View Ridge Security
Back to Cyber HoseThreat Research & Deep Dives

Beacon CRM AWS Key Breach Exposes Data From 1,500 UK Charities

๐Ÿ•ต๏ธ RESEARCH & DEEP DIVES

  • Beacon CRM AWS Key Breach Exposes Data From 1,500 UK Charities
    Beacon CRM exposed data from about 1,500 UK charities after an AWS key compromise.
    • Beacon CRM customers included about 1,500 UK charities, including healthcare and victim-support organizations.
    • Names, email addresses, phone numbers, postal addresses, donation records and attachments were exposed.
    • The AWS access key was potentially published in public JavaScript build artifacts.
    • The attacker used valid credentials to download CRM data from July 27 to 28, 2026, during a 1-hour-27-minute session.
    • AWS encryption at rest did not prevent readable downloads because the valid credentials enabled decryption.
      ๐Ÿ“Ž Coverage: infosecurity-magazine.com ยท ๐Ÿ‘ via BleepingComputer

๐Ÿ“‹ ADVISORIES

  • ๐Ÿ“„ Source for Android Malware Infects DoFun Car Head Units for Ad Fraud and Proxy Botnets โ€” ics-cert.kaspersky.com

  • ๐Ÿ“„ Source for Calix GS7 XGS Router Flaw Allows Unauthenticated NAT Rule Changes โ€” drkq.github.io

๐Ÿ”“ CVEs & KEV

  • CVE-2026-69502 โ€” CVSS 10.0 โ€” Azure SQL Database Elevation of Privilege VulnerabilityServer-side request fo...

  • CVE-2026-63343 โ€” CVSS 9.9 โ€” Arbitrary File Read/Write: metadata.yaml symlink in image allows host filesys...

  • CVE-2026-63125 โ€” CVSS 9.9 โ€” Incus vulnerable to root RCE via image backup.yaml symlinkIncus is a system c...

  • CVE-2026-62941 โ€” CVSS 9.9 โ€” Incus: Cross-project instance copy bypasses target project restrictions via T...

  • CVE-2026-62940 โ€” CVSS 9.9 โ€” Incus has a project restriction bypass via instance migration config override...

  • CVE-2026-62867 โ€” CVSS 9.9 โ€” Incus has an argument injection in storage volume block.create_options that l...

  • CVE-2026-77087 โ€” CVSS 9.4 โ€” Paperclip before 0.3.1 Remote Code Execution via DNS RebindingPaperclip befor...

  • CVE-2026-75932 โ€” CVSS 9.2 โ€” Jet Admin tenant isolation failureJet Admin allows an attacker to create a ma...

  • CVE-2026-75933 โ€” CVSS 8.5 โ€” Jet Admin Stored XSSJet Admin allows an authenticated attacker to inject Java...

  • CVE-2026-55622 โ€” CVSS 7.7 โ€” Incus has a project restriction bypass in instance copy across projectsIncus ...

  • CVE-2026-55621 โ€” CVSS 7.7 โ€” Incus has a project restriction bypass for custom volume copy across projects...

  • CVE-2026-54789 โ€” CVSS 7.5 โ€” mod_auth_openidc has out-of-bounds read and write in state cookie parsingmod_...

  • CVE-2026-49114 โ€” CVSS 6.8 โ€” ONNX symlink-following and path-traversal arbitrary file writeIn ONNX before ...

Need help assessing your exposure?

Start with the free Posture Self-Check to see where you stand against the current threat landscape.

Free Posture Self-Check