The U.K.’s Information Commissioner’s Office has fined a South Staffordshire water supplier $1.3 million, following a multi-year data breach that affected more than 630,000 people.
A security breach at numerous Polish water treatment plants enabled state-sponsored threat actors to manipulate industrial control systems across five cities.
A critical vulnerability discovered by AI spans most of the history of NGINX, which was first made available in 2004. The web server is frequently used as a load balancer and cache for static content, and some recent estimates find that about 20 to 30% of the world's busiest websites make use of it.
A Canvas hack has leaked nearly 280 million records from faculty, staff, and students across 8,809 colleges, online learning platforms, and school districts.
A security flaw in “Claude in Chrome” enables any Chrome extension, including those without permissions, to execute privileged commands, steal data, and perform agentic actions.
A 23-year-old Taiwanese student halted four high-speed rail trains using software-defined radio equipment to trigger emergency braking by sending a high-priority signal.
Video hosting platform Vimeo has confirmed a data breach stemming from a third-party performance metrics platform, Anodot, affecting approximately 119,000 users and customers.
Though it is not yet a matter of official policy, inside sources indicate CISA is weighing a three-day deadline for fixing critical vulnerabilities in federal government systems that have been observed being exploited elsewhere.
A ransomware attack on a healthcare IT solutions provider has disrupted access to patients’ electronic health records (EHRs) across numerous Dutch hospitals.
Red Dead Redemption 2 and GTA 5 game maker Rockstar Games confirms a data breach stemming from a third-party cloud provider after hackers threatened to leak stolen information.










