databreach (27)

31224322883?profile=RESIZE_400xCybersecurity researcher Jeremiah Fowler has identified a significant data exposure involving millions of private facial images.  In a collaborative investigation conducted with ExpressVPN, Fowler discovered a publicly accessible database containing approximately 9,042,977 images.   The collection, totaling 450.2GB of data, was found with no password protection or encryption, leaving it open to any internet user who stumbled upon the repository.[1]

The discovery highlights a worrying security la

31224322883?profile=RESIZE_400xCybersecurity researcher Jeremiah Fowler has identified a significant data exposure involving millions of private facial images.  In a collaborative investigation conducted with ExpressVPN, Fowler discovered a publicly accessible database containing approximately 9,042,977 images.   The collection, totaling 450.2GB of data, was found with no password protection or encryption, leaving it open to any internet user who stumbled upon the repository.[1]

The discovery highlights a worrying security la

31224322883?profile=RESIZE_400xCybersecurity researcher Jeremiah Fowler has identified a significant data exposure involving millions of private facial images.  In a collaborative investigation conducted with ExpressVPN, Fowler discovered a publicly accessible database containing approximately 9,042,977 images.   The collection, totaling 450.2GB of data, was found with no password protection or encryption, leaving it open to any internet user who stumbled upon the repository.[1]

The discovery highlights a worrying security la

31214613470?profile=RESIZE_180x180Contact details of Angelina Jolie, Robert De Niro and Martin Scorsese have been exposed in a data breach.  Jennifer Lawrence, Morgan Freeman, Michael Douglas, Rami Malek, Sharon Stone, and directors George Lucas and Danny Boyle are also said to have been involved in the alleged leak last month.  The stars’ phone numbers and email addresses were revealed after a Tribeca Film Festival database, simply named “contacts”, was accidentally made public online, with Jeremiah Fowler, a researcher for Bla

31214612658?profile=RESIZE_400xRansomware attacks have increased dramatically during the second quarter of 2026, with undisclosed incidents surging 40% year-on-year, according to BlackFog's latest State of Ransomware Report.  The cybersecurity firm documented 2,027 undisclosed attacks in Q2 2026, compared with 1,446 during the same period in 2025.  The report, which provides comprehensive analysis of both publicly disclosed and undisclosed ransomware attacks worldwide, also recorded 306 publicly disclosed attacks during the q

31198463869?profile=RESIZE_400xA hacker recently claimed to have exfiltrated tens of gigabytes of internal development data allegedly belonging to global professional services firm Accenture.  The incident became public when a threat actor on the PwnForums forum boasted of compromising the company and stealing 35 gigabytes of data.  According to the hacker, the stolen information includes Azure access keys, tokens, configuration files, RSA and SSH keys, and internal source code.  As proof of possession, the actor posted a scr

31185654276?profile=RESIZE_400xOrganizations invest heavily in cybersecurity tools, firewalls, and endpoint detection systems.  Yet many still encounter serious difficulties when an actual incident occurs. Incident response requires more than a plan on paper.  It demands swift and effective execution under pressure.  Most small and medium-sized enterprises hold only a basic notion of their actions in a crisis.  Someone would contact the IT team and systems would be examined.  In practice, a real incident arises amid uncertain

31185653453?profile=RESIZE_400xNYC Health + Hospitals (NYCHHC), the healthcare system of New York City and the largest municipal healthcare network in the United States, has confirmed it suffered a cyberattack that resulted in the loss of highly sensitive data on 1.8 million people.  Among the stolen data are fingerprints and palm prints, which can never be changed, making this breach even more disruptive.  This is the latest in a growing number of major data breaches added to the healthcare data breach tracker maintained by

31148712298?profile=RESIZE_400xA recent analysis report by Surfshark found that, among global data breaches, South Africa ranks 42nd in Q1 2026.  Globally, 210.3 million accounts were breached, with the US ranking first at 29% of all breaches from January through March.  France takes second place, followed by India, Brazil, and the UK.[1]  Surfshark is a consumer-focused cybersecurity and privacy product suite.

Since 2004, South Africa has been the second-most breached country in Africa, with 45.7 million compromised user acc

31126688092?profile=RESIZE_400xHackers are claiming to have stolen a trove of data belonging to Lockheed Martin, the world’s largest defense contractor and an American aerospace company.  They are now selling it on the dark web.

