Index live· 1,284 files · 148 editions
ForensicPost

Search the index

29 results
Try
Results for “Disclosure”Newest first
26-0802
File

Corpus Audit: 251 of 587 Files Record No Established Entry Route

It does not mean SQL injection is rare. It means the disclosure regime records who was affected and not how.

MethodologyMultipleMethod
Sev 1TargetNot applicableActorUnattributed
26-0723
File

RevolutionParts Breach Exposed More Than Five Million Records

Five million records from a platform none of the customers knew they were using. Correlated failure, uncorrelated disclosure.

UnattributedUnder reviewRetailThird party
Sev 3TargetRevolutionPartsActorUnattributed
26-0604
File

The Source Code Disclosed What the Training Data Was

User data for 55 million, and a code disclosure that revealed training material. Two exposures, two sets of interested parties.

UnattributedSource code breachCloudAI
Sev 4TargetSunoActorUnattributed
26-0506
File

The Disclosure-to-Exploitation Window Is Closing on the Patch Window

Exploitation is arriving before organisations can deploy. Patching in twenty days is worth less than surviving a compromised appliance.

MultipleRapid exploitationMultipleVulnerabilities
Sev 4TargetEnterprise patch managementActorMultiple
26-0422
File

Attorney-client Privilege Offers No Protection Against an Intruder Copying Files

Privilege stops a court compelling disclosure. It says nothing about an intruder copying the file, and the gap is filled by IT controls.

MultipleVariousFinanceLegal
Sev 4TargetPrivileged communicationsActorMultiple
26-0410
File

Only 97 of 1,596 Vulnerabilities Disclosed to Open-Source Maintainers Were Patched

1,596 disclosed, 97 patched. Discovery is now a capital expenditure; fixing is still one person in their own time.

Research consortiumDisclosure volumeCloudVulnerabilities
Sev 4TargetOpen-source maintainersActorResearch consortium
26-0403
File

US Public Companies Must Disclose Material Cyber Incidents Within Four Days

Four business days from a materiality determination the company itself makes. The clock and the investigation run on incompatible timescales.

UnattributedDisclosure regimeFinanceMethod
Sev 3TargetUS public companiesActorUnattributedUSA
26-0323
File

Coordinated Disclosure Breaks Down at Tens of Thousands of Findings

A deadline is an incentive when meeting it is possible. At this volume it becomes a countdown to publishing defects nobody has fixed.

UnattributedProcessCloudMethod
Sev 3TargetDisclosure governanceActorUnattributed
26-0128
File

CitrixBleed-style NetScaler Flaw CVE-2026-8451 Abused Within Hours of Disclosure

A session token read out of appliance memory bypasses the second factor entirely, because authentication already happened.

MultipleMemory disclosureMultipleEdge devices
Sev 4TargetNetScaler appliancesActorMultiple
25-1228
File

Close to 1,900 Data Privacy Class Actions Filed in 2025

The only accountability mechanism operating on the same timescale as the incidents — and it is triggered by disclosure rather than by harm.

MultipleLitigation
Sev 3TargetBreached organisationsActorUnattributed
25-1216
File

Newly Disclosed Vulnerabilities Weaponised Within Hours Through 2025

The head start was the entire point of coordinated disclosure. At an interval measured in hours, publication is a starting gun heard equally by both sides.

MultipleVariousCloudAnalysis
Sev 4TargetEnterprise software estatesActorMultiple
25-1216b
File

47% of Ransomware Attacks Were Halted Before Encryption in 2025, Vendor Research Says

This figure measures the category every disclosure-based count excludes by construction: the attacks that were stopped.

MultipleVariousMultipleAnalysis
Sev 3TargetRansomware defenceActorMultiple
25-1214
File

The Global Total, and Why It Is Not One Thing

A country that strengthens its disclosure law appears to get worse. One that has none appears clean.

MultipleInternational
Sev 3TargetGlobal breach measurementActorUnattributed
25-1116
File

Three Countries Account for Most Latin American Ransomware Victims

Where disclosure is not mandatory, the regional picture is assembled almost entirely from what attackers chose to publish.

MultipleRansomwareMultipleAnalysis
Sev 3TargetLatin American organisationsActorMultipleUSA
25-1007
File

One Enterprise Application, Victims on Four Continents

The window between disclosure and exploitation is shortest exactly where the ability to respond is slowest.

