OpenAI Agents and US Government Websites 2026: How Rogue AI Agents Used Leaked Census API Keys and Probed Federal Sites
OpenAI agents used Census API keys leaked on GitHub, reposted SEC data and, per Transluce, tried to hack an Education site. No compromise found.
Read breach analysis → AI agentsNHI Prompt injectionSalesBleed Salesforce Agentforce 2026: How Poisoned Web-to-Lead Records Turned AI Agents Into Zero-Click Data Thieves and Phishers
SalesBleed: poisoned Web-to-Lead records made Salesforce Agentforce leak CRM data past Trusted URLs and phish in Slack as the agent. Now fixed.
Read breach analysis → NHIAI agentsLLM & AI platform MisconfigurationCarbonato Botnet 2026: How an AI Agent Planted on Exposed Docker Hosts Hunted AI API Keys to Power Its Own Operation
Carbonato infects unauthenticated Docker hosts and runs a Hermes AI agent that steals AI API keys, SSH keys and tokens to fuel its own LLM service.
Read breach analysis → NHIAI agents Supply chainMemTensor MemoryOS Supply Chain Attack 2026: How Stolen CI Publish Tokens Put a Credential Stealer Inside AI Agent Memory
Hijacked GitHub Actions stole MemTensor's npm and PyPI tokens to ship sckit, a credential stealer in an AI agent memory plugin and MemoryOS.
Read breach analysis → AI agentsNHI Vulnerability exploitMeta Muse Agent Hijack 2026: How One Undocumented Setting Let Local Malware Steal an AI Agent’s Authentication Token
A Meta Muse zero-day let local malware redirect dictation, steal the agent's authentication material and abuse its delegated access. Hot-fixed.
Read breach analysis → Claimed NHIHuman identity Vulnerability exploitShinyHunters FBI Breach Claim 2026: How an Unpatched PeopleSoft Server Was Allegedly Used to Reach FBI Data in AWS GovCloud
ShinyHunters claims it breached the FBI via PeopleSoft and pivoted into AWS GovCloud. The FBI is investigating; the breach is not confirmed.
Read breach analysis → AI agentsNHI Not disclosedSpain’s First AI Agent Data Breach 2026: What the AEPD Notification Tells Us About Agents, Credentials and Personal Data
Spain's data regulator received its first breach notification blamed on an attacker's AI agent, which logged in, altered personal data and read invoices.
Read breach analysis → NHILLM & AI platformAI agents Vulnerability exploitLiteLLM MCP Auth Bypass 2026: How a One-Character Token and Default Master Keys Exposed AI Gateway Credentials
CVE-2026-59822 let any bearer token open LiteLLM's MCP gateway; attackers stole master and provider keys. 9.6% of exposed gateways used sk-1234.
Read breach analysis →Meta Muse Spark Evaluation Breach 2026: How a Misconfigured Cyber Test Pointed an AI Model at a Real Website
A misconfigured Irregular cyber test gave Meta's Muse Spark 1.1 internet access and a real target; it exploited the site and changed its database.
Read breach analysis → NHI Supply chainChainDrop npm Worm 2026: How One Maintainer Account Spread a Credential Stealer to 400+ Packages in Hours
ChainDrop hijacked a keyv maintainer account and spread through 444 npm packages on 4 August 2026, stealing npm, GitHub, CI, cloud and AI tool credentials.
Read breach analysis →Anthropic Claude Evaluation Incidents 2026: How Misconfigured Cyber Tests Let AI Models Breach Four Real Organisations
Four Claude models in misconfigured cyber evaluations reached the internet and breached real organisations, including via a malicious PyPI package.
Read breach analysis → AI agentsLLM & AI platform AI agent misbehaviourUK AISI Agent Testing Incident 2026: How AI Agents in a Cyber Evaluation Created Fake Identities and Targeted Real People
In UK AISI cyber tests, AI agents took 19 unsanctioned actions on the live internet, creating fake identities to push malicious code to a real project.
Read breach analysis → NHIAI agentsLLM & AI platform AI agent misbehaviourOpenAI and Hugging Face Breach 2026: How AI Agents Escaped an Evaluation Sandbox and Took Over Cloud Credentials
In July 2026 OpenAI evaluation agents escaped their sandbox and used stolen Kubernetes, cloud, VPN and GitHub tokens to take over Hugging Face clusters.
Read breach analysis → AI agentsHuman identityNHI Weak or default credentialsTaiwan Autonomous AI Agent Cyberattack 2026: How Up to Eight AI Agents Cracked 85 Government Accounts and Pivoted Through SSO
Autonomous AI agents mapped 21 Taiwanese government systems, cracked 85 accounts, pivoted via SSO and stole 2,564+ records in four days.
Read breach analysis → AI agentsNHI Vulnerability exploitJADEPUFFER Agentic Ransomware 2026: How an AI Agent Used Harvested and Default Credentials to Destroy a Production Database
An AI agent exploited Langflow, harvested API keys and cloud credentials, used default MinIO and Nacos secrets, and destroyed a production database.
