Skip to main content
COSMICBYTEZLABS
NewsSecurityHOWTOsToolsStudyTraining
ProjectsNewsletterHire MeAbout
Subscribe

Press Enter to search or Esc to close

News
Security
HOWTOs
Tools
Study
Training
Projects
Newsletter
Hire Me
About
RSS Feed
Reading List
Subscribe

Stay in the Loop

Get the latest security alerts, tutorials, and tech insights delivered to your inbox.

Subscribe NowFree forever. No spam.
COSMICBYTEZLABS

Your trusted source for IT intelligence, cybersecurity insights, and hands-on technical guides.

1310+ Articles
157+ Guides

CONTENT

  • Latest News
  • Security Alerts
  • HOWTOs
  • Checklists
  • Projects
  • Exam Prep

RESOURCES

  • Search
  • Browse Tags
  • Newsletter Archive
  • Reading List
  • RSS Feed

COMPANY

  • About Us
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 CosmicBytez Labs. All rights reserved.

System Status: Operational
All tags
175 articles

#Data Breach

All CosmicBytez Labs articles tagged #Data Breach, across news, security advisories, how-to guides, and projects.

  • NewsJun 1, 2026

    Tina Peters, Convicted in Election-Security Breach, Emerges Defiant and Vows Legal Fight

    Former Colorado election clerk Tina Peters, convicted for her role in an election security breach, struck an unrepentant pose in her first interview after Colorado Governor Jared Polis commuted her prison sentence — vowing to continue her legal fight.

  • NewsMay 29, 2026

    California AG Sues 23andMe Over 2023 Breach Exposing Genetic Health Data

    California Attorney General Rob Bonta filed a lawsuit against 23andMe — now Chrome Holding Co. — over its failure to protect millions of customers'...

  • NewsMay 29, 2026

    Charter Communications Data Breach Affects 4.9 Million Accounts

    ShinyHunters stole personal information from 4.9 million Charter Communications accounts in an April 2026 hack, confirmed via Have I Been Pwned.

  • NewsMay 29, 2026

    In Other News: Trump Mobile Data Breach, FIFA World Cup Phishing, CISA Responds to Supply Chain Attacks

    Noteworthy cybersecurity stories from the week: Trump Mobile exposes customer data, phishers target 2026 FIFA World Cup fans, and CISA responds to recent...

  • NewsMay 29, 2026

    Man Sent to Prison for Selling Data of 7 Million Elderly Americans

    A North Carolina man was sentenced to more than 10 years in federal prison for selling the personal information of over 7 million elderly Americans to...

  • NewsMay 28, 2026

    Carnival Cruise Confirms Data Breach Affecting Nearly 6 Million People

    Carnival Corporation, the world's largest cruise operator, confirms a breach affecting nearly 6M people after ShinyHunters' April 2026 extortion claim.

  • NewsMay 28, 2026

    Latin American Cybercriminals Hoover Up Government Data

    A reported breach of 5.8M Uruguayan records is the latest in a growing pattern of attackers monetizing Latin American government citizen data.

  • NewsMay 27, 2026

    Dutch Police Arrest Man Over Cyber Breach at Ajax Football Club

    Dutch police arrested a suspect over a cyber breach at Ajax football club, seizing digital storage devices from his home in the town of Buren.

  • NewsMay 26, 2026

    185,000 Likely Impacted by 7-Eleven Data Breach

    ShinyHunters has leaked data allegedly stolen from 7-Eleven containing email addresses, names, physical addresses, and dates of birth for approximately 185,000.

  • NewsMay 26, 2026

    7-Eleven Data Breach Exposes Personal Information of

    The ShinyHunters extortion gang stole the personal information of over 185,000 customers after breaching convenience store giant 7-Eleven in April 2026, with.

  • NewsMay 26, 2026

    DocketWise Data Breach Impacts 143,000 Individuals

    Immigration law practice management software DocketWise has disclosed a data breach affecting 143,000 individuals, with hackers accessing names, addresses.

  • NewsletterMay 26, 2026

    May 26 Digest: SharePoint RCE, Megalodon CI/CD Blitz

    Microsoft patches a CVSS 8.8 SharePoint RCE; the Megalodon campaign poisons 5,561 GitHub repos in six hours; 7-Eleven's ShinyHunters breach hits 185,000; and a.

  • NewsMay 25, 2026

    266,000 Affected by Data Breach at Radiology Associates of

    Radiology Associates of Richmond has disclosed a cyberattack in which threat actors stole files containing names and protected health information belonging to.

  • NewsMay 25, 2026

    Oncology Institute Discloses Data Breach

    An unnamed oncology institute has disclosed a data breach originating from a third-party vendor compromise, with TriZetto cited as one possible candidate.

  • NewsMay 23, 2026

    Grafana Says Codebase and Other Data Stolen via TanStack

    Grafana confirmed attackers stole internal source code and data after a GitHub token compromised in the TanStack npm supply chain attack was never...

  • NewsMay 22, 2026

    Lawmakers Demand Answers as CISA Tries to Contain Data Leak

    Members of Congress are demanding answers from CISA after a contractor intentionally published AWS GovCloud access keys and a trove of agency secrets on a...

  • NewsMay 22, 2026

    Verizon DBIR 2026: Healthcare Fends Off Rising Social

    The 2026 Verizon Data Breach Investigations Report highlights how evolving social engineering tactics are making the healthcare sector more vulnerable,...

