Data broker LexisNexis has disclosed a significant data breach that exposed the personal information of over 346,000 people after a threat actor compromised its GitHub account.
Philippines-based Funnull Technology, along with one of its administrators, has been hit with OFAC sanctions for its role as a knowing infrastructure provider for hundreds of thousands of malicious sites engaging in cyber scams.
Researchers found a security flaw in OneDrive File Picker that grants apps access to any and all files in the account when the user grants permission for just one file upload, with the language governing this process cited as too "vague" and "unclear" to communicate what is actually happening.
German sportswear giant Adidas has confirmed that a third-party breach compromised customer data amid ongoing cybersecurity incidents rocking the company in other countries.
Popular domain registrar and web hosting company GoDaddy was slapped with an FTC order mandating a robust information security program for allegedly failing to stop data breaches and misleading customers about its cybersecurity practices.
A system outage stemming from an apparent ransomware attack disrupted clinical operations at Kettering Health, forcing the healthcare network to cancel and reschedule elective operations.
The new guidance actually focuses on three main areas of AI data security: data drift and potentially poisoned data, and also risks in the data supply chain. The guidance builds upon the NSA’s existing Deploying AI Systems Securely publication, but adds much more detail specific to addressing potential vulnerabilities.
A significant data breach at Legal Aid Agency exposed over 2 million records, including criminal records and financial information of people who applied for legal assistance since 2010.
A major threat actor has been crippled by an international law enforcement action, as the Lumma infostealer malware operation saw its control panel seized along with infrastructure dwelling in Europe and Japan. This was supplemented by Microsoft seizing some 2,300 domains belonging to the group, which has infected over 394,000 Windows computers globally.
Victims that interacted with the fake KeePass ads would get a maliciously modified version of the password manager called "KeeLoader" designed to exfiltrate passwords and provide a backdoor for further malware delivery and ransomware attacks.










