Security firm disclosed a Microsoft data breach that exposed customer data affecting over 65,000 organizations in 111 countries. Microsoft expressed disappointment at the security firm for exaggerated numbers and releasing a search tool.
The cyber attack stemmed from a phishing email and impacted some 113,000 people. The government supplier was also faulted for not following up on an antivirus alert as well as having outdated systems and inadequate staff training in place.
Snake oil marketing tactics by cybersecurity vendors complicate organizations’ security stack and expand the attack surface, according to Egress cybersecurity hype report. 91% of decision-makers found it difficult to select cybersecurity vendors due to unclear marketing about their specific offerings.
Privacy act draft proposes a maximum penalty of the greater of $50 million, three times the value of any benefit obtained through the misuse of information stolen in data breaches, or 30% of the company's annual domestic turnover.
Verizon prepaid customers suffered a SIM swap attack after hackers breached their accounts using the last four digits of their credit card numbers likely obtained via stolen employee accounts.
The investigation into the August Twilio hack was recently concluded, and the company has found that the same attacker was responsible for a vishing attack that led to a smaller breach in June.
Australian Clinical Labs reportedly detected the attack not long after it occurred and was contacted by government authorities in March, and were also notified in June that some of the patient data had been found available for sale on the dark web.
Thomson Reuters database leak exposed 3TB of platform information and customer data after the media company left three databases unsecured and publicly accessible for days.
According to an internal investigation that concluded in September of this year, the credit card theft window may have been open for just over 30 months. See Tickets has sold as many as 20 million tickets per year.
Iran's SIAM system has base-level access to the country's cellular networks and used not just for government surveillance, but also has functions that allow for remote manipulation of individual data collections and backdoors through encryption.