  • NewsMay 21, 2026

    GitHub Links Repo Breach to TanStack npm Supply-Chain Attack

    GitHub has confirmed that hackers who stole 3,800 internal repositories gained access through a malicious version of the Nx Console VS Code extension...

  • NewsMay 20, 2026

    GitHub Breached — Employee Device Hack Led to Exfiltration

    GitHub is investigating unauthorized access to thousands of internal repositories after an employee device was compromised through the TanStack npm supply...

  • NewsMay 20, 2026

    GitHub Confirms Being Hacked by TeamPCP, Says Customer Data

    GitHub has officially confirmed it was breached by the TeamPCP threat actor after the group advertised stolen internal source code on a cybercrime forum....

  • NewsMay 20, 2026

    GitHub Confirms Breach, 4K Internal Repos Stolen

    GitHub has confirmed a data breach in which the TeamPCP threat actor stole approximately 4,000 internal repositories. The company states no customer data...

  • NewsMay 20, 2026

    GitHub Investigating TeamPCP Claimed Breach of ~4,000

    GitHub is investigating unauthorized access to its internal repositories after the TeamPCP threat actor listed approximately 4,000 GitHub internal repos...

  • NewsMay 20, 2026

    Grafana Breach Caused by Missed Token Rotation After

    Grafana Labs has revealed that its May 2026 source code breach was caused by a single GitHub workflow token that was inadvertently missed during the token...

  • NewsMay 20, 2026

    Grafana GitHub Breach Exposes Source Code via TanStack npm

    Grafana Labs confirms its GitHub environment was breached through the TanStack npm supply chain attack, exposing public and private source code...

  • NewsletterMay 20, 2026

    May 20 Digest: Exchange Zero-Day, Verizon DBIR, GitHub

    A Microsoft Exchange zero-day is being exploited with no patch in sight; Verizon DBIR 2026 marks a landmark shift — vulnerability exploitation now...

  • NewsMay 19, 2026

    7-Eleven Confirms Data Breach Claimed by the ShinyHunters

    Convenience store giant 7-Eleven has confirmed a data breach after the ShinyHunters extortion group publicly claimed responsibility for the attack. The...

  • NewsMay 19, 2026

    Verizon DBIR 2026: Vulnerability Exploitation Overtakes

    Verizon's 2026 Data Breach Investigations Report reveals a landmark shift: vulnerability exploitation has surpassed credential abuse as the leading breach...

  • NewsMay 18, 2026

    7-Eleven Data Breach Confirmed After ShinyHunters Ransom

    7-Eleven has confirmed a data breach after ShinyHunters claimed to have stolen more than 600,000 Salesforce records containing personal information and...

  • NewsMay 18, 2026

    Grafana Confirms Breach After Hackers Claim They Stole Data

    Grafana has confirmed a security breach after the Coinbase Cartel cybercrime group — linked to ShinyHunters, Scattered Spider, and Lapsus$ — claimed to...

  • NewsMay 18, 2026

    Grafana Says Stolen GitHub Token Let Hackers Steal Codebase

    Grafana Labs confirmed that hackers downloaded its source code after breaching its GitHub environment using a stolen access token. The attackers attempted...

  • NewsMay 18, 2026

    Millions Impacted Across Several US Healthcare Data Breaches

    Multiple healthcare data breaches impacting hundreds of thousands to millions of individuals have been added to the HHS breach tracker, continuing a...

  • NewsMay 17, 2026

    Grafana GitHub Token Breach Led to Codebase Download and

    Grafana has disclosed that an unauthorized party obtained a GitHub access token, used it to download the company's entire codebase, and then attempted...

  • NewsMay 16, 2026

    In Other News: Big Tech vs Canada Encryption Bill, Cisco's

    Other noteworthy stories this week: Big Tech firms push back against Canada's encryption legislation, Cisco releases a free AI security specification, and...

  • NewsMay 15, 2026

    American Lending Center Data Breach Affects 123,000

    The non-bank lender discovered a ransomware attack nearly one year ago but only recently completed its investigation, notifying over 123,000 individuals...

  • NewsMay 15, 2026

    TeamPCP Hackers Advertise Mistral AI Source Code Repos for

    The TeamPCP threat group claims to have stolen source code repositories from Mistral AI and is advertising them for sale on criminal forums, threatening...

  • NewsMay 14, 2026

    OpenAI Confirms Security Breach in TanStack Supply Chain

    OpenAI confirmed that two employees' devices were compromised during the TanStack supply chain attack, which hit hundreds of npm and PyPI packages. The...

  • NewsMay 13, 2026

    716,000 Impacted by OpenLoop Health Data Breach

    Telehealth platform OpenLoop Health has disclosed that a January 2026 cyberattack resulted in the exfiltration of personal information belonging to...

  • NewsMay 13, 2026

    Foxconn Confirms Cyberattack Claimed by Nitrogen Ransomware

    Foxconn, the world's largest electronics manufacturer, confirmed a cyberattack on its North American factories claimed by the Nitrogen ransomware gang,...

  • NewsMay 13, 2026

    Foxconn Confirms North American Factories Hit by Cyberattack

    Electronics manufacturing giant Foxconn has confirmed a cyberattack on its North American operations after the Nitrogen ransomware group claimed...

  • NewsMay 13, 2026

    Government to Scrutinize Instructure Over Canvas

    The House Committee on Homeland Security has demanded a briefing from Instructure, the company behind the Canvas LMS platform, after a ransomware attack...

