DataBreachToday.com
NY State Fines Dental Plan Firm $2M in Phishing Breach
6 months 4 weeks ago
Healthplex, Part of UnitedHealth Group, Lacked MFA on Compromised Email Account
New York State has fined a dental plan administrator owned by UnitedHealth Group $2 million for failing to protect data with multifactor authentication and other issues related to a phishing breach that affected 90,000 people. It's the state's second fine against Healthplex for the same breach.
New York State has fined a dental plan administrator owned by UnitedHealth Group $2 million for failing to protect data with multifactor authentication and other issues related to a phishing breach that affected 90,000 people. It's the state's second fine against Healthplex for the same breach.
Accounting Firm Pays Feds $175K for HIPAA Ransomware Breach
6 months 4 weeks ago
Settlement Includes Corrective Action Plan Focused on Improving Risk Analysis
An investigation into a ransomware breach reported in 2020 as affecting the protected personal information of 170,000 people led to a $175,000 fine against a certified public accounting and consulting firm. Regulators also required the company to implement a corrective action plan in the settlement.
An investigation into a ransomware breach reported in 2020 as affecting the protected personal information of 170,000 people led to a $175,000 fine against a certified public accounting and consulting firm. Regulators also required the company to implement a corrective action plan in the settlement.
Why the US Needs New Policies to Fight Scams
6 months 4 weeks ago
Fraud Expert Trace Fooshee on Regulatory Steps Needed to Curb Payment Scams
While the U.K. and Australia have mobilized multiple sectors to tackle payment scams, the United States faces complex hurdles. The U.S. can't replicate other regulatory models but it can pursue targeted actions such as regulating scam-prone ad platforms and creating a central fraud-fighting agency.
While the U.K. and Australia have mobilized multiple sectors to tackle payment scams, the United States faces complex hurdles. The U.S. can't replicate other regulatory models but it can pursue targeted actions such as regulating scam-prone ad platforms and creating a central fraud-fighting agency.
Cisco Patches Maximum-Severity Firewall Flaw
6 months 4 weeks ago
Cisco Secure Firewall Management Centers Connected to RADIUS Left Vulnerable
Networking equipment giant Cisco warned firewall customers to patch after discovering a maximum-severity vulnerability that could allow unauthenticated hackers to commandeer the server. The flaw rates a maximum score of 10 on the CVSS system.
Networking equipment giant Cisco warned firewall customers to patch after discovering a maximum-severity vulnerability that could allow unauthenticated hackers to commandeer the server. The flaw rates a maximum score of 10 on the CVSS system.
Ransomware Allegations Surface as Colt Outages Continue
6 months 4 weeks ago
Support Portals Offline as Ransomware Gang Claims It Stole Data
British-based multinational telecom Colt Technology Services said a "cyber incident" is responsible for days-long disruptions to its customer portal and support services. The WarLock ransomware operation took responsibility for the hack, asserting it stole "1 million documents."
British-based multinational telecom Colt Technology Services said a "cyber incident" is responsible for days-long disruptions to its customer portal and support services. The WarLock ransomware operation took responsibility for the hack, asserting it stole "1 million documents."
How OT Device Flaws Can Threaten Hospital Operations
7 months ago
Recent advisories from U.S. federal authorities on vulnerabilities in certain operational technology devices underscore the potential security risks that many healthcare providers frequently underestimate, said Sila Özeren, a security research engineer at Picus Security.
Navigating Multiple State AI Laws in the Wake of US Deregulation
7 months ago
Schellman CEO Avani Desai on Balancing Innovation and Compliance in Uncertain Market
The Trump administration’s AI action plan signals a major deregulatory shift, setting up a patchwork of state regulations on AI deployments. Company policies must be “flexible enough to meet the strictest state without rewriting them every few months," said Avani Desai, CEO, Schellman.
The Trump administration’s AI action plan signals a major deregulatory shift, setting up a patchwork of state regulations on AI deployments. Company policies must be “flexible enough to meet the strictest state without rewriting them every few months," said Avani Desai, CEO, Schellman.
How Cybersecurity Helped Estonia Carve a Niche in Space
7 months ago
Space Policy and Tech Head Paul Liias on Dealing With Satellite Vulnerabilities
A major disruption of civil and military satellites could cause chaos on the ground to communications, navigation and other vital services. But the threats don't just come from missiles. They also comes from hackers who could exploit numerous vulnerabilities, said Estonia's Paul Liias.
A major disruption of civil and military satellites could cause chaos on the ground to communications, navigation and other vital services. But the threats don't just come from missiles. They also comes from hackers who could exploit numerous vulnerabilities, said Estonia's Paul Liias.
Rethinking Software Supply Chain Security
7 months ago
Cyfinoid's Shrivastava Calls for Greater Visibility Over Software Security Risks
Software supply chain security is all too often viewed through a narrow lens, focused mostly on code dependencies and Software Bill of Materials. But the devil remains in the details and risks can emerge from overlooked areas, said Anant Shrivastava, founder and chief researcher at Cyfinoid.
Software supply chain security is all too often viewed through a narrow lens, focused mostly on code dependencies and Software Bill of Materials. But the devil remains in the details and risks can emerge from overlooked areas, said Anant Shrivastava, founder and chief researcher at Cyfinoid.
AI Worker Digital Twins Pose New Insider Threats
7 months ago
Researchers Say AI Bots Blur Lines Between Identity, Consent and Cyber Defense
As generative AI programs continue to evolve, they are introducing new threats to the modern workplace. Digital twins, once confined to industrial systems, now enable hyper-realistic copies of actual employees to mimic vocal patterns, behaviors and even pick up on decision-making trends.
As generative AI programs continue to evolve, they are introducing new threats to the modern workplace. Digital twins, once confined to industrial systems, now enable hyper-realistic copies of actual employees to mimic vocal patterns, behaviors and even pick up on decision-making trends.
