❌

Reading view

There are new articles available, click to refresh the page.

DIVD Dutch Institute for Vulnerability Disclosure investigating agentic AI-powered attack

A Dutch non-profit that has helped so many over the years has discovered it become the victim of what appears to be an agentic AI-powered attack. DIVD, the Dutch Institute for Vulnerability Disclosure, announced the attack on LinkedIn. Consistent with their ethics and history, they didn’t try to minimize the problem: Security people always say...

Source

Two Maryland hospitals still dealing with system issues after cyberattack

On September 22, WYPR reported: Luminis Health says it’s making considerable progress on restoring systems at two Maryland hospitals after they were hit by a cyberattack earlier this month. The company said in an online update that its telephone capabilities at Anne Arundel Medical Center and Doctors Community Medical Center in Lanham have been restored...

Source

Wyoming courts investigate extent of personal data exposed in cybersecurity breach

Maggie Mullen reports: The Wyoming Judicial Branch says it’s awaiting more details regarding the scope of a cybersecurity breach of a third-party software company that may have included a decade’s worth of data from the state’s court system. West Publishing Corporation, which the Wyoming Supreme Court and Wyoming district courts previously used for case management,...

Source

Error on North Carolina jury duty website exposed people’s social security numbers, medical records, more

Kudos to WBTV for following up on an astute observer’s vulnerability report. David Hodges reports: North Carolina residents summoned for jury duty received notice through a letter in the mail but to request an exemption from jury duty in North Carolina, a person can go online and fill out a jury excuse form. Zach Duda...

Source

FBI Hack Exposed FBI’s Own Hacking Unit

Joseph Cox reports: The catastrophic hack of at least thousands of FBI officials’ personal data, including their addresses, phone numbers, and even their spouses, includes members of the FBI’s secretive hacking team, potentially revealing who exactly is in that unit, 404 Media has found. The findings further highlight how sensitive the stolen data is, and...

Source

Ryuk Ransomware Operator Sentenced to 24 Months in Prison

Abinaya reports: An Armenian national extradited from Ukraine to the United States has been sentenced to federal prison for his role in Ryuk ransomware attacks that targeted organizations worldwide, including a company in Oregon. Karen Vardanyan, 35, received a 24-month federal prison sentence followed by 3 years of supervised release, according to the U.S. Attorney’s...

Source

Latvia arrests suspected hacker for electronics repair company breach

Daryna Antoniuk reports: Latvian police arrested a 23-year-old man suspected of hacking at least two companies, stealing personal information and attempting to extort money from the victims, authorities said Wednesday. The first attack was detected in February, while a second — using similar methods — was discovered in early September at TSC, an electronics repair...

Source

The EU spent billions on a cyberattack shield — nobody checked if it worked

The EU built an early-warning system to catch the next major cyberattack before it spreads. Roughly 20 months later, auditors have found it still is not fully switched on. Jonathan Bent reports: Brussels has allocated €1.4 billion to defending Europe from cyberattacks. Its own auditors found that when that funding is passed on to third...

Source

ShinyHunters escalates dispute with FBI; claims to have seized job applicants’ site and acquired data (1)

Joseph Cox reports: A high profile hacking group claims it has breached multiple FBI-related services and stolen data “on all FBI employees and applicants.” A representative of the group, called ShinyHunters, told 404 Media the data includes FBI agents’ names, home addresses, phone number, and information on their spouse. The data breach could be massively...

Source

Israeli cyber manager accused of remotely accessing cameras, stealing passwords and infiltrating 26 companies

Amir Kurz recently reported: Three weeks after his arrest, the State Attorney’s Office’s Cyber Department on Thursday filed a major indictment against Michael “Miki” Bar, a 43-year-old hacker from Ashkelon who served as Chief Information Security Officer for the Hamat Group. The group itself has no connection to the charges. According to the indictment, Bar...

