Tag: breach
-
What security teams miss in email attacks
Email remains the most common entry point for attackers. This article examines how phishing, impersonation, and account takeover continue to drive email breaches and expose … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/01/06/rising-email-breach-risks/
-
Cloud file-sharing sites targeted for corporate data theft attacks
A threat actor known as Zestix has been offering to corporate data stolen from dozens of companies likely after breaching their ShareFile, Nextcloud, and OwnCloud instances. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/cloud-file-sharing-sites-targeted-for-corporate-data-theft-attacks/
-
Covenant Health Notifying 480K Patients of 2025 Data Theft
Ransomware Gang Qilin Had Claimed It Stole 852 GB of Health System’s Data. Nearly half a million patients of a Catholic healthcare network that serves New England and parts of Pennsylvania began the new year by receiving notifications that hackers may have stolen their health information in a May 2025 hacking incident. First seen on…
-
Why cybersecurity needs to focus more on investigation and less on just detection and response
Tags: access, attack, breach, cyber, cyberattack, cybersecurity, data, defense, detection, exploit, network, resilience, risk, threat, tool, vulnerabilityInvestigation: Where the real insights lie: This is where investigation comes in. Think of investigation as the part where you understand the full story. It’s like detective work: not just looking at the footprints, but figuring out where they came from, who’s leaving them, and why they’re trying to break in in the first place.…
-
US broadband provider Brightspeed investigates breach claims
Brightspeed, one of the largest fiber broadband companies in the United States, is investigating security breach and data theft claims made by the Crimson Collective extortion gang. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/us-broadband-provider-brightspeed-investigates-breach-claims/
-
NordVPN Says Breach Claims Involve Dummy Test Data
NordVPN says breach claims involved only dummy data from an isolated test environment. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/threats/nordvpn-says-breach-claims-involve-dummy-test-data/
-
Ten thousand firewalls are vulnerable to old vulnerability
This news brief originally appeared on ComputerSweden.More Fortinet security news:FortiGate firewall credentials being stolen after vulnerabilities discoveredFortinet criticized for ‘silent’ patching after disclosing second zero-day vulnerability in same equipmentFortinet admins urged to update software to close FortiCloud SSO holes First seen on csoonline.com Jump to article: www.csoonline.com/article/4112857/ten-thousand-firewalls-are-vulnerable-to-old-vulnerability.html
-
Breached E-Commerce Giant Details $1B ‘Customer Trust’ Plan
Critics of South Korea’s Coupang Dismiss Offer as Marketing More Than Compensation. After suffering a data breach that exposed personal data for two-thirds of South Korea’ population, online retailer Coupang promised to distribute $1.2 billion in vouchers to restore customer trust. But critics have accused the move of being more about marketing than true compensation.…
-
NordVPN Denies Breach After Hacker Claims Access to Salesforce Dev Data
A hacker using the alias 1011 has claimed to breach a NordVPN development server, posting what appears to… First seen on hackread.com Jump to article: hackread.com/nordvpn-denies-breach-hacker-salesforce-dev-data/
-
Aflac Notifies 22.7 Million People of June Data Theft Attack
Insurer’s Hack Could Rank as Largest US Health Data Breach Reported in 2025. Supplemental health insurer Aflac is notifying 22.65 million people whose sensitive health and personal information, including Social Security numbers, was potentially compromised in a June data theft incident. The incident will likely rank as the biggest U.S. health data breach reported in…
-
Ledger customers impacted by third-party Global-e data breach
Ledger is informing some customers that their personal data has been exposed after hackers breached the systems of third-party payment processor Global-e. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/ledger-customers-impacted-by-third-party-global-e-data-breach/
-
New Zealand Orders Review of Manage My Health Breach Affecting 100,000+ Patients
A breach affecting Manage My Health could have exposed sensitive data for up to 120,000 New Zealand patients First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/new-zealand-orders-review-manage/
-
NordVPN denies breach claims, says attackers have “dummy data”
NordVPN denied allegations that its internal Salesforce development servers were breached, saying that cybercriminals obtained “dummy data” from a trial account on a third-party automated testing platform. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/nordvpn-denies-breach-claims-says-attackers-have-dummy-data/
-
Hackers Steal $35M in Cryptocurrency Following LastPass Breach