The situation began on March 26, 2026, when a Telegram account linked to a dark web marketplace known as Threat Market, which posts in both Russian and English, claimed it had been approached by a group described as “APT IRAN.”  According to the post, the group requested infrastructure support to sell

31125805877?profile=RESIZE_400xGoogle has warned that ransomware gangs are reinventing their business models as traditional encryption-based attacks become less profitable and data-theft extortion surges.   According to new analysis, better cybersecurity controls, improved backup strategies, and stronger recovery capabilities mean more victims can restore their systems without paying, directly eroding criminal revenue. However, threat actors are not retreating; they are adapting their methods to make operations harder to disr

31105892100?profile=RESIZE_400xThe Federal Bureau of Investigation (FBI) has officially confirmed that a limited number of its servers have been compromised in a cybersecurity incident.  The breach affected surveillance systems used by the FBI for lawful foreign intelligence interception operations, with investigators suspecting state-backed Chinese hackers based on suspicious activity patterns.  The security breach occurred during the second week of February 2026 and was detected on 17 February 2026.  The incident has raised

31101311893?profile=RESIZE_400xAs the healthcare sector continues to grapple with the professionalization of cybercrime, the University of Mississippi Medical Center (UMMC) has become the latest high-profile target in a sprawling ransomware attack.  This incident is a reminder of the "identity-first" battlefield and the catastrophic impact of machine-speed exfiltration on clinical operations.  The attack, first disclosed on 19 February 2026, has severely disrupted the state's only academic medical center. UMMC leadership, inc

13770058857?profile=RESIZE_400xSouth Africa has seen its increases in social upheaval and other political struggles.  Cyber-attacks are an additional concern for South Africans to worry about.  South Africa has experienced 110 cybercrime incidents involving extortion, ransomware, and state hacking in the past five years, according to Orange Cyberdefense’s inaugural Security Navigator Africa report.  This is the highest number in Africa and more than double that of Egypt, which ranked second with 46 incidents between 2020 and

13715453285?profile=RESIZE_400xCredit rating company TransUnion has suffered a data breach, which has impacted the personal information of nearly 4.5 million Americans.  The firm revealed that unauthorized access was gained to a third-party application serving its US consumer support operations in a notification letter to impacted customers.  The information was limited to specific data elements and did not include credit reports or core credit information.

TransUnion has not publicly provided any more details on the nature o

13715435097?profile=RESIZE_400xA new sneaky type of malware, known as Raven Stealer, has been identified by the Lat61 Threat Intelligence Team at Point Wild.  The research team, led by Onkar R. Sonawane, has found that this seemingly simple program is surprisingly adept at remaining undetected while stealing your personal information.  The research, shared with Hackread.com, reveals that the malware is primarily spread through underground forums and often bundled with pirated software.

Built using the programming languages De

13712659476?profile=RESIZE_400xA joint study by Cybersecurity at MIT Sloan (CAMS) and Safe Security has examined 2,800 ransomware incidents and found that a staggering 80.83%, or more than 2,272 attacks, were driven by artificial intelligence. This statistic is not theoretical; it's based on comprehensive, real-world data collected during 2023–2024.

The Rethinking the Cybersecurity Arms Race working paper paints a vivid picture of how AI is transforming attack methods. Adversaries are no longer relying on manual orchestration

13712626884?profile=RESIZE_400xWhat began as a quiet investigation into suspicious Salesforce activity has escalated into one of the most significant SaaS supply chain incidents of the year. Google's Threat Intelligence Group (GTIG) reports that a threat actor, tracked as UNC6395, exploited compromised OAuth tokens from Salesloft's Drift integrations to extract data from multiple customers' Salesforce instances. The campaign ran at least from 8 to 18 August 2025. GTIG's assessment is blunt: "GTIG assesses the primary intent o

13698732068?profile=RESIZE_400xCybersecurity researcher Jeremiah Fowler identified two unprotected, misconfigured databases containing nearly one million records linked to Ohio Medical Alliance LLC, a company better known under its brand name Ohio Marijuana Card.  Fowler, who reported the exposure to Website Planet, found that the databases were left open without encryption or password protection, allowing anyone with an internet connection to access names, Social Security numbers (SSN), dates of birth, home addresses, and hi

13698736680?profile=RESIZE_400xWhy hack when hackers are willing to sell guaranteed access to breached networks?  Increasingly, cybercrooks agree they would rather outsource than bother with the tedium of actual network penetration, leading to a flourishing initial access market.  Remote access to a victim's network now retails for an average price of $2,700, although about 40% of what's being sold goes for much less $500 to $1,000, noted in a report from cybersecurity firm Rapid7.   Research is based on listings posted over