The Breach News

Extensive U.S. Property and Demographic Database Uncovers 200 Million Records

Massive Data Exposure Affects Over 200 Million US Citizens In a significant breach of security, more than 200 million records containing sensitive information about US residents were left unprotected in an unsecured online database. The database, hosted on Google Cloud, required no password or authentication for access, making it vulnerable…

Read MoreExtensive U.S. Property and Demographic Database Uncovers 200 Million Records

ENISA Now Serves as a CVE Program Root

Government, Industry Specific European Cybersecurity Agency Takes on Role in CVE Program Akshaya Asokan (asokan_akshaya) • November 20, 2025     Image: ENISA/Shutterstock/ISMG The European Union Agency for Cybersecurity (ENISA) is set to enhance its role in overseeing vulnerability announcements throughout the EU. This development follows ENISA’s recognition as a…

Read MoreENISA Now Serves as a CVE Program Root

Salesforce Probes Data Breach Impacting Customers via Gainsight Applications

The incident involved applications published by Gainsight that connect to Salesforce. Incident Overview Salesforce is currently investigating a data breach that has potentially compromised customer information through applications developed by Gainsight, a notable provider of customer relationship management tools. In a statement, Salesforce indicated that the breach involved “Gainsight-published applications…

Read MoreSalesforce Probes Data Breach Impacting Customers via Gainsight Applications

Four Individuals Indicted in Suspected Scheme to Smuggle Supercomputers and Nvidia Chips to China

Recent Cybersecurity Developments: Allegations of Export Control Violations In a notable legal proceeding, recent allegations have emerged regarding an individual identified as Li, who is accused of engaging in illegal activities tied to the export of restricted technology. Authorities revealed that text messages retrieved from Li suggest he was boasting…

Read MoreFour Individuals Indicted in Suspected Scheme to Smuggle Supercomputers and Nvidia Chips to China

Virgin Media Data Breach Exposes Information of 900,000 Customers

In a significant incident reported recently, Virgin Media, a UK-based telecommunications provider, announced a data leak that has compromised the personal information of approximately 900,000 customers. This revelation coincided with similar news from US-based telecom giant T-Mobile, which also disclosed a security breach involving its own data. Contrary to the…

Read MoreVirgin Media Data Breach Exposes Information of 900,000 Customers

ShinyHunters Compromise Salesforce Accounts Through Gainsight Applications

3rd Party Risk Management, Cybercrime, Fraud Management & Cybercrime Salesforce Revokes Gainsight Authentication Tokens Akshaya Asokan (asokan_akshaya) • November 20, 2025 Image: The Bold Bureau/Shutterstock Salesforce, a leading customer relationship management platform based in the United States, has informed customers of potential data theft by hackers exploiting vulnerabilities in a…

Read MoreShinyHunters Compromise Salesforce Accounts Through Gainsight Applications

Hackers Leverage Magento Vulnerability to Extract Payment Information from E-Commerce Sites

A significant vulnerability has been identified in Magento, with threat actors exploiting this flaw to implant a persistent backdoor in e-commerce platforms. This attack leverages the CVE-2024-20720 vulnerability (CVSS score: 9.1), categorized by Adobe as indicative of “improper neutralization of special elements,” which can lead to arbitrary code execution. The…

Read MoreHackers Leverage Magento Vulnerability to Extract Payment Information from E-Commerce Sites