<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Network Security on Security Blueprints</title>
    <link>https://securityblueprints.io/tags/network-security/</link>
    <description>Recent content in Network Security on Security Blueprints</description>
    <generator>Hugo</generator>
    <language>en</language>
    <managingEditor>user@example.com (Niels Provos)</managingEditor>
    <webMaster>user@example.com (Niels Provos)</webMaster>
    <copyright>Security Blueprints, LLC</copyright>
    <lastBuildDate>Sun, 06 Sep 2026 23:57:44 +0000</lastBuildDate>
    <atom:link href="https://securityblueprints.io/tags/network-security/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>JADEPUFFER Agentic Ransomware Campaign via Langflow CVE-2025-3248 (2026)</title>
      <link>https://securityblueprints.io/data-breaches/jadepuffer-agentic-ransomware-campaign-via-langflow-cve-2025-3248-2026/</link>
      <pubDate>Wed, 01 Jul 2026 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/data-breaches/jadepuffer-agentic-ransomware-campaign-via-langflow-cve-2025-3248-2026/</guid>
      <description>Executive Summary Sysdig’s Threat Research Team published or documented JADEPUFFER on 2026-07-01, assessing it as an end-to-end ransomware operation driven by a large-language-model agent. That date is a publication/documentation date, not an independently established victim-specific compromise date; one source places the activity in late June. The operation began against an internet-exposed Langflow deployment vulnerable to CVE-2025-3248, then reached a separate production environment running MySQL and Alibaba Nacos. No victim organization is publicly identified, and no affected-person count is reported.</description>
    </item>
    <item>
      <title>Salt Typhoon Intrusions into U.S. Telecommunications Carriers (2024)</title>
      <link>https://securityblueprints.io/data-breaches/salt-typhoon-intrusions-into-us-telecommunications-carriers-2024/</link>
      <pubDate>Wed, 25 Sep 2024 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/data-breaches/salt-typhoon-intrusions-into-us-telecommunications-carriers-2024/</guid>
      <description>Executive Summary Salt Typhoon was a China-linked cyber-espionage campaign against U.S. telecommunications providers. The incident is dated 2024-09-25 for this report only; this is report metadata/designation, not a source-confirmed forensic breach date. Public reporting first described the broader compromise in September 2024, while later government statements said the campaign had likely operated for one to two years before disclosure (therecord.media ). By December 2024, officials said at least eight U.S. providers had been targeted; a ninth U.</description>
    </item>
    <item>
      <title>National Public Data Breach of April 2024</title>
      <link>https://securityblueprints.io/data-breaches/national-public-data-breach-of-april-2024/</link>
      <pubDate>Mon, 01 Apr 2024 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/data-breaches/national-public-data-breach-of-april-2024/</guid>
      <description>Executive Summary In April 2024, National Public Data (NPD) became the subject of a significant data breach, compromising sensitive personal information of hundreds of millions of Americans. The breach was attributed to a security oversight, specifically the inadvertent publication of administrative credentials, leading to unauthorized access to NPD&amp;rsquo;s databases. This event highlights substantial gaps in cybersecurity practices and emphasizes the critical need for robust protection and risk management strategies.&#xA;Incident Overview Chronological Sequence of Events December 2023</description>
    </item>
    <item>
      <title>American Express Data Breach March 2024</title>
      <link>https://securityblueprints.io/data-breaches/american-express-data-breach-march-2024/</link>
      <pubDate>Mon, 04 Mar 2024 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/data-breaches/american-express-data-breach-march-2024/</guid>
      <description>Executive Summary On March 4, 2024, American Express announced a data breach resulting from unauthorized access through a third-party merchant processor. This incident compromised customer information, including names, account numbers, and expiration dates, due to a point-of-sale attack affecting systems associated with American Express Travel Related Services Company. It highlights the vulnerabilities within third-party vendor systems in the financial sector. Source Severity of Impact The breach presented significant risks, potentially compromising critical cardholder information.</description>
    </item>
    <item>
      <title>Fujitsu Malware Attack 2024</title>
      <link>https://securityblueprints.io/data-breaches/fujitsu-malware-attack-2024/</link>
      <pubDate>Fri, 01 Mar 2024 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/data-breaches/fujitsu-malware-attack-2024/</guid>
