Click any tag below to further narrow down your results
+ email-spoofing
(1)
+ wildlife-licensing
(1)
+ code-leak
(1)
+ secret-scanning
(1)
+ hardware-exploit
(1)
+ credential-theft
(1)
+ kyushu-electric
(1)
+ customer-data
(1)
+ utilities
(1)
+ physical-security
(1)
+ security-tools
(1)
+ anthropic
(1)
+ supply-chain
(1)
+ ai-attacks
(1)
+ student-data
(1)
Links
The Texas Parks and Wildlife Department says a third-party vendor that handles hunting and fishing licenses was hacked, exposing driver’s license numbers, passport numbers and contact details for over 3 million Texans. Permanent ID data can’t be reset, putting victims at long-term risk of identity fraud. Threat intelligence links this incident to similar attacks on other state wildlife licensing platforms, highlighting vendor security gaps.
This daily roundup covers Fortinet’s FortiBleed campaign exposing 86,000 device credentials, a Texas hunting-license vendor breach affecting 3 million records, and an unpatchable BootROM exploit on Apple A12/A13 chips. It also highlights GitHub’s context-aware secret scanning, the Novo Nordisk code leak via a stolen GitHub token, and other emerging tools and vulnerabilities.
A hacking group breached the University of Nottingham’s PeopleSoft student records system and stole over 40 GB of data on 454,600 current and former students, including names, addresses, financial details and academic records. The university has reported the incident to the UK Information Commissioner’s Office and Action Fraud, while ShinyHunters claims responsibility and posted the stolen archive.
This daily roundup covers a 40 GB data breach at the University of Nottingham, a lost-drive incident exposing 10.9 million Japanese utility customers, and a proof-of-concept Exchange spoofing flaw. It also highlights automated AI-driven attack research, supply-chain toolkits on GitHub, and new product launches for dependency patching and taint analysis.
Kyushu Electric Power misplaced an external backup drive storing personal details for up to 10.9 million customers after leaving it in an unlocked server-room cabinet. The drive contained names, addresses, usage data and phone numbers but no financial records, and the firm has reported the loss to police and regulators while investigating internal access.
Security researchers found that Anthropic’s new Mythos AI model was reachable by unauthorized users through exposed API endpoints. This lapse could expose sensitive prompts and responses, prompting Anthropic to investigate and strengthen its access controls.