Skip to content
Hmmnm brand header logo displayed prominently across the top of the webpage
  • Home
  • Blog
  • About Us
  • Contact
  • Services
  • Products
  • Cybersecurity Learning Paths
  • Toggle website search
Press Escape to close the search panel.
Menu Close
  • Home
  • Blog
  • About Us
  • Contact
  • Services
  • Products
  • Cybersecurity Learning Paths
  • Toggle website search
Search this website

data breach

  1. Home>
  2. Blog>
  3. data breach>
  4. Page 3
Read more about the article InfraGard Portal Breach: Account Takeover Inside the Vetted

InfraGard Portal Breach: Account Takeover Inside the Vetted

  • Post author:Prabhu Kalyan Samal
  • Post published:September 5, 2026
  • Post category:Identity & Phishing/Security

USDoD hijacked a chapter president’s InfraGard account and listed 87,000 members’ PII for sale. Identity lessons for trusted-community portals.

Continue ReadingInfraGard Portal Breach: Account Takeover Inside the Vetted
Read more about the article Uber’s 2022 Hack: A Bought Password, a Flood of Pushes, and vSphere

Uber’s 2022 Hack: A Bought Password, a Flood of Pushes, and vSphere

  • Post author:Prabhu Kalyan Samal
  • Post published:September 5, 2026
  • Post category:Cloud & Infrastructure/Identity & Phishing/Security

An 18-year-old bought a contractor’s Uber password, bombarded them with MFA pushes until one was approved, then roamed to vSphere via hardcoded credentials.

Continue ReadingUber’s 2022 Hack: A Bought Password, a Flood of Pushes, and vSphere
Read more about the article Predatory Sparrow: The OT Hack That Melted Steel on Camera

Predatory Sparrow: The OT Hack That Melted Steel on Camera

  • Post author:Prabhu Kalyan Samal
  • Post published:September 5, 2026
  • Post category:Cloud & Infrastructure/Ransomware & Malware/Security

Furnaces halted, footage released, workers warned. How a state-aligned group turned industrial sabotage into broadcast messaging.

Continue ReadingPredatory Sparrow: The OT Hack That Melted Steel on Camera
Read more about the article PwnKit: The 12-Year Local Root in Every Linux

PwnKit: The 12-Year Local Root in Every Linux

  • Post author:Prabhu Kalyan Samal
  • Post published:September 5, 2026
  • Post category:Cloud & Infrastructure/Security

CVE-2021-4034 gave instant root on default Linux installs via pure logic flaw. Why setuid code still deserves emergency attention.

Continue ReadingPwnKit: The 12-Year Local Root in Every Linux
Read more about the article HermeticWiper: Cyber Arson on Invasion Eve

HermeticWiper: Cyber Arson on Invasion Eve

  • Post author:Prabhu Kalyan Samal
  • Post published:September 5, 2026
  • Post category:Emerging Tech & Architecture/Ransomware & Malware/Security

Hours before tanks rolled, a signed wiper shredded hundreds of Ukrainian networks. The anatomy of the first invasion-synced destructive campaign.

Continue ReadingHermeticWiper: Cyber Arson on Invasion Eve
Read more about the article Twitch Leak: 125GB of Source Code and Payouts on 4chan

Twitch Leak: 125GB of Source Code and Payouts on 4chan

  • Post author:Prabhu Kalyan Samal
  • Post published:September 5, 2026
  • Post category:Identity & Phishing/Security/Supply Chain Security

No malware, no zero-day — one exposed internal endpoint handed over Twitch’s entire codebase and three years of creator earnings.

Continue ReadingTwitch Leak: 125GB of Source Code and Payouts on 4chan
Read more about the article Facebook 533M Leak: Old Scraped Data Never Stops Burning

Facebook 533M Leak: Old Scraped Data Never Stops Burning

  • Post author:Prabhu Kalyan Samal
  • Post published:September 5, 2026
  • Post category:Emerging Tech & Architecture/Identity & Phishing/Security

A 2019 contact-import scrape of 533M users hit every phone number to profile, free-dumped in 2021 and still fueling vishing and SIM-swaps today. Why data age barely dents attacker value.

Continue ReadingFacebook 533M Leak: Old Scraped Data Never Stops Burning
Read more about the article WD My Book Live Mass Wipe: The EOL IoT Disaster

WD My Book Live Mass Wipe: The EOL IoT Disaster

  • Post author:Prabhu Kalyan Samal
  • Post published:September 5, 2026
  • Post category:Cloud & Infrastructure/Security

Tens of thousands of abandoned Western Digital NAS drives got factory-reset by strangers through a decade-old unpatched flaw. The definitive end-of-life IoT case study.

