<?xml version='1.0' encoding='utf-8'?>
<rss version="2.0"><channel><title>Cybersecurity Tracker: Breaches and Incidents</title><link>https://cybersecuritytracker.ai/?cats=breaches-incidents</link><description>Curated cybersecurity news and vulnerability intelligence.</description><lastBuildDate>Sun, 26 Jul 2026 22:32:50 GMT</lastBuildDate><item><title>Developing: AnMed reports phone and internet outage impacting all hospital locations; ERs remain open</title><link>https://databreaches.net/2026/07/26/developing-anmed-reports-phone-and-internet-outage-impacting-all-hospital-locations-ers-remain-open?pk_campaign=feed&amp;pk_kwd=developing-anmed-reports-phone-and-internet-outage-impacting-all-hospital-locations-ers-remain-open</link><guid isPermaLink="false">cst-3229</guid><description>AnMed Health System, which operates four hospitals in Upstate South Carolina and northeast Georgia, experienced a phone and internet outage affecting all locations. Emergency rooms remained operational during the incident despite the connectivity disruption.</description><pubDate>Sun, 26 Jul 2026 14:10:29 GMT</pubDate></item><item><title>A-list directors, actors and celebrities exposed in Tribeca film festival data leak</title><link>https://databreaches.net/2026/07/26/a-list-directors-actors-and-celebrities-exposed-in-tribeca-film-festival-data-leak?pk_campaign=feed&amp;pk_kwd=a-list-directors-actors-and-celebrities-exposed-in-tribeca-film-festival-data-leak</link><guid isPermaLink="false">cst-3230</guid><description>A security researcher discovered four publicly accessible, unencrypted databases connected to the Tribeca Film Festival, including a development database containing over 203,000 records. The databases lacked password protection and exposed sensitive information about festival-associated individuals.</description><pubDate>Sun, 26 Jul 2026 13:06:14 GMT</pubDate></item><item><title>Week in review: ServiceNow pre-auth RCE exploited in the wild, Hugging Face breached</title><link>https://helpnetsecurity.com/2026/07/26/week-in-review-servicenow-pre-auth-rce-exploited-in-the-wild-hugging-face-breached</link><guid isPermaLink="false">cst-3226</guid><description>A weekly news roundup covered multiple security topics, including active exploitation of a ServiceNow pre-authentication remote code execution vulnerability and a breach of Hugging Face. The piece also discussed how organizations increasingly run multiple AI platforms simultaneously across different vendors and departments.</description><pubDate>Sun, 26 Jul 2026 08:00:34 GMT</pubDate></item><item><title>US House Votes to Extend Cyber Sharing Law for 10 Years</title><link>https://databreaches.net/2026/07/25/us-house-votes-to-extend-cyber-sharing-law-for-10-years?pk_campaign=feed&amp;pk_kwd=us-house-votes-to-extend-cyber-sharing-law-for-10-years</link><guid isPermaLink="false">cst-3218</guid><description>The U.S. House of Representatives voted to extend a key cyberthreat sharing law for 10 years by including the reauthorization in the fiscal year 2027 national defense authorization act. The measure passed narrowly on a 216-212 vote Wednesday and was attached to the $1.15 trillion defense policy bill after the reauthorization had been stalled.</description><pubDate>Sat, 25 Jul 2026 14:25:16 GMT</pubDate></item><item><title>AU: Sydney nurse accused of downloading patients’ data in alleged ‘breach of trust’</title><link>https://databreaches.net/2026/07/25/au-sydney-nurse-accused-of-downloading-patients-data-in-alleged-breach-of-trust?pk_campaign=feed&amp;pk_kwd=au-sydney-nurse-accused-of-downloading-patients-data-in-alleged-breach-of-trust</link><guid isPermaLink="false">cst-3219</guid><description>A registered nurse in northern Sydney has been charged after allegedly downloading patient data without authorization. NSW Police launched an investigation following a report to the agency and subsequently searched a home in Frenchs Forest as part of the inquiry.