Coverage
Data Breaches
482 articles on breaches and ransomware
Advertisement
ServiceNow Data Exposure via Unauthenticated API Flaw
ServiceNow warns customers about a security incident after attackers exploited an unauthenticated API vulnerability to access and query customer instance data.
Check Point CVE-2024-24919: CISA Warns of Ransomware Exploitation
CISA mandates emergency patching for CVE-2024-24919 after Check Point VPN devices were targeted by ransomware gangs to gain initial network access.
CVE-2024-24919: Check Point VPN Zero-Day Exploited by Qilin Affiliate
Check Point Security Gateway vulnerability CVE-2024-24919 is being exploited in the wild, enabling unauthenticated information disclosure and network access.
Silent Ransom Group Targets US Law Firms via Vishing and Intrusions
Silent Ransom Group (Luna Moth) targets US law firms using vishing and physical intrusions for data extortion. Technical analysis and mitigation strategies.
SoFi Hong Kong Data Breach via Third-Party Vendor Compromise
Analysis of the SoFi Hong Kong data breach impacting customer information, stemming from a third-party vendor compromise. Includes mitigation strategies.
Oxford University Data Breach: CareerConnect Compromise Analysis
Oxford University warns of a data breach affecting CareerConnect, a platform managed by Group GTI. Personal data of students and alumni was compromised.
CVE-2024-24919: Qilin Ransomware Gang Exploits Check Point VPN Zero-Day
Check Point confirms that the Qilin ransomware group exploited CVE-2024-24919, a critical flaw in VPN gateways, to gain unauthorized network access.
Instagram Account Hijacking: Meta AI Support Exploited by Attackers
Attackers manipulated Meta's AI-powered support system to hijack over 20,000 Instagram accounts via unauthorized password resets. Learn how to secure accounts.
UNC3753: Vishing and Physical Intrusions Fuel U.S. Data Extortion
Mandiant identifies UNC3753 targeting U.S. legal and financial sectors through sophisticated vishing and physical breaches to execute data theft extortion.
Silent Ransom Group Callback Phishing Targets US Law Firms
Silent Ransom Group (Luna Moth) is using callback phishing and legitimate remote access tools to extort U.S. law firms without using file-encrypting ransomware.
UNC3753 Targets US Law Firms with Vishing & Physical Intrusions
UNC3753 (Luna Moth) leverages vishing and physical office intrusions to steal sensitive data from US law firms and professional services, leading to swift extortion.
ShinyHunters Leak 234 GB of DentaQuest Data Impacting 2.6 Million
The ShinyHunters extortion group leaked 234 GB of data from DentaQuest, impacting 2.6 million individuals. Learn about the risks and how to protect PHI.
Unpatched Comodo Antivirus Flaw and Anthropic AI Threat Mapping
Researchers reveal an unpatched privilege escalation flaw in Comodo Antivirus and a new taxonomy for AI-driven cyber threats by Anthropic and the UK AISI.
RCI Hospitality Data Breach: 40,000 SSNs Exposed in Intrusion
RCI Hospitality Holdings confirms a network intrusion impacting 40,000 individuals, involving stolen Social Security numbers and employee data files.
DentaQuest Data Breach: 2.6 Million Accounts Exposed via MOVEit
DentaQuest confirms a massive data breach impacting 2.6 million users following the exploitation of a critical MOVEit Transfer vulnerability.
WFP Palestine Breach: 600,000 Gaza Households' Data Exposed
The UN World Food Programme confirms a data breach in its Palestine registration portal, exposing sensitive data for 600,000 households in the Gaza Strip.
OFAC Sanctions Nobitex: Disrupting Ransomware & Terror Finance
The U.S. Treasury sanctions Nobitex, Iran's largest crypto exchange, for facilitating terrorist financing and ransomware payments.
AI-Built Ransomware Toolkit Automates EDR Evasion, AD Discovery
New AI-powered ransomware toolkit automates Active Directory discovery and EDR evasion, posing advanced threats. Learn its capabilities and mitigation strategies.
23andMe 2023 Data Breach: AG Sues Over Exposed Health Data
California AG sues 23andMe for a 2023 credential stuffing data breach exposing genetic and personal health data of 6.9 million users.
Charter Communications Data Breach: Millions of Records Exposed
ShinyHunters leaked data allegedly from Charter Communications, potentially exposing nearly 5 million customer records. Organizations must assess third-party risk.
Trump Mobile Data Breach and 2026 FIFA World Cup Phishing Risks
Analysis of the Trump Mobile data breach, upcoming 2026 FIFA World Cup phishing campaigns, and CISA's strategic response to recent supply chain attacks.
The Com: Analyzing the Intersection of Cybercrime and Physical Violence
Analysis of The Com, a criminal ecosystem using social engineering and SIM swapping to fund violent activities, sextortion, and neo-Nazi accelerationism.
California Sues 23andMe for Failing to Protect User Genetic Data
California Attorney General files lawsuit against 23andMe (Chrome Holding Co.) for security failures leading to the massive 2023 credential stuffing breach.
Executive Sentenced for Selling PII of 7 Million Elderly Americans
Former Epsilon executive Robert Reger sentenced to 10 years for selling consumer data of 7 million people to scammers for fraudulent sweepstakes schemes.