A misconfigured Elasticsearch instance at Nextcloud exposed internal company data, customer contracts, database credentials and employee contacts over an extended period, but was shut down without detected misuse.
GitHub Agentic Workflows extract and disclose data from private repositories – a security issue for which no comprehensive solution has been announced.
Accenture confirms a security incident involving theft of an estimated 35 gigabytes of data, but provides no further details on scope or attack vector.
The ransomware group Unsafe claims to have breached Deutsche Bank and stolen employee data including email addresses, hashed passwords, and private home addresses.
Agent-driven GitHub workflows can be manipulated through crafted public issues to unauthorisedly disclose private repositories of the enterprise when the agent has organisation-wide read access.
A data breach at GameStop with 54 million potentially affected customer records exposes names, addresses, phone numbers, and purchase histories for targeted phishing and social engineering attacks.
An OAuth vulnerability in the Klue platform allowed attackers to gain access to Salesforce CRM data from enterprise customers and exploit it for extortion purposes.
A publicly accessible Elasticsearch server stored 24 billion credentials from infostealer malware collections, placing millions of accounts without MFA at acute risk.
A current data breach of 4.9 million Wise customers containing names, birth dates, and Spanish tax identification numbers is being traded on the darknet and poses significant risks for identity theft and fraud.