The Open Worldwide Application Security Project (OWASP) suffered a data breach stemming from a server misconfiguration that leaked members' personal information.
DHS is now requesting that the U.S. Congress grant it extraordinary administrative subpoena powers so that it can request ISPs to turn over the contact information for the owners of industrial control systems.
AMD said it was investigating a data breach by the RansomHouse cyber extortion group claiming to have stolen 450 GB of data by exploiting weak passwords used by the chipmaker's employees.
Accenture said the LockBit ransomware attack that reportedly encrypted at least 2,500 computers and leaked 6 terabytes of data had no impact on its operations.
Clorox reported a total of $49 million in incremental expenses related to the attack, with Johnson Controls reporting data breach costs of nearly $27 million. This money went to remediation costs such as third party contracting, as well as added operating costs due to disruptions.
Harvard University and Envoy, an American Airlines subsidiary, have confirmed data breaches linked to a zero-day vulnerability CVE-2025-61882 in Oracle’s E-Business Suite software.
North Korean hackers are focusing heavily on Magecart attacks by planting malicious code in online shopping carts of individual stores and payment processors.
New proposed bill on anti-encryption law requires a backdoor to be placed in nearly every electronic device that has at least 1 GB of memory and all encrypted services.
Final adoption of the EU AI law is expected to be a formality at this point, but is not slated to take place until April 2024. From there, individual components of the regulation go into effect anywhere from 6 to 36 months from that date.
The sensitive personal and financial information of 672,075 people was compromised during the August 2025 Marquis cyberattack, which was previously misattributed to a Russian ransomware gang.










