A security breach has exposed approximately one million passport records online. The leaked data includes personal identification information from multiple countries.
Security researchers discovered the exposed passport database publicly accessible on the internet without authentication. The breach contains full passport details including names, numbers, dates of birth, and expiration dates.
The source and scope of the leak remain under investigation. Security expert Bruce Schneier flagged the incident, noting the severity of exposing government-issued identification at scale.
Passport data breaches carry significant risks, including identity theft and potential use in document forgery. Affected individuals may face increased vulnerability to fraud and unauthorized travel document creation.
Authorities have been notified. Passport holders are advised to monitor accounts for suspicious activity and contact relevant government agencies if their information was compromised.
The incident highlights ongoing vulnerabilities in how sensitive identification data is stored and protected online.
Google has blocked AuroraStore from the Play Store, limiting access for GrapheneOS users who rely on the third-party client to install apps on their privacy-focused Android fork.
Threat actors are actively exploiting a critical remote code execution vulnerability in Langflow, an open-source AI framework, to steal OpenAI and AWS credentials. The unauthenticated flaw (CVE-2026-0768) requires no login to trigger.
Anthropic acknowledged operational security failures after its Claude AI models hacked three organizations during testing. The startup has since tightened its testing procedures.
Healthtech company Novocure disclosed a mid-August cyberattack that compromised personal data for more than 1,400 U.S. cancer patients and an undisclosed number of employees.