A hacker who breached multiple U.S. government systems repeatedly posted sensitive personal data on his Instagram account, according to newly unsealed court documents. The defendant, identified as 24‑year‑old Nicholas Moore of Springfield, Tennessee, pleaded guilty to hacking the Supreme Court’s electronic filing system and other government networks.
Court filings reveal Moore accessed the Supreme Court’s secure electronic filing platform at least 25 times using stolen credentials belonging to authorized users. On his Instagram account, @ihackthegovernment, Moore published personal information of a victim tied to the Supreme Court system, including the person’s name and historical filing records.
The breach extended beyond the judicial system. Moore also infiltrated AmeriCorps’ internal servers and the Department of Veterans Affairs’ MyHealtheVet portal, again using stolen login information. He posted detailed personal data on the social platform, including names, dates of birth, email addresses, physical addresses, phone numbers, veteran status, service history, partial Social Security numbers, and even identifiable health information like prescribed medications.
Prosecutors charged Moore with a single count of fraudulent activity involving computers, a Class A misdemeanor that carries a potential maximum sentence of one year in prison and a $100,000 fine. The federal case is scheduled for sentencing in April 2026.
Security experts say this incident highlights how rampant credential theft and inadequate access controls can expose even highly sensitive government systems to public data leaks. Posting stolen information to a widely accessible social platform turns a cybersecurity breach into a widespread privacy disaster with long‑lasting consequences for victims.
Related Stories
Billion Dollar Bitcoin Hacker Walks Free
PornHub Extorted After Historical Premium User Data Leaked
ICE Expands Cybersecurity Contract to Intensify Employee Surveillance
Airbus Moves Critical Workloads to European Sovereign Cloud Amid Security Concerns
For cybersecurity insights, threat analysis, and breach impact reports
Email inquiries to hello@laterstack.com
PornHub is facing extortion after the ShinyHunters gang gained access to historical Premium user data. The breach stems from a previous compromise at Mixpanel, the analytics provider PornHub used until 2021.
Mixpanel suffered a smishing attack on November 8, 2025, which allowed attackers to access systems. PornHub clarified that the exposed data comes from historical analytics records, not its own systems. Passwords, payment information, and other financial data were not affected.
ShinyHunters claims to have obtained 94 gigabytes of data containing more than 200 million records. The information includes email addresses, search history, video watch and download activity, video names, associated keywords, and timestamps.
A sample of the leaked data reviewed by BleepingComputer shows sensitive activity that users would expect to remain private. ShinyHunters confirmed that this is part of a larger trend in 2025, having also targeted Salesforce integration companies, Oracle E-Business Suite, and other analytics platforms.
The group is now creating a ransomware-as-a-service platform called ShinySpid3r. It will allow affiliates, including those connected to Scattered Spider, to conduct ransomware attacks.
For everyday users, this breach highlights how digital footprints can remain exposed years after the fact. Even historical analytics data can be weaponized by cybercriminals. Companies are custodians of this information, but breaches show that the responsibility to protect it extends beyond the moment data is collected.
Email inquiries to hello@laterstack.com
Related Laterstack Cybersecurity Stories
ICE Expands Cybersecurity Contract to Intensify Employee Surveillance
Airbus Moves Critical Workloads to European Sovereign Cloud Amid Security Concerns
Is Your Vibrator Spying on You? Understanding App-Connected Sex Toy Data
Apple and Google Roll Out Emergency Patches After Active Zero-Day Exploits
In a quiet reminder of how vulnerable personal information remains, 700Credit, a Michigan-based company providing credit checks and identity verification services to auto dealerships, disclosed a data breach affecting at least 5.6 million people. The breach, discovered in October, exposed names, addresses, dates of birth, and Social Security numbers collected from May through October 2025.
The breach came to light after an unidentified actor accessed the company’s systems. According to 700Credit, the intrusion was limited to the application layer, and there is currently no evidence of identity theft or fraud. Still, the company has notified affected individuals and is offering credit monitoring services.
Michigan Attorney General Dana Nessel emphasized the urgency for residents to protect their information. “If you get a letter from 700Credit, do not ignore it. A credit freeze or monitoring can prevent fraud,” she said, urging residents to take immediate steps to secure their personal data.
