Tag: data-breach
-
Erkenntnisse aus dem Verizon Data Breach Investigation Report (DBIR) 2025
First seen on datensicherheit.de Jump to article: www.datensicherheit.de/verizon-data-breach-investigation-report-2025-erkenntnisse
-
VerizonBreach-Investigation-Report Schwachstellen sind der häufigste Einstiegspunkt für Sicherheitsverletzungen
Der aktuelle Verizon-Data-Breach-Investigation-Report, DBIR 2025, veröffentlicht am 2. Mai 2025 in München, liefert einen umfassenden Überblick über die sich wandelnde Bedrohungslandschaft in der Cybersicherheit. Der Bericht wurde durch die Expertise zahlreicher Partner insbesondere Qualys unterstützt, die entscheidend dazu beitrugen, kritische Muster und Schwachstellen aufzudecken und Unternehmen das nötige Wissen zur Abwehr aktueller und […] First…
-
Patients left in the dark months after cybercriminals leak testing lab data
It’s been almost a year since the Qilin cybercrime group breached sensitive data from U.K. pathology services company Synnovis, and its patient information page is still short on details about what was exposed and how many people were affected. First seen on therecord.media Jump to article: therecord.media/synnovis-health-data-breach-investigation-onging
-
People know password reuse is risky but keep doing it anyway
35% of Gen Z said they never or rarely update passwords after a data breach affecting one of their accounts, according to Bitwarden. Only 10% reported always updating … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2025/05/02/passwords-update-security-risks/
-
More than 100,000 impacted by December data breach at Ascension Health
Ascension Health revealed another security incident this week, warning more than 100,000 people in multiple states that their information was likely accessed by hackers late last year. First seen on therecord.media Jump to article: therecord.media/ascension-health-data-breach-impacts-over-100000
-
Breach Roundup: Surge in Edge Device Zero-Day Exploits
Also, Baltimore Public Schools Suffer Data Breach, Disney Menu Hacker Sentenced. This week, zero-day exploits surged, accused Nefilim hacker extradited, Baltimore schools breach, CISA lists Broadcom Brocade, Commvault flaws, a fake WooCommerce patch, Akira hit Hitachi Vantara, ex-Disney worker sentenced and a Darcula phishing kit upgrade. FBI published 42,000 phishing domains. First seen on govinfosecurity.com…
-
Ticket Resale Platform TicketToCash Left 200GB of User Data Exposed
A misconfigured, non-password-protected database belonging to TicketToCash exposed data from 520,000 customers, including PII and partial financial details…. First seen on hackread.com Jump to article: hackread.com/ticket-resale-platform-tickettocash-exposed-user-data/
-
Experts See Little Progress After Major Chinese Telecom Hack
Salt Typhoon Exposed Major Flaws in Telecom Networks. Few Changes Have Been Made. After China’s Salt Typhoon breach of U.S. telecom networks, federal experts told Congress on Wednesday the nation remains dangerously exposed to another attack – despite warnings, investigations and interagency coordination, all of which have yet to produce systemic cyber defense improvements. First…
-
Exposed Git configuration file scanning escalates
Tags: data-breachFirst seen on scworld.com Jump to article: www.scworld.com/brief/exposed-git-configuration-file-scanning-escalates
-
Oregon agency’s 1.3M files leaked by Rhysida ransomware gang
First seen on scworld.com Jump to article: www.scworld.com/brief/oregon-agencys-1-3m-files-leaked-by-rhysida-ransomware-gang
-
Ascension Data Breach: Patient Information ‘Likely Stolen’ After ‘Inadvertently’ Being Shared With Former Business Partner
Ascension, a Catholic health system that suffered one of the worst health care-related cyberattacks in history, said it discovered a separate breach late last year. First seen on crn.com Jump to article: www.crn.com/news/security/2025/ascension-data-breach-patient-information-likely-stolen-after-inadvertently-being-shared-with-former-business-partner
-
AirBorne flaws can lead to fully hijack Apple devices
Vulnerabilities in Apple’s AirPlay protocol and SDK exposed Apple and third-party devices to attacks, including remote code execution. Oligo Security found serious flaws, collectively tracked as AirBorne, in Apple’s AirPlay protocol and SDK, affecting Apple and third-party devices. Attackers can exploit the vulnerabilities to perform zero-/one-click RCE, bypass ACLs, read local files, steal data, and…
-
Over 400 servers found to be exposed to SAP NetWeaver bug
First seen on scworld.com Jump to article: www.scworld.com/news/over-400-servers-found-to-be-exposed-to-sap-netweaver-bug
-
Data breach disclosed by UrbanOne following Cactus ransomware claims
First seen on scworld.com Jump to article: www.scworld.com/brief/data-breach-disclosed-by-urbanone-following-cactus-ransomware-claims
-
VeriSource cops to 4 million accounts lost in 2024 data breach
First seen on scworld.com Jump to article: www.scworld.com/news/verisource-cops-to-4-million-accounts-lost-in-2024-data-breach
-
Hackers ramp up scans for leaked Git tokens and secrets
