Skip to content
Hmmnm brand header logo displayed prominently across the top of the webpage
  • Home
  • Blog
  • About Us
  • Contact
  • Services
  • Products
  • Cybersecurity Learning Paths
  • Toggle website search
Press Escape to close the search panel.
Menu Close
  • Home
  • Blog
  • About Us
  • Contact
  • Services
  • Products
  • Cybersecurity Learning Paths
  • Toggle website search
Search this website

data breach

  1. Home>
  2. Blog>
  3. data breach>
  4. Page 9
Read more about the article Okta’s Weak Link: When Your IdP’s Vendor Gets Pwned

Okta’s Weak Link: When Your IdP’s Vendor Gets Pwned

  • Post author:Prabhu Kalyan Samal
  • Post published:September 3, 2026
  • Post category:Identity & Phishing/Security/Supply Chain Security

One contractor’s stolen credentials reached super-admin support tooling across 366 Okta tenants. The identity supply chain’s hardest lesson.

Continue ReadingOkta’s Weak Link: When Your IdP’s Vendor Gets Pwned
Read more about the article Samsung’s 190 GB: Lapsus$ and Source-Code Extortion

Samsung’s 190 GB: Lapsus$ and Source-Code Extortion

  • Post author:Prabhu Kalyan Samal
  • Post published:September 3, 2026
  • Post category:Security/Supply Chain Security

One contractor’s credentials, 190 GB of Galaxy bootloader and biometrics code, and the pure steal-and-dump model that outlived encryption ransomware.

Continue ReadingSamsung’s 190 GB: Lapsus$ and Source-Code Extortion
Read more about the article Conti’s 60,000 Chats: Anatomy of a Ransomware Giant

Conti’s 60,000 Chats: Anatomy of a Ransomware Giant

  • Post author:Prabhu Kalyan Samal
  • Post published:September 3, 2026
  • Post category:Emerging Tech & Architecture/Ransomware & Malware/Security

A pro-Russia statement, a furious insider, and the full Jabber archive of history’s most damaging ransomware brand — dumped for everyone to read.

Continue ReadingConti’s 60,000 Chats: Anatomy of a Ransomware Giant
Read more about the article OpenSea’s $1.7M Phish: The Signature Trap

OpenSea’s $1.7M Phish: The Signature Trap

  • Post author:Prabhu Kalyan Samal
  • Post published:September 3, 2026
  • Post category:Cryptography & PKI/Identity & Phishing/Security

Seventeen users, one fake migration flow, and $1.7M in Apes gone — the phishing heist that made signature UX a security discipline.

Continue ReadingOpenSea’s $1.7M Phish: The Signature Trap
Read more about the article Lapsus$ Rising: Identity-Driven Extortion’s Breakout

Lapsus$ Rising: Identity-Driven Extortion’s Breakout

  • Post author:Prabhu Kalyan Samal
  • Post published:September 3, 2026
  • Post category:Identity & Phishing/Security/Supply Chain Security

No zero-days, no malware — just MFA fatigue, SIM swaps, and help-desk social engineering. How Lapsus$ broke every assumption.

Continue ReadingLapsus$ Rising: Identity-Driven Extortion’s Breakout
Read more about the article Apache httpd CVE-2021-44790: The RCE After Log4Shell

Apache httpd CVE-2021-44790: The RCE After Log4Shell

  • Post author:Prabhu Kalyan Samal
  • Post published:September 3, 2026
  • Post category:Cloud & Infrastructure/Security/Web & API Security

A mod_lua multipart buffer overflow announced ten days after Log4Shell. Narrow exposure, but a masterclass in triage under fatigue.

Continue ReadingApache httpd CVE-2021-44790: The RCE After Log4Shell
Read more about the article Crypto.com’s $34M Lesson: The 2FA Bypass Blueprint

Crypto.com’s $34M Lesson: The 2FA Bypass Blueprint

  • Post author:Prabhu Kalyan Samal
  • Post published:September 3, 2026
  • Post category:Cryptography & PKI/Identity & Phishing/Security

Attackers defeated the second factor, not the vault, draining $34M from 483 accounts before a platform-wide withdrawal halt stopped them.

Continue ReadingCrypto.com’s $34M Lesson: The 2FA Bypass Blueprint
Read more about the article Kronos Ransomware: When Payroll SaaS Went Dark

Kronos Ransomware: When Payroll SaaS Went Dark

  • Post author:Prabhu Kalyan Samal
  • Post published:September 3, 2026
  • Post category:Ransomware & Malware/Security

UKG’s Kronos Private Cloud ransomware outage forced thousands of employers onto paper time cards. The definitive SaaS continuity case.

