Information security

[ follow ]
#data-breach

Ascension cyberattack exposed personal data of 5.6 million people

The ransomware attack on Ascension affected nearly 5.6 million people, significantly disrupting patient care and compromising data.
Initial reports underestimated the scale of the breach, highlighting vulnerabilities in healthcare cybersecurity.

IntelBroker leaks 2.9 TB of exposed Cisco records - and there's more to come

Cisco data breach exposes sensitive information due to misconfiguration.
Hackers leaked 2.9 TB of data from Cisco, affecting major firms.
Cisco addressed the incident quickly, ensuring no internal systems were compromised.

LastPass breach comes back to haunt users as hackers steal $12 million in two days

The LastPass data breach continues to impact users two years later, with hackers stealing millions in cryptocurrency.

5M unique credit and debit cards exposed in data breach

5 million card details were exposed due to an Amazon S3 data breach, putting shoppers at financial risk.

Nebraska sues Change Healthcare over security failings that led to medical data breach of over 100 million Americans | TechCrunch

Nebraska has sued Change Healthcare over a data breach affecting 100 million Americans due to alleged security failings.
The breach highlights significant vulnerabilities in healthcare technology security measures.

LastPass breach comes back to haunt users as hackers steal $12 million in two days

The LastPass data breach continues to impact users, leading to significant cryptocurrency thefts two years later.

Ascension cyberattack exposed personal data of 5.6 million people

The ransomware attack on Ascension affected nearly 5.6 million people, significantly disrupting patient care and compromising data.
Initial reports underestimated the scale of the breach, highlighting vulnerabilities in healthcare cybersecurity.

IntelBroker leaks 2.9 TB of exposed Cisco records - and there's more to come

Cisco data breach exposes sensitive information due to misconfiguration.
Hackers leaked 2.9 TB of data from Cisco, affecting major firms.
Cisco addressed the incident quickly, ensuring no internal systems were compromised.

LastPass breach comes back to haunt users as hackers steal $12 million in two days

The LastPass data breach continues to impact users two years later, with hackers stealing millions in cryptocurrency.

5M unique credit and debit cards exposed in data breach

5 million card details were exposed due to an Amazon S3 data breach, putting shoppers at financial risk.

Nebraska sues Change Healthcare over security failings that led to medical data breach of over 100 million Americans | TechCrunch

Nebraska has sued Change Healthcare over a data breach affecting 100 million Americans due to alleged security failings.
The breach highlights significant vulnerabilities in healthcare technology security measures.

LastPass breach comes back to haunt users as hackers steal $12 million in two days

The LastPass data breach continues to impact users, leading to significant cryptocurrency thefts two years later.
moredata-breach
#cybersecurity

TP-Link routers may be banned in the US next year - what that means for you

The US is considering banning TP-Link routers due to national security risks associated with hacking incidents.
TP-Link holds a significant share of the US router market, raising concerns over the impact of a potential ban.

LockBit Developer Rostislav Panev Charged for Billions in Global Ransomware Damages

Rostislav Panev, a dual Russian-Israeli national, faces charges for developing the LockBit ransomware since 2019, allegedly profiting over $230,000.

Top 10 cyber crime stories of 2024 | Computer Weekly

Ransomware attacks in 2024 caused unprecedented devastation, particularly affecting the UK's NHS and the British Library.
Increased transparency and proactive measures by the NCSC and NCA signal a stronger fight against cybercrime.

Nearly 400,000 WordPress credentials stolen

A security breach by MUT-1244 has resulted in the theft of over 390,000 WordPress credentials, highlighting the vulnerability of security researchers and pentesters.

Credential phishing attacks rose by 703% in H2 of 2024

Credential theft attacks surged 703% in H2 2024, indicating rising phishing threats.

APT29 Hackers Target High-Value Victims Using Rogue RDP Servers and PyRDP

APT29 is repurposing legitimate red teaming methodologies to execute sophisticated cyber attacks using malicious RDP configurations.

