Incident Desk LIVE
When a breach breaks, the first question is usually an identity question: whose credentials, which tokens, what could they reach. Emergency briefings separate what is confirmed from what is only claimed and say what to check this week. The feed below tracks identity-related incidents from official and specialist sources as they are reported.
Emergency briefings
Denmark's CPR Breach: When a Lookup Number Becomes a Skeleton Key to 8.8 Million Identities
Abuse of a small Danish firm's legitimate register access exposed names, addresses and CPR numbers for 8.8 million people, living and dead. The cause and scale of misuse remain unconfirmed.
ASOS and the push notification that spoke for the attacker: secure the identities that talk to your customers
ASOS app users received an "ASOS HACKED" push alert. What is confirmed, what is only claimed, and seven checks every retailer should make on the identities that can message its customers.
Live identity incident feed
-
Fake ChatGPT, Gemini Sites steal advertising accounts, MFA codes
Fake AI sites use browser-in-browser attacks to steal advertising account credentials and MFA codes.
-
ClickFix campaign in Ukraine compromises over 100 websites to spread Lunex malware
Fake Cloudflare verification pages lure visitors into ClickFix infections delivering an infostealer.
-
Zombie instructions on carefully constructed web pages could trick GitHub Copilot CLI into sharing secrets
Web-page instructions can trick Copilot CLI into sharing secrets in autopilot mode.
-
Hitachi Energy Asset Suite
Asset Suite vulnerabilities permit unauthenticated servlet access.
-
Denmark's ID register spills more people's details than the country has residents
Abuse of a private firm's register access exposed identity records, including those of deceased people and emigrants.
-
Legacy sign-on service comes back to bite school software provider Bromcom
A superseded sign-on service kept running for an internal system exposed email addresses.
-
Nikkei discloses breaches of employees’ Microsoft, Google email accounts
Attackers compromised employee email accounts and used one to send thousands of phishing emails.
-
Denmark Says Attackers Accessed CPR Data for 8.8 Million People via Company Account
Access through a company account exposed names, addresses and personal identification numbers in the national population register.
-
Rejetto HFS servers now actively scanned for critical RCE flaw
A weak signing key enables session forgery, account takeover and remote code execution.
-
Denmark population registry data breach affects 8.8 million people
A population registry breach exposed personal information of registered individuals.
-
Attackers Target Rejetto HFS Flaw That Enables Admin Session Forgery and RCE
Administrator session forgery enables remote code execution.
-
New NetScaler Zero-Day Exploited in Targeted Attacks Can Knock SAML Deployments Offline
An exploited NetScaler flaw can take SAML deployments offline.
-
China-Aligned TA419 Targets U.S. AI Policy Experts With Microsoft AitM Phishing
Adversary-in-the-middle phishing targets Microsoft credentials belonging to US AI policy experts.
-
Dell CSM Flaws Enable Unauthenticated Admin Access and Root on Kubernetes Nodes
CSM flaws allow unauthenticated administrative access and root access on Kubernetes nodes.
-
CISA Adds Two Known Exploited Vulnerabilities to Catalog
A session-fixation vulnerability is being actively exploited.
-
AI agents hacked the hackers, stealing email addresses from security research org
Chained Zammad flaws enabled session hijacking, code execution and root escalation.
-
ThreatsDay: AI-Powered Zero-Day Chain, 543K Live Secrets, Model Inspection RCE and 13 More Stories
Live secret exposure features alongside zero-day chains and code-execution risks.
-
Suspected Chinese spies spoofed an Anthropic exec, ex-White House official in AI phishing
Attackers impersonated an Anthropic executive and former White House official in fake AI policy committee invitations.
-
Meari IoT Cloud Platform OpenAPI Service
OpenAPI flaws can expose device credentials and allow unauthorized configuration changes.
-
Johnson Controls EasyIO Neo Series EC and CW Controllers
The flaw can expose credentials and session data to interception.
-
CISA Adds Exploited Cisco Catalyst SD-WAN Manager Auth Bypass to KEV
An authentication bypass in Catalyst SD-WAN Manager is being actively exploited.
-
Citrix NetScaler Post-Exploitation Payload Creates Superuser, Maps Web Shell to CSS-Like URLs
Post-exploitation payloads create superuser accounts and attempt to steal NetScaler configuration data.
-
Attackers Exploit Zimbra Flaw to Deploy Web Shells and Harvest Authentication Secrets
Exploited Zimbra deployments enabled web shells, mailbox access and authentication-secret harvesting.
-
Cisco Warns of Attackers Exploiting Critical Authentication Bypass in SD-WAN Manager
Attackers are exploiting an authentication bypass in SD-WAN Manager.
- CISA Adds One Known Exploited Vulnerability to Catalog
-
Medela breach added to Have I Been Pwned (423,947 accounts)
Allegedly stolen account data was published following a pay-or-leak extortion campaign.
-
US-Focused CSuite Phishing Steals Microsoft 365 Sessions and Deploys RMM Tools for Remote Access
Phishing steals Microsoft 365 sessions and deploys remote-management tools for remote access.
-
French Tax Data Theft Using Stolen Staff Passwords Went Undetected for Seven Weeks
Stolen staff passwords enabled tax-data theft that went undetected for seven weeks.
-
Anjvision YSSD-RTMP-H5
Vulnerabilities could allow access to user accounts alongside sensitive information and full device control.
-
OpenAI’s dirty deeds Down Under included security bypass attempts, using exposed keys, source code siphon
Agents attempted security bypasses and used exposed keys while accessing Australian government sites.
Check your exposure
Has this password been in a breach?
Your password never leaves this page. Your browser hashes it and sends only the first five characters of the hash to Have I Been Pwned's Pwned Passwords service, then compares the results locally.
Is this email address in a known breach?
Coming soon. Until then you can check at haveibeenpwned.com.
How this works
The feed reads the UK National Cyber Security Centre, CISA, Have I Been Pwned's newly added breaches and specialist security news (The Record, BleepingComputer, The Hacker News, The Register) every 15 minutes. Each new item is rated by a model for how much identity is at the heart of it; only identity-related items appear here. Ratings are automated and can be wrong, and a feed item is a report, not a confirmed fact.
Briefings are written from multiple reports, fact-checked against those sources, and reviewed by me before they are published. If something here affects you or your organisation, get in touch.