<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Application Security on Security Blueprints</title>
    <link>https://securityblueprints.io/tags/application-security/</link>
    <description>Recent content in Application Security on Security Blueprints</description>
    <generator>Hugo</generator>
    <language>en</language>
    <managingEditor>user@example.com (Niels Provos)</managingEditor>
    <webMaster>user@example.com (Niels Provos)</webMaster>
    <copyright>Security Blueprints, LLC</copyright>
    <lastBuildDate>Sun, 06 Sep 2026 23:57:45 +0000</lastBuildDate>
    <atom:link href="https://securityblueprints.io/tags/application-security/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>JADEPUFFER Agentic Ransomware Campaign via Langflow CVE-2025-3248 (2026)</title>
      <link>https://securityblueprints.io/data-breaches/jadepuffer-agentic-ransomware-campaign-via-langflow-cve-2025-3248-2026/</link>
      <pubDate>Wed, 01 Jul 2026 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/data-breaches/jadepuffer-agentic-ransomware-campaign-via-langflow-cve-2025-3248-2026/</guid>
      <description>Executive Summary Sysdig’s Threat Research Team published or documented JADEPUFFER on 2026-07-01, assessing it as an end-to-end ransomware operation driven by a large-language-model agent. That date is a publication/documentation date, not an independently established victim-specific compromise date; one source places the activity in late June. The operation began against an internet-exposed Langflow deployment vulnerable to CVE-2025-3248, then reached a separate production environment running MySQL and Alibaba Nacos. No victim organization is publicly identified, and no affected-person count is reported.</description>
    </item>
    <item>
      <title>Samsung Data Breach November 2023</title>
      <link>https://securityblueprints.io/data-breaches/samsung-data-breach-november-2023/</link>
      <pubDate>Mon, 13 Nov 2023 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/data-breaches/samsung-data-breach-november-2023/</guid>
      <description>Executive Summary On November 13, 2023, Samsung Electronics detected a data breach originating from a vulnerability in a third-party application. This breach affected customers who made purchases through the Samsung UK online store between July 1, 2019, and June 30, 2020, exposing personal information, including names, phone numbers, postal addresses, and email addresses. Samsung notified affected customers on November 16, 2023.&#xA;Severity of Impact The breach&amp;rsquo;s significance lies in the exposure of sensitive personal information, even though financial data and passwords were not compromised.</description>
    </item>
    <item>
      <title>DuoLingo Data Breach August 2023</title>
      <link>https://securityblueprints.io/data-breaches/duolingo-data-breach-august-2023/</link>
      <pubDate>Tue, 01 Aug 2023 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/data-breaches/duolingo-data-breach-august-2023/</guid>
      <description>Executive Summary In August 2023, DuoLingo experienced a significant data exposure incident caused by a data scraping attack targeting an exposed Application Programming Interface (API). The breach affected approximately 2.6 million users, with personal data such as names, email addresses, and other identifiable information being posted online (source 1 , source 4 ).&#xA;Severity of Impact The exposure compromised personal information of approximately 2.6 million users, including critical identifiers like login names and email addresses, heightening risks for phishing and other cyber threats (source 3 , source 6 ).</description>
    </item>
    <item>
      <title>MOVEit Data Breach June 2023</title>
      <link>https://securityblueprints.io/data-breaches/moveit-data-breach-june-2023/</link>
      <pubDate>Thu, 01 Jun 2023 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/data-breaches/moveit-data-breach-june-2023/</guid>
      <description>Executive Summary In June 2023, a significant data breach involving the MOVEit Transfer software began; within its first weeks it had affected over 200 organizations globally, a toll that continued climbing for more than a year afterward (Axios ). This breach was triggered by exploiting a zero-day vulnerability, CVE-2023-34362, within the MOVEit Transfer tool by Progress Software Corporation. The Clop ransomware group, using its Ransomware as a Service (RaaS) model, claimed responsibility for the data theft operations.</description>
    </item>
    <item>
      <title>Microsoft Email Accounts Security Breach</title>
      <link>https://securityblueprints.io/data-breaches/microsoft-email-accounts-security-breach/</link>
      <pubDate>Mon, 01 May 2023 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/data-breaches/microsoft-email-accounts-security-breach/</guid>
      <description>Executive Summary In May 2023, a data breach occurred at Microsoft when China-based hackers, identified as Storm-0558, used forged authentication tokens to gain unauthorized access to customer email accounts. This incident highlighted vulnerabilities in Microsoft&amp;rsquo;s authentication systems and raised concerns over national security implications.&#xA;Key Dates and Timeline Breach Date: May 2023 Discovery Date: June 2023, by the U.S. Department of State source . Public Disclosure Date: April 2024, following a thorough review by the Cyber Safety Review Board source .</description>
