Alleged Sale of Unauthorized Root Access to 1,500+ Linux Systems at Stevens Sales Company (SSCO)

A threat actor using the handle SantaAd posted an auction on a known exploit forum claiming to sell unauthorized root access to over 1,500 Linux systems tied to Stevens Sales Company. The listing references a “US DB” and ssco.net, identifying the compromise as initial access with medium severity and root-level permissions….

Read More
Universidad Autónoma de Sinaloa (UAS) Data Breach Affects Thousands

Universidad Autónoma de Sinaloa (UAS) reportedly suffered a data breach that exposed personal records for 55,566 students and 12,418 professors, which were posted on a popular hacking forum. The leaked database allegedly includes highly sensitive identifiers and contact information such as full names, CURP, account numbers, addresses, phone numbers, emails, and…

Read More
Spain Ministry of Universities Data Breach

Spain’s Ministry of Universities has reportedly been compromised after a high-severity IDOR vulnerability granted an unauthorized actor admin-level access to its database. The breach allegedly used leaked credentials combined with sequential DNI iteration to systematically exfiltrate large amounts of student and applicant PII and financial records, including passport scans, DNI/NIE scans,…

Read More
The “Vibe Coding” Disaster: How a Simple Bug Exposed 4.75 Million Records on the AI Social Network Moltbook

Moltbook, an AI-only forum where users connect autonomous agents (often via OpenClaw), suffered a major data breach that exposed 4.75 million records including 1.5 million API authorization tokens, over 35,000 emails, 29,000 early-registration addresses, 4,060 private agent messages and plain-text OpenAI API keys. Wiz found the breach was enabled by exposed…

Read More