Discussion
Loading...

#Tag

Log in
  • About
  • Code of conduct
  • Privacy
  • Users
  • Instances
  • About Bonfire
Mastodon Migration boosted
Marcus "MajorLinux" Summers
Marcus "MajorLinux" Summers
@majorlinux@toot.majorshouse.com  ·  activity timestamp 5 days ago

If you haven't migrated from Substack yet, maybe this can serve as an incentive...

Substack CEO informs users of a data breach

https://www.engadget.com/cybersecurity/substack-ceo-informs-users-of-a-data-breach-151113809.html?src=rss&guccounter=1

#Substack #Data #Breach #Security #Tech

Sorry, no caption provided by author
Sorry, no caption provided by author
Sorry, no caption provided by author
Engadget

Substack CEO informs users of a data breach

The newsletter platform only just became aware of the hack, which happened more than three months ago.
  • Copy link
  • Flag this post
  • Block
Marcus "MajorLinux" Summers
Marcus "MajorLinux" Summers
@majorlinux@toot.majorshouse.com  ·  activity timestamp 5 days ago

If you haven't migrated from Substack yet, maybe this can serve as an incentive...

Substack CEO informs users of a data breach

https://www.engadget.com/cybersecurity/substack-ceo-informs-users-of-a-data-breach-151113809.html?src=rss&guccounter=1

#Substack #Data #Breach #Security #Tech

Sorry, no caption provided by author
Sorry, no caption provided by author
Sorry, no caption provided by author
Engadget

Substack CEO informs users of a data breach

The newsletter platform only just became aware of the hack, which happened more than three months ago.
  • Copy link
  • Flag this post
  • Block
Dave V. ND9JR boosted
Ami
Ami
@ami@mastodon.world  ·  activity timestamp 2 weeks ago

If the #government gave a crap about any of us the #databroker industry simply wouldn't exist.

It should be illegal to harvest people's data and even worse to sell it. It's called #stalking when we do it.

They are vultures and pick over the corpse of every #databreach

#privacy #PII #security #data #breach

  • Copy link
  • Flag this post
  • Block
Ami
Ami
@ami@mastodon.world  ·  activity timestamp 2 weeks ago

If the #government gave a crap about any of us the #databroker industry simply wouldn't exist.

It should be illegal to harvest people's data and even worse to sell it. It's called #stalking when we do it.

They are vultures and pick over the corpse of every #databreach

#privacy #PII #security #data #breach

  • Copy link
  • Flag this post
  • Block
Angela Antunovic boosted
Chris Slane
Chris Slane
@slanecartoon@mastodon.nz  ·  activity timestamp 3 weeks ago

#NZpol cartoon sketch concept carousel - which is your fave? #WIP #privacy #breach #cybersec

3 media
Sorry, no caption provided by author
Sorry, no caption provided by author
Sorry, no caption provided by author
Sorry, no caption provided by author
Sorry, no caption provided by author
Sorry, no caption provided by author
Sorry, no caption provided by author
Sorry, no caption provided by author
Sorry, no caption provided by author
  • Copy link
  • Flag this post
  • Block
Chris Slane
Chris Slane
@slanecartoon@mastodon.nz  ·  activity timestamp 3 weeks ago

#NZpol cartoon sketch concept carousel - which is your fave? #WIP #privacy #breach #cybersec

3 media
Sorry, no caption provided by author
Sorry, no caption provided by author
Sorry, no caption provided by author
Sorry, no caption provided by author
Sorry, no caption provided by author
Sorry, no caption provided by author
Sorry, no caption provided by author
Sorry, no caption provided by author
Sorry, no caption provided by author
  • Copy link
  • Flag this post
  • Block
Hacker News
Hacker News
@h4ckernews@mastodon.social  ·  activity timestamp last month

Flock Hardcoded the Password for America's Surveillance Infrastructure 53 Times

https://nexanet.ai/blog/53-times-flocksafety-hardcoded-the-password-for-americas-surveillance-infrastructure

#HackerNews #FlockSafety #Surveillance #Infrastructure #Password #Breach #Cybersecurity #Privacy #Issues #America