  • NewsMay 13, 2026

    Škoda Warns of Customer Data Breach After Online Shop Hack

    Škoda Auto, the Czech automaker wholly owned by Volkswagen Group, has disclosed a data breach after attackers compromised its official online shop and...

  • NewsMay 12, 2026

    Instructure Reaches Ransom Agreement with ShinyHunters to

    Educational technology company Instructure, parent of Canvas LMS, has reached an undisclosed 'agreement' with the ShinyHunters extortion group after a...

  • NewsMay 12, 2026

    UK Fines Water Supplier $1.3M for Exposing Data of 664K

    The UK's Information Commissioner's Office has fined South Staffordshire Water Plc and its parent company £963,900 ($1.3 million) after a cyberattack...

  • NewsMay 12, 2026

    West Pharmaceutical Services Hit by Disruptive Ransomware

    West Pharmaceutical Services, a global manufacturer of drug delivery systems and packaging, has taken systems offline worldwide after hackers exfiltrated...

  • NewsMay 12, 2026

    West Pharmaceutical Warns of Ransomware Attack Impacting

    West Pharmaceutical Services filed an SEC disclosure warning that hackers breached the company on May 4, stole data, and encrypted systems — forcing a...

  • NewsletterMay 12, 2026

    May 12 Digest: AI-Generated Zero-Day, Shai-Hulud Worm

    Google confirms the first AI-generated zero-day in the wild; TeamPCP's Mini Shai-Hulud worm hits TanStack, Mistral AI, and Guardrails AI; Instructure pays...

  • NewsMay 11, 2026

    Skoda Data Breach Hits Online Shop Customers

    Hackers exploited a vulnerability in Skoda's online shop portal to access customer personal data including names, addresses, email addresses, and phone...

  • NewsMay 11, 2026

    UK Water Utility Fined £963,900 After Cl0p Lurked

    The UK's Information Commissioner's Office fined South Staffordshire Water nearly £1 million after the Cl0p ransomware group maintained undetected access...

  • NewsMay 11, 2026

    Why Changing Passwords Doesn't End an Active Directory

    Resetting compromised passwords is a natural first response to a breach, but it's not enough. Cached credentials, Kerberos ticket grants, and persistent...

  • NewsMay 10, 2026

    Canvas Breach Disrupts Schools & Colleges Nationwide

    A data extortion attack against Canvas LMS defaced login pages with a ransom demand, disrupting classes and coursework at school districts and...

  • NewsMay 10, 2026

    Canvas Login Portals Hacked in Mass ShinyHunters Extortion

    ShinyHunters has struck education technology giant Instructure again, exploiting a fresh vulnerability to deface Canvas login portals across hundreds of...

  • NewsMay 10, 2026

    GM to Pay Over $12 Million in California Privacy Settlement

    General Motors has agreed to pay over $12 million to settle California privacy violations under the CCPA after sharing detailed driver behavior data —...

  • NewsMay 10, 2026

    Multiple Universities Forced to Reschedule Final Exams

    Dozens of universities were forced to reschedule final examinations after a cybercriminal group displayed threatening messages through Canvas, the widely...

  • NewsMay 9, 2026

    GM to Pay Over $12 Million in Largest-Ever CCPA Fine Over

    California regulators have issued a record $12 million settlement against General Motors for sharing OnStar driving behavior data with insurers without...

  • NewsMay 9, 2026

    Trellix Source Code Breach Highlights Growing Supply Chain

    Trellix, the enterprise security vendor formed from the merger of McAfee Enterprise and FireEye, has suffered a source code breach claimed by the...

  • NewsMay 9, 2026

    Zara Data Breach Exposed Personal Information of 197,000

    Hackers gained access to Zara's customer databases and stole personal information belonging to more than 197,000 individuals, with the breach surfacing...

  • NewsMay 8, 2026

    NVIDIA Confirms GeForce NOW Data Breach Affecting Armenian

    NVIDIA has confirmed that GeForce NOW user data was exposed in a data breach, with the incident specifically affecting users in Armenia. The company...

  • NewsMay 8, 2026

    Trellix Source Code Breach Claimed by RansomHouse Hackers

    The RansomHouse threat group has claimed responsibility for the Trellix source code repository breach disclosed last week, leaking a set of proof images...

  • NewsMay 2, 2026

    Critical cPanel Flaw Mass-Exploited in 'Sorry' Ransomware

    A newly disclosed critical vulnerability in cPanel and WHM tracked as CVE-2026-41940 is being mass-exploited by ransomware actors to breach web hosting...

  • NewsMay 2, 2026

    Edu-Tech Firm Instructure Discloses Cyber Incident, Probes

    Instructure, the company behind the widely used Canvas learning management system, has disclosed a cybersecurity incident and is investigating its scope....

  • NewsMay 2, 2026

    Trellix Confirms Source Code Breach With Unauthorized

    Cybersecurity vendor Trellix has confirmed unauthorized access to a portion of its source code repository, engaging leading forensic experts to assess the...

  • NewsMay 1, 2026

    15-Year-Old Detained Over French Govt Agency Data Breach

    French authorities have detained a 15-year-old suspected of selling data stolen in a cyberattack on France Titres (ANTS), the agency responsible for...

