Index live· 1,284 files · 148 editions
ForensicPost

Search the index

56 results
Try
Results for “Technology”Newest first
26-0817
File

Unisoc Modem Flaw Gives Android Kernel Access Through a Video Call, With No Fix

A video call reaches the Android kernel on three Unisoc chipsets, and the vendor has not replied.

VoLTE modem firmware to kernelTechnologyVulnerabilities
Sev 4TargetUnisoc-based Android devicesActorUnattributedNot established
26-0811
File

Metabase Zero-Day Hit Five Companies Before the Flaw Was Disclosed

A CVSS 10.0 flaw in a reporting tool that stores the credentials for every warehouse behind it.

UnattributedCVE-2026-72898TechnologySupply chain
Sev 5TargetMetabase deploymentsActorUnattributedUSA
26-0714b
File

CISA Tells SharePoint Operators to Hunt Before They Rotate Keys

Rotating the stolen key is the fix. It is also what erases the proof anyone used it.

UnattributedRemote code executionTechnologyExploitation
Sev 5TargetOn-premises SharePoint operatorsActorUnattributedUSA
26-0228
File

A Third of School Breaches Happen at Somebody Else’s Company

Around 32% of K-12 breaches originate at a vendor. Districts outsourced the technology and kept the accountability.

MultipleThird-party vendorEducationEducation
Sev 3TargetK-12 school districtsActorMultiple
26-0224
File

Employee Compromise at Figure Technology Solutions Affected 967,000 Accounts

967,000 accounts at a lending platform. Underwriting assembles identity, income and obligations — including for people who were declined.

ShinyHuntersEmployee social engineeringFinanceIdentity
Sev 4TargetFigure Technology SolutionsActorShinyHunters
26-0203
File

Unauthorised Activity Hit PayPal Working Capital Accounts Over Six Months

A six-month window on a small-business lending product, in one of the most heavily monitored environments in commercial technology.

UnattributedAccount compromiseFinanceFinance
Sev 3TargetPayPal Working CapitalActorUnattributed
26-0127
File

Sixty Institutions, One Technology Provider

Sixty institutions down through one provider. Pooling technology is what lets small member-owned banks exist, and it concentrates the risk.

UnattributedRansomwareFinanceThird party
Sev 4TargetCredit union technology providerActorUnattributed
26-0121
File

Attacks on Automotive and Smart Mobility Organisations More Than Doubled in 2025

Three technology estates in one company. The research attention is on the vehicles; the billion-pound losses are in enterprise IT.

MultipleVariousManufacturingAnalysis
Sev 4TargetAutomotive manufacturersActorMultiple
25-1220b
File

Four Properties Combine in Healthcare That Combine Nowhere Else

A hospital carries the operational-technology problem of a utility alongside the data-protection problem of a bank.

MultipleRansomwareHealthcareAnalysis
Sev 4TargetHealthcare sectorActorMultiple
24-1104
File

Nokia Source Code Leaked From a Contractor’s Server With Default Logins

Nokia was right that its systems were not breached. Its code was published anyway.

IntelBrokerThird-party contractor serverTechnologySupply chain
Sev 3TargetNokiaActorIntelBrokerFinland
24-1031
File

Sophos Published Five Years of Attacks on Its Own Firewalls and Its Use of an Implant

A private company placed monitoring code on machines it did not own, and published that it had.

China-based groups, per the vendorEdge-device vulnerabilitiesTechnologyInfrastructure
Sev 5TargetSophos perimeter devicesActorChina-based groups, per the vendorUnited Kingdom
24-0710
File

Squarespace Migration Dropped Two-Factor, Crypto Domains Hijacked

Whatever does not survive a migration is removed silently, and nobody is told.

UnattributedAccount takeover after migrationTechnologyIdentity
Sev 4TargetSquarespace domain customersActorUnattributedUSA
24-0703
File

Twilio Confirmed 33 Million Authy Phone Numbers Through an Open Endpoint

The factor held. Being known to use it became the attack surface.

