Denmark CPR Data Breach: 8.8 Million Records

Denmark CPR data breach: 8.8 million records pulled through one company's lawful registry access. An oversized invoice exposed it after ten days.

The Denmark CPR data breach exposed the names, addresses and personal ID numbers of about 8.8 million people, roughly four in five records in the country’s Central Person Register. Unauthorized parties reached it through a smaller company’s lawful lookup access, ran more than 14 million queries over about ten days in September, and were noticed…

Read More

September 2026 Cybersecurity Roundup

September 2026 Cybersecurity Roundup: Berlin's Rhysida leak, Keio, Landsberg, 220M exposed travel records, plus 4 exploited CVEs.

This September 2026 Cybersecurity Roundup covers a month in which ransomware kept disrupting public services and critical infrastructure, while flaws in widely used network appliances created serious exposures of their own. Attacks hit German government and utility networks, and a misconfigured database exposed 220 million Vietnam-linked travel records. Below are the month’s key cyberattacks and…

Read More

Revolut Data Breach: Trusted Channel Abuse

Revolut data breach report showing customer information exposed through fraudulent government requests

A recent Revolut data breach shows how attackers can exploit trust without breaking into a bank’s core infrastructure. By using a compromised Italian government email account to submit fraudulent customer-data requests, attackers reportedly persuaded Revolut staff to disclose sensitive information linked to roughly 680 customers across several European countries. The incident exposed a second problem:…

Read More

August 2026 Cybersecurity Roundup

August 2026 Cybersecurity Roundup: breaches at SafePal, CEVA Logistics, France's tax authority, Latvia's CSDD, and Manchester Airports, plus 5 critical CVEs.

This August 2026 Cybersecurity Roundup lands in a month when several of the biggest breaches traced back to familiar weaknesses: a compromised employee credential, an overlooked customer-facing plugin, and infrastructure monitoring that watched the wrong signals. Here’s a look at the month’s key cyberattacks and CVEs, along with our take on what they mean for…

Read More

Metabase CVSS 10 SQL Injection Zero-Day Hits Admin Access

The Metabase CVSS 10 SQL injection zero-day gives attackers admin access and every connected database credential. Framework and Tally already hit.

The Metabase CVSS 10 SQL injection zero-day lets an unauthenticated attacker turn a self-hosted analytics dashboard into a master key for every database it touches. Active exploitation began August 3, 2026, and two named victims — Framework and Tally — have already confirmed customer data theft. If your organization runs Metabase for internal reporting, this…

Read More