    </item>
    <item>
      <title>ChatGPT Data Breach</title>
      <link>https://securityblueprints.io/data-breaches/chatgpt-data-breach/</link>
      <pubDate>Mon, 20 Mar 2023 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/data-breaches/chatgpt-data-breach/</guid>
      <description>Executive Summary Overview of the Incident In March 2023, OpenAI&amp;rsquo;s ChatGPT platform experienced a data breach caused by a bug in the open-source library, Redis-py, used by the service. This issue resulted in the exposure of sensitive user data, including names, emails, payment addresses, and partial credit card details (last four digits and expiration dates). The breach was identified on March 20, 2023, during a service outage, revealing private information in error source .</description>
    </item>
    <item>
      <title>Chick-fil-A Data Breach March 2023</title>
      <link>https://securityblueprints.io/data-breaches/chick-fil-a-data-breach-march-2023/</link>
      <pubDate>Wed, 01 Mar 2023 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/data-breaches/chick-fil-a-data-breach-march-2023/</guid>
      <description>Executive Summary In March 2023, Chick-fil-A confirmed a data breach resulting from unauthorized login activity via a credential stuffing attack. This attack, utilizing previously leaked credentials, enabled access to customer accounts through Chick-fil-A&amp;rsquo;s mobile application (TechRadar ).&#xA;Breach Details Unauthorized access occurred between December 18, 2022, to February 12, 2023, impacting approximately 71,473 accounts (less than 2% of users). The exposed information included names, email addresses, Chick-fil-A One membership details, and partial payment information (ClassAction.</description>
    </item>
    <item>
      <title>Norton Life Lock Credential Stuffing Data Breach</title>
      <link>https://securityblueprints.io/data-breaches/norton-life-lock-credential-stuffing-data-breach/</link>
      <pubDate>Fri, 13 Jan 2023 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/data-breaches/norton-life-lock-credential-stuffing-data-breach/</guid>
      <description>Executive Summary In January 2023, Norton LifeLock reported a data breach due to a credential stuffing attack, allowing attackers to exploit previously compromised passwords to access over 6,000 customer accounts. The incident highlighted vulnerabilities within password management services, raising concerns about the security of stored credentials [source1 ].&#xA;Severity of Impact The breach exposed personal data, including names, phone numbers, and mailing addresses, and potentially compromised credentials stored in the Norton Password Manager.</description>
    </item>
    <item>
      <title>T-Mobile January 2023 Data Breach</title>
      <link>https://securityblueprints.io/data-breaches/t-mobile-january-2023-data-breach/</link>
      <pubDate>Fri, 25 Nov 2022 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/data-breaches/t-mobile-january-2023-data-breach/</guid>
      <description>Executive Summary In January 2023, T-Mobile disclosed a significant data breach that affected approximately 37 million current customers. The breach, initiated through unauthorized access to an API, began in late November 2022. T-Mobile detected the breach on January 5, 2023, and publicly disclosed it on January 19, 2023.&#xA;Technical Details The breach was facilitated through a vulnerability in an API, which allowed attackers to access personal data, including names, billing addresses, email addresses, phone numbers, and dates of birth.</description>
    </item>
    <item>
      <title>LinkedIn Data Scraping Incident</title>
      <link>https://securityblueprints.io/data-breaches/linkedin-data-scraping-incident/</link>
      <pubDate>Thu, 01 Apr 2021 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/data-breaches/linkedin-data-scraping-incident/</guid>
      <description>Executive Summary In April 2021, LinkedIn reported a significant data scraping incident involving approximately 700 million user records, totaling over 93% of its user base. The breach was disclosed in June 2021 after data was discovered being sold on dark web forums by the hacker known as &amp;ldquo;GOD User TomLiner,&amp;rdquo; who intended to sell the dataset for an estimated $5,000 to $6,600.&#xA;Severity of the Impact The breach&amp;rsquo;s significance lies in the vast volume of exposed personal information, such as full names, email addresses, phone numbers, LinkedIn IDs, and sensitive data like gender, industry, and inferred salaries.</description>
    </item>
    <item>
      <title>Microsoft Exchange Server Breach</title>
      <link>https://securityblueprints.io/data-breaches/microsoft-exchange-server-breach/</link>
      <pubDate>Sun, 03 Jan 2021 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/data-breaches/microsoft-exchange-server-breach/</guid>
