u/raptorhunter22

Adobe has faced an alleged data breach via 3rd party Indian BPO leading to 13M support tickets and 15,000 employe data leak
🔥 Hot ▲ 350 r/webdev+3 crossposts

Adobe has faced an alleged data breach via 3rd party Indian BPO leading to 13M support tickets and 15,000 employe data leak

A suspected major data breach at Adobe, allegedly by a hacker called “Mr. Raccoon,” may have exposed millions of records via a third-party Indian BPO. Reports claim up to 13 million support tickets, 15,000 employee records, and HackerOne submissions were accessed. Adobe hasn’t confirmed the breach, but shared evidence suggests serious gaps in access control and vendor security.

thecybersecguru.com
u/raptorhunter22 — 17 hours ago
Cisco source code stolen by ShinyHunters via Trivy supply-chain attack. AWS keys breached, 300+ repos cloned and more
🔥 Hot ▲ 331 r/netsec+1 crossposts

Cisco source code stolen by ShinyHunters via Trivy supply-chain attack. AWS keys breached, 300+ repos cloned and more

Cisco reportedly suffered a breach of its internal development environment after attackers leveraged credentials stolen during the recent Trivy supply-chain compromise. More details linked with sample data

thecybersecguru.com
u/raptorhunter22 — 2 days ago
Axios npm package compromised in supply chain attack. Downloads malware dropper package
🔥 Hot ▲ 135 r/netsec+1 crossposts

Axios npm package compromised in supply chain attack. Downloads malware dropper package

Axios is one of the most used npm packages which just got hit by a supply chain attack. Malicious versions of Axios (1.14.1 and 0.30.4) hit the npm registry yesterday. They carry a malware dropper called plain-crypto-js@4.2.1. If you ran npm install in the last 24 hours, check your lockfile. Roll back to 1.14.0 and rotate every credential that was in your environment. Currently, as of now, npmjs has removed the compromised versions of axios package along with the malicious plain crypto js package. Live updates + info linked.

thecybersecguru.com
u/raptorhunter22 — 4 days ago
LiteLLM supply chain compromise - a complete analysis
▲ 7 r/netsec

LiteLLM supply chain compromise - a complete analysis

Analysis of the LiteLLM incident: stolen CI tokens → malicious PyPI releases → credential exfiltration from runtime environments.

With focus on trust boundaries in CI/CD and secret exposure.

thecybersecguru.com
u/raptorhunter22 — 9 days ago
Navia breach exposed HackerOne employee PII due to a BOLA-style access in third-party system
▲ 19 r/netsec

Navia breach exposed HackerOne employee PII due to a BOLA-style access in third-party system

Breach occurred at Navia Benefit Solutions, a 3rd party, not HackerOne infra.

Around 287 HackerOne employees PII leaked.

Navia delayed breach notifications by weeks. Filed at Maine AG.

Navia was independently breached. Over 10K US employee's PII exposed.

Reports point to an auth flaw (BOLA-type) enabling access to employee PII (SSNs, DoB, addresses, benefits data).

Exposure window: Dec 2025 to Jan 2026.

thecybersecguru.com
u/raptorhunter22 — 10 days ago