News
Sagawa Express leaks ~70,000 users' data: delivery emails showed other people's names, caused by a config error
Japanese CompaniesPrivacySecurity
Japanese delivery giant Sagawa Express says up to about 70,000 users' personal data may have leaked through its "Smart Club" service. Delivery notification emails showed another person's name, email address and parcel tracking number. The cause was not a cyberattack but a configuration mistake made during recovery work. Here is what leaked, what did not, and how to avoid the Sagawa-impersonating scam emails that follow.
2026.07.2026 views
News Updated yesterday
Metabase CVE-2026-72898 (CVSS 10.0) Leaked Customer Data — Patch Now
SecurityPrivacyDevelopment
A serious flaw (CVE-2026-59827, severity 9.9) in the analytics tool Metabase—used by roughly 50,000 companies—lets attackers take over the server. In many default setups, just an ordinary account able to run SQL can seize the in-house server and steal the credentials of every connected database. A second admin-exploitable hole, CVE-2026-59826, was disclosed at the same time. We explain the affected versions and how to update now.
2026.07.1050 views
News
No-Code App Builder 'Adalo' Flaw CVE-2026-10706 Exposes User Data Across 1M+ Apps — No Patch Yet, Avoid Storing Sensitive Data
SecurityPrivacyDevelopment
A flaw in the popular no-code app builder Adalo (CVE-2026-10706) lets any authenticated user pull the full sign-up data—emails and more—of other people's apps. Over one million apps are affected, and because it is a platform-level flaw, users cannot fix it themselves. With no patch yet, avoid storing sensitive data. We explain the scope, the mechanism, and what to do now.
2026.07.1016 views
News
Aflac Japan Leaks Data on 4.38 Million Customers: What Policyholders Should Do, and the 'Instant Withdrawal' Myth
SecurityJapanese CompaniesPrivacy
Aflac Japan leaked ~4.38M customers' data via unauthorized access, incl. bank accounts for ~230,000. Does that mean instant withdrawal, and what should policyholders do?
2026.07.0136 views
News
KDDI email breach: count corrected to 12,231,954 and resets are done
PrivacyJapanese CompaniesSecurity
KDDI's ISP email system was breached, possibly exposing up to 14.22M email addresses and passwords. @nifty, BIGLOBE and more affected. Here's what to do now.
2026.06.2321 views
Roundup
Kitakyushu's national health insurance slips go wrong for 44,000 homes
PrivacyJapanese CompaniesDevelopment
Kitakyushu City found defects in the national health insurance payment slips it mailed out. Another person's slip was enclosed in some envelopes, and the barcodes for the January-March installments carried someone else's data. About 44,000 households are affected. The cause: a vendor program flaw in the system swapped in May, plus an error in the new envelope-stuffing machine. We break down what happened, why it slipped through, and what recipients should do.
2026.06.1717 views
Roundup
Awa Bank's 27,745-record leak: what happened in a test environment left running
Japanese CompaniesPrivacySecurity
Awa Bank leaked a cumulative 27,745 records of customer and shareholder data. The cause was a test environment left running long after development ended, with real customer data never deleted, then accessed from outside. We break down what leaked, how it could be abused, and how it should have been prevented.
2026.06.1714 views
Roundup
Hacker and Ransomware Groups Explained: Qilin, Anonymous, and Attacks on Japan
PrivacySecurityLawsuits & Regulation
A guide to the hacker and ransomware groups you see in the news—Qilin, Anonymous, North Korea's Lazarus and more—sorted into four types: ransomware, state-backed, social extortion and hacktivist. Where they came from, who's in them, which famous companies they hit, and what it means for ordinary life, including groups that struck Japan's Asahi, KADOKAWA and local governments.
2026.06.1539 views
Roundup
Asahi Net Profit Falls 36.7% (Confirmed): The Full Ransomware Chain Behind It, From Breach to Earnings
SecurityJapanese CompaniesPrivacy
In June 2026 Asahi Group cut its net-profit outlook from 167.5 billion to 120 billion yen, blaming the September 2025 ransomware attack. We trace the nine-month chain—breach via a VPN device, halted orders and shipping, 115,513 leaked records, the refusal to pay Qilin, and the 47.5-billion-yen hit—and explain what hole was breached and how the company responded.
2026.06.15116 views
News Updated 6 days ago
Cheap Wi-Fi Cameras Hijacked, Still No Fix: CVE-2026-28742
SecurityMobilePrivacy
Cheap Wi-Fi cameras and doorbells sold on Temu and Amazon (Naxclow / V720, X3) have a flaw that lets a stranger hijack the camera with no login, and CISA has issued an advisory. Your Wi-Fi password leaks too, and there is no patch. Here is CVE-2026-28742 and what owners should do.
2026.06.1344 views
News
Aqara Smart Locks and Cameras Could Be Hijacked: Cloud Flaws Including CVE-2026-50083
PrivacySecurityMobile
Researchers disclosed 10 vulnerabilities in Aqara's smart-home cloud, including CVE-2026-50083, that let an unauthenticated attacker operate smart locks and cameras. Here is the takeover chain and what owners should do.
2026.06.13111 views
News
Tapo D100C, L535E and P300 Leak Setup Data Over Bluetooth (CVE-2026-34126) — Update Now
PrivacySecurity
TP-Link's Tapo smart-home devices — the D100C doorbell chime, L535E bulb, and P300 power strip — leak their initial-setup Bluetooth communication in cleartext, letting someone nearby intercept it or hijack the device (CVE-2026-34126). Fixed firmware is out; here is how to check and update affected models and what to do if already set up.
2026.06.0563 views