PortSwigger
PortSwigger says HTTP Terminator, an artificial intelligence (AI)-assisted research system built by James Kettle, generated and proved new HTTP desynchronization techniques after exploring 30,000 candidate attack vectors
SaaS platforms, cloud providers, developer tooling, and app-layer infrastructure are concentrated attack surfaces. One tech vendor breach can expose thousands of downstream customers. Below is every tech-sector breach LeakTrace has indexed.
PortSwigger says HTTP Terminator, an artificial intelligence (AI)-assisted research system built by James Kettle, generated and proved new HTTP desynchronization techniques after exploring 30,000 candidate attack vectors
24B stolen credential records publicly exposed
On March 24, 2026, developers building AI applications with LiteLLM — a Python package with 95 million monthly downloads — unknowingly installed malicious code. A threat actor group known as TeamPCP had compromised the P
62M records exposed to federal regulators
Major cyber breach affecting tens of thousands of students and teachers via education technology platform
10,869,543 records exposed — Dates of birth, Email addresses, Genders, Names and 3 more
Alleged data breach of customer records by threat actor on underground hacking forums
BlackFile has rebranded as Redact after an alleged affiliate hijack, with Google linking the group to ongoing vishing and extortion campaigns
Officer PII and justice partner emails exposed
More than 3 million Americans impacted by 2024 breach affecting multiple states
Cyber-attack exposed medical records including Medicare numbers and pathology results
Progress LoadMaster Command Injection Vulnerability — Progress LoadMaster contains a command injection vulnerability that allows an un-authenticated attacker to execute arbitrary commands on the LoadMaster appliance by e
INC_RANSOM ransomware attack confirmed
200 firms hit via stale credential including LastPass and HackerOne
28K records with passport photos and loan documents stolen
Police and government contact data on dark web
Data breach affecting hundreds of thousands of Washington customers, notification law violations
Nearly 1 petabyte stolen in extortion attack
Client tax documents accessed via third-party platform
900K customer PII records stolen via vishing
2M government records leaked