</description><pubDate>Sat, 25 Jul 2026 14:24:50 GMT</pubDate></item><item><title>No Need to Hack When It’s Leaking: Click to Pray edition</title><link>https://databreaches.net/2026/07/25/no-need-to-hack-when-its-leaking-click-to-pray-edition?pk_campaign=feed&amp;pk_kwd=no-need-to-hack-when-its-leaking-click-to-pray-edition</link><guid isPermaLink="false">cst-3220</guid><description>The Click To Pray app, a prayer application endorsed by the Pope with hundreds of thousands of users, exposed users' names and email addresses through a data leak. An ethical hacker discovered the exposure, which had persisted for months or longer.</description><pubDate>Sat, 25 Jul 2026 14:24:35 GMT</pubDate></item><item><title>OpenAI confirms ChatGPT is down worldwide</title><link>https://bleepingcomputer.com/news/artificial-intelligence/openai-confirms-chatgpt-is-down-worldwide</link><guid isPermaLink="false">cst-3208</guid><description>OpenAI confirmed that ChatGPT experienced a worldwide outage affecting access to the artificial intelligence chatbot. The company did not provide details on the cause or expected resolution timeline in the initial report.</description><pubDate>Sat, 25 Jul 2026 09:31:09 GMT</pubDate></item><item><title>OnTrac notifies customers of data breach after network hack</title><link>https://bleepingcomputer.com/news/security/ontrac-notifies-customers-of-data-breach-after-network-hack</link><guid isPermaLink="false">cst-3195</guid><description>OnTrac, a parcel delivery company, disclosed that attackers breached its corporate network and potentially accessed customer personal information. The company is notifying affected customers of the incident.</description><pubDate>Fri, 24 Jul 2026 19:55:01 GMT</pubDate></item><item><title>Chick-fil-A data breach affects more than 13,000 customers</title><link>https://bleepingcomputer.com/news/security/chick-fil-a-data-breach-affects-more-than-13-000-customers</link><guid isPermaLink="false">cst-3178</guid><description>Chick-fil-A confirmed that attackers using credential stuffing tactics compromised more than 13,000 customer accounts on its website and mobile app during a three-day period in mid-June. The breach involved unauthorized access to customer data through reused or weak credentials rather than a direct compromise of the company's systems.</description><pubDate>Fri, 24 Jul 2026 14:04:29 GMT</pubDate></item><item><title>Suspect arrested in investigation into sadistic “764” group</title><link>https://databreaches.net/2026/07/24/suspect-arrested-in-investigation-into-sadistic-764-group?pk_campaign=feed&amp;pk_kwd=suspect-arrested-in-investigation-into-sadistic-764-group</link><guid isPermaLink="false">cst-3187</guid><description>A suspect from North Holland was arrested on July 20 in connection with an online sadistic network called '764'. The individual allegedly coerced minors to engage in self-harm and create 'bloodsigns' bearing his username as evidence of compliance.</description><pubDate>Fri, 24 Jul 2026 13:47:04 GMT</pubDate></item><item><title>Vatican's Official Prayer App Leaks 700K+ Global Users' PII</title><link>https://darkreading.com/vulnerabilities-threats/vatican-official-prayer-app-leaks-700k-pii</link><guid isPermaLink="false">cst-3167</guid><description>Vatican's official prayer application contained a vulnerable API endpoint that exposed personal information for over 700,000 users worldwide. The exposed data included names, email addresses, location information, and site status that could be accessed without authentication through a standard web browser.</description><pubDate>Fri, 24 Jul 2026 13:00:00 GMT</pubDate></item><item><title>Crime Stoppers assured people their tips would be anonymous. Then more than 1 million tips leaked.</title><link>https://databreaches.net/2026/07/24/crime-stoppers-assured-people-their-tips-would-be-anonymous-then-more-than-1-million-tips-leaked?pk_campaign=feed&amp;pk_kwd=crime-stoppers-assured-people-their-tips-would-be-anonymous-then-more-than-1-million-tips-leaked</link><guid isPermaLink="false">cst-3188</guid><description>A breach of Navigate360's systems exposed more than one million tips submitted to Crime Stoppers and law enforcement programs that relied on the company's software for anonymous reporting. The incident undermines trust in anonymous tip submission channels that promised confidentiality to sources.