Two zero-day vulnerabilities in Ivanti products that were disclosed in January (and patched weeks later) have turned out to be the source of a breach of MITRE, the US government-funded cybersecurity research center. China's nation-state hackers are suspected to be behind the attack given similarities in exploiting these same vulnerabilities in other incidents, but this is not confirmed as of yet.
Global chipmaker Nexperia confirmed a significant data breach after hackers accessed some of its systems and potentially stole sensitive information, including the company’s intellectual property.
The LabHost phishing service had been active since 2021 and was responsible for the theft of at least 480,000 credit and debit card numbers with 64,000 pin numbers. According to the London Metropolitan Police, university students were among the 37 suspects recently rounded up in a law enforcement operation that took down the LabHost phishing service.
A “large-scale cyber attack” has taken down local government services in several French municipalities since the night of Tuesday, April 9. Local media reported that municipal workers who reported to work on Wednesday were instructed not to switch on their computers or use other devices.
Leading cybersecurity firm Mandiant believes that a notorious group of Russian hackers is behind a recent rash of attacks on water utilities in several countries, including the United States. On January 18 the group was able to induce a tank overflow at a Texas water treatment plant, and has made similar incursions in France and Poland.
After weathering two waves of credential stuffing attacks thus far in 2024, the second of which involved over half a million compromised accounts, Roku is now requiring that customers set up a 2FA method.
Home improvement retail chain Home Depot suffered a third-party data breach when a trusted vendor leaked a sample of 10,000 employee records during software testing.
As with many of these recent attempts at a comprehensive federal privacy law, the bill has bipartisan support. But its fate is just as uncertain as any of its predecessors during a Congressional period in which data privacy has been kept in the backseat.
Cisco Duo customers may have had VoIP and SMS MFA logs exposed to an attacker in early April. Third party breach is the result of one of the provider's employees being phished. The attackers then seemed to target the MFA logs of specific clients of interest.
A password compromise affecting business intelligence and analytics firm Sisense has triggered a CISA alert urging customers to reset their account login credentials and secrets.










