DataBreachToday.com
New York AG Sues Zelle Over Alleged Poor Cybersecurity
7 months ago
Zelle Provider Allowed $1 Billion of Fraudulent Transactions, Prosecutors Say
The state of New York is suing the privately held fintech company behind the Zelle money transfer system in a complaint that alleges years of poor cybersecurity and protections against fraud. The New York complaint targets Early Warning Services, the company behind the money transfer app.
The state of New York is suing the privately held fintech company behind the Zelle money transfer system in a complaint that alleges years of poor cybersecurity and protections against fraud. The New York complaint targets Early Warning Services, the company behind the money transfer app.
Federal Judiciary Breach Highlights Poor Cybersecurity
7 months ago
Congress Pressed to Fund Federal Court System Cyber Upgrades Amid Escalating Risks
A breach of the U.S. national court filing system intensified concerns over the federal judiciary's cybersecurity, with critics urging reforms and congressional funding to close gaps that could expose sealed cases, confidential informants and other sensitive information.
A breach of the U.S. national court filing system intensified concerns over the federal judiciary's cybersecurity, with critics urging reforms and congressional funding to close gaps that could expose sealed cases, confidential informants and other sensitive information.
Feds Issue More HIPAA Guidance in Push for Patient Access
7 months ago
HHS Says New FAQs Support HHS' 'Make Health IT Great Again' Interoperability Effort
Federal regulators issued updated HIPAA privacy rule guidance that aims to clarify when patients' protected health information can be shared with value-based care organizations, and also the types of health records that patients have a right to access upon request. Does it cover any new ground?
Federal regulators issued updated HIPAA privacy rule guidance that aims to clarify when patients' protected health information can be shared with value-based care organizations, and also the types of health records that patients have a right to access upon request. Does it cover any new ground?
Erlang/OTP SSH Exploits Spiked After April Patch
7 months ago
Majority of Attacks Target Operational Technology Networks
Exploitation attempts against a severe vulnerability in a runtime system widely deployed in operational technology environments spiked globally in the days after open-source maintainers of the Erlang/OTP project published a patch. Attackers could take full control of systems.
Exploitation attempts against a severe vulnerability in a runtime system widely deployed in operational technology environments spiked globally in the days after open-source maintainers of the Erlang/OTP project published a patch. Attackers could take full control of systems.
Data Theft From Dutch Cancer Screening Lab Affects 485,000
7 months ago
Clinical Diagnostics Lab Hack Among Latest Recent Cyberattacks in the Netherlands
A Dutch population health research agency is notifying 485,000 participants of a cervical cancer screening program of a hacking incident at a clinical diagnostics laboratory that potentially compromised patients' personal and health information, including lab test results.
A Dutch population health research agency is notifying 485,000 participants of a cervical cancer screening program of a hacking incident at a clinical diagnostics laboratory that potentially compromised patients' personal and health information, including lab test results.
Russian Hackers Exploit WinRAR Zero-Day
7 months ago
RomCom Group Deployed SnipBot, RustyClaw and Mythic Agent Variants
A Russian speaking hacking group is exploiting a zero-day flaw in WinRAR, a sign of the group's growing sophistication and evolution from a cybercrime outfit into a cyberespionage operation. The campaign exploited a vulnerability now tracked as CVE-2025-8088, a path traversal vulnerability.
A Russian speaking hacking group is exploiting a zero-day flaw in WinRAR, a sign of the group's growing sophistication and evolution from a cybercrime outfit into a cyberespionage operation. The campaign exploited a vulnerability now tracked as CVE-2025-8088, a path traversal vulnerability.
Russia Accused of Hacking Sensitive US Court Filing System
7 months ago
US Reportedly Blames Kremlin for Major Breach Affecting Court Management System
U.S. Department of Justice officials were reportedly recently informed that "persistent and sophisticated cyberthreat actors have recently compromised sealed records" in a widespread attack on a court management system containing sensitive records with potential national security implications.
