#DataLeaks

2025-04-30

Gizmodo: An Employee Surveillance Company Leaked Over 21 Million Screenshots Online. “With the refinement of digital tools, companies are subjecting their employees to increasing levels of surveillance — and increasing risks. Now, the security of thousands of employees and their parent companies is at risk after real-time images of their computers were leaked by an employee surveillance […]

https://rbfirehose.com/2025/04/30/gizmodo-an-employee-surveillance-company-leaked-over-21-million-screenshots-online/

2025-04-29

The Register: From 112K to 4M folks’ data – HR biz attack goes from bad to mega bad. “Houston-based VeriSource Services’ long-running probe into a February 2024 digital break-in shows the data of 4 million people – not just a few hundred thousand as it first claimed – was accessed by an ‘unknown actor’. The tech company, which provides employee benefits administration services, began […]

https://rbfirehose.com/2025/04/29/the-register-from-112k-to-4m-folks-data-hr-biz-attack-goes-from-bad-to-mega-bad/

Sam Bentdoingfedtime
2025-04-28

Don’t store passwords in browsers.
Browsers are common malware targets.

2025-04-25

Did you know❓

🏴‍☠️ On average, 1.4 billion social media accounts are compromised every month, that’s about 32 accounts every second.*

🛡️ Make sure to use strong passwords, avoid clicking suspicious links… and use Epieos to check if your passwords have been exposed in #dataleaks.

*Study conducted by Dr. Michelle Moore, Director of the Graduate Cyber Security Operations & Leadership program and Professor of Practice at the University of San Diego.

2025-04-25

The HIPAA Journal: Blue Shield of California Announces Impermissible Disclosure of PHI to Google Ads: 4.7 Million Affected. “On April 9, 2025, the health insurance plan provider Blue Shield of California disclosed a web tracking-related privacy breach involving user data being shared with Google’s advertising product, Google Ads. The breach was recently reported to the HHS’ Office for […]

https://rbfirehose.com/2025/04/25/the-hipaa-journal-blue-shield-of-california-announces-impermissible-disclosure-of-phi-to-google-ads-4-7-million-affected/

2025-04-19

Techdirt: Whoops: T-Mobile Reveals Names, Real-Time Locations Of Customers’ Kids. “T-Mobile sells a GPS service called SyncUP that lets parents monitor the locations of their children (one of several similar apps like Life360), then turns around and monetizes these vast troves of data. Except that 404 Media was the first to report that an apparent bug with T-Mobile’s service resulted in […]

https://rbfirehose.com/2025/04/19/whoops-t-mobile-reveals-names-real-time-locations-of-customers-kids-techdirt/

2025-04-17

Sensitive Information Disclosure (SID) is a significant vulnerability where private data such as passwords, emails, internal docs, user credentials, IPs, business logic, source code, PII, payment information, or health records are unintentionally exposed. This occurs due to dev mistakes, misconfigurations, sketchy apps, or third-party integrations. Examples of real breaches include Tesla (2018), NASA (2018), Yahoo! (2014), Uber (2016), T-Mobile (2021), and Panama Papers (2016). To prevent SID, follow best practices like disabling directory listing, error silencing, secure secrets handling, API response verification, thoughtful file uploads, regular security tests, and bug bounty participation. #Cybersecurity #DataLeaks #InfoSec #BugBounty #DevOpsSecurity

medium.com/@sachinpv2004/data-

🏁 FullDRSFullDRS
2025-04-17

After failing to properly write court documents with competitive evaluations, lawyers from Apple, Google and Snap expressed their annoyance at the lack of care with highly sensitive information.

A leak that did not go unnoticed in Silicon Valley

2025-03-30

BBC: Kink and LGBT dating apps exposed 1.5m private user images online. “Researchers have discovered nearly 1.5 million pictures from specialist dating apps – many of which are explicit – being stored online without password protection, leaving them vulnerable to hackers and extortionists. Anyone with the link was able to view the private photos from five platforms developed by M.A.D […]

https://rbfirehose.com/2025/03/30/bbc-kink-and-lgbt-dating-apps-exposed-1-5m-private-user-images-online/

BiyteLümbiytelum
2025-03-24

💀 There are entire Telegram channels dedicated to selling your leaked data.

We’re talking:
✅ Full ID bundles (name, address, SSN, license/passport)
✅ Hacked medical records
✅ Database dumps from past breaches

📌 If you’ve uploaded your ID or personal info, it could be there.
📌 Use Optery or Incogni to remove exposed data
📌 Freeze credit. Monitor accounts. Stay alert.

