WhisperX tag archive

#Data Leak

This page collects WhisperX intelligence signals tagged #Data Leak. It is designed for humans, search engines, and AI agents: each item links to a canonical source-backed record with sector, source, timestamp, credibility, and exportable structured data.

Latest Signals (20)

The Lab · 2026-03-30 04:27:05 · GitHub Issues

1. GitHub Copilot Prompt Leak: Interactive Cybersecurity Simulation Prototype Details SOC Attack Scenario

A detailed GitHub Copilot prompt, intended for building a private cybersecurity training simulation, has been publicly exposed in a GitHub repository. The prompt outlines the technical specifications for a four-page interactive prototype designed to demonstrate a chained attack against a corporate HR system. The scenar...

The Lab · 2026-03-27 07:26:54 · GitHub Issues

2. Library Management API Exposes All Borrow Records via Invalid Status Parameter

A critical security flaw in a library management system's API allows any attacker to bypass access controls and retrieve the entire dataset of borrow records simply by sending an invalid query parameter. The vulnerability, classified as HIGH severity, resides in the `BorrowController.java` file where a silent exception...

The Office · 2026-03-28 06:56:49 · Japan Times

4. Hyogo Governor Saito Denies Role in Whistleblower Data Leak, Avoids Indictment

Hyogo Governor Motohiko Saito has avoided indictment but remains at the center of a politically charged information leak case involving a deceased whistleblower. The governor has publicly denied any involvement in the leak of the individual's private information, which occurred prior to the whistleblower's death in Jul...

The Lab · 2026-03-28 13:26:58 · CoinDesk

5. Anthropic's 'Capybara' AI Model Leaked Via Unsecured Cache, Company Warns of 'Unprecedented' Cyber Risks

A draft blog post detailing Anthropic's most powerful AI model to date, codenamed 'Capybara,' was exposed through an unsecured data cache. The company itself has flagged the incident as revealing 'unprecedented' cybersecurity risks, signaling a major internal security failure that precedes any official product announce...

The Lab · 2026-03-28 18:26:53 · GitHub Issues

6. [SECURITY/P2] Critical Exposure: Confidential Security Plan and Attack Surface Analysis Committed to Git Repository

A confidential security planning document, detailing the complete attack surface analysis, specific vulnerabilities, and remediation timelines for an entire codebase, has been mistakenly committed to a git repository. The file, `SECURITY_10X_PLAN.md`, is marked CONFIDENTIAL and contains 60KB of sensitive data, includin...

The Lab · 2026-03-31 08:27:05 · GitHub Issues

7. [SECURITY TRIAGE] Critical: Hugging Face Token Leak in Training Data, 240+ Code Alerts, Coherence Failures

A critical security triage reveals a live Hugging Face API token has been publicly exposed in the repository's training data for at least 18 hours. The token, with the prefix `hf_sUYKuMlbFnJkwGkewyHNlNKbD...`, was found embedded within two key data files: `training-data/sft/consolidated_root_sft.jsonl` and `training-da...

The Lab · 2026-03-31 23:26:57 · VentureBeat

9. Anthropic's Claude Code Source Code Leaks via Public npm Registry, Exposing Core AI IP

Anthropic has suffered a major intellectual property breach, with the complete source code for its flagship Claude Code product accidentally exposed to the public. The leak occurred when a 59.8 MB JavaScript source map file, intended solely for internal debugging, was included in the public release of the `@anthropic-a...

The Lab · 2026-04-01 09:27:19 · GitHub Issues

10. Anthropic's Second Major Breach: Claude Code Source Code Leak Exposes AI Secrets

Anthropic has suffered its second major security breach in days, this time leaking the source code for its proprietary AI coding tool, Claude Code. The incident, which exposed hundreds of thousands of lines of code, potentially reveals the internal architecture of the company's systems and upcoming models, raising imme...

The Lab · 2026-04-01 09:27:20 · GitHub Issues

11. Anthropic's Second Major Breach: Claude Code Source Code Leak Exposes AI Secrets

Anthropic has suffered its second major security lapse in days, with the source code for its AI coding tool, Claude Code, leaking online. The breach, which exposed hundreds of thousands of lines of proprietary code, raises immediate concerns about the company's security practices and the potential for malicious actors ...

The Lab · 2026-04-01 17:27:33 · GitHub Issues

12. Storybook Security Alert: CVE-2025-68429 Exposes .env File Variables in Built Applications

A critical security vulnerability, CVE-2025-68429, has been disclosed in Storybook, a widely used frontend workshop tool. The flaw, discovered via responsible disclosure on December 11th, is a bug in how Storybook processes environment variables defined in `.env` files. This vulnerability is present in certain built an...

The Lab · 2026-04-02 22:56:48 · The Verge

14. Granola AI Note-Taking App Exposes Private Notes to Anyone With a Link by Default

Granola, an AI-powered note-taking app, is shipping with a critical privacy flaw: notes are not private by default. Despite marketing claims of privacy, the app's default settings make any note viewable to anyone who possesses a shareable link, effectively broadcasting potentially sensitive meeting summaries and person...

The Lab · 2026-04-03 15:27:00 · GitHub Issues

15. Athena M2M OAuth2 Client Secret Exposed in Next.js Logs — Critical P0 Vulnerability

A critical security vulnerability has been identified within the Athena platform's machine-to-machine OAuth2 client registration system. The flaw exposes plaintext client secrets in server logs, creating a high-risk data leak. The issue is classified as Priority P0 (Critical) and maps directly to the OWASP A02:2021 cat...

The Lab · 2026-04-04 05:26:59 · GitHub Issues

16. Percolator Mainnet Launch Blocked: Critical Security Gaps Expose Supabase Key, Upgrade Authority, Oracle Markets

The mainnet launch of the Percolator protocol is halted by three critical security failures, each requiring immediate action from a single developer, Khubair. A leaked Supabase service key has been exposed for over seven weeks, the program's upgrade authority remains a vulnerable single keypair, and a migration script ...

The Lab · 2026-04-05 21:27:04 · GitHub Issues

17. Typefully API Error Handling Exposes Sensitive Internal Data to End Users

A low-severity but persistent information disclosure vulnerability has been identified in the Typefully API integration, where raw error responses are directly exposed to users. The flaw, located in the `src/services/typefully.ts` file, fails to sanitize API error messages before they are thrown, potentially leaking se...

The Stage · 2026-04-07 07:56:53 · Koreaboo

18. DinDin's Phone Number Leaked by YouTube Production Team's Editing Error

A celebrity's private phone number was exposed to the public due to a critical editing mistake by a YouTube production team. Singer and rapper DinDin revealed he was forced to change his number after the blunder, highlighting a recurring vulnerability where personal data is compromised not by hackers, but by simple hum...

The Lab · 2026-04-08 14:26:57 · Ars Technica

19. Anthropic's 'Mythos' AI Model Leaked, Now Restricted to Elite Tech & Government Vetting

Anthropic has launched its new Claude Mythos Preview AI model under a veil of heightened secrecy and restricted access, a direct response to a significant internal data leak. The cybersecurity-focused AI is now available only to a handpicked consortium of vetted organizations, locking out the broader market immediately...

The Lab · 2026-04-10 18:52:27 · Ars Technica

20. Valve's 'SteamGPT' Leak: AI Tools Spotted in Client Files for Game Incident Review

A recent Steam client update has leaked files referencing an internal AI project dubbed 'SteamGPT,' signaling that Valve is actively developing artificial intelligence tools for its gaming platform. The discovery, made by the automated SteamTracking GitHub project, points to a concrete move beyond industry hype, with t...