TP-Link routers may be banned in the US next year - what that means for you

The US is considering banning TP-Link routers due to national security risks associated with hacking incidents.
TP-Link holds a significant share of the US router market, raising concerns over the impact of a potential ban.

LockBit Developer Rostislav Panev Charged for Billions in Global Ransomware Damages

Rostislav Panev, a dual Russian-Israeli national, faces charges for developing the LockBit ransomware since 2019, allegedly profiting over $230,000.

Top 10 cyber crime stories of 2024 | Computer Weekly

Ransomware attacks in 2024 caused unprecedented devastation, particularly affecting the UK's NHS and the British Library.
Increased transparency and proactive measures by the NCSC and NCA signal a stronger fight against cybercrime.

Nearly 400,000 WordPress credentials stolen

A security breach by MUT-1244 has resulted in the theft of over 390,000 WordPress credentials, highlighting the vulnerability of security researchers and pentesters.

Credential phishing attacks rose by 703% in H2 of 2024

Credential theft attacks surged 703% in H2 2024, indicating rising phishing threats.

APT29 Hackers Target High-Value Victims Using Rogue RDP Servers and PyRDP

APT29 is repurposing legitimate red teaming methodologies to execute sophisticated cyber attacks using malicious RDP configurations.
morecybersecurity
#social-security

Senate passes Social Security benefits boost for many public service retirees

The Senate's bipartisan bill aims to enhance Social Security benefits for nearly 3 million public employees, rectifying long-standing inequities.

The Surprising Reason You Might End Up With Less Social Security

Social Security benefits can be taxed, affecting many seniors.
Tax thresholds for Social Security have not changed in decades.
Proposals to eliminate taxes on Social Security face feasibility issues.

I Signed Up for Social Security but Haven't Received My First Check. What Do I Do?

Timing is key in signing up for Social Security benefits, affecting monthly income based on personal earnings.

How Could Elon Musk's DOGE Impact Social Security?

Government spending can become inefficient, leading to initiatives like DOGE aimed at reducing waste and securing financial stability for programs like Social Security.

Senate passes Social Security benefits boost for many public service retirees

The Senate's bipartisan bill aims to enhance Social Security benefits for nearly 3 million public employees, rectifying long-standing inequities.

The Surprising Reason You Might End Up With Less Social Security

Social Security benefits can be taxed, affecting many seniors.
Tax thresholds for Social Security have not changed in decades.
Proposals to eliminate taxes on Social Security face feasibility issues.

I Signed Up for Social Security but Haven't Received My First Check. What Do I Do?

Timing is key in signing up for Social Security benefits, affecting monthly income based on personal earnings.

How Could Elon Musk's DOGE Impact Social Security?

Government spending can become inefficient, leading to initiatives like DOGE aimed at reducing waste and securing financial stability for programs like Social Security.
moresocial-security

Pakistan: Islamist militants kill 16 security personnel DW 12/21/2024

A deadly overnight raid by Islamists on a Pakistani army outpost resulted in the deaths of 16 security personnel, claiming responsibility for the attack.

Chancellor Scholz to visit site of Magdeburg attack DW 12/21/2024

The incident questions the effectiveness of existing security measures at Christmas markets in Germany.

Cyber attack costing six-figure sum, council says

Hackney Council's financial struggles are exacerbated by a cyber attack recovery, leading to significant overspending on staffing and IT consulting.
from New York Post
1 day ago

Massive data breach at federal credit union exposes 240K members

SRP Federal Credit Union's data breach exposed sensitive information of over 240,000 individuals due to inadequate security measures and delayed detection.

Executives targeted in mobile spearphishing attacks

Organizations need advanced, AI-driven solutions to defend against sophisticated mobile phishing campaigns.
Implementing comprehensive mobile defense strategies is crucial to reducing vulnerabilities.
#cybercrime

Israeli hacker alleged to be software dev for LockBit faces extradition to U.S. for role in global ransomware network

Rostislav Panev faces extradition to the U.S. for cybercrimes associated with the LockBit ransomware group.

