Data Breach Security News

Confirmed and reported data breaches: what was exposed, which organizations were affected, and how the incident came to light.

A data breach is an incident where sensitive information (customer records, credentials, source code, internal documents) is accessed or exfiltrated without authorization. Newly disclosed breaches land here as organizations, researchers or the attackers themselves report them, including what was exposed and how the compromise happened. These disclosures are often incomplete at first and get revised as investigations continue.

Recent Data Breach items

How a Sandbox Breach Halted Frontier AI Training and Reconstructed the AI Cybersecurity Paradigm https://kylesinvestigation.com/2026/09/28/how-a-sandbox-breach-halted-frontier-ai-training-and-reconstr…
@secharvester · Sep 29, 2026
CVE-2026-40854 WNC T-Mobile 5G Box IDU router contains an authentication bypass vulnerability in the portal.cgi component. The session verification mechanism improperly validates the sessionid cookie…
@cveNotify · Sep 28, 2026
Times Car confirms data breach affecting 6.6 million user accounts Japanese car-sharing service Times Car has confirmed that approximately 6.6 million user accounts were compromised in a cyberattack d…
@bleepingcomputer · Sep 28, 2026
Times Car confirms data breach affecting 6.6 million user accounts https://ift.tt/e69C10x
@ctinow · Sep 28, 2026
Bitget Restarts Bitcoin Withdrawals Following $387.5m Wallet Breach 📔 Bitget has restarted Bitcoin withdrawals after a 387.5m breach of its hot and warm wallets. 📖 Read more. 🔗 Via " Infosecurity Maga…
@cibsecurity · Sep 28, 2026
Anthropic Declines Australian AI Hearing as OpenAI Agent Breach Faces Scrutiny 🦿 Anthropic declined an Australian Senate AI hearing as officials investigate an OpenAI agent breach and consider mandato…
@cibsecurity · Sep 28, 2026
CVE-2026-93355 LiteLLM contains a weak authentication vulnerability that allows an attacker holding a valid JWT from the configured identity provider to authenticate as any existing user by exploiting…
@cveNotify · Sep 28, 2026
Cyber Alert ‼️ 🇪🇸 Spain - 𝗝𝘂𝗻𝘁𝗮 𝗱𝗲 𝗔𝗻𝗱𝗮𝗹𝘂𝗰í𝗮 Meduza Locker hacking group claims to have breached Junta de Andalucía. According to the threat actor, the compromised data includes client, confidential,…
@hackmanac_cybernews · Sep 28, 2026
CVE-2026-80359 Dell Boot Optimized Server Storage (BOSS), versions prior to 2.2.13.2038, contains an On-Chip Debug and Test Interface With Improper Access Control vulnerability in the SMCU on 17G BOSS…
@cveNotify · Sep 28, 2026
CVE-2026-80358 Dell Boot Optimized Server Storage (BOSS), versions prior to 2.2.13.2038, contains an On-Chip Debug and Test Interface With Improper Access Control vulnerability in the SMCU on 17G BOSS…
@cveNotify · Sep 28, 2026
CVE-2026-80357 Dell Boot Optimized Server Storage (BOSS), versions prior to 2.2.13.2038, contains an On-Chip Debug and Test Interface With Improper Access Control vulnerability in the SMCU on 17G BOSS…
@cveNotify · Sep 28, 2026
Nearly 400,000 Medicaid Beneficiaries Caught in Medicaid and DC Healthcare Alliance Data Exposure https://securityaffairs.com/199926/data-breach/nearly-400000-medicaid-beneficiaries-caught-in-medicaid…
@PentestingNews · Sep 28, 2026
Researchers Discover Cybercrime Server Containing AI Tools, Phishing Kits and Stolen Data https://gbhackers.com/ai-tools-for-attack/
@PentestingNews · Sep 28, 2026
CVE-2026-80359 Dell Boot Optimized Server Storage (BOSS), versions prior to 2.2.13.2038, contains an On-Chip Debug and Test Interface With Improper Access Control vulnerability in the SMCU on 17G BOSS…
@cveNotify · Sep 28, 2026
CVE-2026-80359 Dell Boot Optimized Server Storage (BOSS), versions prior to 2.2.13.2038, contains an On-Chip Debug and Test Interface With Improper Access Control vulnerability in the SMCU on 17G BOSS…
@cveNotify · Sep 28, 2026
