Tag: data
-
Hacks Targeting Cloud Single Sign-On Rose in 2024
Hackers Deploying Infostealers for Data and Credential Theft. Hacks targeting cloud infrastructure rose significantly last year, with attackers exploiting misconfiguration and single sign-on features to deploy infostealers for data and credential theft. Hackers target centralized cloud assets secured with single sign-ons. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/hacks-targeting-cloud-single-sign-on-rose-in-2024-a-28083
-
Max-Severity Commvault Bug Alarms Researchers
Though already patched, the vulnerability is especially problematic because of the highly privileged access it offers to business-critical systems, sensitive data, and backups for attackers. First seen on darkreading.com Jump to article: www.darkreading.com/cyber-risk/max-severity-commvault-bug-researchers
-
Data breach victimization in the US escalates
First seen on scworld.com Jump to article: www.scworld.com/brief/data-breach-victimization-in-the-us-escalates
-
Blue Shield of California exposes 4.7M individuals’ data to Google Ads
First seen on scworld.com Jump to article: www.scworld.com/brief/blue-shield-of-california-exposes-4-7m-individuals-data-to-google-ads
-
US Data Breach Impact Grows in 2025
First seen on scworld.com Jump to article: www.scworld.com/brief/us-data-breach-impact-grows-in-2025
-
Judge tosses citizenship provisions in Trump elections order
Requests to block federal agencies from sharing federal data with states and to condition federal election funding were denied by Judge Colleen Kollar-Kotelly. First seen on cyberscoop.com Jump to article: cyberscoop.com/elections-white-house-executive-order-court-proof-of-citizenship-requirements/
-
Kyndryl Expands Microsoft Partnership to Strengthen Enterprise Data Security and AI Readiness
First seen on scworld.com Jump to article: www.scworld.com/news/kyndryl-expands-microsoft-partnership-to-strengthen-enterprise-data-security-and-ai-readiness
-
US data security fears prompt subpoena on Chinese telcos
First seen on scworld.com Jump to article: www.scworld.com/brief/us-data-security-fears-prompt-subpoena-on-chinese-telcos
-
Client-Side Security Breach Alert: Blue Shield of California Exposes 4.7 Million Members’ Health Data Through Web Analytics Configuration
by Source Defense A recent incident at Blue Shield of California highlights the critical importance of client-side security controls when implementing third-party scripts on healthcare websites. The nonprofit health plan has disclosed a significant data breach affecting 4.7 million members, stemming from a misconfiguration of Google Analytics on their web properties between April 2021 and…
-
Dialysis company DaVita reviewing data leaked by ransomware gang
The Interlock ransomware gang posted samples from a trove of data it is claiming to have stolen from the company. First seen on therecord.media Jump to article: therecord.media/dialysis-davita-reviewing-data-leak
-
Yale New Haven Health Notifying 5.5 Million of March Hack
Incident Is Largest Health Data Breach Reported So Far to Feds in 2025. Yale New Haven Health System is notifying more than 5.5 million patients that their information was potentially among data stolen in a March hack. The incident, which is among several other recent major hacks, ranks is the largest health data breach reported…
-
Yale New Haven Health (YNHHS) data breach impacted 5.5 million patients
Yale New Haven Health (YNHHS) announced that threat actors stole the personal data of 5.5 million patients in a cyberattack. Yale New Haven Health (YNHHS) disclosed a data breach that exposed personal information of 5.5 million patients following a cyberattack that occurred earlier this month. Yale New Haven Health System (YNHHS) is a nonprofit healthcare…
-
Breach Roundup: Cookie Bite Exposes MFA Achilles Heel
Tags: attack, breach, cyberattack, data, data-breach, google, mfa, microsoft, north-korea, ransomwareAlso, Blue Shield Breach Exposes 4.7M, Cyberattack Disrupts City Systems in Texas. This week, Cookie Bite bypasses MFA in Azure Entra ID, Microsoft fixed RDP Freezes, a ransomware attack in Catalonia, Blue Shield exposed data to Google, a cyberattack disrupted city systems in Texas, South Korean telecom breach exposed USIM data and a warning about…
-
Blue Shield Leaked Millions of Patient Info to Google for Years
Blue Shield of California exposed the health data of 4.7 million members to Google for years due to… First seen on hackread.com Jump to article: hackread.com/blue-shield-leaked-millions-patient-info-google-years/
-
Verizon DBIR Report: Small Businesses Identified as Key Targets in Ransomware Attacks
Tags: attack, breach, business, credentials, cyber, cybersecurity, data, data-breach, exploit, ransomware, security-incident, vulnerabilityVerizon Business’s 2025 Data Breach Investigations Report (DBIR), released on April 24, 2025, paints a stark picture of the cybersecurity landscape, drawing from an analysis of over 22,000 security incidents, including 12,195 confirmed data breaches. The report identifies credential abuse (22%) and exploitation of vulnerabilities (20%) as the predominant initial attack vectors, with a 34%…