  • NewsApr 30, 2026

    France Investigates 15-Year-Old Over Alleged Hack of

    French authorities took a 15-year-old into police custody on April 25 over suspected involvement in a data breach targeting ANTS, the National Agency for...

  • NewsApr 30, 2026

    Moldova's Health Insurance Agency Reports Possible Data

    Moldova's national health insurance agency CNAM has disclosed a cyberattack that occurred several weeks ago, with technical assessments indicating a...

  • NewsApr 30, 2026

    Sandhills Medical Says Ransomware Breach Affects 170,000

    Healthcare organization took nearly one year to publicly disclose a data breach after being targeted by Inc Ransom ransomware, with approximately 170,000...

  • NewsApr 29, 2026

    Learning from the Vercel Breach: Shadow AI and OAuth Sprawl

    The Vercel breach, traced to a compromised third-party AI tool with OAuth access, illustrates how Shadow AI adoption and unchecked OAuth integrations are...

  • NewsApr 28, 2026

    Medtronic Hack Confirmed After ShinyHunters Threatens Data

    Medical device giant Medtronic has confirmed a data breach after the ShinyHunters cybercrime group claimed to have stolen records belonging to 9 million...

  • NewsApr 28, 2026

    Video Service Vimeo Confirms Anodot Breach Exposed User Data

    Vimeo has confirmed that customer and user data was accessed without authorization following a security breach at Anodot, a data anomaly detection...

  • NewsletterApr 28, 2026

    Apr 28 Digest: Medtronic 9M Breach, GitHub RCE, LiteLLM

    ShinyHunters hits Medtronic and ADT in the same week, exposing millions of records; a critical one-push RCE lands in GitHub; LiteLLM's pre-auth SQL...

  • NewsApr 27, 2026

    Checkmarx Confirms GitHub Repository Data Posted on Dark

    Checkmarx has confirmed that data from its GitHub repositories has been published on the dark web following an investigation into the March 23 supply...

  • NewsApr 27, 2026

    Home Security Giant ADT Data Breach Affects 5.5 Million

    The ShinyHunters extortion group stole the personal information of 5.5 million individuals after breaching the systems of home security giant ADT earlier...

  • NewsApr 27, 2026

    Medtronic Confirms Breach After Hackers Claim 9 Million

    Medical device giant Medtronic has disclosed a data breach after hackers claimed to have stolen data from 9 million individuals across the company's...

  • NewsApr 27, 2026

    PhantomCore Exploits TrueConf Vulnerabilities to Breach

    Pro-Ukrainian hacktivist group PhantomCore has been attributed to a sustained campaign targeting TrueConf video conferencing servers across Russia since...

  • NewsApr 26, 2026

    American Utility Firm Itron Discloses Breach of Internal IT

    Itron, Inc. has disclosed a cybersecurity incident via SEC Form 8-K in which an unauthorized third party accessed certain internal systems at the utility...

  • NewsApr 25, 2026

    ADT Says Customer Data Stolen in Cyber Intrusion

    Home security giant ADT confirmed that cybercriminals breached its systems and stole a limited set of customer and prospective customer information. The...

  • NewsApr 25, 2026

    DORA and Operational Resilience: Credential Management as a

    Article 9 of DORA makes authentication and access control a legal obligation for EU financial entities. With stolen credentials now the single largest...

  • NewsApr 24, 2026

    ADT Confirms Data Breach After ShinyHunters Leak Threat

    Home security giant ADT has confirmed a data breach after the ShinyHunters extortion group threatened to publish stolen data unless a ransom is paid,...

  • SecurityApr 24, 2026

    CVE-2026-6887: Borg SPM 2007 SQL Injection Exposes Full

    A critical SQL injection vulnerability in the end-of-life Borg SPM 2007 application allows unauthenticated remote attackers to inject arbitrary SQL...

  • NewsApr 23, 2026

    Vercel Finds More Compromised Accounts in Context.ai-Linked

    Vercel has expanded its breach investigation tied to the Context.ai supply chain compromise and identified additional customer accounts with unauthorized...

  • NewsApr 22, 2026

    France Titres Confirms Data Breach as Hacker Offers Stolen

    France Titres, the French government agency responsible for issuing and managing administrative documents, has confirmed a cyberattack after a threat...

  • NewsApr 21, 2026

    Cloud Platform Vercel Says Company Breached Through

    Vercel has confirmed a security breach in which limited customer credentials were exposed after an employee's workstation was compromised through malware...

  • NewsApr 21, 2026

    French Government Agency France Titres Confirms Data Breach

    France Titres, the French government agency responsible for issuing administrative identity documents, has confirmed a data breach after a threat actor...

  • NewsletterApr 21, 2026

    Apr 21 Digest: Vercel AI Tool Breach, DPRK $290M, ActiveMQ

    Vercel confirms breach through a compromised third-party AI coding tool; North Korean hackers attributed to a $290 million crypto theft; 6,400 Apache...

  • NewsApr 20, 2026

    Next.js Creator Vercel Hacked

    Vercel confirmed suffering a breach after a hacker claiming to be part of ShinyHunters offered to sell stolen data for $2 million, affecting the company...

  • NewsApr 20, 2026

    Vercel Breach Tied to Context AI Hack Exposes Limited

    Vercel's security breach originated from the compromise of Context.ai, a third-party AI tool used by a company employee, allowing attackers to gain...