</description><pubDate>Fri, 24 Jul 2026 12:49:59 GMT</pubDate></item><item><title>Origin silent on settlement as alleged fired employee breach detail emerges</title><link>https://databreaches.net/2026/07/24/origin-silent-on-settlement-as-alleged-fired-employee-breach-detail-emerges?pk_campaign=feed&amp;pk_kwd=origin-silent-on-settlement-as-alleged-fired-employee-breach-detail-emerges</link><guid isPermaLink="false">cst-3170</guid><description>Origin Energy has declined to publicly comment on a reported private settlement of a cyber extortion threat. The alleged breach involved unauthorized access through a former employee's credentials, creating concurrent disclosure obligations to regulators, the ASX, and insurers.</description><pubDate>Fri, 24 Jul 2026 12:08:15 GMT</pubDate></item><item><title>T-Mobile violated WA data breach notification law, judge rules</title><link>https://databreaches.net/2026/07/24/t-mobile-violated-wa-data-breach-notification-law-judge-rules?pk_campaign=feed&amp;pk_kwd=t-mobile-violated-wa-data-breach-notification-law-judge-rules</link><guid isPermaLink="false">cst-3171</guid><description>A King County Superior Court judge ruled that T-Mobile violated Washington state data breach notification law by failing to properly notify customers of a 2024 breach affecting 40 million people whose sensitive personal information was stolen and sold on the dark web. The Washington attorney general's office filed the civil lawsuit against T-Mobile in January 2025. The ruling establishes that T-Mobile's notification practices did not meet the state's legal requirements.</description><pubDate>Fri, 24 Jul 2026 12:08:06 GMT</pubDate></item><item><title>Furious KPMG boss expels senior partner over confidential documents in locker</title><link>https://databreaches.net/2026/07/24/furious-kpmg-boss-expels-senior-partner-over-confidential-documents-in-locker?pk_campaign=feed&amp;pk_kwd=furious-kpmg-boss-expels-senior-partner-over-confidential-documents-in-locker</link><guid isPermaLink="false">cst-3172</guid><description>KPMG's chief operating officer, Eileen Hoggett, was expelled after an investigation confirmed she and other senior partners illegally accessed sensitive Lendlease board documents and stored them in a work locker. The expulsion followed a whistleblower claim regarding the unauthorized possession of confidential materials.</description><pubDate>Fri, 24 Jul 2026 12:07:56 GMT</pubDate></item><item><title>Millions of California-bought cars can be hijacked via Bluetooth</title><link>https://databreaches.net/2026/07/24/millions-of-california-bought-cars-can-be-hijacked-via-bluetooth?pk_campaign=feed&amp;pk_kwd=millions-of-california-bought-cars-can-be-hijacked-via-bluetooth</link><guid isPermaLink="false">cst-3174</guid><description>Researchers at UC San Diego identified Bluetooth vulnerabilities affecting at least 2.2 million vehicles equipped with dealer-installed KARR and SWDS security systems. The flaws allow nearby attackers to unlock doors or disable vehicle ignition through wireless attacks. The full research details are forthcoming.</description><pubDate>Fri, 24 Jul 2026 12:06:56 GMT</pubDate></item><item><title>Man gets six years for hacking 750 women's Snapchat accounts</title><link>https://bleepingcomputer.com/news/security/man-gets-six-years-for-hacking-750-womens-snapchat-accounts</link><guid isPermaLink="false">cst-3159</guid><description>An Illinois man received a 76-month prison sentence and three years of supervised release for hacking over 750 women's Snapchat accounts to obtain their nude photos. The case illustrates criminal liability for unauthorized account access and theft of intimate images.</description><pubDate>Fri, 24 Jul 2026 11:17:19 GMT</pubDate></item><item><title>Microsoft 365 outage affects Teams, SharePoint and other services</title><link>https://bleepingcomputer.com/news/microsoft/microsoft-365-outage-affects-teams-sharepoint-and-other-services</link><guid isPermaLink="false">cst-3100</guid><description>Microsoft experienced a widespread outage affecting Teams, SharePoint, and other Microsoft 365 services, with impact concentrated in North America. The disruption impacted collaboration and productivity tools relied upon by thousands of organizations.