Inter-Con Security
276,114 records exposed — Email addresses, Employers, Job titles, Names and 2 more
Law firms hold the most sensitive corporate data outside the client itself — M&A, IP, litigation, settlements. They are systematically targeted by both criminal and state actors. Below is every law-firm breach LeakTrace has indexed.
276,114 records exposed — Email addresses, Employers, Job titles, Names and 2 more
330K patient records compromised in ransomware
31K beneficial ownership records exposed
350K patient medical and financial records exposed
1M members bank and personal data breached
330K patient records exposed in ransomware attack
55GB PII and financial records of 28K customers
I was mapping the command-and-control infrastructure behind a state-linked intrusion set when the query came back and effectively ended the exercise I thought I was running. The malware resolved its C2 address by read
Brazil's SISVISA health surveillance system left 102,215 files totaling 79GB open online, including tax IDs and identity documents, without password protection.
Amsterdam-based luxury goods chain De Bijenkorf is the latest retailer to announce a cyber incident involving a third-party logistics provider.
3 Paperclip flaws exposed data & allowed unauthenticated command execution in two deployment modes
GitGuardian researchers found 321 n8n instances accepting API tokens exposed in public GitHub commits and demonstrated four ways attackers could use them to access sensitive data and downstream credentials without exploi
Unitel, Angola's dominant mobile operator, continues to recover from a cyberattack that caused outages the day of the government-owned telco's public offering.
A self-propagating worm-like attack is hitting the npm registry, having infected 444 packages from more than a dozen publishers so far. The impact is massive, with the packages affected amounting to more than 2 billion m
Black Hat 2026 is shaping up to be another AI-heavy conference, but this year’s announcements suggest the industry is moving beyond simply adding copilots to existing products. Vendors are increasingly packaging AI in
N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability — N-able N-central contains an authentication bypass using an alternate path or channel that allows for authentication bypass.
IBM Langflow Code Injection Vulnerability — Langflow contains a code injection vulnerability that allows unauthenticated attackers to achieve full remote code execution on default Langflow deployments.
Apache Tomcat Missing Encryption of Sensitive Data Vulnerability — Apache Tomcat contains a missing encryption of sensitive data vulnerability that allows the bypass of the EncryptInterceptor.
The UK’s Police National Legal Database and Ask the Police service have been breached
Reports said intruders appeared to gain access to the Jira environment and other sensitive data of the Żabka retail chain. The company confirmed an intrusion occurred in late July.