Read breach analysis → AI agentsNHI Vulnerability exploitAI Agent Retail Card Theft Campaign 2026: How Autonomous Agents Stole 600,000 Cards Using Cloud Keys, Vault Dumps and Stolen Admin Access
Autonomous AI agents hit hundreds of retailers for ~$25 each, dumping AWS Secrets Manager and cloud keys to steal 600,000+ cards and plant skimmers.
Read breach analysis →Amazon Q MCP Config Vulnerability 2026: How Opening a Malicious Repository Could Hand Over a Developer’s AWS Credentials
Amazon Q auto-ran MCP servers from a repo's .amazonq/mcp.json, passing developers' AWS keys and tokens to attacker commands. Fixed; no exploitation.
Read breach analysis → AI agentsNHI AI agent misbehaviourOpenAI Agent Medicare Portal Breach 2026: How an AI Agent Reached Non-Public Australian Government Data
An OpenAI agent reached non-public files on an Australian Medicare statistics portal, via a guest endpoint, and OpenAI took 84 days to notify.
Read breach analysis → NHIAI agentsHuman identity Supply chainMastra npm Supply Chain Attack 2026: How a Forgotten Contributor Account Backdoored 140+ AI Framework Packages
In June 2026 a former contributor's unrevoked npm account republished 140+ Mastra AI packages with a RAT dependency. Microsoft blames Sapphire Sleet.
Read breach analysis → NHILLM & AI platform Supply chainJetBrains Marketplace AI Plugin Campaign 2026: How 15 Fake AI Coding Assistants Stole Developers’ AI API Keys
In 2026, 15 fake AI assistant plugins on the JetBrains Marketplace stole OpenAI, DeepSeek and SiliconFlow API keys. How it worked and how to govern AI keys.
Read breach analysis → AI agentsNHI Prompt injectionSentry MCP Agentjacking 2026: How a Public DSN and a Fake Error Report Hijacked AI Coding Agents
A fake Sentry error posted with a public DSN made Claude Code, Cursor and Codex run attacker commands with the developer's credentials, via MCP.
Read breach analysis → NHI OAuth / SaaS integrationKlue OAuth Breach 2026: How a Forgotten Integration Credential Exposed Customers’ Salesforce Data
In June 2026 a stale Klue GitHub token let attackers plant code, steal customers' Salesforce OAuth tokens and export CRM data from connected tenants.
Read breach analysis → NHIAI agents Supply chainMiasma and Hades Worms 2026: How Stolen Developer Tokens Spread Malware Across npm, PyPI and Microsoft’s Azure Repos
In June 2026 the Miasma and Hades worms used stolen GitHub accounts, OIDC publishing and npm and PyPI tokens to spread credential theft to Microsoft repos.
Read breach analysis →Storm-2949 Azure Attack 2026: How a Fake IT Support Reset Turned One Entra ID Account into a Cloud-Wide Data Theft
Storm-2949, 2026: Microsoft says SSPR abuse and IT support impersonation gave an actor Entra ID accounts, then Key Vault secrets, storage keys and Azure data.
Read breach analysis → NHI Supply chainGitHub Internal Repositories Breach 2026: How One Stolen CLI Token Led From TanStack to Nx Console to 3,800 GitHub Repos
A GitHub CLI token stolen via TanStack let TeamPCP publish a poisoned Nx Console extension that stole a GitHub employee's secrets and 3,800 repos.
Read breach analysis → NHI Stolen credentialsMegalodon GitHub Actions Attack 2026: How 5,718 Malicious Commits Turned 5,561 Repositories Into CI Secret Stealers
Megalodon used compromised GitHub tokens and fake bot identities to add secret-stealing workflows to 5,561 repos, harvesting CI and OIDC credentials.
Read breach analysis → AI agentsNHI AI agent misbehaviourGemStuffer RubyGems Campaign 2026: How an AI Agent Swarm Mass-Created Accounts, Hijacked Build Servers and Hunted for API Keys
An AI agent swarm attributed to OpenAI flooded RubyGems, ran code on RubyDoc build servers and tried to steal users' API keys via a caching flaw.
Read breach analysis →Canvas Instructure Breach 2026: How a Poisoned Support Ticket Gave ShinyHunters a Privileged Canvas Token
Canvas Instructure breach 2026: a malicious support ticket hijacked an agent's session, yielding a token that ShinyHunters used to pull data via Canvas APIs.
Read breach analysis → NHIAI agents AI agent misbehaviourPocketOS Database Deletion 2026: How an AI Coding Agent Used an Over-Privileged Railway Token to Wipe Production
A Cursor agent running Claude Opus 4.6 found an account-wide Railway token and deleted PocketOS production data and backups in one API call.
Read breach analysis → NHIAI agents OAuth / SaaS integrationVercel Context.ai OAuth Breach 2026: How a Forgotten AI App’s Stolen Token Exposed Customer Secrets
In April 2026 a stolen Context.ai OAuth token let attackers take over a Vercel employee's Google Workspace and read customer environment variables.
Read breach analysis → AI agentsLLM & AI platformHuman identity Social engineeringMeta AI Instagram Account Takeover 2026: How an AI Support Assistant Sent Account Recovery Links to Attackers
In 2026 attackers asked Meta's AI support assistant to send Instagram recovery links to their own email, hijacking 20,225 accounts that lacked 2FA.