Threat actors are intensifying internet-wide scanning for Git configuration files that can reveal sensitive secrets and authentication tokens used to compromise cloud services and source code repositories. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/hackers-ramp-up-scans-for-leaked-git-tokens-and-secrets/
-
Apple ‘AirBorne’ flaws can lead to zero-click AirPlay RCE attacks
Tags: apple, attack, data-breach, flaw, programming, rce, remote-code-execution, software, vulnerabilityA set of security vulnerabilities in Apple’s AirPlay Protocol and AirPlay Software Development Kit (SDK) exposed unpatched third-party and Apple devices to various attacks, including remote code execution. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/apple-airborne-flaws-can-lead-to-zero-click-airplay-rce-attacks/
-
SK Telecom cyberattack: Free SIM replacements for 25 million customers
South Korean mobile provider SK Telecom has announced free SIM card replacements to its 25 million mobile customers following a recent USIM data breach, but only 6 million cards are available through May. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/sk-telecom-cyberattack-free-sim-replacements-for-25-million-customers/
-
Verizon 2025 Report Highlights Surge in Cyberattacks Through Third Parties
Verizon Business unveiled its 2025 Data Breach Investigations Report (DBIR) today, painting a stark picture of the escalating cyber threat landscape. Analyzing over 22,000 security incidents, including 12,195 confirmed data breaches, the report reveals a alarming 30% involvement of third parties in breaches-a figure that has doubled from previous years. This underscores the growing risks…
-
GPUAF: Two Methods to Root Qualcomm-Based Android Phones
Security researchers have exposed critical vulnerabilities in Qualcomm GPU drivers, impacting a vast array of Android devices from brands like Samsung, Honor, Xiaomi, and Vivo. These exploits, centered around the GPU Address Fault (GPUAF) primitive, target the kgsl_mem_entry and Virtual Buffer Object (VBO) structures. By leveraging race conditions and memory management flaws, attackers can achieve…
-
Threat Actors Accelerate Transition from Reconnaissance to Compromise New Report Finds
Tags: api, attack, automation, cloud, cyber, cybercrime, data, data-breach, identity, technology, threat, tool, voipCybercriminals are leveraging automation across the entire attack chain, drastically reducing the time from reconnaissance to compromise. The data shows a staggering 16.7% global increase in scans, with over 36,000 scans per second targeting not just exposed ports but delving into operational technology (OT), cloud APIs, and identity layers. Sophisticated tools probe SIP-based VoIP systems,…
-
21 million employee screenshots leaked in bossware breach blunder
If you thought only your boss was peeking at your work screen, think again. First seen on bitdefender.com Jump to article: www.bitdefender.com/en-us/blog/hotforsecurity/21-million-employee-screenshots-leaked-in-bossware-breach-blunder
-
VeriSource data breach impacted 4M individuals
VeriSource breach exposed data of 4M people in Feb 2024; stolen info includes personal details from an employee benefits services provider. VeriSource is alerting 4 million people after a February 2024 breach that exposed personal information. The data was stolen on February 27, 2024, and the incident was discovered on February 28, 2024. The company…
-
Unbefugter Zugriff bei einem Medienunternehmen aus den USA
Media firm Urban One confirms data breach after cybercriminals claim February attack First seen on therecord.media Jump to article: therecord.media/urban-one-data-breach-african-amercian-media
-
Weaponized Uyghur Language Software: Citizen Lab Uncovers Targeted Malware Campaign
In a new report, researchers at Citizen Lab have exposed a spearphishing campaign targeting senior members of the First seen on securityonline.info Jump to article: securityonline.info/weaponized-uyghur-language-software-citizen-lab-uncovers-targeted-malware-campaign/
-
Earth Kurma APT is actively targeting government and telecommunications orgs in Southeast Asia
Tags: apt, business, cloud, credentials, data, data-breach, espionage, government, malware, risk, theft, threatEarth Kurma APT carried out a sophisticated campaign against government and telecommunications sectors in Southeast Asia. Trend Research exposed the Earth Kurma APT campaign targeting Southeast Asia’s government and telecom sectors. Threat actors use custom malware, rootkits, and cloud storage for espionage, credential theft, and data exfiltration, posing a high business risk with advanced evasion…
-
TikTok user database purportedly compromised, over 900K users’ info exposed
Tags: data-breachFirst seen on scworld.com Jump to article: www.scworld.com/brief/tiktok-user-database-purportedly-compromised-over-900k-users-info-exposed
-
Media firm Urban One confirms data breach after cybercriminals claim February attack
Urban One, the largest media company primarily serving African Americans, disclosed a data breach to regulators. A ransomware group said it had attacked the company. First seen on therecord.media Jump to article: therecord.media/urban-one-data-breach-african-amercian-media

