< ciso
brief />
Tag Banner

All news with #data breach tag

934 articles · page 3 of 47

Hundreds of GitHub App private keys still valid

🔒 Research from GitGuardian found thousands of exposed GitHub App private keys in public code, with 474 still authenticating as 440 distinct Apps. The leaked keys never expire unless manually revoked, enabling holders to request indistinguishable access tokens and potentially gain wide repository and organizational privileges. Several high-impact keys affected private repositories and organization administration, prompting coordinated disclosures and key rotations.
read more →

Sweden fines Miljödata over municipal data breach

🔒 IMY, Sweden’s data protection authority, fined IT provider Miljödata SEK 1.8 million ($183,000) after an August 2025 cyberattack exposed personal data of 2.2 million people across municipal systems. The regulator found the company failed to perform adequate checks on newly installed software and lacked automated real-time monitoring to detect intrusions, violating GDPR Article 32(1). The attack disrupted services in over 200 regions and saw stolen data published by the threat actor “Datacarry.”
read more →

BigCommerce warns merchants of Ribon app breach

🔔 BigCommerce alerted merchants after attackers compromised credentials for third-party Ribon applications and injected malicious scripts into a subset of storefronts. The platform confirmed the compromise on September 17, removed the affected apps, and said its core systems were not breached. Affected merchants, including UK retailer Master of Malt, reported exposure of shopper names, emails, phone numbers, and shipping addresses.
read more →

DPC fines Google €403M for location data breaches

📌 Ireland’s Data Protection Commission fined Google €403 million for GDPR breaches tied to processing users’ location data. The investigation, opened in February 2020, reviewed three features — Web & App Activity, Location History, and Location Accuracy — active during May 25, 2018 to February 4, 2020. The DPC found failures in transparency, lawful processing, and retention practices, and ordered compliance within six months. Google says it has since updated policies and added user controls for location data.
read more →

ShinyHunters Claims Hack of Clop Ransomware Group

🛡️ The ShinyHunters gang claims to have breached the Clop ransomware group's dark web leak site, defacing it on 18 September and posting a message stating “THIS SITE HAS BEEN PWN3D BY SHINYHUNTERS”. They say they stole private keys, server data, activity logs and IP addresses that could identify Clop members, and left a ransom demand directing Clop to contact them. The incident appears to be part of a wider feud between the two groups dating to 2025 over claimed ownership of Oracle E-Business Suite exploits, including CVE-2025-61882.
read more →

Gyazo breach exposes massive image metadata trove

🔒 Security experts warned that a Gyazo breach disclosed on September 11 exposed nearly 24 million customer records and an additional 490 million image metadata entries after attackers exploited an upload-server vulnerability. The exposed metadata included image IDs, source IPs, user agents, EXIF location data, OCR-extracted text, titles, source URLs, and hashed passphrases, potentially allowing unauthorized access to images. Gyazo's developer, Helpfeel, said some image viewing was temporarily disabled while remediation occurred and urged password changes and vigilance against phishing.
read more →

Revolut customers targeted in post-breach smishing wave

📱Malwarebytes reports that Revolut customers have been targeted by smishing campaigns following a data breach acknowledged by the firm. Messages mimicked legitimate Revolut texts and urged recipients to follow links to confirm identity, with some pages requesting camera access to perform fake liveness checks. The campaign may leverage breached data and has reportedly targeted several hundred accounts, particularly high-net-worth crypto users.
read more →

ShinyHunters breaches Clop leak site, claims keys

🔒 The ShinyHunters extortion group breached and defaced the Clop (Cl0p) ransomware gang's Tor data leak site after exploiting an alleged unauthenticated file upload flaw in Grav CMS. The attackers uploaded a taunting text file and replaced the site with ASCII art, claiming to have obtained server data, logs, source code, and the onion service's private keys. BleepingComputer confirmed the defacement and file upload but has not independently verified theft of logs or keys, while ShinyHunters says it will extort Clop within 72 hours.
read more →

Gyazo breach exposes millions of user records

🛡️ Gyazo, a cloud-based screenshot and screen-recording service, confirmed a data breach after attackers exploited a server vulnerability on September 11, 2026, stealing roughly 23.62 million user records. The company detected the activity on September 12, patched the flaw, and has taken the service offline for maintenance while investigating with external experts. Exposed data may include names, emails, password hashes, session tokens, image metadata, and more, prompting recommendations that users change reused credentials and watch for suspicious communications.
read more →

Spain Reports First Agentic AI Personal Data Breach

🛡️ Spain’s data protection agency (AEPD) disclosed the country’s first agentic AI-powered personal data breach after an AI agent using a known language model scanned files, logged in, searched for vulnerabilities, and modified personal data and invoices. The AEPD said the agent was used to chain together attack phases, implying deliberate misuse by a threat actor rather than a rogue model. Officials call for AI risks to be included in risk analyses and for machine-speed incident response and stronger identity and credential protections.
read more →