</description><pubDate>Thu, 23 Jul 2026 15:34:43 GMT</pubDate></item><item><title>Chick-fil-A Accounts Get Fried in Credential Stuffing Attack</title><link>https://securityweek.com/chick-fil-a-accounts-get-fried-in-credential-stuffing-attack</link><guid isPermaLink="false">cst-3109</guid><description>Threat actors used credentials from previous breaches to gain unauthorized access to Chick-fil-A One customer accounts through credential stuffing. The attack relied on reused passwords rather than exploiting a vulnerability in the restaurant chain's systems.</description><pubDate>Thu, 23 Jul 2026 14:55:19 GMT</pubDate></item><item><title>Major Australian energy supplier confirms customer data compromised</title><link>https://therecord.media/australia-origin-energy-data-breach</link><guid isPermaLink="false">cst-3113</guid><description>Origin Energy, a major Australian energy supplier, confirmed that customer data was compromised in a recent breach and is investigating the scope of the incident to determine how many Australians were affected.</description><pubDate>Thu, 23 Jul 2026 13:20:00 GMT</pubDate></item><item><title>Microsoft working to fix Exchange Online mailbox quarantine issue</title><link>https://bleepingcomputer.com/news/microsoft/microsoft-working-to-fix-exchange-online-mailbox-quarantine-issue</link><guid isPermaLink="false">cst-3069</guid><description>Microsoft is addressing an issue with Exchange Online that has been incorrectly quarantining customer mailboxes since Sunday. The company is working to resolve the problem and restore normal service for affected users.</description><pubDate>Thu, 23 Jul 2026 09:20:10 GMT</pubDate></item><item><title>ID: Kootenai County notifies residents of data breach</title><link>https://databreaches.net/2026/07/22/id-kootenai-county-notifies-residents-of-data-breach?pk_campaign=feed&amp;pk_kwd=id-kootenai-county-notifies-residents-of-data-breach</link><guid isPermaLink="false">cst-3057</guid><description>Kootenai County is notifying residents of a ransomware attack discovered on March 30, 2026, that compromised personal information on its computer network. The county took immediate action to secure and restore its systems following the detection.</description><pubDate>Thu, 23 Jul 2026 00:45:56 GMT</pubDate></item><item><title>TN: Data breach delays start of Sumner County school year</title><link>https://databreaches.net/2026/07/22/tn-data-breach-delays-start-of-sumner-county-school-year?pk_campaign=feed&amp;pk_kwd=tn-data-breach-delays-start-of-sumner-county-school-year</link><guid isPermaLink="false">cst-3058</guid><description>Sumner County Schools in Tennessee discovered a data breach in its computer network and postponed the start of the school year to resolve the incident before students return. The breach was identified earlier in the week, prompting district officials to revise the calendar.</description><pubDate>Thu, 23 Jul 2026 00:25:52 GMT</pubDate></item><item><title>Instructure Incident Driving 58 Percent of Breach Notices in 2026</title><link>https://databreaches.net/2026/07/22/instructure-incident-driving-58-percent-of-breach-notices-in-2026?pk_campaign=feed&amp;pk_kwd=instructure-incident-driving-58-percent-of-breach-notices-in-2026</link><guid isPermaLink="false">cst-3059</guid><description>A single Instructure incident generated 471 million breach notices in the first half of 2026, accounting for 58 percent of all breach notifications despite 1,029 total compromises being reported during that period. The Identity Theft Resource Center documented this concentration of impact from one major breach event among organizations handling large datasets.</description><pubDate>Wed, 22 Jul 2026 23:12:10 GMT</pubDate></item><item><title>Upbound says hack caused $13 million in fraudulent Acima leases</title><link>https://bleepingcomputer.com/news/security/upbound-says-hack-caused-13-million-in-fraudulent-acima-leases</link><guid isPermaLink="false">cst-3047</guid><description>Threat actors who compromised Upbound Group's systems used stolen data to fraudulently originate approximately $13 million in Acima leases. The breach highlighted the exposure of customer information and the downstream financial impact when stolen credentials are weaponized for unauthorized transactions.