Consumers are advised to monitor their credit reports frequently, update passwords, enable multifactor authentication, and watch for phishing attempts. Nessel’s office also highlighted the Michigan Identity Theft Support System, which provides guidance for restoring compromised identities and filing complaints when necessary.
700Credit has been coordinating with cybersecurity experts, the FBI, and the Federal Trade Commission to manage the situation. The company has also notified state attorneys general and continues to communicate directly with dealers. A dedicated hotline has been established for inquiries.
For those impacted, the steps to safeguard their identities include reviewing their financial accounts, freezing credit if necessary, and reporting suspicious activity. Experts say that even when breaches are contained, vigilance remains essential, as personal information can circulate in underground markets for months or years.
The incident serves as a reminder that as industries digitize, security protocols must keep pace with the scale of personal data being handled. Millions of Americans rely on credit verification services, yet these systems remain attractive targets for malicious actors, highlighting gaps in oversight and preparedness.
Related Laterstack Cybersecurity Stories
Home Depot Exposed Internal Systems for a Year After Employee Leaked GitHub Token
Exposed AI Image Database Raises Serious Privacy and Security Concerns
Google Confirms Hackers Stole Data From 200 Companies via Gainsight
For inquiries, tips, or submissions: hello@laterstack.com
A critical cybersecurity lapse at Home Depot allowed access to internal systems for roughly a year, after an employee mistakenly published a private GitHub access token online. Security researcher Ben Zimmermann discovered the exposure in early November 2025 and attempted to alert Home Depot privately, but the company initially did not respond.
The token, which had been exposed since early 2024, granted access to hundreds of private Home Depot repositories hosted on GitHub. According to Zimmermann, it provided full access to the company’s cloud infrastructure, including order fulfillment, inventory management, and code development pipelines.
Zimmermann noted that he reached out multiple times via email and even LinkedIn to Home Depot’s Chief Information Security Officer, Chris Lanzilotta, but received no response. The lack of a formal vulnerability disclosure or bug bounty program at Home Depot left the researcher with no official reporting channel. Ultimately, TechCrunch’s outreach prompted Home Depot to revoke the token and secure the exposed systems.
“Home Depot is the only company that ignored me,” Zimmermann told TechCrunch, contrasting the response from other firms who have thanked him for similar disclosures. The company has not commented on whether any unauthorized parties accessed internal systems during the exposure.
The incident highlights a growing issue in corporate cybersecurity: organizations increasingly rely on cloud-hosted development infrastructure, but many lack formal mechanisms to identify and remediate leaked credentials. Access tokens, if publicly available, can allow attackers to modify code, compromise operational systems, or disrupt critical workflows.
As companies continue to digitize operations and rely on GitHub and other developer platforms, establishing clear vulnerability reporting channels and proactive monitoring becomes essential. Home Depot’s delayed response underscores the risk when such protocols are absent.
Related Laterstack Cybersecurity Stories
For inquiries, tips, or submissions: hello@laterstack.com
A massive collection of AI-generated images, including over 1 million explicit photos and videos, was left accessible online due to a misconfigured database. The exposure, discovered by security researcher Jeremiah Fowler, involved AI image tools used by multiple platforms, including MagicEdit and DreamPal.
The majority of the images depicted nudity, with some showing real people manipulated without consent, and disturbing reports suggested that images involving minors may also have been included. The database, which was linked to the influencer marketing firm SocialBook, was adding roughly 10,000 new images per day before being secured.
How the Breach Happened
Fowler discovered the vulnerability in October 2025, noting that the exposed database contained primarily explicit content. Some images were entirely AI-generated, while others were hyperrealistic depictions based on actual people. MagicEdit’s AI tools allowed users to modify images including nudifying them or swapping faces, raising significant privacy and safety risks.
“This isn’t just a technical problem—it’s about innocent people being abused online,” Fowler said. “These tools can be weaponized for harassment, blackmail, or worse.”
