Essex NHS Trust/Synnovis
Thousands of NHS patient records stolen in ransomware cyberattack on Mid South Essex Foundation Trust
Hospitals, clinics, insurers, and medical-IT vendors are the highest-value targets in cybercrime. Below is every healthcare-sector breach LeakTrace has indexed — patient records, HIPAA disclosures, ransomware victims, and supply-chain compromises.
Thousands of NHS patient records stolen in ransomware cyberattack on Mid South Essex Foundation Trust
Thousands of patient records stolen in ransomware cyberattack affecting Essex NHS trust
63,926 records exposed — Email addresses, IP addresses, Passwords, Support tickets and 1 more
Palo Alto Networks PAN-OS Authentication Bypass Vulnerability — Palo Alto Networks PAN-OS contains an authentication bypass vulnerability that allows attackers to bypass security restrictions and establish an unauthorize
Sloppy AI-generated npm infostealer leaked its own GitHub token, exposing the operator
269,299 records exposed — Email addresses, Names, Partial credit card data, Phone numbers and 2 more
4,851,517 records exposed — Email addresses, Job titles, Names, Phone numbers and 1 more
Nx Console Embedded Malicious Code Vulnerability — Nx Console contains an embedded malicious code vulnerability that allowed a malicious version of Nx Console to be published. The compromised extension fetched an obfusca
84,108 records exposed — Email addresses, Names, Partial credit card data, Phone numbers and 3 more
All Major LLMs Exposed to Multi-Turn Manipulation, Warn Researchers
Daemon Tools Lite Embedded Malicious Code Vulnerability — Daemon Tools contains an unspecified vulnerability that has a high impact on confidentiality, integrity, and availability.
TanStack Unspecified Vulnerability — TanStack contains an unspecified vulnerability that allowed malicious versions of the product to be published to the npm registry to publish credential-stealing malware under a truste
CERT-In urges 12-hour patching of exposed flaws as AI compresses exploitation timelines
502,597 records exposed — Email addresses, Employers, Financial transactions, Job titles and 3 more
LiteSpeed cPanel Plugin Privilege Escalation Vulnerability — LiteSpeed cPanel Plugin contains privilege escalation vulnerability that is exposed via the user-end cPanel plugin, which can be abused by any cPanel user acco
185,256 records exposed — Dates of birth, Email addresses, Names, Phone numbers and 1 more
The infostealer payload in this campaign collect a vast amount of data, from collaboration authentication keys to cryptocurrency wallets
Lawmakers in both houses of Congress are demanding answers from the U.S. Cybersecurity & Infrastructure Security Agency (CISA) after KrebsOnSecurity reported this week that a CISA contractor intentionally published
Drupal Core SQL Injection Vulnerability — Drupal Core contains a SQL injection vulnerability that could allow for privilege escalation and remote code execution via specially crafted requests sent with the database abstr
Grafana Labs has confirmed a recent data breach was caused by the TanStack supply chain attack
Langflow Origin Validation Error Vulnerability — Langflow contains an origin validation error vulnerability in which an overly permissive CORS configuration combined with a refresh token cookie configured as SameSite=Non
Trend Micro Apex One (On-Premise) Directory Traversal Vulnerability — Trend Micro Apex One (on-premise) contains a directory traversal vulnerability that could allow a pre-authenticated local attacker to modify a key tab
126,293 records exposed — Dates of birth, Email addresses, Names, Passwords and 2 more
46,105 records exposed — Email addresses, IP addresses, Passwords, Usernames