</description><pubDate>Wed, 22 Jul 2026 21:43:39 GMT</pubDate></item><item><title>South Korea discloses data breach impacting diplomats worldwide</title><link>https://bleepingcomputer.com/news/security/south-korea-discloses-data-breach-impacting-diplomats-worldwide</link><guid isPermaLink="false">cst-3048</guid><description>South Korea's National Diplomatic Academy suffered a ten-month breach of its online education system, exposing personal information of current and former Ministry of Foreign Affairs employees and diplomats stationed abroad. The incident remained undetected for an extended period before disclosure.</description><pubDate>Wed, 22 Jul 2026 20:06:54 GMT</pubDate></item><item><title>Real world incident response: Microsoft and AXA XL strengthen cyber resilience</title><link>https://microsoft.com/en-us/security/blog/2026/07/22/real-world-incident-response-microsoft-and-axa-xl-strengthen-cyber-resilience</link><guid isPermaLink="false">cst-3041</guid><description>Microsoft and AXA XL have established a partnership to integrate Microsoft Defender Experts Cybersecurity Incident Response services into AXA XL's cyber insurance offerings for policyholders. The collaboration aims to coordinate technical response, business decisions, and insurance coverage in parallel during incidents rather than sequentially, reducing response delays and risk. The model emphasizes pre-crisis alignment among security, executive, legal, and insurance teams to streamline decision-making when incidents occur.</description><pubDate>Wed, 22 Jul 2026 16:00:00 GMT</pubDate></item><item><title>Suno, Paidwork Data Breaches Affect Tens of Millions of Accounts</title><link>https://securityweek.com/suno-paidwork-data-breaches-affect-tens-of-millions-of-accounts</link><guid isPermaLink="false">cst-3015</guid><description>Data breaches at Suno and Paidwork exposed personally identifiable information and financial data from tens of millions of accounts. Attackers leaked names, email addresses, phone numbers, passwords, and financial information from both platforms.</description><pubDate>Wed, 22 Jul 2026 15:02:11 GMT</pubDate></item><item><title>Chick-fil-A discloses data breach after credential stuffing attacks</title><link>https://bleepingcomputer.com/news/security/chick-fil-a-discloses-data-breach-after-credential-stuffing-attacks</link><guid isPermaLink="false">cst-2975</guid><description>Chick-fil-A disclosed a data breach affecting customer accounts compromised through credential stuffing attacks. The restaurant chain is notifying affected customers as part of its response to the incident.</description><pubDate>Wed, 22 Jul 2026 06:40:29 GMT</pubDate></item><item><title>Milford, New Hampshire Confirms Unauthorized Activity, Withholds Details of Suspected Cyberattack</title><link>https://databreaches.net/2026/07/21/milford-new-hampshire-confirms-unauthorized-activity-withholds-details-of-suspected-cyberattack?pk_campaign=feed&amp;pk_kwd=milford-new-hampshire-confirms-unauthorized-activity-withholds-details-of-suspected-cyberattack</link><guid isPermaLink="false">cst-2974</guid><description>Milford, New Hampshire confirmed unauthorized activity affecting town systems beginning July 15 but has not disclosed specific details about the suspected cyberattack. The town issued alerts to residents about the incident, though the full scope and nature of the compromise remain unclear.</description><pubDate>Wed, 22 Jul 2026 00:01:07 GMT</pubDate></item><item><title>Cyberattack against Maine telecom disrupted municipal internet service in 23 towns</title><link>https://databreaches.net/2026/07/21/cyberattack-against-maine-telecom-disrupted-municipal-internet-service-in-23-towns?pk_campaign=feed&amp;pk_kwd=cyberattack-against-maine-telecom-disrupted-municipal-internet-service-in-23-towns</link><guid isPermaLink="false">cst-2967</guid><description>A cyberattack against a Maine telecommunications company on Sunday disrupted internet service across 23 towns in the midcoastal region. At least one municipal government, including the town of Damariscotta, experienced service loss as a result of the incident.