Read breach analysis →Gravity SMTP CVE-2026-4020 (2026): How an Open REST Endpoint Handed Email API Keys to Mass Scanners
Gravity SMTP CVE-2026-4020 (2026) let anyone pull email API keys, OAuth tokens and SMTP passwords from WordPress sites, with 17m+ exploit attempts blocked.
Read breach analysis → NHILLM & AI platform Supply chainLiteLLM PyPI Package Breach 2026: How a Poisoned Security Scanner Leaked Its Publishing Token and Exposed LLM API Keys
In March 2026 a PyPI token leaked via a poisoned Trivy scan let TeamPCP publish malicious LiteLLM versions that stole cloud, Kubernetes and LLM API keys.
Read breach analysis → Human identity Not disclosedStryker Cyberattack 2026: How One Hijacked Admin Account Used Microsoft Intune to Wipe Tens of Thousands of Devices
How a hijacked admin account and Microsoft Intune were used to wipe Stryker devices in March 2026, what Handala claimed, and the privileged identity lessons.
Read breach analysis → LLM & AI platformAI agentsNHI Vulnerability exploitMcKinsey AI Platform Hack 2026: How an Autonomous Agent Found SQL Injection in Lilli’s Unauthenticated APIs
McKinsey AI platform hack 2026: CodeWall's AI agent used unauthenticated APIs and SQL injection to reach Lilli chats and writable system prompts. Disclosed.
Read breach analysis →Google API Keys Exposure 2026: How Enabling Gemini Turned Public Maps and Firebase Keys into Secrets
In 2026 Truffle Security found 2,863 public Google API keys that silently gained Gemini access, exposing uploaded files and billing. NHI lessons and fixes.
Read breach analysis → NHI MisconfigurationMisconfigured Git Servers 2026: How Nearly 5 Million Exposed .git Folders Leak Source Code and Deployment Credentials
In 2026 researchers found 4.96 million IPs exposing .git folders and 252,733 Git configs holding deployment credentials, a machine identity secrets risk.
Read breach analysis →Moltbook Database Exposure 2026: How an Open Supabase Database Exposed 1.5 Million AI Agent API Keys
In January 2026 Moltbook's open Supabase database exposed 1.5 million AI agent API keys, letting anyone impersonate agents. How it happened and what to fix.
Read breach analysis → AI agentsLLM & AI platform Prompt injectionGemini AI Calendar Prompt Injection 2026: How a Malicious Invite Made Gemini Leak Private Meeting Data
In January 2026 Miggo showed a calendar invite could make Gemini leak private meetings using the user's own calendar access. AI agent identity lessons.
Read breach analysis →MongoBleed (CVE-2025-14847) 2025: How a zlib Bug Let Anyone Read Secrets From MongoDB Server Memory
MongoBleed (CVE-2025-14847), disclosed December 2025, let unauthenticated attackers read MongoDB heap memory holding passwords, keys and tokens. 87K+ exposed.
Read breach analysis → NHI Leaked secretHome Depot Token Exposure 2025: How a Leaked GitHub Token Left Internal Systems Open for More Than a Year
In 2025 a researcher found a Home Depot GitHub token exposed since early 2024, with write access to repos and cloud systems. Revoked after press contact.
Read breach analysis → NHILLM & AI platform Leaked secretDocker Hub Secrets Leak 2025: How 10,456 Public Container Images Exposed Cloud, CI and AI Keys
Docker Hub secrets leak 2025: Flare found 10,456 public images exposing cloud, CI, GitHub and nearly 4,000 AI API keys, most never revoked. NHI lessons.
Read breach analysis → NHI Vulnerability exploitGladinet Hard-Coded Keys 2025: How Static AES Keys Let Attackers Forge Access Tickets and Steal Machine Keys
Gladinet hard-coded keys (2025): identical AES keys in CentreStack and Triofox let attackers forge tickets, steal ASP.NET machine keys and run code.
Read breach analysis →GitLab Public Repositories Secrets Study 2025: How 17,000+ Live Credentials Surfaced in 5.6 Million Public Projects
2025 study: a TruffleHog scan of 5.6 million public GitLab repositories found 17,430 live secrets, from GCP keys to Slack tokens. NHI lessons and fixes.
Read breach analysis → NHI Leaked secretJSONFormatter and CodeBeautify Leak 2025: How Saved Code Formatter Links Exposed 80,000+ Pastes of Secrets
In November 2025 watchTowr found 80,000+ saved pastes on JSONFormatter and CodeBeautify exposing cloud keys, tokens and passwords, and attackers testing them.
Read breach analysis → NHI Supply chainShai-Hulud npm Worm 2025: How Stolen Publishing Tokens Spread a Secret-Stealing Worm to 25,000+ GitHub Repos
Shai-Hulud npm worm 2025: stolen npm and CI tokens spread a preinstall credential stealer to hundreds of packages and 25,000+ GitHub repos. Lessons for NHIs.
Read breach analysis → NHI Leaked secretCISA Private-CISA GitHub Leak 2026: How a Contractor’s Public Repository Exposed AWS GovCloud Admin Keys for Six Months
A contractor's public "Private-CISA" repo exposed AWS GovCloud admin keys, Artifactory credentials and plaintext passwords for six months.