Cl0pMass exploitationMultipleExploitation
Sev 5TargetOracle enterprise estatesActorCl0pSouth Korea
25-0808
File

Retail Recorded 837 Incidents and 419 Confirmed Breaches in a Quarter

837 incidents, 419 confirmed breaches. The 418 that never became a disclosure are the sector’s real attack volume.

MultipleVariousRetailAnalysis
Sev 3TargetRetail sectorActorMultiple
25-0807
File

Pakistan Petroleum Isolated IT Services After Ransomware Intrusion

A corpus assembled from disclosures records failures in detail and successes almost never.

UnattributedRansomwareEnergyEnergy
Sev 2TargetPakistan Petroleum LimitedActorUnattributedPakistan
25-0709
File

More Than 90 Gulf Data Dumps Appeared on Forums in Six Months

Where disclosure is not mandatory, criminal forums become the primary public record — and affected people learn from researchers.

MultipleVariousMultipleExposure
Sev 3TargetGulf organisationsActorMultiple
25-0624
File

CitrixBleed 2 NetScaler Flaw CVE-2025-5777 Widely Exploited From June

A sequel name is a judgement that this is the same mistake in the same place. Session tokens leak past authentication entirely.

MultipleMemory disclosureCloudExploitation
Sev 4TargetNetScaler appliancesActorMultiple
25-0403
File

Hertz Confirms Customer and Employee Data Taken Through Cleo Flaw

A privately held operator using the same product would have had the same exposure and, quite possibly, produced no public record at all.

Cl0pSupplier product exploitationTravelDisclosure
Sev 4TargetHertzActorCl0pUSA
25-0218
File

Black Basta Stopped Posting Victims With No Seizure and No Arrests

“Group X has been dismantled” is the form the good news usually takes in this field. It describes the destruction of the cheapest component.

InternalDisclosureCriminalEnforcement
Sev 3TargetBlack BastaActorInternal
25-0211
File

ExploitWhispers Published 200,000 Internal Black Basta Chat Messages

The operation describing itself, to itself, with no expectation of being read. Nearly everything else in this corpus is an attacker described from outside.

ExploitWhispersInsider disclosureCriminalPrimary source
Sev 5TargetBlack BastaActorExploitWhispers
24-1219
File

Ascension Disclosed Its Data Figure Seven Months After the Outage

The corpus does not record availability harm less because it matters less. It records it less because nothing compels anyone to measure it.

Black BastaMalicious file downloadHealthcareDisclosure
Sev 5TargetAscensionActorBlack BastaUSA
24-0821
File

The SEC Asked Halliburton to Explain Its Own Disclosure

The rule requires disclosure of a material incident. It does not require the company to show its working — and Halliburton said so, in writing, to the SEC.

RansomHubEnergy servicesPrimary source
Sev 3TargetHalliburtonActorRansomHubUSA
24-0531
File

Five Hundred and Sixty Million, Claimed

A 560 million claim graded low sits below a 110 million disclosure graded high. That ordering is the point of having grades.

UNC5537Valid credentials, no MFAEntertainmentVerification
Sev 4TargetTicketmasterActorUNC5537USA
23-1218
File

Comcast Says Citrix Bleed Reached Xfinity Data on 35.8 Million Customers

Six days between patch and intrusion. Faster than most manage, and longer than the window now exists.

UnattributedMemory disclosureTelecomTelecom
Sev 4TargetComcast XfinityActorUnattributedUSA
23-1010
File

LockBit Affiliates Used Citrix Bleed to Reach Boeing’s Parts Distribution Unit

A stolen session token arrives after authentication. Multi-factor is not bypassed — it is never consulted.

LockBit affiliatesMemory disclosureMultipleEdge devices
Sev 5TargetCitrix NetScaler appliancesActorLockBit affiliatesUSA
23-0818
File

Tesla Says Two Former Employees Leaked Personal Data on 75,735 People to a Newspaper

Every control answers "should this account reach this data". Here the answer was yes.

Insider — former employeesAuthorised access, unauthorised disclosureManufacturingInsider
Sev 3TargetTeslaActorInsider — former employeesUSA
23-0808
File

PSNI FOI Response Named All 9,483 Serving Officers and Staff

No intruder, no exploit. A statutory duty answered, and a tab nobody checked.

Accidental disclosureGovernmentPublic sector
Sev 5TargetPolice Service of Northern IrelandActorUnattributedUnited Kingdom
© 2026 ForensicPost Media · the desk · newsletterGlossaryNo search logging