Alex Ebert
Alex Ebert reports: Wilmer Cutler Pickering Hale & Dorr should pay millions of dollars in damages for loss of clients’ personal information in a May data breach, a putative class action claims. The lawsuit, filed Tue
Law firms hold the most sensitive corporate data outside the client itself — M&A, IP, litigation, settlements. They are systematically targeted by both criminal and state actors. Below is every law-firm breach LeakTrace has indexed.
Alex Ebert reports: Wilmer Cutler Pickering Hale & Dorr should pay millions of dollars in damages for loss of clients’ personal information in a May data breach, a putative class action claims. The lawsuit, filed Tue
A threat actor has published hundreds of fake GitHub repositories impersonating legitimate software and security projects to distribute infostealer malware. [...]
I was really unpleasantly surprised when they let him out while on appeal, and now they may not be able to return him to prison? Did no one foresee that he might not stick around to be sent back to prison? Daryna Antoni
Supermarket giant Lidl has revealed details of a supplier breach impacting customer data
Attackers whose methods line up with the data-extortion group ShinyHunters have spent the past year walking into corporate Salesforce environments without exploiting a single flaw in the platform. The way in h
The defendant's lawyer told Finnish media that he does not know where his client is but believes Kivimäki is outside Finland.
SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability — SonicWall SMA1000 Appliances contain a server-side request forgery vulnerability that could allow a remote unauthenticated attacker to potentially
Microsoft SharePoint Server Missing Authentication for Critical Function Vulnerability — Microsoft SharePoint contains a missing authentication for critical function vulnerability that allows an unauthorized attacker to
SonicWall SMA1000 Appliances Code Injection Vulnerability — SonicWall SMA1000 Appliances contain a code injection vulnerability which in specific conditions could potentially enable a remote authenticated attacker as adm
The D1R cybercrime group claimed to have stolen valuable data from Synopsys and Bosch, threatening to leak it unless a ransom is paid. The post Synopsys Finds No Evidence of Data Breach Amid Bosch Hack Claims appeared f
Abror Shuhratov reports: xAI, the company founded by Elon Musk, has announced emergency measures following a serious controversy involving the unauthorized uploading of users’ private code and confidential informat
Eduard Kovacs reports: A new ransomware group named D1R in recent days listed Synopsys and Bosch on its Tor-based leak website. The cybercriminals claimed to have exploited a vulnerability in Synopsys’ website to access
Microsoft Active Directory Federation Services Insufficient Granularity of Access Control Vulnerability — Microsoft Active Directory Federation Services contains an insufficient granularity of access control vulnerabili
Misconfigured server exposed three phishing operators running Evilginx forks to bypass MFA
Cisco IOS Cross-Site Request Forgery Vulnerability — Cisco IOS 12.4 contains multiple cross-site forgery vulnerabilities that allows remote attackers to execute arbitrary commands via (1) a certain "show privilege" comma
The Jscrambler client-side web security company disclosed that a threat actor published a malicious version of its npm package that has been downloaded almost 1,500 times. [...]
Japan's largest taxi operator, Nihon Kotsu, announced that its systems were compromised in a cyberattack, forcing the company to shut down part of its infrastructure. [...]
A statement on ZEGO Textilveredelungszentrum GmbH’s website explains why they are filing for insolvency: Insolvency proceedings have been initiated – and why we are still looking ahead Ladies and gentlemen, dear b
The WorldLeaks extortion group claimed to have stolen 720 GB of data from the healthcare testing and laboratory services provider. The post Centers Laboratory Data Breach Affects 540,000 Individuals appeared first on Sec
The retailer said the incident did not affect its online shopping platform itself but involved a separately stored customer database maintained by a third-party provider. According to notifications sent to Lidl's German,
Fatima Abdullahi reports: The Federal High Court in Abuja has fixed July 21, 2026, for the arraignment of Zenith Bank Plc and three other defendants over allegations of illegally accessing and disclosing the confidential
The Cybersecurity and Infrastructure Security Agency (CISA) has issued a postmortem on a data leak in which a contractor published dozens of internal CISA credentials -- including AWS Govcloud keys -- in a public GitHub
793,925 records exposed — Academic records, Dates of birth, Email addresses, Genders and 4 more
Version 8.14.0 of the jscrambler npm package shipped with a malicious preinstall hook that silently drops and runs a native infostealer during installation, one build each for Windows, macOS, and Linu