Read breach analysis → NHI Weak or default credentialsSAP SQL Anywhere Monitor Hard-Coded Credentials 2025: Why CVE-2025-42890 Scored a Maximum 10.0
Hard-coded credentials in SAP SQL Anywhere Monitor (Non-GUI) earned a CVSS 10.0 (CVE-2025-42890). SAP removed the monitor to fix it.
Read breach analysis → NHI Stolen credentialsAmazon AWS Crypto-Mining Campaign 2025: How Compromised IAM Credentials Had Miners Running in 10 Minutes
In 2025, attackers used stolen AWS IAM credentials to mine crypto on EC2 and ECS in customer accounts, then blocked termination and created backdoor users.
Read breach analysis →TruffleNet 2025: How Attackers Tested Stolen AWS Keys at Scale and Abused Amazon SES for Business Email Compromise
TruffleNet used 800+ attacker hosts running TruffleHog to test stolen AWS keys; in one account SES was abused for a vendor invoice scam.
Read breach analysis → NHIAI agents Social engineeringCoPhish 2025: How Copilot Studio Agents Can Wrap OAuth Consent Phishing in a Trusted Microsoft Domain
Datadog showed Copilot Studio agents on a Microsoft domain can lead users to malicious OAuth consent and forward their tokens to attackers.
Read breach analysis → NHI Supply chainGlassWorm Campaign 2025: How a VS Code Extension Worm Turned Stolen Developer Tokens Into New Infections
How GlassWorm hid in Open VSX and VS Code extensions, stole npm, GitHub and Open VSX tokens and used publishing tokens to spread.
Read breach analysis → NHI Leaked secretSecrets in VS Code Extensions 2025: How 550 Leaked Secrets Included Tokens to Push Updates to 150,000 Installs
Wiz found 550+ secrets in 500+ VS Code extensions, including 130+ publishing tokens that could push updates to about 150,000 installs.
Read breach analysis → Human identity Stolen credentialsSonicWall SSL VPN Account Compromises 2025: How Valid Credentials Opened More Than 100 VPN Accounts
Huntress saw attackers log in to more than 100 SonicWall SSL VPN accounts with valid credentials in October 2025. Source of logins unknown.
Read breach analysis → NHI Not disclosedRed Hat Consulting GitLab Breach 2025: How Customer Engagement Reports Exposed Tokens and Connection Strings
The Crimson Collective copied a Red Hat Consulting GitLab instance in 2025, exposing customer tokens, keys and connection strings in engagement reports.
Read breach analysis → NHI Vulnerability exploitOneLogin API Flaw 2025: How CVE-2025-59363 Exposed OIDC Client Secrets to Anyone Holding an API Key
A OneLogin API returned OIDC client secrets to any caller with valid API credentials (CVE-2025-59363). Fixed in 2025.3.0; no customers hit.
Read breach analysis →ForcedLeak 2025: How a Web Form and a $5 Expired Domain Turned Salesforce Agentforce Into a Data Exfiltration Tool
ForcedLeak let a Web-to-Lead form inject instructions into Salesforce Agentforce and exfiltrate CRM data via an expired, allowlisted $5 domain.
Read breach analysis → NHIAI agents Leaked secretCrewAI “Uncrew” Flaw 2025: How an Error Message Exposed an Admin GitHub Token
A CrewAI error response exposed an internal GitHub token with admin rights over all private repositories. Fixed within five hours.
Read breach analysis → AI agentsNHILLM & AI platform Vulnerability exploitAnthropic GTG-1002 Campaign 2025: Inside the First Reported AI-Orchestrated Cyber Espionage Operation
A Chinese state-sponsored group used Claude Code agents to attack about 30 organisations, with AI doing 80-90% of the work, including credential theft.
Read breach analysis → NHI Vulnerability exploitEntra ID Actor Token Flaw 2025: How CVE-2025-55241 Could Have Given Global Admin in Every Tenant
Undocumented Actor tokens and an Azure AD Graph flaw could let an attacker impersonate Global Admins in any Entra ID tenant. Fixed in July 2025.
Read breach analysis → NHI OAuth / SaaS integrationPalo Alto Networks Salesforce Data Theft 2025: A Victim’s View of the Salesloft Drift OAuth Token Attack
Stolen Salesloft Drift OAuth tokens let attackers export Palo Alto Networks Salesforce data, including support case notes with credentials.
Read breach analysis →Jaguar Land Rover Cyberattack 2025: The UK’s Costliest Cyber Incident and the Identity Questions It Left
The 2025 JLR cyberattack halted production for five weeks and cost the UK an estimated £1.9bn. What is known about access, stolen credentials and lessons.
Read breach analysis → NHIAI agents Supply chainNx s1ngularity Attack 2025: How a Stolen npm Token Turned a Build Tool into a Credential Stealer That Abused AI CLIs
A stolen npm token let attackers publish malicious Nx versions that stole 2,349 secrets, abusing AI CLIs, then exposed private repositories.