      <description>Executive Summary In January 2021, Microsoft Exchange email servers were targeted in a significant cyberattack that exploited multiple zero-day vulnerabilities, affecting over 30,000 organizations in the United States. Initially detected by Volexity on January 3, 2021, the breach was publicly acknowledged by Microsoft on March 2, 2021, upon releasing emergency patches (source , source ).&#xA;Severity of the Impact Globally, the breach compromised up to 250,000 servers, impacting critical sectors such as government, banking, and infrastructure, thereby posing risks to operational integrity and data confidentiality (source , source ).</description>
    </item>
    <item>
      <title>Sina Weibo Data Breach 2020</title>
      <link>https://securityblueprints.io/data-breaches/sina-weibo-data-breach-2020/</link>
      <pubDate>Thu, 19 Mar 2020 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/data-breaches/sina-weibo-data-breach-2020/</guid>
      <description>Executive Summary In March 2020, Sina Weibo, a leading Chinese microblogging platform, experienced a significant data breach impacting approximately 538 million users. The breach was publicly acknowledged when an attacker leveraged a logic flaw in the Sina Weibo API to access and sell personal user information on the dark web for about USD 250. This breach exposed sensitive details such as real names, usernames, gender, location, and phone numbers for 172 million users, though passwords were not compromised.</description>
    </item>
    <item>
      <title>Alibaba Taobao Data Breach</title>
      <link>https://securityblueprints.io/data-breaches/alibaba-taobao-data-breach/</link>
      <pubDate>Fri, 01 Nov 2019 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/data-breaches/alibaba-taobao-data-breach/</guid>
      <description>Executive Summary In November 2019, Alibaba&amp;rsquo;s Taobao platform experienced a breach involving unauthorized data scraping activities by a developer. This breach involved collecting 1.1 billion pieces of user data, including usernames and mobile numbers, over several months until discovered in July 2020. Officially acknowledged on June 16, 2021, the breach stands as significant due to its volume and impact.&#xA;Severity of Impact The breach is one of the largest data leaks recorded, affecting approximately 710 million Taobao users.</description>
    </item>
    <item>
      <title>SolarWinds Supply Chain Attack</title>
      <link>https://securityblueprints.io/data-breaches/solarwinds-supply-chain-attack/</link>
      <pubDate>Sun, 01 Sep 2019 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/data-breaches/solarwinds-supply-chain-attack/</guid>
      <description>Executive Summary The SolarWinds Supply Chain Attack represents a pivotal cyber incident with substantial global repercussions. This sophisticated breach resulted in the compromise of SolarWinds&amp;rsquo; software development infrastructure, spreading malicious updates within their Orion software. The attack, initiated in September 2019, culminated with the distribution of malicious updates starting in March 2020, which were installed by over 18,000 SolarWinds customers. This infiltration allowed attackers unauthorized access for data theft and espionage, as publicly disclosed in December 2020.</description>
    </item>
    <item>
      <title>First American Financial Corp Data Breach</title>
      <link>https://securityblueprints.io/data-breaches/first-american-financial-corp-data-breach/</link>
      <pubDate>Fri, 24 May 2019 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/data-breaches/first-american-financial-corp-data-breach/</guid>
      <description>Executive Summary In May 2019, a data breach at First American Financial Corp. resulted in the exposure of approximately 885 million file records due to inadequate security measures on their web portal. The breach came to light when a real estate developer discovered the vulnerability, and cybersecurity journalist Brian Krebs publicly disclosed it on May 24, 2019. The exposed records included sensitive financial documents such as bank account numbers, mortgage-related documents, and Social Security numbers, with records dating back to 2003.</description>
    </item>
    <item>
      <title>Copay Cryptocurrency Wallet Data Breach</title>
      <link>https://securityblueprints.io/data-breaches/copay-cryptocurrency-wallet-data-breach/</link>
      <pubDate>Tue, 27 Nov 2018 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/data-breaches/copay-cryptocurrency-wallet-data-breach/</guid>
      <description>Executive Summary In November 2018, the Copay cryptocurrency wallet, developed by BitPay, experienced a data breach due to a malicious update to the event-stream Node.js library, specifically within its flatmap-stream dependency. Unauthorized access to users&amp;rsquo; private keys and cryptocurrency funds was achieved, significantly impacting wallets containing over 100 Bitcoins or 1000 Bitcoin Cash source .&#xA;Key Dates August 5, 2018: Initial release of the flatmap-stream package. September 9, 2018: Integration of flatmap-stream into event-stream.</description>
    </item>
    <item>
      <title>2017 Equifax Data Breach</title>
      <link>https://securityblueprints.io/data-breaches/2017-equifax-data-breach/</link>
