Data Breach Security News

Confirmed and reported data breaches — what was exposed, which organizations were affected, and how the incident came to light.

A data breach is an incident where sensitive information — customer records, credentials, source code, internal documents — is accessed or exfiltrated without authorization. This feed tracks newly disclosed breaches as organizations, researchers or attackers themselves report them, including what data was exposed and how the compromise happened. Breach disclosures are often incomplete at first and get revised as investigations continue.

Recent Data Breach items

Scottish Govt Suffers Potentially Widening Data Breach at Prosecutor's Officehttps://ift.tt/CjamMWg
@ctinow · Aug 14, 2026
CVE-2026-63702Dell Wyse Management Suite (WMS), versions prior to 2605.0.2, contain a Use of Hard-coded Credentials vulnerability. A low privileged attacker with local access could potentially exploit…
@cveNotify · Aug 14, 2026
CVE-2026-16967IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to gain unauthorized access to system objects due to a time-of-check to time-of-use (TOCTOU) race condition invol…
@cveNotify · Aug 14, 2026
CVE-2026-72835filebrowser versions before v2.63.21 fail to canonicalize paths before evaluating access rules, allowing authenticated users to bypass administrator-defined deny rules using case-variant…
@cveNotify · Aug 14, 2026
RingCentral data breach exposed info of 1.6 million accountshttps://ift.tt/bgxpswz
@ctinow · Aug 14, 2026
1.6 Million Likely Impacted by RingCentral Data Breachhttps://ift.tt/XdV1Jf9
@ctinow · Aug 14, 2026
Over 1,000 Charities Hit by Beacon CRM Data Breachhttps://ift.tt/uJxpYeW
@ctinow · Aug 14, 2026
14,000 Trezor Customers Impacted by Data Breach at ShipMonkhttps://ift.tt/p9sKbj0
@ctinow · Aug 14, 2026
Trezor Shipping Provider Data Breach Exposes Personal Data of 13,689 Customershttps://gbhackers.com/trezor-shipping-provider-data-breach/
@PentestingNews · Aug 14, 2026
Beacon CRM Data Breach Exposes Customer Data via Compromised AWS Access Keyhttps://gbhackers.com/beacon-crm-data-breach-exposes-customer-data/
@PentestingNews · Aug 14, 2026
CVE-2026-16967IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to gain unauthorized access to system objects due to a time-of-check to time-of-use (TOCTOU) race condition invol…
@cveNotify · Aug 14, 2026
CVE-2026-19297IBM Langflow OSS 1.0.0 through 1.9.6 could allow a remote attacker to obtain unauthorized access to user accounts due to improper restriction of excessive authentication attempts.🎖@cveNo…
@cveNotify · Aug 13, 2026
Hackers breach govt webmail while running parallel crypto fraudhttps://ift.tt/lEumRkp
@ctinow · Aug 13, 2026
CVE-2026-73266A flaw was found in the clusterclaims-controller component of Multicluster Engine (MCE). An authenticated tenant can exploit this vulnerability by manipulating ClusterClaim labels. This…
@cveNotify · Aug 13, 2026
CVE-2026-73572In Zimbra Collaboration (ZCS) before 10.1.17, a stored cross-site scripting (XSS) vulnerability exists in the Zimbra Classic Web Client due to insufficient sanitization of specific attac…
@cveNotify · Aug 13, 2026
Trezor discloses data breach affecting nearly 14,000 customershttps://ift.tt/Yerx6Qj
@ctinow · Aug 13, 2026
CVE-2026-73188Unauthenticated Sensitive Data Exposure in KiviCare
@cveNotify · Aug 13, 2026
CVE-2026-60908Vulnerability in the Oracle Installed Base product of Oracle E-Business Suite (component: Create Item Instance). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitab…
@cveNotify · Aug 13, 2026
CVE-2026-3835The Prevent Direct Access – Protect WordPress Files plugin for WordPress is vulnerable to unauthorized access of protected files due to insufficient token validation in the `get_advance_f…
@cveNotify · Aug 13, 2026
CVE-2026-0293A vulnerability in Palo Alto Networks Prisma® Access Agent on Windows enables a local attacker with administrator privileges to bypass the anti-tamper protection, enabling unauthorized ac…
@cveNotify · Aug 13, 2026
CVE-2026-73298The Microsoft Container Migration Solution Accelerator is a multi-service application that provides a multi-agent, AI-driven migration solution for moving container service configuration…
@cveNotify · Aug 12, 2026
CVE-2026-18726A flaw was found in open-iscsi. This vulnerability allows a remote attacker on the same local network segment to cause a Denial of Service (DoS) in the iscsiuio daemon. By sending a spec…
@cveNotify · Aug 12, 2026
CVE-2026-66696Contributor Sensitive Data Exposure in Gutenberg Blocks by Kadence Blocks
@cveNotify · Aug 12, 2026
CVE-2026-66685Unauthenticated Sensitive Data Exposure in Featured Video Plus
@cveNotify · Aug 12, 2026
CVE-2026-66684Unauthenticated Sensitive Data Exposure in Export Import Menus
@cveNotify · Aug 12, 2026
CVE-2026-66683Unauthenticated Sensitive Data Exposure in Custom CSS and JavaScript
@cveNotify · Aug 12, 2026
CVE-2026-73298The Microsoft Container Migration Solution Accelerator is a multi-service application that provides a multi-agent, AI-driven migration solution for moving container service configuration…
@cveNotify · Aug 12, 2026
CVE-2026-61000Vulnerability in the Oracle Process Manufacturing Systems product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Ea…
@cveNotify · Aug 12, 2026
CVE-2026-60893Vulnerability in the Oracle Payroll product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulne…
@cveNotify · Aug 12, 2026
CVE-2026-60877Vulnerability in the Oracle Trade Management product of Oracle E-Business Suite (component: Claim LOV). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulner…
@cveNotify · Aug 12, 2026

Other topics

CVE
Recent CVE identifiers and vulnerability disclosures aggregated from security feeds — new CVE IDs, published advisories, and the vendors and products they affect.
Ransomware
Ransomware attacks, extortion group activity, victim disclosures and decryptor releases tracked as they are reported.
Phishing
Phishing campaigns, credential-harvesting kits, and social-engineering techniques used to compromise users and organizations.
Zero-Day
Zero-day vulnerabilities being actively exploited before a patch exists, and the fixes that follow.
Exploit
Public exploit code, proof-of-concept releases, and technical exploitation write-ups for known vulnerabilities.
Patch
Vendor patches, security updates and fix releases for previously disclosed vulnerabilities.