Breaches — Page 7

DHS Probes Intrusion Into HSIN, the Federal Info-Sharing Platform
The Homeland Security Information Network was compromised, according to the department. Attribution remains open. The exposure question is bigger than the intrusion itself.

NAIC Says ShinyHunters Walked Out With Public Data and Stale Logs After PeopleSoft Zero-Day Hit
The regulator-of-regulators confirms an Oracle PeopleSoft zero-day was the entry point, but disputes the extortion crew's claims about what was taken.

Klue Breach Compromises Salesforce Data via OAuth Token Theft
Unauthorized access exposes CRM data; threat actors exploit legacy credentials.

Klue Confirms OAuth Token Theft as 'Icarus' Crew Stakes Public Claim
The market intelligence vendor's disclosure adds another name to the lengthening list of Salesforce-adjacent SaaS breaches tied to stolen OAuth credentials.

DBIR 2026: Vulnerabilities and Ransomware Shape Incident Readiness
Verizon's latest report reveals exploitation of vulnerabilities and rising ransomware as key challenges. Preparation is crucial.

Tchap Account Takeover Exposes 73,000 French Government Users
France's sovereign messaging platform wasn't broken — a user was. Social engineering got an attacker inside, and unencrypted public rooms did the rest.

Ultrahuman Data Leak, Ransomware Tradecraft, and a Browser That Mines Your CPU: The Week's Overlooked Stories
Three stories that didn't dominate the feed — a wearable-tech data exposure, a dissection of The Gentlemen ransomware, and Hola Browser quietly bundling a cryptominer.

ShinyHunters Hits Canvas LMS: 275 Million Records, a Defaced Login Page, and a Free-Tier Attack Vector
The extortion group's May 2026 strike on Instructure exposed how peripheral, lower-security environments can become the entry point that compliance badges never covered.

Dashlane Says Brute-Force Run Pulled Encrypted Vaults From Under 20 Accounts
An unknown actor hammered 2FA on personal-tier accounts on May 31, 2026. The company says the blast radius is small. The vaults stay encrypted.

The Login Page That Demanded a Ransom
ShinyHunters defaced Canvas mid-finals week, taking the learning platform offline and exposing what one researcher calls an eight-month attack arc against Instructure.

Lithuania Probes Foreign Hand in Leak of 600,000-Plus National Register Records
Lithuanian authorities suspect state-linked actors after a data breach exposed more than 600,000 entries from government population and registration databases.