Microsoft DirectX
Microsoft DirectX NULL Byte Overwrite Vulnerability — Microsoft DirectX contains a NULL byte overwrite vulnerability in the QuickTime Movie Parser Filter in quartz.dll in DirectShow which could allow remote attackers to
Law firms hold the most sensitive corporate data outside the client itself — M&A, IP, litigation, settlements. They are systematically targeted by both criminal and state actors. Below is every law-firm breach LeakTrace has indexed.
Microsoft DirectX NULL Byte Overwrite Vulnerability — Microsoft DirectX contains a NULL byte overwrite vulnerability in the QuickTime Movie Parser Filter in quartz.dll in DirectShow which could allow remote attackers to
Adobe Acrobat and Reader Heap-Based Buffer Overflow Vulnerability — Adobe Acrobat and Reader contain a heap-based buffer overflow vulnerability which could allow remote attackers to execute arbitrary code via a crafted P
Microsoft Internet Explorer Use-After-Free Vulnerability — Microsoft Internet Explorer contains an use-after-free vulnerability that could allow remote attackers to execute arbitrary code by accessing a pointer associate
468,124 records exposed — Email addresses, Names, Phone numbers
34,532,941 records exposed — Age groups, Credit scores, Device information, Email addresses and 9 more
Microsoft Exchange Server Cross-Site Scripting Vulnerability — Microsoft Exchange Server contains a cross-site scripting vulnerability during web page generation in Outlook Web Access and when certain interaction conditi
711,099 records exposed — Email addresses, Employers, Job titles, Names and 2 more
Cisco Catalyst SD-WAN Controller Authentication Bypass Vulnerability — Cisco Catalyst SD-WAN Controller & Manager contain an authentication bypass vulnerability that allows an unauthenticated, remote attacker to bypass a
237,810 records exposed — Email addresses, Job titles, Names, Phone numbers and 3 more
Instructure says it reached an agreement with ShinyHunters over the Canvas breach data
The ICO has fined South Staffordshire Water nearly £1m for a series of data protection failings
HiddenLayer reveals infostealer malware in a Hugging Face repository
310,431 records exposed — Email addresses, Job titles, Names, Phone numbers and 2 more
ShinyHunters gets away with emails and other data on 200,000 Zara customers
ShinyHunters has escalated its Canvas extortion campaign, defacing hundreds of school login pages and threatening to leak stolen data unless institutions negotiate
ACSC warns over a campaign targeting organizations which uses ClickFix to deliver Vidar infostealer malware
197,376 records exposed — Email addresses, Geographic locations, Purchases, Support tickets
BerriAI LiteLLM SQL Injection Vulnerability — BerriAI LiteLLM contains a SQL injection vulnerability that allows an attacker to read data from the proxy's database and potentially modify it, leading to unauthorized acces
Ivanti Endpoint Manager Mobile (EPMM) Improper Input Validation Vulnerability — Ivanti Endpoint Manager Mobile (EPMM) contains an improper input validation vulnerability that allows a remotely authenticated user with adm
447,593 records exposed — Email addresses, Names, Phone numbers, Physical addresses
Rapid7 reveals an Iranian false flag operation masquerading as a Chaos ransomware attack
Palo Alto Networks PAN-OS Out-of-bounds Write Vulnerability — Palo Alto Networks PAN-OS contains an out-of-bounds write vulnerability in the User-ID Authentication Portal (aka Captive Portal) service that can allow an un
10,144 records exposed — Email addresses, Names, Passwords, Purchases
119,167 records exposed — Email addresses, Names