Researchers from Truffle Security found 64,024 live AWS access key pairs and root credentials exposed across public repositories, AI datasets, container images, and CI logs, affecting more than 9,900 AWS accounts worldwide. The leaked keys could grant full administrative control and cause major cloud abuse and unexpected spending, including hundreds of…
Category: Cyber Attack
Baylor Genetics disclosed a cybersecurity incident in which an unauthorized third party accessed parts of its network between June 11 and June 17, 2026, potentially exposing personal information for patients and some current or former employees. The company secured affected systems, completed a forensic review, notified impacted individuals, and confirmed that laboratory operations, patient care, and test result integrity were not affected. #BaylorGenetics
Sakura Internet disclosed that attackers breached its customer management system on August 9, 2026, potentially affecting up to 1,360,563 customer accounts and exposing contract agreements plus personal and corporate data. The company said the incident involved malware and unauthorized logins, but it was not a ransomware attack and no confirmed data…
A forum user named Satanic allegedly offered Wrappiness.co’s customer database for sale, claiming it contains 3 million order records and 115 administrator accounts. The published fields include names, emails, phone numbers, addresses, tracking numbers, and personalization details, but the claim remains unverified. #Wrappiness.co #Satanic…
A forum user calling themselves ChimeraZ allegedly leaked 43GB of data from bergerat-rent.com in the eleventh release of a numbered series, now explicitly linking the source to the BlgCloud platform. The reported material includes email content, CRM records, invoices, and financial exposure fields, but the claim remains unverified. #BergeratRent #ChimeraZ #BlgCloud…
Alation, a major data and AI company, confirmed it was hit by a cyberattack after recently reporting an incident that affected service availability for some customers. The company is still investigating and has not disclosed the attack type, root cause, or how many clients were impacted. #Alation
SafePal disclosed a breach that exposed order and contact details for about 39,798 customers because of an authorization flaw in an order-tracking plug-in. The company says seed phrases, private keys, wallet passwords, and funds were not exposed, while a threat actor now claims to be selling the stolen data. #SafePal…
Latvia’s Road Traffic Safety Directorate (CSDD) suffered a large-scale cyberattack that exposed data tied to 1.2 million individuals and 200,000 companies, including names, payment details, licence plates, and registered addresses. Authorities warned the stolen information could be abused by fraudsters, while Prime Minister Andris Kulbergs ordered an investigation and said the incident may have national security implications. #CSDD #AndrisKulbergs #Leta
An alleged data exposure tied to Argentine hardware wallet retailer coincustody.io may have revealed named buyers, home addresses, DNI/CUIT numbers, phone numbers, and other order details. If true, the leak could enable physical targeting, identity fraud, SIM swapping, and highly convincing wallet-seed phishing attempts against crypto users. #coincustodyio #kingloki #Trezor #Ledger…
Ryomo Systems confirmed an unauthorized intrusion into its internal systems on August 14 and is investigating how the attack occurred and whether any data was stolen. The Japanese IT company serves critical sectors including water, energy, healthcare, and government, making the incident especially sensitive. #RyomoSystems
CG Power reported a suspected cybersecurity incident affecting its IT systems, while confirming that its core operational systems and manufacturing production remained unaffected. The company said the incident is under investigation by internal and external experts and has been notified to CERT-In. #CGPower #CERTIn
A forum user known as Satanic allegedly exported data from hundreds of Stripe merchant accounts using 1,033 compromised API keys, with the claim covering 662 datasets totaling 33GB. The post is unverified, and the evidence suggests merchant credential theft rather than a breach of Stripe itself. #Stripe #Satanic #APIKeys…
A hacker attack on two Berlin Senate administrations has caused major disruptions, cutting off internet and external email access and making home office work impossible. Authorities have activated a crisis team and are investigating possible data exfiltration and a severe cyber incident in the Berlin state network. #BerlinSenate #Landesnetz #BSI #LKA
A privacy issue in Moonshot AI’s Kimi Work desktop client causes feedback submissions to automatically upload the five most recently updated agent sessions, along with diagnostic logs, without clearly disclosing this to users. The uploaded session data can include raw execution records and other sensitive information from unrelated work, highlighting a…
A listing claims to sell a 452.29GB imaging backup from 301 Hospital, PLA General in Beijing, but the headline’s claim about a head of state scan is unverified. The archive is said to contain DICOM studies and patient metadata, yet the post remains unconfirmed and may be partly promotional. #301Hospital #Beijing…