Ukrainian National Sentenced to Federal Prison in "Raccoon Infostealer" Cybercrime Case

Mark Sokolovsky was sentenced to 60 months for conspiracy related to the Raccoon Infostealer malware operation.

What to Do If Hackers Steal Your Cryptocurrency (And How to Stay Protected Against Fraud)

Cryptocurrency fraud, particularly account takeovers, is on the rise, creating significant risks for users and businesses.

US reveals charges against alleged LockBit ransomware developer

Rostislav Panev has been charged for his role in the LockBit ransomware group, reflecting ongoing efforts to combat cybercrime.

Romanian National Sentenced to 20 Years in Prison in Connection with NetWalker Ransomware Attacks

A Romanian man received a 20-year prison sentence for his involvement in the NetWalker ransomware attacks, which specifically targeted the healthcare sector during COVID-19.

Israeli hacker alleged to be software dev for LockBit faces extradition to U.S. for role in global ransomware network

Rostislav Panev faces extradition to the U.S. for cybercrimes associated with the LockBit ransomware group.

Ukrainian National Sentenced to Federal Prison in "Raccoon Infostealer" Cybercrime Case

Mark Sokolovsky was sentenced to 60 months for conspiracy related to the Raccoon Infostealer malware operation.

What to Do If Hackers Steal Your Cryptocurrency (And How to Stay Protected Against Fraud)

Cryptocurrency fraud, particularly account takeovers, is on the rise, creating significant risks for users and businesses.

US reveals charges against alleged LockBit ransomware developer

Rostislav Panev has been charged for his role in the LockBit ransomware group, reflecting ongoing efforts to combat cybercrime.

Romanian National Sentenced to 20 Years in Prison in Connection with NetWalker Ransomware Attacks

A Romanian man received a 20-year prison sentence for his involvement in the NetWalker ransomware attacks, which specifically targeted the healthcare sector during COVID-19.
morecybercrime

Attorney General James Secures $500,000 from Auto Insurance Company Over Data Breach

Noblr was fined $500,000 for a data breach impacting over 80,000 New Yorkers, stressing the need for strong cybersecurity measures among auto insurance firms.

N Korea hackers stole $1.3bn of crypto this year - report

North Korean hackers significantly contribute to rising cryptocurrency theft, with $1.3bn stolen this year, showcasing an escalating threat in the crypto sector.

$2.2 Billion Stolen in 303 Crypto Hacks in 2024: Chainalysis Report Security Bitcoin News

The 2024 Chainalysis crypto crime report showed that North Korean hackers were responsible for over 60% of stolen crypto.

Rspack npm Packages Compromised with Crypto Mining Malware in Supply Chain Attack

Rspack npm packages @rspack/core and @rspack/cli were compromised, leading to the distribution of malware through malicious versions published on npm.

FTC Finalizes Order with Marriott and Starwood Requiring Them to Implement a Robust Data Security Program to Address Security Failures

Marriott and Starwood must implement a comprehensive information security program after FTC breaches affected over 344 million customers.

5 Cybersecurity trends in 2024

Cybersecurity incidents in 2024 highlight the risks of open-source attacks and the ongoing sophistication of bot attacks, necessitating improved security measures.

Microsoft 365 users affected by random product deactivation error

User 'Product Deactivated' errors in Office apps stem from administrative license changes.
Affected users can resolve issues through reactivation or restarting apps.

Edge users used Copilot functionality 10 billion times

Edge browser's Copilot expected to reach 10 billion interactions by 2024, signifying growing AI usage.
Bing search engine sees daily usage by 140 million users, driven by Edge's features.
User-friendly tools and significant performance improvements contribute to Edge's rising popularity.

Survey: Parking lot safety influences holiday shopping habits

Retailers must prioritize safety, especially in parking lots, as it heavily influences consumer shopping decisions. Security technology is essential for boosting shopper confidence.

