โŒ

Normal view

There are new articles available, click to refresh the page.
Today โ€” 26 June 2026Security/Privacy

Colorado Health Network Notifies Patients of Last Yearโ€™s Breachโ€”But Key Details Remain Undisclosed

By: Dissent
25 June 2026 at 12:23
In August 2025, DataBreaches added the Colorado Health Network (CHN) to our non-public worksheets after threat actors called Cephalus added the provider to itsโ€™ dark web leak site with a claim that they had acquired 900 GB of data. Cephalus disappeared from public view days later, and never leaked the data on any server that...

Source

No need to hack when itโ€™s leaking: Dialog edition

By: Dissent
25 June 2026 at 08:48
Yes, another entry in our โ€œno need to hack when itโ€™s leakingโ€ archives, and another example of entities trying to excuse their securityย  failures by claiming they were โ€œhacked.โ€ Danny Bradbury cuts to the chase: Some organizations exist to be exclusive. Theyโ€™re invite-only, and discreet, the kind of place where the membership directory is the...

Source

Before yesterdaySecurity/Privacy

โ€œThe Timeline Is Months, Not Yearsโ€: Five Eyes Warns of AI-Powered Cyberattacks

By: Dissent
23 June 2026 at 14:44
MITSloan reports: The intelligence alliance of the United States, United Kingdom, Canada, Australia, and New Zealand, commonly known as Five Eyes, has raised concerns over rapidly advancing artificial intelligence, which can supercharge offensive hacking capabilities. In a three-page statement, the alliance called for urgent action to confront the threat. โ€œFrontier AI models are anticipated to...

Source

Cybersecurity Incidents: The Problem Isnโ€™t Just Who Attacks

By: Dissent
23 June 2026 at 08:20
Over on SuspectFile, Marco A. De Felice reflects on how we may overfocus on identifying threat actors exploiting vulnerabilities while failing to focus enough on root causes and incident response. He highlights what he calls a structural fragility that cannot be ignored: that many organizations continue to collect, centralize, and retain vast amounts of sensitive...

Source

Cherry Health provides preliminary notice of recent data breach

By: Dissent
22 June 2026 at 11:22
On April 19, 2026, Cherry Health in Michigan detected suspicious network activity. Investigation revealed that an unknown person or persons had gained access to its network and copied data. On June 18, Cherry Health published a preliminary notice on its website.ย  The notice makes no mention of any earlier reporting on the incident that had...

Source

UK: More than one year later, HCRG is first notifying patients of ransomware attack

By: Dissent
18 June 2026 at 13:32
In February 2025, after the Medusa ransomware gang claimed responsibility for an attack on the UK healthcare provider HCRG Care Group, HCRG confirmed it had been breached but would only say it was investigating. While they remained silent, SuspectFile obtained and reported on data provided to them by Medusa. SuspectFilesโ€˜s reporting made it clear that...

Source

Data analysis of the Global Schools Group breach, Part 2

By: Dissent
18 June 2026 at 12:59
In Part 1,ย  DataBreaches published some totals and aggregate data from the recent Global Schools Group data breach. All analyses and statistics were provided to this site by FulcrumSec, who had attacked Global Schools Group (GSG) and exfiltrated the data. Data from three of GSGโ€™s school brands were included in Part 1. Data for the...

Source

Cybersecurity breach includes Crime Stoppers of Hamilton data

By: Dissent
18 June 2026 at 12:52
The Navigate360 (โ€œP3โ€) data breach seems to finally be getting some attention in Canada. Nicole Oโ€™Reilly reports: Hamilton police say theyโ€™ve been made aware that a cybersecurity incident earlier this year affecting a U.S.-based online platform includes a breach of Crime Stoppers of Hamilton data. The P3 platform, owned by Navigate360, is under contract with...

Source

Data analysis of the Global Schools Group breach, Part 1

By: Dissent
18 June 2026 at 10:46
This is the first part of a two-part report of findings from the Global Schools Group data breach. All statistical analyses and findings were provided to DataBreaches by FulcrumSec, and are presented to assist those investigating the breach as well as parents and employees who might be concerned as to what types of data were...

Source

Active FortiBleed Campaign Impacting Fortinet Devices Across 194 Countries

By: Dissent
18 June 2026 at 08:23
From Arctic Wolf: Summary In mid-June 2026, security researchers identified an active, large-scale credential compromise campaign affecting Fortinet FortiGate firewalls, dubbed FortiBleed. Threat actors have been systematically extracting configuration files from internet-facing FortiGate devices and cracking the stored credential hashes, resulting in verified working administrator credentials for between 30,000 and 75,000 devices across 194 countries....