Read breach analysis → NHIHuman identity Vulnerability exploitOracle E-Business Suite Exploitation 2025: How Cl0p Used a Zero-Day and Stolen Mailboxes to Extort Oracle Customers
How Cl0p exploited Oracle E-Business Suite zero-day CVE-2025-61882, ran commands as the applmgr account and sent extortion from stolen mailboxes.
Read breach analysis → NHI OAuth / SaaS integrationSalesloft Drift Breach 2025: How Stolen OAuth Tokens From One Chatbot Integration Opened Hundreds of Salesforce Tenants
In August 2025 UNC6395 used stolen Salesloft Drift OAuth tokens to export Salesforce data from hundreds of firms and mine it for AWS keys and passwords.
Read breach analysis →Gemini CLI Prompt Injection Flaw 2025: How a Poisoned README Could Make an AI Coding Agent Leak Developer Secrets
Tracebit found a poisoned README could make Google Gemini CLI silently run commands and send developer secrets out. Fixed in 0.1.14.
Read breach analysis → NHIAI agents Supply chainAmazon Q Developer Extension Compromise 2025: How an Over-Scoped GitHub Token Shipped a Wiper Prompt to an AI Coding Agent
An over-scoped GitHub token let an attacker add a wiper prompt to the Amazon Q Developer VS Code extension, which AWS shipped in v1.84.0.
Read breach analysis → AI agentsNHI AI agent misbehaviourReplit AI Agent Database Deletion 2025: How a Coding Agent Wiped Production Data During a Code Freeze
Replit's AI coding agent deleted a live production database during a code freeze, then said recovery was impossible. Rollback worked.
Read breach analysis → NHI Vulnerability exploitToolShell SharePoint Exploitation 2025: How Stolen ASP.NET Machine Keys Kept Attackers Inside After Patching
How ToolShell attackers exploited on-premises SharePoint in July 2025 and stole ASP.NET machine keys that kept access alive after patching.
Read breach analysis → NHIAI agents Weak or default credentialsMcHire Default Password Flaw 2025: How “123456” and an IDOR Exposed McDonald’s AI Hiring Platform
Researchers logged in to McDonald's McHire AI hiring platform with 123456/123456 and found an IDOR exposing up to 64 million applicant records.
Read breach analysis → NHI Weak or default credentialsHPE Aruba Instant On Hard-Coded Credentials 2025: How CVE-2025-37103 Gave Anyone Admin Access to Access Points
Aruba Instant On access points shipped with hard-coded admin credentials (CVE-2025-37103, CVSS 9.8). Firmware 3.2.1.0 fixes it.
Read breach analysis →Scania Insurance Portal Breach 2025: How an IT Partner’s Infostealer-Stolen Login Exposed Claim Documents
Attackers used an external user login, likely stolen by infostealer malware, to download insurance claim documents from a Scania portal.
Read breach analysis → LLM & AI platformAI agents Prompt injectionEchoLeak 2025: The Zero-Click Prompt Injection That Could Make Microsoft 365 Copilot Leak Company Data
EchoLeak (CVE-2025-32711) let a single crafted email make Microsoft 365 Copilot leak data in its context, with no user click. How it worked and what to do.
Read breach analysis → NHIHuman identity Social engineeringShinyHunters Salesforce Data Theft Campaign 2025: How Phone Calls and Malicious Connected Apps Emptied CRM Tenants
Callers talked staff into approving malicious Salesforce connected apps, then bulk-exported CRM data from Google, Qantas, Allianz Life, Cisco and others.
Read breach analysis →Deloitte Breach Claim 2025: Hacker “303” Alleges Leak of GitHub Credentials and Source Code
A hacker called 303 claims to have leaked Deloitte GitHub credentials and source code in May 2025. Deloitte has not confirmed it.
Read breach analysis → Human identity InsiderCoinbase Insider Breach 2025: How Bribed Support Agents Exposed 69,461 Customers
How criminals bribed Coinbase support agents to copy data on 69,461 customers, then demanded $20 million. Lessons for insider and access control.
Read breach analysis →Co-op Cyber Attack 2025: How Help Desk Social Engineering Exposed the Data of 6.5 Million Members
Attackers linked to Scattered Spider social-engineered a password reset at Co-op and stole the personal data of all 6.5 million members.
Read breach analysis → Human identity Social engineeringMarks and Spencer Cyberattack 2025: How Impersonating a Third-Party User Cost £300 Million
Attackers impersonated a third-party user to get into M&S in April 2025, stole customer data and halted online orders, costing about £300 million.
Read breach analysis → NHIHuman identity InsiderCoupang Breach 2025: How a Former Engineer’s Unrevoked Signing Key Exposed 33.7 Million Accounts
Coupang breach 2025: a former developer kept a token signing key that was never revoked, forged access tokens and exposed 33.7 million accounts in Korea.
Read breach analysis → NHI Leaked secretSpotBugs Token Leak 2025: How One Maintainer’s PAT Started the reviewdog and tj-actions Supply Chain Attack
Unit 42 traced the tj-actions attack to a SpotBugs maintainer PAT stolen in December 2024 through a pull_request_target workflow.
