Topic

Breaches & Data Leaks

Real-world intrusions and data leaks — how they started and the lessons for security teams.

66 articles in this topic

Breaches & Data Leaks

GitHub Breached via Poisoned VS Code Extension: 3,800 Internal Repos Exfiltrated by TeamPCP

A poisoned VS Code extension gave TeamPCP access to 3,800 GitHub internal repositories — exposing Copilot, Actions, and CodeQL source code. Here's what Saudi CISOs must do about developer tool supply chain risk.

20 May 2026 5 min
Breaches & Data Leaks

Coinbase Insider Bribery Breach: Why Saudi Financial CISOs Must Rethink Third-Party Personnel Risk

Bribed overseas contractors stole data from 70,000 Coinbase customers — a $400M lesson in why insider threat programs for third-party personnel are non-negotiable under SAMA CSCC and NCA ECC.

20 May 2026 5 min
Breaches & Data Leaks

ShinyHunters' 2026 Breach Spree: How One Group Compromised Billions of Records Across Six Sectors

ShinyHunters breached the EU Commission, Medtronic, Rockstar Games, and 8,809 universities in five months — all through OAuth misconfigurations and supply chain trust. Here's what Saudi financial CISOs must do now.

19 May 2026 6 min
Software Engineering

Grafana GitHub Token Breach: How a CI/CD Misconfiguration Exposed the Codebase Behind Your SOC Dashboards

A single misconfigured GitHub Action let attackers steal Grafana's entire codebase. For Saudi financial institutions relying on Grafana for SOC dashboards, the breach raises urgent questions about CI/CD pipeline security and open-source supply chain risk.

19 May 2026 5 min
Supply Chain & Third Party

Mini Shai-Hulud Worm: How One npm Install Compromised 160+ Packages and Stole CI/CD Secrets

A self-propagating worm dubbed Mini Shai-Hulud hijacked 160+ npm and PyPI packages — including TanStack and Mistral AI — turning every compromised developer into a new infection vector. Here's what your DevSecOps team needs to act on immediately.

19 May 2026 5 min
Breaches & Data Leaks

Instructure Pays ShinyHunters Ransom After 275M Canvas Records Stolen: SaaS Vendor Risk Lessons for Financial Institutions

Instructure paid ShinyHunters after 275M Canvas records were stolen in two breaches within one week. Critical SaaS vendor risk lessons for SAMA-regulated financial institutions.

17 May 2026 6 min
Ransomware

Everest Ransomware Hits Two US Banks via Third-Party Vendor: A Wake-Up Call for Saudi Financial Sector Supply Chain Security

Everest ransomware breached two US banks through a single shared vendor, exposing 250K customer records. Here's what Saudi financial institutions must learn about third-party risk under SAMA CSCC.

16 May 2026 5 min
Breaches & Data Leaks

The Vercel Breach: How One Forgotten OAuth Token Exposed an Entire Platform

A single employee's forgotten trial of an AI tool handed attackers the keys to Vercel's kingdom. Here's what Saudi financial institutions must learn about OAuth sprawl and shadow AI before it happens to them.

16 May 2026 6 min
Software Engineering

Mini Shai-Hulud Supply Chain Worm Hits TanStack and Breaches OpenAI Through Trusted CI/CD Pipelines

A self-spreading worm hijacked TanStack's legitimate GitHub Actions pipeline, published malicious packages indistinguishable from real ones, and breached OpenAI — exposing fatal gaps in software supply chain security.

16 May 2026 5 min
Ransomware

Everest Ransomware Breaches TSYS and Two Major Banks Through a Single Vendor

The Everest ransomware group compromised a payment processor and two major US banks through a single third-party vendor — exposing 3.6 million records. Here's what Saudi financial institutions must do about third-party risk now.

14 May 2026 5 min
Breaches & Data Leaks

Canvas Breach: How ShinyHunters Stole 275 Million Education Records and What It Means for Saudi Data Protection

ShinyHunters stole 275 million records and 3.65TB of data from Instructure's Canvas LMS — the largest education breach in history. Here's what Saudi CISOs must learn about vendor risk and PDPL obligations.

14 May 2026 6 min
Vulnerabilities

CVE-2026-3854: Critical GitHub RCE Flaw Exposed Millions of Repositories via Single Git Push

A single git push command was all it took to execute arbitrary code on GitHub's backend servers. CVE-2026-3854 exposed millions of public and private repositories — here's what Saudi financial institutions must do now.

13 May 2026 5 min

Start a conversation

What are you working through?

Describe where you stand, and a specialist will reply with a clear next step — not a generic pitch.

  • A free first consultation
  • A reply within one business day
  • Full confidentiality