</description><pubDate>Tue, 21 Jul 2026 19:07:18 GMT</pubDate></item><item><title>Spain fines 23andMe nearly $3 million for cybersecurity failings enabling 2023 hack</title><link>https://therecord.media/spain-fines-23andme-3-million-cyber-failings-data-breach</link><guid isPermaLink="false">cst-2958</guid><description>Spain's data protection authority fined 23andMe approximately 2.9 million euros for security failures that enabled a 2023 breach impacting 6.9 million users globally, with over 2,600 Spanish residents affected. The penalty reflects regulatory enforcement against inadequate safeguards that allowed unauthorized access to personal genetic data.</description><pubDate>Tue, 21 Jul 2026 17:10:00 GMT</pubDate></item><item><title>AI music generator Suno breach affects 55M users, per Have I Been Pwned</title><link>https://techcrunch.com/2026/07/21/ai-music-generator-suno-breach-affects-55m-users-per-have-i-been-pwned</link><guid isPermaLink="false">cst-2945</guid><description>A breach of Suno, an AI music generator, exposed personal information including names, phone numbers, and physical addresses for 55 million users. The incident was reported through the Have I Been Pwned breach notification service.</description><pubDate>Tue, 21 Jul 2026 14:48:18 GMT</pubDate></item><item><title>FortiBleed Emergency: 74,000 Fortinet Logins Exposed</title><link>https://youtube.com/watch?v=fwnEN-OIH_w</link><guid isPermaLink="false">cst-2916</guid><description>A security issue called FortiBleed has resulted in the exposure of approximately 74,000 Fortinet login credentials. The incident appears to affect Fortinet products and services used by organizations worldwide.</description><pubDate>Tue, 21 Jul 2026 13:21:42 GMT</pubDate></item><item><title>Personal data of all South Korean diplomats believed leaked in ‘unprecedented’ cyberattack</title><link>https://databreaches.net/2026/07/21/personal-data-of-all-south-korean-diplomats-believed-leaked-in-unprecedented-cyberattack?pk_campaign=feed&amp;pk_kwd=personal-data-of-all-south-korean-diplomats-believed-leaked-in-unprecedented-cyberattack</link><guid isPermaLink="false">cst-2940</guid><description>South Korea's Foreign Ministry reported that personal data of nearly all diplomatic personnel was compromised in a cyberattack on the Korea National Diplomatic Academy's data system, affecting up to 10,000 administrative and intelligence records. The ministry characterized the incident as unprecedented in scope.</description><pubDate>Tue, 21 Jul 2026 12:58:07 GMT</pubDate></item><item><title>NYSDFS Secures $50 Million Penalty from Swedbank for Withholding Information from Investigators</title><link>https://databreaches.net/2026/07/21/nysdfs-secures-50-million-penalty-from-swedbank-for-withholding-information-from-investigators?pk_campaign=feed&amp;pk_kwd=nysdfs-secures-50-million-penalty-from-swedbank-for-withholding-information-from-investigators</link><guid isPermaLink="false">cst-2941</guid><description>The New York Department of Financial Services (NYSDFS) secured a $50 million penalty from Swedbank for withholding information from investigators. The settlement relates to ongoing investigations stemming from the Panama Papers leak of 2016, which exposed the law firm Mossack Fonseca's role in facilitating financial secrecy schemes. Swedbank's non-cooperation with regulators constituted a significant compliance violation.</description><pubDate>Tue, 21 Jul 2026 12:53:29 GMT</pubDate></item><item><title>Suno Data Breach had a breach in 2025. Why is it first being known now?</title><link>https://databreaches.net/2026/07/21/suno-data-breach-had-a-breach-in-2025-why-is-it-first-being-known-now?pk_campaign=feed&amp;pk_kwd=suno-data-breach-had-a-breach-in-2025-why-is-it-first-being-known-now</link><guid isPermaLink="false">cst-2942</guid><description>AI music generation platform Suno experienced a data breach in November 2025 that remained unreported until July 2026. The incident exposed user data, with details initially disclosed by 404 Media and later documented on the Have I Been Pwned breach notification service.