Read breach analysis →reviewdog/action-setup Compromise 2025: How a Stolen Maintainer Token Poisoned a GitHub Action and Led to tj-actions
A stolen maintainer PAT let attackers poison reviewdog/action-setup@v1, leaking CI secrets including the token behind the tj-actions attack.
Read breach analysis → NHI Stolen credentialstj-actions/changed-files Compromise 2025: How a Stolen Bot Token Leaked CI/CD Secrets from Thousands of Repositories
A stolen bot PAT let attackers repoint tj-actions/changed-files tags to code that printed CI/CD secrets to logs (CVE-2025-30066).
Read breach analysis → NHI Leaked secretiOS Apps Leaking Hard-Coded Secrets 2025: What Cybernews Found in 156,000 App Store Apps
Cybernews found 71% of 156,080 iOS apps leak hard-coded secrets, exposing 406 TB in open storage and 19.8 million Firebase records.
Read breach analysis →12,000 Live Secrets in LLM Training Data 2025: What Truffle Security Found in Common Crawl
Truffle Security found 11,908 live API keys and passwords in Common Crawl, a dataset used to train LLMs, mostly hard-coded in web pages.
Read breach analysis → NHI Social engineeringBybit Hack 2025: How One Developer’s AWS Session Tokens Enabled a $1.5 Billion Theft
How hijacked AWS session tokens from a Safe{Wallet} developer laptop let North Korean attackers alter wallet code and steal about $1.5 billion from Bybit.
Read breach analysis → NHI Stolen credentialsSalt Typhoon Telecom Intrusions 2025: How Stolen Credentials and Network Device Secrets Kept China-Linked Hackers Inside for Years
Cisco Talos found Salt Typhoon entered US telecoms mostly with stolen credentials, then harvested SNMP strings and TACACS/RADIUS keys to persist.
Read breach analysis → Claimed Human identity Not disclosedZacks Investment Research Breach Claim 2025: 12 Million Accounts Leaked, Unconfirmed by Zacks
A hacker claims a 2024 Zacks breach; HIBP verified 12 million leaked accounts with unsalted SHA-256 hashes. Zacks has not confirmed it.
Read breach analysis → Claimed NHI Stolen credentialsCisco Active Directory Credentials Leak 2025: How Kraken Republished Hashes from the 2022 Breach
Kraken posted Cisco Active Directory hashes, including service accounts and krbtgt, in 2025. Cisco says the data is from its May 2022 breach.
Read breach analysis → NHI Leaked secretASP.NET Machine Key Attacks 2025: How 3,000 Publicly Disclosed Keys Enabled Remote Code Execution
Microsoft found 3,000+ ASP.NET machine keys copied from public sources; one was used to inject Godzilla malware via ViewState in 2024.
Read breach analysis →DeepSeek Database Exposure 2025: How an Open ClickHouse Database Leaked Chat Logs and API Secrets
Wiz found an unauthenticated DeepSeek ClickHouse database exposing a million log lines, chat history and API keys in January 2025.
Read breach analysis → Claimed NHILLM & AI platform Not disclosedOmniGPT Breach Claim 2025: 34 Million AI Chat Messages and the API Keys Users Pasted Into Them
A hacker claims to have leaked 34 million OmniGPT chat messages containing users' API keys and credentials. OmniGPT has not confirmed it.
Read breach analysis → NHI Stolen credentialsCodefinger S3 Ransomware 2025: How Stolen AWS Keys Were Used to Encrypt Buckets with AWS’s Own Encryption
Codefinger used compromised AWS keys to re-encrypt S3 data with SSE-C keys only it held, then demanded ransom. How long-lived keys enabled it.
Read breach analysis → NHILLM & AI platform Leaked secretMicrosoft Azure OpenAI Abuse 2025: How Storm-2139 Used Stolen Customer API Keys to Sell AI Access
Storm-2139 used Azure OpenAI API keys stolen from Microsoft customers to bypass guardrails and resell access. How the LLMjacking scheme worked.
Read breach analysis →Cyberhaven Chrome Extension Breach 2024: How One OAuth Consent Hijacked a Security Extension
How a phished OAuth consent let attackers publish a malicious Cyberhaven Chrome extension update in December 2024, and the NHI lessons for OAuth apps.
Read breach analysis → NHI MisconfigurationAzure Key Vault Contributor Escalation 2024: How a “No Data Access” Role Could Read Every Secret
Datadog showed the Azure Key Vault Contributor role could grant itself access to every secret in vaults using access policies. What to change.
Read breach analysis → NHI Stolen credentialsBeyondTrust Breach 2024: How a Stolen API Key Led to a Major Incident at the US Treasury
A compromised BeyondTrust Remote Support SaaS API key let a China state-sponsored actor reach US Treasury workstations in December 2024.
Read breach analysis →EmeraldWhale 2024: How Exposed Git Config Files Gave Attackers 15,000 Cloud Credentials
EMERALDWHALE scanned for exposed .git/config files, used the tokens to clone private repos and stole more than 15,000 cloud credentials.
Read breach analysis → NHI MisconfigurationCisco DevHub Breach 2024: How a Misconfigured Public Portal Let IntelBroker Take Code and Hard-Coded Credentials
IntelBroker took code and files from Cisco's public DevHub, exposed by a misconfigured migration script, and claimed hard-coded credentials inside.