      <description>Executive Summary In March 2024, Fujitsu identified a malware infection on its corporate network, indicating a notable cybersecurity breach that potentially compromised customer information. Details of the breach were made public on March 15, 2024, highlighting unauthorized access achieved using advanced malware techniques (source , source , source ).&#xA;Severity of Impact The incident is classified as severe, as it may involve sensitive customer data exposure. Although certain data access was confirmed, no misuse evidence has emerged so far (source ).</description>
    </item>
    <item>
      <title>Change Healthcare February 2024 Data Breach</title>
      <link>https://securityblueprints.io/data-breaches/change-healthcare-february-2024-data-breach/</link>
      <pubDate>Mon, 12 Feb 2024 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/data-breaches/change-healthcare-february-2024-data-breach/</guid>
      <description>Executive Summary The Change Healthcare data breach involved a ransomware attack in February 2024, attributed to the BlackCat group, also known as ALPHV. This cyber assault led to considerable disruptions within pharmacy operations and potentially exposed sensitive client data. source Severity of Impact The breach significantly impacted Change Healthcare&amp;rsquo;s extensive network, which comprises over 1.6 million healthcare professionals, 70,000 pharmacies, and 8,000 healthcare facilities. The breach&amp;rsquo;s financial impact is estimated at $872 million, highlighting the substantial economic consequences.</description>
    </item>
    <item>
      <title>U-Haul Data Breach</title>
      <link>https://securityblueprints.io/data-breaches/u-haul-data-breach/</link>
      <pubDate>Tue, 05 Dec 2023 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/data-breaches/u-haul-data-breach/</guid>
      <description>Executive Summary The U-Haul data breach was publicly disclosed in February 2024, impacting approximately 67,000 customers across the United States and Canada. Initially discovered on December 5, 2023, unauthorized individuals accessed an internal system by exploiting stolen credentials, exposing sensitive personal information, including customer names and driver’s license numbers. Financial information remained unaffected (BleepingComputer ; SecurityWeek ).&#xA;Severity of the Impact The exposure of personal identifiers poses risks such as identity theft, although the absence of financial data reduction slightly limits potential damage.</description>
    </item>
    <item>
      <title>British Library Ransomware Attack October 2023</title>
      <link>https://securityblueprints.io/data-breaches/british-library-ransomware-attack-october-2023/</link>
      <pubDate>Sat, 28 Oct 2023 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/data-breaches/british-library-ransomware-attack-october-2023/</guid>
      <description>Executive Summary The British Library experienced a ransomware attack carried out by the Rhysida ransomware group in 2023. This cyber incident was identified on October 28, 2023. Public announcements regarding ongoing technology outages followed on November 17, 2023. The attack demonstrated vulnerabilities within the library&amp;rsquo;s IT infrastructure, resulting in significant disruptions due to data encryption.&#xA;Severity of the Impact The ransomware attack severely affected services, disrupting digital and physical operations including public Wi-Fi and possibly internal human resources files.</description>
    </item>
    <item>
      <title>Indian Council of Medical Research Data Breach 2023</title>
      <link>https://securityblueprints.io/data-breaches/indian-council-of-medical-research-data-breach-2023/</link>
      <pubDate>Mon, 09 Oct 2023 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/data-breaches/indian-council-of-medical-research-data-breach-2023/</guid>
      <description>Executive Summary In 2023, the Indian Council of Medical Research (ICMR) experienced a significant data breach, resulting in the unauthorized access and theft of approximately 815 million records. The data compromised included sensitive personal information such as Aadhaar IDs, passport details, names, phone numbers, and addresses. The threat actor, identified as pwn0001, advertised the stolen data for sale on the dark web (source , source , source ).&#xA;Incident Details Discovery Date: October 9, 2023, when the data sale was announced on dark web forums.</description>
    </item>
    <item>
      <title>MGM Grand Data Breach - September 2023</title>
      <link>https://securityblueprints.io/data-breaches/mgm-grand-cyberattack/</link>
      <pubDate>Fri, 08 Sep 2023 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/data-breaches/mgm-grand-cyberattack/</guid>