2025-03-23

Micah Lee: Exploring the Paramilitary Leaks. “It’s come to my attention that this dataset is rather challenging for journalists and researchers to wrap their heads around. I wrote a book, Hacks, Leaks, and Revelations, aimed at teaching journalists and researchers how to analyze datasets just like this. I’m also quite interested in what’s in here myself – this is one of the only datasets […]

https://rbfirehose.com/2025/03/23/micah-lee-exploring-the-paramilitary-leaks/

Anonymous 🐈️🐾☕🍵🏴🇵🇸 :af:youranonriots@kolektiva.social
2025-03-07

Japanese telecommunication services provider #NTT Communications Corporation (NTT) is warning almost 18,000 corporate customers that their information was compromised during a cybersecurity incident. #DataLeaks #CyberAttacks bleepingcomputer.com/news/secu

Anonymous 🐈️🐾☕🍵🏴🇵🇸 :af:youranonriots@kolektiva.social
2025-03-05

#CyberAlerts NTT Communications #Japan
#NTT Com Confirms Potential Information Leak due to Unauthorized System Access

#TOKYO, JAPAN, March 5, 2025 — NTT Communications Corporation (NTT Com), announced today that on February 5th, it determined that unauthorized access to its systems had occurred. On the following day, the company established that certain information may have been leaked.
#DataLeaks #CyberAttacks
#Internet ntt.com/en/about-us/press-rele

RainSMediaRadiorainsmediaradio
2025-03-02

ICYMI: RainSMediaRadio NewsMeta Fires 20 Employees Over Alleged Data Leaks and Confidentiality Breaches rainsmediaradio.com/2025/03/me Follow, Like & Share

2025-02-25

HIPAA Journal: Clinical Trials Database Containing 1.6 Million Records Exposed Online. “A database containing approximately 1.6 million clinical trial records has been exposed over the Internet and could be accessed without a password. The 2 TB database was found by cybersecurity researcher Jeremiah Fowler, who reports that the database contains 1,674,218 records, including PDF survey results […]

https://rbfirehose.com/2025/02/25/hipaa-journal-clinical-trials-database-containing-1-6-million-records-exposed-online/

2025-02-24

Tom’s Hardware: Security researcher finds vulnerability in internet-connected bed, could allow access to all devices on network. “Dylan Ayrey has released an extended blog with the help of Jake King highlighting the security flaws of the Eight Sleep and the steps he ended up taking to make them no longer an issue, particularly in the face of features that wounded up locked behind a […]

https://rbfirehose.com/2025/02/24/toms-hardware-security-researcher-finds-vulnerability-in-internet-connected-bed-could-allow-access-to-all-devices-on-network/

Miguel Afonso Caetanoremixtures@tldr.nettime.org
2025-02-12

"Hackers leaked thousands of files from Lexipol, a Texas-based company that develops policy manuals, training bulletins, and consulting services for first responders.

The manuals, which are crafted by Lexipol’s team of public sector attorneys, practitioners, and subject-matter experts, are customized to align with the specific needs and local legal requirements of agencies across the country.

But the firm also faces criticism for its blanket approach to police policies and pushback on reforms.

The data, a sample of which was given to the Daily Dot by a group referring to itself as “the puppygirl hacker polycule,” includes approximately 8,543 files related to training, procedural, and policy manuals, as well as customer records that contain names, usernames, agency names, hashed passwords, physical addresses, email addresses, and phone numbers.

Among the manuals seen by the Daily Dot, agencies include police departments, fire departments, sheriff’s offices, and narcotics units."

dailydot.com/debug/lexipol-dat

#USA #Hacking #Lexipol #DataLeaks #PoliceState

Anonymous 🐈️🐾☕🍵🏴🇵🇸 :af:youranonriots@kolektiva.social
2025-02-08

Hewlett Packard Enterprise (HPE) is notifying employees whose data was stolen from the company's Office 365 email environment by Russian state-sponsored hackers in a May 2023 cyberattack. #OpIsrael #DataLeaks
bleepingcomputer.com/news/secu

2025-01-31

The Register: Guess who left a database wide open, exposing chat logs, API keys, and more? Yup, DeepSeek . “Wiz, a New York-based infosec house, says that shortly after the DeepSeek R1 model gained widespread attention, it began investigating the machine-learning outfit’s security posture. What Wiz found is that DeepSeek – which not only develops and distributes trained openly available […]

https://rbfirehose.com/2025/01/31/the-register-guess-who-left-a-database-wide-open-exposing-chat-logs-api-keys-and-more-yup-deepseek/

Client Info

Server: https://mastodon.social
Version: 2025.04
Repository: https://github.com/cyevgeniy/lmst