Skip to content
Hmmnm brand header logo displayed prominently across the top of the webpage
  • Home
  • Blog
  • About Us
  • Contact
  • Services
  • Products
  • Cybersecurity Learning Paths
  • Toggle website search
Press Escape to close the search panel.
Menu Close
  • Home
  • Blog
  • About Us
  • Contact
  • Services
  • Products
  • Cybersecurity Learning Paths
  • Toggle website search
Search this website

data breach

  1. Home>
  2. Blog>
  3. data breach>
  4. Page 8
Read more about the article Nomad Bridge: The $190M Config Bug That Became a Mob Looting

Nomad Bridge: The $190M Config Bug That Became a Mob Looting

  • Post author:Prabhu Kalyan Samal
  • Post published:September 3, 2026
  • Post category:Cryptography & PKI/Security

A routine upgrade left message proofs rubber-stamped. Hundreds of copycats drained the bridge in crypto’s most chaotic heist.

Continue ReadingNomad Bridge: The $190M Config Bug That Became a Mob Looting
Read more about the article Twitter’s 5.4M Scrape: When an API Becomes a Breach Oracle

Twitter’s 5.4M Scrape: When an API Becomes a Breach Oracle

  • Post author:Prabhu Kalyan Samal
  • Post published:September 3, 2026
  • Post category:Identity & Phishing/Security/Web & API Security

A patched OAuth endpoint answered one question too honestly: which phone belongs to which handle. The dataset sold for $30k — the class lesson is still with us.

Continue ReadingTwitter’s 5.4M Scrape: When an API Becomes a Breach Oracle
Read more about the article 26 Million Requests Per Second: Cloudflare’s Record DDoS

26 Million Requests Per Second: Cloudflare’s Record DDoS

  • Post author:Prabhu Kalyan Samal
  • Post published:September 3, 2026
  • Post category:Cloud & Infrastructure/Security

Five thousand cloud VMs, each pushing 5,000 rps of encrypted traffic at one small website. June 2022’s record flood and the edge doctrine it sealed.

Continue Reading26 Million Requests Per Second: Cloudflare’s Record DDoS
Read more about the article Harmony Horizon: $100M for Two Stolen Keys

Harmony Horizon: $100M for Two Stolen Keys

  • Post author:Prabhu Kalyan Samal
  • Post published:September 3, 2026
  • Post category:Cryptography & PKI/Security

A 2-of-5 multisig guarding nine figures. Lazarus took the two keys it needed, and the bridge-custody era changed for good.

Continue ReadingHarmony Horizon: $100M for Two Stolen Keys
Read more about the article Follina in the Wild: TA413, Patch Gaps and Zero-Day Economics

Follina in the Wild: TA413, Patch Gaps and Zero-Day Economics

  • Post author:Prabhu Kalyan Samal
  • Post published:September 3, 2026
  • Post category:Security/Web & API Security

Sixteen days between disclosure and patch. Who exploited Follina in the gap, how fast state and commodity actors moved, and the doctrine it forged.

Continue ReadingFollina in the Wild: TA413, Patch Gaps and Zero-Day Economics
Read more about the article Confluence CVE-2022-26134: OGNL Injection RCE Under Fire

Confluence CVE-2022-26134: OGNL Injection RCE Under Fire

  • Post author:Prabhu Kalyan Samal
  • Post published:September 3, 2026
  • Post category:Cloud & Infrastructure/Security/Web & API Security

Exploited in the wild two days before the patch existed. How OGNL injection turned Confluence into June 2022’s internet-scale fire drill — and the playbook it left behind.

Continue ReadingConfluence CVE-2022-26134: OGNL Injection RCE Under Fire
Read more about the article Heroku Held the Keys: Anatomy of a Vendor-Token Breach

Heroku Held the Keys: Anatomy of a Vendor-Token Breach

  • Post author:Prabhu Kalyan Samal
  • Post published:September 3, 2026
  • Post category:Identity & Phishing/Security/Supply Chain Security

GitHub’s OAuth tokens lived in Heroku’s infrastructure. One compromised CI cache later, an ecosystem learned where vendor tokens really live.

Continue ReadingHeroku Held the Keys: Anatomy of a Vendor-Token Breach
Read more about the article Beanstalk’s $182M Flash-Loan Governance Attack: Thirteen Seconds

Beanstalk’s $182M Flash-Loan Governance Attack: Thirteen Seconds

  • Post author:Prabhu Kalyan Samal
  • Post published:September 3, 2026
  • Post category:Cryptography & PKI/Security

No key stolen, no bug exploited — an attacker borrowed a voting majority on Aave, passed his own proposal, and drained the vaults in one block.