      <description>Executive Summary In September 2023, MGM Resorts International experienced a major cyberattack attributed to the hacking group Scattered Spider, known for its association with the ALPHV/BlackCat ransomware group. The attack resulted in significant disruptions to operations at MGM&amp;rsquo;s Las Vegas venues, including the MGM Grand and Bellagio, with estimated financial losses ranging from $80 million to $100 million. This incorporates direct impacts on revenue and heightened cybersecurity expenses. The attackers exploited vulnerabilities in service desk operations through social engineering tactics like vishing, which allowed unauthorized system access.</description>
    </item>
    <item>
      <title>Yum! Brands Ransomware Data Breach</title>
      <link>https://securityblueprints.io/data-breaches/yum-brands-ransomware-data-breach/</link>
      <pubDate>Thu, 06 Apr 2023 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/data-breaches/yum-brands-ransomware-data-breach/</guid>
      <description>Executive Summary In January 2023, Yum! Brands, which owns KFC, Taco Bell, and Pizza Hut, fell victim to a ransomware attack, resulting in a data breach. This incident compromised corporate and employee data and was publicly disclosed by Yum! Brands in April 2023. Formal notifications to employees and potentially affected individuals about the data compromise began around the same time.&#xA;Discovery and Disclosure The ransomware attack was first identified in January 2023.</description>
    </item>
    <item>
      <title>Google Fi Data Breach Linked to T-Mobile Incident</title>
      <link>https://securityblueprints.io/data-breaches/google-fi-data-breach-linked-to-t-mobile-incident/</link>
      <pubDate>Wed, 01 Feb 2023 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/data-breaches/google-fi-data-breach-linked-to-t-mobile-incident/</guid>
      <description>Executive Summary Incident Overview: In February 2023, Google Fi suffered a data breach due to vulnerabilities originating from a prior T-Mobile security incident. This breach exposed Google Fi customers&amp;rsquo; phone numbers and related technical details, posing significant risks such as SIM swap attacks and unauthorized account activities (source ).&#xA;Key Dates: The association with T-Mobile&amp;rsquo;s broader data breach was identified on January 19, 2023. Affected individuals received notifications in early February 2023 (source ).</description>
    </item>
    <item>
      <title>NCB Management Services Data Breach February 2023</title>
      <link>https://securityblueprints.io/data-breaches/ncb-management-services-data-breach-february-2023/</link>
      <pubDate>Wed, 01 Feb 2023 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/data-breaches/ncb-management-services-data-breach-february-2023/</guid>
      <description>Executive Summary In February 2023, NCB Management Services experienced a significant data breach due to an unauthorized system compromise, exposing sensitive personal and financial information. The breach was detected on February 4, 2023, affecting clients associated with major financial institutions including Capital One, Bank of America, and TD Bank.&#xA;Severity of the Impact The breach compromised data for over 1 million individuals, with specific numbers varying by institution: approximately 16,779 Capital One customers and nearly 495,000 Bank of America customers were directly impacted.</description>
    </item>
    <item>
      <title>Norton Life Lock Credential Stuffing Data Breach</title>
      <link>https://securityblueprints.io/data-breaches/norton-life-lock-credential-stuffing-data-breach/</link>
      <pubDate>Fri, 13 Jan 2023 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/data-breaches/norton-life-lock-credential-stuffing-data-breach/</guid>
      <description>Executive Summary In January 2023, Norton LifeLock reported a data breach due to a credential stuffing attack, allowing attackers to exploit previously compromised passwords to access over 6,000 customer accounts. The incident highlighted vulnerabilities within password management services, raising concerns about the security of stored credentials [source1 ].&#xA;Severity of Impact The breach exposed personal data, including names, phone numbers, and mailing addresses, and potentially compromised credentials stored in the Norton Password Manager.</description>
    </item>
    <item>
      <title>Activision HR Data Breach 2023</title>
      <link>https://securityblueprints.io/data-breaches/activision-hr-data-breach-2023/</link>
      <pubDate>Sun, 04 Dec 2022 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/data-breaches/activision-hr-data-breach-2023/</guid>
