Last updated: August 19, 2026 at 1:47 AM UTC
All 741 Vulnerability 286 Breach 129 Threat 319 Defense 7

Vatican prayer app left personal data of 700,000 users exposed

Researchers found that an official Vatican prayer app exposed the personal information of more than 700,000 users worldwide through an insecure configuration. The exposed data included details that can identify individuals and tie them to their use of the app. Faith and health apps are sensitive because the mere fact of using them can be revealing, and religious affiliation is a protected category in many jurisdictions, so even a modest data set carries outsized risk for the people in it. The exposure stemmed from the way the app's backend was set up rather than a sophisticated intrusion, a recurring pattern in mobile app data leaks where access controls are misconfigured.

Check
App developers should review backend access controls and confirm that user data stores require authentication and are not readable by anyone who can reach the endpoint.
Affected
More than 700,000 users of the Vatican prayer app whose personal information was exposed; because the data links people to a religious app, it is sensitive even where individual fields seem limited.
Fix
Developers should enforce authentication on all data endpoints, apply least privilege to backend stores, test for misconfiguration before release, and minimize the personal data collected by faith and health apps.

Chick-fil-A says attackers hijacked loyalty accounts using passwords stolen elsewhere

Chick-fil-A has disclosed a data breach following credential stuffing attacks against customer loyalty accounts. In this kind of attack there is no flaw in the targeted company's systems: attackers take username and password pairs harvested from unrelated breaches and replay them automatically against a login page, and any customer who reused a password elsewhere has their account opened. Loyalty and rewards accounts are attractive because they often hold stored balances, order history, and partial payment details, and they tend to receive less scrutiny than banking logins. Affected customers are advised to change their password.

Check
Chick-fil-A customers should change their account password immediately and change it anywhere else the same password was used, then enable multi-factor authentication where the service offers it.
Affected
Customers who reused a password from another breached service on their Chick-fil-A account; attackers replay stolen credential pairs automatically, and reuse alone is enough for an account takeover.
Fix
Use a unique password per service and a password manager. Organizations should rate limit and monitor login attempts, watch for credential stuffing patterns, and offer multi-factor authentication on consumer accounts.

Suno breach exposes 55 million accounts eight months after a developer was compromised

Data from a November 2025 breach at AI music platform Suno surfaced publicly in July, with Have I Been Pwned indexing 55,282,226 unique email addresses. Alongside the addresses, the corpus held names, phone numbers, physical addresses, and purchase records, plus tens of thousands of Stripe entries containing partial card data: card type, expiry date, and the last four digits. Reporting indicates the intrusion started with malware delivered through third-party code on a developer's machine, which yielded credentials for private repositories and internal databases. Suno has said no sensitive personal information was compromised and has not notified affected users.

Check
Suno users should check Have I Been Pwned, change the password there and anywhere it was reused, and be alert to phishing that references their account or past purchases.
Affected
Roughly 55 million Suno users whose email addresses, names, phone numbers, physical addresses, and purchase records were exposed, with partial card data for a subset; most have not been notified.
Fix
Use unique passwords and enable multi-factor authentication where offered. Organizations should treat developer workstations as high value targets, since third-party code running there can hand over repository and database access.

Estée Lauder says attackers took personal data from its Oracle HR system

Estée Lauder is notifying people that personal information was stolen after attackers reached the Oracle E-Business Suite environment it uses for human resources. The company says an unauthorized third party gained access on or around August 9, 2025, and that it confirmed on June 19, 2026 that personal information had been taken, a gap of more than ten months between intrusion and confirmation. The notice does not name the vulnerability exploited, though the timing lines up with the mass exploitation campaign against Oracle E-Business Suite that ran through last year. Affected people are being offered two years of identity monitoring.

Check
Organizations running Oracle E-Business Suite should confirm the environment is patched against last year's exploited flaws and review access logs from that period, since intrusions there went undetected for months.
Affected
People whose personal information sat in Estée Lauder's Oracle E-Business Suite human resources environment; the data was taken in 2025 and only confirmed in June 2026, leaving a long window for misuse.
Fix
Affected people should enroll in the offered monitoring and consider a credit freeze. Organizations should patch and segment enterprise resource platforms, limit the personal data they hold, and monitor for unusual access.

Hugging Face says an autonomous AI agent breached its production systems

Hugging Face, the largest public repository of AI models and datasets, disclosed an intrusion into its production infrastructure that it says was driven end to end by an autonomous AI agent system. The attacker used code execution paths in the dataset processing pipeline for initial access, then harvested credentials and reached internal clusters, though the company found no evidence that public models or datasets were tampered with. The campaign ran thousands of actions across short lived sandboxes, with self migrating command and control staged on public services. Hugging Face's own AI assisted anomaly detection flagged it, and it has rotated affected credentials and rebuilt compromised nodes.

Check
Users of Hugging Face should rotate access tokens and review recent account activity, and teams should check what credentials their model and dataset pipelines hold and how far those reach.
Affected
Organizations running AI model and dataset pipelines that execute untrusted content; Hugging Face's own dataset processing paths gave an autonomous agent initial access, credentials, and reach into internal clusters.
Fix
Rotate Hugging Face tokens, treat datasets and models as untrusted code rather than data, sandbox processing pipelines, limit credentials reachable from them, and tighten admission controls on clusters running that work.

