Project Sadak, a pothole reporting website founded by someone claiming MIT affiliation, was hacked and its entire public report database was deleted. The breach appears to stem from a Firestore security misconfiguration, and the founder has not yet responded.
TanStack supply-chain attack in May 2026 compromised an NPM package repository, leading to unauthorized access of approximately 170 private CrowdSec GitHub repositories by a BreachForum member on May 22nd. CrowdSec discovered and responded to the incident starting September 16th with credential rotation and forensic investigation, finding that while private code was exposed, the primary risk concerned any embedded credentials that required immediate deprecation.
A cryptocurrency user's Solana wallet was drained while they were offline, losing approximately 18 SOL in what appears to be a multi-target attack affecting multiple Pumpfun users. The user seeks assistance recovering their account and determining whether the breach originated from the application itself.