Mimecast confirms SolarWinds attackers breached security certificate, 'potentially exfiltrated' credentialsCyberScoop·Jan 26, 20:15 UTC · Jan 26, 2021Data breach in the wild60
Indonesian e-commerce giant probes reported breach of 91 million credentialsCyberScoop·May 4, 14:41 UTC · May 4, 2020Data breach in the wild60
More than 1.1 million online credentials found in NY AG credential stuffing investigationCyberScoop·Jan 5, 15:27 UTC · Jan 5, 2022Data breach in the wild60
The ‘16 billion password breach’ story is a farceCyberScoop·Jun 24, 15:22 UTC · Jun 24, 2025Data breach60
Pentera introduces capability to detect Git repository risk exposureHelp Net Security·Jul 17, 06:15 UTC · Jul 17, 2025Data breach60
20% Of Credential Stuffing Attacks Target Media CompaniesHelp Net Security·Jul 16, 00:00 UTC · Jul 16, 2020Data breach60
CISA emergency directive tells agencies to fix credentials after Microsoft breachCyberScoop·Apr 11, 21:19 UTC · Apr 11, 2024Data breach60
New XM Cyber Research: 80% of Exposures from Misconfigurations, Less Than 1% from CVEsThe Hacker News·May 17, 12:12 UTC · May 17, 2024Data breach60
Swiss real estate agency Neho fails to put a password on its systemsSecurity Affairs·May 31, 12:23 UTC · May 31, 2023Data breach60
Cybersecurity Companies Expose Data OnlineInfosecurity Magazine·Sep 8, 12:05 UTC · Sep 8, 2020Data breach60
The Importance of Behavioral Analytics in AIThe Hacker News·Mar 20, 10:00 UTC · Mar 20, 2026Data breach60
Threat Source newsletter (March 9, 2023) — Stop freaking out about ChatGPTCisco Talos·Mar 9, 19:00 UTC · Mar 9, 2023Data breach160
Cybercriminals targeting social media: Facebook and Instagram are becoming phishers’ favoritesHelp Net Security·May 3, 00:00 UTC · May 3, 2019Data breach60
GitHub Breach Traced to Malicious ‘Nx Console’ VS Code ExtensionInfosecurity Magazine·May 21, 14:45 UTC · May 21, 2026Data breachCVE-2026-48027160
EasyJet announces breach impacting 9 million peopleCyberScoop·May 19, 20:26 UTC · May 19, 2020Data breach in the wild60
Guarding Healthcare Patient Privacy With Security IntelligenceRecorded Future·Sep 8, 00:00 UTC · Sep 8, 2025Data breach60
TeamPCP breached GitHub's internal codebase via poisoned VS Code extensionHelp Net Security·May 20, 00:00 UTC · May 20, 2026Data breach60
⚡ Weekly Recap: Rogue AI Models, $88M Bitcoin Theft, WaterThe Hacker News·Aug 3, 14:03 UTC · Aug 3, 2026Data breachCVE-2026-42897CVE-2026-6606660
UNC3886 Uses Fortinet, VMware 0-Days and Stealth Tactics in LongThe Hacker News·Jun 22, 05:45 UTC · Jun 22, 2024Data breachCVE-2022-41328CVE-2022-22948CVE-2023-20867+1 CVEs60
Cyberattack at med-tech conglomerate Hoya slowed production at Thai factory by 60 percentCyberScoop·Apr 8, 19:57 UTC · Apr 8, 2019Data breach in the wild60
PHP tool 'Adminer' leaks passwordsSansec (Magento / e-commerce security)·Apr 14, 20:16 UTC · Apr 14, 2026Data breach60
US CISA published an alert on the Sisense data breachSecurity Affairs·Apr 11, 18:26 UTC · Apr 11, 2024Data breach60
HSBC discloses breach of U.S. bank accountsCyberScoop·Nov 6, 22:41 UTC · Nov 6, 2018Data breach in the wild60
⚡ THN Weekly Recap: From $1.5B Crypto Heist to AI Misuse & Apple’s Data DilemmaThe Hacker News·May 6, 07:05 UTC · May 6, 2025Data breachCVE-2018-0171CVE-2025-24989CVE-2025-23209+32 CVEs60
Data leak at fintech giant Direct Trading TechnologiesSecurity Affairs·Jan 31, 08:50 UTC · Jan 31, 2024Data breach60
Hackers Breach ZoneAlarm's Forum Site — Outdated vBulletin to BlameThe Hacker News·Nov 11, 15:44 UTC · Nov 11, 2019Data breachCVE-2019-1675960
Russian Hackers Exploit Microsoft OWA Flaw to Keep Mailbox Access After Credential RotationThe Hacker News·Jul 30, 07:40 UTC · Jul 30, 2026Data breachCVE-2026-42897CVE-2025-6637660
Popular code formatting sites are exposing credentials and other secretsHelp Net Security·Nov 25, 00:00 UTC · Nov 25, 2025Data breach60
UNC4899 Breached Crypto Firm After Developer AirDropped Trojanized File to Work DeviceThe Hacker News·Mar 18, 11:23 UTC · Mar 18, 2026Data breach60
Breach database LeakedSource is down after reportedly being raided by fedsCyberScoop·Jan 26, 22:33 UTC · Jan 26, 2017Data breach in the wild60
Researchers Identify Rack::Static Vulnerability Enabling Data Breaches in Ruby ServersThe Hacker News·Apr 25, 10:29 UTC · Apr 25, 2025Data breachCVE-2025-27610CVE-2025-27111CVE-2025-25184+1 CVEs160
Hackers Exploit WordPress mu-Plugins to Inject Spam and Hijack Site ImagesThe Hacker News·Apr 1, 05:37 UTC · Apr 1, 2025Data breachCVE-2024-27956CVE-2024-8353CVE-2024-434560
Secrets, Secrets Are No Fun. Secrets, Secrets (Stored in Plain Text Files) Hurt SomeoneThe Hacker News·Jul 5, 11:28 UTC · Jul 5, 2023Data breach60
Nearly 773 million email addresses leaked, spelling trouble for people who reCyberScoop·Jan 17, 14:31 UTC · Jan 17, 2019Data breach in the wild60
New Research: 64% of 3rd-Party Applications Access Sensitive Data Without JustificationThe Hacker News·Jan 15, 00:00 UTC · Jan 15, 2026Data breach60
How Companies Can Protect Themselves from Password Spraying AttacksThe Hacker News·Aug 12, 13:02 UTC · Aug 12, 2021Data breach60
European Commission Confirms Cloud Data BreachInfosecurity Magazine·Mar 30, 08:15 UTC · Mar 30, 2026Data breach60
Stock trading app Robinhood says user passwords were readable on internal systemsCyberScoop·Jul 24, 22:31 UTC · Jul 24, 2019Data breach in the wild60
Security Breach Exposes Dropbox Sign UsersInfosecurity Magazine·May 2, 12:24 UTC · May 2, 2024Data breach60
Internet-connected teddy bear company hacked; 2 million parentCyberScoop·Feb 27, 23:05 UTC · Feb 27, 2017Data breach in the wild60