Source

National Cancer Centre e-mail lapse allegedly exposes patients’ details

The mistaken cc: breach still happens.  Ann Neo reports: An invitation to an event sent by the National Cancer Centre Singapore (NCCS) has sparked privacy concerns after a mailing list exposed the identities, contact details and, in some instances, workplaces of individuals with a genetic cancer condition. The e-mail, an invitation to a Living with...

Source

Ransomware attack on Kansas county will affect some services

Joseph McCarty reports: A Kansas county’s government says it has been hit by a ransomware attack. Ellis County discovered the attack on parts of its information technology systems Thursday morning. Officials said they “immediately took steps to contain the disruption” by isolating the affected systems and enlisting the help of cybersecurity experts. The county said...

Source

Foreign actors breach Colorado water systems

Alayna Alvarez reports: Foreign actors last month breached two small Colorado water utilities and manipulated equipment used to control drinking water systems. The two privately owned utilities, each serving fewer than 200 people, were breached in late August, Gov. Jared Polis’ office told Axios. The hackers changed equipment settings, disabled remote access and alarms, and...

Source

The U.S. military leaked more than 93,000 tips via insecure P3 Global Intel. Has anyone been notified?

As part of DataBreaches.net’s ongoing investigation into the Navigate360 breach, this report covers approximately 94,000 unclassified but sensitive tips submitted through P3 Global Intel apps and websites used by the military. What has Homeland Security done in response to the breach?  When the Navigate360 breach first broke, DDoSecrets.org called it “BlueLeaks 2.0” because of the...

Source

Raon data leak: Insider leak of 1,894 cases went undetected for 4 years

Choi Won-woo reports: Internal data amounting to 1,894 cases from the Korean-type heavy ion accelerator ‘Raon,’ built with a state budget of 1.5 trillion Korean won [USD $1,080,038,017.50 at today’s rates] was confirmed to have been leaked externally. The estimated time of the leak is 2022, and the Institute for Basic Science (IBS) Heavy Ion...

Source

EU chief wants joint response to cyberattacks, sabotage

Alexander Martin reports: European Commission President Ursula von der Leyen proposed on Wednesday an emergency mechanism allowing any EU country to summon the bloc’s governments in response to security threats including sabotage, cyberattacks and drone incursions. Delivering her annual State of the Union address in Strasbourg, Von der Leyen said threats were “mounting on our...

Source

Navigate360 may soon release a public notice about its horrific breach, but will any individuals be notified?

Six months ago, a hacktivist announced that they had accessed and acquired 8.3 million tips submitted on supposedly anonymous tip lines and platforms used by schools, communities, Crime Stoppers organizations, law enforcement, and the military. Six months later, individuals affected by the breach STILL haven’t been notified.  Since April, DataBreaches has reported Navigate360’s lack of public transparency about the...

Source

Canada: Nipigon hospital hit by ransomware attack

Mike Stimpson reports: Some patient services may be affected as the general hospital in Nipigon responds to what it describes as a “cyber security incident.” An incident involving ransomware affected information technology systems, Nipigon District Memorial Hospital stated in a post on social media. […] Nipigon Mayor Suzanne Kukko told CFNO’s Al Cresswell “the hospital...

Source

Revolut’s paperwork breach shows why insurers are rethinking what counts as a ‘cyber attack’

Matthew Sellers reports: Revolut wasn’t hacked in the usual sense. No one broke into its servers or slipped malware past its defences. Someone asked for customer data, from what looked like a genuine government email address, and Revolut handed it over. That email is now behind one of the stranger data incidents to hit a...

Source

Ransomware group claims attack on Missouri’s Cedar County Memorial Hospital after IT outage

DysruptionHub reports: Cedar County Memorial Hospital in El Dorado Springs, Missouri, shut down its IT networks Aug. 14 after a disruption left its electronic health record, patient portal and internet access unavailable. The outage also disrupted diagnostic imaging. Hospital systems could not transmit images to radiologists, so the emergency department partially diverted trauma and critical...

Source

❌