  • NewsApr 20, 2026

    Vercel Employee's AI Tool Access Led to Data Breach

    Stolen OAuth tokens from a compromised employee AI tool enabled attackers to pivot into Vercel's internal systems. Security researchers warn that...

  • NewsApr 20, 2026

    Vercel's Security Breach Started with Malware Disguised as

    The Vercel security breach originated at Context.ai after an employee downloaded Lumma Stealer disguised as Roblox cheat software. The incident exposes...

  • NewsApr 19, 2026

    6-Year Ransomware Campaign Targets Turkish Homes and SMBs

    A ransomware campaign operating since at least 2019 has persistently targeted Turkish home users and small-to-medium businesses, largely evading major...

  • NewsApr 19, 2026

    Microsoft, Salesforce Patch AI Agent Data Leak Flaws

    Prompt injection vulnerabilities in Salesforce Agentforce and Microsoft Copilot would have allowed unauthenticated attackers to exfiltrate sensitive CRM...

  • NewsApr 19, 2026

    Vercel Confirms Breach as Hackers Claim to Be Selling

    Cloud development platform Vercel has confirmed a security incident after threat actors claimed to have stolen internal databases, API keys, tokens, and...

  • NewsApr 11, 2026

    Your Next Breach Will Look Like Business as Usual

    Credential-based attacks now dominate the threat landscape, and traditional detection models are failing. Here are the fundamental shifts cybersecurity...

  • NewsApr 10, 2026

    Hims & Hers Breach Exposes the Most Sensitive Kinds of

    ShinyHunters exploited compromised Okta SSO credentials to breach the Hims & Hers Zendesk customer support platform, exposing treatment category data for...

  • NewsApr 9, 2026

    Breach Exposes Sensitive LAPD Files Stored in City Attorney

    A data breach of the Los Angeles city attorney's office systems has exposed sensitive LAPD law enforcement files, with social media posts advertising 7.7...

  • NewsApr 9, 2026

    Cryptocurrency ATM Giant Bitcoin Depot Reports $3.6 Million

    Bitcoin Depot, one of North America's largest Bitcoin ATM operators, has filed an SEC disclosure revealing a cyberattack in which threat actors gained...

  • NewsApr 9, 2026

    Eurail Says December Data Breach Impacts 300,000 Individuals

    Eurail B.V. has confirmed that a December 26, 2025 breach exposed the personal data of 308,777 individuals — including passport copies, IBAN bank details,...

  • NewsApr 9, 2026

    Hackers Steal $3.6 Million from Crypto ATM Giant Bitcoin

    Bitcoin Depot, operator of one of the largest Bitcoin ATM networks in North America, disclosed that attackers stole $3.665 million in Bitcoin from its hot...

  • NewsApr 8, 2026

    300,000+ Passport Numbers Leaked in December Eurail Data

    Eurail has disclosed a December 2025 data breach in which a hacker stole 1.3 TB of data including passport numbers for over 300,000 customers, source...

  • NewsApr 8, 2026

    Snowflake Customers Hit in Data Theft Attacks After SaaS

    Over a dozen companies have suffered data theft attacks after a SaaS integration provider was breached and authentication tokens stolen, enabling...

  • NewsApr 7, 2026

    FBI: Americans Lost a Record $21 Billion to Cybercrime Last

    The FBI's Internet Crime Complaint Center reports that U.S. victims lost nearly $21 billion to cyber-enabled crimes in 2025 — an all-time record — driven...

  • NewsApr 7, 2026

    Medusa Ransomware Is Fast to Exploit Fresh Vulnerabilities

    SecurityWeek reports that the Medusa ransomware group has developed a dangerous capability: rapidly weaponizing newly disclosed vulnerabilities —...

  • NewsApr 7, 2026

    Medusa Ransomware Exploits Zero-Days to Deploy Ransomware

    Microsoft has raised the alarm over Medusa ransomware's unprecedented operational speed, with the group now exploiting zero-day vulnerabilities before...

  • NewsApr 7, 2026

    The Hidden Cost of Recurring Credential Incidents

    IBM's 2025 Cost of a Data Breach Report puts the average breach at $4.4 million — but that headline figure understates the true damage when credential...

  • NewsApr 6, 2026

    Medusa Ransomware Group Exploits Zero-Days to Strike Within

    Microsoft warns that Medusa ransomware operators are exploiting zero-day vulnerabilities approximately one week before public disclosure, enabling the...

  • NewsApr 6, 2026

    GPUBreach: New Rowhammer Attack on GPU GDDR6 Memory Enables

    Researchers from the University of Toronto have demonstrated GPUBreach, a novel attack that induces Rowhammer bit-flips in GPU GDDR6 memory to bypass...

  • NewsApr 6, 2026

    Why Simple Breach Monitoring Is No Longer Enough

    Infostealers are harvesting credentials and session cookies at scale, quietly bypassing MFA and traditional defenses. Here's why organizations need...

  • NewsApr 4, 2026

    EU Cyber Agency Attributes Major Data Breach to TeamPCP

    ENISA has officially attributed the massive European Commission data breach — and a wider campaign affecting 30 EU institutions — to the TeamPCP hacking...

  • NewsApr 4, 2026

    European Commission Confirms Data Breach Linked to Trivy

    The European Commission has confirmed a major data breach of its AWS environment, with over 300GB of data stolen — including personal information of EU...

  • NewsApr 4, 2026

    Hims & Hers Warns of Data Breach After Zendesk Support

    Telehealth giant Hims & Hers Health is warning customers of a data breach after support tickets were stolen from a third-party customer service platform,...