CVE-2026-80358 Dell Boot Optimized Server Storage (BOSS), versions prior to 2.2.13.2038, contains an On-Chip Debug and Test Interface With Improper Access Control vulnerability in the SMCU on 17G BOSS…
@cveNotify · Sep 28, 2026
CVE-2026-80357 Dell Boot Optimized Server Storage (BOSS), versions prior to 2.2.13.2038, contains an On-Chip Debug and Test Interface With Improper Access Control vulnerability in the SMCU on 17G BOSS…
@cveNotify · Sep 28, 2026
Nearly 400,000 Medicaid Beneficiaries Caught in Medicaid and DC Healthcare Alliance Data Exposure https://ift.tt/aRt4KNC
@ctinow · Sep 28, 2026
Cyber Alert ‼️ 🇨🇭 Switzerland - 𝗠𝘂𝗻𝗶𝗰𝗶𝗽𝗶𝗼 𝗱𝗶 𝗠𝗮𝗻𝗻𝗼 SafePay claims to have breached Municipio di Manno. Threat actor: SafePay Sector: Gov / Mil / LE Data exposure (claimed): Not specified Data type: No…
@hackmanac_cybernews · Sep 28, 2026
FBI agents’ blood tests and doctors’ notes surface after breach https://ift.tt/lEszNjb
@ctinow · Sep 28, 2026
Cyber Alert ‼️ 🇪🇸 Spain - 𝗥𝗲𝘃𝗲𝗻𝗴𝗮 𝗦𝗺𝗮𝗿𝘁 𝗦𝗼𝗹𝘂𝘁𝗶𝗼𝗻𝘀 Qilin hacking group claims to have breached Revenga Smart Solutions. Threat actor: Qilin Sector: Telco Data exposure (claimed): Not specified Data typ…
@hackmanac_cybernews · Sep 28, 2026
Cyber Alert ‼️ 🇯🇵 Japan - 𝗧𝗶𝗺𝗲𝘀 𝗠𝗼𝗯𝗶𝗹𝗶𝘁𝘆 / 𝗧𝗶𝗺𝗲𝘀 𝗖𝗔𝗥 / 𝗧𝗶𝗺𝗲𝘀 𝗕𝘂𝘀𝗶𝗻𝗲𝘀𝘀 𝗦𝗲𝗿𝘃𝗶𝗰𝗲 Times Mobility, operator of Japan’s Times CAR car-sharing service, confirmed that an unauthorized third party obtained dat…
@hackmanac_cybernews · Sep 28, 2026
Belnet Email Breach Exposes Messages and Attachments From Outside Senders Emails sent to Belgium’s Belnet were copied by attackers, including their attachments. Its September 25 disclosure covers inco…
@topcybersecurity · Sep 28, 2026
CyberCodex: Autonomous 22-Source Zero-Cost OSINT, Data Breach, Infostealer & Threat Intelligence CLI Engine + Cyber Warfare Encyclopedia (Zero Dependencies, 0 API Keys) https://ift.tt/rkBJavK
@ctinow · Sep 27, 2026
Rydox Admin Faces 20 Years After Selling Stolen Data and Fraud Tools https://securityaffairs.com/199825/uncategorized/rydox-admin-faces-20-years-after-selling-stolen-data-and-fraud-tools.html
@PentestingNews · Sep 27, 2026
Rydox Admin Faces 20 Years After Selling Stolen Data and Fraud Tools https://ift.tt/KdVWa0C
@ctinow · Sep 27, 2026
Cyber Alert ‼️ 🇯🇵 Japan - 𝗞𝗲𝗶𝗼 𝗖𝗼𝗿𝗽𝗼𝗿𝗮𝘁𝗶𝗼𝗻 (𝗞𝗲𝗶𝗼 𝗘𝗹𝗲𝗰𝘁𝗿𝗶𝗰 𝗥𝗮𝗶𝗹𝘄𝗮𝘆) Keio Corporation (Keio Electric Railway) disclosed that it detected a ransomware attack against servers belonging to the Keio Group i…
@hackmanac_cybernews · Sep 27, 2026
CVE-2026-100860 heym before 0.0.105 does not act on the result of the credential authorization lookup in the Redis workflow node (backend/app/services/node_execution/nodes/redis_node.py). When _get_ac…
@cveNotify · Sep 27, 2026
CVE-2026-83311 Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: BI Platform Security). Supported versions that are affected are 8.2.0.0.0, 12.2.1.4.0 and 26.01.0.0.0. E…
@cveNotify · Sep 27, 2026
Google Confirms Gemini Autonomously Hacked Three Companies During Security Testing Google confirmed its Gemini AI model autonomously breached the protected systems of three companies during red-team t…
@Cyber_Security_Channel · Sep 26, 2026

Other topics

CVE
Recent CVE identifiers and vulnerability disclosures aggregated from security feeds: new IDs, published advisories, and the vendors and products they affect.
Ransomware
Ransomware attacks, extortion group activity, victim disclosures and decryptor releases.
Phishing
Phishing campaigns, credential-harvesting kits, and social-engineering techniques used to compromise users and organizations.
Zero-Day
Zero-day vulnerabilities being actively exploited before a patch exists, and the fixes that follow.
Exploit
Public exploit code, proof-of-concept releases, and technical exploitation write-ups for known vulnerabilities.
Patch
Vendor patches, security updates and fix releases for previously disclosed vulnerabilities.