Datadog Inc.
APM and logging data from 340 enterprise customers exposed via compromised CI/CD pipeline
SaaS platforms, cloud providers, developer tooling, and app-layer infrastructure are concentrated attack surfaces. One tech vendor breach can expose thousands of downstream customers. Below is every tech-sector breach LeakTrace has indexed.
APM and logging data from 340 enterprise customers exposed via compromised CI/CD pipeline
450K customer records exposed in targeted attack
2.3M guest records compromised in phishing campaign targeting hotels
560K manufacturing and IoT device records exposed
560K corporate client records stolen
560K automation records exposed
17.5M account records posted to BreachForums
672,247 records exposed — Email addresses, Forum posts, Passwords, Private messages and 1 more
120K workspace records exposed via OAuth misconfiguration
Hewlett Packard Enterprise (HPE) OneView Code Injection Vulnerability — Hewlett Packard Enterprise (HPE) OneView contains a code injection vulnerability that allows a remote unauthenticated user to perform remote code ex
Microsoft Office PowerPoint Code Injection Vulnerability — Microsoft Office PowerPoint contains a code injection vulnerability that allows remote attackers to execute arbitrary code via a PowerPoint file with an OutlineT
340K gaming records exposed in ransomware
MongoDB and MongoDB Server Improper Handling of Length Parameter Inconsistency Vulnerability — MongoDB Server contains an improper handling of length parameter inconsistency vulnerability in Zlib compressed protocol head
2,364,431 records exposed — Dates of birth, Display names, Email addresses, Genders and 4 more
Digiever DS-2105 Pro Missing Authorization Vulnerability — Digiever DS-2105 Pro contains a missing authorization vulnerability which could allow for command injection via time_tzsetup.cgi.
2.3M subscriber records leaked on hacking forum
WatchGuard Firebox Out of Bounds Write Vulnerability — WatchGuard Fireware OS iked process contains an out of bounds write vulnerability in the OS iked process. This vulnerability may allow a remote unauthenticated attac
96,320 records exposed — Dates of birth, Email addresses, Passwords, Usernames
487,226 records exposed — Email addresses, Names, Phone numbers, Physical addresses and 3 more
Cisco Multiple Products Improper Input Validation Vulnerability — Cisco Secure Email Gateway, Secure Email, AsyncOS Software, and Web Manager appliances contains an improper input validation vulnerability that allows thr
SonicWall SMA1000 Missing Authorization Vulnerability — SonicWall SMA1000 contains a missing authorization vulnerability that could allow for privilege escalation appliance management console (AMC) of affected devices.
ASUS Live Update Embedded Malicious Code Vulnerability — ASUS Live Update contains an embedded malicious code vulnerability client were distributed with unauthorized modifications introduced through a supply chain compro
515,149 records exposed — Email addresses, IP addresses, Passwords, Usernames
Fortinet Multiple Products Improper Verification of Cryptographic Signature Vulnerability — Fortinet FortiOS, FortiSwitchMaster, FortiProxy, and FortiWeb contain an improper verification of cryptographic signature vulner