Coverage
Data Breaches
482 articles on breaches and ransomware
Advertisement
Windows BlueHammer Flaw Exploited by Ransomware Gangs — Patch Now
CISA warns that ransomware gangs are now exploiting the BlueHammer privilege escalation vulnerability in Microsoft Defender to bypass security controls.
ShinyHunters Breach NAIC via PeopleSoft Zero-Day: Public Data Stolen
ShinyHunters exploited an Oracle PeopleSoft zero-day to breach NAIC, exfiltrating public data, logs, and configuration files. Review PeopleSoft security.
Nissan Breach: Oracle PeopleSoft Zero-Day Exploited by ShinyHunters
Nissan discloses a data breach impacting current and former employees, attributed to an exploited Oracle PeopleSoft zero-day vulnerability linked to the ShinyHunters…
KDDI Data Breach Exposes 14.2 Million Email Logins Across Six ISPs
KDDI Corporation reports a massive data breach affecting 14.2 million email accounts across six Japanese ISPs following unauthorized shared system access.
Education Sector Third-Party Risk: Protecting Student Data
The education sector confronts growing third-party breach threats, endangering student data.
Klue-Salesforce Breach Exposes Competitive Data; Threat Actors Hacked
Klue's Salesforce instance breach exposed customer competitive intelligence and contact data via an API vulnerability.
Millions of Passports Leaked via Low-Value Identity Verification Breach
A database of nearly a million passports globally was leaked online, originating from a breach in a low-value ID verification system, exposing high-value credentials.
Mexico's 2025–2030 Cybersecurity Plan: Addressing Evolving Threats
Analysis of Mexico's 2025–2030 National Cybersecurity Plan, evaluating its strategy against ransomware, organized crime, and AI-driven threats.
Europe's Ransomware Surge: Mitigating Risks for EU Organizations and Suppliers
European organizations and their suppliers are now primary targets for ransomware gangs. Understand the escalating threat and implement critical defenses.
Tata Electronics Confirms Cyberattack and Data Leak
Tata Electronics confirms a cyberattack impacting its IT infrastructure, leading to data leakage. Analysis of the breach and defense strategies.
Proactive Exploit Validation: Mitigating Rapidly Weaponized Vulnerabilities
Security teams face rapidly weaponized vulnerabilities. Learn how to proactively validate exploitability and fortify defenses against emerging threats, even before…
CVE-2024-40766: SonicWall SonicOS Patch and Configuration Guide
Analysis of CVE-2024-40766, a critical improper access control flaw in SonicWall SonicOS exploited by ransomware groups. Learn how to secure management interfaces.
Xsolis Data Breach: 1.4 Million Records Compromised
Healthcare AI provider Xsolis reports a major data breach affecting 1.4 million individuals, exposing Social Security numbers and protected health information.
Squidbleed: Heartbleed-Style Data Exposure in Squid Proxy
A critical flaw dubbed Squidbleed in Squid Proxy, affecting versions 3.5-6.x, enables Heartbleed-style memory leakage exposing user credentials and session data.
Squidbleed: 29-Year-Old Squid Proxy Bug Leaks Cleartext HTTP Requests
A 29-year-old heap over-read vulnerability, dubbed 'Squidbleed,' in Squid web proxy's default configuration can leak cleartext HTTP requests and credentials.
TPWD Data Breach: Third-Party Vendor Compromise Impacts 3 Million
A significant data breach at a Texas Parks and Wildlife Department vendor exposed PII of 3 million individuals. Learn about the supply chain risks involved.
Prinz Eugen Ransomware Prioritizes Recent Files to Maximize Impact
Prinz Eugen ransomware targets files modified within 30 days to disrupt active operations, using a Go-based encrypter and unconventional ransom demands.
Klue OAuth Breach: Icarus Threat Group Targets Salesforce
Klue confirms an OAuth token breach by the Icarus group, potentially exposing customer Salesforce environments. Learn how to secure your integrations.
GentleKiller EDR Framework: The Gentlemen RaaS Defense Evasion Tactics
The Gentlemen RaaS leverages the GentleKiller framework to terminate 400+ security processes. Learn how this tool impairs EDR and antivirus defenses.
Texas Data Breach Exposes 3M Driver's Licenses via Vendor
A data breach at a third-party vendor of the Texas Parks and Wildlife Department exposed over 3 million driver's licenses, impacting Texans' PII.
Klue Security Incident: Mitigating Third-Party Risk in Intelligence
Analyze the impact of the Klue security incident on Recorded Future. Learn how to secure SaaS integrations and improve third-party vendor risk management.
FortiBleed Data Leak: Securing Fortinet VPNs Against Exposure
CISA warns organizations after 74,000 Fortinet VPN credentials were leaked online. Learn how to mitigate the FortiBleed threat and secure your network.
Nintendo Confirms Third-Party TinyPulse Data Breach — Supply Chain Risks
Nintendo confirms employee survey data was stolen via a breach at TinyPulse, a third-party vendor owned by WebMD subsidiary Internet Brands.
Gentlemen Ransomware: EDR Evasion Tactics and Mitigation Strategies
Runtime Rebel details Gentlemen ransomware's advanced EDR killer suite, analyzing its impact and providing actionable strategies to defend against sophisticated evasion.