      <pubDate>Sat, 29 Jul 2017 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/data-breaches/2017-equifax-data-breach/</guid>
      <description>Executive Summary The 2017 Equifax data breach marked a critical event in data security, caused by exploiting a known vulnerability, CVE-2017-5638, in the Apache Struts web application framework. Unauthorized access led to the exposure of sensitive information of approximately 145.5 million individuals.&#xA;Severity of Impact This breach was one of the largest in history, significantly affecting Personally Identifiable Information (PII), including names, Social Security numbers, birth dates, and, in certain instances, driver&amp;rsquo;s license numbers and credit card data.</description>
    </item>
    <item>
      <title>AdultFriendFinder Data Breach</title>
      <link>https://securityblueprints.io/data-breaches/adultfriendfinder-data-breach/</link>
      <pubDate>Thu, 20 Oct 2016 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/data-breaches/adultfriendfinder-data-breach/</guid>
      <description>Executive Summary The AdultFriendFinder data breach, a significant incident in 2016, compromised approximately 412 million user accounts across platforms under FriendFinder Networks, including AdultFriendFinder.com, Cams.com, and Penthouse.com. This breach unveiled notable security vulnerabilities within the company&amp;rsquo;s systems.&#xA;Breach Details The breach occurred in October 2016 when attackers exploited Local File Inclusion (LFI) vulnerabilities within the website&amp;rsquo;s architecture, enabling unauthorized access to sensitive information. This data was publicly posted on November 13, 2016.</description>
    </item>
    <item>
      <title>Adobe 2013 Data Breach</title>
      <link>https://securityblueprints.io/data-breaches/adobe-2013-data-breach/</link>
      <pubDate>Thu, 03 Oct 2013 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/data-breaches/adobe-2013-data-breach/</guid>
      <description>Executive Summary In October 2013, Adobe became the victim of a cyberattack that compromised nearly 153 million user records, ranking as one of the largest breaches in cybersecurity history (source ). The attack resulted in the exposure of encrypted customer credit card information and user account details, prompting concerns about Adobe&amp;rsquo;s cybersecurity protocols (source ).&#xA;Key Details Breach Discovery: Internal discovery occurred on September 17, 2013, with public disclosure by Adobe on October 3, 2013 (source ).</description>
    </item>
    <item>
      <title>MySpace Data Breach</title>
      <link>https://securityblueprints.io/data-breaches/myspace-data-breach/</link>
      <pubDate>Sat, 01 Jun 2013 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/data-breaches/myspace-data-breach/</guid>
      <description>Executive Summary The MySpace data breach disclosed in June 2016 affected over 360 million user accounts, underscoring substantial deficiencies in the company&amp;rsquo;s data security measures. At the time, MySpace utilized weak hashing algorithms like SHA-1 without salting, a method known for its cryptographic weaknesses. Users&amp;rsquo; widespread password reuse across different services amplified the breach&amp;rsquo;s repercussions. Consequently, MySpace updated its security practices post-breach, transitioning to double-salted hashes.&#xA;Technical Details The breach highlighted significant vulnerabilities due to inadequate security measures.</description>
    </item>
    <item>
      <title>LinkedIn Password Breach</title>
      <link>https://securityblueprints.io/data-breaches/linkedin-password-breach/</link>
      <pubDate>Fri, 01 Jun 2012 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/data-breaches/linkedin-password-breach/</guid>
      <description>Executive Summary In 2012, LinkedIn experienced a significant data breach affecting its user base. Initially reported to have compromised 6.5 million hashed passwords, the breach&amp;rsquo;s true extent, revealed in 2016, affected over 117 million accounts. The compromised passwords were stored using the SHA1 hashing algorithm without salting, making them vulnerable to brute force and rainbow table attacks. These inadequacies exposed LinkedIn users to substantial risks as the leaked credentials circulated on cybercrime forums like LeakedSource.</description>
    </item>
    <item>
      <title>Heartland Payment Systems Data Breach</title>
      <link>https://securityblueprints.io/data-breaches/heartland-payment-systems-data-breach/</link>
      <pubDate>Wed, 26 Dec 2007 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/data-breaches/heartland-payment-systems-data-breach/</guid>
      <description>Executive Summary Heartland Payment Systems experienced a major data breach compromising approximately 130 million payment card records, marking one of the largest breaches involving consumer credit and debit card information. The breach originated from SQL injection attacks and malware deployment starting around December 26, 2007, and was discovered by authorities in October 2008. Public disclosure followed on January 20, 2009. This information is corroborated by multiple sources (source , source , source ).</description>
    </item>
  </channel>
</rss>