  • NewsApr 3, 2026

    250,000 Affected by Data Breach at Nacogdoches Memorial

    Nacogdoches Memorial Hospital in Texas has disclosed a January 2026 data breach in which a threat actor accessed its internal network and stole personal...

  • NewsApr 3, 2026

    Blast Radius of TeamPCP Attacks Expands Amid Hacker

    As organizations disclose breaches tied to TeamPCP's supply chain attacks, ShinyHunters and Lapsus$ are taking credit and creating a murky attribution...

  • NewsApr 3, 2026

    CERT-EU: European Commission Hack Exposes Data of 30 EU

    CERT-EU has attributed the European Commission cloud account compromise to the TeamPCP threat group, revealing the breach exposed sensitive data from at...

  • NewsApr 3, 2026

    Claude Source Code Leak Highlights Big Supply Chain Missteps

    The accidental exposure of Anthropic's Claude Code source code via an npm packaging error is the latest reminder that software supply chains need...

  • NewsApr 3, 2026

    Die Linke German Political Party Confirms Data Stolen by

    The Qilin ransomware group has claimed responsibility for an attack against German political party Die Linke, forcing an IT systems outage and threatening...

  • NewsApr 2, 2026

    Hackers Exploit CVE-2025-55182 to Breach 766 Next.js Hosts

    A large-scale credential harvesting campaign has been observed exploiting the React2Shell vulnerability (CVE-2025-55182) as an initial infection vector,...

  • NewsApr 2, 2026

    Nissan Says Stolen Data Came from Third-Party Vendor After

    A hacking group claimed to have breached the file-transfer system used by a company that provides services to Nissan and Infiniti dealerships across North...

  • NewsApr 1, 2026

    Claude Code Source Leaked via npm Packaging Error

    Anthropic confirmed that internal source code for its Claude Code AI coding assistant was accidentally published to npm due to a human packaging error. No...

  • NewsMar 31, 2026

    Cisco Source Code Stolen in Trivy-Linked Dev Environment

    Cisco has suffered a major cyberattack after threat actors leveraged stolen credentials from the recent Trivy supply chain compromise to breach its...

  • NewsMar 31, 2026

    Dutch Finance Ministry Takes Treasury Banking Portal

    The Netherlands Ministry of Finance has taken its treasury banking portal offline after detecting a cyberattack that went undetected for roughly two...

  • NewsMar 31, 2026

    Leak Bazaar: New Criminal Service Plans to Monetize Data

    A new underground platform called Leak Bazaar positions itself as a data-processing business, offering to monetize stolen records on behalf of ransomware...

  • NewsMar 31, 2026

    Stolen Logins Are Fueling Everything From Ransomware to

    A new report reveals how industrialized credential theft has become the common thread connecting ransomware campaigns, SaaS platform breaches, and...

  • NewsMar 30, 2026

    European Commission Confirms Data Breach After Europa.eu

    The European Commission has confirmed a data breach after its Europa.eu web platform was compromised in an attack claimed by the ShinyHunters extortion gang.

  • NewsMar 30, 2026

    Healthcare Software Firm CareCloud Informs SEC of Potential

    CareCloud has notified the U.S. Securities and Exchange Commission of a cyberattack that may have resulted in the unauthorized access and potential...

  • NewsMar 30, 2026

    Healthcare Tech Firm CareCloud Says Hackers Stole Patient

    Healthcare IT company CareCloud has disclosed a cyberattack that resulted in the theft of sensitive patient data and caused an eight-hour network outage,...

  • NewsMar 29, 2026

    FBI Confirms Hack of Director Patel's Personal Email Inbox

    Iran-linked Handala hackers have breached the personal email account of FBI Director Kash Patel, publishing stolen photos and documents in a high-profile...

  • NewsMar 29, 2026

    ShinyHunters Breach Infinite Campus — K-12 Platform Serving

    ShinyHunters claimed a breach of Infinite Campus on March 22, 2026, after gaining access through an employee's Salesforce account. The K-12 student...

  • NewsMar 28, 2026

    Iran-Linked Hackers Breach FBI Director's Personal Email

    Iran's Handala Hack Team breached the personal email of FBI Director Kash Patel, leaking photos and documents online, while simultaneously launching a...

  • NewsMar 27, 2026

    European Commission Investigating Breach After Amazon Cloud

    The European Commission is investigating a security breach after a threat actor gained unauthorized access to its Amazon Web Services cloud environment...

  • NewsMar 26, 2026

    Russia Detains Alleged Admin of LeakBase Cybercrime Forum

    Russian authorities have detained a suspected administrator of LeakBase, a major stolen-data marketplace with over 147,000 subscribers, just weeks after...

  • NewsMar 25, 2026

    DarkSword GitHub Leak Threatens to Turn Elite iPhone

    Researchers say the GitHub leak of the DarkSword iOS exploit chain — six chained vulnerabilities targeting iOS 18.4 through 18.7 — threatens to...

  • NewsMar 25, 2026

    LeakBase Admin Arrested in Russia Over Massive Stolen

    Russian law enforcement has arrested the alleged administrator of LeakBase — a credential marketplace operating since 2021 with 142,000 members and...

  • NewsletterMar 25, 2026

    Mar 25 Digest: DarkSword Leaks iPhone Zero-Days

    This week: the DarkSword iOS exploit chain published on GitHub threatens to democratize nation-state-grade iPhone hacking; CanisterWorm turns the Trivy...

