Tag: breach
-
FTC rescinds policy statement requiring health apps to notify customers after a breach
The policy, passed under the Biden administration, forced health apps to disclose when users’ personal health records were exposed in a breach or shared without authorization. First seen on cyberscoop.com Jump to article: cyberscoop.com/ftc-rescinds-health-app-data-breach-policy/
-
FTC rescinds policy statement requiring health apps to notify customers after a breach
The policy, passed under the Biden administration, forced health apps to disclose when users’ personal health records were exposed in a breach or shared without authorization. First seen on cyberscoop.com Jump to article: cyberscoop.com/ftc-rescinds-health-app-data-breach-policy/
-
Florida confirms DMV database breached via stolen police account
The Florida Department of Highway Safety and Motor Vehicles (FLHSMV) has confirmed that its DAVID driver database suffered a data breach, saying the attackers gained access using credentials belonging to a police department employee. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/florida-confirms-dmv-database-breached-via-stolen-police-account/
-
Florida confirms DMV database breached via stolen police account
The Florida Department of Highway Safety and Motor Vehicles (FLHSMV) has confirmed that its DAVID driver database suffered a data breach, saying the attackers gained access using credentials belonging to a police department employee. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/florida-confirms-dmv-database-breached-via-stolen-police-account/
-
CISA Calls for More Guidance, Less Spin, as Cyber Outages Escalate
A new joint government advisory signals a regulatory shift, pressing organizations to adopt more transparent breach notification and incident response protocols. First seen on darkreading.com Jump to article: www.darkreading.com/cyber-risk/cisa-calls-for-more-guidance-less-spin-as-cyber-outages-escalate
-
CISA Calls for More Guidance, Less Spin, as Cyber Outages Escalate
A new joint government advisory signals a regulatory shift, pressing organizations to adopt more transparent breach notification and incident response protocols. First seen on darkreading.com Jump to article: www.darkreading.com/cyber-risk/cisa-calls-for-more-guidance-less-spin-as-cyber-outages-escalate
-
Breach of Confidence, 11 September 2026
I’ve discovered that the best way to avoid working is to write a newsletter about work. It’s meta-procrastination. My therapist would be proud if I could afford one after this week’s Claude bill. Grizzly Bears Understand Infrastructure Better Than Most… First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/breach-of-confidence-11-september-2026/
-
Rhysida Publishes 1.4 Million Berlin Government Files After Ransom Refusal
Rhysida published nearly 1.4 million files stolen from Berlin after a Euro2 million ransom demand failed, exposing personal and sensitive government data. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/threats/news-berlin-cyberattack-rhysida-dark-web-emea/
-
Novo Nordisk Data Breach Tied to Stolen GitHub Access Tokens
Tags: access, breach, cloud, credentials, cyber, data, data-breach, defense, exploit, extortion, github, group, infrastructureCyber Extortion Group Continues to Target Exposed Cloud-Based Data Over Endpoints. Cyber extortion group FulcrumSec continues to find hardcoded credentials in public-facing IT infrastructure and exploit them as part of what it’s dubbed a Hardcoded Horrorshow that counts Ozempic maker Novo Nordisk among its victims. Here are defenses organizations need to put in place now.…
-
McKesson Data Leak Includes 6.4M Email Addresses After $55.2M Extortion Demand
McKesson breach data includes 6.4 million unique email addresses after ShinyHunters allegedly demanded $55.2 million to keep the records private. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/news/news-mckesson-breach-6-4-million-shinyhunters/
-
Scammers target hundreds of thousands of crypto owners after Trezor confirms data breach of email provider
This is the second data breach affecting a company that hardware crypto wallet maker Trezor relies on. First seen on techcrunch.com Jump to article: techcrunch.com/2026/09/11/scammers-target-hundreds-of-thousands-of-crypto-owners-after-trezor-confirms-data-breach-of-email-provider/
-
The Cyber Express Weekly Roundup: Iranian Bounty, Airline Data Leak, and AI-Model Prompt Injection
This weekly roundup covers a bounty offer targeting an alleged Iranian cyber official, a massive data-exposure incident affecting airline travelers, a breach of an education platform used by students, a flaw exposing ChatGPT users’ Gmail data, and a new EU compliance deadline for connected-product manufacturers. First seen on thecyberexpress.com Jump to article: thecyberexpress.com/weekly-roundup-iran-bounty-airline-leak/
-
AI agents exploited PaperCut flaws to breach 395 organizations
A threat actor built a working exploit for PaperCut print management software, then handed the job of breaking into hundreds of organizations to AI agents that did most of the … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/09/11/ai-agents-papercut-ng-mf-attack-campaign/
-
IDScan confirms breach after 153 million driver’s licenses leak on dark web
Days after reports linked IDScan to a dark web database holding more than 153 million driver’s license scans, the identity verification company has confirmed hackers … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/09/11/idscan-net-data-breach-153-million-drivers-licenses/
-
Trezor: 347,000 users targeted in phishing attacks after Brevo breach