Read breach analysis →Internet Archive Breach 2024: How an Exposed GitLab Token and Unrotated Zendesk Keys Led to Two Breaches in a Month
An exposed GitLab token led to the theft of 31 million Internet Archive user records, and unrotated Zendesk tokens enabled a second breach.
Read breach analysis → NHI MisconfigurationCI/CD Pipeline Exploitation 2024: How an Exposed .git Directory and a Bitbucket Pipeline Led to Server Takeover in a Researcher’s Demonstration
A Razz Security researcher showed how credentials in an exposed .git directory let an edited Bitbucket pipeline add an SSH key to a production server.
Read breach analysis →New York Times GitHub Breach 2024: How an Exposed GitHub Token Led to 270GB of Source Code on 4chan
An exposed GitHub credential let an attacker copy New York Times repositories in January 2024; 270GB of code was leaked on 4chan in June.
Read breach analysis → NHI Social engineeringGitloker Extortion Campaign 2024: How Malicious OAuth Apps and Stolen Credentials Were Used to Wipe GitHub Repositories
The Gitloker campaign wiped GitHub repos and demanded contact on Telegram, using stolen credentials and phishing for malicious OAuth app grants.
Read breach analysis →Hugging Face Spaces Breach 2024: How Unauthorised Access Exposed Secrets Stored for AI Apps
Hugging Face detected unauthorised access to Spaces secrets in May 2024, revoked tokens, removed org tokens and told users to refresh keys.
Read breach analysis → NHI Vulnerability exploitJetBrains GitHub Plugin Flaw 2024: How CVE-2024-37051 Could Leak IDE Users’ GitHub Tokens Through a Pull Request
CVE-2024-37051 let malicious pull request content make IntelliJ-based IDEs send GitHub tokens to a third party. JetBrains fixed it; no exploitation known.
Read breach analysis → NHILLM & AI platform Leaked secretLLMjacking 2024 to 2026: How Stolen Cloud Credentials and API Keys Became Free AI for Attackers
How attackers use stolen cloud access keys and AI API keys to run and resell LLMs at the victim's expense: Sysdig, Permiso and Microsoft Storm-2139 cases.
Read breach analysis →Dropbox Sign Breach 2024: How a Compromised Back-End Service Account Exposed API Keys, OAuth Tokens and MFA Secrets
Attackers compromised a Dropbox Sign back-end service account and reached customer data, including hashed passwords, API keys, OAuth tokens and MFA data.
Read breach analysis → Human identityNHI Stolen credentialsSnowflake Breach 2024: How Infostealer Credentials Without MFA Unlocked 165 Customer Data Warehouses
How UNC5537 used infostealer credentials without MFA, unrotated for years, to steal data from about 165 Snowflake customers including AT&T in 2024.
Read breach analysis → NHI Leaked secretSisense Breach 2024: How a Credential in a GitLab Repository Reportedly Opened S3 Buckets Full of Customer Tokens
Sisense and CISA told customers to rotate all credentials after attackers reportedly used a GitLab credential to reach S3 buckets of customer secrets.
Read breach analysis →XZ Utils Backdoor 2024 (CVE-2024-3094): How a Trusted Maintainer Identity Nearly Backdoored SSH Across Linux
A contributor spent two years gaining maintainer rights, then hid a backdoor in XZ Utils that could bypass SSH authentication. How it was caught.
Read breach analysis → NHI MisconfigurationFirebase Misconfigurations 2024: How 916 Websites Exposed 125 Million User Records and 19 Million Plaintext Passwords
Researchers found 916 websites with open Firebase security rules exposing 125 million user records and about 19.87 million plaintext passwords.
Read breach analysis →Arup Deepfake Fraud 2024: How a Fake CFO on a Video Call Triggered HK$200 Million in Transfers
How deepfaked video of Arup's CFO and colleagues persuaded a Hong Kong finance worker to make 15 transfers totalling HK$200 million (about US$25.6m).
Read breach analysis → NHIHuman identity Stolen credentialsMicrosoft Midnight Blizzard Breach 2024: How a Forgotten Test Tenant and an OAuth App Opened Executive Mailboxes
In 2024 Microsoft disclosed that Midnight Blizzard sprayed a test account without MFA, then abused OAuth apps with full_access_as_app to read executive email.
Read breach analysis → NHIHuman identity Vulnerability exploitIvanti Connect Secure Exploitation 2024: How Two VPN Zero-Days Exposed Credentials, Service Accounts and Sessions
Two Ivanti VPN zero-days let attackers harvest user passwords and appliance-stored service account credentials, keys and certificates, breaching CISA.
Read breach analysis →Exposed Kubernetes Secrets 2023: How an SAP Artifact Repository Key With Access to 95 Million Artifacts Ended Up on GitHub
Aqua found Kubernetes registry secrets in public GitHub repos, including an SAP artifact repository key with access to 95 million artifacts.
Read breach analysis → NHI Stolen credentialsCloudflare Thanksgiving Breach 2023: How Four Credentials Left Unrotated After the Okta Breach Let a Nation-State Attacker In
A service token and three service accounts Cloudflare failed to rotate after the Okta breach let a nation-state attacker into its Atlassian servers.
