DataBreachToday.com
SharePoint Zero-Days Exploited to Unleash Warlock Ransomware
2 months 2 weeks ago
145 Organizations Compromised by China-Linked Ransomware Hackers and Others
Nearly 150 different organizations' on-premises SharePoint servers have been exploited by attackers targeting the zero-day vulnerabilities now tracked as ToolShell, researchers warn. Early attacks have been attributed to China-linked groups, in some cases leading to Warlock ransomware infections.
Nearly 150 different organizations' on-premises SharePoint servers have been exploited by attackers targeting the zero-day vulnerabilities now tracked as ToolShell, researchers warn. Early attacks have been attributed to China-linked groups, in some cases leading to Warlock ransomware infections.
Coyote Trojan Turns Accessibility Into Attack Surface
2 months 2 weeks ago
Brazil-Targeting Malware Exploits Windows UIA to Evade Detection
A banking Trojan long confined to Brazil has become the first known malware to exploit Microsoft's UI Automation framework to extract credentials, signaling a new tactic that may evade conventional detection. Akamai's findings point to a growing trend of attackers using legitimate system features.
A banking Trojan long confined to Brazil has become the first known malware to exploit Microsoft's UI Automation framework to extract credentials, signaling a new tactic that may evade conventional detection. Akamai's findings point to a growing trend of attackers using legitimate system features.
Oracle/Cerner EHR Hack: Breach Reports Still Trickling In
2 months 2 weeks ago
At Least 410,000 Patients Reported Affected, But Likely Even More Victims
Months after news first broke that a hacking incident compromised legacy patient data hosted by Cerner electronic health record servers that were set to migrate to parent company Oracle's cloud environment, data breach reports related to the hack are still slowly trickling in to regulators. What's taking so long?
Months after news first broke that a hacking incident compromised legacy patient data hosted by Cerner electronic health record servers that were set to migrate to parent company Oracle's cloud environment, data breach reports related to the hack are still slowly trickling in to regulators. What's taking so long?
VPN Use Surges as UK Online Safety Act Takes Effect
2 months 2 weeks ago
New UK Law Requiring Age-Verification Measures on Porn Sites Causes VPN Use to Soar
Free virtual private network services are soaring to the top of the app charts in the United Kingdom after a new law went into effect Friday requiring platforms that contain adult content - including sites like X and Reddit - to confirm users' ages through "robust" verification measures.
Free virtual private network services are soaring to the top of the app charts in the United Kingdom after a new law went into effect Friday requiring platforms that contain adult content - including sites like X and Reddit - to confirm users' ages through "robust" verification measures.
Rise of Chaos Ransomware Tied to BlackSuit Group's Exit
2 months 2 weeks ago
Operation Checkmate Disrupts One of the Large Russian-Speaking Ransomware Groups
An international law enforcement operation has disrupted BlackSuit, a ransomware group tied to hundreds of victims and ransom demands that exceeded half a billion dollars. The takedown occurred as security experts tracked the rise of a new group called Chaos, which may be a BlackSuit rebrand.
An international law enforcement operation has disrupted BlackSuit, a ransomware group tied to hundreds of victims and ransom demands that exceeded half a billion dollars. The takedown occurred as security experts tracked the rise of a new group called Chaos, which may be a BlackSuit rebrand.
Allianz Life Breach Tied to CRM Compromise
2 months 2 weeks ago
Attackers Stole US Customer Data Using Social Engineering
A malicious actor breached a customer relationship management platform used by Allianz Life Insurance of North America on July 16 and stole personally identifiable information of most of its 1.4 million U.S. customers, financial professionals and some employees, the company said.
A malicious actor breached a customer relationship management platform used by Allianz Life Insurance of North America on July 16 and stole personally identifiable information of most of its 1.4 million U.S. customers, financial professionals and some employees, the company said.
Health System Settles Web Tracker Lawsuit for up to $9.25M
2 months 2 weeks ago
Lawsuit Claims BJC Health Shared Patient Info From MyChart Portal Without Consent
A Missouri healthcare system has agreed to pay up to $9.25 million to settle a proposed class action lawsuit alleging that its use of online tracking tools in its patient portals transmitted sensitive patient information to third-party firms without the patients' knowledge or consent.