Gyazo breach exposes millions of user records

🔒 Helpfeel's image-sharing service Gyazo disclosed a breach that exposed about 23.62 million user records and roughly 490 million image metadata records, mostly from January 2019 or earlier. The attacker exploited a vulnerability in Gyazo's image upload server to run arbitrary commands and access the database; Helpfeel has disabled some image viewing and urged users to change passwords and watch for suspicious messages. The company says no payment data was exposed and external forensics are ongoing.
read more →

KREMLIN malware forces browser extension installs

🔒 Researchers at Elastic Security Labs uncovered a banking malware toolkit called KREMLIN that has been active since mid-2025 and installs malicious Chrome and Edge extensions to steal credentials, session tokens, and other sensitive data. The infection begins with a malicious JavaScript file posing as banking documents, which downloads Node.js, establishes persistence, and retrieves payload locations from an Ethereum smart contract. KREMLIN copies extensions into browser profile directories, regenerates integrity HMACs using browser keys, and enables them without user consent, while also operating as an info-stealer and delivering RATs like REMCOS.
read more →

Radaris Loses Domains After New Jersey Privacy Case

📰 A New Jersey judge ordered radaris.com and more than a dozen related domains transferred to plaintiffs after finding the data broker repeatedly ignored removal requests under Daniel’s Law. Atlas Data Privacy Corp sued Radaris in 2024, alleging the company published personal data for state law enforcement and other officials and employed evasive shell-company tactics. The transfer follows extensive litigation, investigative reporting and documentary evidence tying multiple sites to a common operator.
read more →

Spain’s data agency reports first AI-powered breach

🔒 The Spanish Data Protection Agency (AEPD) was notified of an alleged attack carried out by an AI agent powered by a known large language model. The agent reportedly searched for flaws, logged into systems, probed applications, modified personal data, and accessed financial documents. The AEPD has not yet verified the incident but warns that AI-related breaches are now realistic and urges revised risk and response measures.
read more →

Twitch extension with 30K installs exposes OAuth tokens

🔒 A browser extension named Twitch Enhanced Viewer | JeetBot, listed in the Chrome and Firefox stores with over 30,000 installs, captures Twitch OAuth session tokens and transmits them to a commercial proxy service. Socket's analysis shows the extension appends the token as an auth= URL parameter when redirecting playlist requests, causing tokens to be logged in proxy server request logs. The vendor JeetBot, a Russian-language streaming/chatbot service, can therefore access those tokens and potentially hijack sessions.
read more →

Revolut data breach exposes sensitive customer records

🔒 Fintech firm Revolut disclosed a data breach after an attacker impersonating a government agency obtained customer data by sending requests from an email address using the agency's legitimate domain. The company said the request carried valid domain authentication, so it was fulfilled in good faith, and that systems and customer funds remain unaffected. Affected records include identity documents, contact details, account statements, transaction histories, and facial verification images, and Revolut says only a very limited number of customers were impacted.
read more →

Florida DMV DAVID Database Breach Confirmed

🛡️ The Florida Department of Highway Safety and Motor Vehicles (FLHSMV) confirmed a breach of its DAVID driver database after the ShinyHunters extortion group claimed to have compromised the system. The agency says the intrusion involved compromised credentials from a single Plant City Police Department user improperly stored on a personal device and that the incident was quickly mitigated. FLHSMV is coordinating with state authorities and treating the matter as an ongoing criminal investigation.
read more →

Trezor customers targeted after Brevo email breach

📧 Trezor disclosed that phishing emails sent via a breached third-party provider targeted 347,000 opted-in newsletter addresses and prompted 2,500 recipients to click a malicious link. The messages falsely claimed a microcontroller vulnerability in STM32 chips and urged users to download an app to enter wallet backups. Trezor disabled the malicious domain within 20 minutes and suspended the Brevo account to halt further distribution. The company emphasized no other Trezor systems were accessed.
read more →

Surfshark reports breach of internal test proxy servers

🔒 Surfshark disclosed that a misconfigured internal test server was reachable from the internet and accessed by unauthorized parties, exposing service configurations, portions of binaries, and build-related credentials. The company said production VPN infrastructure and customer data were not impacted, and the compromised machine acted as a proxy without access to user identities, IPs, encryption keys, or browsing traffic. Surfshark detected the activity on August 31, contained it by September 2, rotated affected credentials, revoked exposed tokens, and implemented additional monitoring and hardening.
read more →

Mass Drivers License Data for Sale Sparks Alarm

🛡️ A database of 153 million drivers licenses is reported for sale on the dark web, raising urgent privacy and security concerns. The post argues that current AI LLM systems accelerate attacks on ID document databases, making holdings of such data increasingly risky. It questions the wisdom of widespread storage of primary ID documents and urges limiting access to only those tasks that truly require ID verification. The piece criticizes recent trends toward mandatory ID collection and calls for treating ID verification data as crown-jewel assets.
read more →