The Mercedes-Benz UK breach raised new cybersecurity concerns after reports revealed that attackers accessed sensitive company data tied to employees and customers. Investigators said the stolen information later appeared online following unauthorized access to internal systems. The incident highlights the growing cyber risks facing automotive companies as threat actors increasingly target organizations that manage large…
Concerns surrounding a potential WhatsApp user data leak continue growing as cybersecurity researchers warn that exposed phone numbers and account details may support phishing campaigns and social engineering attacks. Researchers previously identified massive databases containing hundreds of millions of WhatsApp-linked phone numbers circulating across underground forums and cybercrime marketplaces. Some datasets allegedly included records connected…
Hackers claim they are selling a massive dataset allegedly tied to OnlyFans creators and subscribers, raising serious concerns about privacy, phishing, and identity exposure. Posts published on a cybercrime forum claim the alleged OnlyFans mega leak contains roughly 340 million records connected to user accounts. The dataset reportedly includes usernames, email addresses, account statistics, and…
A new German Football Association breach claim has raised cybersecurity concerns after threat actors allegedly leaked login credentials tied to the organization on a cybercrime forum. Researchers said the available sample appears limited, but the incident still highlights growing risks facing sports organizations that manage large digital platforms and member databases. At this stage, investigators…
The Station Casinos data breach has placed another major Las Vegas gaming operator in the spotlight after the company confirmed a cybersecurity incident earlier this year. The disclosure adds to growing concerns about cyberattacks targeting casino and hospitality companies across the United States. Although the company has not revealed the full scope of the breach,…
Starbucks data breach claims are circulating across dark web forums after a threat group alleged that it stole sensitive company information from Amazon Web Services infrastructure. However, cybersecurity researchers investigating the claims said the attackers have not provided convincing proof that Starbucks systems were actually compromised. The allegations triggered attention because the attackers claimed they…
A recent Grafana breach was linked to a missed token rotation following the earlier TanStack supply-chain attack. Grafana confirmed that attackers regained access to internal systems because one compromised credential remained active after the original incident response process. The incident highlights the growing dangers surrounding token management and cloud credential security. Researchers warn that attackers…
A major NYC Health breach exposed sensitive medical records, fingerprint data, and personal information belonging to around 1.8 million people. The incident affected NYC Health + Hospitals, the largest public healthcare system in the United States. Researchers said attackers gained unauthorized access to systems for several months before the breach was discovered. During that period,…
A security incident involving a compromised Visual Studio Code extension has raised fresh concerns about software supply chain attacks targeting developer ecosystems. Researchers discovered that attackers abused extension infrastructure connected to GitHub workflows to expose source code, authentication secrets, and sensitive development data from affected systems. The breach highlights how trusted developer tools continue becoming…
A major data exposure involving Chinese arcade gaming company Wahlap has raised concerns about user privacy and internal security practices. Researchers discovered an unsecured database containing sensitive records tied to the company’s operations, including WeChat identifiers, employee information, and backend management data. The exposed database reportedly remained publicly accessible online without password protection before researchers…