A Missouri healthcare system has agreed to pay up to $9.25 million to settle a proposed class action lawsuit alleging that its use of online tracking tools in its patient portals transmitted sensitive patient information to third-party firms without the patients' knowledge or consent.
Corelight Uses Gen AI to Power Smarter Threat Detection
2 months 2 weeks ago
SaaS Enhancements Aim to Boost Network Detection, Response for Small Security Teams
Corelight's SaaS platform Investigator is designed to bring scalable network detection and response to smaller security teams. CEO Brian Dye says generative AI workflows and enriched network context help defenders identify threats faster and with greater confidence than ever.
Corelight's SaaS platform Investigator is designed to bring scalable network detection and response to smaller security teams. CEO Brian Dye says generative AI workflows and enriched network context help defenders identify threats faster and with greater confidence than ever.
Dropzone AI Gets $37M to Build Out Cyber AI Agent Ecosystem
2 months 2 weeks ago
Startup Targets Next-Gen Security Opportunities Beyond Autonomous SOC Agents
Dropzone AI raised $37 million to scale its flagship AI SOC analyst and build new agentic AI tools for cybersecurity operations. CEO Edward Wu says the funding supports demand surges as enterprises shift toward human-augmenting AI to handle alert fatigue and security tool sprawl.
Dropzone AI raised $37 million to scale its flagship AI SOC analyst and build new agentic AI tools for cybersecurity operations. CEO Edward Wu says the funding supports demand surges as enterprises shift toward human-augmenting AI to handle alert fatigue and security tool sprawl.
Russia's Flag Carrier Cancels Flights After Hack Attack
2 months 2 weeks ago
Aeroflot Hit With Wiper Malware, Claim Pro-Ukrainian Hackers From Belarus
Russia's largest airline, Aeroflot, canceled dozens of flights on Monday and delayed more due to an IT disruption. Two pro-Ukrainian hacking groups from Belarus claimed to have wiped stolen extensive customer data before wiping 7,000 physical and virtual servers used by the airline.
Russia's largest airline, Aeroflot, canceled dozens of flights on Monday and delayed more due to an IT disruption. Two pro-Ukrainian hacking groups from Belarus claimed to have wiped stolen extensive customer data before wiping 7,000 physical and virtual servers used by the airline.
Scattered Spider Exploiting VMware vSphere
2 months 2 weeks ago
Hacking Tactics Linked to Retail, Airline Compromises
The loosely connected band of adolescent cybercriminals tracked as Scattered Spider has joined the VMware hypervisor hacking bandwagon, pivoting into virtual servers through corporate instances of Active Directory. vSphere integration with Active Directory adds a yet another layer of insecurity.
The loosely connected band of adolescent cybercriminals tracked as Scattered Spider has joined the VMware hypervisor hacking bandwagon, pivoting into virtual servers through corporate instances of Active Directory. vSphere integration with Active Directory adds a yet another layer of insecurity.
New York Unveils 'Nation-Leading' Water Sector Cyber Rules
2 months 2 weeks ago
State Seeks Public Input on New Reporting Rules and Regulations for Water Sector
New York State has unveiled a comprehensive set of water and wastewater cybersecurity regulations aimed at bolstering defenses for the vulnerable critical infrastructure sector, in addition to a new competitive investment program to help modernize under-resourced entities.
New York State has unveiled a comprehensive set of water and wastewater cybersecurity regulations aimed at bolstering defenses for the vulnerable critical infrastructure sector, in addition to a new competitive investment program to help modernize under-resourced entities.
How Torq Is Rewiring SOCs With Autonomous Cyber Agents
2 months 2 weeks ago
CEO Ofer Smadari: AI Agents Now Resolving Threat Cases at Scale with Accuracy
With its Revrod acquisition, Torq is pushing deeper into autonomous threat response. CEO Ofer Smadari outlines how AI runbooks and autopilot tech such as Socrates are reducing human workloads and helping security teams scale amid rising alert volumes and phishing attacks.
