DataBreachToday.com
Ukrainian Signal Users Fall to Russian Social Engineering
1 month 1 week ago
Google Expects Tactics to Spread; Global Targets and Other Services at Risk
Russian nation-state hackers are using phishing attacks to target Ukrainian users of the chat app Signal, say security researchers. Rather than circumventing Signal's end-to-end encryption via a cryptographic attack, attackers use malicious prompting to prod victims into exposing messages.
Russian nation-state hackers are using phishing attacks to target Ukrainian users of the chat app Signal, say security researchers. Rather than circumventing Signal's end-to-end encryption via a cryptographic attack, attackers use malicious prompting to prod victims into exposing messages.
API Security Matters: The Risks of Turning a Blind Eye
1 month 2 weeks ago
Live Webinar | Evaluating Cybersecurity Proposals – The Secret Formula
1 month 2 weeks ago
Live Webinar | The Future of Manufacturing IT: Trends & Best Practices
1 month 2 weeks ago
Clinical Trial Database Exposes 1.6M Records to Web
1 month 2 weeks ago
Researcher Says Firm Failed to Secure Sensitive Health Data From Survey Forms
An unsecured database containing 2 terabytes of data allegedly exposed more than 1.6 million clinical research records to the internet, including sensitive personal and medical information of patients, said the security researcher who discovered the lapse. Why does this keep happening?
An unsecured database containing 2 terabytes of data allegedly exposed more than 1.6 million clinical research records to the internet, including sensitive personal and medical information of patients, said the security researcher who discovered the lapse. Why does this keep happening?
North Korea Stealing Cryptocurrency With JavaScript Implant
1 month 2 weeks ago
'Marstech1' Malware Targets Developers Through GitHub Repository
New North Korean malware is targeting crypto wallets with an unconventional command-and-control infrastructure and through malware embedded into a GitHub repository that's apparently the account of a Pyongyang hacker. The implant appears to have emerged late last December.
New North Korean malware is targeting crypto wallets with an unconventional command-and-control infrastructure and through malware embedded into a GitHub repository that's apparently the account of a Pyongyang hacker. The implant appears to have emerged late last December.
Dream Raises $100M to Strengthen AI-Driven National Security
1 month 2 weeks ago
Investment Led by Bain Capital to Enhance Predictive Threat Detection Capabilities
Dream raised $100 million in Series B funding from Bain Capital on a $1.1 billion valuation to enhance its proprietary Cyber Language Model and expand globally, with a focus on U.S. market entry to address growing national security threats through AI-driven cybersecurity and predictive solutions.
Dream raised $100 million in Series B funding from Bain Capital on a $1.1 billion valuation to enhance its proprietary Cyber Language Model and expand globally, with a focus on U.S. market entry to address growing national security threats through AI-driven cybersecurity and predictive solutions.
DOGE Team Wins Legal Battle, Retains Access to Federal Data
1 month 2 weeks ago
Court Clears Way for Musk's DOGE Team to Continue Accessing Sensitive Federal Data
A federal judge has ruled against a lawsuit from 14 state attorneys general requesting a temporary restraining order against Elon Musk and the Department of Government Efficiency amid controversy surrounding the billionaire's access to sensitive government systems.
A federal judge has ruled against a lawsuit from 14 state attorneys general requesting a temporary restraining order against Elon Musk and the Department of Government Efficiency amid controversy surrounding the billionaire's access to sensitive government systems.
Is Russia Reining In Ransomware-Wielding Criminals?
1 month 2 weeks ago
Flurry of Arrests a Potential Prelude to Russia-Ukraine Peace Negotiations
Even before Donald Trump took office on Jan. 20, there were signs that Russian President Vladimir Putin ordered cybercriminals operating inside his country's borders to be reined in, potentially as a bargaining chip in negotiations over Russia's stalemated war of conquest against Ukraine.
Even before Donald Trump took office on Jan. 20, there were signs that Russian President Vladimir Putin ordered cybercriminals operating inside his country's borders to be reined in, potentially as a bargaining chip in negotiations over Russia's stalemated war of conquest against Ukraine.
Why Some States Are Beefing Up Their Health Cyber Regs
1 month 2 weeks ago
States will increasingly be stepping up to fill gaps in the healthcare sector with new cyber legislation and requirements as the Trump administration promises to roll back regulations, predicts attorney Amy Magnano of the law firm Morgan Lewis' healthcare practice.
Researchers Caution AI Benchmark Score Reliability
1 month 2 weeks ago
Leaderboard Race May Be More Marketing Than Merit
Artificial intelligence model makers routinely publish benchmark scores of their performance, but the leaderboard race may be more of an exercise in marketing than an accurate reflection of the models' abilities. Understanding model failures can be more valuable than celebrating high scores.
Artificial intelligence model makers routinely publish benchmark scores of their performance, but the leaderboard race may be more of an exercise in marketing than an accurate reflection of the models' abilities. Understanding model failures can be more valuable than celebrating high scores.
