Hackers demanded $10 million after executing a ransomware attack on a French hospital, disrupting operations and forcing the deferral of appointments and referral of patients to other facilities.
In the roughly five months that the Okta phishing campaign has been active, it has racked up 9,931 login credentials from about 130 organizations. 5,541 included MFA codes, and 3,120 included the victim's email account.
Alarms raised about embedded TikTok browser capable of tracking keystrokes. Company says that the ability exists within the code, but that it is not active and only used internally for debugging and testing purposes.
Recent security breach at password manager LastPass does not appear to be an immediate threat to the encrypted vaults that customers use to store their passwords, but the hackers may have made off with source code and proprietary information.
A class action lawsuit accuses Oracle of creating “global surveillance” profiles for five billion people worldwide, attaching things like purchase records and GPS locations to their name and contact information.
Security researchers discovered 9,000 unsecured internet-facing VNC servers that threat actors could use to access internal networks, including critical infrastructure organizations.
Cloud infrastructure provider Digital Ocean severed ties with the marketing automation provider Mailchimp after a security breach exposed its customer email addresses.
A shocking whistleblower report from Peiter ‘Mudge’ Zatko, a well-known cybersecurity expert who served as Twitter's head of security from mid-2020 to early 2022, asserts that the company is "grossly negligent" in "several areas" of information security and privacy protections.
Apps handling sensitive health data, including some that interface with labs and other entities covered by HIPAA privacy regulations, were found to be sharing health data with third party trackers that provide cues for targeted Facebook ads.
The BlackByte ransomware gang's "2.0" reboot of their data leak site sports a new "feature" for its victims: a tiered payment system that allows for smaller payments to delay publication of sensitive data, or to simply download and recover it prior to having it dumped for public viewing.








