The sensitive personal and financial information of 672,075 people was compromised during the August 2025 Marquis cyberattack, which was previously misattributed to a Russian ransomware gang.
Cyber Security
Cyber criminals, state-sponsored hackers and even the occasional disgruntled employee are constantly looking to gain unauthorized access for a variety of purposes: theft of money, cyber espionage, personal information for sale or for use in scams, and damage to critical infrastructure for just a few of the most common.
So how does an organization mitigate an entire world full of continual cyber attacks? Just as buildings have a number of necessary elements of physical security: access control, cameras, alarms and so on; there are similar key elements of cyber security that are absolutely vital for just about any modern business.
It starts with identifying and closing the most common doors that attackers use. For example, phishing attacks on employees are far and away the most common initial point of entry. The breach of even a low-level employee account can quickly turn into an escalation in access privileges and the ability to reach sensitive information. This is also true of smart devices, which are generally more poorly secured than computers and phones.
Security leaders often assume patching failures stem from technical limitations. In reality, many of the most disruptive patching delays originate from coordination breakdowns across teams, tools, and timelines.
A new vulnerability chain discovered by Oasis Security can compromise the Claude AI chatbot and does not require the target to have the app installed or even have an account with the service. The attack chain instead begins with a malicious webpage doctored up to place highly in search results for Claude, which passes the user to a pre-filled chat URL that exploits other vulnerabilities in the AI agent.
A data breach at the Washington-based benefits administrator Navia Benefit Solutions has exposed the sensitive personal information of nearly 2.7 million individuals.
New US National Security Directive: Foreign Internet Routers Require Special FCC Approval to be Sold
Consumer-grade internet routers have been added as a category to the FCC's Covered List, which establishes communications equipment and services deemed to be an unacceptable national security risk. Some individual manufacturers, such as Huawei and ZTE, have already been added to this list in years past.
Armed forces would prefer to keep the exact locations of their assets secret as they come within striking range of hostile forces. Just one soldier using a fitness app or tracking device can out this location if their fitness results are automatically posted to a public profile.
Fraudsters used Nordstrom’s official email system to promote a crypto scam promising to double funds sent to the scammers’ wallet addresses as a St. Patrick’s Day giveaway.
As to the apocalyptic "Q-Day" end to every security standard that keeps the internet and cryptographic secrets functioning, the timeline is still not clear. Sooner is obviously better than later in terms of encryption transition, but Google's announcement surprised many who have been working in the quantum computing field.
A group of hackers widely believed to be supported by Iran's government breached a personal email account belonging to FBI director Kash Patel, which contained material dating from 2010 to 2019. The hackers claimed this was in retaliation for recent FBI operations against them.
A security breach at the European Commission has enabled a threat actor to steal hundreds of gigabytes of data from its Amazon cloud infrastructure used to manage the Europa.eu web platform.










