmed a cybersecurity breach weeks after stolen data was advertised on a hacker forum. Tata Electronics confirmed a cyberattack affected parts of its IT…
-
Breach Roundup: How Hackers Exploited a Cisco SD-WAN Flaw
Also, Three Ubiquiti Flaws Under Exploitation. This week, Mandiant detailed a Cisco SD-WAN hack as attackers exploited Ubiquiti flaws. London Hydro disclosed a customer data breach, researchers flagged cross-cloud bucket hijacking risks an INC ransomware leak, Texas and Gravity SMTP incidents. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/breach-roundup-how-hackers-exploited-cisco-sd-wan-flaw-a-32080
-
FortiBleed: The Broker Who Turned 73,000 Firewalls Into a Product Catalog
FortiBleed exposed valid credentials for 73,000+ Fortinet firewalls, revealing a large-scale access-brokering operation targeting organizations worldwide. In mid-June 2026, researcher Volodymyr >>Bob<< Diachenko found a live, exposed server containing working login credentials for tens of thousands of Fortinet firewalls, a data leak code-named FortiBleed. The headline number, valid remote-access logins for 73,932 devices across 21,632…
-
Tata Electronics Leak Exposes 200,000 Files, Including Apple and Tesla Documents
Tata Electronics is investigating a cyber incident after leaked files reportedly included manufacturing documents for Apple and Tesla. The post Tata Electronics Leak Exposes 200,000 Files, Including Apple and Tesla Documents appeared first on TechRepublic. First seen on techrepublic.com Jump to article: www.techrepublic.com/article/news-apac-india-tata-electronics-data-leak/
-
Tata Electronics confirms cyberattack as hackers leak data
Tata Electronics has confirmed in a statement to BleepingComputer that it was the target of a cyberattack that impacted parts of its IT infrastructure. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/tata-electronics-confirms-cyberattack-as-hackers-leak-data/
-
Scope of Salesforce Attacks Expands as Icarus Leaks Data
More victims have emerged after attackers breached application vendor Klue and used its OAuth tokens to steal customers’ Salesforce data. First seen on darkreading.com Jump to article: www.darkreading.com/cyberattacks-data-breaches/scope-salesforce-attacks-expands-icarus-leaks-data
-
Squidbleed: 29-Year-Old Squid Bug Leaks User Credentials
Squidbleed is a 29-year-old Squid Proxy flaw that can leak credentials, tokens, and other users’ HTTP data through a memory overread. Researchers at Calif.io have disclosed CVE-2026-47729, a memory leak vulnerability in Squid Proxy that was introduced in 1997 and has remained undetected through nearly three decades of releases, audits, and rewrites. They named it…
-
29-Year-Old Squid Proxy Bug ‘Squidbleed’ Can Leak Cleartext HTTP Requests
A heap over-read in the Squid web proxy can leak another user’s cleartext HTTP request, including any credentials or session tokens it carries, to anyone already allowed to send traffic through the same proxy.The bug traces to a 1997 FTP-parsing change and is still live in Squid’s default configuration. Researchers at Calif.io disclosed it in…
-
29-Year-Old Squid Proxy Bug ‘Squidbleed’ Can Leak Cleartext HTTP Requests
A heap over-read in the Squid web proxy can leak another user’s cleartext HTTP request, including any credentials or session tokens it carries, to anyone already allowed to send traffic through the same proxy.The bug traces to a 1997 FTP-parsing change and is still live in Squid’s default configuration. Researchers at Calif.io disclosed it in…
-
29-Year-Old Squid Proxy Bug ‘Squidbleed’ Can Leak Cleartext HTTP Requests
A heap over-read in the Squid web proxy can leak another user’s cleartext HTTP request, including any credentials or session tokens it carries, to anyone already allowed to send traffic through the same proxy.The bug traces to a 1997 FTP-parsing change and is still live in Squid’s default configuration. Researchers at Calif.io disclosed it in…

