Skip to content

breach_cve_trends

React2Shell (CVE-2025-55182): Pre‑Auth RCE In React & Next.js- A Log4Shell‑Style Wake‑Up Call

On 3rd December 2025, a critical remote code execution vulnerability was disclosed in the React Server Components (RSC) ecosystem, widely known as React2Shell and tracked as CVE‑2025‑55182 (React) and CVE‑2025‑66478 (Next.js, later merged into the main CVE). The flaw allows unauthenticated remote code execution (pre‑auth RCE) on servers using React Server Components and frameworks like… Read More »React2Shell (CVE-2025-55182): Pre‑Auth RCE In React & Next.js- A Log4Shell‑Style Wake‑Up Call

Inotiv Ransomware Attack

Date of Incident: August 2025 Overview: In August 2025, Inotiv, a healthcare services company, suffered a ransomware attack that disrupted business operations and compromised the personal information of 9,542 individuals. The cyberattack involved exploiting vulnerable remote access services and phishing techniques, encrypting 162,000 files totaling 176 GB. The attack aligned with MITRE ATT&CK techniques, featuring… Read More »Inotiv Ransomware Attack

Freedom Mobile Data Breach

Date of Incident: October 23, 2023 Overview: The Freedom Mobile Data Breach occurred on October 23, 2023, impacting the telecommunications sector. Unauthorized access led to the theft of personal information, including names, addresses, dates of birth, phone numbers, and account numbers of a limited number of customers. While there is no evidence of data misuse… Read More »Freedom Mobile Data Breach

Leroy Merlin data breach

Date of Incident: 2023 Overview: In 2023, Leroy Merlin, a company in the retail sector, experienced a data breach resulting in the exposure of customers’ personal information, including full names, phone numbers, email addresses, postal addresses, birth dates, and loyalty program details. There was no evidence of banking data or passwords being compromised, and no… Read More »Leroy Merlin data breach

Marquis Data Breach

Date of Incident: August 2025 Overview: The Marquis data breach, reported in December 2025, affected the finance sector, impacting over 400,000 customers across 74 U.S. banks and credit unions. Personal information, including Social Security numbers and financial account details, was exposed. Despite no evidence of data misuse, Marquis paid a ransom to prevent further data… Read More »Marquis Data Breach