</description><pubDate>Tue, 21 Jul 2026 12:53:16 GMT</pubDate></item><item><title>Seoul Notifies 4.62 Million of Ttareungyi Data Breach, Offers Free Passes</title><link>https://databreaches.net/2026/07/21/seoul-notifies-4-62-million-of-ttareungyi-data-breach-offers-free-passes?pk_campaign=feed&amp;pk_kwd=seoul-notifies-4-62-million-of-ttareungyi-data-breach-offers-free-passes</link><guid isPermaLink="false">cst-2943</guid><description>Seoul's metropolitan government is notifying approximately 4.62 million residents of a data breach affecting Ttareungyi, the city's public bike-sharing service. Affected individuals will receive text notifications and compensation including 30-day passes to the service.</description><pubDate>Tue, 21 Jul 2026 12:53:07 GMT</pubDate></item><item><title>Clover Health Investments Discloses Data Breach</title><link>https://securityweek.com/clover-health-investments-discloses-data-breach</link><guid isPermaLink="false">cst-2889</guid><description>Clover Health Investments disclosed a data breach in which attackers used social engineering to compromise employee accounts containing personal and health information.</description><pubDate>Tue, 21 Jul 2026 09:36:51 GMT</pubDate></item><item><title>Estée Lauder discloses data breach via Oracle E-Business flaw</title><link>https://bleepingcomputer.com/news/security/est-e-lauder-discloses-data-breach-via-oracle-e-business-flaw</link><guid isPermaLink="false">cst-2875</guid><description>Estée Lauder disclosed a data breach resulting from attackers exploiting a vulnerability in Oracle E-Business Suite, which the company deployed for HR operations. The breach affected customer data stored within systems accessible through the compromised application.</description><pubDate>Mon, 20 Jul 2026 22:39:30 GMT</pubDate></item><item><title>Hackers steal $23.7 million in crypto from Ostium in off-chain attack</title><link>https://bleepingcomputer.com/news/security/hackers-steal-237-million-in-crypto-from-ostium-in-off-chain-attack</link><guid isPermaLink="false">cst-2868</guid><description>Ostium, a trading platform, lost $23.75 million when an attacker compromised off-chain infrastructure that supplied price data to the protocol, enabling the theft from its liquidity provider vault. The attack exploited the dependency on external systems to feed critical information into the platform's operations.</description><pubDate>Mon, 20 Jul 2026 22:22:56 GMT</pubDate></item><item><title>Hackers were inside South Korea's diplomat training system for 9 months</title><link>https://therecord.media/south-korea-cyberattack-foreign-ministry</link><guid isPermaLink="false">cst-2842</guid><description>Unidentified attackers gained access to an online education system operated by South Korea's diplomatic academy and maintained presence for nine months, during which they exfiltrated personal information of current and former Ministry of Foreign Affairs staff. The incident went undetected until discovered through an investigation.</description><pubDate>Mon, 20 Jul 2026 15:15:00 GMT</pubDate></item><item><title>Paidwork breach exposes sensitive data of 23 million user</title><link>https://helpnetsecurity.com/2026/07/20/paidwork-data-breach-23-million-users</link><guid isPermaLink="false">cst-2845</guid><description>Paidwork, a microtask platform that pays users for activities like watching ads and completing surveys, suffered a breach exposing data for over 23 million users. The incident affected a large user base reliant on the platform for modest earnings from online tasks.</description><pubDate>Mon, 20 Jul 2026 14:52:29 GMT</pubDate></item><item><title>Italy fines WINDTRE €1.7 million over security flaws behind two data breaches</title><link>https://helpnetsecurity.com/2026/07/20/italy-windtre-1-7-million-fine</link><guid isPermaLink="false">cst-2832</guid><description>Italy's data protection authority fined WINDTRE, a major Italian telecom operator, €1.7 million for serious data security shortcomings that enabled two separate breaches in February 2025. The attackers used social engineering techniques, impersonating support technicians to gain access, and exfiltrated personal data from over 365,000 customers.