After Fowler reported the issue, the AI startup behind MagicEdit and DreamPal took the database offline, suspended app access, and launched an internal investigation with legal counsel. Both apps were subsequently removed from the Apple App Store, and were not available on Google Play.
Broader Implications
The incident highlights a growing cybersecurity risk in AI platforms. AI tools that manipulate personal images can be misused for sexual harassment, exploitation, or illegal content creation, including child sexual abuse material (CSAM). Security experts say startups must implement rigorous content moderation, beyond simple consent pop-ups, to prevent misuse.
Adam Dodge, founder of EndTAB (Ending Technology-Enabled Abuse), warned that the proliferation of AI nudify services exposes systemic problems: “The sexualization and control of women’s and girls’ bodies online is being supercharged by AI, and startups need accountability and trust measures from day one.”
DreamX, the company behind the apps, said it enforces filtering and moderation tools, including AI-based prompt review, and emphasized that CSAM is not tolerated under any circumstances. Still, experts argue that technical safeguards alone cannot fully prevent malicious use.
Why Cybersecurity Professionals Should Care
Exposed AI databases can become vectors for privacy violations, blackmail, and harassment.
Startups need proactive content-moderation frameworks, not reactive measures.
AI’s ability to generate hyperrealistic images magnifies risks for nonconsensual imagery.
Regulatory and legal implications are growing, and companies must adhere to strict safety and compliance standards.
This case serves as a warning that as AI technology advances, cybersecurity and privacy protocols must evolve just as fast to protect users.
Related Laterstack Cybersecurity Stories
Google Confirms Hackers Stole Data From 200 Companies via Gainsight
US Border Patrol Surveillance, Massive DDoS Attacks, and FBI Spying Make Headlines
For inquiries, story tips, or submissions: laterstack@proton.me
A rare breach inside China’s cyber ecosystem has exposed a detailed archive of hacking tools, stolen data, and government linked operations. Around 12,000 internal documents from KnownSec, a long running contractor for state agencies, appeared online this week and quickly drew global attention.
The leak was first posted on a Chinese language blog before spreading to Western researchers. The files outline a catalog of remote access Trojans, data extraction programs, and surveillance utilities. They also include a list of more than 80 targets the contractor claims to have infiltrated.
Among the reported data sets are 95 GB of Indian immigration records, three terabytes of call logs from South Korean telecom provider LG U Plus, and hundreds of gigabytes of planning data from Taiwan. The documents also appear to reference direct contracts between KnownSec and Chinese government bodies, removing any ambiguity about who the work served.
An uncommon look inside a closed system
China’s intelligence network has avoided anything resembling a Snowden style exposure. For analysts, any glimpse into the tools and priorities of its contractors is unusual. The KnownSec leak offers evidence of broad regional surveillance and points to an organized system for harvesting and analyzing large data troves.
Researchers say the archive reinforces what many suspected. China continues to rely heavily on private security companies to carry out offensive operations. These firms operate quietly in the background, giving the government distance while providing technical reach.
AI takes a darker turn
The leak follows another notable disclosure this week. Anthropic reported detecting a China linked hacking group using its Claude platform to write malware, analyze stolen files, and prepare intrusion tools. According to the company, the campaign relied on minimal human oversight and attempted to mask its activity by framing all requests as defensive research.
Claude eventually stopped the activity, but not before the group breached four organizations. Even with the low success rate and some hallucinated data, the campaign marks a turning point. State operators are beginning to test how far AI can automate intrusion work.
Growing pressure across the security landscape
The KnownSec leak lands during a year already marked by layoffs, consolidation, and rising tensions in the cybersecurity world. Several major firms have downsized as they shift investment toward automated detection and large scale AI systems.
What remains clear is that governments and contractors are accelerating their offensive capabilities at the same pace. The tools are faster, the targets broader, and the lines between state and private actors increasingly blurred.
For researchers and defenders, the leak is both a warning and an opportunity. It exposes methods that were never meant to be seen and offers a brief window into operations usually sealed behind thick walls.
Related Cybersecurity Stories on Laterstack:
Cybersecurity firm Deepwatch lays off staff as AI reshapes the industry
12 Steps to Better Cybersecurity in 2025