Trezor has revealed that phishing attacks against its customers earlier this week targeted 347,000 email addresses and affected 2,500 users who clicked an embedded malicious link. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/trezor-347-000-users-targeted-in-phishing-attacks-after-brevo-breach/
-
Breach Roundup: ShinyHunters Claims Florida DMV Hack
Also, N-Able Patches Critical N-Central Zero-Day, Nightmare Eclipse Zero-Day. This week: ShinyHunters claims Florida DMV breach, N-able patch, Bimbo Bakeries breach, French police arrest suspected ZeroBytes hackers, Patch Tuesday, a new Nightmare Eclipse zero-day, Grindr agrees to $35 million U.K. privacy settlement, SAP patch. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/breach-roundup-shinyhunters-claims-florida-dmv-hack-a-32792
-
Quantum’s Bigger Threat: Forged Identities, Not Data Theft
Applied Quantum’s Marin Ivezic on Why Forged Signatures Beat Stolen Data as a Risk. Data theft dominates quantum risk planning, but a quieter threat could prove even worse. Marin Ivezic, CEO at Applied Quantum, says quantum computers used to forge digital signatures at some point in the future could undermine trust across IT and OT…
-
Hawley probes OpenAI over Hugging Face breach
The Republican lawmaker called OpenAI’s leadership decisions “reckless,” and used recent warnings about the existential risk of AI to bolster his inquiry. First seen on cyberscoop.com Jump to article: cyberscoop.com/openai-hugging-face-probe-senate-hawley/
-
AI lets small actors run state-level hacking campaigns, Anthropic report finds
The report details a Russian-aligned espionage campaign against more than 20 organizations, an exploit foundry run by Chinese undergraduates and ShinyHunters-affiliated breaches, among other disrupted operations. First seen on cyberscoop.com Jump to article: cyberscoop.com/anthropic-report-ai-enabled-cyber-attacks/
-
IDScan confirms breach after hackers offer 153 million driver’s license scans for sale
A notice dated September 4 but not widely shared shows that IDScan acknowledged a data breach but did not specify how many people were affected. First seen on therecord.media Jump to article: therecord.media/idscan-data-breach-notice-drivers-licenses
-
Multiple crypto companies warn customers of phishing emails after alleged provider breach
Subscribers to newsletters from Trezor, CoinTracking and BitBox received corrupted messages through an email provider that all three companies use. First seen on therecord.media Jump to article: therecord.media/trezor-bitbox-cointracking-phishing-crypto-holders
-
Cryptohack Roundup: Trezor’s Phishing Warning
Also: ‘White-Hat’ Hackers Withdraw $320M From Liquid. Every week, ISMG rounds up cybersecurity incidents in digital assets. This week, Trezor warns customers after email provider breach, Liquid pauses network after $320 million Bitcoin withdrawal, man pleads guilty in $245 million theft and India targets 15 crypto platforms over compliance failures. First seen on govinfosecurity.com Jump…
-
IDScan confirms breach tied to 153 million stolen driver’s licenses
Identity verification company IDScan has confirmed that hackers accessed customer data stored in its cloud platform, days after reports linked the company to a massive database containing more than 153 million driver’s license scans. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/idscan-confirms-breach-tied-to-153-million-stolen-drivers-licenses/
-
ID verification giant IDScan confirms data breach with more than 150 million driver’s licenses stolen
The ID checking company said the data breach included people’s full names and driver’s licenses and other government-issued identity documents. First seen on techcrunch.com Jump to article: techcrunch.com/2026/09/10/id-verification-giant-idscan-confirms-data-breach-with-more-than-150-million-drivers-licenses-stolen/
-
How to build a continuous pentesting program
IntroductionAn unpatched flaw is now the most common entry point for a breach, at 31%, ahead of stolen credentials at 13%, and the median time to fix one has crept up to 43 days (Verizon’s 2026 DBIR). So an annual… First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/how-to-build-a-continuous-pentesting-program/
-
Trezor warns users of email provider breach, phishing attacks
Trezor warned customers on Wednesday that threat actors who breached its third-party email provider are targeting them in phishing attacks. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/trezor-warns-users-of-email-provider-breach-phishing-attacks/
-
New AI Workflow Identity Hijacking Attack Lets Hackers Exfiltrate Sensitive Data
Security researchers have recently disclosed a new enterprise AI attack technique known as Workflow Identity Hijacking. This method enables external attackers to exfiltrate sensitive corporate information by submitting seemingly harmless requests to AI-powered automations. Research published by Noma Labs researcher Sasi Levi reveals that this attack does not rely on prompt injection, stolen credentials, or…
-
FTC rescinds policy requiring health apps to notify customers after a breach
The policy, passed under the Biden administration, forced health apps to disclose when users’ personal health records were exposed in a breach or shared without authorization. First seen on cyberscoop.com Jump to article: cyberscoop.com/ftc-rescinds-health-app-data-breach-policy/
-
Electronic health record company says customer data stolen in breach
Veradigm said access was limited to a specific interface, and did not impact the company’s broader environment such as its networks, servers or databases. The incident did not result in operational disruptions, the company added. First seen on therecord.media Jump to article: therecord.media/electronic-health-record-company-says-customer-data-stolen-in-breach