Microsoft investigating 365 Office activation gremlin

There is an ongoing activation issue in Microsoft 365 Office triggered by licensing changes by administrators.

Sophos Issues Hotfixes for Critical Firewall Flaws: Update to Prevent Exploitation

Sophos has patched critical vulnerabilities in its Firewall products to prevent remote code execution and privileged access.

"Lock Her Up": Trump's Team Is Now Doing the Exact Thing They Screamed About Hillary Clinton Doing

Trump's transition team is reportedly using private servers, raising cybersecurity concerns and echoes of Clinton's email controversy.
Foreign intelligence poses a significant threat during presidential transitions, necessitating secure communication practices.

Feds issue another warning about texting dangers - the scary reason to stop using two-factor authentication now

Users should avoid receiving two-factor authentication codes via SMS due to security vulnerabilities exposed by recent telecom breaches.

Has Serbia hacked activists', journalists' phones? Why?

Serbian activists and journalists are reportedly being unlawfully surveilled by police using spyware, raising significant privacy concerns.

How Zero Trust redefines traditional authentication and authorization practices

Zero Trust requires constant verification of user identities and access rights, significantly enhancing security in modern network environments.

Thousands Download Malicious npm Libraries Impersonating Legitimate Tools

Malicious typosquats of legitimate npm packages have been discovered, posing significant risks to developers.

CISA Mandates Cloud Security for Federal Agencies by 2025 Under Binding Directive 25-01

CISA's BOD 25-01 mandates federal agencies to secure cloud environments and adopt secure configuration standards.

LockBit ransomware gang teases February 2025 return | Computer Weekly

LockBit ransomware gang is launching LockBit 4.0 despite recent law enforcement setbacks, aiming to rebuild its brand and attract new affiliates.

The Breachies 2024: The Worst, Weirdest, Most Impactful Data Breaches of the Year

Data breaches are rampant, and often result from companies failing to minimize the data they collect, leading to increased harm to victims.

North Korea-linked hackers accounted for 61% of all crypto stolen in 2024 | TechCrunch

North Korean hackers significantly contribute to the rise in cryptocurrency theft, reflecting an organized, state-sponsored cybercrime effort. They target crypto to evade sanctions.

3 holiday email scams to watch for - and how to stay safe

The holiday season increases email scams, prompting users to be vigilant and report suspicious activities to protect themselves.

Bugs in a major McDonald's India delivery system exposed sensitive customer data | TechCrunch

McDonald's India delivery system flaws exposed personal data and allowed unauthorized access to customer and driver information.
Vulnerabilities in their API were identified by a security researcher, leading to potential data risks.

Latest attempt to override UK's outdated hacking law stalls | Computer Weekly

The proposal to amend the Computer Misuse Act failed, highlighting the need for legal protections for cybersecurity professionals in the UK.

Rounding Up 2024's Biggest Tech Fails: What Went Wrong This Year?

The CrowdStrike outage was a significant technological failure in 2024, but it also demonstrated effective recovery and the importance of cybersecurity vigilance.

The Data Bill: It's time to cyber up | Computer Weekly

The Computer Misuse Act needs urgent updates to address modern cyber security challenges and allow legitimate research.

Two new bugs discovered in Windows 11 24H2 release

Microsoft's Windows 11 24H2 has new audio and Auto HDR bugs affecting users, prompting temporary update halts.

Report: Elon Musk failed to report movement required by security clearance

Elon Musk has failed to self-report crucial life details affecting his security clearance, raising transparency and compliance issues.
from ITPro
3 days ago

Machine identity attacks will be top of mind for security leaders in 2025

Machine identities like access tokens and service accounts are becoming primary targets for cyber attacks, markedly affecting cloud native security.

Meta Fined 251 Million for 2018 Data Breach Impacting 29 Million Accounts

Meta Platforms fined €251 million for a 2018 data breach affecting millions, exposing serious privacy violations.
[ Load more ]