#DataExposure

2026-02-06

Substack has disclosed a security incident involving unauthorized access to limited user data, reportedly obtained through scraping activity described by the threat actor as “noisy.”

The company states that credentials and financial information were not affected, and that mitigations were implemented quickly after discovery. Users have been advised to remain cautious of potential phishing attempts.

From an infosec perspective, this incident underscores challenges around detection timing, data exposure via scraping, and post-incident communication.

How should platforms better monitor and respond to large-scale scraping risks?

Source: securityweek.com/substack-disc

Engage in the discussion and follow @technadu for measured cybersecurity analysis.

#Infosec #DataExposure #Scraping #IncidentResponse #CyberRisk #TechNadu #SecurityOperations

Substack Discloses Security Incident After Hacker Leaks Data
Yonhap Infomax Newsinfomaxkorea
2026-02-06

Naver Corp. CEO Choi Soo-yeon apologized after a technical update exposed past Knowledgei answers of public figures, assuring prompt resolution and full cooperation with regulators.

en.infomaxai.com/news/articleV

2026-01-28

SoundCloud’s December 2025 breach has been added to HIBP, confirming exposure of ~29.8M user accounts.

The incident stemmed from unauthorized access to an internal service dashboard that enabled correlation of email addresses with public profile data. No credentials or financial information were compromised, but the case highlights how internal tooling can expand the attack surface.

What practical controls help reduce correlation risk in large platforms?
Source: cyberinsider.com/soundcloud-br

Share insights and follow TechNadu for independent InfoSec coverage.

#InfoSec #SoundCloud #HIBP #DataExposure #PrivacyEngineering #CyberRisk #SecurityOperations

SoundCloud breach added to HIBP, 29.8 million accounts exposed
2026-01-12

The reported BreachForums database exposure illustrates a recurring pattern in underground ecosystems: infrastructure weaknesses outweigh perceived anonymity.

Key considerations:
• Metadata remains a critical risk vector
• Forum resilience often masks fragile backends
• Legal and reputational fallout can be long-lasting

This incident reinforces why data minimization and secure configuration matter - regardless of intent or audience.

Source: cybersecuritynews.com/breachfo

Join the discussion and follow @technadu for fact-based cybersecurity reporting.

#InfoSec #ThreatIntel #DarkWeb #DataExposure #CyberRisk #OperationalSecurity

BreachForums Hack: Hackers Expose All User Records from Popular Dark Web Forum
2025-12-08

Healthcare staff data is being exposed at alarming rates — protecting patients starts with protecting those who care for them. 🩺🔓 #HealthDataSecurity #DataExposure

helpnetsecurity.com/2025/12/05

2025-11-19

Researchers enumerated 3.5B WhatsApp phone numbers through the platform’s contact-discovery feature, revealing public profile photos and text for millions of users. Meta applied rate-limiting after the disclosure and says no non-public data was exposed.
This case raises important questions about phone numbers as identifiers and long-term privacy safeguards.
Share your insights & follow for more security-focused analysis.

#InfoSec #CyberSecurity #Privacy #DataExposure #WhatsApp #SecurityResearch #DigitalIdentity #TechNadu

Researchers enumerated 3.5B WhatsApp phone numbers through the platform’s contact-discovery feature, revealing public profile photos and text for millions of users.
2025-11-05

Oops… Ernst & Young accidentally exposed 4TB of data on Azure — a reminder that even experts can slip when cloud hygiene falters. ☁️🧾 #CloudSecurity #DataExposure

securityaffairs.com/184062/dat

Tommy Kavanaghancatdubh@mastodon.ie
2025-11-01

4TB and no client or personal data eh? 👏🏻

infosec.exchange/@technadu/115 - A 4TB SQL Server backup tied to EY was exposed on Microsoft Azure, discovered by Neo Security during an asset mapping scan.

EY remediated promptly, confirming no client or personal data was affected.

#CyberSecurity #EY #DataExposure #Azure #Infosec #ThreatIntel #DataProtection #CloudSecurity

2025-11-01

A 4TB SQL Server backup tied to EY was exposed on Microsoft Azure, discovered by Neo Security during an asset mapping scan.

The file’s naming pattern and metadata indicated it was a full unencrypted database dump - a critical visibility gap in cloud storage hygiene.

EY remediated promptly, confirming no client or personal data was affected.

As botnets continuously scan public cloud assets, how can enterprises proactively detect these exposures before attackers do?

💬 Join the discussion & follow @technadu for deeper security intelligence.

#CyberSecurity #EY #DataExposure #Azure #Infosec #ThreatIntel #DataProtection #CloudSecurity

EY
2025-10-09

compliance-savvy narratives to amplify pressure and market impact. Defenders must assume both data leakage and reputational/legal escalation vectors when triaging similar claims. #ransomNews #redhat #dataexposure

TechCrunch | Startup and Technology Newstechcrunch.com@web.brid.gy
2025-10-04
2025-10-02

⚠️ WestJet breach leaks travel data of 12M The Canadian airline WestJet suffered a data breach exposing flight itineraries, passport info, email addresses and more for 12 million customers. The airline is notifying affected individuals. #ransomNews #WestJetBreach #DataExposure

TechCrunch | Startup and Technology Newstechcrunch.com@web.brid.gy
2025-09-26
2025-09-09

Salesloft confirms breach via GitHub → attackers stole Drift OAuth tokens & compromised Salesforce integrations.

Victims include Cloudflare, Zscaler, Palo Alto, Tenable, Rubrik, Proofpoint, Elastic & more (700+ orgs).
Experts: Non-human identities like API tokens are the next security blind spot.

💬 How is your org tackling API token risks? Follow @technadu for updates.

#Salesloft #GitHubBreach #CyberAttack #DataExposure #ThreatActor #CyberSecurity #SupplyChainRisk

salesloft,
2025-09-02

🚨 CVE-2025-49870: High-risk SQLi in WordPress Paid Membership Subscriptions plugin (10K+ sites).
✅ Fixed in v2.15.2
❌ Exploitable without login
💥 Attackers could query or tamper with DB data
Still shocking to see SQL injection so prevalent in 2025.
💬 Are devs overlooking basics, or is plugin culture the real issue?
🔔 Follow @technadu for more threat intel.

#WordPress #SQLInjection #Vulnerability #PluginSecurity #WebSecurity #DataExposure #CMSecurity

Wordpress
2025-08-27

🚨 Security researcher finds 1,300+ exposed TeslaMate servers leaking
Tesla data — from trip locations to charging times.

⚡ “You’re unintentionally sharing your car’s movements with the world.” – Seyfullah Kiliç, SwordSec
💬 Who’s responsible — open-source devs or end-users?

🔎 Follow @technadu for more #infosec & #privacy insights.

#Tesla #CyberSecurity #DataExposure

tesla
2025-07-15

👜 Louis Vuitton suffers global data breach impacting customers in the UK, South Korea, and Turkey. Luxury comes at a cost—especially when data is on the line.
#LuxuryBreach #DataExposure 🌐🔓

securityaffairs.com/179908/dat

2025-07-08

🔐 94% of enterprises faced API security incidents in the past year—yet only 36% have dedicated API security solutions. Time to rethink your strategy.
#APISecurity #DataExposure 🚧📊

helpnetsecurity.com/2025/07/08

Client Info

Server: https://mastodon.social
Version: 2025.07
Repository: https://github.com/cyevgeniy/lmst