❌

Reading view

There are new articles available, click to refresh the page.

AI breach puts cyber insurance notification rules under scrutiny

Roxanne Libatique writes: An OpenAI agent accessed Australian government health data in June 2026. The government was not told until September. That gap – nearly three months between breach and disclosure – is not just a political problem. It is a cyber insurance problem, and one that brokers with public sector and health sector clients...

Source

DIVD Dutch Institute for Vulnerability Disclosure investigating agentic AI-powered attack

A Dutch non-profit that has helped so many over the years has discovered it become the victim of what appears to be an agentic AI-powered attack. DIVD, the Dutch Institute for Vulnerability Disclosure, announced the attack on LinkedIn. Consistent with their ethics and history, they didn’t try to minimize the problem: Security people always say...

Source

OpenAI agent breached Australian government health website, Albanese says

Alexander Martin reports: An OpenAI agent gained “unauthorized access” to “non-public files” from an Australian government health website in June, Prime Minister Anthony Albanese said Wednesday. The agent — an AI system designed to carry out tasks autonomously — accessed a public portal for Medicare statistics, Albanese said at a press conference in New York...

Source

Stevens Point servers go offline, city officials not sure if caused by a cyberattack

Brandi Makuski reports: Stevens Point officials are investigating a possible cyberattack after several city computer servers went offline early Wednesday, disrupting municipal phone and email services and leaving employees unable to access some city systems. District 4 Councilwoman Andrea Olson said city IT employees notified staff and council members of a cyberattack in a 6:51...

Source

Kosovar National Pleads Guilty to Operating Cybercrime Marketplace Offering Tools and Products to Cybercriminals

From the DOJ: Ardit Kutleshi, 28, a Kosovar national, pleaded guilty to charges related to his creation and operation of Rydox, an illicit website and marketplace for cybercriminals to buy, sell and trade stolen personal information, and to access devices and other tools for carrying out cybercrime and fraud. “The guilty plea of Ardit Kutleshi...

Source

Two Maryland hospitals still dealing with system issues after cyberattack

On September 22, WYPR reported: Luminis Health says it’s making considerable progress on restoring systems at two Maryland hospitals after they were hit by a cyberattack earlier this month. The company said in an online update that its telephone capabilities at Anne Arundel Medical Center and Doctors Community Medical Center in Lanham have been restored...

Source

Wyoming courts investigate extent of personal data exposed in cybersecurity breach

Maggie Mullen reports: The Wyoming Judicial Branch says it’s awaiting more details regarding the scope of a cybersecurity breach of a third-party software company that may have included a decade’s worth of data from the state’s court system. West Publishing Corporation, which the Wyoming Supreme Court and Wyoming district courts previously used for case management,...

Source

Error on North Carolina jury duty website exposed people’s social security numbers, medical records, more

Kudos to WBTV for following up on an astute observer’s vulnerability report. David Hodges reports: North Carolina residents summoned for jury duty received notice through a letter in the mail but to request an exemption from jury duty in North Carolina, a person can go online and fill out a jury excuse form. Zach Duda...

Source

California Enacts Several Minors’ Privacy and Safety Laws

Lindsey Tonsager, Jenna Zhang, and Irene Kim of Covington and Burling summarize some recent bills signed into law. From their article: Companion Chatbots. Adam’s Law (SB 1119) requires operators of a “companion chatbot” to determine the age of users consistent with the Digital Age Assurance Act and imposes a series of obligations before making a...

Source

FBI Hack Exposed FBI’s Own Hacking Unit

Joseph Cox reports: The catastrophic hack of at least thousands of FBI officials’ personal data, including their addresses, phone numbers, and even their spouses, includes members of the FBI’s secretive hacking team, potentially revealing who exactly is in that unit, 404 Media has found. The findings further highlight how sensitive the stolen data is, and...

Source

Canva hacked via vendor’s Salesforce instance; Other customers affected as well

A new dedicated leak site by threat actors calling themselves “The Seven Deadly Sins” lists Canva Pty Ltd among the sites that haven’t paid them. DataBreaches obtained additional details on the incident and this new group. Attack on Canva A spokesperson for The Seven Deadly Sins (TSDS) informed DataBreaches that on August 28, TSDS attacked...

Source

Ryuk Ransomware Operator Sentenced to 24 Months in Prison

Abinaya reports: An Armenian national extradited from Ukraine to the United States has been sentenced to federal prison for his role in Ryuk ransomware attacks that targeted organizations worldwide, including a company in Oregon. Karen Vardanyan, 35, received a 24-month federal prison sentence followed by 3 years of supervised release, according to the U.S. Attorney’s...

Source

Latvia arrests suspected hacker for electronics repair company breach

Daryna Antoniuk reports: Latvian police arrested a 23-year-old man suspected of hacking at least two companies, stealing personal information and attempting to extort money from the victims, authorities said Wednesday. The first attack was detected in February, while a second — using similar methods — was discovered in early September at TSC, an electronics repair...

Source

The EU spent billions on a cyberattack shield — nobody checked if it worked

The EU built an early-warning system to catch the next major cyberattack before it spreads. Roughly 20 months later, auditors have found it still is not fully switched on. Jonathan Bent reports: Brussels has allocated €1.4 billion to defending Europe from cyberattacks. Its own auditors found that when that funding is passed on to third...

Source

Elsevier Evolve, ClinicalPharmacology, and GSDD APIs Hijacked: LAPSUS$ Redirect Campaign

Sorami Consulting reports: Users and systems trying to connect to Elsevier Evolve, Sherpath, and ClinicalPharmacology are being redirected to extortion splash pages tied to LAPSUS$ (pointing to domains including lapsus[.]ar[.]io and lapsus[.]bz). While public discussion on Reddit is dominated by nursing and medical students locked out of exams and simulation charting, the real blast radius...

Source

ShinyHunters escalates dispute with FBI; claims to have seized job applicants’ site and acquired data (1)

Joseph Cox reports: A high profile hacking group claims it has breached multiple FBI-related services and stolen data “on all FBI employees and applicants.” A representative of the group, called ShinyHunters, told 404 Media the data includes FBI agents’ names, home addresses, phone number, and information on their spouse. The data breach could be massively...

Source

Israeli cyber manager accused of remotely accessing cameras, stealing passwords and infiltrating 26 companies

Amir Kurz recently reported: Three weeks after his arrest, the State Attorney’s Office’s Cyber Department on Thursday filed a major indictment against Michael “Miki” Bar, a 43-year-old hacker from Ashkelon who served as Chief Information Security Officer for the Hamat Group. The group itself has no connection to the charges. According to the indictment, Bar...

Source

Spokane Public Schools takes some systems offline after ‘network security incident’

Shannon Moudy reports: Some systems are offline Monday after Spokane Public Schools says it experienced an overnight ‘network security incident.’ In an email sent to families Monday, the district says the situation is being investigated. “Out of an abundance of caution, we have chosen to take several of our systems offline. As a result, families...

Source

Canadian regulator opens probe of IDScan for allegedly violating data privacy laws

Suzanne Smalley reports: Privacy Commissioner of Canada Philippe Dufresne has launched a probe of IDScan.net in the wake of reports that a bad actor penetrated company databases to steal personal data and scans of 153 million people’s drivers’ licenses. IDScan.net’s technology is widely used by industry — particularly in the retail and hospitality sectors —...

Source

❌