Continue ReadingWD My Book Live Mass Wipe: The EOL IoT Disaster
Read more about the article Living Off Trusted Infrastructure: C2 via Legitimate Services

Living Off Trusted Infrastructure: C2 via Legitimate Services

  • Post author:Prabhu Kalyan Samal
  • Post published:September 5, 2026
  • Post category:Security/Technology

DragonForce’s Backdoor.Turn routes ransomware C2 through Microsoft Teams TURN relays using anonymous visitor tokens — LOTI, living off trusted infrastructure. Why network detection dies and what still works.

Continue ReadingLiving Off Trusted Infrastructure: C2 via Legitimate Services
Read more about the article Western Digital’s My Cloud Outage: Vendor Risk for NAS

Western Digital’s My Cloud Outage: Vendor Risk for NAS

  • Post author:Prabhu Kalyan Samal
  • Post published:September 5, 2026
  • Post category:Cloud & Infrastructure/Ransomware & Malware/Security

WD’s 2023 intrusion took My Cloud services offline mid-extortion claims, locking users out of their own files. Cloud-tethered storage lessons.

Continue ReadingWestern Digital’s My Cloud Outage: Vendor Risk for NAS
Read more about the article The 3CX Supply-Chain Attack: When Signed Updates Turn Against You

The 3CX Supply-Chain Attack: When Signed Updates Turn Against You

  • Post author:Prabhu Kalyan Samal
  • Post published:September 5, 2026
  • Post category:AI & Agent Security/Security/Supply Chain Security

3CX’s signed desktop app shipped a trojan after its build pipeline fell to an upstream vendor compromise — the first documented double supply-chain attack.

Continue ReadingThe 3CX Supply-Chain Attack: When Signed Updates Turn Against You
Read more about the article GoDaddy’s Multi-Year cPanel Breach: 2.5 Years of Dwell

GoDaddy’s Multi-Year cPanel Breach: 2.5 Years of Dwell

  • Post author:Prabhu Kalyan Samal
  • Post published:September 5, 2026
  • Post category:Cloud & Infrastructure/Security/Supply Chain Security

GoDaddy’s 2023 filing admitted intermittent intruder access since 2020, malware in cPanel servers, and email interception affecting ~6.95M customers.

Continue ReadingGoDaddy’s Multi-Year cPanel Breach: 2.5 Years of Dwell
  • Go to the previous page
  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • …
  • 14
  • Go to the next page
Press Escape to close the search panel.

Categories

  • AI Security (1)
  • Aviation and Aerospace Security (9)
  • Beyond Security (1)
  • Security (339)
  • Technology (62)

Recent Posts

  • Abusing OIDC in CI/CD: A Step-by-Step Tutorial on GitHub Actions Token Trust Chains
  • How to Hash Passwords in 2026: Argon2id, bcrypt and the NIST Baseline
  • Terraform State: The Most Sensitive File in Your Infrastructure
  • Hands-On Container Escape Lab: Privilege Escalation from Pod to Node with Real Commands
  • JWT Security: alg=none, Key Confusion and Why the Header Lies
  • Weekly Threat Intel: Supply Chain Compromises, Autumn CVE Exploitation and Infostealer Trends
  • UEFI Secure Boot and BlackLotus: The Boot Chain of Trust Under Attack
  • Weekly Threat Intel: Edge CVEs, MCP Agent Abuse, Stealer Cashouts
  • HTTP/3 and QUIC: How the Web Moved to a New Transport
  • Dependency Confusion Lab: Reproduce and Defend Your Pipeline
  • Cosign Signing and Verification Lab: Sign, Verify, Enforce
  • Kerberos Attack Paths: Golden Tickets, Silver Tickets and Kerberoasting
  • DNSSEC Explained: Chain of Trust, NSEC3 and the October 2026 Root Rollover
  • BOLA and Broken Auth API Attacks with Burp Suite: Lab Guide
  • OWASP ZAP DAST Lab: Authenticated API Scanning Explained

Archives

  • September 2026 (260)
  • August 2026 (98)

Newsletter

Get all latest content delivered to your email a few times a month. Updates and news about all categories will send to you.
Email is required Email is not valid
This field is required
Thanks for your subscription.
Failed to subscribe, please contact admin.
Hmmnm

Our Other Sites

  • Hmmnm.in
  • Odia.hmmnm.in

Quick Links

  • Security Services
  • Learning Paths
  • About Us
  • Contact
  • Blog
  • Privacy Policy
  • Disclaimer
  • Security Products
  • Terms of Service

Contact Info

  • 📧 contact@hmmnm.com
  • 🌐 hmmnm.com
in
© 2026 @Hmmnm

We use cookies to understand how the site is used and to improve your experience. You can accept analytics cookies or continue with essential cookies only. Privacy Policy

  • Home
  • Blog
  • Security
  • Experience
  • About Us
  • Services
  • Contact