Ernst and Young says client tax documents were stolen from a support platform

Ernst & Young is notifying clients of a breach at a third-party IT service management platform used by staff supporting its tax practice. Support tickets submitted through the platform could include attached documents containing client tax information, and the firm says an unauthorized third party accessed the platform between March 28 and April 12 and downloaded documents belonging to a number of clients. EY detected the activity on April 23, roughly two weeks after it stopped, and filed breach notifications with the California Attorney General in July. The exposed data includes personal and financial information used to prepare tax filings.

Check
EY tax clients should watch for a notification letter, monitor financial accounts and credit, and treat unexpected messages referencing their tax filings or the firm as likely phishing.
Affected
EY tax clients whose documents were attached to support tickets; personal and financial information used to prepare tax filings was downloaded, which supports identity theft and convincing targeted phishing.
Fix
Affected clients should consider a credit freeze and monitor accounts. Organizations should limit what sensitive data staff attach to helpdesk tickets, set retention limits on attachments, and assess vendor security.

Coca-Cola's Fairlife halts US dairy production after a ransomware attack

Coca-Cola disclosed in a securities filing that a ransomware attack on its Fairlife dairy subsidiary has disrupted operations and temporarily suspended production across the United States. The company said Fairlife detected unauthorized access to some systems, including production-related systems, and that it activated incident response and business continuity plans, brought in outside experts, and notified law enforcement. It says product quality and safety were not affected, and Canadian operations continue. The full impact is still being investigated, and no ransomware group has been named. Ransomware at food and beverage producers has caused weeks-long shutdowns and empty shelves in past incidents.

Check
Manufacturers should review their ability to keep production running during a cyberattack, confirm that business and production systems are segmented, and test backups and incident-response and continuity plans against a ransomware scenario.
Affected
Manufacturers and food and beverage producers whose production depends on connected systems; a ransomware attack can force a full production halt even when product safety is unaffected, as with Fairlife's US suspension.
Fix
Segment production and business networks, maintain tested offline backups, enforce phishing-resistant MFA on remote access, rehearse recovery, and prepare business-continuity plans that keep critical operations running during a systems shutdown.

Lidl notifies online shop customers of breach at a service provider

Discount supermarket chain Lidl has notified online shop customers in Germany, Belgium, and the Netherlands of a data breach that stemmed from a hack at one of its service providers rather than Lidl's own systems. According to the company, the exposed information involves customer contact and order-related details, while payment card data was not affected. The incident is another example of third-party or supply-chain risk, where attackers compromise a vendor to reach a larger brand's customer data. Even without financial data, the exposed details can fuel convincing phishing and scams that impersonate Lidl, especially messages referencing real orders to make fraudulent requests look legitimate to shoppers who recently used the online shop.

Check
Lidl online shop customers in the affected countries should watch for the notification, be wary of messages referencing Lidl or their orders, and avoid clicking links or sharing details in unsolicited messages.
Affected
Lidl online shop customers in Germany, Belgium, and the Netherlands whose contact and order details were exposed through a hacked service provider; payment card data was not affected.
Fix
Treat Lidl-themed messages with caution and verify through official channels. Organizations should assess vendors' security, limit the customer data third parties hold, and require breach-notification and security commitments in supplier contracts.

Glendale College breach exposes data on 793,000 students and applicants

Glendale Community College has had data on roughly 793,000 people exposed after the extortion group ShinyHunters stole files from its student information systems. Have I Been Pwned indexed 793,925 accounts, and the attackers claim to have taken more than 62GB across roughly 304,000 files, including student records with personal identifiers, financial aid exports, immunization logs, admission checklists, and transcripts dating back to 2020. The theft came from the college's PeopleSoft Campus Solutions environment, tying it to the wider ShinyHunters campaign against Oracle PeopleSoft that has hit numerous universities and companies. The breadth of academic and personal data raises the risk of identity theft and targeted phishing against students, applicants, and staff.

Check
People connected to Glendale Community College as students, applicants, or staff should watch for a breach notice, check Have I Been Pwned, monitor financial accounts, and be alert to college-themed phishing.
Affected
Around 793,000 Glendale Community College students, applicants, and staff whose personal, academic, financial aid, and health-related records were exposed; the depth of data supports identity theft and convincing targeted phishing.
Fix
Affected people should consider a credit freeze and monitor accounts. Organizations using Oracle PeopleSoft should apply its mitigations, review access logs, and enforce phishing-resistant MFA against this ongoing campaign.

AssuranceAmerica breach exposes driver's license data of 6.9 million people

US auto insurer AssuranceAmerica has confirmed a breach affecting nearly 6.9 million people, the largest known exposure of Americans' driver's license data this year. The company detected the intrusion on March 17 after attackers compromised a single employee's credentials the day before and copied data files, but a lengthy review of the files was not finished until June 15, delaying notifications until now. The stolen data includes names, contact details, driver's license numbers, auto insurance policy and claims information, and, for some people, Social Security numbers. AssuranceAmerica has not detailed how the employee's credentials were taken, though such incidents are often tied to phishing or credential-stealing malware.

Check
People insured by AssuranceAmerica should watch for a breach notification, monitor bank and credit accounts and credit reports for fraud, and be wary of messages referencing their policy or claims.
Affected
Roughly 6.9 million AssuranceAmerica customers whose driver's license numbers, contact details, and insurance information were exposed, along with Social Security numbers for some; the data enables identity theft and convincing targeted phishing.
Fix
Affected people should consider a credit freeze given exposed license and Social Security numbers, monitor financial accounts, and treat insurance-themed messages cautiously. Organizations should enforce phishing-resistant MFA on employee accounts.