      <description>Executive Summary In December 2022, Activision, a leading video game developer, encountered a data breach caused by a sophisticated SMS phishing attack targeting a Human Resources (HR) employee. This breach resulted in unauthorized access to internal data, including employee names, phone numbers, email addresses, job titles, and workplace locations. Despite discrepancies regarding the exact public disclosure date, the breach became widely acknowledged in February 2023, highlighting substantial risks to employee data security [TechCrunch ] [Intrix ].</description>
    </item>
    <item>
      <title>Los Angeles Unified School District (LAUSD) Ransomware Breach</title>
      <link>https://securityblueprints.io/data-breaches/los-angeles-unified-school-district-lausd-ransomware-breach/</link>
      <pubDate>Thu, 01 Sep 2022 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/data-breaches/los-angeles-unified-school-district-lausd-ransomware-breach/</guid>
      <description>Executive Summary In September 2022, the Los Angeles Unified School District (LAUSD), the second-largest school district in the United States, experienced a significant ransomware attack orchestrated by the Vice Society gang. This incident, detected over the Labor Day holiday weekend, compromised more than 1,000 schools, affecting approximately 600,000 students and staff members. Sensitive data, including psychological evaluations and Social Security numbers, was exposed and disseminated on the dark web following LAUSD&amp;rsquo;s decision not to pay the ransom source .</description>
    </item>
    <item>
      <title>Microsoft Exchange Server Breach</title>
      <link>https://securityblueprints.io/data-breaches/microsoft-exchange-server-breach/</link>
      <pubDate>Sun, 03 Jan 2021 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/data-breaches/microsoft-exchange-server-breach/</guid>
      <description>Executive Summary In January 2021, Microsoft Exchange email servers were targeted in a significant cyberattack that exploited multiple zero-day vulnerabilities, affecting over 30,000 organizations in the United States. Initially detected by Volexity on January 3, 2021, the breach was publicly acknowledged by Microsoft on March 2, 2021, upon releasing emergency patches (source , source ).&#xA;Severity of the Impact Globally, the breach compromised up to 250,000 servers, impacting critical sectors such as government, banking, and infrastructure, thereby posing risks to operational integrity and data confidentiality (source , source ).</description>
    </item>
    <item>
      <title>Twitter 2020 Data Breach Incident</title>
      <link>https://securityblueprints.io/data-breaches/twitter-2020-data-breach-incident/</link>
      <pubDate>Wed, 15 Jul 2020 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/data-breaches/twitter-2020-data-breach-incident/</guid>
      <description>Executive Summary In July 2020, a critical cybersecurity breach, termed the Twitter 2020 Data Breach, occurred, wherein a 17-year-old hacker, Graham Ivan Clark, along with accomplices, exploited vulnerabilities in Twitter’s security infrastructure. They gained unauthorized access to Twitter&amp;rsquo;s internal network, commandeering numerous high-profile accounts to disseminate a Bitcoin scam.&#xA;Key Dates Breach Occurrence: July 15, 2020 Public Disclosure: July 15, 2020 Severity of Impact The breach affected highly influential accounts such as those of Barack Obama and Elon Musk, resulting in fraudulent tweets promoting a Bitcoin scam.</description>
    </item>
    <item>
      <title>Norsk Hydro Ransomware Attack - March 2019</title>
      <link>https://securityblueprints.io/data-breaches/norsk-hydro-ransomware-attack/</link>
      <pubDate>Tue, 19 Mar 2019 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/data-breaches/norsk-hydro-ransomware-attack/</guid>
      <description>Executive Summary In March 2019, Norsk Hydro, a significant global aluminum producer, encountered a ransomware attack via the LockerGoga malware. This attack caused substantial disruptions across 160 locations, impacting over 20,000 systems worldwide, and forced the company to shift to manual operations (source ).&#xA;Key Dates Discovery and Disclosure Date: March 19, 2019 Severity of Impact The attack resulted in significant financial repercussions, with initial losses estimated at $40 million USD within the first week, subsequently summing to over 350 million Norwegian krone (source ).</description>
    </item>
    <item>
      <title>2017 Equifax Data Breach</title>
      <link>https://securityblueprints.io/data-breaches/2017-equifax-data-breach/</link>
      <pubDate>Sat, 29 Jul 2017 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/data-breaches/2017-equifax-data-breach/</guid>
      <description>Executive Summary The 2017 Equifax data breach marked a critical event in data security, caused by exploiting a known vulnerability, CVE-2017-5638, in the Apache Struts web application framework. Unauthorized access led to the exposure of sensitive information of approximately 145.5 million individuals.&#xA;Severity of Impact This breach was one of the largest in history, significantly affecting Personally Identifiable Information (PII), including names, Social Security numbers, birth dates, and, in certain instances, driver&amp;rsquo;s license numbers and credit card data.</description>