Continue ReadingKronos Ransomware: When Payroll SaaS Went Dark
Read more about the article Log4Shell (CVE-2021-44228): How One Logging Library Broke the Internet

Log4Shell (CVE-2021-44228): How One Logging Library Broke the Internet

  • Post author:Prabhu Kalyan Samal
  • Post published:September 3, 2026
  • Post category:Cloud & Infrastructure/Security/Web & API Security

A single JNDI lookup string turned every Java logger into a front door. The anatomy, response, and lasting lessons of Log4Shell.

Continue ReadingLog4Shell (CVE-2021-44228): How One Logging Library Broke the Internet
Read more about the article AWS us-east-1 Outage: When Multi-Region Wasn’t

AWS us-east-1 Outage: When Multi-Region Wasn’t

  • Post author:Prabhu Kalyan Samal
  • Post published:September 3, 2026
  • Post category:Cloud & Infrastructure/Security

A DYNOMITE autoscaler impairment cascaded through AWS’s busiest region and its own consoles. The dependency-concentration landmark.

Continue ReadingAWS us-east-1 Outage: When Multi-Region Wasn’t
Read more about the article Fake FBI Warnings: The 2021 fbi.gov Email Spoofing

Fake FBI Warnings: The 2021 fbi.gov Email Spoofing

  • Post author:Prabhu Kalyan Samal
  • Post published:September 3, 2026
  • Post category:Identity & Phishing/Security

Attackers abused a misconfigured FBI notification system to spam fake cyber-warnings from the real fbi.gov address, exposing the limits of email trust.

Continue ReadingFake FBI Warnings: The 2021 fbi.gov Email Spoofing
Read more about the article GoDaddy Breach: One Phished Password, 1.2 Million Sites Exposed

GoDaddy Breach: One Phished Password, 1.2 Million Sites Exposed

  • Post author:Prabhu Kalyan Samal
  • Post published:September 3, 2026
  • Post category:Cloud & Infrastructure/Security/Supply Chain Security

Two months of undetected access to managed WordPress hosting, wholesale sFTP and database credential harvesting, and SSL keys in the bargain.

Continue ReadingGoDaddy Breach: One Phished Password, 1.2 Million Sites Exposed
  • Go to the previous page
  • 1
  • …
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • …
  • 14
  • Go to the next page
Press Escape to close the search panel.

Categories

  • AI Security (1)
  • Aviation and Aerospace Security (9)
  • Beyond Security (1)
  • Security (339)
  • Technology (62)

Recent Posts

  • Abusing OIDC in CI/CD: A Step-by-Step Tutorial on GitHub Actions Token Trust Chains
  • How to Hash Passwords in 2026: Argon2id, bcrypt and the NIST Baseline
  • Terraform State: The Most Sensitive File in Your Infrastructure
  • Hands-On Container Escape Lab: Privilege Escalation from Pod to Node with Real Commands
  • JWT Security: alg=none, Key Confusion and Why the Header Lies
  • Weekly Threat Intel: Supply Chain Compromises, Autumn CVE Exploitation and Infostealer Trends
  • UEFI Secure Boot and BlackLotus: The Boot Chain of Trust Under Attack
  • Weekly Threat Intel: Edge CVEs, MCP Agent Abuse, Stealer Cashouts
  • HTTP/3 and QUIC: How the Web Moved to a New Transport
  • Dependency Confusion Lab: Reproduce and Defend Your Pipeline
  • Cosign Signing and Verification Lab: Sign, Verify, Enforce
  • Kerberos Attack Paths: Golden Tickets, Silver Tickets and Kerberoasting
  • DNSSEC Explained: Chain of Trust, NSEC3 and the October 2026 Root Rollover
  • BOLA and Broken Auth API Attacks with Burp Suite: Lab Guide
  • OWASP ZAP DAST Lab: Authenticated API Scanning Explained

Archives

  • September 2026 (260)
  • August 2026 (98)

Newsletter

Get all latest content delivered to your email a few times a month. Updates and news about all categories will send to you.
Email is required Email is not valid
This field is required
Thanks for your subscription.
Failed to subscribe, please contact admin.
Hmmnm

Our Other Sites

  • Hmmnm.in
  • Odia.hmmnm.in

Quick Links

  • Security Services
  • Learning Paths
  • About Us
  • Contact
  • Blog
  • Privacy Policy
  • Disclaimer
  • Security Products
  • Terms of Service

Contact Info

  • 📧 contact@hmmnm.com
  • 🌐 hmmnm.com
in
© 2026 @Hmmnm

We use cookies to understand how the site is used and to improve your experience. You can accept analytics cookies or continue with essential cookies only. Privacy Policy

  • Home
  • Blog
  • Security
  • Experience
  • About Us
  • Services
  • Contact