#breach — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #breach, aggregated by home.social.
-
Why are we still talking about miniorange? Just because it was handled so poorly?
-
Remember #FirstManufacturing either selling my email address or letting it be stolen and refusing to admit to either?
The evidence that this happened just got more concrete: yesterday, I received spam to that address from another merchant, _and it mentions First Manufacturing in the header_.
I've emailed the company again and await their response. I also posted a 1-⭐️ review on Google Maps.
Details here if you're curious: https://blog.kamens.us/2026/07/18/first-manufacturing-co-selling-customer-email-addresses-in-violation-of-its-own-privacy-policy/#update0822
#infosec #privacy #spam #breach -
9 million images exposed by a facial recognition platform — without authentication, apparently. The real question isn't just "how did this happen" but "why is biometric data this easy to leave open". Default-secure infrastructure for sensitive data remains an unsolved deployment problem, not just a tech one. #infosec #privacy #breach
https://www.securitymagazine.com/articles/102505-9m-images-exposed-by-facial-recognition-platform -
PC gamers and now Pokemon fans!
Official Pokemon Site Hit By Data Breach That Leaked Customer Info
https://www.polygon.com/pokemon-center-customer-data-breach-july-2026/
-
#GitHub may have a data #leak...
Yesterday I got a spam message sent to my dedicated GitHub email address. "Dedicated" means I only use it to log into GitHub. The option to "Keep my email addresses private" is active.
As far as I can tell, I'm not leaking this email address anywhere myself. A Google search turns up nothing.
Soooo, is it just me, or is there anyone else who got the impression there's something wrong?
Maybe the recent #outage is related?
-
CareCloud Breach Hits 3.7 Million, Ten Times Initial Estimate
Healthcare solutions provider CareCloud confirms its March network intrusion affected 3.7 million individuals, far more than the 350,000 first reported.
-
France's tax authority had data stolen on 680k taxpayers
https://korben.info/en/france-tax-authority-data-breach-680000-taxpayers.html
Comments: https://news.ycombinator.com/item?id=49298303
#HackerNews #France #Tax #Authority #Data #Breach #Taxpayers #Cybersecurity #Privacy
-
Over 181,000 AI meeting recordings left wide open in note taking app
https://bobdahacker.com/blog/tldv-hack
Comments: https://news.ycombinator.com/item?id=49242739
#HackerNews #AImeetings #OpenData #Security #Breach #NoteTaking
-
8 emails from Wise saying I am trying to create an account with an email address that's only used with them. Hmm... how long till they admit a breach? #breach
-
Google's top hacker hunter explains why hacking groups get codenames | TechCrunch #hacker #google #breach #hack https://techcrunch.com/2026/08/08/googles-top-hacker-hunter-explains-why-hacking-groups-get-codenames/
-
🚨 Oh look, another #data breach! This time featuring #Metabase as the unwitting sidekick in the circus act of "Oops, Your Data is Showing!" 🎪 Framework's fans are just thrilled with the speedy notification—as if that's going to stitch their #privacy back together. 🤡🔧
https://community.frame.work/t/framework-data-breach-discussion/83939 #breach #Framework #notification #cybersecurity #HackerNews #ngated -
Framework discloses data breach via Metabase 0-day
https://community.frame.work/t/framework-data-breach-discussion/83939
Comments: https://news.ycombinator.com/item?id=49206130
#HackerNews #Framework #Metabase #data #breach #cybersecurity #vulnerability #0day
-
@frameworkcomputer sent me this email (they didn't post it on blog or fediverse):
Notice of Limited Data Breach
We confirmed that the following information was accessed:
Full name
Email address
Login IPs
Billing and shipping address information
Country
Address
City
State
Zip code
Phone number
Company
For Framework for Business customers, we are investigating whether the following information may additionally have been accessed:
Company
Phone
VAT
EIN
Billing Email
No other personally identifiable information, order information, or payment information was accessed.
Dear Valued Framework Customer,
We are writing to inform you of a data breach at our business intelligence database provider Metabase that resulted in an attacker accessing customer names, email addresses, phone numbers, and addresses. Your information was in the database that was accessed in this breach. This breach did not include order or payment information.
We have full details on the incident below. We are deeply sorry for this breach of information, and are reviewing and improving our methodology for data storage in external database vendors.
We are also in the process of notifying the regulatory authorities in each region where relevant regulations exist. Note that while regulations in most regions do not require notification for breaches of names, email addresses, phone numbers, and addresses, we are sending this email to you regardless to ensure you have visibility and can take any actions needed.
What happened?
On August 6th, 2026 at 9am Pacific Time, Metabase notified us of a breach of their systems with the following email message:
On Monday, August 3, we discovered that Metabase Cloud was attacked by someone utilizing an unknown (“0-day”) security vulnerability in versions 1.58 and above. We immediately blocked the endpoints used for the attack, then quickly identified and patched the vulnerability. We notified law enforcement, and we have engaged with a third party forensics firm to conduct an independent investigation.
