Trezor Reveals Its ShipMonk Breach Was Far Bigger Than First Disclosed
Hardware wallet maker Trezor has confirmed that a breach at its fulfillment partner ShipMonk exposed far more customers than originally reported, after retained order data that should have...
Lenovo ID Trust Flaw Opened About 5,000 Dropbox Accounts to Takeover
Dropbox says attackers compromised roughly 5,000 accounts by creating Lenovo IDs with victims’ email addresses and abusing a federated-login integration. The incident demonstrates why matching email claims cannot...
Boston Scientific Cyber Incident Disrupts Manufacturing and Device Shipments
Boston Scientific is recovering from a cyber incident that interrupted on-premises systems supporting manufacturing, order processing and product shipments. The company says connected devices and previously enrolled remote...
Houston Healthcare Company Nutex Health Confirms Data Breach and Exfiltration
Nutex Health, a Houston-based healthcare operator, has disclosed in an SEC filing that an unknown third party accessed its network and exfiltrated data, potentially including patient and employee...
28,000 Public .git Folders Left AWS Keys, Stripe Tokens, and HR Files Wide Open, Researchers Find
A large-scale internet scan uncovered 28,000 publicly accessible .git directories exposing hundreds of live cloud and payment credentials, along with sensitive employee records — a reminder that scrubbing...
Breach at France’s Tax Authority Exposes Financial Records of Nearly 680,000 People
France's Directorate General of Public Finances has confirmed that attackers used compromised employee and third-party credentials to access tax records belonging to roughly 678,000 individuals and businesses. No...
Shell Launches Investigation After Cl0p Extortion Group Claims Theft of Nearly 90GB of Internal Data
Energy giant Shell has activated its incident response process after the Cl0p extortion syndicate listed the company on its dark-web leak site, claiming to have stolen roughly 89GB...
Stolen Azure Logins Expose Employee Data at McDonald’s, Vodafone and Seven Other Global Firms
A dark-web seller known as TheHatman is offering internal employee directories lifted from nine Fortune 500 companies, including McDonald's and Vodafone, after harvesting Azure Active Directory credentials through...