Fanlore wiki breach exposes 144,520 accounts with email and password hashes
OTW disclosed unauthorized access to its Fanlore wiki, exposing ~145k emails, usernames, and MD5/PBKDF2 password hashes.
A running digest of identity-related exploit and breach news — new zero-days, exposed credential dumps, and directory-security advisories — each summarized in our own words with a link to the primary source.
OTW disclosed unauthorized access to its Fanlore wiki, exposing ~145k emails, usernames, and MD5/PBKDF2 password hashes.
Australian retailer Oz Hair and Beauty had nearly 2M customer records leaked after an xpl0itrs extortion attack in August 2026.
CISA added four exploited vulnerabilities to its KEV Catalog, including a SharePoint weak authentication bug and a macOS improper authentication flaw.
CISA advisory flags multiple auth-related flaws in ANDRITZ HIPASE-250/250 SCALA energy devices, including reversible password storage and hard-coded credentials.
A shared hard-coded credential in the FL-100 brain stimulation device lets nearby attackers bypass authentication and alter stimulation parameters.
CISA advisory warns Airwall <=4.0.4 contains a hardcoded cryptographic key and path traversal flaw enabling authentication bypass and data decryption.
Two vulnerabilities in Siemens License Server allow local privilege escalation and arbitrary file reads, with one leading to full root compromise.
Hardcoded AES key and unsalted hashing in Siemens LOGO! Soft Comfort let local attackers decrypt project data and crack passwords.
ShinyHunters leaked data on ~1.6M RingCentral users including emails, names, addresses and phone numbers after a July 2026 extortion attempt.
CISA advisory details multiple authentication and credential vulnerabilities in Mira's health monitor and app that could enable full account takeover.
CISA details Gunra ransomware-as-a-service, which abuses exposed VPN and RDP infrastructure and lateral movement to encrypt and exfiltrate data.
Eye care firm Alcon named in a ShinyHunters 'pay or leak' extortion; leaked data includes 218k emails, names, phone numbers and addresses.
ShinyHunters published data allegedly stolen from Brinks Home, exposing 732K email addresses plus personal and partial payment details of leads, customers and staff.
ShinyHunters published stolen Exact Sciences data affecting 10.9M people, including emails, contact details and health records.
CISA advisory warns Johnson Controls TL280 devices below v5.63 contain embedded credentials and a weak cryptographic algorithm exposing sensitive data.
ShinyHunters published data allegedly stolen from Inter-Con Security, exposing 276K email addresses plus names, addresses, job titles and phone numbers.
Three vulnerabilities added to CISA's KEV Catalog, including an actively exploited authentication bypass in N-able N-central RMM.
A shared, hard-coded Bluetooth authentication key in KARR BT and DR-100 anti-theft systems lets nearby attackers unlock doors and bypass immobilizers.
CVE-2026-18577, an authentication bypass in N-able N-central, is under active exploitation and added to CISA's KEV Catalog.
Russian VPN service SplitVPN (formerly NotVPN) suffered a July 2026 breach exposing 865K email addresses, IPs, and partial payment card details.
CISA warns of a missing-authentication flaw (CVE-2026-12562) giving unauthenticated attackers full root access to Toptech energy-sector devices.
CVE-2026-20316, a hard-coded password flaw in Cisco Secure FMC, is under active exploitation and added to CISA's KEV Catalog.
A ShinyHunters extortion campaign leaked 832k email addresses plus names, addresses, phone numbers, and academic records from Houston City College.
A CISA advisory flags CVE-2026-16581 in the igloohome Smart Lock Android app, where hardcoded sensitive data let attackers reach insufficiently protected backend services.
CISA warns MikroTik RouterOS and Cloud Hosted Router lack effective brute-force protections, letting attackers rapidly guess credentials for unauthorized access.
A documentation gap around the System.User entity in Siemens Mendix leads to overly permissive access rules, risking data exposure and privilege escalation.
CISA advisory flags multiple IntraVUE vulnerabilities, including plaintext password storage that leaks cleartext credentials through the API.
CISA warns that Russian state-backed actors are targeting Zimbra Collaboration Suite users via phishing and a novel zero-day to steal email data.
CISA advisory details vulnerabilities in Weintek cMT3092X HMI that let low-privileged users escalate privileges and view other users' credentials.
CISA added two actively exploited flaws to its KEV Catalog, including a Check Point SmartConsole improper authentication bug directly relevant to identity security.
CISA advisory warns a CVSS 9.8 auth bypass lets unauthenticated attackers gain admin sessions and access stored credentials on Tycon monitoring devices.
CVE-2026-10714 in FactoryTalk Services Platform allows JWT signature bypass, enabling low-privilege users to impersonate authorized accounts.
An unquoted search path vulnerability in Siemens IAM Client lets an authenticated local attacker escalate privileges across many Siemens engineering products.
A critical flaw in Siemens Opcenter X before V2604 lets unauthenticated attackers forge JWTs and impersonate any user, including admins.
A November 2025 breach at AI music tool Suno leaked over 55M unique emails, phone numbers, and tens of thousands of partial Stripe payment records.