From Awareness to Action: Building Lasting Cybersecurity Habits
7 months ago
Every October, organizations revisit the same cybersecurity routines. "Security is everyone’s responsibility,” makes the rounds. However, if awareness alone were enough, we would not see so many security incidents linked to human behavior.
Hackers Breach Canadian Government Via Microsoft Exploit
7 months ago
Microsoft Urges Immediate Mitigation as State Actors Target SharePoint Flaw
Hackers breached a sensitive database containing office locations and personal details of elected officials and staff in Canada's House of Commons. Hackers were able to "exploit a recent Microsoft vulnerability," according to an internal email sent to members and staff.
Hackers breached a sensitive database containing office locations and personal details of elected officials and staff in Canada's House of Commons. Hackers were able to "exploit a recent Microsoft vulnerability," according to an internal email sent to members and staff.
US Sanctions Crypto Exchange Tied to Russian Ransomware
7 months ago
US Treasury Says Crypto Exchange Helped Launder $100 Million for Ransomware Gangs
The U.S. Department of Treasury sanctioned Thursday a Russian founder and co-owners of the Garantex cryptocurrency exchange in a bid to tighten methods criminal hackers use to launder extortion money and Kremlin sanctions busting. Regulators also sanctioned Garantex successor Grinex.
The U.S. Department of Treasury sanctioned Thursday a Russian founder and co-owners of the Garantex cryptocurrency exchange in a bid to tighten methods criminal hackers use to launder extortion money and Kremlin sanctions busting. Regulators also sanctioned Garantex successor Grinex.
North Korean Hackers Launch New Cyber Assault on South Korea
7 months ago
Report North Korean Hacking Group Adds Ransomware to Traditional Playbook
A ScarCruft subgroup dubbed "ChinopuNK" has launched a disruptive ransomware campaign across South Korea, using phishing lures, AutoIt loaders and microphone-capturing malware - marking a major change in the North Korean hacking group's traditionally espionage-focused cyber tactics.
A ScarCruft subgroup dubbed "ChinopuNK" has launched a disruptive ransomware campaign across South Korea, using phishing lures, AutoIt loaders and microphone-capturing malware - marking a major change in the North Korean hacking group's traditionally espionage-focused cyber tactics.
Middle Eastern Organizations Targeted With Charon Ransomware
7 months ago
New Ransomware Possibly Linked to Earth Baxia
A previously uncatalogued ransomware strain is targeting public sector and aviation organizations in the Middle East. The threat actor uses techniques similar to a previously documented hacking group tracked as Earth Baxia and likely based in China.
A previously uncatalogued ransomware strain is targeting public sector and aviation organizations in the Middle East. The threat actor uses techniques similar to a previously documented hacking group tracked as Earth Baxia and likely based in China.
Man Charged in Cyberstalking the Widow of Slain UHC CEO
7 months ago
Experts Warn of Expanding Intersection of Digital and Physical Threats to Victims
Federal prosecutors have charged a New York man with criminal cyberstalking the widow of murdered UnitedHealthCare CEO Brian Thompson. Experts say the case spotlights the ongoing convergence of physical violence and digital threats facing executives, their families and others.
Federal prosecutors have charged a New York man with criminal cyberstalking the widow of murdered UnitedHealthCare CEO Brian Thompson. Experts say the case spotlights the ongoing convergence of physical violence and digital threats facing executives, their families and others.
Breach Roundup: Russian Hackers Attacked Norwegian Dam
7 months ago
Also: Spain Defies Pressure to Eject Huawei, Hackers Leak North Korea Kimsuky Data
This week, Norway said Russian hackers attacked a flood gate, Spain defied pressure to eject Huawei, a cyberattack against the Office of the Pennsylvania Attorney General. Hackers leaked stolen North Korean Kimsuky data, Microsoft patched a Kerberos zero-day and a big Chrome bug bounty.
This week, Norway said Russian hackers attacked a flood gate, Spain defied pressure to eject Huawei, a cyberattack against the Office of the Pennsylvania Attorney General. Hackers leaked stolen North Korean Kimsuky data, Microsoft patched a Kerberos zero-day and a big Chrome bug bounty.
Beware FIDO-Downgrade Attacks Bypassing Phishing Defenses
7 months ago
Proof-of-Concept Attack Demonstrates FIDO Downgrade Against Microsoft Entra ID
The FIDO standard, a bulwark against credential-stealing phishing attacks, has an implementation chink that's poised for commoditization by cybercriminals, say security researchers in news that's good for phishing-as-a-service providers but terrible for everyone else.
The FIDO standard, a bulwark against credential-stealing phishing attacks, has an implementation chink that's poised for commoditization by cybercriminals, say security researchers in news that's good for phishing-as-a-service providers but terrible for everyone else.
Cryptohack Roundup: Do Kwon Pleads Guilty in $40B Fraud Case
7 months ago
Also: Trump Signs Pro-Crypto EO, Credix Disappears After $4.5M Hack
Every week, Information Security Media Group rounds up cybersecurity incidents in digital assets. This week, includes Do Kwon's guilty plea, Trump's crypto-linked executive order, Credix's post-hack disappearance, $7M Odin.fun exploit and hackers using fake Firefox crypto wallet extensions for theft.
Every week, Information Security Media Group rounds up cybersecurity incidents in digital assets. This week, includes Do Kwon's guilty plea, Trump's crypto-linked executive order, Credix's post-hack disappearance, $7M Odin.fun exploit and hackers using fake Firefox crypto wallet extensions for theft.
Checked
2 hours 18 minutes ago
DataBreachToday.com RSS News Feeds on data breach today news, regulations, blogs and education
DataBreachToday.com feed