Beacon CRM Breach Exposes UK Charities
A cyberattack on the CRM provider Beacon has resulted in the potential theft of sensitive database backups for numerous UK charities.
23 results for “theft”
A cyberattack on the CRM provider Beacon has resulted in the potential theft of sensitive database backups for numerous UK charities.
New data reveals a surge in violent physical thefts targeting cryptocurrency holders, with millions lost in the first half of 2026.
A Canadian national has admitted to his role in a massive 2024 campaign that compromised over 165 major corporate Snowflake accounts.
Threat actors are hijacking hotel network gateways to push fraudulent software updates and capture user credentials via deceptive portals.
A health IT firm is notifying over 350,000 individuals following an unauthorized access incident within its AWS environment.
A critical vulnerability in the vault-secrets-webhook allows unauthorized outbound requests and potential theft of cluster-wide service account tokens.
An Illinois man was sentenced to 76 months in federal prison for orchestrating a campaign to compromise 750 social media accounts.
New research details how threat actors are ditching delayed credential harvesting for live, session-based account hijacking.
Threat actors are exploiting a severe vulnerability in PTC Windchill and FlexPLM to exfiltrate sensitive enterprise product data.
A critical vulnerability in Budibase allows unauthenticated attackers to steal stored REST datasource credentials via a cross-origin request leak.
A March network intrusion at logistics firm OnTrac has triggered data protection warnings for affected customers.
A critical vulnerability in LightRAG allows unauthorized cross-origin requests, potentially exposing sensitive documents and knowledge graph data.
A cyberattack on the billing software provider has resulted in the theft of employee, customer, and partner records.
Time is running out for victims of the 2024 Fidelity data breach to claim their share of a $2.5 million settlement fund.
A newly identified Go-based botnet is pivoting from simple compute-hijacking to harvesting cloud credentials from exposed AI services.
North Korean threat actors are using fake coding tests and steganography to compromise developer systems and steal sensitive data.
ACR Stealer exploits user-executed commands to siphon session tokens and files, bypassing traditional software vulnerabilities.
Compromised AsyncAPI and Jscrambler packages expose developers to credential theft via automated malicious injection.
New updates to X's Grok model aim to reroute ad revenue from content thieves back to original creators using automated detection.
New findings reveal that compromised credentials are now the primary catalyst for ransomware breaches, eclipsing software flaws.
Synopsys refutes claims of a massive database breach after a ransomware group alleged the theft of sensitive Bosch data.
A breach at Nelnet Servicing has compromised the personal information of millions, creating a prime target for future phishing.
A new subscription-based phishing service leverages device code theft and AI to bypass traditional security defenses.