Skip to main content

Data Breaches

Developer workstation with VS Code on laptop and monitor, subtle security threat hinted in background.

GitHub Breach Exposes 3800 Repositories via Poisoned VS Code Extension

A malicious Visual Studio Code extension, Nx Console, was briefly listed on official registries and used to breach GitHub, exposing approximately 3,800 internal repositories to unauthorized access. The popular extension, with 2.2 million installs, was compromised for just 18 minutes, but long enough to cause significant damage.

Analyst 207
Rows of computer servers in a brightly-lit data storage room with a blurred password screen on a monitor.

Attackers Expose Plaintext Passwords of 46k Myspace Users

A shocking data breach has exposed the plaintext passwords of 46,000 Myspace users, putting their online security at risk. This alarming leak, linked to a 2021 security incident, also reveals email addresses and other sensitive credentials.

Analyst 207
Developer workstation with laptop, coding tools, and scattered papers.

GitHub Breach Exposes 3,800 Repositories via Malicious VS Code Extension

GitHub's security chief confirms that customer data remains safe, with no evidence of impact outside of GitHub's internal repositories. The breach originated from a poisoned VS Code extension installed on a compromised employee device, allowing attackers to steal credentials.

Analyst 207
Developer workstation with laptop and monitor showing Visual Studio Code interface with a blurred section, set against a…

GitHub Discloses Breach from Poisoned VS Code Extension

GitHub swiftly detected and contained a security breach that originated from a tainted Visual Studio Code extension, taking immediate action to remove the malicious version and isolate the affected endpoint. The breach appears to be limited to GitHub's internal repositories, with the company rotating critical secrets and conducting a thorough investigation.

Analyst 207
Computer screen displays GitHub repository on a clutter-free desk with scattered papers.

CISA Exposes Sensitive Data in Unsecured GitHub Repository

A shocking security lapse was uncovered when a GitGuardian researcher stumbled upon a public GitHub repository containing 844 MB of sensitive production infrastructure material from a national agency, left exposed for a staggering six months. This alarming data leak highlights the gravity of unsecured data, with expert Guillaume Valadon describing it as one of the most serious secrets leaks he's ever seen.

Analyst 207
A small medical clinic's waiting room with a reception desk and chairs, bathed in soft daylight.

Smaller Healthcare Providers Targeted in Rising Wave of Cyberattacks

Smaller healthcare providers are being hit hard by a rising wave of cyberattacks, with eight recent hacking incidents affecting nearly 2 million individuals. These breaches, impacting medical practices across the US, are a stark reminder that no healthcare organization is immune to the threat of cyber breaches.

Analyst 207
Disarrayed developer workstation with scattered coding tools and crossed-out code.

GitHub Breach Exposes 3,800 Internal Repositories

GitHub has confirmed a significant breach, revealing that hackers made off with approximately 3,800 internal repositories after a developer fell victim to a poisoned VS Code script. Fortunately, the company assures that customer data appears to be safe, and the incident seems to be contained within GitHub's internal systems.

Analyst 207
Brightly-lit tech workspace with rows of workstations and a few developers in the background.

GitHub Breach Exposes Internal Repositories

GitHub has confirmed a cyber incident that exposed its internal repositories, sparking concerns about the security of code and sensitive data. The breach raises questions about the potential impact on users and the measures being taken to prevent future incidents.

Analyst 207
Cluttered developer workstation with laptop and monitor in bright office setting.

GitHub Hit by Internal Repo Breach via Malicious VS Code Extension

GitHub's internal repositories were breached after a malicious Visual Studio Code extension was used to launch the attack, but thankfully, customer data appears to be safe. The incident has left users wondering what else may have been compromised.

Analyst 207
Developer workstation with laptop, monitor, and office supplies in a neutral background.

GitHub Breach Exposes 3800 Internal Repositories to Malicious VS Code Extension

GitHub's security team swiftly contained a breach that exposed 3,800 internal repositories to a malicious VS Code extension, and immediately took action to prevent further damage. The company has completed critical secret rotations and is now meticulously analyzing logs to ensure the incident is fully resolved.

Analyst 207
Laptop screen displays GitHub repository page on a clean workspace surface.

Grafana GitHub Breach Exposes Source Code in TanStack npm Attack

Grafana Labs recently reported a security breach that exposed source code and internal data, but fortunately, there's no evidence that customer production systems were compromised. The breach, detected on May 11, was confined to the company's GitHub environment and involved both public and private source code and internal repositories.

Analyst 207
Blurred office scene with employees working, a faintly glowing laptop in the foreground.

GitHub Probes Internal Breach Claimed by TeamPCP Hackers

GitHub is investigating a possible internal breach after a hacking group claimed unauthorized access to its repositories. The company says it has no evidence that customer data has been compromised so far.

Analyst 207
Brightly-lit tech office interior with employees at desks and a large window in the background.

