Skip to main content

tags

Breaches

Browse Pomerium articles tagged Breaches.

Topic archive

Resources Tagged: Breaches

Another GlobalProtect bypass, another reminder that the VPN is the wrong place to put your trust
blog posts

Another GlobalProtect bypass, another reminder that the VPN is the wrong place to put your trust

The Register reported today that CVE-2026-0257 , an authentication bypass in Palo Alto's GlobalProtect, has moved from a quiet medium-severity advisory to confirmed exploitation in the wild. Rapid7 traced successful attacks back to at least May 17 and reproduced the technique themselves. The flaw now sits in CISA's Known Exploited Vulnerabilities catalog with a same-day patch deadline for federal agencies.

When AI Has Root: Lessons from the Supabase MCP Data Leak
blog posts

When AI Has Root: Lessons from the Supabase MCP Data Leak

In a post by Simon Willison , we saw a lethal trifecta in action: an LLM agent with broad database privileges was tricked by a user's support-ticket text into exfiltrating secrets. The scenario with Cursor (a Claude-based IDE) and Supabase's new Model Context Protocol (MCP) is eerily simple but deadly: the developer's LLM agent runs with the full service_role key, bypassing all Row-Level Security (RLS). It ingests customer support messages as input. An attacker files a ticket containing hidden instructions like:

May 2025 Data Breaches: 184M Passwords, 364K SSNs Leaked
blog posts

May 2025 Data Breaches: 184M Passwords, 364K SSNs Leaked

Cyber attacks showed no signs of slowing down this past May 2025, with high-profile breaches and settlements making headlines. While the root causes behind many of these breaches remain undisclosed, a familiar pattern persists: insufficient access controls, third-party exposures, and delayed detection. These recurring weaknesses highlight the continued urgency for organizations to adopt zero-trust security principles—designed to prevent lateral movement, minimize damage, and detect anomalies before it’s too late.

April 2025 Data Breaches: 4 Million SSNs Leaked, 23M+ in Settlements
blog posts

April 2025 Data Breaches: 4 Million SSNs Leaked, 23M+ in Settlements

Cyber attacks didn’t slow down this past April 2025, recording sizable breaches and settlements—one data breach compromised the personal identifiable data of 4 million individuals. The cause behind many of these breaches was undisclosed, however, there is a recurring theme of insufficient access controls, third-party vulnerabilities, and delayed breach detection—all weaknesses that zero-trust security measures could have addressed.

March 2025 Data Breaches: 5M+ Impacted, $39.9M+ in Damages
blog posts

March 2025 Data Breaches: 5M+ Impacted, $39.9M+ in Damages

March 2025 saw yet another wave of significant cyber incidents affecting organizations across industries, with over 5 million individuals impacted and damages exceeding $39.9 million from just three settlements alone. These breaches reinforce a crucial reality: successful attacks rarely require sophisticated tactics, but instead exploit widespread gaps in basic security measures.

January 2025 Data Breaches [LIST]
blog posts

January 2025 Data Breaches [LIST]

According to the 2024 Annual Data Breach Report by the Identity Theft Resource Center, there were more than 1.7 million victim notices, “a measure of the scale of events and impacts on individuals,” last year, a number that was triple that of 2023. With 3,158 total compromises recorded in 2024, it’s no surprise that this past January 2025 was also full of data breaches.

Get a Personalized Demo

Schedule a Call with a Pomerium Engineer

Get a Demo