UnattributedUnauthenticated API enumerationTechnologyIdentity
Sev 4TargetTwilio AuthyActorUnattributedUSA
24-0510
File

Dell Partner Portal API Gave Up 49 Million Records to Fake Resellers

The portal checked that the caller was a partner. It never checked whose records they could see.

UnattributedPartner portal enumerationTechnologyAPI
Sev 4TargetDellActorUnattributedUSA
24-0425
File

Kaiser Permanente Trackers Sent 13.4 Million Members’ Data to Advertisers

A member looking up a condition is not browsing. The page is what reveals the worry.

Tracking technology, by designHealthcareHealthcare
Sev 4TargetKaiser PermanenteActorUnattributedUSA
24-0317
File

Fujitsu Found Malware That Copied Files and Was Not Ransomware

Ransomware has to announce itself. Malware that only copies succeeds by staying unremarkable.

UnattributedTechnologyMethod
Sev 3TargetFujitsuActorUnattributedJapan
24-0123
File

Trello Profile Data for 15 Million Users Scraped Through a Public API

Every record was already public. The endpoint added the one thing that was not: confirmation.

UnattributedUnauthenticated API enumerationTechnologyAPI
Sev 3TargetTrelloActorUnattributedUSA
23-1220
File

MongoDB Says Phishing Reached Support Systems but Not Customer Clusters

No lookalike domain and no spoofed sender. The message came from a real colleague’s real account.

UnattributedPhishingTechnologyIdentity
Sev 2TargetMongoDBActorUnattributed
23-1219
File

Rhysida Published 1.3 Million Insomniac Files Including Employee Passports

Reporting follows interest. The harm that is interesting gets recorded; the harm that is serious sometimes does not.

RhysidaTechnologyAftermath
Sev 4TargetInsomniac GamesActorRhysidaUSA
23-1030
File

SEC Charged SolarWinds and Named Its Security Officer Personally

Nobody is fined for being breached. People are fined for what they said beforehand.

RegulatorTechnologyAccountability
Sev 2TargetSolarWindsActorRegulatorUSA
23-1020
File

Okta Support System Breach Exposed HAR Files Belonging to 134 Customers

A HAR file does its job by capturing exactly the material an attacker needs.

UnattributedStolen credentialsTechnologyIdentity
Sev 4TargetOktaActorUnattributed
23-1010b
File

HTTP/2 Rapid Reset Drove DDoS Peaks of 398 Million Requests per Second

No vendor to patch and no version to check. Every implementation had to fix it separately.

UnattributedCVE-2023-44487TechnologyExploitation
Sev 4TargetHTTP/2 implementationsActorUnattributedUSA
23-0918
File

A Single Storage Token Exposed 38TB of Microsoft AI Research Data

Nobody attacked anything. A sharing mechanism offered a wider scope than the task needed.

ExposureMisconfigurationTechnologyExposure
Sev 3TargetMicrosoft AI researchActorExposure
23-0913
File

A Synced Authenticator Turned Retool’s Second Factor Into No Factor

Once the seeds live in an account protected by the same identity, there is one factor wearing two names.

UnattributedSMS phishingTechnologyIdentity
Sev 4TargetRetoolActorUnattributed
23-0823
File

Data on 2.6 Million Duolingo Accounts Was Scraped Through an Open API

An interface that answers yes or no about a person is a service for whoever asks it a few million times.

UnattributedAPI scrapingTechnologyAPI
Sev 2TargetDuolingoActorUnattributed
23-0818b
File

CloudNordic Lost Customer Data After Backups Were Encrypted Alongside Production

Nobody decided to remove the isolation. It was lost while moving the servers.

UnattributedPre-existing infection, network mergedTechnologyAvailability
Sev 5TargetCloudNordic and AzeroCloudActorUnattributedDenmark
23-0712
File

JumpCloud Says a Nation-State Phish Reached Fewer Than Five Customers

The blast radius was tiny because the targeting was precise, not because the access was limited.

UNC4899Spear-phishingTechnologySupply chain
Sev 4TargetJumpCloudActorUNC4899
23-0619
File

Reddit Says Phishing Took Source Code and Internal Documents, Not User Passwords

The only demand in this database attaching a condition unrelated to payment. Nobody repeated it.