53 Times Flock Safety Hardcoded the Password for America's Surveillance Infrastructure

A responsible disclosure documenting an organization-wide ArcGIS API key exposed across 53 public-facing assets, granting access to the mapping infrastructure underlying approximately 12,000 law enforcement, community, and private sector deployments.
  • Copy link
  • Flag this post
  • Block
Hacker News
Hacker News
@h4ckernews@mastodon.social  ·  activity timestamp 2 months ago

MongoBleed

https://github.com/joe-desimone/mongobleed/blob/main/mongobleed.py

#HackerNews #MongoBleed #cybersecurity #vulnerabilities #data #breach #hacking #security

GitHub

mongobleed/mongobleed.py at main · joe-desimone/mongobleed

Contribute to joe-desimone/mongobleed development by creating an account on GitHub.
  • Copy link
  • Flag this post
  • Block
Hacker News
Hacker News
@h4ckernews@mastodon.social  ·  activity timestamp 2 months ago

SoundCloud confirms breach after member data stolen, VPN access disrupted

https://www.bleepingcomputer.com/news/security/soundcloud-confirms-breach-after-member-data-stolen-vpn-access-disrupted/

#HackerNews #SoundCloud #Breach #DataSecurity #Cybersecurity #VPNHacked #MemberData

  • Copy link
  • Flag this post
  • Block
Hacker News
Hacker News
@h4ckernews@mastodon.social  ·  activity timestamp 2 months ago

Mixpanel Security Breach

https://mixpanel.com/blog/sms-security-incident/

#HackerNews #Mixpanel #Security #Breach #DataPrivacy #CyberSecurity #IncidentAlert #BreachResponse

Mixpanel

  • Copy link
  • Flag this post
  • Block
Alex Akselrod boosted
AI6YR Ben
AI6YR Ben
@ai6yr@m.ai6yr.org  ·  activity timestamp 3 months ago

Major breach of an emergency notification provider (CodeRed/Onsolve), which is a very bad thing.

“Dear Valued Customer,

Further to our previous communications, we’d like to provide you with an update regarding the cybersecurity incident which damaged the OnSolve CodeRED environment in a targeted attack by an organized cybercriminal group. Our forensic analysis continues to indicate that this is an incident strictly contained within the OnSolve CodeRED environment with no contagion beyond.

We have learned that data associated with the legacy OnSolve CodeRED platform was removed from our systems. While there is currently no indication that this data has been published online, we are proactively informing you that it may be leaked.

It appears that the impacted dataset may contain contact information of OnSolve CodeRED users: name, address, email address, phone numbers, and/or associated passwords used to create user profiles for alerts. If the same password is used by users for any other personal or business accounts, those passwords should be changed immediately.”

https://dcsheriff.net/important-nationwide-codered-outage-data-breach-update/

#cybersecurity #breach #codered #onsolve

  • Copy link
  • Flag this post
  • Block
AI6YR Ben
AI6YR Ben
@ai6yr@m.ai6yr.org  ·  activity timestamp 3 months ago

Major breach of an emergency notification provider (CodeRed/Onsolve), which is a very bad thing.

“Dear Valued Customer,

Further to our previous communications, we’d like to provide you with an update regarding the cybersecurity incident which damaged the OnSolve CodeRED environment in a targeted attack by an organized cybercriminal group. Our forensic analysis continues to indicate that this is an incident strictly contained within the OnSolve CodeRED environment with no contagion beyond.

We have learned that data associated with the legacy OnSolve CodeRED platform was removed from our systems. While there is currently no indication that this data has been published online, we are proactively informing you that it may be leaked.

