Home/ Blog/ Topics/ Data breaches
Topic

Data breaches

Confirmed breaches and large-scale data theft: what was taken, how it happened, and what exposed organizations should do next.

Security news

A public exploit turns Kaspersky's endpoint agent into a privilege-escalation tool on fully patched Windows 11

A public exploit, HardBreacher, coerces Kaspersky Endpoint Security into a privileged write on fully patched Windows 11. Vendor says fixed, no CVE yet.

Security news

Manchester Airports breach: a marketing API key exposed in client-side JavaScript

An extortion group says it pulled 86GB from Manchester Airports Group using a marketing API key exposed in client-side JavaScript.

Security news

CISA red team breached two critical infrastructure networks. Only one SOC noticed.

A CISA red team hit two critical infrastructure networks with the same tradecraft. One SOC contained it in minutes, the other never noticed. Here is the gap.

Security news

Encrypted page instructions make Grok leak your chat history

Adversa AI showed encrypted web-page instructions can make xAI's Grok leak your chat history and session data. Why plaintext filters miss it, and how to defend.

Security news

A breach at shipping partner Ceva Logistics exposed customer data for Steam, ING and other brands

A cyberattack on shipping partner Ceva Logistics exposed customer names, addresses and order details for Steam, ING, bol and more.

Security news

Fake IT help-desk calls are stealing Microsoft 365 and Okta data

A vishing crew posing as IT help desk on personal phones steals Microsoft 365 and Okta sessions, then renames to dodge IOC lists. Here is how to detect it.

Security news

Atlassian Rovo could leak Jira and Confluence data; one of two attack routes is unconfirmed as fixed

Two firms found Atlassian Rovo could be tricked into leaking Jira, Confluence and SharePoint data. One attack route is patched; the other is unconfirmed.

Security news

Metabase zero-day (CVSS 10.0): unauthenticated SQL injection hands attackers admin and data. Patch now.

Metabase's SQL injection zero-day (CVSS 10.0) gives unauthenticated attackers admin access and stored database credentials. Exploited now: patch and rotate.

Security news

The Snowflake hacker pleaded guilty. The breach used no exploit, just old passwords and MFA left off.

The Snowflake hacker pleaded guilty to breaching 165 companies and exposing 100M people.

Security news

Anthropic's own AI models breached three real companies in tests

Anthropic says three of its AI models breached real companies during security tests after a sandbox misconfiguration. Two of three victims never noticed.

Security news

An AI agent breached Hugging Face. Blocklists can't catch it.

Hugging Face says an autonomous AI agent breached it, taking internal data and service credentials.

Security news

EY's breach came through the help desk, not the audit floor

EY says client tax data leaked from a third-party IT support platform, not its audit systems. Why help-desk tooling is a crown-jewel store, and how to watch it.

Security news

Progress tells ShareFile users to shut servers down, and no patch means assume breach

Progress told ShareFile customers to shut down on-premises Storage Zone Controllers over a credible threat.

Security news

A rigged Jira ticket can trick the mcp-atlassian AI connector into leaking server files

mcp-atlassian before 0.22.0 reads files off its own host when a caller or a prompt-injected agent supplies a server-side path.

Security news

A public GitHub issue made an AI agent leak a private repo. No patch closes this class.

A crafted public GitHub issue tricked an AI Agentic Workflow into posting a private repo's contents as a public comment. Why no patch closes this class.

Security news

Kairos stole 2TB, encrypted nothing, and still got $1M. Watch the login, not the file locker.

Kairos stole 2TB from a US county, encrypted nothing, and was paid $1M. Encryptionless extortion breaks file-locker alarms. Detect the login and egress.

Security news

A USB worm swaps your crypto address mid-paste, and no breach alarm ever fires

Microsoft found a USB worm that hijacks the clipboard to swap crypto wallet addresses and hides its command channel in Tor. Here is why it beats your controls.

Security news

Your Salesforce wasn't breached. A connected app handed over the data.

The Icarus group stole Salesforce CRM data through Klue's connected app, not a Salesforce flaw. Why OAuth integration tokens are the unmonitored attack surface.

Security news

SearchLeak in Microsoft 365 Copilot: prompt injection as a new door to old bugs

SearchLeak chained prompt injection, an HTML render race, and Bing SSRF to steal Microsoft 365 Copilot data in one click. What it means for detection.

Security news

Ivanti Sentry's CVE-2026-10520: patch the gateway, then hunt for the breach

Ivanti Sentry CVE-2026-10520 is an unauthenticated root RCE under active attack. CISA's new 3-day patch rule applies; patched gateways were already breached.

Security news

PeopleSoft's PSEMHUB zero-day turns the patch service into the breach

CVE-2026-35273 sits in PeopleSoft's Updates Environment Management module. Mandiant ties active exploitation to ShinyHunters, with 100+ orgs already breached.

Ready to meet the Guardians?

Deploys fast - agentless for monitoring and cloud, a lightweight agent for deep endpoint security. Just Suriq, standing watch.