Publishing platform Substack has disclosed a data breach that leaked nearly 700,000 user records after an unauthorized third-party exploited a security flaw.
A massive data leak has exposed over 8.7 billion records of primarily Chinese people stored on an unsecured Elasticsearch cluster on bulletproof infrastructure.
Security researchers believe that Chinese hackers are to blame for the attack in part because of the "selective" nature of the targets that were chosen for follow-on compromise via malicious software updates. Notepad++ is a free and broadly popular piece of software that is thought to have tens of millions of users worldwide.
Moltbook has been the talk of social media the past week, as its AI agent user base seemingly does everything from conspire against humanity to form new religions. But, relegated to the less sensational world of security news, a data leak has already exposed masses of API authentication tokens, private messages and email addresses.
A headline-grabbing international lawsuit has cast some doubt on the security of WhatsApp chats, with claims that parent company Meta is not providing true end-to-end encryption and retains the ability to access user conversations internally.
A decade-old critical security vulnerability affects over 800,000 internet-exposed telnet servers, with reports of active exploitation and attempted malware deployment.
Law enforcement authorities have seized the notorious cybercrime forum RAMP, which advertised and facilitated the sale of various hacking services, including ransomware.
Vishing attacks targeting identity management platform Okta have compromised corporate data aggregator CrunchBase, streaming website SoundCloud, and fintech robo-advisor Betterment.
A massive credentials leak has compromised the login information of over 149 million accounts, stolen via an infostealer after a threat actor failed to secure a cloud database.
The Nov 2025 data breach at the American apparel giant Under Armour has leaked the personal information of over 72 million people following a ransomware attack.










