Est. 2001·3,000+ placements · six offices · four regions
Sentry — source image

Image via Forkast News

Cybersecurity Incidentcurated sourcedetected 2026-08-09 · confidence 95%

Last updated

Sentry: Cybersecurity Incident

Publicly exposed Sentry Data Source Names (DSNs) were exploited as an attack vector via AI coding agents (Claude Code, Cursor) through Model Context Protocol integrations to achieve remote code execution and credential exfiltration. Attack succeeded 85% of the time across 100+ organizations; 2,388 organizations identified with publicly discoverable DSNs including 71 in Tranco top-1M and ~27% of Fortune 1000 via Cloudflare MCP alone. Sentry notified June 3, 2026; deployed content filter by June 12 but declined platform-level root-cause remediation.

Source: Forkast News

The leadership read

Security engineering and incident response build-out required: threat intelligence analysts to identify compromised organizations and exposed credentials; vulnerability assessment specialists to audit DSN exposure across customer base; platform security architects to design and implement authentication/authorization controls for ingest endpoints; incident response coordinators to manage customer notifications and remediation guidance; DevSecOps engineers to implement MCP-layer security controls and agent sandboxing; product security managers to establish vulnerability disclosure and patch prioritization processes.

Market context: Backdrop: a 102.5 (Warm) Talent Market Index (down 1.7 on the month) with Americas activity easing (-2.3pts).

Sentry: 1 signal in the last 90 days.

More signals across Americas

Cybersecurity Incident · Americas

Kaiser Permanente

Kaiser Permanente patient suffered wrongful hysterectomy due to pathology lab sample labeling error and misidentification, resulting in false cancer diagnosis and months of unnecessary treatment

Cybersecurity Incident · Americas

Point72

Point72 was targeted in a social engineering campaign by threat actor UNC6671, in which attackers impersonated IT help desk staff via phone calls to employees' personal devices, attempting to steal credentials and MFA tokens for unauthorized cloud access.

Cybersecurity Incident · Americas

Two Sigma

Two Sigma was targeted in a social engineering campaign by threat actor UNC6671, in which attackers impersonated IT help desk staff via phone calls to employees' personal devices, attempting to steal credentials and MFA tokens for unauthorized cloud access.

Cybersecurity Incident · Americas

CME Group

Hackers devised phishing websites targeting employee credentials at CME Group and multiple other major financial institutions and private equity firms. Attack coordinated by threat actors operating under names including Redact, Pink, Falcon and Helix.

Cybersecurity Incident · Americas

Levi Strauss & Co.

Levi Strauss & Co. confirmed that hackers used social engineering to compromise three employees and steal corporate data from their machines.

Cybersecurity Incident · Americas

Blackstone

Hackers targeted Blackstone and other US private equity and financial firms with phishing websites designed to steal employee passwords

Weekly briefing

Track companies like Sentry — with our analysis

Anyone can set an alert for one company. We send a weekly read on the whole peer set — who's moving, and what it means for leadership. Pick what to follow:

Intelligence powered by Autonodal ↗

Nearby in the record