ALPHV/BlackCatPhishingTechnologyActors
Sev 3TargetRedditActorALPHV/BlackCat
23-0512c
File

Discord Says a Support Vendor’s Agent Account Exposed Ticket Contents

People write to support when something has gone wrong, and they explain it.

UnattributedThird-party account compromiseTechnologyThird party
Sev 2TargetDiscordActorUnattributed
23-0420
File

Mandiant Traced the 3CX Compromise to a Trojanised X_TRADER Installer

Nobody assessing a phone-system vendor thinks to ask about its staff’s trading software.

UNC4736Trojanised X_TRADER installerTechnologySupply chain
Sev 5Target3CXActorUNC4736USA
23-0413
File

Cl0p and LockBit Both Exploited PaperCut a Month After the Patch Shipped

High privilege, low attention, reachable. The vulnerable thing is rarely the one anyone would name.

Cl0p, LockBitCVE-2023-27350TechnologyExploitation
Sev 4TargetPaperCut MF/NG operatorsActorCl0p, LockBitUSA
23-0402
File

Western Digital Took My Cloud Offline for Eleven Days After Network Intrusion

Personal cloud storage is sold on one promise. For eleven days the product did not exist.

UnattributedTechnologyAvailability
Sev 4TargetWestern DigitalActorUnattributedUSA
23-0329
File

Mandiant Says One Supply Chain Compromise Caused Another at 3CX

Code signing answers "did this come from the vendor". Here the answer was yes, and it was the wrong question.

UNC4736Supply chain compromiseTechnologySupply chain
Sev 5Target3CXActorUNC4736
23-0324
File

OpenAI Says a Redis Client Bug Showed Users Other People’s Chat Titles

A conversation title is a list of what somebody asked a machine in private.

Software defectTechnologyAI
Sev 2TargetOpenAIActorUnattributed
23-0227
File

LastPass Says a Keylogger on an Engineer’s Home Computer Reached Its Vault Backups

The corporate boundary turned out to run through a domestic living room.

UnattributedKeylogger on personal deviceTechnologyIdentity
Sev 5TargetLastPassActorUnattributed
23-0124
File

Riot Games Refused a Ransom After League of Legends Source Code Was Stolen

Costly to the refuser, costless to everyone else. The only one in the database like that.

UnattributedSocial engineeringTechnologyAftermath
Sev 3TargetRiot GamesActorUnattributedUSA
23-0104
File

CircleCI Rotated Every Customer Secret After Malware Stole an Engineer’s Session

The credential that mattered was not the password. It was the thing issued after the password.

UnattributedSession token theftTechnologyTokens
Sev 4TargetCircleCIActorUnattributed
22-1222
File

Encrypted Vault Backups for the Entire Customer Base

The vaults were encrypted. Offline, with no lockout and no clock, that is a timer rather than a wall.

UnattributedCompromised engineer endpointTechnologyConcentration
Sev 5TargetLastPassActorUnattributedUSA
22-1202
File

The Hosted Email Service Did Not Come Back

The stopgap became the destination. Hosted Exchange was retired rather than restored.

PlayCVE-2022-41080 — zero-dayTechnologyAvailability
Sev 4TargetRackspaceActorPlayUSA
22-1101
File

Dropbox Says Phishing Reached 130 Repositories After a Hardware Key Code Was Relayed

Cloudflare was not saved by the metal. It was saved by origin binding — and this key was not doing that.

UnattributedPhishing → OTP relayTechnologySupply chain
Sev 3TargetDropboxActorUnattributedUSA
22-1020
File

Advocate Aurora Told 3 Million Patients Tracking Pixels Sent Data to Meta and Google

No credential stolen, no flaw exploited. Somebody wanted to understand how patients used the portal.

Tracking technology, by designHealthcareHealthcare
Sev 4TargetAdvocate Aurora HealthActorUnattributedUSA
22-1005
File

Former Uber Security Chief Convicted Over $100,000 Routed Through the Bug Bounty Programme

The concealment ran through a control rather than around one. That is what made it work.

TechnologyAccountability
Sev 2TargetUberActorUnattributedUSA
22-0930
File

ProxyNotShell Mitigation Described One Exploit and Was Bypassed Twice

Blocking a URL pattern encodes the exploit you have seen, not the defect that allows it.