A gig economy platform breach leaked over 23M email addresses along with bcrypt password hashes, banking data, and payout history.
CVE-2026-11889 allows an authenticated operator to bypass partition boundaries and access spaces outside their assigned tenancy in SALTO ProAccess Space <6.13.
CISA advisory covers multiple SICAM 8 vulnerabilities, including an unverified password change weakness and insecure default initialization affecting ICS devices.
CISA advisory warns of a stored XSS flaw (CVE-2026-9292) in FactoryTalk DataMosaix that can lead to credential theft and account takeover.
ShinyHunters published 100GB+ of data from test equipment maker Fluke, exposing 800k+ email addresses, names, phone numbers and addresses.
A breach of Goose Creek's Shopify instance leaked 6.6M email addresses along with names, phone numbers, addresses, and order details.
CISA flagged four actively exploited CVEs, including a Microsoft AD FS access-control flaw and SonicWall SMA1000 gateway bugs, mandating federal remediation.
Three actively exploited SharePoint Server flaws allow unauthorized access, RCE, and IIS machine key theft for persistence across all supported on-prem versions.
A missing-authentication flaw in Rockwell's 1715-AENTR adapter lets unauthenticated remote attackers run intrusive CLI commands via an exposed debug port.
Joint advisory details FSB Center 16 opportunistically compromising poorly configured networking devices, including via weak SNMP and default credentials, across critical sectors.
A ShinyHunters 'pay or leak' campaign hit Glendale Community College, leaking nearly 800k emails plus SSNs, names and enrollment data.
CISA advisory flags multiple vulnerabilities in Schneider PowerChute Serial Shutdown <=1.4 that could allow unauthorized account access and credential resets.
CVSS 9.8 access control and session flaws in Hydro-Québec's Le Circuit Electrique charging backend could enable privilege escalation and DoS.
CISA advisory warns of authentication bypass and XSS flaws in Digi International serial device servers that could expose credentials.
A cleartext HTTP transmission flaw (CVE-2026-10763) in PROMOD V could let attackers intercept credentials, hijack sessions, or gain unauthorized access.
A ShinyHunters 'pay or leak' campaign led to 2.3M email addresses and personal details of donors, students and alumni being published publicly.
Satellite terminals expose REST API endpoints without authentication, letting remote attackers pull sensitive device identity data or trigger DoS.
CISA advisory details critical Gardyn IoT Hub vulnerabilities, including a hard-coded privileged key allowing unauthenticated attackers to control managed devices.
CISA warns Delta Electronics DVP12SE PLCs allow unauthenticated Modbus TCP commands, letting remote attackers control device logic without credentials.
CVE-2026-13207 lets remote attackers bypass authentication via dot-segment path tricks to enumerate all users and role assignments in FUXA SCADA/HMI.
CISA advisory warns unauthenticated attackers can access credentials stored in firmware or system files of Schneider Electric RTUs.
CISA warns of critical StoneFly Storage Concentrator vulnerabilities, including hard-coded credentials enabling root-level unauthorized access.
CISA added a SimpleHelp authentication bypass flaw to its KEV Catalog citing active exploitation, requiring rapid federal remediation.
A ShinyHunters extortion attack on Sysco leaked 2.7M email addresses plus names, phone numbers, addresses, and internal job titles.
ShinyHunters published data on 200k+ individuals tied to American Tower after a pay-or-leak extortion attempt, exposing emails, names, addresses, and phone numbers.
CISA warns of path traversal, unrestricted file upload, and hard-coded credential flaws in Daktronics Controller Firmware enabling unauthenticated root-level takeover.
CISA advisory details missing authentication, weak session handling, and exposed credentials in EVoke CSMS, enabling unauthorized admin control of charging stations.
A SSRF flaw in OHIF DICOM Web Viewer (<=v3.12.0) can leak an authenticated clinician's OIDC Bearer token to an attacker-controlled server.
UNC6395 stole OAuth tokens tied to the Salesloft Drift integration and used them to export data — and hunt for cloud credentials — from over 700 organizations' Salesforce instances.
UNC5537 used credentials harvested by infostealer malware — some years old and never rotated — to loot 100+ Snowflake customer databases, including AT&T and Ticketmaster.
BlackCat ransomware actors logged into Change Healthcare's Citrix remote-access portal with stolen credentials and no MFA — the largest healthcare data breach in U.S. history.
A legacy, non-production tenant account with no MFA was compromised by password spray, then abused through OAuth to read senior Microsoft executives' email.
Attackers reused passwords leaked on other sites to break into ~14,000 23andMe accounts, then scraped the DNA Relatives feature to reach 6.9 million users.
Attackers accessed Okta's customer support case-management system and obtained HAR files containing session tokens, which were then used against several downstream customers.
A zero-click Outlook vulnerability (CVE-2023-23397) let attackers capture Net-NTLMv2 authentication hashes simply by sending a crafted email — exploited in the wild before patch.
CVE-2020-1472 let an unauthenticated attacker with network access to a domain controller reset its machine-account password and seize the entire Active Directory domain.