ThreatsDay
A fake login page. A fake security scan. A fake productivity app. Apparently, pretending to be useful is still one of the easier ways into a machine. The rest of the week gets stranger: botnets borrowing AI, command tra
Hospitals, clinics, insurers, and medical-IT vendors are the highest-value targets in cybercrime. Below is every healthcare-sector breach LeakTrace has indexed — patient records, HIPAA disclosures, ransomware victims, and supply-chain compromises.
A fake login page. A fake security scan. A fake productivity app. Apparently, pretending to be useful is still one of the easier ways into a machine. The rest of the week gets stranger: botnets borrowing AI, command tra
The ShinyHunters extortion group has published sensitive data from nearly 13 million accounts stolen from clothing retailer giant Carhartt earlier this month, according to data breach notification service Have I Been Pwn
Red Hat Automatic Bug Reporting Tool Privilege Escalation Vulnerability — Red Hat Automatic Bug Reporting Tool (ABRT) contains a privilege escalation vulnerability that could allow local users with certain permissions to
Citrix NetScaler ADC and NetScaler Gateway Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability — Citrix NetScaler ADC and NetScaler Gateway contain an improper restriction of operations
Microsoft SQL Server Remote Code Execution Vulnerability — Microsoft SQL Server contains a remote code execution vulnerability that could allow an attacker to execute code in the context of the SQL Server Database Engine
Nutex Health has informed the SEC that it recently detected unauthorized access and data exfiltration. The post Sensitive Information Exposed in Nutex Health Data Breach appeared first on SecurityWeek.
Here’s one we missed last week. Hannah Spray reports: The personal information of more than 2,000 people was stolen from Autism Services of Saskatoon during a data breach last year. In the aftermath, the organizati
Ajax.NET Professional Deserialization of Untrusted Data Vulnerability — Ajax.NET Professional (AjaxPro) contains a deserialization of untrusted data vulnerability that could allow for remote code execution via arbitrary
Microsoft is warning that the window for patching vulnerabilities is rapidly shrinking, as attackers move from disclosure to exploitation faster than enterprises can safely deploy fixes, and is urging organizations to ad
Red Hat Libuser Race Condition Vulnerability — Red Hat libuser contains a race condition vulnerability that allows authenticated local users to corrupt the /etc/passwd file to cause a denial of service or privilege escal
Linux Kernel Out-of-Bounds Write Vulnerability — Linux Kernel contains an out-of-bounds memory write vulnerability which could allow a local user to gain privileged access or cause a denial of service on the system.
Medical technology company Boston Scientific has been targeted in a cyberattack that disrupted some of its IT systems, causing operational disruptions globally. [...]
The medical device-maker says it cannot yet determine any financial impact from the attack it suffered this week.
The company released a statement and filed documents with the Securities and Exchange Commission (SEC) saying a cybersecurity incident was discovered on Tuesday.
The agency has released guidance on reducing internet exposure in the wake of the recent Iran-linked hacker attacks. The post CISA: Over 100 Internet-Exposed Water Systems Targeted in July Cyberattacks appeared first on
WeedHack Minecraft Malware Survives C2 Takedown: Fake Client Sites Still Active, SEO Poisoning Puts Malicious Downloads at the Top of Google McAfee Labs published a follow-up report on the WeedHack Malware-as-a-Service c
Gitea Code Injection Vulnerability — Gitea contains a code injection vulnerability that allows an attacker with repository write access to send a malicious patch to the diffpatch API endpoint to plant an executable Git h
Healthcare and services provider Nutex is investigating a data breach incident where an unauthorized third party exfiltrated information from company servers. [...]
Vaughn Stupart, Matthew W. Van Hise, and Craig A. Hoffman of BakerHostetler write: One ruling is not a trend. And there can be unique factors at play in regulatory investigations related to large incidents. But a summary
The Los Angeles County Museum of Art (LACMA) has announced that a breach last year exposed customer and employee information. [...]
12,933,413 records exposed — Email addresses, Names, Phone numbers, Physical addresses
As breach costs reach record highs and defense spending nears $240 billion, small businesses are dangerously exposed, threatening supply chain security.
A Chinese-speaking cybercrime group is using AI-driven tools to help compromise internet-facing Windows and Linux web servers, according to Cisco Talos, Cisco’s threat intelligence research unit. Talos said the activity
Yesterday, DataBreaches reported that ShinyHunters had added ReliaQuest to its dedicated leak site, but without any substantive proof — only a few screenshots showing access to a user account on reliaquest.okta[.]com/end