Italian Privacy Agency Warns Against Unlawful Spyware Use
1 month 2 weeks ago
Use Other Than for Police Purposes Can Invoke Fine Up to 20 Million Euros
The Italian Data Protection Authority warned against unlawful use of Graphite spyware following reports of mass hacking campaigns using the tool. The Italian privacy regulator published a warning targeting commercial spyware developed by Israeli firm Paragon Solutions.
The Italian Data Protection Authority warned against unlawful use of Graphite spyware following reports of mass hacking campaigns using the tool. The Italian privacy regulator published a warning targeting commercial spyware developed by Israeli firm Paragon Solutions.
Attackers Exploit Palo Alto Zero-Day Authentication Bypass
1 month 2 weeks ago
Surge in Attack Attempts Spotted After Palo Alto Networks Details and Patches Flaw
Attackers have stepped up efforts to exploit a vulnerability in the software that runs Palo Alto Networks firewall appliances that could give them direct access to the underlying software. Unauthenticated hackers could use PHP scripts to bypass the PAN-OS management web interface.
Attackers have stepped up efforts to exploit a vulnerability in the software that runs Palo Alto Networks firewall appliances that could give them direct access to the underlying software. Unauthenticated hackers could use PHP scripts to bypass the PAN-OS management web interface.
Why Private Equity Is Now Kicking the Tires on Trend Micro
1 month 2 weeks ago
Sluggish Sales Growth and Lower Relevance in Endpoint Could Make Trend Attractive
Endpoint security vendors are changing up their ownership or business models as Microsoft and CrowdStrike increasingly blot out the sun in this rapidly consolidating market. Reuters said that Advent International, Bain Capital, EQT AB and KKR have expressed interest in taking Trend Micro private.
Endpoint security vendors are changing up their ownership or business models as Microsoft and CrowdStrike increasingly blot out the sun in this rapidly consolidating market. Reuters said that Advent International, Bain Capital, EQT AB and KKR have expressed interest in taking Trend Micro private.
Court: UnitedHealth Must Answer for AI-Based Claim Denials
1 month 2 weeks ago
Lawsuit Alleges Insurer Used AI Tool in Denying Patients Medically Necessary Care
A proposed class action lawsuit against UnitedHealth Group, which claims the company's insurance unit UnitedHealthcare used artificial intelligence tools to deny Medicare Advantage claims for medically necessary care, has the green light to proceed from a federal judge.
A proposed class action lawsuit against UnitedHealth Group, which claims the company's insurance unit UnitedHealthcare used artificial intelligence tools to deny Medicare Advantage claims for medically necessary care, has the green light to proceed from a federal judge.
The Crux of Security Awareness: Stopping 'Death Clickers'
1 month 2 weeks ago
Who Are 'Death Clickers,' and How Do They Weaken Company's Cyber Defense?
Employees who repeatedly click on malicious links or "death clickers" are a risk to an organization's cybersecurity. This blog explains how awareness, behavior testing and simulations can help organizations strengthen their cybersecurity culture and manage human risks.
Employees who repeatedly click on malicious links or "death clickers" are a risk to an organization's cybersecurity. This blog explains how awareness, behavior testing and simulations can help organizations strengthen their cybersecurity culture and manage human risks.
Live Webinar | Get Off the Assessment Treadmill. Take a Data-First, Questionnaire-Second Approach to TPRM
1 month 2 weeks ago
Emerging Legal Considerations of AI Governance
1 month 2 weeks ago
Legal Experts Marian Waldmann Agarwal and Marijn Storm on Impact of AI Regulations
AI regulations are tightening, bringing new compliance challenges, especially for high-risk systems. Morrison Foerster partners Marian Waldmann Agarwal and Marijn Storm explain how EU and Colorado AI regulations are reshaping governance and security requirements for organizations.
AI regulations are tightening, bringing new compliance challenges, especially for high-risk systems. Morrison Foerster partners Marian Waldmann Agarwal and Marijn Storm explain how EU and Colorado AI regulations are reshaping governance and security requirements for organizations.
AI Action Summit and Regulatory Concerns That Won't Go Away
1 month 2 weeks ago
Forrester's Thomas Husson on Reactions to DeepSeek, Fears of Overregulation
The AI Action Summit this week came on the heels of the DeepSeek-R1 launch by Chinese AI company, as well as recent enforcement actions of the EU AI Act. A number of leaders from both inside and outside of Europe criticized the EU law, fearing that new regulations will stymie innovation.
The AI Action Summit this week came on the heels of the DeepSeek-R1 launch by Chinese AI company, as well as recent enforcement actions of the EU AI Act. A number of leaders from both inside and outside of Europe criticized the EU law, fearing that new regulations will stymie innovation.
Checked
5 hours 46 minutes ago
DataBreachToday.com RSS News Feeds on data breach today news, regulations, blogs and education
DataBreachToday.com feed