handmade.social is one of the many independent Mastodon servers you can use to participate in the fediverse.
handmade.social is for all handmade artisans to create accounts for their Etsy and other handmade business shops.

Server stats:

37
active users

#databreach

2 posts2 participants0 posts today

Just got a data breach notification from Lee Valley.

Full name address, credit card details from a cloud server that was popped from Oct 8, 2024 to March 12, 2025.

If you bought stuff from the Lee Valley website in that time be on the lookout for a breach notification and get ready to freeze/replace your credit card.

From the notification it sounds like the attacker was able to add code to the website frontend to siphon off credit card info.

"A government whistleblower told lawmakers that DOGE's access to National Labor Relations Board (NLRB) systems went far beyond what was needed to analyze agency operations and apparently led to a data breach. NLRB employee Daniel Berulis, a DevSecOps architect, also says he received a threat when he was preparing his whistleblower disclosure.

"Mr. Berulis is coming forward today because of his concern that recent activity by members of the Department of Government Efficiency ('DOGE') have resulted in a significant cybersecurity breach that likely has and continues to expose our government to foreign intelligence and our nation's adversaries," said a letter from the group Whistleblower Aid to the Senate Select Committee on Intelligence leaders and the US Office of Special Counsel.

The letter, Berulis' sworn declaration, and an exhibit with screenshots of technical data are available here. "This declaration details DOGE activity within NLRB, the exfiltration of data from NLRB systems, and—concerningly—near real-time access by users in Russia," Whistleblower Aid Chief Legal Counsel Andrew Bakaj wrote. "Notably, within minutes of DOGE personnel creating user accounts in NLRB systems, on multiple occasions someone or something within Russia attempted to login using all of the valid credentials (e.g. Usernames/Passwords). This, combined with verifiable data being systematically exfiltrated to unknown servers within the continental United States—and perhaps abroad—merits investigation."

Bakaj said they notified law enforcement about an "absolutely disturbing" threat Berulis received on April 7."

arstechnica.com/tech-policy/20

Elon Musk wearing a T-shirt with the word "DOGE" printed on the front.
Ars Technica · Government IT whistleblower calls out DOGE, says he was threatened at homeBy Jon Brodkin
#USA#Trump#DOGE

🏥 Oracle Health breach compromises patient data at US hospitals
@BleepingComputer

「 Oracle says that the threat actor used compromised customer credentials to breach the servers sometime after January 22, 2025, and copied data to a remote server. This stolen data "may" have included patient information from electronic health records 」

bleepingcomputer.com/news/secu

🫠 Oracle attempt to hide serious cybersecurity incident from customers in Oracle SaaS service

「 Oracle told Bleeping Computer, and customers, “There has been no breach of Oracle Cloud. The published credentials are not for the Oracle Cloud. No Oracle Cloud customers experienced a breach or lost any data” 」

#oracle #databreach #cybersecurity
doublepulsar.com/oracle-attemp

DoublePulsar · Oracle attempt to hide serious cybersecurity incident from customers in Oracle SaaS serviceBy Kevin Beaumont

When they say no-one is safe, here is the evidence 🙄
We are all vulnerable to phishing, even @troyhunt has been caught! If it can happen to Troy, it can happen to us all. Each and every one of us.

“…the penny has just dropped that a Mailchimp phish has grabbed my credentials, logged into my account and exported the mailing list for this blog. I'm deliberately keeping this post very succinct to ensure the message goes out to my impacted subscribers ASAP, then I'll update the post with more details.“

troyhunt.com/a-sneaky-phish-ju
#CyberSecurity #DataBreach #InfoSec #Phishing

Troy Hunt · A Sneaky Phish Just Grabbed my Mailchimp Mailing ListYou know when you're really jet lagged and really tired and the cogs in your head are just moving that little bit too slow? That's me right now, and the penny has just dropped that a Mailchimp phish has grabbed my credentials, logged into my account and exported the mailing

Another Monday. Another edition of the Privacy Roundup featuring news items curated with end user #privacy and #security in mind.

This edition features:

- #Android Apps using #Bluetooth and Wi-Fi connection data to estimate and collect user location data
- #Apple Passwords app used insecure HTTP
- Video gamers beware: another game pulled from Steam for being #malware in disguise
- Free online converters adding malware to converted files
- Threat actors using #Reddit posts to push information stealing malware, primarily targeting #cryptocurrency traders/enthusiasts
- Data breaches at the largest US sperm bank and a large teacher union

… and more.

#privacymatters #databreach #cybersecurity #cybersecurity #infosec #gaming

avoidthehack.com/privacy-week1

Avoid the Hack (avoidthehack!)Privacy Roundup: Week 12 of Year 2025Week 12 of the Privacy Roundup includes news items covering Android apps using bluetooth and Wi-Fi to track user location, Apple Passwords using insecure HTTP, sensitive information compromised in hacks of a large teacher union and a sperm bank, threat actors using Reddit posts to push information stealing malware, and more!

📨 Latest issue of my curated #cybersecurity and #infosec list of resources for week #12/2025 is out!

