Education Sector Data Breaches (11599 indexed)
Liechtenstein Government
31K beneficial ownership records exposed
CareCloud Health Tech
350K patient medical and financial records exposed
Cookeville Regional Medical Center
330K patient records exposed in ransomware attack
Basic-Fit Gym Operator
1M members bank and personal data breached
I was mapping the command-and-control infrastructure behind a state-linked intrusion set
I was mapping the command-and-control infrastructure behind a state-linked intrusion set when the query came back and effectively ended the exercise I thought I was running. The malware resolved its C2 address by read
Canadian Credit Firm
55GB PII and financial records of 28K customers
Brazil's SISVISA health surveillance system left 102,215 files totaling 79GB open
Brazil's SISVISA health surveillance system left 102,215 files totaling 79GB open online, including tax IDs and identity documents, without password protection.
Dutch retailer De Bijenkorf
Amsterdam-based luxury goods chain De Bijenkorf is the latest retailer to announce a cyber incident involving a third-party logistics provider.
GitGuardian researchers found 321 n8n instances accepting API tokens exposed in public
GitGuardian researchers found 321 n8n instances accepting API tokens exposed in public GitHub commits and demonstrated four ways attackers could use them to access sensitive data and downstream credentials without exploi
3 Paperclip flaws exposed data & allowed unauthenticated command execution in two
3 Paperclip flaws exposed data & allowed unauthenticated command execution in two deployment modes
Unitel, Angola's dominant mobile operator, continues to recover from a cyberattack that
Unitel, Angola's dominant mobile operator, continues to recover from a cyberattack that caused outages the day of the government-owned telco's public offering.
Reports said intruders appeared to gain access to the Jira environment and other
Reports said intruders appeared to gain access to the Jira environment and other sensitive data of the Żabka retail chain. The company confirmed an intrusion occurred in late July.
A self-propagating worm-like attack is
A self-propagating worm-like attack is hitting the npm registry, having infected 444 packages from more than a dozen publishers so far. The impact is massive, with the packages affected amounting to more than 2 billion m
The UK’s Police National Legal Database and Ask the Police service have been breached
The UK’s Police National Legal Database and Ask the Police service have been breached
Swiss IT agency
The Federal Office for Information Technology and Communications (BIT) said specialists detected anomalies in on-premises Microsoft servers. The Swiss agency could not confirm exactly how the hackers got in.
The top cybersecurity product
Black Hat 2026 is shaping up to be another AI-heavy conference, but this year’s announcements suggest the industry is moving beyond simply adding copilots to existing products. Vendors are increasingly packaging AI in
A crafted prompt to a low-privilege Google ADK agent could be used to pass a malicious
A crafted prompt to a low-privilege Google ADK agent could be used to pass a malicious hand-off comment to a privileged agent. The post Gemini Agent-to-Agent Attack Method Exposed Secrets, Enabled Pull Request Tampering
Black Hat 2026 is shaping up to be another AI-heavy conference, but this year’s
Black Hat 2026 is shaping up to be another AI-heavy conference, but this year’s announcements suggest the industry is moving beyond simply adding copilots to existing products. Vendors are increasingly packaging AI in
IBM Langflow
IBM Langflow Code Injection Vulnerability — Langflow contains a code injection vulnerability that allows unauthenticated attackers to achieve full remote code execution on default Langflow deployments.