The FBI warns that cybercriminals are targeting plastic surgery offices and stealing sensitive information, including medical records, in a multi-stage cyber extortion campaign.
Okta Support System Compromised by Cookie Hijacking, Security Breach May Have Exposed Customer Files
Attackers were able to steal a session cookie from the Okta support system and access an administrator account, possibly providing them with further access to customer environments in an early October security breach.
Taiwanese networking giant D-Link has confirmed a data breach after an employee fell victim to a phishing attack. The company said the stolen information originated from a product registration system that reached its end of life in 2015.
Annual Cisco Consumer Privacy Survey, a study including the opinions of over 2,600 respondents of varying demographics in 12 countries, indicates that consumer awareness of data privacy rights is continuing to grow and that AI has some work to do to earn public trust.
A UK GDPR fine that would have cost Clearview AI £7.5 million fine has been overturned, as an appeals court found that lead regulator ICO was outside of its jurisdiction in penalizing the foreign facial recognition firm.
Joint international law enforcement effort involving about a dozen countries has taken down Ragnar Locker ransomware gang's dark web site, with an announcement that at least one arrest had been made.
Google is making passkeys the default sign-in option across its services for all users. User feedback found that at least 64% of users said passkeys were easier to use than passwords or two-factor authentication.
BianLian ransomware group disputed Air Canada's claim that data breach impacted only limited personal information of some employees and certain records. Ransomware group claims to have stolen 210 GB of technical and operational data spanning from 2008 to 2023.
Flagstar Bank suffered a MOVEit data breach via a third-party payment processor and mobile banking services provider, impacting over 800,000 customers in the US.
Cloudflare reports attackers using the HTTP/2 protocol zero-day vulnerability to conduct over 1,100 DDoS attacks at over 10 million requests per second since August, and 184 broke the previous record of 71 million requests. At its peak, 200 million requests per second was observed.










