Arrested: Ajax Hacker Accessed 300K Fan Records
A 35-year-old from Buren is in custody after exploiting Ajax's bare APIs to access 300,000 fan records and put 42,000 season tickets at risk of theft.
Lawsuits, patent wars, and enforcement actions.
A 35-year-old from Buren is in custody after exploiting Ajax's bare APIs to access 300,000 fan records and put 42,000 season tickets at risk of theft.
Glassworm spent two years poisoning 300+ GitHub repos until CrowdStrike and Google killed all four of its C2 channels simultaneously.
A non-government UK visa portal exposed 100K passports on a public S3 bucket, then sent BakerHostetler instead of patching the server.
Charter denies any sensitive data left its systems, but ShinyHunters claims 40 million records stolen and demands payment by May 27.
OMB scrapped Biden's M-21-31 logging mandate before CISA's replacement is ready, giving agencies six months with no enforceable standard.
ShinyHunters dumped 185,300 people's data after 7-Eleven refused ransom: names, dates of birth, and addresses from a Salesforce breach.
Dutch FIOD arrested two men who kept 800 servers running for Russia's cyber network even after EU sanctions targeted the infrastructure.
If Treasury acts on Moolenaar's COINS Act request, deals like BMS's $15.2B Hengrui partnership would need federal clearance before closing.
The Fed's new payment account category hands FinTechs direct settlement access while stripping interest, discount window, and intraday credit.
FDIC's third GENIUS Act NPRM adds AML/CFT rules to stablecoin issuers, completing a compliance stack that changes who can enter the market.
Trump Mobile confirmed a customer data exposure linked to a third-party provider, then said it's still weighing whether to notify those affected.
C.A. Cloud's CEO and CSO pleaded guilty to concealing a five-year fraud scheme that funneled calls to scammers targeting elderly victims worldwide.
Cox Media Group's "Active Listening" AI never used voice data; the FTC's $880K settlement shows it was email lists at markup. Small businesses paid.
When Europol obtained First VPN's user database, it told every client they'd been identified. Now 25 ransomware gangs know their cover is gone.
Trump's May 19 EO gives the Fed 120 days to weigh fintech access to payment rails. The master account question finally has a clock.
Ukrainian cyberpolice identified the Odesa teen on May 12: he ran the infrastructure behind $721K in unauthorized purchases from 28,000 accounts.
TeamPCP stole 3,800 GitHub internal repos via a poisoned VS Code extension live for just 18 minutes, now demanding at least $50K for the data.
California's first-ever Yotta penalty is $1M, but the 18,000 California customers still waiting for Synapse restitution call it a rounding error.
SEC closed its FCPA probe of Methode Electronics with no enforcement action, after two subpoenas covering executive pay and hotline tips.
TeamPCP breached GitHub via a poisoned VS Code extension, pulling approximately 3,800 internal repos now listed on criminal forums.