SpaceXAI has faced backlash after reports that Grok Build CLI uploaded entire Git repositories, including private code and unredacted secrets, to a Google Cloud bucket without clear user consent. The company says privacy settings can disable sharing and may delete previously uploaded data, but it has not explained the scope, retention,…
Category: Cyber Attack
A threat actor using the alias 888 claims to have leaked a second database from Conasems, exposing data tied to 766,000 unique users. The alleged leak includes CPF numbers, passwords, contact details, and highly sensitive personal attributes, but the claim remains unverified. #Conasems #888 #Brazil #CPF…
Loyalist College is dealing with a major institution-wide technical disruption that has taken down systems, services, internet, and email. The incident, which began last week, is linked to an external cyber threat and has forced the suspension of online classes while in-person instruction continues. #LoyalistCollege
Grok Build was found to silently upload entire local repositories to Google GCP storage buckets, raising concerns about leaked credentials, API keys, and possible use of the data for future model training. SpaceXAI claimed privacy mode could stop the behavior, but @Cereblab showed that repository uploads were controlled separately by a…
Nihon Kotsu, one of Japan’s largest taxi operators, confirmed unauthorized access to its internal systems and a malware infection that disrupted phone taxi dispatch and reservation-related services. The company isolated affected systems, is investigating with cybersecurity experts, and said no customer data leakage has been detected so far. #NihonKotsu
Threat actors using the aliases misere and ChimeraZ claim to have breached Litige.fr and exposed data for 595,024 users through unauthenticated access-control flaws. The alleged leak includes personal, contact, IP, postal, and legal-case information, with claims that account takeover and staff-dashboard access may still be possible. #Litige.fr #misere #ChimeraZ…
Suitable AI, an AI recruitment platform serving India and the USA, was allegedly breached through GraphQL API weaknesses, leading to a partial dump of 15,176 applicant records. The exposed data reportedly included names, contact details, resumes, and salary information from a pool of about 53,681 applicants. #SuitableAI #NightBroker #GraphQLAPI…
Pushpanjali Hospital in Agra was hit by a ransomware attack that locked critical data, backup files, and the hospital’s phone software on its Windows server, disrupting operations. Authorities have registered a complaint and are investigating the incident to identify the cybercriminals behind the attack. #PushpanjaliHospital #Agra #DelhiGate
The City of Carros confirmed it was the victim of a cyberattack that caused its municipal website to become unavailable. Technical teams are working to restore services, while the exact nature of the attack and whether any data was leaked have not been confirmed yet. #VilledeCarros
The municipal websites of Baraolt and Ghidfalău have been offline for several days following a cyberattack, prompting local authorities to work with maintenance companies to restore the platforms. Officials are also seeking support from the National Cyber Security Directorate, while stressing that no sensitive data is stored on the Ghidfalău platform. #Baraolt #Ghidfalău #DirectionatNaționaldeSecuritateCibernetică
A threat actor using the alias 84City claimed to leak an SQL dump attributed to PPA Business School in France, containing 293,967 records tied to students, alumni, prospects, and applicants. The alleged exposure includes names, emails, phone numbers, home addresses, dates of birth, nationality, student IDs, and enrollment details, though the…
A threat actor using the alias ChimeraZ claims to have leaked an SQL dump from the Bebeboutik seller portal, with about 500,000 rows spread across 1,890 files and totaling 1.4GB. The alleged breach is unverified, but it could expose merchant, order, inventory, pricing, and sales data from the French baby-products marketplace….
Dutch police, led by the National Public Prosecution Service and Team High Tech Crime, have launched a major investigation into the Odido hack after more than six million customer records were stolen and later leaked. Investigators say they found strong signs that Dutch criminals were involved, and they are asking anyone with information to contact the police as the case continues for months. #Odido #TeamHighTechCrime #LandelijkParket
The City of Winkler in Manitoba was affected by a cybersecurity incident that forced officials to isolate impacted systems and take some municipal services offline as a precaution. Phone and payment systems are currently unavailable, and external experts have been brought in while police have been notified. #CityofWinkler #Manitoba
Thepha District Public Health Office in Thailand was reportedly breached, with the attacker claiming a full dump of databases, files, logs, and documents. The exposed data reportedly includes site accounts, hashes, and documents, and live server access was also offered. #ThephaDistrictPublicHealthOffice #Thailand #Monkeydance…