Golden Boy Promotions claims Oscar De La Hoya and other staff were denied credentials for Ryan Garcia’s event at the T-Mobile Arena, challenging Dana White’s denial that De La Hoya chose not to attend and highlighting disputed access policies around the fight.
Influencers Meg Radice and Audrey Jongens of The VIP List were kicked out of the US Open after posting photos of their credentials; the USTA said they were never properly credentialed and were submitted via a food vendor, which is not allowed for media or content creators, so access was revoked. The incident adds to ongoing influencer-related controversy at the tournament, including disruptive lighting by attendees during matches.
Two parallel CISA red-team assessments against two critical infrastructure orgs produced opposite results: Org A was fully compromised at the domain level with access to sensitive business systems and cloud resources, while Org B detected the phishing quickly and cut off command-and-control, then reproduced access via an assume-breach test. The common weaknesses—cleartext credentials, misconfigured AD CS, default machine account quota, static cloud keys, and over-permissioned Entra ID—are attributed more to people and processes than to tools.
A threat actor named TheHatman is selling massive Azure/Entra tenant dumps containing employee records from multiple major companies, including McDonald’s (~1.7M) and Vodafone (~425k), exfiltrated via compromised credentials. The data fields cover names, corporate emails, phone numbers, addresses, job titles, departments, and privileged accounts, enabling targeted BEC and privilege escalation. While the exact intrusion vector isn’t confirmed, researchers link the leaks to Infostealer infections and credential abuse rather than a Azure zero-day. Defenders should monitor for credential exposure, enforce MFA, and review third-party access to Azure directories to mitigate risk.}
Cybersecurity researchers flagged malicious VS Code extensions named 'solidity-pro' that evolve from loader to information stealer, capable of harvesting browser profiles, crypto wallets, API keys, SSH keys, and Telegram bot tokens, exfiltrating data via a Telegram bot; they use obfuscation and delayed activation to evade detection, with similar incidents in the past. Users should remove the extensions, review dependencies, block known C2 domains, and monitor for risky command usage.
1Password today announced 1Password for Claude, a feature that lets Claude perform tasks using your credentials while ensuring secrets never reach the model or Anthropic's servers through a per-session, zero-exposure framework. Credentials are injected securely to target sites, and an Agentic Mode keeps access locked down when an AI takes control of your browser; future support for payment cards and identity details is planned. The service is available now on Mac for business, family, and individual plans.
Security researchers say a broad breach of Fortinet firewalls exposed plaintext credentials for about 74,000 devices across 194 countries, enabling attackers to access centralized authentication systems and move laterally into networks of major organizations including Oracle, Lenovo, FedEx, and a Turkish NATO contractor; investigators note many compromised devices remained online and the attackers reportedly used a GPU-based password-cracking operation, underscoring the risk across multiple industries.
Security researchers revealed that a public GitHub repo named Private-CISA exposed plaintext passwords, SSH private keys, tokens, and other sensitive CISA assets since at least November 2025, potentially enabling high-privilege access to AWS GovCloud; the repo is now offline and reportedly managed by Nightwing, a CISA contractor, which has not publicly commented, following earlier CISA missteps including a director uploading sensitive docs to ChatGPT.
Attackers exploited a GitHub Actions workflow to gain access to signing keys and credentials, publishing a malicious element-data 0.23.3 package that scanned environments for sensitive data; the package was removed within ~12 hours, credentials rotated, and users are urged to upgrade to 0.23.4, purge caches, and rotate any exposed secrets.
Misconfigured Moltbot (formerly Clawdbot) control panels exposed hundreds of internet-facing dashboards, leaking API keys, private chats and other credentials. With autonomous agent capabilities, attackers could impersonate operators, inject messages, and even run commands with elevated privileges. The root cause was localhost-trust and reverse-proxy defaults; the project has rebranded Clawdbot to Moltbot (Molty) while keeping the same core functionality.
A security researcher found an unsecured database containing about 149 million usernames and passwords from services including Gmail, Facebook, Yahoo, Netflix, and more. The data, accessed without authentication and likely compiled by infostealing malware, was hosted on a Canadian provider and expanded over a month before being removed after notification. The breach enables potential account takeovers and identity theft across email, social media, streaming, banking, and government services. Experts advise using unique passwords with a password manager, enabling multi-factor authentication, and monitoring accounts for suspicious activity.
Google has denied reports of a massive Gmail data breach, clarifying that the compromised accounts were part of a collection of credentials stolen over years through malware, phishing, and other attacks, not a new breach. The false claims originated from misinterpretations of stolen credential databases, causing unnecessary alarm. Google emphasizes the importance of changing passwords if credentials are exposed, but reassures users that their Gmail security remains strong.
The reported 16 billion credential breach is likely exaggerated and based on recycled, outdated data rather than a single, recent event, highlighting the dangers of misinformation in cybersecurity and the importance of focusing on proven threats like infostealer malware and online hygiene.
A massive data breach dubbed the 'Mother of All Data Breaches' allegedly exposed 16 billion user credentials from various platforms, but experts suggest it may be a compilation of old breaches rather than a new one. The breach highlights the ongoing risks of credential theft and the use of malware like infostealers, emphasizing the importance of updating passwords and enhancing online security.
A webinar on July 9th will explore how cybercriminals are increasingly breaching networks using stolen credentials instead of vulnerabilities, covering attack methods, detection, and prevention strategies, with insights from industry experts.