Source

GitHub dismissed security reports on flaws now exploited by supply-chain worm, researchers say

By: Dissent
17 June 2026 at 07:47
Alexander Martin reports: GitHub rejected two formal vulnerability reports identifying design flaws that researchers say are enabling variants of the Shai-Hulud supply-chain worm to infect and compromise hundreds of software packages and developer accounts worldwide. The reports, submitted by threat intelligence group Deep Specter Research through GitHubโ€™s bug disclosure channel on HackerOne, were both closed...

Source

One threat actor demanded $50 million from Novo Nordisk. Another one demanded $25 million. Neither got paid.

By: Dissent
16 June 2026 at 14:24
Yesterday, DataBreaches reported thatย FulcrumSec had hacked Danish pharmaceutical giantย Novo Nordisk. FulcrumSec followed up on that reporting by releasing their own very detailed report on their dark web leak site about the incident and what they had acquired. This morning, DataBreaches woke up to find messages waiting on Signal from someone claiming they, too, had hacked...

Source

Scoop: FulcrumSec Leaks Novo Nordisk Data After $25M Demand Goes Unpaid (2)

By: Dissent
15 June 2026 at 20:51
Danish pharma giant Novo Nordisk disclosed a cybersecurity incident last week, and although the firmโ€™s name may not be familiar to everyone, they are a major producer of insulin and semaglutide. Semaglutide is marketed as Wegovy for weight loss and Ozempic for Type 2 diabetes. In its June 11 update, the firm stated that the...

Source

ShinyHunters Targets Education Sector with Oracle PeopleSoft Exploit

By: Dissent
12 June 2026 at 12:30
From Mandiant and Google Threat Intelligence Group, an advisory: Mandiant and Google Threat Intelligence Group (GTIG) have identified an active compromise and extortion campaign attributed to UNC6240 (ShinyHunters) targeting Oracle PeopleSoft application infrastructure. The activity was observed between May 27, 2026, and June 9, 2026 and is consistent with the exploitation ofย CVE-2026-35273, a critical remote...

Source

Who Runs the Ransomware Group โ€˜The Gentlemen?โ€™

By: Dissent
10 June 2026 at 10:55
Brian Krebs reports: A cybercrime group known asย The Gentlemenย has emerged as the second most active ransomware gang by victim count, rapidly attracting a talented pool of hackers through an aggressive recruitment strategy that promises affiliates 90 percent of any ransom paid by victims. This post examines clues pointing to a real life identity for the...

Source

Silent Ransom Group (SRG): Uncovering DNS Fast Flux Infrastructure

By: Dissent
7 June 2026 at 15:07
In 2022, DataBreaches wondered whether a group with no name might be the most successful group we had never heard about. Our impression that the group was unique was somewhat confirmed in 2024, when it walked away from a ransom offer of $1.8 million. ย More recently, the group, now commonly referred to as the โ€œSilent...

Source

Ex-Threat Intel Exec Accuses IBM and AT&T of Hiding Hacks

By: Dissent
7 June 2026 at 14:36
Tiffany Wang reports: IBM and AT&T lacked basic security controls and hid nation-state hacking breaches from the government, a former IBM threat intelligence official alleged in a newly unsealed lawsuit. Former IBM Vice President of Threat Intelligence William Barlow claimed the companies did not keep logs for AT&T-managed VPN connections into IBM cloud services and...

Source

Was โ€œExPresidentsโ€ a real hacker or a fabricated account?

By: Dissent
7 June 2026 at 14:36
DataBreaches recently recommended an article by Alberto Daniel Hill about digital security in Argentina, Uruguay, and Mexico. In describing his article, DataBreaches reported: In one section of his report, Hill calls out a company for allegedly manufacturing cyber threats, which he claims they then use to create public panic through media amplification. With the public...

Source

Most organizations that miss 24-hour patch window report breaches

By: Dissent
2 June 2026 at 19:24
Steve Zurier reports: The Cloud Security Alliance (CSA) found that 80% of organizations that miss the 24-hour patch window report security incidents involving known vulnerabilities. CSAโ€™s study,ย released June 2, also found that even pre-production controls are not stopping known flaws in the AI age as 82% of organizations lack real-time visibility into AI runtime behavior....

Source

Alberto Daniel Hillโ€™s Cybermidnight Coverage of the Latin American Digital Sovereignty Crisis (Marchโ€“June 2026)

By: Dissent
1 June 2026 at 20:16
Alberto Daniel Hillโ€™s report is a must-read for anyone who wants to begin to understand what is going on in Argentina, Uruguay, and Mexico with respect to digital security. One of the many limitations of being a solo blogger is that there are entire areas of the world or sectors I basically know nothing about...

Source

โŒ
โŒ