Microsoft has experienced another security lapse after inadvertently exposing employee credentials for accessing internal databases and systems via an unsecured Azure cloud server, which was accessible over the public Internet without a password for nearly a month after discovery.
A blogpost from LastPass Labs warns of an attempted voice phishing attack on an employee that made use of an audio deepfake of company CEO Karim Toubba. The attacker peppered the LastPass employee with a series of calls, text messages, though the employee recognized it as a scam attempt and no damage was done.
RansomHub has claimed credit for the new cyber extortion attempt on Change Healthcare. The group says that it stole 4 TB of data that includes sensitive personal information, including financial information and medical records belonging to US military personnel.
The Department of State is investigating an alleged data breach exposing sensitive government data from the Pentagon, the Five Eyes intelligence alliance, and other US allies.
The Open Worldwide Application Security Project (OWASP) suffered a data breach stemming from a server misconfiguration that leaked members' personal information.
The CSRB found that the security breach was preventable, and that a "a corporate culture that deprioritized enterprise security investments and rigorous risk management" ended up leaving open doors for the Chinese hackers.
Online shopping platform Pandabuy confirms a data breach that impacted over 1.3 million customers after an apparent cover-up when data surfaced on BreachForums.
A new development in an old data breach has seen 73 million AT&T customer passcodes published to an underground forum. The data leak now appears to be as bad as originally advertised with customer contact information attached to weakly encrypted passcodes that are easily deciphered.
The settlement would impact all Incognito Mode data collected from June 1, 2016 to before the start of 2024. Google says that it would delete most of this browsing data, but in some cases would "de-identify" records instead.
The Inc Ransom cyber gang has published part of NHS Scotland's stolen data and threatened to release the entire trove of 3 terabytes online unless a ransom is paid.










