Alleged 160-Million-Record Decathlon Customer Database Surfaces on Cybercrime Forum
A threat actor is advertising what they claim is a Decathlon customer database of roughly 160 million records on an underground forum, seeking cryptocurrency payment. Decathlon has not...
Gig Economy Platform Paidwork Leaks Banking and Personal Data of 23 Million Users
A data breach at gig-economy platform Paidwork has exposed banking details, payout histories, and personal information for more than 23 million users, with the stolen dataset publicly leaked...
Hugging Face Breach Reveals a New Front: AI Agents Attacking, AI Agents Defending
Hugging Face has confirmed a production infrastructure intrusion driven by an autonomous AI agent, exploiting two flaws in its dataset processing pipeline. The company's own AI-based forensic analysis...
EY Notifies Clients After Breach of IT Support Platform Exposes Tax Documents
Ernst & Young is notifying clients that attackers accessed a third-party IT support ticketing platform for roughly two weeks this spring, downloading documents containing sensitive tax and investment...
Accenture Data Breach: Hackers Claim Theft of 35 GB of Source Code and Azure Credentials
A threat actor known as "888" claims to have stolen 35 GB of Accenture source code, RSA/SSH keys, and Azure access tokens, offering the data for sale in...
DHS Confirms Hackers Breached HSIN, the Government’s Emergency Information-Sharing Platform
The Department of Homeland Security has confirmed a breach of the Homeland Security Information Network (HSIN), the unclassified platform used by federal, state, local, and international partners to...
World Leaks Ransomware Dumps 630 GB of Tata Electronics Data — Confidential Apple and Tesla Files Exposed
Ransomware group World Leaks has published 630+ GB of stolen Tata Electronics data including confidential Apple iPhone manufacturing specs and Tesla engineering drawings marked as trade secrets. Tata...
LastPass Customer Data Exposed Through Klue Supply Chain Attack — OAuth Tokens Abused to Access Salesforce CRM
LastPass disclosed a supply chain breach via vendor Klue, where stolen OAuth tokens gave attackers access to customer CRM data in Salesforce. Password vaults were not affected. IOCs...