Reading view

There are new articles available, click to refresh the page.

Republican attorneys general urge OpenAI to preserve records on Hugging Face breach

Miranda Nazzaro reports: More than a dozen Republican attorneys general are calling on OpenAI to preserve records on its models’ recent breach of another company, suggesting the AI firm may have violated state or federal laws in the incident. In a letter sent Monday to OpenAI CEO Sam Altman, 15 attorneys general wrote the ChatGPT-maker may have...

Source

A “No-Logs” VPN That Kept 58 Million Connection Logs: Inside the NotVPN / SplitVPN Breach

They advertised and pinky swore “no logs.” But according to research by MysteriumVPN, they logged. Key takeaways from MysteriumVPN: A threat actor on the Altenen cybercrime forum is distributing a 17 GB SQL database they claim was stolen from SplitVPN (formerly NotVPN), a Russian VPN used to bypass internet blocks. The Mysterium research team obtained...

Source

Weaponizing Exposed Data

Lab-1 Dark-web Research Team Contributors:Alex Necula, Anastasia Sentasnova, Ellis Stannard, Jeffrey Bell, Manuel Boll, Valéry Rieß-Marchive Mannie W writes: Ransomware and data-extortion groups are moving beyond bulk dumps to analyze, index and price stolen data before it is published or sold — removing the “weaponization tax” and turning breaches into searchable, tranched and targetable assets....

Source

Suspect arrested in investigation into sadistic “764” group

From the Dutch Police: In an investigation into so-called online sadistic COM networks, a suspect from North Holland was arrested on Monday, July 20. As a member of the group ‘764’, the suspect allegedly asked girls to cut themselves and write his online username on surfaces such as walls with their blood—known as ‘bloodsigns’. He...

Source

Doxbin admin jailed for egging on swatters from behind a screen

Connor Jones reports: A Welshman was sentenced to prison on Tuesday for his role in numerous swattings in the UK, US, and Canada. Callum Dare, 26, was an administrator of Doxbin, a dark web platform frequented by individuals that expose the personally identifiable information (PII) of people, usually to encourage harassment or to target them through...

Source

The “Anonymous” Tip System That Wasn’t: Three Months Later, Why Hasn’t Navigate360 Notified Anyone?

Trigger Warning: This post includes content from tips submitted to anonymous tiplines by or about students. While identity information is redacted, tips may include obscenities and explicit references to sexual abuse, rape, assault, self-harm, violence, suicidal ideation, pornography, and pedophilia.  Overview On March 18, 2026, DDoSecrets and Straight Arrow News reported on a dataset provided...

Source

Alberta, Centurion Project sued over alleged data breach that affected millions of voters

Carrie Tait reports: A retired lawyer is suing Alberta, its Chief Electoral Officer and two organizations that support secession for their respective roles in an alleged data breach affecting 2.9 million residents in the province. Clint Docken, a former class-action lawyer, last week filed a sweeping lawsuit stemming from allegations the Centurion Project unlawfully obtained...

Source

NAIC suspends investment risk designations after cyber attack

The National Association of Insurance Commissioners (NAIC) is the U.S. standard-setting and regulatory support organization. It is governed by the chief insurance regulators from the 50 states, the District of Columbia, and five U.S. territories. The organization serves the public interest by setting standards and regulatory best practices, acting as a forum to exchange information,...

Source

Another BreachForums Clone Shuts Down, Citing Fears of ShinyHunters

If there were a soundtrack for this post, it would be Queen’s “Another One Bites the Dust.” There’s another chapter in the ongoing drama that is “BreachForums.” Yesterday,  the BreachForums clone at breached[.hn]  was listed for sale for $3k USD. By today, they had dropped the price to $ 1,500 USD and still couldn’t seem...

Source

Two Data Breaches Didn’t Sink Novo Nordisk’s Stock. Why Not?

June was a challenging month for Novo Nordisk regarding cybersecurity and intellectual property protection. The pharma giant allegedly had some of its data — including intellectual property — stolen by two independent groups of threat actors. Unaware of each other, each group claimed to have acquired a large amount of valuable information. One demanded $25...

Source

Canadian hacker pleads guilty to charges for cyberattack on Texas Republican website

Alexandra Posadzki reports: Canadian hacker Aubrey Cottle has pleaded guilty to three charges stemming from a cyberattack linked to notorious hacktivist group Anonymous on the Texas Republican Party. Mr. Cottle, who appeared in court in Newmarket, Ont., on Thursday, pleaded guilty to fraudulently obtaining a computer service, namely the systems of web-hosting company Epik, causing mischief...

Source

Cybersecurity breach includes Crime Stoppers of Hamilton data

The Navigate360 (“P3”) data breach seems to finally be getting some attention in Canada. Nicole O’Reilly reports: Hamilton police say they’ve been made aware that a cybersecurity incident earlier this year affecting a U.S.-based online platform includes a breach of Crime Stoppers of Hamilton data. The P3 platform, owned by Navigate360, is under contract with...

Source

GitHub dismissed security reports on flaws now exploited by supply-chain worm, researchers say

Alexander Martin reports: GitHub rejected two formal vulnerability reports identifying design flaws that researchers say are enabling variants of the Shai-Hulud supply-chain worm to infect and compromise hundreds of software packages and developer accounts worldwide. The reports, submitted by threat intelligence group Deep Specter Research through GitHub’s bug disclosure channel on HackerOne, were both closed...

Source

AU: American Express ordered to fix security gaps after customer was spied on

Harriet Alexander and Julie Lewis report: The privacy watchdog has ordered American Express to rectify security flaws in five of its data systems to guard against “insider threats” and to restrict employee access to specific customer information to protect vulnerable and high-profile customers. Privacy Commissioner Carly Kind found the payments giant had “failed to implement...

Source

ShinyHunters Claims Theft of 297GB of Council of Europe Data; Claims Unconfirmed As Yet

Bhaswati Guha Majumder reports: The cybercrime group ShinyHunters has claimed responsibility for a major breach involving the Council of Europe, threatening to publish hundreds of gigabytes of allegedly stolen data unless its demands are met by 16 June. The claim comes in the wake of a confirmed cybersecurity incident affecting European infrastructure. According to information...

Source

LA: St. George fire district sues IT company over cyberattack

Deon Guillory reports: St. George Fire Protection District No. 2 filed a lawsuit against its former IT security provider, alleging the company’s failures led to a cyberattack that compromised the fire district’s network. The lawsuit, filed March 20 in the 19th Judicial District Court, claims General Informatics LLC breached its contract and fiduciary duty by...

Source

Instagram Recovery Tool Bug Exposed 20,225 Accounts to Password Reset Abuse

Waqas reports: Meta has disclosed a security incident involving an Instagram account recovery tool after attackers used a flaw to send password reset links to email addresses that were not connected to the targeted accounts. According to a data breach notice filed with the Maine Attorney General’s Office, Meta Platforms said the issue affected 20,225 people in...

Source

❌