Hims & Hers has disclosed a security incident involving unauthorized access to its Zendesk customer support platform. The breach resulted in exposure of sensitive information shared by users during support interactions, such as personal details and account-related data. The company clarified that the incident was limited to a third-party service provider and did not impact its core infrastructure, reinforcing concerns around the security of external platforms integrated into business operations. The attackers were able to access the Zendesk environment, which stores customer queries and communication records. These support tickets often contain personally identifiable information (PII) and other confidential details submitted by users while seeking assistance. Based on current findings, the compromise was contained within the support system, and there is no evidence suggesting intrusion into primary systems or internal databases. Although the exact entry point has not been publicly confirmed, such breaches are commonly linked to credential misuse, phishing attacks, or weak access controls in SaaS environments. After this incident was identified, Hims & Hers take steps to contain the issue, assess its impact, and informed to affected parties. This incident underscores the importance of strengthening third-party security practices, enforcing strict access management, and limiting sensitive data exposure within customer support platforms.
Aurora ransomware operators have been observed using SpaceX’s Cursor AI coding assistant, powered by Anthropic’s Claude Sonnet, to plan and execute attacks against organization...
Russian cybersecurity vendor Kaspersky has uncovered a campaign in which the Silver Fox threat actor is distributing the ValleyRAT backdoor, also known as Winos 4.0, disguised as a...
Security researcher Olivier Laflamme has disclosed two independent root remote code execution (RCE) chains affecting the Unitree G1 EDU robot. Tracked as CVE-2026-76639 and CVE-202...