Data Breaches

Updates and analysis on data breaches.

Posts

Self-driving car camera view with adversarial road sign

Road Signs Can Hijack Self-Driving Cars

12 February 2026 · 5 min read

Researchers at UC Santa Cruz and Johns Hopkins hijacked self-driving cars and autonomous drones using commands written on road signs. AI systems followed illicit instructions with success rates up to 95.5% in tests.

Read more
Windscribe VPN server infrastructure

Dutch Police Seized Windscribe Server Without Warrant

7 February 2026 · 3 min read

Dutch authorities seized a Windscribe VPN server without a warrant and told the company they'd return it after analysis. Windscribe disclosed the incident publicly on X. Dutch police have issued no statement and referenced no judicial warrant.

Read more
Exposed database API keys and credentials

Researcher Found Moltbook Database Key in Minutes

6 February 2026 · 2 min read

Moltbook, a social media platform for AI agents, exposed its entire production database containing user secrets and personally identifying information within days of launch. The creator bragged on X that AI wrote all the code. Researcher Gal Nagli found the database API key exposed on the front end in minutes.

Read more
Google AI infrastructure server room

Former Google Engineer Convicted of Stealing AI Secrets for China

3 February 2026 · 5 min read

Former Google engineer Linwei Ding was convicted on 14 counts for stealing over 2,000 pages of AI trade secrets and transferring them to Chinese companies. He uploaded confidential files to his personal cloud while secretly founding a Chinese AI startup and pitching investors using stolen Google technology.

Read more
AI stuffed dinosaur toy with chat interface

Don't Buy Internet-Connected Toys For Your Kids

2 February 2026 · 4 min read

Security researchers found that Bondu's AI dinosaur toys left over 50,000 chat logs exposed to anyone with a Gmail account. Children's names, birth dates, family details, and every private conversation sat on a web portal anyone could access without hacking.

Read more
Exposed AI server infrastructure map

175,000 Open AI Servers Found Online With No Security

30 January 2026 · 3 min read

SentinelOne SentinelLABS and Censys discovered 175,000 publicly accessible Ollama AI servers operating without authentication across 130 countries. The servers form a massive unmanaged layer of AI infrastructure running outside corporate security controls.

Read more
INTERPOL Red Notice warning symbol

Black Basta Ransomware Leader on EU Most Wanted List

19 January 2026 · 2 min read

Oleg Nefedov, a 35-year-old Russian national, has been added to the EU Most Wanted and INTERPOL Red Notice lists as the alleged leader of Black Basta ransomware. Ukrainian and German authorities identified two Ukrainian accomplices who worked as password crackers for the group.

Read more
Chrome Web Store malicious extension warning screen

Chrome Extensions Stole Enterprise Credentials From 2,300 Users

18 January 2026 · 2 min read

Malicious Chrome extensions posing as enterprise productivity tools stole authentication credentials from Workday, NetSuite, and SAP SuccessFactors users. The extensions extracted session cookies every 60 seconds and blocked access to security management pages.

Read more
Flock Safety camera pointed at playground

Flock Safety Exposes Children to Creeps

24 December 2025 · 3 min read

Flock Safety exposed dozens of Condor cameras filming unattended children and lone adults directly to the internet. Predators accessed live video and full archives with no login or trace.

Read more
AI browser security warning

AI Browsers Are Unsafe by Design

23 December 2025 · 2 min read

AI browsers combine instruction-following models with direct access to sensitive systems, creating failure modes vendors admit cannot be eliminated.

Read more
Cloud cryptomining abuse

AWS Accounts Hijacked for Cryptomining

18 December 2025 · 3 min read

Attackers are using stolen AWS credentials to spin up massive cryptomining workloads within minutes, draining accounts without exploiting any AWS vulnerability.

Read more
Browser extension surveillance diagram

Your AI Chats Were Never Private

16 December 2025 · 3 min read

A Google featured browser extension with millions of users silently intercepted AI chats across major platforms and exported them to analytics servers as a business model.

Read more
malware loader memory evasion graphic

Ransomware’s New Secret Weapon

9 December 2025 · 2 min read

Shanya proves stealth is now a commodity. Ransomware gangs no longer build their own evasion. They rent it and walk straight past EDR tools still relying on a broken Windows trust model.

Read more
Broken VPN icons scattered

The VPN Industry’s Rot Laid Bare

8 December 2025 · 4 min read

A new peer reviewed study shows enormous VPN brands lying about ownership, hard coding encryption keys, and quietly piping user data through insecure tunnels. The rot is systemic and it has been hidden behind Singapore shell companies and marketing gloss.

Read more
AI coding tool security diagram

IDEsaster Exposes 30 Flaws in AI Coding Tools

7 December 2025 · 3 min read

Thirty vulnerabilities in AI coding tools show how prompt injection and auto approved actions can escalate into data theft and remote code execution. Every major AI IDE tested was vulnerable.

Read more
WhatsApp data breach concept image

WhatsApp leak exposes 3.5 billion users

22 November 2025 · 1 min read

Researchers scraped 3.5 billion WhatsApp profiles using WhatsApp’s own contact discovery feature. No hack. No breach. Just a system that exposes too much data by design.

Read more