U.S. Department of Justice officials were reportedly recently informed that "persistent and sophisticated cyberthreat actors have recently compromised sealed records" in a widespread attack on a court management system containing sensitive records with potential national security implications.
AI Firms Race to Offer Feds Low Cost Contracts
7 months ago
OpenAI, Anthropic Launch $1 Year-Long Offerings as Critics Warn of Vendor Lock-In
Leading artificial intelligence firms are racing to introduce services to federal agencies with ultra low-cost first-year contracts, despite warnings that the bids may lead to vendor lock-in, compliance risks and future challenges adopting emerging technology offerings from competitors.
Leading artificial intelligence firms are racing to introduce services to federal agencies with ultra low-cost first-year contracts, despite warnings that the bids may lead to vendor lock-in, compliance risks and future challenges adopting emerging technology offerings from competitors.
Dutch Investigators Blame Hacks on Multiple Threat Actors
7 months ago
NCSC-NL Says Hack of Citrix NetScaler Flaw Also Targeted Critical Infrastructure
A preliminary assessment by the Dutch NCSC into a suspected Russian hacking campaign has concluded that more than one group likely carried out the May breach of the country’s law enforcement network. Investigators say hacks of Citrix NetScaler flaw also targeted critical infrastructure.
A preliminary assessment by the Dutch NCSC into a suspected Russian hacking campaign has concluded that more than one group likely carried out the May breach of the country’s law enforcement network. Investigators say hacks of Citrix NetScaler flaw also targeted critical infrastructure.
Service Providers Are Risking Security for User Retention
7 months ago
Bell Labs' Siddharth Rao on the Need for Stronger Safeguards in Account Recovery
Many service providers are prioritizing usability over security in account recovery to retain users. Siddharth Rao, senior security research scientist at Nokia Bell Labs, says this trade-off exposes systems to threats through vulnerable recovery channels and inconsistent policies.
Many service providers are prioritizing usability over security in account recovery to retain users. Siddharth Rao, senior security research scientist at Nokia Bell Labs, says this trade-off exposes systems to threats through vulnerable recovery channels and inconsistent policies.
Third-Party Risk Set to Reshape AI Security
7 months ago
Lytical Ventures' Taylor Margot on Autonomous Agents and New AI Defenses
As AI shifts toward autonomous agents, organizations face growing exposure from third-party systems. Strong permissioning, data orchestration and new defenses are essential to protect against opaque and potentially costly security risks, said Taylor Margot, partner at Lytical Ventures.
As AI shifts toward autonomous agents, organizations face growing exposure from third-party systems. Strong permissioning, data orchestration and new defenses are essential to protect against opaque and potentially costly security risks, said Taylor Margot, partner at Lytical Ventures.
Pediatric Practice, IT Vendor Settle $5.15M Breach Suit
7 months ago
At Least 918K Affected in 2024 BianLian Data Theft Attack
A New York-based pediatric practice and its managed services vendor have agreed to pay $5.15 million to settle a proposed class action lawsuit stemming from a 2024 data theft attack affecting more than 918,000 people and allegedly carried out by cybercrime gang BianLian.
A New York-based pediatric practice and its managed services vendor have agreed to pay $5.15 million to settle a proposed class action lawsuit stemming from a 2024 data theft attack affecting more than 918,000 people and allegedly carried out by cybercrime gang BianLian.
Dutch Investigators Blame Multiple Threat Actors on Hacks
7 months ago
NCSC-NL Says Hack of Citrix NetScaler Flaw Also Targeted Critical Infrastructure
A preliminary assessment by the Dutch NCSC into a suspected Russian hacking campaign has concluded that more than one group likely carried out the May breach of the country’s law enforcement network. Investigators say hacks of Citrix NetScaler flaw also targeted critical infrastructure.
A preliminary assessment by the Dutch NCSC into a suspected Russian hacking campaign has concluded that more than one group likely carried out the May breach of the country’s law enforcement network. Investigators say hacks of Citrix NetScaler flaw also targeted critical infrastructure.
