1 link tagged with all of: data-breach + code-leak + hardware-exploit
Click any tag below to further narrow down your results
Links
This daily roundup covers Fortinet’s FortiBleed campaign exposing 86,000 device credentials, a Texas hunting-license vendor breach affecting 3 million records, and an unpatchable BootROM exploit on Apple A12/A13 chips. It also highlights GitHub’s context-aware secret scanning, the Novo Nordisk code leak via a stolen GitHub token, and other emerging tools and vulnerabilities.
- FortiBleed exposed 86,000+ valid Fortinet credentials across 194 countries via 1.16 billion login attempts against 320,000 FortiGate devices, with hashes cracked on a 45-GPU cluster.
- A Texas hunting/fishing license vendor breach leaked driver's license and passport numbers for 3.09 million people, already being sold by a threat actor linked to a prior Virginia wildlife breach.
- The unpatchable "usbliter8" BootROM exploit affects Apple A12/A13 chips (iPhone XS to iPhone 11), installing a restart-persistent handler that downgrades security and boots unsigned code.
- GitHub's new context-aware LLM secret scanning cuts false positives by over 75% by isolating code paths where secrets feed into API calls, auth headers, or database clients.
- FulcrumSec stole a GitHub PAT to exfiltrate 1.3 TB from Novo Nordisk, including the Ozempic formula and clinical-trial data for 11,500 patients, leaking 264 GB after a refused $25 million ransom.