They Never Became Customers. Their Identity Data Was Still in the Breach.

A Heights Finance cloud-platform breach reached borrowers, applicants and people who only enquired. Data retention turned a past interaction into a present risk.

A Heights Finance cloud-platform breach reached borrowers, applicants and people who only enquired. Data retention turned a past interaction into a present risk.

A flaw in BounceBit Chain's inherited Evmos authorisation logic let an attacker move 286.5 million BB. The response will permanently retire the Layer 1 and reissue BB on BNB Chain.

The malicious crates and the new video-call campaign are separate incidents. They meet at the same target: the people and credentials trusted to publish Rust packages.

A critical SharePoint deserialization flaw is under active exploitation. Applying the security update closes the entry point, but stolen machine keys can preserve attacker access unless recovery goes further.

CISA has added actively exploited Zimbra CVE-2026-73570 to its KEV catalogue with a 24 August deadline. Patch to 10.1.20, then check for prior compromise.

France’s Education Ministry is testing whether a breach first described as staff-only reached student records across a fragmented national data estate.

UT San Antonio says an intrusion attempt was stopped before core systems, yet precautionary shutdowns disrupted services and delayed fall classes.

Cisco says attackers are exploiting a denial-of-service flaw in ASA and Secure Firewall Threat Defense. The lesson is not only to patch the VPN edge, but to design for the moment the security device itself becomes unavailable.

Sakura Internet's investigation expanded from 583 rented-server accounts to a separate sales system holding 1.36 million customer accounts. Access was possible, but data exfiltration was not confirmed.

ExfilSquad’s leaked data points to exposed Dataverse records, not a confirmed Dynamics exploit. Anonymous low-code permissions can be the entire breach path.