    </item>
    <item>
      <title>NotPetya Ransomware Attack</title>
      <link>https://securityblueprints.io/data-breaches/notpetya-ransomware-attack/</link>
      <pubDate>Tue, 27 Jun 2017 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/data-breaches/notpetya-ransomware-attack/</guid>
      <description>Executive Summary The NotPetya ransomware attack in June 2017 is considered one of the most destructive cyber incidents on record. Originating through a compromised update of MeDoc, a Ukrainian accounting software, the malware propagated swiftly, impacting organizations across more than 65 countries within hours of being detected on June 27, 2017. The event highlighted significant vulnerabilities in software supply chains.&#xA;Severity of the Impact NotPetya inflicted damages exceeding $10 billion globally, with significant disruptions in healthcare, logistics, and government sectors.</description>
    </item>
    <item>
      <title>Anthem Data Breach Incident Analysis</title>
      <link>https://securityblueprints.io/data-breaches/anthem-data-breach-incident-analysis/</link>
      <pubDate>Wed, 04 Feb 2015 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/data-breaches/anthem-data-breach-incident-analysis/</guid>
      <description>Executive Summary The data breach at Anthem Inc. in 2015 stands as a critical incident in healthcare cybersecurity, involving unauthorized access to approximately 78.8 million records. The breach was disclosed publicly on February 4, 2015, illustrating significant weaknesses within the protection of Personal Identifiable Information (PII) in healthcare systems. This incident underscores a vital need for enhanced cybersecurity measures in the sector, emphasizing the risks associated with large-scale data compromises.</description>
    </item>
    <item>
      <title>JPMorgan Chase Data Breach</title>
      <link>https://securityblueprints.io/data-breaches/jpmorgan-chase-data-breach/</link>
      <pubDate>Sun, 01 Jun 2014 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/data-breaches/jpmorgan-chase-data-breach/</guid>
      <description>Executive Summary In June 2014, JPMorgan Chase became the target of a significant data breach, compromising data from over 76 million households and 7 million small businesses. The breach, discovered in July and publicly disclosed in September 2014, highlighted substantial deficiencies in the bank’s cybersecurity framework (source ).&#xA;Severity of Impact Approximately 83 million accounts were affected, with exposed data including names, addresses, phone numbers, and email addresses. However, no financial data or Social Security numbers were compromised, reducing the risk of direct financial fraud, yet increasing chances for phishing and identity theft (source ).</description>
    </item>
    <item>
      <title>Home Depot Data Breach April 2014</title>
      <link>https://securityblueprints.io/data-breaches/home-depot-data-breach-april-2014/</link>
      <pubDate>Tue, 01 Apr 2014 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/data-breaches/home-depot-data-breach-april-2014/</guid>
      <description>Executive Summary In April 2014, Home Depot faced a significant data breach resulting in the theft of over 56 million payment card records. Custom-built malware targeted Home Depot&amp;rsquo;s point-of-sale (POS) systems, affecting customers across the United States and Canada. The breach was detected in September 2014.&#xA;Severity of Impact The breach is among the largest recorded in retail history, with anticipated financial consequences projected to potentially reach $179 million, encompassing immediate response and legal costs.</description>
    </item>
    <item>
      <title>TJX Companies Inc. Data Breach</title>
      <link>https://securityblueprints.io/data-breaches/tjx-companies-inc.-data-breach/</link>
      <pubDate>Fri, 01 Jul 2005 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/data-breaches/tjx-companies-inc.-data-breach/</guid>
      <description>Executive Summary The TJX Companies Inc., a major retailer with brands such as TJ Maxx and Marshalls, suffered a significant data breach disclosed in January 2007, affecting approximately 94 million records. The breach revealed critical vulnerabilities in TJX&amp;rsquo;s data protection protocols and stands as one of the largest security incidents in retail history.&#xA;Key Dates Initial Intrusion: July 2005 Discovery: December 2006 Public Disclosure: January 17, 2007 (source ) Severity of Impact The data breach involved 94 million records, including credit and debit card data and personal information such as driver&amp;rsquo;s license numbers.</description>
    </item>
  </channel>
</rss>
