home.social

#breach — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #breach, aggregated by home.social.

fetched live
  1. Remember #FirstManufacturing either selling my email address or letting it be stolen and refusing to admit to either?
    The evidence that this happened just got more concrete: yesterday, I received spam to that address from another merchant, _and it mentions First Manufacturing in the header_.
    I've emailed the company again and await their response. I also posted a 1-⭐️ review on Google Maps.
    Details here if you're curious: blog.kamens.us/2026/07/18/firs
    #infosec #privacy #spam #breach

  2. 9 million images exposed by a facial recognition platform — without authentication, apparently. The real question isn't just "how did this happen" but "why is biometric data this easy to leave open". Default-secure infrastructure for sensitive data remains an unsolved deployment problem, not just a tech one. #infosec #privacy #breach
    securitymagazine.com/articles/

  3. #GitHub may have a data #leak...

    Yesterday I got a spam message sent to my dedicated GitHub email address. "Dedicated" means I only use it to log into GitHub. The option to "Keep my email addresses private" is active.

    As far as I can tell, I'm not leaking this email address anywhere myself. A Google search turns up nothing.

    Soooo, is it just me, or is there anyone else who got the impression there's something wrong?

    Maybe the recent #outage is related?

    #dataprotection #breach

  4. CareCloud Breach Hits 3.7 Million, Ten Times Initial Estimate

    Healthcare solutions provider CareCloud confirms its March network intrusion affected 3.7 million individuals, far more than the 350,000 first reported.

    pulseofnations.lol/carecloud-b

    #Breach #Carecloud #DataBreach #Healthcare #Hitss

  5. Just learned about the #Carhartt data #breach because of a phishing email to my Carhartt-specific email.

    Congrats to them for refusing to pay the ShinyHunters ransom. However, I haven't seen any kind of actual breach notification. Not so good.

  6. The 'no-logs' VPN that allegedly logged everything: what the SplitVPN leak actually shows

    Follow @1ban_news for daily coverage.

    1ban.news/splitvpn-notvpn-no-l

    #1ban #splitvpn #notvpn #logs #breach #tech

  7. 8 emails from Wise saying I am trying to create an account with an email address that's only used with them. Hmm... how long till they admit a breach? #breach

  8. 🚨 Oh look, another #data breach! This time featuring #Metabase as the unwitting sidekick in the circus act of "Oops, Your Data is Showing!" 🎪 Framework's fans are just thrilled with the speedy notification—as if that's going to stitch their #privacy back together. 🤡🔧
    community.frame.work/t/framewo #breach #Framework #notification #cybersecurity #HackerNews #ngated

  9. @frameworkcomputer sent me this email (they didn't post it on blog or fediverse):
    Notice of Limited Data Breach

    We confirmed that the following information was accessed:
        Full name
        Email address
        Login IPs
        Billing and shipping address information
            Country
            Address
            City
            State
            Zip code
            Phone number
            Company
    For Framework for Business customers, we are investigating whether the following information may additionally have been accessed:
        Company
        Phone
        VAT
        EIN
        Billing Email
    No other personally identifiable information, order information, or payment information was accessed.