Tags: attack, blockchain, breach, crypto, cyber, cybercrime, data-breach, encryption, hacker, intelligence, password, russiaRussian cybercriminals have laundered over $35 million in stolen cryptocurrency linked to the devastating 2022 LastPass breach, according to new forensic analysis by blockchain intelligence firm TRM Labs. The 2022 attack exposed encrypted password vaults belonging to roughly 30 million customers worldwide. While the vaults were initially protected by encryption, attackers who downloaded them could…
-
Crimson Collective Claims Alleged Breach of Brightspeed Fiber Network
A threat actor group operating under the name >>Crimson Collective
-
âš¡ Weekly Recap: IoT Exploits, Wallet Breaches, Rogue Extensions, AI Abuse & More
The year opened without a reset. The same pressure carried over, and in some places it tightened. Systems people assume are boring or stable are showing up in the wrong places. Attacks moved quietly, reused familiar paths, and kept working longer than anyone wants to admit.This week’s stories share one pattern. Nothing flashy. No single…
-
Cybersecurity firm turns tables on threat actors with decoy data trap
Evidence of real breach remains thin: Despite Resecurity’s detailed account, the threat actors have not backed up their original claims with additional verifiable evidence. After posting the screenshots, no substantiated leaks of internal systems or actual client data have appeared. Independent analysis by various cybersecurity researchers supports Resecurity’s assertion that no production assets were compromised.On…
-
Cybersecurity firm turns tables on threat actors with decoy data trap
Evidence of real breach remains thin: Despite Resecurity’s detailed account, the threat actors have not backed up their original claims with additional verifiable evidence. After posting the screenshots, no substantiated leaks of internal systems or actual client data have appeared. Independent analysis by various cybersecurity researchers supports Resecurity’s assertion that no production assets were compromised.On…
-
New Zealand orders review into ManageMyHealth cyberattack
Government ‘incredibly’ concerned about breach potentially affecting more than 100,000 patients First seen on theregister.com Jump to article: www.theregister.com/2026/01/05/nz_managemyhealth_breach_review/
-
New Zealand orders review into ManageMyHealth cyberattack
Government ‘incredibly’ concerned about breach potentially affecting more than 100,000 patients First seen on theregister.com Jump to article: www.theregister.com/2026/01/05/nz_managemyhealth_breach_review/
-
European Space Agency Confirms Server Breach
Tags: breachThe European Space Agency has said that external servers were recently involved in a security “issue” First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/european-space-agency-confirms/
-
2026 Is the Year to Be Breach Ready: Augment Cyber Resilience with Operational Excellence
A very happy New Year 2026 to you. Those of you who are familiar with my work know that I preach breach readiness, cyber resilience, and building practical capabilities to remain “unaffected” by cyberattacks. A lot of what I have written in 2025 came from how great wars were fought. There is still a lot to learn about modern cyber resilience from them….…
-
Experts Trace $35m in Stolen Crypto to LastPass Breach
TRM Labs says it has recorded $35m drained from users’ wallets following 2022 LastPass breach First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/experts-trace-35m-stolen-crypto/
-
Experts Trace $35m in Stolen Crypto to LastPass Breach
TRM Labs says it has recorded $35m drained from users’ wallets following 2022 LastPass breach First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/experts-trace-35m-stolen-crypto/
-
Experts Trace $35m in Stolen Crypto to LastPass Breach
TRM Labs says it has recorded $35m drained from users’ wallets following 2022 LastPass breach First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/experts-trace-35m-stolen-crypto/
-
How OSINT + Breach Data Connects the Dots in Attribution Investigations
Attribution isn’t about one clue, it’s about connecting many Attribution investigations almost never hinge on a single “gotcha” artifact. Most of the work happens in the messy middle: weak signals, partial identifiers, reused aliases, and contradictory breadcrumbs across environments. Security teams might have a suspicious email address, a dark web mention, a forum username,… First…
-
Sedgwick discloses data breach after TridentLocker ransomware attack
Sedgwick confirmed a cyber incident at its federal contractor unit after TridentLocker claimed to steal 3.4GB of data. Sedgwick is a leading global claims management and risk services provider operating in the insurance and risk solutions sector. It employs roughly 33,000 people worldwide, across more than 80 countries. Estimated annual revenue is in the multi-billion…
-
Sedgwick discloses data breach after TridentLocker ransomware attack
Sedgwick confirmed a cyber incident at its federal contractor unit after TridentLocker claimed to steal 3.4GB of data. Sedgwick is a leading global claims management and risk services provider operating in the insurance and risk solutions sector. It employs roughly 33,000 people worldwide, across more than 80 countries. Estimated annual revenue is in the multi-billion…

