They Did Not Steal Passwords. They Stole the Map of Who to Attack Next.

Alleged Entra directory theft exposed organisational maps rather than passwords. Treat bulk directory reads as a high-impact identity event.

Alleged Entra directory theft exposed organisational maps rather than passwords. Treat bulk directory reads as a high-impact identity event.

SafePal says private keys and funds were not exposed, but order records linked wallet ownership to names, contact details and home addresses.

A Heights Finance cloud-platform breach reached borrowers, applicants and people who only enquired. Data retention turned a past interaction into a present risk.

A critical SharePoint deserialization flaw is under active exploitation. Applying the security update closes the entry point, but stolen machine keys can preserve attacker access unless recovery goes further.

The EU e-Evidence Regulation makes cross-border data orders an eight-hour operational challenge for service providers, not merely a legal process.

France’s Education Ministry is testing whether a breach first described as staff-only reached student records across a fragmented national data estate.

UT San Antonio says an intrusion attempt was stopped before core systems, yet precautionary shutdowns disrupted services and delayed fall classes.
Meta Pixel and Yandex Metrica used Android localhost connections to link browser activity with native-app identities, bypassing familiar privacy controls.

US prosecutors allege Mabna Institute hackers served Iranian state clients while selling stolen research and university access through commercial sites.

Cisco says attackers are exploiting a denial-of-service flaw in ASA and Secure Firewall Threat Defense. The lesson is not only to patch the VPN edge, but to design for the moment the security device itself becomes unavailable.