With its Revrod acquisition, Torq is pushing deeper into autonomous threat response. CEO Ofer Smadari outlines how AI runbooks and autopilot tech such as Socrates are reducing human workloads and helping security teams scale amid rising alert volumes and phishing attacks.
Patients Still Struggle With Full Access to Health Info
2 months 2 weeks ago
Tech Standards, Regulatory Levers Have Removed Barriers. What's Still in the Way?
Patients these days have an easier path to securely accessing their electronic health information, thanks in large part to advancements in certain technology standards and a big push by federal regulatory policies in recent years. But obstacles still exist.
Patients these days have an easier path to securely accessing their electronic health information, thanks in large part to advancements in certain technology standards and a big push by federal regulatory policies in recent years. But obstacles still exist.
Critical Infrastructure Leaders: Threat Level Remains High
2 months 3 weeks ago
OT Experts Advocate for Collaboration and "Adversary-Hostile" National Defenses
OT environments have long been bereft of their traditional shelter from cyberattacks made from hacker ignorance or disinterest. Industrial environments are forefronts for nation-state hacking, the risk heightened by global tensions and the convergence of operational technology with IT counterparts.
OT environments have long been bereft of their traditional shelter from cyberattacks made from hacker ignorance or disinterest. Industrial environments are forefronts for nation-state hacking, the risk heightened by global tensions and the convergence of operational technology with IT counterparts.
Feds Fine Surgery Practice $250K in Ransomware Breach
2 months 3 weeks ago
2021 Pysa Hack Compromised PHI of Nearly 25,000 Patients
A HIPAA breach investigation into a 2021 attack involving a variant of Pysa ransomware resulted in a $250,000 fine for an upstate New York specialty surgery practice, which also agreed to a corrective action plan that will be monitored by federal regulators for the next two years.
A HIPAA breach investigation into a 2021 attack involving a variant of Pysa ransomware resulted in a $250,000 fine for an upstate New York specialty surgery practice, which also agreed to a corrective action plan that will be monitored by federal regulators for the next two years.
Trump's CISA Nominee Grilled Over 2020 Election Fraud Claims
2 months 3 weeks ago
Sean Plankey Dodges Election Security Questions in Senate Confirmation Hearing
Sean Plankey, a former Energy Department and National Security Council cybersecurity official, faced tough questions from lawmakers about President Donald Trump's false claims of voting machine vulnerabilities and election fraud in the 2020 election during his Thursday confirmation hearing.
Sean Plankey, a former Energy Department and National Security Council cybersecurity official, faced tough questions from lawmakers about President Donald Trump's false claims of voting machine vulnerabilities and election fraud in the 2020 election during his Thursday confirmation hearing.
Vectra CEO: SOCs Need AI Agents to Keep Up With Attacks
2 months 3 weeks ago
CEO Hitesh Sheth: New AI Offerings Boost Efficiency, Address Modern Network Needs
President and CEO Hitesh Sheth details how Vectra AI uses triage, stitching and prioritization agents to enhance SOC performance and curb alert fatigue. The network detection and response vendor is expanding AI Analyst via AWS Bedrock and integrations with Zscaler and CrowdStrike.
President and CEO Hitesh Sheth details how Vectra AI uses triage, stitching and prioritization agents to enhance SOC performance and curb alert fatigue. The network detection and response vendor is expanding AI Analyst via AWS Bedrock and integrations with Zscaler and CrowdStrike.
Quantum Data Centers Await Use Cases and Tech Maturity
2 months 3 weeks ago
CIR's Lawrence Gasman on Why Quantum Data Centers Remain Years From Enterprise Use
Quantum data centers could become viable if business use cases emerge, says Lawrence Gasman, founder, Communications Industry Researchers. Technical hurdles, such as physical form factor, environment, cost and photonic interconnects, must be addressed for enterprise adoption.
Quantum data centers could become viable if business use cases emerge, says Lawrence Gasman, founder, Communications Industry Researchers. Technical hurdles, such as physical form factor, environment, cost and photonic interconnects, must be addressed for enterprise adoption.
Checked
3 hours 33 minutes ago
DataBreachToday.com RSS News Feeds on data breach today news, regulations, blogs and education
DataBreachToday.com feed