devtake.dev

#data-breach

RSS
An open Framework Laptop 13 in DIY configuration on a white desk, mainboard exposed, with two 32GB memory modules and an SSD beside it
Security·

Metabase's password-reset endpoint handed out admin, and Framework had to email every customer

A CVSS 10.0 SQL injection in Metabase was exploited from August 3. Framework told every customer their data was taken. Tally lost emails and password hashes.

An iPhone disassembled into its logic board, battery, and camera components, the kind of manufacturing detail the Tata Electronics leak exposed.
Security·

World Leaks stole 630GB from Tata Electronics and leaked Apple's iPhone 18 Pro files

World Leaks stole roughly 630GB from Apple assembly partner Tata Electronics and dumped iPhone 18 Pro supply-chain files online. India opened a criminal probe.

The LastPass logo, the password manager that notified customers of a data breach traced to its vendor Klue.
Security·

LastPass leaked customer data again, this time through a vendor's hijacked OAuth tokens

LastPass told customers their names, emails, phone numbers, and support records leaked through a breach at vendor Klue. Vaults stayed locked.

A 7-Eleven storefront, the retail chain whose franchisee document store was breached and leaked.
Security·

ShinyHunters dumped 9.4GB of 7-Eleven franchisee data after a rejected ransom demand

ShinyHunters breached a 7-Eleven Salesforce instance holding franchisee documents, exposing 185,000 people. The 9.4GB archive hit a leak site after 7-Eleven declined to pay.

Illustration of students affected by a cybersecurity breach
Security·

ShinyHunters hit Canvas LMS for the second time. 275 million student records, 9,000 schools.

ShinyHunters breached Canvas LMS again, claiming 275 million records from 9,000 schools. Names, emails, student IDs, and private messages exposed.

Vercel logo displayed on the company's security incident bulletin page
Security·

Vercel got breached through a third-party AI tool's OAuth app. Here's what leaked.

A Context.ai compromise let attackers take over a Vercel employee's Google Workspace. Non-sensitive env vars were exposed, and a ShinyHunters persona is asking $2M.