</description><pubDate>Mon, 20 Jul 2026 13:19:05 GMT</pubDate></item><item><title>Hugging Face confirms breach affected internal datasets and credentials, urges users to take action</title><link>https://techcrunch.com/2026/07/20/hugging-face-confirms-breach-affected-internal-datasets-and-credentials-urges-users-to-take-action</link><guid isPermaLink="false">cst-2834</guid><description>Hugging Face confirmed a breach that exposed internal datasets and credentials, prompting the company to advise users to rotate access tokens and review account activity. The incident affected data stored on the platform and required immediate user action to secure compromised authentication materials.</description><pubDate>Mon, 20 Jul 2026 12:39:28 GMT</pubDate></item><item><title>New Index Tracks Material Breaches — And Refuses to Add Up the Losses</title><link>https://securityweek.com/new-index-tracks-material-breaches-and-refuses-to-add-up-the-losses</link><guid isPermaLink="false">cst-2829</guid><description>A cybersecurity executive named Richard Bird created an index designed to track material breaches for use by security professionals, journalists, policymakers, and the general public. The index deliberately avoids aggregating financial loss figures across incidents.</description><pubDate>Mon, 20 Jul 2026 11:46:50 GMT</pubDate></item><item><title>Broken Promises of Anonymity: Four Months Later, Still No Transparency. Now We’re Seeking Accountability.</title><link>https://databreaches.net/2026/07/20/broken-promises-of-anonymity-four-months-later-still-no-transparency-now-were-seeking-accountability?pk_campaign=feed&amp;pk_kwd=broken-promises-of-anonymity-four-months-later-still-no-transparency-now-were-seeking-accountability</link><guid isPermaLink="false">cst-2849</guid><description>Navigate360 disclosed that 8.3 million anonymous tips were exposed in a breach on March 18, 2026. Four months after the incident, the company has provided limited transparency and downstream programs relying on its platform have remained silent. DataBreaches.net is pursuing accountability through state and federal regulators.</description><pubDate>Mon, 20 Jul 2026 11:36:04 GMT</pubDate></item><item><title>Ernst &amp; Young Data Breach Affects Personal, Financial Information</title><link>https://securityweek.com/ernst-young-data-breach-affects-personal-financial-information</link><guid isPermaLink="false">cst-2830</guid><description>Ernst and Young experienced a data breach involving a third-party management platform, resulting in the theft of names, addresses, Social Security numbers, and credit or debit card details. The incident exposed both personal and financial information of affected individuals.</description><pubDate>Mon, 20 Jul 2026 11:27:38 GMT</pubDate></item><item><title>Software provider to more than 2,000 US hospitals says hackers stole employee and customer data</title><link>https://therecord.media/software-provider-for-us-hospitals-customer-data-breach</link><guid isPermaLink="false">cst-2831</guid><description>Craneware, a software provider serving more than 2,000 US hospitals, disclosed that unauthorized access to a subset of its data environment was detected, prompting the company to engage external forensic investigators to assess the breach.</description><pubDate>Mon, 20 Jul 2026 11:00:00 GMT</pubDate></item><item><title>Microsoft confirms Windows Server Update Services sync delays</title><link>https://bleepingcomputer.com/news/microsoft/microsoft-working-to-fix-wsus-server-sync-delays-and-timeouts</link><guid isPermaLink="false">cst-2825</guid><description>Microsoft is addressing a known issue that disrupted Windows Server Update Services (WSUS) synchronization for more than a week. The company is actively working on a fix for the affected infrastructure.</description><pubDate>Mon, 20 Jul 2026 10:47:28 GMT</pubDate></item></channel></rss>