It appears that the impacted dataset may contain contact information of OnSolve CodeRED users: name, address, email address, phone numbers, and/or associated passwords used to create user profiles for alerts. If the same password is used by users for any other personal or business accounts, those passwords should be changed immediately.”

https://dcsheriff.net/important-nationwide-codered-outage-data-breach-update/

#cybersecurity #breach #codered #onsolve

  • Copy link
  • Flag this post
  • Block
Em :official_verified: boosted
Jonathan Kamens 86 47
Jonathan Kamens 86 47
@jik@federate.social  ·  activity timestamp 3 months ago

They say "no sensitive information" was compromised, after a data breach involving real names, email addresses, phone numbers, and physical addresses.
That's some serious bullshit right there.
That is, in fact, "sensitive information," you idiots.
#infosec #privacy #DoorDash #breach
DoorDash confirms data breach impacting users’ phone numbers and physical addresses | TechCrunch
https://techcrunch.com/2025/11/17/doordash-confirms-data-breach-impacting-users-phone-numbers-and-physical-addresses/

  • Copy link
  • Flag this post
  • Block
Jonathan Kamens 86 47
Jonathan Kamens 86 47
@jik@federate.social  ·  activity timestamp 3 months ago

They say "no sensitive information" was compromised, after a data breach involving real names, email addresses, phone numbers, and physical addresses.
That's some serious bullshit right there.
That is, in fact, "sensitive information," you idiots.
#infosec #privacy #DoorDash #breach
DoorDash confirms data breach impacting users’ phone numbers and physical addresses | TechCrunch
https://techcrunch.com/2025/11/17/doordash-confirms-data-breach-impacting-users-phone-numbers-and-physical-addresses/

  • Copy link
  • Flag this post
  • Block
Hacker News
Hacker News
@h4ckernews@mastodon.social  ·  activity timestamp 3 months ago

I have recordings proving Coinbase knew about breach months before disclosure

https://jonathanclark.com/posts/coinbase-breach-timeline.html

#HackerNews #Coinbase #Breach #Disclosure #Breach #Timeline #Security #Concerns #Cryptocurrency

  • Copy link
  • Flag this post
  • Block
AI6YR Ben
AI6YR Ben
@ai6yr@m.ai6yr.org  ·  activity timestamp 3 months ago

Oops

BleepingComputer: Hyundai AutoEver America data breach exposes SSNs, drivers licenses

"...Its role is to supply IT solutions and services tailored to the automotive industry, particularly for Hyundai and Kia affiliates, including vehicle telematics, OTA (over-the-air) updates, maps, vehicle connectivity, embedded systems, and autonomous driving systems...."

https://www.bleepingcomputer.com/news/security/hyundai-autoever-america-data-breach-exposes-ssns-drivers-licenses/

#privacy #breach #cybersecurity #hyundai

  • Copy link
  • Flag this post
  • Block
Jonathan Kamens 86 47
Jonathan Kamens 86 47
@jik@federate.social  ·  activity timestamp 3 months ago

Looks like somebody broke into #atari's #Sendgrid account and used it to send a bunch of phishing emails.
No explanation given for how; perhaps @zackwhittaker can wheedle it out of them.
Since it says here that they've "secured" the account, my guess is a bad password (or infostealer) + no #2FA. The most obvious explanation is usually the correct one.
Though I suppose a cracked Lastpass vault is also a possibility.
#infosec #breach

Email screenshot. From "Atari - Update <update@atari.com>". Subject "Official notice from Atari – Ignore recent phishing emails pretending to be us".  Atari logo. Text:

 Earlier this week, an unauthorized party gained limited, temporary access to our third-party email service provider and used it to send phishing emails. These emails were not sent by anyone from Atari.

We have already identified and resolved the issue, secured the account, and while our investigation is ongoing, upon initial review it appears that no personal information, customer data, or internal systems were accessed or compromised.

If you received a suspicious or unexpected email from Atari between October 21 and October 30, please delete or ignore it. We sincerely apologize for any confusion or inconvenience this may have caused.

Protecting our community’s trust and security is extremely important to us, and we are taking additional steps to further safeguard our systems going forward.