It includes the following and much more:

@wiz to be Acquired by Alphabet and will join #Google Cloud;
➝ GitHub Action tj-actions/changed-files was compromised, risking secrets in over 23k repositories;
@vulncheck has raised $12 million in a Series A #funding round;
➝ Clearview AI tried to buy millions of arrest records;
➝ Infosys to Pay $17.5 Million in Settlement Over 2023 #DataBreach;
➝ Oracle denies #breach;

Subscribe to the #infosecMASHUP newsletter to have it piping hot in your inbox every week-end ⬇️

infosec-mashup.santolaria.net/

X’s InfoSec Newsletter🕵🏻‍♂️ [InfoSec MASHUP] 12/2025Wiz to be Acquired by Alphabet and will join Google Cloud; GitHub Action tj-actions/changed-files was compromised, risking secrets in over 23k repositories; VulnCheck has raised $12 million in a Series A funding round; Clearview AI tried to buy millions of arrest records; Infosys to Pay $17.5 Million in Settlement Over 2023 Data Breach; Oracle denies breach;

#Amazon is still hosting #stalkerware victims' data weeks after breach alert
#Cocospy, #Spyic, and #Spyzie, have collectively compromised over 3.1 million Android phones, which we know because apps each had a #databreach in Feb.
As part of our investigation into stalkerware operations, which included analyzing the apps themselves, TechCrunch found that some of the contents of a device compromised by the stalkerware apps are being uploaded to storage servers run by #AWS.
techcrunch.com/2025/03/13/amaz

TechCrunch · Amazon is still hosting stalkerware victims' data weeks after breach alert | TechCrunchAmazon won't say if it will stop hosting data from three phone surveillance operations that spilled private data on millions of people.

Thanks to everyone in the fediverse who has favorited, boosted, and reached out to me supportively over the injunction and takedown order that I wouldn't comply with (overview: infosec.exchange/@PogoWasRight)

Special thanks to @zackwhittaker for reporting about it all on #TechCrunch:

techcrunch.com/2025/03/06/hack

Infosec ExchangeDissent Doe :cupofcoffee: (@PogoWasRight@infosec.exchange)Here's my post on the court injunction my site got hit with: HCRG Care's lawyers claimed an injunction issued in a "private" hearing required us to remove two posts. We didn't comply. HCRG Care was represented by the Pinsent Masons law firm in the UK in this matter. The injunction was issued by the High Court of Justice, King's Bench Division, Media and Communications List by the Honorable Mr. Justice Soole. Pinsent Mason's attempt to get my web host to remove my posts also failed. As always, I feel blessed to have the legal support of Covington and Burling's Kurt Wimmer Pro Media Freedom Initiative, which has represented my site pro bono for the last 16 years. Read about the letter, the injunction, and why the High Court's over-reaching injunction endangers UK journalists and doesn't serve the public well. https://databreaches.net/2025/03/05/hcrg-cares-lawyers-claimed-an-injunction-issued-in-a-private-hearing-required-us-to-remove-two-posts-we-didnt-comply/ Oh, and I'm not the only one ignoring the injunction. Medusa also got served with the injunction via tox chat, they tell me. And like other injunctions they have received, they are ignoring it. So what has HCRG really accomplished? #databreach #ransomware #Medusa #transparency #censorship #pressfreedom #injunction #FirstAmendment @zackwhittaker@mastodon.social @campuscodi@mastodon.social @lawrenceabrams @iainthomson@mastodon.social @amvinfe @lawfare @freedomofpress@freedom.press

Last Friday I received a letter from a U.K. law firm with an attached injunction. The law firm claimed I must remove two posts about their client.

That is not going to happen. I am not under the jurisdiction of the U.K. or the High Court of Justice. My lawyer informed them of that yesterday.

But DataBreaches.net might disappear tomorrow because the U.K. law firm sent the injunction to my domain registrar who, innocently believing them, informed me they will suspend my site if I don't remove the posts within 24 hours. I have replied to them but have not heard back.

So...

If my site is gone tomorrow, I will let you know where you can read a lot more about the injunction and how the injunction poses a serious risk of censorship in the U.K.

If my site is still online tomorrow, I will still let you know here where you can read about the over-reaching injunction obtained in a private hearing where no one represented journalists whose reporting was being censored.

#censorship #injunction #pressfreedom
#AssociatedPress #RCFP #databreach #ransomware #journalism

@freedomofpress @campuscodi @zackwhittaker @aj_vicens @carlypage @iainthomson @amvinfe @lawfare @lawrenceabrams

🇳🇿 I've had quite a few outrageous responses to my alerts, this is another one of those, sent by teammateapp.com CEO.

After my initial alert and follow up email, I get a reply lying about the severity of the exposure and telling me to stop harassing the company.

This CEO also didn't know what Proton is and thought I work for them and threatened to report me to them in case I didn't stop. :blobshrug:

Read about it here: jltee.substack.com/p/new-zeala

The Hub of Stupi.. *misconfigs · New Zealand Company’s ‘Impossible-to-Hack’ Security Turns Out to Be No Security at AllBy JayeLTee

"This is the largest #databreach in American history,” Tong said in a statement on Friday. “#Doge is an unlawfully constituted band of renegade #techbros combing through #confidentialrecords, #sensitivedata and critical payment systems. What could go wrong?”

Judge temporarily blocks #Musk’s ‘Doge’ team from accessing #treasury records | #ElonMusk | The Guardian
theguardian.com/technology/202

#USpol
#democracy
#ruleoflaw
#privacylaws
#confidentialinformation

The Guardian · Judge temporarily blocks Musk’s ‘Doge’ team from accessing treasury recordsBy Guardian staff reporter