Google Dawn
Google Dawn Use-After-Free Vulnerability — Google Dawn contains an use-after-free vulnerability that could allow a remote attacker who had compromised the renderer process to execute arbitrary code via a crafted HTML pag
SaaS platforms, cloud providers, developer tooling, and app-layer infrastructure are concentrated attack surfaces. One tech vendor breach can expose thousands of downstream customers. Below is every tech-sector breach LeakTrace has indexed.
Google Dawn Use-After-Free Vulnerability — Google Dawn contains an use-after-free vulnerability that could allow a remote attacker who had compromised the renderer process to execute arbitrary code via a crafted HTML pag
Citrix NetScaler Out-of-Bounds Read Vulnerability — Citrix NetScaler ADC (formerly Citrix ADC), NetScaler Gateway (formerly Citrix Gateway) and NetScaler ADC FIPS and NDcPP contain an out-of-bounds reads vulnerability wh
Lloyds app glitch exposed up to 447,936 customers’ transactions and personal data during update
The European Commission has revealed details of a data breach impacting its AWS infrastructure
339,778 records exposed — Email addresses, Passwords, Usernames
1 petabyte data theft affecting 28 companies via multi-month breach by ShinyHunters
1 petabyte stolen by ShinyHunters including call records, FBI data
900K customer marketing contacts with names and email addresses exposed
User account metadata, contact details from January breach
Restaurant POS system breach, customer emails exposed
F5 BIG-IP Stack-Based Buffer Overflow Vulnerability — F5 BIG-IP APM contains a stack-based buffer overflow vulnerability that could allow a threat actor to achieve remote code execution.
15K+ employees/customers data including SSNs, driver's licenses
15K+ employee and customer records including SSNs via service provider hack
128,683 records exposed — Display names, Email addresses, IP addresses, Passwords and 1 more
Aquasecurity Trivy Embedded Malicious Code Vulnerability — Aquasecurity Trivy contains an embedded malicious code vulnerability that could allow an attacker to gain access to everything in the CI/CD environment, includin
Langflow Code Injection Vulnerability — Langflow contains a code injection vulnerability that could allow building public flows without requiring authentication.
420K government contract records from Canadian IT services firm exposed in supply chain attack
222,762 records exposed — Email addresses, IP addresses, Passwords, Usernames
A financially motivated data theft and extortion group is attempting to inject itself into the Iran war, unleashing a worm that spreads through poorly secured cloud services and wipes data on infected systems that use Ir
1.6M enterprise customer records from S/4HANA Cloud exposed via authentication bypass
6M records from 140K+ tenants allegedly accessed via authentication bypass in legacy systems
Apple Multiple Products Improper Locking Vulnerability — Apple watchOS, iOS, iPadOS, macOS, visionOS, and tvOS contain an improper locking vulnerability that could allow a malicious application to cause unexpected change
Apple Multiple Products Classic Buffer Overflow Vulnerability — Apple watchOS, iOS, iPadOS, macOS, visionOS, and tvOS contain a classic buffer overflow vulnerability which could allow a malicious application to cause une
Apple Multiple Products Buffer Overflow Vulnerability — Apple Safari, iOS, watchOS, visionOS, iPadOS, macOS, and tvOS contain a buffer overflow vulnerability that could allow the processing of maliciously crafted web con