
Rapid7 deployed right the first time.
Full-platform Rapid7 rollouts - InsightVM, InsightIDR, event sources, agents, tuning - by a Registered Partner who has done it at state-agency scale, including OT/SCADA.
Talk deployment
A recent cyberattack on CEVA Logistics, a shipping partner for Steam hardware in Europe, exposed sensitive customer data, including names, addresses, phone numbers, emails, and order details, between July 29 and August 1, 2026. Valve has notified affected customers about the breach, which may have compromised their personal information.

A zero-day exploit in analytics provider Metabase has led to a data breach at laptop maker Framework, exposing personal customer information, and prompting a review of its data storage methods with external vendors. Metabase has since patched the bug, blocked attack endpoints, and deployed a fix across its cloud service to prevent further exploitation.

Metabase Cloud was recently hit by a data-theft attack, exploiting a previously unknown security vulnerability in versions 1.58 and above, which the company has since patched and confirmed had a maximum severity rating. If you're a self-hosted customer, you'll need to update manually to protect yourself.

A shocking data breach at Unlimited Technology Systems has put the personal information of 3.8 million people at risk, after a server hack exposed sensitive data for a five-day window in October 2025. The breach was only detected on October 19, 2025, and it took until July 2026 for the company to notify authorities and affected individuals.

A cyberattack brought North Carolina's ports to a grinding halt, forcing delays and manual processing at the Port of Wilmington, the Port of Morehead City, and the Charlotte Inland Port. The U.S. Coast Guard is now monitoring the situation and coordinating a response with partner agencies to get operations back on track.

Levi Strauss & Co. recently suffered a cybersecurity breach, but fortunately, it was quickly contained and terminated, protecting consumer data from exposure. The incident did, however, involve the unauthorized access and exfiltration of certain corporate information.

NHS Tayside is launching an investigation into a disturbing data breach at Ninewells Hospital, where a nine-year-old girl's medical records were allegedly accessed without authorization by staff. The incident has triggered a probe into how sensitive patient information was compromised.

A cyberattack has brought North Carolina's ports to a grinding halt, causing a systems-wide outage that has delayed operations and truckers at the Port of Wilmington, the Port of Morehead City, and the Charlotte Inland Port. Gates at all three locations are now back to a normal operating schedule, but the impact of the disruption is still being felt.

Full-platform Rapid7 rollouts - InsightVM, InsightIDR, event sources, agents, tuning - by a Registered Partner who has done it at state-agency scale, including OT/SCADA.
Talk deploymentA cyber incident at CRM provider Beacon has potentially exposed the sensitive data of 1,500 UK charities, prompting swift notification and containment efforts by the company. Beacon is now working closely with its customers to help them communicate with those potentially affected.

A phishing scam led to a breach of a US defense supplier's Microsoft 365 account, exposing sensitive data including customer communications, engineering docs, and potentially export-controlled tech info. The intruder gained access to mailbox contents, but the company found no evidence that the data was copied or exfiltrated.

A 26-year-old Canadian hacker has pleaded guilty to masterminding a massive Snowflake extortion scheme that compromised over 100 million AT&T customers' sensitive call and text history records. Connor Riley Moucka faces up to 30 years in prison for his role in the cross-border hacking and extortion operation.

The Swiss government's Microsoft SharePoint system was breached, compromising the login credentials of around 200 accounts, after security specialists detected unusual activity on July 28. The breach was quickly contained and remediated, with external internet access to the SharePoint environment blocked and patches applied.

In a major win for justice, Connor Moucka, a Canadian national, has pleaded guilty to masterminding a massive data extortion scheme targeting Snowflake customer environments, a case that could put him behind bars for up to 32 years. The guilty plea marks a significant milestone in one of the most expansive data-theft-and-extortion campaigns of 2024.

A massive data breach at Snowflake has left a staggering 100 million people vulnerable, after hackers exploited stolen credentials to access sensitive records at over 165 organizations. The mastermind behind the breach, Connor Riley Moucka, has pleaded guilty to multiple charges, including computer fraud and identity theft.

A Canadian hacker has pleaded guilty to stealing sensitive data and extorting victims, including one instance where he re-extorted a victim by threatening to disclose their stolen information. The 26-year-old faces up to 32 years in prison when sentenced on October 27.

When victims share their most sensitive information with the police, they trust that it will be kept safe - but in two shocking data breaches, the Metropolitan Police Service let that trust down, putting a stalking victim's new address and number at risk. The incidents have sparked a stern warning from regulators about the force's handling of sensitive information.

No IT department, no security budget, real exposure. Nubivance builds right-sized security foundations for small companies. Send them this.
Send it along
Thousands of n8n instances are at risk after GitGuardian researchers discovered 321 live instances accepting leaked API tokens, allowing attackers to steal raw credentials without exploiting software vulnerabilities. A staggering 4,576 credentials tied to 1,255 hostnames were compromised, putting countless users at risk of data breaches.
A cyberattack on Beacon CRM has compromised the data of a UK charity, with the company confirming that an unauthorized third-party likely downloaded copies of its database backups. If you're a Beacon CRM user, it's best to assume that all your stored data, including files, may have been accessed.

Lawmakers are pushing for a bill that would provide lifetime identity protection for the 4.2 million federal employees and contractors affected by the 2015 Office of Personnel Management breach, giving them the peace of mind they deserve. The proposed RECOVER PII Act aims to make the currently expiring protection program permanent, ensuring victims are safeguarded against ID theft for life.

With the federal government's identity protection services set to expire on September 30, 22.1 million breach victims from the 2015 China-linked breaches face a looming gap in lifetime protection. Will they be left vulnerable after a decade of coverage?

A sensitive police database has been breached, putting the personal details of police officers, staff, and justice professionals at risk after being published on the dark web. The breach, detected on July 26, exposed names, work email addresses, and organizations, but thankfully, no passwords or security credentials were compromised.

A massive data breach has hit the UK police force, with a hacking group claiming to have stolen sensitive information from over 100,000 officers, including names, organizations, and email addresses. The breach, attributed to ExfilSquad, has left thousands of police personnel and government partners vulnerable to potential identity theft and harassment.

A recent PNLD data breach has exposed sensitive contact information of U.K. police, government officials, and customers on the dark web, including names, work email addresses, and organisation details. The breach could make it easier for scammers to craft convincing phishing messages targeting law enforcement officers.

A shocking security lapse at KT has left 16,647 users vulnerable to unauthorized micropayments totaling $175,000, after a hacker exploited a lost femtocell to breach the company's mobile network. This costly breach has resulted in stolen identities and a hefty penalty for South Korea's largest telecommunications company.