  • NewsMar 24, 2026

    3.1 Million Impacted by QualDerm Partners Data Breach

    QualDerm Partners, a national dermatology network operating 158 practices across 17 states, disclosed a December 2025 data breach that exposed the medical...

  • NewsMar 24, 2026

    Hacker Walks Away with $24.5 Million After Breaching Resolv

    A compromised private key allowed an attacker to mint $80 million in unbacked USR stablecoins on the Resolv DeFi protocol, extract $24.5 million in ETH,...

  • NewsMar 23, 2026

    Crunchyroll Probes Breach After Hacker Claims to Steal 6.8M

    Popular anime streaming platform Crunchyroll is investigating a breach after hackers claimed to have stolen personal information for approximately 6.8...

  • NewsMar 23, 2026

    Mazda Discloses Security Breach Exposing Employee and

    Mazda Motor Corporation has disclosed a security incident detected in December 2025 in which unauthorized access to a warehouse management system exposed...

  • NewsMar 22, 2026

    Cegedim Santé Breach Exposes 15.8 Million French Healthcare

    A cyberattack on French healthcare software vendor Cegedim Santé exposed 15.8 million patient records from 3,800 doctors, with leaked data including...

  • NewsMar 22, 2026

    Malaysia Airlines Listed by Qilin Ransomware Group

    The Qilin ransomware-as-a-service group has listed Malaysia Airlines on its leak site, claiming access to passenger records, personnel files, and...

  • NewsMar 22, 2026

    Trivy Vulnerability Scanner Breached to Push Infostealer

    The Trivy open-source vulnerability scanner was compromised in a supply chain attack by the threat group TeamPCP, which hijacked 75 release tags and...

  • NewsMar 21, 2026

    Two US Cybersecurity Professionals Plead Guilty to BlackCat

    Former incident responder Ryan Goldberg and ransomware negotiator Kevin Martin admitted to running ALPHV/BlackCat ransomware operations against five US...

  • NewsMar 21, 2026

    Marquis Fintech Breach Exposes 672,000 Banking Customers

    Plano-based fintech vendor Marquis disclosed that a ransomware attack exploiting a SonicWall firewall vulnerability compromised Social Security numbers,...

  • NewsMar 20, 2026

    Navia Data Breach Impacts 2.7 Million People

    Navia Benefit Solutions has confirmed a data breach that exposed personal and health plan information belonging to approximately 2.7 million individuals,...

  • NewsMar 20, 2026

    Navia Discloses Data Breach Impacting 2.7 Million People

    Navia Benefit Solutions has notified nearly 2.7 million individuals of a data breach that exposed sensitive personal and health-related information to...

  • NewsMar 20, 2026

    Trivy Security Scanner GitHub Actions Breached — 75 Tags

    Trivy, Aqua Security's widely used open-source vulnerability scanner, was compromised a second time in a month. Attackers hijacked 75 GitHub Actions tags...

  • NewsMar 18, 2026

    Marquis Ransomware Breach: 672K People Exposed as Attack

    Texas fintech Marquis Software Solutions has confirmed a ransomware attack in August 2025 exposed data of 672,000+ individuals and disrupted operations at...

  • NewsMar 18, 2026

    Shadow AI in SaaS: How Hidden AI Agents Are Enabling

    A new Grip Security report analyzing 23,000 SaaS environments finds 100% of companies operate shadow AI they cannot see or control — with a 490% spike in...

  • NewsletterMar 17, 2026

    Mar 17 Digest: GlassWorm Poisons Python, n8n RCE Hits KEV

    This week: GlassWorm escalates with 72 malicious Open VSX extensions and a GitHub token force-push campaign poisoning hundreds of Python repos; CISA adds...

  • NewsMar 13, 2026

    England Hockey Investigating Data Breach After AiLock

    England Hockey, the national governing body for field hockey in England, is investigating a potential data breach after the AiLock ransomware group listed...

  • NewsMar 13, 2026

    Telus Digital Confirms Massive Breach After ShinyHunters

    Canadian telecom giant Telus Digital has confirmed a security incident after the ShinyHunters hacking group claimed to have stolen nearly 1 petabyte of...

  • NewsletterMar 11, 2026

    Mar 11 Digest: npm Supply Chain Seizes AWS Admin, 3.4M

    This week: UNC6426 weaponizes a stale npm supply chain compromise to seize full AWS admin in 72 hours, Cognizant TriZetto leaks 3.4 million patient...

  • NewsMar 9, 2026

    Ericsson US Discloses Data Breach Affecting Employees and

    Ericsson's U.S. subsidiary has disclosed a data breach after attackers hacked a third-party service provider between April 17–22, 2025, exposing names,...

  • NewsMar 7, 2026

    Cognizant TriZetto Breach Exposes Health Data of 3.4

    TriZetto Provider Solutions, a Cognizant subsidiary serving 875,000 US healthcare providers, has confirmed a 2024 cyberattack went undetected for nearly a...

  • NewsMar 4, 2026

    LexisNexis Confirms Cloud Breach Exposing 400K User

    LexisNexis Legal & Professional confirms a data breach after threat actor FulcrumSec exploited an unpatched React2Shell vulnerability to exfiltrate 2.04...

