Hackers outsmart Oxford Uni career progression platform – student data potentially compromised
A bug in a third-party system has been exploited by hackers to steal emails from an undisclosed number of individuals associated with Oxford University's career progression platform, raising concerns about the security of sensitive student data.

WPN Brief
- What Happened
A bug in a third-party system has been exploited by hackers to steal emails from an undisclosed number of individuals associated with Oxford University's career progression platform, raising concerns about the security of sensitive student data.
- Why It Matters
This incident highlights significant vulnerabilities in the university's data protection measures, potentially undermining trust among students and staff regarding the safety of their personal information.
- The Bigger Picture
The breach reflects a troubling trend in cybersecurity, as institutions and companies face increasing threats from hackers, with similar incidents reported across various sectors, indicating a broader issue of inadequate security protocols and the need for enhanced protective measures.
Related Reports
More coverage on this story
10 reports across the wire
UK Visa Portal website leaks thousands of user passport data and photos online
The UK Visa Portal has reportedly leaked thousands of user passport data, including verification selfies and other supporting documents, due to being stored in an unsecured cloud storage repository. This incident raises serious concerns about data security and privacy for users of the portal.
Hackers threaten to leak Mistral files online — AI giant confirms breach, but not what data is involved
Hackers known as TeamPCP have threatened to leak sensitive files from Mistral if they are not sold within a week, prompting the AI company to confirm a breach but withholding details about the specific data involved.
Worrying open-source security issue 'BadHost' could affect millions of AI agents, experts warn
A critical security vulnerability known as 'BadHost' has been identified in the Starlette open-source package, which is used by millions of AI agents. Researchers warn that this flaw could lead to the exfiltration of passwords and sensitive data, posing a significant risk to users and organizations relying on these AI systems.
The shocking reason 43% of UK businesses have been hit by cyber attacks last year
A recent report reveals that 43% of businesses in the UK experienced cyber attacks last year, highlighting a significant vulnerability within the sector. The findings suggest that certain organizations are more exposed to these threats, raising concerns about the overall cybersecurity landscape in the country.
Škoda warns customers their data may have been breached following online shop hit
Škoda has alerted customers that their data may have been compromised due to a vulnerability in its ecommerce software, which allowed unauthorized access to sensitive information. This breach raises significant concerns about the security measures in place to protect customer data.
Messaging app Tokee may have leaked 1.2 million user profiles — experts say exposed personal data 'presents significant privacy, security, and regulatory risks'
Messaging app Tokee has reportedly leaked the personal profiles of approximately 1.2 million users, raising significant concerns regarding privacy and security. Experts warn that the exposed data could lead to serious regulatory implications and increased risks for users.
Meta patches flaw that allowed MetaAI support bot to hand out password reset links without 2FA
Hackers were targeting high-profile accounts by tricking AI into sharing reset codes without validation.
Hackers claim to be selling 340 million stolen OnlyFans records — but experts are already skeptical on how serious hack is
Hackers have claimed to be selling 340 million stolen records from OnlyFans, raising concerns about data security; however, experts have expressed skepticism regarding the seriousness of this alleged breach, with OnlyFans stating that the claims are false.
Over a million WordPress sites hit in plugin flaw — so patch now or face the consequences
A significant security vulnerability has been discovered in a widely used WordPress plugin, affecting over a million sites and potentially leading to data leaks. The flaws necessitate immediate patching to prevent exploitation by malicious actors.
Websites are using this FROST-y new technique to spy on users by snooping on their SSD activity
A new side-channel attack technique has been discovered, allowing websites to spy on users by monitoring their solid-state drive (SSD) activity through JavaScript executed in browsers. This method raises significant privacy concerns as it can reveal sensitive user data and behavior.