Click any tag below to further narrow down your results
+ email-spoofing
(1)
+ wildlife-licensing
(1)
+ code-leak
(1)
+ secret-scanning
(1)
+ hardware-exploit
(1)
+ credential-theft
(1)
+ kyushu-electric
(1)
+ customer-data
(1)
+ utilities
(1)
+ physical-security
(1)
+ security-tools
(1)
+ anthropic
(1)
+ supply-chain
(1)
+ ai-attacks
(1)
+ student-data
(1)
Links
The Texas Parks and Wildlife Department says a third-party vendor that handles hunting and fishing licenses was hacked, exposing driver’s license numbers, passport numbers and contact details for over 3 million Texans. Permanent ID data can’t be reset, putting victims at long-term risk of identity fraud. Threat intelligence links this incident to similar attacks on other state wildlife licensing platforms, highlighting vendor security gaps.
- A hack of a third-party TPWD vendor exposed driver's license numbers, passport numbers, and contact info for over 3 million Texans, with conflicting reports on whether SSNs were also included.
- The same hacker ("Wikkid") was selling this data on dark-web forums before the breach was disclosed, and similar attack patterns have hit Virginia's wildlife licensing system, suggesting a broader vulnerability across shared vendor platforms (Aspira Connect, PayIt Outdoors, Tyler Technologies).
- No federal standard requires these licensing vendors to maintain baseline security, and state contracts often skip mandatory security audits.
- Affected Texans can get free credit monitoring through Kroll until September 14, 2026, but since driver's license and passport numbers can't be reset like passwords, the exposure creates long-term identity fraud risk.
This daily roundup covers Fortinet’s FortiBleed campaign exposing 86,000 device credentials, a Texas hunting-license vendor breach affecting 3 million records, and an unpatchable BootROM exploit on Apple A12/A13 chips. It also highlights GitHub’s context-aware secret scanning, the Novo Nordisk code leak via a stolen GitHub token, and other emerging tools and vulnerabilities.
- FortiBleed exposed 86,000+ valid Fortinet credentials across 194 countries via 1.16 billion login attempts against 320,000 FortiGate devices, with hashes cracked on a 45-GPU cluster.
- A Texas hunting/fishing license vendor breach leaked driver's license and passport numbers for 3.09 million people, already being sold by a threat actor linked to a prior Virginia wildlife breach.
- The unpatchable "usbliter8" BootROM exploit affects Apple A12/A13 chips (iPhone XS to iPhone 11), installing a restart-persistent handler that downgrades security and boots unsigned code.
- GitHub's new context-aware LLM secret scanning cuts false positives by over 75% by isolating code paths where secrets feed into API calls, auth headers, or database clients.
- FulcrumSec stole a GitHub PAT to exfiltrate 1.3 TB from Novo Nordisk, including the Ozempic formula and clinical-trial data for 11,500 patients, leaking 264 GB after a refused $25 million ransom.
A hacking group breached the University of Nottingham’s PeopleSoft student records system and stole over 40 GB of data on 454,600 current and former students, including names, addresses, financial details and academic records. The university has reported the incident to the UK Information Commissioner’s Office and Action Fraud, while ShinyHunters claims responsibility and posted the stolen archive.
- ShinyHunters stole 40GB of data on 454,600 current and former Nottingham students, including financial details, credit card info, passport numbers, and academic records.
- The group exploited zero-day and older vulnerabilities in Oracle PeopleSoft, hitting over 100 organizations in this campaign, with Oracle yet to confirm active exploitation.
- Similar PeopleSoft-linked breaches recently hit Oxford University's CareerConnect and Instructure's Canvas LMS.
This daily roundup covers a 40 GB data breach at the University of Nottingham, a lost-drive incident exposing 10.9 million Japanese utility customers, and a proof-of-concept Exchange spoofing flaw. It also highlights automated AI-driven attack research, supply-chain toolkits on GitHub, and new product launches for dependency patching and taint analysis.
- ShinyHunters exploited a zero-day gadget chain in University of Nottingham's PeopleSoft to steal 40GB of data on 454,600 students, including passport numbers and disability details.
- Kyushu Electric Power lost a physical backup drive exposing personal and usage data for 10.9 million customers.
- InfoGuard's "Ghost-Sender" exploit spoofs any Exchange Online address (even CEO/noreply) via a one-line PowerShell script, bypassing SPF, DKIM, and DMARC.
- A researcher earned over $500,000 in bug bounties using an AI-driven fuzzer to scrape thousands of Google API keys and find leaky internal-only endpoints.
Kyushu Electric Power misplaced an external backup drive storing personal details for up to 10.9 million customers after leaving it in an unlocked server-room cabinet. The drive contained names, addresses, usage data and phone numbers but no financial records, and the firm has reported the loss to police and regulators while investigating internal access.
- Kyushu Electric lost a backup drive holding personal data for up to 10.9 million customer accounts after it vanished from a locked cabinet in a secure server room, discovered missing a month after being stored (April 27 to May 26).
- The drive contained names, addresses, usage data, phone numbers, and retail electricity provider details, but no financial information.
- The company questioned all 57 people who had accessed the server room, filed a police report, and notified regulators including Japan's Personal Information Protection Commission.
- METI has ordered a full incident report with countermeasures by July 8, and it remains unclear whether the drive was stolen or lost through another security failure.
Security researchers found that Anthropic’s new Mythos AI model was reachable by unauthorized users through exposed API endpoints. This lapse could expose sensitive prompts and responses, prompting Anthropic to investigate and strengthen its access controls.
- Anthropic's Mythos AI model was accessed by unauthorized users after API keys leaked onto public Slack channels
- Anthropic rotated all impacted keys, shut down mismatched sessions, and tightened authentication after detecting unusual traffic
- The company hasn't disclosed how many keys leaked or how many unauthorized calls were made
- Some enterprise customers paused rollouts pending clearer safeguards on key security