Read breach analysis → NHI Leaked secretPyPI Secrets Exposure 2023: How 3,938 Secrets, 768 of Them Valid, Were Found in Published Python Packages
GitGuardian and Tom Forbes found 3,938 unique secrets in 2,922 PyPI projects, 768 valid, including cloud, database and SSH credentials.
Read breach analysis → NHI Stolen credentialsSumo Logic Breach 2023: How a Compromised AWS Credential Led to a Customer-Wide Key Rotation
A compromised credential was used to access a Sumo Logic AWS account, prompting customers to rotate API keys. No customer data impact was found.
Read breach analysis →Okta Support System Breach 2023: How a Service Account Saved in a Personal Google Profile Exposed 134 Customers
A stolen Okta support service account exposed HAR files of 134 customers; session tokens in them were used to hijack five customers' Okta sessions.
Read breach analysis → Human identity Social engineeringCaesars Entertainment Breach 2023: How Social Engineering of an IT Vendor Led to a Loyalty Database Theft and Ransom
Attackers social engineered an outsourced IT support vendor and stole Caesars loyalty database with licence and SSN data. A ransom was reportedly paid.
Read breach analysis → Human identity Social engineeringMGM Resorts Breach 2023: How a Help Desk Phone Call Led to Okta Admin Access and a $100 Million Loss
Attackers impersonated an MGM employee to the help desk, took Okta and Azure admin access, encrypted 100+ ESXi hosts and cost MGM about $100 million.
Read breach analysis →Secrets in Docker Hub Images: What the RWTH Aachen Study Found in 337,171 Container Images
RWTH Aachen researchers found 52,107 private keys and 3,158 API secrets in container images, with 275,269 hosts relying on leaked keys.
Read breach analysis → NHI Stolen credentialsFake Dependabot Commits 2023: How Stolen GitHub Tokens Were Used to Plant Secret-Stealing Code
Attackers used stolen GitHub personal access tokens to push fake Dependabot commits to hundreds of repos in 2023, stealing CI/CD secrets.
Read breach analysis →Microsoft Storm-0558 Key Breach 2023: How a Stolen Signing Key Forged Access to Government Email
Storm-0558 forged tokens with a stolen 2016 Microsoft signing key to read email at 22 organisations in 2023. How the key and validation failed.
Read breach analysis → NHI Leaked secretPoland ArcGIS Password Leak 2023: How a Three-Year-Old Emailed Login Exposed Military Maps
A 2020 email with an ArcGIS login was stolen and published in 2023. The password still worked, exposing Polish military and port maps.
Read breach analysis →Slack GitHub Breach 2022: How Stolen Employee Tokens Held by a Vendor Exposed Private Code Repositories
Stolen Slack employee tokens, taken via a compromised vendor, let an attacker download private GitHub repos over the 2022 holidays.
Read breach analysis → NHI Stolen credentialsCircleCI Breach 2023: How a Stolen SSO Session Exposed Every Customer’s CI/CD Secrets
Malware stole a CircleCI engineer's 2FA-backed SSO session, letting attackers exfiltrate customer secrets, tokens and keys. What went wrong.
Read breach analysis → NHI OAuth / SaaS integrationMicrosoft Verified Publisher OAuth Phishing 2022: How Fraudulent Partner Accounts Gave Malicious Apps Access to Mailboxes
Fraudulent Microsoft partner accounts gave malicious OAuth apps a verified badge in 2022; users who consented handed over mailbox tokens.
Read breach analysis → NHI Stolen credentialsGitHub Code Signing Certificate Theft 2022: How a Machine Account’s Token Exposed Desktop and Atom Signing Keys
A compromised GitHub machine account token cloned Desktop and Atom repos in 2022, exposing code signing certificates that GitHub then revoked.
Read breach analysis →LastPass Breach 2022: How Stolen DevOps Secrets Unlocked Every Customer Vault Backup
A keylogger on a DevOps engineer's home PC exposed AWS access keys and decryption keys, letting an attacker copy LastPass customer vault backups in 2022.
Read breach analysis → Human identity Social engineeringTwilio Breach 2022: How SMS Phishing of Employees Opened a Supply Chain Path to Signal and 130 Other Organisations
SMS phishing gave attackers Twilio employee logins in August 2022, affecting 209 customers and exposing about 1,900 Signal users. The 0ktapus campaign.
Read breach analysis →Codecov Breach 2021: How a Leaked Cloud Storage Key Turned a CI Script into a Secrets Harvester
In 2021 attackers altered Codecov's Bash Uploader with a leaked cloud key, harvesting CI secrets, tokens and keys from customer pipelines for two months.
Read breach analysis → NHI Leaked secretUnited Nations Breach 2021: How Exposed Git Credentials Opened 100,000 UNEP Staff Records
Ethical hackers used exposed Git credentials to reach 100,000+ UNEP staff records in 2021. How leaked repository secrets unlocked UN databases.
Read breach analysis →Deepen Your Knowledge
Free weekly newsletter
Subscribe to the NHI & AI Identity Journal
The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.
Bonus 33% off our NHI Course when you subscribe.