UK water supplier, South Staffordshire PLC, suffered a Clop ransomware attack during one of the country’s worst droughts, with the gang mistakenly identifying another water utility as the victim.
The BlackByte ransomware gang's "2.0" reboot of their data leak site sports a new "feature" for its victims: a tiered payment system that allows for smaller payments to delay publication of sensitive data, or to simply download and recover it prior to having it dumped for public viewing.
Apps handling sensitive health data, including some that interface with labs and other entities covered by HIPAA privacy regulations, were found to be sharing health data with third party trackers that provide cues for targeted Facebook ads.
A shocking whistleblower report from Peiter ‘Mudge’ Zatko, a well-known cybersecurity expert who served as Twitter's head of security from mid-2020 to early 2022, asserts that the company is "grossly negligent" in "several areas" of information security and privacy protections.
Cloud infrastructure provider Digital Ocean severed ties with the marketing automation provider Mailchimp after a security breach exposed its customer email addresses.
Security researchers discovered 9,000 unsecured internet-facing VNC servers that threat actors could use to access internal networks, including critical infrastructure organizations.
A class action lawsuit accuses Oracle of creating “global surveillance” profiles for five billion people worldwide, attaching things like purchase records and GPS locations to their name and contact information.
Recent security breach at password manager LastPass does not appear to be an immediate threat to the encrypted vaults that customers use to store their passwords, but the hackers may have made off with source code and proprietary information.
Alarms raised about embedded TikTok browser capable of tracking keystrokes. Company says that the ability exists within the code, but that it is not active and only used internally for debugging and testing purposes.
In the roughly five months that the Okta phishing campaign has been active, it has racked up 9,931 login credentials from about 130 organizations. 5,541 included MFA codes, and 3,120 included the victim's email account.








