Une entreprise de distribution d'eau au Royaume-Uni a subi une fuite de données — et les victimes décrivent un sentiment d'intrusion profonde. Ce qui frappe : les infrastructures critiques cumulent deux défis, la sécurité technique ET la relation de confiance avec des usagers qui n'ont pas choisi d'être clients. La surface d'attaque est aussi humaine. #infosec #breach #infrastructuresCritiques
https://malware.news/t/uk-victims-feel-violated-after-water-firm-s-data-breach/107274
UK: Victims feel ‘violated’ after water firm’s data breach

Oprah Flash reports: “Violated” and being “unable to trust” have been the feelings plaguing victims of a cyber attack on a Midlands-based water company. The personal data of 633,887 people was stolen and published on the dark web, after South Staffs Water was hacked in 2020. Customers said they faced a deluge of scam emails… Introduction to Malware Binary Triage (IMBT) Course Looking to level up your skills? Get 10% off using coupon code: MWNEWS10 for any flavor. Enroll Now and Save 10%: Coup...

Malware Analysis, News and Indicators
🤦‍♂️ Ah, the classic government strategy: wait for a massive #data #breach and then demand answers in a bewildered frenzy. Meanwhile, CISA's strategy of posting sensitive keys on a public GitHub is a bold new frontier in cloud storage solutions. 🚀🌐
https://krebsonsecurity.com/2026/05/lawmakers-demand-answers-as-cisa-tries-to-contain-data-leak/ #governmentstrategy #CISA #cloudstorage #cybersecurity #HackerNews #ngated
Lawmakers Demand Answers as CISA Tries to Contain Data Leak – Krebs on Security

Trump Mobile confirms it exposed customers’ personal data, including phone numbers and home addresses

Phone provider Trump Mobile has confirmed that it was exposing customers’ names, email addresses, mailing addresses, cell numbers, and order identifiers to the open internet.

https://techcrunch.com/2026/05/22/trump-mobile-confirms-it-exposed-customers-personal-data-including-phone-numbers-and-home-addresses/

#trumpphone #android #security #breach

Trump Mobile confirms it exposed customers' personal data, including phone numbers and home addresses | TechCrunch

President Trump’s branded cell phone maker and cell provider said the exposure was linked to a third-party platform, and was evaluating whether it needs to notify customers.

TechCrunch
Data of around 1,700 people potentially compromised in Canvas data breach, N.W.T. gov't says
Approximately 1,700 teachers, education staff, government employees, program participants and contractors are affected by a breach that may have compromised email addresses, enrollment information and training data.
https://www.cbc.ca/news/canada/north/canvas-breach-nwt-9.7208039?cmp=rss
#GitHub confirmed a #breach of approximately 3,800 #internalrepositories after an employee installed a malicious VS Code extension. The company removed the extension and secured the compromised device. The TeamPCP hacker group claimed responsibility for the breach, demanding $50,000 for the stolen data. https://www.bleepingcomputer.com/news/security/github-confirms-breach-of-3-800-repos-via-malicious-vscode-extension/?eicker.news #tech #media #news
GitHub confirms breach of 3,800 repos via malicious VSCode extension

GitHub has confirmed that roughly 3,800 internal repositories were breached after one of its employees installed a malicious VS Code extension.

BleepingComputer

GitHub Investigating TeamPCP Claimed Breach of ~4,000 Internal Repositories

Ravie Lakshmanan
May 20, 2026

https://thehackernews.com/2026/05/github-investigating-teampcp-claimed.html

#github #breach

GitHub Breached — Employee Device Hack Led to Exfiltration of 3,800+ Internal Repos

GitHub is investigating unauthorized access to internal repositories after TeamPCP listed alleged source code and internal organizations for sale.

The Hacker News

The GitHub breach last night was worse than reported. 4000 or so private repos for sale on Tor. LAPSUS$ is claiming it's for sale already but it isn't on their release site.

https://thehackernews.com/2026/05/github-investigating-teampcp-claimed.html?m=1

#github #breach

GitHub Breached — Employee Device Hack Led to Exfiltration of 3,800+ Internal Repos

GitHub is investigating unauthorized access to internal repositories after TeamPCP listed alleged source code and internal organizations for sale.

The Hacker News

GitHub Discloses Breach from Poisoned VS Code Extension

GitHub swiftly detected and contained a security breach that originated from a tainted Visual Studio Code extension, taking immediate action to remove the malicious version and isolate the affected endpoint. The breach appears to be limited to GitHub's internal repositories, with the company rotating critical secrets and conducting a thorough…

https://osintsights.com/github-discloses-breach-from-poisoned-vs-code-extension?utm_source=mastodon&utm_medium=social

#Github #VisualStudioCode #SupplyChain #CodePoisoning #Breach

GitHub Discloses Breach from Poisoned VS Code Extension

GitHub reveals breach from poisoned VS Code extension, takes swift action to contain threat, learn how they responded and what it means for you now.

OSINTSights

GitHub Says 3,800 Repositories Breached

GitHub에서 내부 직원의 악성 VS Code 확장 프로그램 설치로 인해 약 3,800개의 내부 저장소가 침해되는 보안 사고가 발생했다. 해킹 그룹 TeamPCP는 GitHub 소스 코드와 내부 조직 정보를 탈취했다고 주장하며 5만 달러에 판매하려 하고, 구매자가 없으면 데이터를 공개하겠다고 위협 중이다. GitHub는 고객 데이터 유출은 없다고 밝혔으나, 2단계 인증과 패스키 사용 등 계정 보안 강화를 권고하고 있다. 이번 사건은 개발자 인프라 보안과 공급망 취약점 대응의 중요성을 다시 한번 부각시킨다.

https://www.forbes.com/sites/daveywinder/2026/05/20/github-says-3800-repositories-breached-teampcp-hackers-demand-50000/

#github #security #breach #supplychain #phishing

GitHub Says 3,800 Repositories Breached—TeamPCP Hackers Demand $50,000

A GitHub employee has unwittingly allowed 3,800 internal repositories to be breached after a device compromise with a poisoned VS Code extension.

Forbes

🗡️ GitHub says hackers stole data from thousands of internal repositories
by Zack Whittaker @zackwhittaker.com @zackwhittaker
at @TechCrunch
#Github #Security #Breach #Cybersecurity

https://techcrunch.com/2026/05/20/github-says-hackers-stole-data-from-thousands-of-internal-repositories/