GitHub Probes Breach Claim by TeamPCP Hackers

GitHub is investigating a security breach claim by hackers TeamPCP, who allegedly stole around 4,000 of the platform's internal repositories and put the source code up for sale for a hefty $50,000. The company has already sprung into action, detecting and containing the breach and taking steps to mitigate the risk.

Analyst 207
Disorganized cables and patch cords in a network operations room with rows of computer servers and monitoring screens.

Exploits Emerge as Top Breach Entry Point

With attackers exploiting vulnerabilities at an alarming rate, it's clear that organizations are struggling to keep up with the pace of security defects - and it's leaving them exposed. Exploits have now become the top breach entry point, accounting for 31% of all known initial access vectors.

Analyst 207
Blurred code on a laptop screen in a brightly-lit workspace with a coding environment in the background.

CISA Credentials Exposed in GitHub Leak

A security researcher has uncovered a public GitHub repository exposing sensitive credentials tied to the Cybersecurity and Infrastructure Security Agency, sparking fears that malicious actors could exploit the data for nefarious purposes. The leak, linked to a contractor-maintained repository called "Private-CISA," reportedly included privileged AWS GovCloud accounts and internal CISA systems.

Analyst 207
Hospital corridor with patients and staff, laptop screen in foreground, conveying concern.

NYC Health Breach Exposes 1.8M Patients' Sensitive Data

A massive data breach at NYC Health + Hospitals has exposed the sensitive information of 1.8 million patients, highlighting the alarming vulnerability of personal data in the healthcare system. This incident serves as a stark reminder of the devastating consequences of a breach, especially when it comes to biometric data that can never be truly reset.

Analyst 207
7-Eleven store interior with customers shopping and a franchisee near a filing cabinet.

7-Eleven Breach Exposes Franchisee Data to Cyber Risk

A recent 7-Eleven data breach has put franchisee information at risk, with sensitive documents accessed by an unauthorized party, potentially exposing names, addresses, and other personal data. Fortunately, customers who used their credit cards to make purchases can breathe a sigh of relief, as their payment info appears to be safe.

Analyst 207
Laptop screen displays GitHub repository in a bright, minimalist workspace.

CISA Exposes Security Lapse with Open GitHub Repository

The US's leading cyber-defense agency, CISA, made a shocking security blunder by leaving a GitHub repository open, exposing sensitive passwords, keys, and tokens with alarmingly obvious filenames. This careless mistake raises serious concerns about the agency's ability to protect itself and the nation from cyber threats.

Analyst 207
Concerned 7-Eleven employee or franchisee looks at document near blurred POS terminal.

7-Eleven Breach Exposes Franchisee Data After ShinyHunters Attack

7-Eleven recently confirmed a data breach that exposed sensitive franchisee information after a cyberattack by the group ShinyHunters, with unauthorized access detected on April 8. The company swiftly launched an investigation and began notifying affected individuals on May 1.

Analyst 207
Technicians work in a network operations center with a prominent server in the foreground.

Vulnerability Exploitation Surges in Data Breaches

Vulnerability exploitation is now the top attack vector, responsible for a staggering one-third of all data breaches. This alarming trend highlights the urgent need for robust patch management and cybersecurity measures to stay ahead of threats.

Analyst 207
Laptop screen displays blurred code in a coding environment on a plain surface with papers and a notebook nearby.

Grafana Labs Discloses Source Code Theft by Hackers

Hackers recently breached Grafana Labs' security, gaining unauthorized access to a GitHub token that allowed them to download the company's source code, and subsequently attempting to extort payment to keep it under wraps. The incident was swiftly investigated, and the compromised token was promptly invalidated.

Analyst 207
Empty computer workstation with laptop and papers in a neutral office setting, hint of coding workspace in background.

CISA Contractor Exposes AWS GovCloud Keys in GitHub Leak

A contractor for the Cybersecurity & Infrastructure Security Agency (CISA) made a critical mistake by exposing sensitive AWS GovCloud keys, plaintext passwords, and internal files in a public GitHub repository. The leak, described as one of the worst ever witnessed, included highly privileged credentials and build artifacts for numerous internal CISA systems.

Analyst 207
Brightly-lit computer lab with laptops and computers, hinting at disruption.

SaaS Breaches Expose Gaps in Enterprise Security Thinking

In a shocking display of vulnerability, ShinyHunters breached Instructure's Canvas platform not once, but twice in a single week, siphoning off a staggering 3.65 terabytes of data from 275 million users across 8,000 institutions. The brazen attacks left hundreds of schools reeling during final exams, forcing Canvas offline and lining the attackers' pockets with a ransom payment.

Analyst 207
Developer workstation with laptop, notebook, and coffee cup in a brightly-lit setting.

Grafana Breach Exposes Source Code via Stolen GitHub Token

Grafana Labs revealed that hackers breached its GitHub environment using a stolen access token, downloading the company's source code, but fortunately, took swift action to invalidate the token and beef up security measures. The incident is currently under investigation, with more details to be shared once complete.

Analyst 207