Bitget Freezes Withdrawals After $351.6 Million Hot-Wallet Breach
Bitget says unauthorized transfers exposed about $351.6 million in assets held in parts of its hot- and warm-wallet infrastructure. The exchange has paused withdrawals, while its cold wallets...
FBI Investigates Jobs Portal Intrusion as ShinyHunters Claims Sensitive Data Theft
The FBI is investigating unauthorized activity involving FBIjobs.gov after a defacement and expansive breach claims attributed to ShinyHunters. Some sample records reportedly matched real people, but the alleged...
Suspected Chinese-Speaking Hackers Chain Two WordPress Bugs to Loot a Government Database
A likely Chinese-speaking threat actor strung together two WordPress vulnerabilities to breach at least 49 organizations in 29 countries, with one Western government agency losing 18,566 records, including...
TanStack Supply-Chain Breach Exposes 170 Private CrowdSec Repositories
CrowdSec says attackers cloned roughly 170 private GitHub repositories after stealing an OAuth token through the TanStack npm supply-chain compromise. The incident remained hidden for months and highlights...
CenterPoint Energy Confirms Customer Data Theft From Internet-Facing System
CenterPoint Energy says an unauthorized party accessed customer personal information through an internet-facing company system. Energy delivery remains unaffected, but the utility has not yet disclosed the number...
Japan Digital Agency Breach Exposes 246,000 Records After VPN Intrusion
Attackers exploited a previously patched VPN weakness to enter Japan’s shared government IT environment, potentially exposing about 246,000 personal records. The incident highlights the continuing danger of delayed...
Fraudulent Government Request Exposes Revolut KYC Records and Transaction Histories
Revolut disclosed that a fraudulent request sent from an official government email domain led to the release of highly sensitive customer records. The incident shows why authenticated email...
Veradigm Discloses Patient SSNs Exposed After Vendor Credentials Were Stolen
Healthcare technology firm Veradigm has disclosed to the SEC that stolen vendor credentials were used to access an API and download patient data, including Social Security numbers. The...