ShinyHunters Strikes Again: Brinks Home Confirms Breach Tied to Salesforce Systems
Brinks Home has confirmed attackers broke into systems connected to its Salesforce environment after the ShinyHunters extortion crew claimed to have stolen nearly five million records. The company...
865,000 ‘No-Logs’ VPN Users Exposed After SplitVPN Breach Reveals Hidden Connection Records
A breach at Russian VPN provider SplitVPN, formerly NotVPN, has exposed the records of roughly 865,000 users despite the service's long-standing 'no logs' promise. The leaked database reportedly...
Chipmaker Analog Devices Confirms Breach as Extortion Group Claims 570,000 Stolen Records
Analog Devices has confirmed unauthorized access to internal systems and file exfiltration in an SEC filing, weeks after a group calling itself ExfilSquad listed the semiconductor giant on...
Alleged 160-Million-Record Decathlon Customer Database Surfaces on Cybercrime Forum
A threat actor is advertising what they claim is a Decathlon customer database of roughly 160 million records on an underground forum, seeking cryptocurrency payment. Decathlon has not...
Gig Economy Platform Paidwork Leaks Banking and Personal Data of 23 Million Users
A data breach at gig-economy platform Paidwork has exposed banking details, payout histories, and personal information for more than 23 million users, with the stolen dataset publicly leaked...
Hugging Face Breach Reveals a New Front: AI Agents Attacking, AI Agents Defending
Hugging Face has confirmed a production infrastructure intrusion driven by an autonomous AI agent, exploiting two flaws in its dataset processing pipeline. The company's own AI-based forensic analysis...
EY Notifies Clients After Breach of IT Support Platform Exposes Tax Documents
Ernst & Young is notifying clients that attackers accessed a third-party IT support ticketing platform for roughly two weeks this spring, downloading documents containing sensitive tax and investment...
Accenture Data Breach: Hackers Claim Theft of 35 GB of Source Code and Azure Credentials
A threat actor known as "888" claims to have stolen 35 GB of Accenture source code, RSA/SSH keys, and Azure access tokens, offering the data for sale in...