Continue ReadingBeanstalk’s $182M Flash-Loan Governance Attack: Thirteen Seconds
Read more about the article Costa Rica’s Conti Emergency: When Ransomware Became a National Crisis

Costa Rica’s Conti Emergency: When Ransomware Became a National Crisis

  • Post author:Prabhu Kalyan Samal
  • Post published:September 3, 2026
  • Post category:Emerging Tech & Architecture/Ransomware & Malware/Security

Conti encrypted the treasury during tax season, declared war on the government, and forced the world’s first ransomware state of emergency.

Continue ReadingCosta Rica’s Conti Emergency: When Ransomware Became a National Crisis
Read more about the article Spring4Shell: The RCE That Wasn’t Log4Shell (but Still Bit Hard)

Spring4Shell: The RCE That Wasn’t Log4Shell (but Still Bit Hard)

  • Post author:Prabhu Kalyan Samal
  • Post published:September 3, 2026
  • Post category:Cloud & Infrastructure/Security/Web & API Security

A JDK 9 property path reopened a 2010-era bug class in Spring’s data binder — and gave every Tomcat admin a very bad 48 hours.

Continue ReadingSpring4Shell: The RCE That Wasn’t Log4Shell (but Still Bit Hard)
Read more about the article Lapsus$ vs Microsoft: When Teen Hackers Beat a Hyperscaler’s Odds

Lapsus$ vs Microsoft: When Teen Hackers Beat a Hyperscaler’s Odds

  • Post author:Prabhu Kalyan Samal
  • Post published:September 3, 2026
  • Post category:Identity & Phishing/Security/Supply Chain Security

37GB claimed, one account compromised, no customer data lost — and a DEV-0536 profile that taught the industry how social engineering beats MFA.

Continue ReadingLapsus$ vs Microsoft: When Teen Hackers Beat a Hyperscaler’s Odds
Read more about the article Ronin Bridge: The $625M Heist That Ran on Five Keys

Ronin Bridge: The $625M Heist That Ran on Five Keys

  • Post author:Prabhu Kalyan Samal
  • Post published:September 3, 2026
  • Post category:Cryptography & PKI/Security

North Korea’s Lazarus Group drained Axie Infinity’s Ronin bridge of $625M with five forged signatures and a leftover permission nobody revoked.

Continue ReadingRonin Bridge: The $625M Heist That Ran on Five Keys
  • Go to the previous page
  • 1
  • …
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • …
  • 14
  • Go to the next page
Press Escape to close the search panel.

Categories

  • AI Security (1)
  • Aviation and Aerospace Security (9)
  • Beyond Security (1)
  • Security (339)
  • Technology (62)

Recent Posts

  • Abusing OIDC in CI/CD: A Step-by-Step Tutorial on GitHub Actions Token Trust Chains
  • How to Hash Passwords in 2026: Argon2id, bcrypt and the NIST Baseline
  • Terraform State: The Most Sensitive File in Your Infrastructure
  • Hands-On Container Escape Lab: Privilege Escalation from Pod to Node with Real Commands
  • JWT Security: alg=none, Key Confusion and Why the Header Lies
  • Weekly Threat Intel: Supply Chain Compromises, Autumn CVE Exploitation and Infostealer Trends
  • UEFI Secure Boot and BlackLotus: The Boot Chain of Trust Under Attack
  • Weekly Threat Intel: Edge CVEs, MCP Agent Abuse, Stealer Cashouts
  • HTTP/3 and QUIC: How the Web Moved to a New Transport
  • Dependency Confusion Lab: Reproduce and Defend Your Pipeline
  • Cosign Signing and Verification Lab: Sign, Verify, Enforce
  • Kerberos Attack Paths: Golden Tickets, Silver Tickets and Kerberoasting
  • DNSSEC Explained: Chain of Trust, NSEC3 and the October 2026 Root Rollover
  • BOLA and Broken Auth API Attacks with Burp Suite: Lab Guide
  • OWASP ZAP DAST Lab: Authenticated API Scanning Explained

Archives

  • September 2026 (260)
  • August 2026 (98)

Newsletter

Get all latest content delivered to your email a few times a month. Updates and news about all categories will send to you.
Email is required Email is not valid
This field is required
Thanks for your subscription.
Failed to subscribe, please contact admin.
Hmmnm

Our Other Sites

  • Hmmnm.in
  • Odia.hmmnm.in

Quick Links

  • Security Services
  • Learning Paths
  • About Us
  • Contact
  • Blog
  • Privacy Policy
  • Disclaimer
  • Security Products
  • Terms of Service

Contact Info

  • 📧 contact@hmmnm.com
  • 🌐 hmmnm.com
in
© 2026 @Hmmnm

We use cookies to understand how the site is used and to improve your experience. You can accept analytics cookies or continue with essential cookies only. Privacy Policy

  • Home
  • Blog
  • Security
  • Experience
  • About Us
  • Services
  • Contact