Tag / 22 entries / page 1 of 3 / feed available

Application Security

22 of the 76 analyses in Data Breaches carry this tag. All 22 are scored against the four invariants; the matrix below is that evidence.

How this tag scores against the four invariants

HSF · PEC · EGR · SCA — filled where the invariant would have prevented or contained the breach

076

JADEPUFFER Agentic Ransomware Campaign via Langflow CVE-2025-3248 (2026)

Contained by: PEC, EGR

JADEPUFFER exploited an internet-exposed Langflow deployment vulnerable to CVE-2025-3248, then accessed MinIO, PostgreSQL, MySQL, and Alibaba Nacos environments. The operation encrypted exactly 1,342 Nacos configuration items, deleted original tables, and attempted additional database destruction; a later ENCFORGE payload targeted AI and machine-learning files. No victim organization or affected-person count was publicly reported, and the degree of human involvement in the agentic campaign remains unresolved.

061

Samsung Data Breach November 2023

A vulnerability in a third-party application used by Samsung led to a data breach affecting UK customers who made purchases via the Samsung UK online store. The breach exposed personal information including names, phone numbers, postal addresses, and emails. The unauthorized access was the result of exploiting the vulnerability, with the specifics around the threat actors and exact details remaining undisclosed.

056

MOVEit Data Breach June 2023

Contained by: PEC

The June 2023 MOVEit data breach began with the exploitation of a zero-day SQL injection vulnerability (CVE-2023-34362) in the MOVEit Transfer software; over 200 organizations were confirmed affected within the first weeks, a toll that climbed to more than 2,700 organizations and over 95 million individuals as disclosures continued into 2024. The Clop ransomware group was responsible, utilizing web shell deployment and data exfiltration methods to access and steal personal and sensitive information, highlighting substantial risks in application security and third-party systems.

054

Microsoft Email Accounts Security Breach

In May 2023, Microsoft suffered a data breach conducted by China-based hackers, Storm-0558, who used forged authentication tokens to access customer email accounts. This breach impacted governmental entities, resulting in the unauthorized access and potential exfiltration of approximately 60,000 unclassified emails, emphasizing the breach’s serious national security implications.

051

ChatGPT Data Breach

Contained by: SCA

In March 2023, a data breach on OpenAI’s ChatGPT platform exposed sensitive user data, including names, email addresses, payment information, and partial credit card details due to a bug in the Redis-py library. Approximately 1.2% of ChatGPT Plus users were affected. The breach was caused internally, stemming from an open-source library vulnerability, highlighting the risks associated with external dependencies.

049

Chick-fil-A Data Breach March 2023

Prevented by: HSF

In March 2023, Chick-fil-A experienced a significant data breach due to unauthorized login activities via a credential stuffing attack. The incident exposed personal information of approximately 71,473 users, including names, email addresses, membership details, and partial payment information. This breach was facilitated by credential reuse and highlights the vulnerabilities in login security protocols.

045

Norton Life Lock Credential Stuffing Data Breach

Prevented by: HSF

In January 2023, Norton LifeLock experienced a data breach impacting over 6,000 customer accounts due to a credential stuffing attack. The attackers used previously compromised passwords from dark web datasets to gain unauthorized access. Exposed data included personal information such as names, phone numbers, and addresses, increasing the risk of identity theft. Although approximately 925,000 accounts were targeted, only a fraction was breached.

036

LinkedIn Data Scraping Incident

In April 2021, LinkedIn experienced a massive data scraping incident, exposing approximately 700 million user records. The breach involved personal information such as full names, email addresses, and professional details extracted through LinkedIn’s public API by a threat actor named ‘GOD User TomLiner.’ Although passwords and financial details were not compromised, the incident highlights significant risks for identity theft and phishing attacks.

RSS feed for this tag →

Now playing Bandcamp