CRA has lost about $190 million in payments made to scammers since 2020, with the highlight item being a $40 million tax refunds scam in which the perpetrator simply logged into an account and requested the astounding sum of money using false T4A income reporting slips.
Natural gas supplier Superior Plus suffered a ransomware attack that knocked its systems offline although customer safety and security and personal data were not affected.
The CircleCI security breach leaves most of its CI/CD platform clients with a pile of time-consuming cleanup of assorted keys, tokens and variables as they are forced to immediately rotate secrets.
Open-source software company Red Hat has confirmed a security breach on one of its GitLab instances after a threat actor claimed to have stolen nearly 570 GB of data from across various repositories.
Salesforce has confirmed another third-party breach affecting Gainsight applications integrated with customer instances, enabling attackers to exfiltrate customer data.
The National Cybersecurity Strategy Implementation Plan (NCSIP) establishes 65 high-impact initiatives that agencies will be required to meet within set timelines for each. A greater degree of public-private partnership is also being promoted.
Octo Tempest has gradually stepped up from data theft, to data extortion, and now to ransomware as of this summer (becoming an affiliate of the ALPHV/BlackCat group). The cybercriminals are entirely financially motivated and nearly always leads with either a phishing email/message or a social engineering call. It also looks to execute SIM swap attacks.
Krispy Kreme has disclosed that the December 2024 disruption to its online ordering systems resulted from a cyber attack later claimed by the Play ransomware group.
Apple argued that Corellium's use of its software constituted a copyright violation; a federal judge has disagreed, throwing the case out on the basis of the company's software being a tool for security researchers.
The opening of the Irish data center is part of the final stage of a EU privacy plan TikTok kicked off in mid-2021, seeking to address user data security concerns and the legal status of its international data transfers.