UnattributedCVE-2022-41040 → CVE-2022-41082TechnologyExploitation
Sev 4TargetOn-premises Exchange operatorsActorUnattributedUSA
22-0915
File

The Contractor Approved the Eighteenth Prompt

The second factor was not bypassed. It was delivered to the right person, who said yes.

Lapsus$MFA fatigue → social engineeringTechnologyIdentity
Sev 4TargetUberActorLapsus$USA
22-0825
File

LastPass Developer Breach Took 14 Repositories Four Months Before the Vault Theft

Everything the company said in August was true. In December none of it helped.

UnattributedCompromised developer accountTechnologyConcentration
Sev 3TargetLastPassActorUnattributedUSA
22-0815
File

Signal Says Twilio Breach Exposed 1,900 Users, With Three Numbers Targeted by Name

1,900 is the exposure. Three is the objective. No notification scheme has a field for that.

UnattributedThird-party compromise — TwilioTechnologyThird party
Sev 3TargetSignalActorUnattributedUSA
22-0808
File

Same Phish, Same Week, Two Companies, Two Outcomes

Three Cloudflare employees typed their password into the attacker’s page. Nothing happened.

0ktapusSMS phishing → credential relayTechnologyIdentity
Sev 4TargetTwilioActor0ktapusUSA
22-0804
File

Slack Sent Hashed Passwords to Workspace Members for Five Years

Duration and severity are independent axes. Only one of them gets published as a headline.

Application defectTechnologyVerification
Sev 2TargetSlackActorUnattributedUSA
22-0721
File

Twitter Flaw Exposed 5.4 Million Accounts Despite Privacy Settings

For a pseudonymous account, a phone number is not contact data. It is the link to the person.

UnattributedUnauthenticated API lookupTechnologyIdentity
Sev 3TargetTwitterActorUnattributedUSA
22-0720
File

Neopets Database of 69 Million Accounts Offered for Four Bitcoin

Collected from a child, retained past the relationship, past the product, past recognition.

UnattributedTechnologyIdentity
Sev 3TargetNeopetsActorUnattributedUSA
22-0527
File

Follina Exploited Word Documents With No Macro and No Protected View Warning

Ten years of telling people not to enable macros, and this one did not ask.

UnattributedCVE-2022-30190 — zero-dayTechnologyExploitation
Sev 4TargetWindows usersActorUnattributedUSA
22-0524
File

Cisco Breach Began With Corporate Credentials Synced to a Personal Google Account

The browser did nothing wrong. It carried a work password into a personal account, exactly as designed.

YanluowangSynced credentials → vishing → MFA pushTechnologyIdentity
Sev 3TargetCiscoActorYanluowangUSA
22-0523
File

ICO Fined Clearview AI £7.5 Million Over 20 Billion Scraped Images, Later Overturned

A remedy that fitted the harm and could not reach the party holding it.

Web scraping, by designTechnologyEnforcement
Sev 3TargetClearview AIActorUnattributedUnited Kingdom
22-0412
File

GitHub Says Stolen Heroku and Travis-CI Tokens Exposed Private Repositories at Dozens of Organisations

The security of a system is the security of everyone it has delegated to — a set nobody enumerates.

UnattributedStolen OAuth tokensTechnologySupply chain
Sev 4TargetGitHub customers, incl. npmActorUnattributedUSA
22-0322
File

Lapsus$ Took Source Code From Nvidia, Samsung and Microsoft Without Encrypting Anything

The encryption step was always optional. Drop it and you keep the reputational leverage for a fraction of the work.

Lapsus$TechnologyExtortion
Sev 4TargetNvidia, Samsung, MicrosoftActorLapsus$USA
22-0120
File

The Identity Provider Was Reached Through Its Outsourced Support Desk

The alert fired on day one. The customers heard on day sixty-one, from the attackers.

Lapsus$Contractor remote accessTechnologyThird party
Sev 4TargetOktaActorLapsus$USA
© 2026 ForensicPost Media · the desk · newsletterGlossaryNo search logging