Temu Data Leak Claim: 310M Records for Sale
Major data leaks rarely begin with hard proof. The Temu case follows that same pattern. A loud claim on a shadow forum can point to a real breach. Or it can point to an...
Major data leaks rarely begin with hard proof. The Temu case follows that same pattern. A loud claim on a shadow forum can point to a real breach. Or it can point to an...
Unidentified threat actors successfully breached the National Association of Insurance Commissioners (NAIC). They exploited a critical vulnerability within Oracle PeopleSoft. Consequently, the organization temporarily suspended assigning investment ratings to insurance assets. Furthermore, they disabled...
Target/Victims: Klue, LastPass, and others. Delivery Vector: Compromised integration service credentials from 2022. Key Capabilities: Unauthorized Salesforce CRM access via stolen OAuth tokens. Threat Actor: Icarus ransomware group (Suspected). Source: Klue, LastPass, and affected...
FortiBleed began as mass password guessing. Then it grew into an attack chain, where hijacked firewalls gathered fresh credentials for the next breach. A new timeline shows that the published FortiGate password database was...
The longer an electronics supply chain grows, the harder it gets to keep trade secrets inside factory walls. India’s Tata Electronics has now confirmed a recent cyber incident. The confirmation followed reports that files...
The market intelligence platform Klue has confirmed a breach of part of its integration infrastructure. Attackers obtained OAuth tokens, the digital keys that grant access between services. With those keys, they slipped into the...
Novo Nordisk recently fell victim to a sophisticated cyberattack. Consequently, this incident compromised a segment of patient data from clinical trials. Fortunately, the company asserted that names and direct identifiers remained unexposed. Therefore, unauthorized...
Account recovery architectures often resemble emergency entries during credential failures. However, a flaw in this mechanism enabled widespread profile takeovers. Recently, Meta disclosed a severe infrastructure breach. The corporate giant revealed that adversaries weaponized...
Exploitation of Booking Architecture Guests across dozens of Dutch hotels recently encountered highly deceptive communications. Specifically, these fraudulent notifications demanded immediate payment to validate active room reservations. Consequently, industry data indicates that adversaries successfully...
IKEA is currently investigating a bold claim by the cybercrime syndicate Lapsus$. Specifically, the group asserts it breached 180 gigabytes of internal files from Ingka Group. This entity operates as the brand’s primary global...
Websites possess a novel, obscured mechanism to monitor online visitors. Crucially, this approach completely bypasses traditional hardware peripherals like cameras, microphones, or weaponized browser extensions. Instead, it merely utilizes standard JavaScript code to detect...
An illicit ledger advertised within subterranean cybercrime forums is currently being cross-examined by security researchers following assertions that it encapsulates 340 million sensitive user records harvested from OnlyFans. While the preliminary manifesto suggested a...