GPT-5 Launch Meets With Praise, User Pushback and Price Wars
7 months ago
CEO Altman Promises Fixes to 'Way Dumber' Performance, Transparency Amid Glitches
When OpenAI unveiled GPT-5, the company promised a smarter, faster AI at a bargain price. But day-one glitches prompted some users to call for a return to GPT-4. The company’s CEO apologized for the problems as OpenAI cut its pricing model and set up a potential large language model price war.
When OpenAI unveiled GPT-5, the company promised a smarter, faster AI at a bargain price. But day-one glitches prompted some users to call for a return to GPT-4. The company’s CEO apologized for the problems as OpenAI cut its pricing model and set up a potential large language model price war.
Ghanaians Extradited to Face US Romance Scam and BEC Charges
7 months ago
$150 Million Stolen From Victims and Laundered, Allege Federal Prosecutors
Four Ghanian nationals have been charged with stealing more than $100 million by perpetrating romance scams and business email compromises against U.S. organizations, as well as laundering the stolen proceeds. Three of the suspects have been extradited to the United States to stand trial.
Four Ghanian nationals have been charged with stealing more than $100 million by perpetrating romance scams and business email compromises against U.S. organizations, as well as laundering the stolen proceeds. Three of the suspects have been extradited to the United States to stand trial.
Why AI Security Needs Continuous Red Teaming
7 months ago
NIST's Apostol Vassilev Explains Need for Dynamic Response, Not Static Testing
As AI models grow in scale and power, leading to even more unpredictable outcomes, security teams are grappling with how to defend technologies that some experts can't begin to fully comprehend. Cyber response teams are exploring the practice of continuous red teaming, said NIST's Apostol Vassilev.
As AI models grow in scale and power, leading to even more unpredictable outcomes, security teams are grappling with how to defend technologies that some experts can't begin to fully comprehend. Cyber response teams are exploring the practice of continuous red teaming, said NIST's Apostol Vassilev.
How Insurers Use Threat Intelligence to Reduce Losses
7 months ago
Tokio Marine HCC Targets Vulnerabilities Before They’re Exploited
With ransomware incidents at record highs, Tokio Marine HCC integrates dark web monitoring, vulnerability scanning and incident data into its underwriting process to help clients close gaps and lower the chance of costly breaches.
With ransomware incidents at record highs, Tokio Marine HCC integrates dark web monitoring, vulnerability scanning and incident data into its underwriting process to help clients close gaps and lower the chance of costly breaches.
Insurance Firm Notifies 156K Victims - 1 Year After the Hack
7 months 1 week ago
What Makes Timely and Accurate Breach Reporting So Difficult for Some Organizations?
An Illinois-based brokerage firm that works with employers, businesses and consumers to obtain various types of insurance coverage is notifying nearly 156,000 people that their protected health information was compromised in a data theft hack that occurred more than a year ago. Why the delay?
An Illinois-based brokerage firm that works with employers, businesses and consumers to obtain various types of insurance coverage is notifying nearly 156,000 people that their protected health information was compromised in a data theft hack that occurred more than a year ago. Why the delay?
EU Cyber Index Reveals Strengths and Setbacks
7 months 1 week ago
ENISA's Laura Heuvinck Shares Index Findings, Implications for EU Cybersecurity
In the latest EU Cybersecurity Index, member states scored an average of 64.51 out of 100, reflecting a moderately strong level of preparedness for cyber incidents. ENISA's Laura Heuvinck breaks down the findings and key areas for improving Europe's cybersecurity posture.
In the latest EU Cybersecurity Index, member states scored an average of 64.51 out of 100, reflecting a moderately strong level of preparedness for cyber incidents. ENISA's Laura Heuvinck breaks down the findings and key areas for improving Europe's cybersecurity posture.
Checked
3 hours 52 minutes ago
DataBreachToday.com RSS News Feeds on data breach today news, regulations, blogs and education
DataBreachToday.com feed