Colorado Laboratory Already Facing Several Proposed Class Action Breach Lawsuits A Colorado-based pathology laboratory is notifying more than 1.8 million patients that their sensitive information was compromised in an April hack, one of the largest breaches reported by a medical testing lab to U.S. federal regulators to date. Ransomware gang Medusa is blamed for the attack.
New Funding to Aid US Government Growth, Generative AI Security Product Development Zenity has closed a $38 million Series B round to advance its agentic AI security platform and extend its no-code and low-code application support. With investment from Third Point Ventures and DTCP, the funding enables Zenity to cater to clients in sectors like financial services and healthcare.
Lazarus Group in Particular Using Cross-Platform Languages to Hit macOS Targets Cryptocurrency-seeking hackers are increasingly targeting macOS users. So warn security researchers as they track a rise in macOS backdoors and information-stealing malware, much of which traces back to a well-known cryptocurrency heist culprit: North Korea.
Volt Typhoon, APT31 and APT41 Tied to Campaigns Targeting Sophos' Edge Devices Firewall maker Sophos disclosed Thursday a half-decade worth of efforts by multiple nation-state Chinese hacking groups to infiltrate its appliances, calling the admission a wake-up call for the cybersecurity industry. Targeting firewall appliances is a known nation-state tactic.
A vulnerability was found in Fortinet FortiWan up to 4.2.4 and classified as critical. This issue affects some unknown processing of the file linkreport/tmp/admin_global of the component Cookie Handler. The manipulation as part of GET Request leads to information disclosure.
The identification of this vulnerability is CVE-2016-4968. The attack may be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability has been found in Fortinet FortiWan up to 4.2.4 and classified as critical. This vulnerability affects unknown code of the file script/cfg_show.php. The manipulation leads to information disclosure.
This vulnerability was named CVE-2016-4967. The attack can be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability, which was classified as critical, was found in Fortinet FortiWan up to 4.2.4. This affects an unknown part of the file diagnosis_control.php. The manipulation of the argument UserName as part of GET Request leads to improper authentication (File).
This vulnerability is uniquely identified as CVE-2016-4966. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability has been found in Samba up to 3.6.x and classified as very critical. This vulnerability affects the function TrustDomainInfoControllers of the component NDR PULL LSA. The manipulation leads to numeric error.
This vulnerability was named CVE-2012-1182. The attack can be initiated remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.