  • NewsFeb 27, 2026

    IDMerit KYC Data Breach Exposes 1 Billion Records Across 26

    An unprotected MongoDB instance belonging to identity verification firm IDMerit left over 1 billion personal records — including SSNs, passport numbers,...

  • NewsFeb 24, 2026

    AT&T Breach Data Resurfaces: 176 Million Records with Fully

    A repackaged dataset containing 176 million AT&T customer records — including 148 million now-decrypted Social Security numbers — began circulating among...

  • NewsFeb 23, 2026

    HellCat Ransomware Group Breaches Ascom, Exfiltrates 44GB

    The HellCat ransomware group has breached Swiss enterprise communications provider Ascom by exploiting Jira credentials harvested through infostealer...

  • NewsFeb 20, 2026

    Fintech Giant Figure Technology Confirms Breach: Nearly 1

    Blockchain-based lending platform Figure Technology Solutions confirms a data breach affecting nearly 1 million customers after ShinyHunters exploited an...

  • NewsFeb 20, 2026

    ShinyHunters Dumps Harvard and UPenn Data After Ransom

    The ShinyHunters cybercriminal syndicate has published stolen data from Harvard University and the University of Pennsylvania after both institutions...

  • NewsFeb 20, 2026

    Japan Airlines Confirms Data Breach Affecting 28,000

    Japan Airlines reveals unauthorized access to its Same-Day Baggage Delivery Service reservation system compromised personal data of up to 28,000...

  • NewsFeb 20, 2026

    WormGPT Hacked: 19,000 Cybercriminal AI Platform Users

    A threat actor has published a database allegedly containing 19,000 user records from WormGPT, the underground AI platform marketed for offensive hacking...

  • NewsFeb 19, 2026

    Conduent Breach Balloons to Tens of Millions of Americans

    The January 2025 ransomware attack on government technology giant Conduent continues to expand in scope, now confirmed to affect 15.4 million in Texas and...

  • NewsFeb 19, 2026

    Hacker Accesses 1.2 Million French Bank Accounts via

    The French Economy Ministry confirmed that a hacker stole credentials from a government official and accessed France's FICOBA centralized bank account...

  • NewsFeb 16, 2026

    ShinyHunters Dumps 600K+ Canada Goose Customer Records on

    Data extortion group ShinyHunters posts 1.67 GB of alleged Canada Goose customer data including names, emails, addresses, and partial payment card...

  • NewsFeb 13, 2026

    AI Chat App Exposes 300 Million Private Messages from 25

    A misconfigured Google Firebase backend in the Chat & Ask AI app exposed 300 million private chatbot conversations from 25 million users, including...

  • NewsFeb 13, 2026

    Odido Data Breach Exposes 6.2 Million Dutch Telecom

    The Netherlands' largest mobile network operator Odido has disclosed a data breach affecting 6.2 million customers, exposing names, addresses, bank...

  • NewsFeb 12, 2026

    Louis Vuitton, Dior, and Tiffany Fined $25 Million Over

    South Korea's data protection authority has fined three LVMH luxury brands a combined $25 million for data breaches affecting millions of customers, with...

  • NewsFeb 11, 2026

    6.8 Billion Emails Exposed Online in Massive Data Leak

    A hacker revealed 6.8 billion email addresses online on February 11, 2026, in one of the largest email database leaks in history, raising concerns about...

  • NewsFeb 5, 2026

    ShinyHunters Dumps 5.1 Million Panera Bread Customer

    The ShinyHunters hacking group published a 760 MB archive of 5.1 million Panera Bread customer records on the dark web after the company refused to pay a...

  • NewsFeb 5, 2026

    Substack Discloses Data Breach After 100-Day Undetected

    Substack CEO Chris Best disclosed a data breach on February 5 affecting approximately 700,000 users, after an unauthorized party accessed the platform...

  • SecurityFeb 5, 2026

    Conduent Breach Expands: 15.4 Million Texans Affected, 8TB

    Government technology provider Conduent's January 2025 ransomware breach now confirmed to affect at least 15.4 million people in Texas alone, with 8TB of...

  • SecurityFeb 5, 2026

    Iron Mountain Responds to Everest Ransomware Breach Claims

    Information management giant Iron Mountain clarifies that alleged 1.4TB breach was limited to marketing materials after single credential compromise.

  • NewsFeb 4, 2026

    Ransomware Attacks Surge in Early 2026 with 26 Claims in

    Threat intelligence reports show 8 active ransomware groups claimed 26 victims on February 2nd alone, with major corporations including BASF and Honeywell...

  • NewsJan 23, 2026

    Nike Hit by Data Breach: 1.4 TB of Supply Chain Data Leaked

    WorldLeaks extortion group claims responsibility for a data breach on Nike, allegedly exposing 1.4 terabytes of internal data including supply chain and...

  • NewsJan 15, 2026

    Covenant Health Ransomware Attack Impacts 478,000 Patients

    Qilin ransomware group claims responsibility for massive healthcare breach, stealing 850GB of sensitive patient data across multiple states. Initial...

  • NewsJan 12, 2026

    Telegram Investigating Claims of 30 Million User Data Breach

    Telegram is investigating claims that a threat actor is selling data from 30 million users. The company denies any breach of its systems while the...

  • NewsJan 5, 2026

    Sedgwick Government Solutions Hit by TridentLocker

    Claims administration firm Sedgwick confirms cybersecurity incident at government subsidiary after TridentLocker ransomware group claims theft of 3.4 GB...