Topic: security breach

  • Vercel Data Breach Traced to Third-Party AI Tool

    Vercel Data Breach Traced to Third-Party AI Tool

    A security breach at Vercel originated from a compromised third-party AI tool (Context.ai), allowing attackers to pivot from an employee's Google Workspace account into Vercel's internal systems and access non-sensitive environment variables. The incident was enabled by overly permissive OAuth gr...

    Read More »
  • eScan Server Breach Delivers Malicious Software Update

    eScan Server Breach Delivers Malicious Software Update

    eScan antivirus software experienced a supply chain attack where a compromised regional update server distributed a malicious file to a limited number of customers during a specific window in January 2026. The malicious update delivered a tampered component that established persistence, executed ...

    Read More »
  • SoundCloud Data Breach Exposes User Info, Disrupts VPN Access

    SoundCloud Data Breach Exposes User Info, Disrupts VPN Access

    SoundCloud confirmed a security breach where unauthorized access to an internal system led to the theft of a user database, exposing email addresses and public profile information for a significant portion of its user base. The breach caused service disruptions, including users being blocked with...

    Read More »
  • Hugging Face Hack Linked to Autonomous AI Agent

    Hugging Face Hack Linked to Autonomous AI Agent

    An autonomous AI agent infiltrated Hugging Face's internal systems by exploiting a security vulnerability, marking an escalation in AI-driven cyberattacks that can operate without direct human command. The breach was quickly contained after detection through routine monitoring, but it potentially...

    Read More »
  • Hugging Face breach exposed internal data; users urged to act

    Hugging Face breach exposed internal data; users urged to act

    Hugging Face disclosed a security breach that compromised internal datasets and service credentials after an uploaded dataset exploited a vulnerability, allowing attackers to run malicious code and escalate permissions on its servers. The company has fixed the exploited vulnerability, revoked sto...

    Read More »
  • CPUID site hacked to distribute malware via HWMonitor

    CPUID site hacked to distribute malware via HWMonitor

    The official CPUID website, known for tools like HWMonitor, was compromised earlier this year, redirecting users to credential-stealing malware for a critical six-hour window. This was a sophisticated supply chain attack that exploited user trust in the official brand to distribute data-harvestin...

    Read More »
  • CBP Facility Codes Leaked in Online Flashcards

    CBP Facility Codes Leaked in Online Flashcards

    A publicly accessible Quizlet flashcard set labeled "USBP Review" disclosed sensitive U.S. Customs and Border Protection details, including confidential access codes and operational procedures, before being made private in late March 2026 after a media inquiry. The exposed information included sp...

    Read More »
  • Step Finance Blames Hacked Execs for $40M Crypto Theft

    Step Finance Blames Hacked Execs for $40M Crypto Theft

    A major Solana analytics platform suffered a $40 million security breach, attributed to compromised executive devices, highlighting critical vulnerabilities in DeFi beyond smart contract audits. The breach involved unauthorized access to treasury wallets via a known attack vector, with the platfo...

    Read More »
  • Brightspeed Customers Disconnected in Alleged Hack

    Brightspeed Customers Disconnected in Alleged Hack

    A hacking group called Crimson Collective claims to have breached Brightspeed, a major U.S. internet service provider, compromising extensive customer data including personal details, location information, and partial financial records. The group also claims to have intentionally disrupted custom...

    Read More »
  • Sedgwick Subsidiary Breach Exposes Government Contractor Data

    Sedgwick Subsidiary Breach Exposes Government Contractor Data

    A data breach at Sedgwick Government Solutions exposed sensitive information from over twenty federal agency clients, including CISA, DHS, and CBP, though the parent company's core network was unaffected. The breach was isolated to a file transfer system, with no evidence of access to primary cla...

    Read More »
  • Salesforce Reveals Gainsight Breach Details and Investigation Steps

    Salesforce Reveals Gainsight Breach Details and Investigation Steps

    Salesforce disclosed a security incident involving Gainsight applications, with unauthorized access likely starting on November 8 and suspicious activity detected from mid-November using IPs from VPNs, Tor, and AWS. Indicators of compromise include specific IP addresses and a suspicious User Agen...

    Read More »
  • State-Sponsored Hackers Breached SonicWall in September

    State-Sponsored Hackers Breached SonicWall in September

    State-sponsored hackers breached SonicWall's cloud environment in September, accessing firewall configuration backup files via an API call, but no products, firmware, or customer networks were compromised. The exposed backup files contained sensitive credentials, prompting SonicWall to advise aff...

    Read More »
  • SonicWall Firewall Backups Compromised by Attackers

    SonicWall Firewall Backups Compromised by Attackers

    SonicWall confirmed that attackers used brute-force methods to access its cloud backup API, compromising configuration backup files for all customers who used the service, contradicting earlier statements about a limited impact. The compromised files contain sensitive data like network settings, ...

    Read More »
  • SonicWall Urges Password Reset Following Security Breach

    SonicWall Urges Password Reset Following Security Breach

    SonicWall has advised customers to reset passwords after detecting unauthorized access to firewall configuration backup files in some MySonicWall accounts, which contain sensitive data like credentials and tokens. The company confirmed this was not a ransomware attack but a series of targeted bru...

    Read More »
  • Google: Salesloft AI Agent Data Breach Escalates Significantly

    Google: Salesloft AI Agent Data Breach Escalates Significantly

    Google has issued a critical alert warning that all security tokens for Salesloft Drift AI should be considered compromised due to unauthorized access via stolen credentials. The breach, initially thought to be limited to Salesforce integration, has expanded to include other services, prompting G...

    Read More »
  • Suno AI Trained on 2M+ YouTube Songs

    Suno AI Trained on 2M+ YouTube Songs

    A hacker leaked Suno's source code, revealing the AI music company scraped millions of songs and lyrics from YouTube, Deezer, Genius, and Pond5 to train its model, including over 2 million YouTube video clips and 420,000 podcasts. Suno employed targeted methods like searching for a cappella versi...

    Read More »
  • LiteLLM Ends Partnership with Delve AI

    LiteLLM Ends Partnership with Delve AI

    LiteLLM has ended its partnership with Delve AI following a security breach that compromised its open-source software with credential-stealing malware. Delve AI faces whistleblower allegations of fabricating compliance data and using auditors with insufficient oversight, which it denies while off...

    Read More »
  • Dutch police reveal data breach from phishing attack

    Dutch police reveal data breach from phishing attack

    The Dutch National Police confirmed a contained security breach from a phishing attack, with its Security Operations Center swiftly terminating access and preliminary findings indicating no exposure of citizens' data or sensitive investigative information. This incident follows a September 2024 d...

    Read More »
  • US Nuclear Plant Hacked Through SharePoint Vulnerabilities

    US Nuclear Plant Hacked Through SharePoint Vulnerabilities

    A foreign actor breached the Kansas City National Security Campus by exploiting unpatched Microsoft SharePoint vulnerabilities, revealing critical cybersecurity flaws in sensitive government infrastructure. The compromised facility, managed by Honeywell FM&T for the NNSA, produces essential non-n...

    Read More »
  • Meta Halts Employee Tracking After Internal Data Leak

    Meta Halts Employee Tracking After Internal Data Leak

    Meta has paused its Model Compatibility Initiative (MCI) employee surveillance program after an internal data breach exposed potentially sensitive information collected through the tool to other staff members. The MCI tool collects computer inputs like mouse movements, clicks, and keystrokes to t...

    Read More »