Your instance of Metabase was vulnerable to this 0-day. Therefore, to protect your company, we recommend you:
Rotate the credentials for every database connected to your instance; and
Review the admin accounts on your instance and remove anything you don't recognize.
We also discovered that the attacker was able to gain access to your instance. We created a report on the actions we believe the attacker took on your instance, which includes log files, and which you can get from the Metabase Store at [removed url].
(If you do not have access to the Metabase Store, are having issues accessing the report, or do not want to click on a link in an unexpected email, you can log into your instance directly and reach us at Help > Get help in the grid menu in the upper right hand corner. We'll confirm this message is from us and email you the report.)
This report is based on our own application logs. We did not query or read the data in your connected databases.
Depending on the jurisdictions in which you operate and kinds of data your instance connects to, you may have notification obligations under applicable laws. If you have concerns in this regard, we recommend you assess potential notification obligations with your company’s legal or compliance experts.
We regret any inconvenience this incident may cause you, and we are here to support you. If you have questions, please reply to this email or email us at [removed email address], and we'll get back to you as quickly as we can.
Sameer Al-Sakran Founder and CEO Metabase
We immediately investigated the logs Metabase provided to us and confirmed that our database instance was accessed by the attacker.
1/2
#framework #breach #hack #metabase -
Now I got a breach notification from Framwork, that Metabase cloud apparently was breached, some business intelligence company.
Perhaps related to Feedly?
-
Looks like #Metabase was breached via SQL injection from an unauthenticated endpoint. I was informed because #Framework emailed me saying my data was in the database that was accessed. Framework states they were notified of the #breach August 6th.
Metabase info: https://github.com/metabase/metabase/security/advisories/GHSA-vwf4-m7j8-wcjf
What was accessed according to Framework:
We immediately investigated the logs Metabase provided to us and confirmed that our database instance was accessed by the attacker. We confirmed that the following information was accessed:
Full name
Email address
Login IPs
Billing and shipping address information
Country
Address
City
State
Zip code
Phone number
CompanyFor Framework for Business customers, we are investigating whether the following information may additionally have been accessed:
Company
Phone
VAT
EIN
Billing EmailIn the notification to Framework on the 6th, Metabase stated that it was a preliminary update and they were still investigating at that time, though they say they have patched the vulnerability.
-
52% of Americans Think Their Personal Data Will Be Breached. They're Probably Right
A new survey finds most Americans believe a data breach is inevitable, reflecting growing concerns about online privacy, AI-generated misinformation, and the future of the internet.
-
#RydeTechnology has had a breach - which is responsible for the the Ryde #escooters in #Scandinavia.
https://www.ryde-technology.com/security-incident-2026-08-02
-
🚨 Breaking News: Atlassian's #AI #Rovo thinks it's a secret agent, successfully sneaking out #Jira and #Confluence #data like a #clumsy #spy in a slapstick comedy. 🤡 Turns out, it's easier to bypass their "controls" than to find the coffee machine in the office. ☕️🔍
https://www.promptarmor.com/resources/atlassian-rovo-exfiltrates-data #Atlassian #Breach #HackerNews #ngated -
Apple says more ex-employees may have taken confidential data to OpenAI
Comments: https://news.ycombinator.com/item?id=49170479
#HackerNews #Apple #OpenAI #data #breach #ex-employees #confidentiality #tech #news
-
#FirstManufacturing now says they are investigating how the unique email address I gave only to them ended up in the hands of another merchant, #LeatherNewYork. They also continue to deny any information was leaked, which is clearly false, and I wrote back and told them so. Additional details here if you're curious:
https://blog.kamens.us/2026/07/18/first-manufacturing-co-selling-customer-email-addresses-in-violation-of-its-own-privacy-policy/#update0804
#infosec #privacy #spam #breach -
Iran Hackss Water Systems In 7 States - USA Losing War
#breach #CriticalInfrastructure #Iran #GOPLiesAboutEverything #water
youtube.com/watch?v=erMc...
Iran Hacks Water Systems in 7 ... -
RE: https://psiren.eu/@PSiReN/111217564398876151
#YouKnow what is awesome about #Mastodon...?
#IT #AutomaticallyCounts the #Number of #Days #Since: An #InstanceAdministrator #Performs a #ShadowBan, #Lies to its #Members and then seeks to #CoverUp their #Breach by #Forcing a #PrivateDiscussion...
Also, it #AutomaticallyCounts the #Number of #Days it takes for the #InstanceAdministrator to #Apologise... #Automatically...!And, #QuoteToots... #StillQuiteCool
🧙🎠🤖:wolfparty:🤖🎠🧙 | :fediverse:🦹:PirateBadge:🦄:PirateBadge:🦹:fediverse:
-
🚨 Breaking news: Tailscale's #security wizardry couldn't stop an #intrusion at a company named after a children's toy 🤖🧸. But fear not, they invite you to a #conference where they'll likely discuss how to secure everything except what's already been breached. 🎟️🔒
https://tailscale.com/blog/hugging-face-intrusion #Tailscale #Cybersecurity #Breach #ToyCompany #HackerNews #ngated