Leading cybersecurity firm Mandiant believes that a notorious group of Russian hackers is behind a recent rash of attacks on water utilities in several countries, including the United States. On January 18 the group was able to induce a tank overflow at a Texas water treatment plant, and has made similar incursions in France and Poland.
After weathering two waves of credential stuffing attacks thus far in 2024, the second of which involved over half a million compromised accounts, Roku is now requiring that customers set up a 2FA method.
Home improvement retail chain Home Depot suffered a third-party data breach when a trusted vendor leaked a sample of 10,000 employee records during software testing.
As with many of these recent attempts at a comprehensive federal privacy law, the bill has bipartisan support. But its fate is just as uncertain as any of its predecessors during a Congressional period in which data privacy has been kept in the backseat.
Cisco Duo customers may have had VoIP and SMS MFA logs exposed to an attacker in early April. Third party breach is the result of one of the provider's employees being phished. The attackers then seemed to target the MFA logs of specific clients of interest.
A password compromise affecting business intelligence and analytics firm Sisense has triggered a CISA alert urging customers to reset their account login credentials and secrets.
Microsoft has experienced another security lapse after inadvertently exposing employee credentials for accessing internal databases and systems via an unsecured Azure cloud server, which was accessible over the public Internet without a password for nearly a month after discovery.
A blogpost from LastPass Labs warns of an attempted voice phishing attack on an employee that made use of an audio deepfake of company CEO Karim Toubba. The attacker peppered the LastPass employee with a series of calls, text messages, though the employee recognized it as a scam attempt and no damage was done.
RansomHub has claimed credit for the new cyber extortion attempt on Change Healthcare. The group says that it stole 4 TB of data that includes sensitive personal information, including financial information and medical records belonging to US military personnel.
The Department of State is investigating an alleged data breach exposing sensitive government data from the Pentagon, the Five Eyes intelligence alliance, and other US allies.