-
Data in Danger: Detecting Cross-Site Scripting in Grafana
Learn how SonarQube detected a Cross-Site Scripting (XSS) vulnerability in Grafana, a popular open-source data observability platform. First seen on securityboulevard.com Jump to article: securityboulevard.com/2025/04/data-in-danger-detecting-cross-site-scripting-in-grafana/
-
Despite Recent Security Hardening, Entra ID Synchronization Feature Remains Open for Abuse
Microsoft synchronization capabilities for managing identities in hybrid environments are not without their risks. In this blog, Tenable Research explores how potential weaknesses in these synchronization options can be exploited. Synchronizing identity accounts between Microsoft Active Directory (AD) and Entra ID is important for user experience, as it seamlessly synchronizes user identities, credentials and groups…
-
Assassin’s Creed maker faces GDPR complaint for forcing single-player gamers online
Collecting data from solo players is a Far Cry from being necessary, says noyb First seen on theregister.com Jump to article: www.theregister.com/2025/04/24/ubisoft_noyb_complaint/
-
Data breach class action costs mount up
Organisations exposed to the US market paid out over $150m in class action settlements in just six months. Security leaders must do more to address cyber gaps, respond better to incidents and demonstrate compliance First seen on computerweekly.com Jump to article: www.computerweekly.com/news/366622911/Data-breach-class-action-costs-mount-up
-
Frederick Health data breach impacts nearly 1 million patients
A ransomware attack in January at Frederick Health Medical Group, a major healthcare provider in Maryland, has led to a data breach affecting nearly one million patients. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/frederick-health-data-breach-impacts-nearly-1-million-patients/
-
Interlock ransomware claims DaVita attack, leaks stolen data
The Interlock ransomware gang has claimed the cyberattack on DaVita kidney dialysis firm and leaked data allegedly stolen from the organization. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/interlock-ransomware-claims-davita-attack-leaks-stolen-data/
-
Blue Shield of California Data Breach Affects 4.7 Million Members
A misconfigured tracking tool has exposed protected health information of 4.7 million Blue Shield members to Google Ads First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/blue-shield-california-data-breach/
-
HYCU Tackles SaaS Data Protection With New R-Shield Solution
HYCU introduces R-Shield to provide comprehensive cyber resilience across SaaS, cloud, and on-premises environments as organizations face growing supply chain attacks. First seen on securityboulevard.com Jump to article: securityboulevard.com/2025/04/hycu-tackles-saas-data-protection-with-new-r-shield-solution/
-
Yale New Haven Health data breach affects 5.5 million patients
Yale New Haven Health (YNHHS) is warning that threat actors stole the personal data of 5.5 million patients in a cyberattack earlier this month. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/yale-new-haven-health-data-breach-affects-55-million-patients/
-
NVIDIA NeMo Vulnerability Enables Remote Exploits
NVIDIA has issued an urgent security advisory addressing three high-severity vulnerabilities in its NeMo Framework, a platform widely used for developing AI-powered applications. The flaws, if exploited, could allow attackers to execute malicious code, tamper with data, or take control of vulnerable systems. Users are advised to update to NeMo Framework version 25.02 immediately to…
-
Verbessertes Data Security Posture Management – Kyndryl und Microsoft kooperieren für mehr Datensicherheit
First seen on security-insider.de Jump to article: www.security-insider.de/kyndryl-beratungsdienste-microsoft-purview-a-c105f7ffe3e2a4a7ea2d68e57a9a3216/
-
GitHub secrets: Deleted files still pose risks
git diff) the list of files with its parent commit,” Briznov said. Once deleted files were restored, a simple search for secrets that were still active was performed through another automation. AI made the exploit much easier: Interestingly, Brizinov relied on AI to do a lot of routine tasks in the exploit. For instance, a…
-
South Korea Accuses DeepSeek of Unlawful Data Transfers Amid AI Expansion
Chinese artificial intelligence startup DeepSeek has come under intense scrutiny from South Korean authorities for allegedly transferring user data and AI prompts without proper consent. The controversy erupted after Korea’s data protection authority, the Personal Information Protection Commission (PIPC), released a detailed statement on April 18, 2025, accusing Hangzhou DeepSeek Artificial Intelligence Co. Ltd. of…