If you have any questions or concerns, please feel free to reach out to us at https://atari.com/pages/contact.
Email screenshot. From "Atari - Update <update@atari.com>". Subject "Official notice from Atari – Ignore recent phishing emails pretending to be us". Atari logo. Text: Earlier this week, an unauthorized party gained limited, temporary access to our third-party email service provider and used it to send phishing emails. These emails were not sent by anyone from Atari. We have already identified and resolved the issue, secured the account, and while our investigation is ongoing, upon initial review it appears that no personal information, customer data, or internal systems were accessed or compromised. If you received a suspicious or unexpected email from Atari between October 21 and October 30, please delete or ignore it. We sincerely apologize for any confusion or inconvenience this may have caused. Protecting our community’s trust and security is extremely important to us, and we are taking additional steps to further safeguard our systems going forward. If you have any questions or concerns, please feel free to reach out to us at https://atari.com/pages/contact.
Email screenshot. From "Atari - Update <update@atari.com>". Subject "Official notice from Atari – Ignore recent phishing emails pretending to be us". Atari logo. Text: Earlier this week, an unauthorized party gained limited, temporary access to our third-party email service provider and used it to send phishing emails. These emails were not sent by anyone from Atari. We have already identified and resolved the issue, secured the account, and while our investigation is ongoing, upon initial review it appears that no personal information, customer data, or internal systems were accessed or compromised. If you received a suspicious or unexpected email from Atari between October 21 and October 30, please delete or ignore it. We sincerely apologize for any confusion or inconvenience this may have caused. Protecting our community’s trust and security is extremely important to us, and we are taking additional steps to further safeguard our systems going forward. If you have any questions or concerns, please feel free to reach out to us at https://atari.com/pages/contact.
  • Copy link
  • Flag this post
  • Block
Stefano Marinelli boosted
Pete Orrall
Pete Orrall
@peteorrall@mastodon.bsd.cafe  ·  activity timestamp 4 months ago

Wow, the damage from that Red Hat GitLab breach seems to be getting worse by the day. Jeez.

The Crimson Collective, the cybercriminal gang claiming responsibility for breaching the repo and stealing over 500GB of data, now seems to be collaborating with other cybercriminal gangs to extort Red Hat.

From the article, the cybercrim alliance:

"threatens to publish a "multi terabyte of data haul of your most sensitive intellectual property" and accuses Red Hat of failing to safeguard what it claims are trade secrets and personal data, invoking GDPR and US state privacy laws. It also reckons Red Hat's doors were kicked in on September 13 – weeks before the company came clean about the break-in."

https://www.theregister.com/2025/10/07/red_hat_breach_new_claims/?td=rt-9bp

#redhat #gitlab #news #technews #cyberattack #breach #cybersecurity #security #cybercrime #crime #extortion

  • Copy link
  • Flag this post
  • Block
Pete Orrall
Pete Orrall
@peteorrall@mastodon.bsd.cafe  ·  activity timestamp 4 months ago

Wow, the damage from that Red Hat GitLab breach seems to be getting worse by the day. Jeez.

The Crimson Collective, the cybercriminal gang claiming responsibility for breaching the repo and stealing over 500GB of data, now seems to be collaborating with other cybercriminal gangs to extort Red Hat.

From the article, the cybercrim alliance:

"threatens to publish a "multi terabyte of data haul of your most sensitive intellectual property" and accuses Red Hat of failing to safeguard what it claims are trade secrets and personal data, invoking GDPR and US state privacy laws. It also reckons Red Hat's doors were kicked in on September 13 – weeks before the company came clean about the break-in."

https://www.theregister.com/2025/10/07/red_hat_breach_new_claims/?td=rt-9bp

#redhat #gitlab #news #technews #cyberattack #breach #cybersecurity #security #cybercrime #crime #extortion

  • Copy link
  • Flag this post
  • Block
Thib
Thib
@thibaultamartin@mamot.fr  ·  activity timestamp 4 months ago

Missed opportunity to use surprised_pikachu.jpg as a link preview image here

https://www.theverge.com/news/792032/discord-customer-service-data-breach-hack

#discord #breach #security

The Verge

Discord customer service data breach leaks user info and scanned photo IDs

An “unauthorized party” may have accessed the names of users, the last four digits of credit card numbers, and more.
  • Copy link
  • Flag this post
  • Block

bonfire.cafe

A space for Bonfire maintainers and contributors to communicate

bonfire.cafe: About · Code of conduct · Privacy · Users · Instances
Bonfire social · 1.0.2-alpha.22 no JS en
Automatic federation enabled
Log in
  • Explore
  • About
  • Members
  • Code of Conduct