Finance & Banking Data Breaches (10961 indexed)
Suno AI Music
55.3M accounts leaked with partial payment data
Liechtenstein Government
31K beneficial ownership records exposed
Brazil's SISVISA health surveillance system left 102,215 files totaling 79GB open
Brazil's SISVISA health surveillance system left 102,215 files totaling 79GB open online, including tax IDs and identity documents, without password protection.
I was mapping the command-and-control infrastructure behind a state-linked intrusion set
I was mapping the command-and-control infrastructure behind a state-linked intrusion set when the query came back and effectively ended the exercise I thought I was running. The malware resolved its C2 address by read
Dutch retailer De Bijenkorf
Amsterdam-based luxury goods chain De Bijenkorf is the latest retailer to announce a cyber incident involving a third-party logistics provider.
3 Paperclip flaws exposed data & allowed unauthenticated command execution in two
3 Paperclip flaws exposed data & allowed unauthenticated command execution in two deployment modes
Cookeville Regional Medical
330K patient records breached
Inter-Con Security
276,114 records exposed — Email addresses, Employers, Job titles, Names and 2 more
GitGuardian researchers found 321 n8n instances accepting API tokens exposed in public
GitGuardian researchers found 321 n8n instances accepting API tokens exposed in public GitHub commits and demonstrated four ways attackers could use them to access sensitive data and downstream credentials without exploi
Unitel, Angola's dominant mobile operator, continues to recover from a cyberattack that
Unitel, Angola's dominant mobile operator, continues to recover from a cyberattack that caused outages the day of the government-owned telco's public offering.
A self-propagating worm-like attack is hitting the npm registry, having infected 444
A self-propagating worm-like attack is hitting the npm registry, having infected 444 packages from more than a dozen publishers so far. The impact is massive, with the packages affected amounting to more than 2 billion m
N-able N-central
N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability — N-able N-central contains an authentication bypass using an alternate path or channel that allows for authentication bypass.
Black Hat 2026 is shaping up to be another AI-heavy conference, but this year’s
Black Hat 2026 is shaping up to be another AI-heavy conference, but this year’s announcements suggest the industry is moving beyond simply adding copilots to existing products. Vendors are increasingly packaging AI in
IBM Langflow
IBM Langflow Code Injection Vulnerability — Langflow contains a code injection vulnerability that allows unauthenticated attackers to achieve full remote code execution on default Langflow deployments.
Apache Tomcat
Apache Tomcat Missing Encryption of Sensitive Data Vulnerability — Apache Tomcat contains a missing encryption of sensitive data vulnerability that allows the bypass of the EncryptInterceptor.
Reports said intruders appeared to gain access to the Jira environment and other
Reports said intruders appeared to gain access to the Jira environment and other sensitive data of the Żabka retail chain. The company confirmed an intrusion occurred in late July.
The UK’s Police National Legal Database and Ask the Police service have been breached
The UK’s Police National Legal Database and Ask the Police service have been breached
Swiss federal IT office
SwissInfo.ch reports: Following a cyberattack on the SharePoint servers operated by the Federal Office of Information Technology, Systems and Telecommunication (FOITT), access via the internet has been blocked for people
Swiss IT agency
The Federal Office for Information Technology and Communications (BIT) said specialists detected anomalies in on-premises Microsoft servers. The Swiss agency could not confirm exactly how the hackers got in.
The top cybersecurity product
Black Hat 2026 is shaping up to be another AI-heavy conference, but this year’s announcements suggest the industry is moving beyond simply adding copilots to existing products. Vendors are increasingly packaging AI in
A crafted prompt to a low-privilege Google ADK agent could be used to pass a malicious
A crafted prompt to a low-privilege Google ADK agent could be used to pass a malicious hand-off comment to a privileged agent. The post Gemini Agent-to-Agent Attack Method Exposed Secrets, Enabled Pull Request Tampering
A hacker has drained nearly $89m from Coldcard Bitcoin wallets after exploiting a legacy
A hacker has drained nearly $89m from Coldcard Bitcoin wallets after exploiting a legacy bug