    Dear Valued Framework Customer,
    We are writing to inform you of a data breach at our business intelligence database provider Metabase that resulted in an attacker accessing customer names, email addresses, phone numbers, and addresses. Your information was in the database that was accessed in this breach. This breach did not include order or payment information.
    We have full details on the incident below. We are deeply sorry for this breach of information, and are reviewing and improving our methodology for data storage in external database vendors.
    We are also in the process of notifying the regulatory authorities in each region where relevant regulations exist. Note that while regulations in most regions do not require notification for breaches of names, email addresses, phone numbers, and addresses, we are sending this email to you regardless to ensure you have visibility and can take any actions needed.
    What happened?
    On August 6th, 2026 at 9am Pacific Time, Metabase notified us of a breach of their systems with the following email message:
    On Monday, August 3, we discovered that Metabase Cloud was attacked by someone utilizing an unknown (“0-day”) security vulnerability in versions 1.58 and above. We immediately blocked the endpoints used for the attack, then quickly identified and patched the vulnerability. We notified law enforcement, and we have engaged with a third party forensics firm to conduct an independent investigation.
    Your instance of Metabase was vulnerable to this 0-day. Therefore, to protect your company, we recommend you:
    Rotate the credentials for every database connected to your instance; and
    Review the admin accounts on your instance and remove anything you don't recognize.
    We also discovered that the attacker was able to gain access to your instance. We created a report on the actions we believe the attacker took on your instance, which includes log files, and which you can get from the Metabase Store at [removed url].
    (If you do not have access to the Metabase Store, are having issues accessing the report, or do not want to click on a link in an unexpected email, you can log into your instance directly and reach us at Help > Get help in the grid menu in the upper right hand corner. We'll confirm this message is from us and email you the report.)
    This report is based on our own application logs. We did not query or read the data in your connected databases.
    Depending on the jurisdictions in which you operate and kinds of data your instance connects to, you may have notification obligations under applicable laws. If you have concerns in this regard, we recommend you assess potential notification obligations with your company’s legal or compliance experts.
    We regret any inconvenience this incident may cause you, and we are here to support you. If you have questions, please reply to this email or email us at [removed email address], and we'll get back to you as quickly as we can.
    Sameer Al-Sakran Founder and CEO Metabase
    We immediately investigated the logs Metabase provided to us and confirmed that our database instance was accessed by the attacker.
    1/2

    #framework #breach #hack #metabase

  10. Now I got a breach notification from Framwork, that Metabase cloud apparently was breached, some business intelligence company.

    Perhaps related to Feedly?

    #Breach #Incident

  11. Looks like #Metabase was breached via SQL injection from an unauthenticated endpoint. I was informed because #Framework emailed me saying my data was in the database that was accessed. Framework states they were notified of the #breach August 6th.

    Metabase info: github.com/metabase/metabase/s

    What was accessed according to Framework:

    We immediately investigated the logs Metabase provided to us and confirmed that our database instance was accessed by the attacker. We confirmed that the following information was accessed:

    Full name
    Email address
    Login IPs
    Billing and shipping address information
    Country
    Address
    City
    State
    Zip code
    Phone number
    Company

    For Framework for Business customers, we are investigating whether the following information may additionally have been accessed:
    Company
    Phone
    VAT
    EIN
    Billing Email

    In the notification to Framework on the 6th, Metabase stated that it was a preliminary update and they were still investigating at that time, though they say they have patched the vulnerability.

  12. 52% of Americans Think Their Personal Data Will Be Breached. They're Probably Right

    A new survey finds most Americans believe a data breach is inevitable, reflecting growing concerns about online privacy, AI-generated misinformation, and the future of the internet.

    pcmag.com/news/52-of-americans

    #pcmag #breach #incogni #internet

  13. 🚨 Breaking News: Atlassian's #AI #Rovo thinks it's a secret agent, successfully sneaking out #Jira and #Confluence #data like a #clumsy #spy in a slapstick comedy. 🤡 Turns out, it's easier to bypass their "controls" than to find the coffee machine in the office. ☕️🔍
    promptarmor.com/resources/atla #Atlassian #Breach #HackerNews #ngated

  14. #FirstManufacturing now says they are investigating how the unique email address I gave only to them ended up in the hands of another merchant, #LeatherNewYork. They also continue to deny any information was leaked, which is clearly false, and I wrote back and told them so. Additional details here if you're curious:
    blog.kamens.us/2026/07/18/firs
    #infosec #privacy #spam #breach

  15. 🚨 Breaking news: Tailscale's #security wizardry couldn't stop an #intrusion at a company named after a children's toy 🤖🧸. But fear not, they invite you to a #conference where they'll likely discuss how to secure everything except what's already been breached. 🎟️🔒
    tailscale.com/blog/hugging-fac #Tailscale #Cybersecurity #Breach #ToyCompany #HackerNews #ngated