The National Railroad Passenger Corporation is notifying customers of a data breach affecting their Amtrak Guest Rewards accounts. Amtrak believes the threat actor gained access via a credential stuffing attack.
CDK Global, a SaaS provider for the auto industry, has suffered a second cyber attack while recovering from a previous cybersecurity incident, disrupting thousands of auto dealers.
In total, the cyber attack on Indonesia’s national data center impacted about 200 government agencies. Travel and immigration saw the most dramatic impacts, but also received priority attention and have largely been restored at this point.
A Microsoft whistleblower says that the Active Directory security flaw that led to the SolarWinds breach was ignored because, at the time, the company was preparing a major bid for the government's cloud computing business.
Leading forklift manufacturer Crown Equipment has confirmed that the prolonged disruption resulted from a cyber attack by an international cybercriminal organization.
TikTok continues to remain entangled in children's privacy issues, as an ongoing investigation by the FTC has now been referred to the DOJ for potential violation of the Children’s Online Privacy Protection Act (COPPA).
The ransomware group LockBit put itself in the international headlines once again last week when it boldly claimed to have stolen 33 TB of data from the US Federal Reserve. But the sample of stolen data turns out to have come from just one US bank.
A statement from TeamViewer indicated that the security breach was detected on June 26, and an employee account was apparently compromised as the APT group's source of access. There is not yet any mention of loss of data.
Evolve Bank and Trust has confirmed a LockBit data breach after the Russian ransomware group published the stolen records containing personal information on the dark web.
A statement of claim attached to mandatory court filings reveals that the ACMA will frame the Optus data breach as a case of negligence, asserting that the company failed to address an access control coding error that it had known about for some years.










