Alleged Żabka Breach Exposes Jira Data, Source Code, and API Keys
Alleged Żabka data leak offered for €5,000 includes Jira data, GitLab repos, and secrets; researchers verified much of the sample. A brand-new forum account showed up on August 2, posted once, and asked five grand for what it claims is a full data dump from Żabka Polska. Żabka Polska is Poland’s largest convenience store operator […]

A brand-new forum account showed up on August 2, posted once, and asked five grand for what it claims is a full data dump from Żabka Polska.
Żabka Polska is Poland’s largest convenience store operator and one of the country’s leading retail companies. Founded in 1998, it operates a franchise network of more than 11,000 convenience stores across Poland, serving millions of customers every day.
Related breach coverage
- GitLab Users Urged to Patch After Research Reveals Critical RCE Chain2026-07-27
Researchers chained two Oj parser bugs to achieve GitLab RCE via Jupyter notebook diffs, affecting authenticated users on unpatched versions. Depthfirst researchers published a working remote code execution exploit for GitLab on July 24, chaining two memory corruption bugs in Oj, a Ruby JSON parser with a native C implementation, into full command execution inside […]
- VPN Breach Exposes 58 Million Connection Logs Despite “No-Logs” Claims2026-07-29
A breached “no-logs” VPN exposed 58 million connection logs and millions of user, device, and payment records, contradicting its privacy claims. A threat actor on the Altenen cybercrime forum is distributing a 17 GB SQL database claimed to have been stolen from SplitVPN, formerly known as NotVPN, a Russian VPN marketed for bypassing internet censorship. […]
- AsyncAPI npm Supply Chain Attack: Malware Injected Into Packages With 2 Million Weekly Downloads2026-07-15
AsyncAPI npm packages with 2M weekly downloads were compromised, spreading malware with info-stealing, crypto-theft and RAT capabilities. OX Security researchers disclosed on July 14 that the AsyncAPI npm organization was compromised, with malicious code injected into four packages that together account for over 2 million weekly downloads. The affected versions are @asyncapi/generator 3.3.1, @asyncapi/generator-components 0.7.1, […]
- What an LLM Can Find: A Practical, Cheap Path to Code-level Threat Discovery2026-07-31
An AI-assisted audit found 29 flaws in GlobaLeaks, showing LLMs make large-scale code reviews faster, cheaper, and accessible. GlobaLeaks, a mature whistleblowing platform that had already undergone six independent professional audits over the past thirteen years, was subjected to an LLM-assisted security review that cost roughly USD 3,140 in API calls. The review identified 29 […]