GitLab
560K repository metadata and pipeline records stolen
SaaS platforms, cloud providers, developer tooling, and app-layer infrastructure are concentrated attack surfaces. One tech vendor breach can expose thousands of downstream customers. Below is every tech-sector breach LeakTrace has indexed.
560K repository metadata and pipeline records stolen
287,863 records exposed — Email addresses, IP addresses, Passwords, Usernames
OpenPLC ScadaBR Cross-site Scripting Vulnerability — OpenPLC ScadaBR contains a cross-site scripting vulnerability via system_settings.shtm.
6,414,990 records exposed — Email addresses, Passwords, Usernames
1,829,314 records exposed — Email addresses, Names, Passwords, Phone numbers
103,077 records exposed — Email addresses, Names, Usernames
Oracle Fusion Middleware Missing Authentication for Critical Function Vulnerability — Oracle Fusion Middleware contains a missing authentication for critical function vulnerability, allowing unauthenticated remote attack
1,041,238 records exposed — Email addresses, Names, Phone numbers, Physical addresses and 1 more
340,349 records exposed — Email addresses, Geographic locations, Names, Usernames
Google Chromium V8 Type Confusion Vulnerability — Google Chromium V8 contains a type confusion vulnerability that allows for heap corruption.
Fortinet FortiWeb OS Command Injection Vulnerability — Fortinet FortiWeb contains an OS command Injection vulnerability that may allow an authenticated attacker to execute unauthorized code on the underlying system via c
240K customer APM configurations exposed via compromised CI/CD signing key
Fortinet FortiWeb Path Traversal Vulnerability — Fortinet FortiWeb contains a relative path traversal vulnerability that may allow an unauthenticated attacker to execute administrative commands on the system via crafted
198,520 records exposed — Email addresses, Names, Phone numbers, Physical addresses and 1 more
1,957,476,021 records exposed — Email addresses, Passwords
890K subscriber records exposed in vendor breach
190K customer deployment records and API keys compromised
340K customer records compromised
450K client infrastructure records exposed
Employee and corporate data exposed in third-party service provider breach
340K semiconductor records compromised
3,864,364 records exposed — Email addresses, Profile photos, Usernames
Customer support case management system breached — HAR files with session tokens stolen
Internal developer portal breached — source code, credentials, internal tools exposed