Customer data (name, date of birth, email, phone number, customer number) was leaked from an IT service provider for Lidl; payment data and passwords remained untouched.
Accenture confirms a security incident involving theft of an estimated 35 gigabytes of data, but provides no further details on scope or attack vector.
81 million password-spray attempts against Microsoft 365 over two weeks demonstrate that MFA enforcement and real-time anomaly detection are critical CISO controls against credential attacks.
Klue customers must review their Salesforce integrations as OAuth tokens have been compromised and a new extortion group claims responsibility for the attack.
A campaign called FortiBleed conducted by Russian-speaking actors has compromised over 86,600 Fortinet FortiGate devices and requires immediate protective measures by affected organizations.
Leaked GitHub tokens at Novo Nordisk demonstrate that secrets management must be properly addressed as an identity problem, not merely as a tooling challenge.
144 npm packages of the Mastra Framework have been infected with an infostealer that steals wallet and browser data during installation, already affecting the heavily-used core package.