Aggregator
McLaren Health Will Pay $14M to Settle Lawsuits in 2 Attacks
1 day 20 hours ago
2023 and 2024 Ransomware Breaches Affected More Than 2.5M
Michigan-based McLaren Health Care has agreed to pay $14 million to settle consolidated class action litigation involving two ransomware attacks - allegedly by Alphv/BlackCat in 2023 and by Inc Ransom in 2024 - that affected about 2.5 million patients and employees.
Michigan-based McLaren Health Care has agreed to pay $14 million to settle consolidated class action litigation involving two ransomware attacks - allegedly by Alphv/BlackCat in 2023 and by Inc Ransom in 2024 - that affected about 2.5 million patients and employees.
AI Is Transforming the Chief Data Officer Role
1 day 20 hours ago
AI Elevates CDO Job From Gatekeeper to Data-Driven Change Agent
The chief data officer is being pushed out of the shadows and into the C-suite spotlight with the rise of AI. While the role emerged as one rooted in compliance and risk management, it has evolved to be a business driver, holding the keys to value creation and human-centered transformation.
The chief data officer is being pushed out of the shadows and into the C-suite spotlight with the rise of AI. While the role emerged as one rooted in compliance and risk management, it has evolved to be a business driver, holding the keys to value creation and human-centered transformation.
Norway Says Salt Typhoon Hackers Hit Vulnerable Systems
1 day 20 hours ago
Security Service Says China-Linked Actor Compromised Vulnerable Network Devices
Norway's security service confirmed it was targeted by the China-linked Salt Typhoon campaign, marking one of Europe’s clearest public acknowledgements that the cyberespionage operation extended beyond U.S. telecom and federal networks into allied infrastructure.
Norway's security service confirmed it was targeted by the China-linked Salt Typhoon campaign, marking one of Europe’s clearest public acknowledgements that the cyberespionage operation extended beyond U.S. telecom and federal networks into allied infrastructure.
Sanctioned Bulletproof Host Tied to DNS Hijacking
1 day 20 hours ago
Shadow Aeza International Directed Traffic to Malicious Adtech
A financially motivated threat actor hacked dozens of domain name system resolvers, connecting them to the infrastructure of a Russian bulletproof hosting service sanctioned by the U.S. Department of Treasury for its criminal links, researchers found.
A financially motivated threat actor hacked dozens of domain name system resolvers, connecting them to the infrastructure of a Russian bulletproof hosting service sanctioned by the U.S. Department of Treasury for its criminal links, researchers found.
Admin Rights Are a Vulnerability, Not an Enabler
1 day 20 hours ago
Enabling Practical Endpoint Control Without Productivity Trade-offs
Removing local admin rights often creates helpdesk and user friction. An identity-first model reduces risk while keeping business operational. Join CyberArk's practical webinar session to learn how identity-first endpoint control replaces standing admin rights with just-in-time access.
Removing local admin rights often creates helpdesk and user friction. An identity-first model reduces risk while keeping business operational. Join CyberArk's practical webinar session to learn how identity-first endpoint control replaces standing admin rights with just-in-time access.
Webinar | Beyond Compliance: Building True Cyber Resilience
1 day 20 hours ago
Webinar | From Compliant to Cyber Ready: Closing the Gap
1 day 20 hours ago
Webinar | Connected Resilience: Lessons in Cyber Collaboration from City, County, and State Leaders
1 day 20 hours ago
McLaren Health Will Pay $14M to Settle Lawsuits in 2 Attacks
1 day 20 hours ago
2023 and 2024 Ransomware Breaches Affected More Than 2.5M
Michigan-based McLaren Health Care has agreed to pay $14 million to settle consolidated class action litigation involving two ransomware attacks - allegedly by Alphv/BlackCat in 2023 and by Inc Ransom in 2024 - that affected about 2.5 million patients and employees.
Michigan-based McLaren Health Care has agreed to pay $14 million to settle consolidated class action litigation involving two ransomware attacks - allegedly by Alphv/BlackCat in 2023 and by Inc Ransom in 2024 - that affected about 2.5 million patients and employees.
AI Is Transforming the Chief Data Officer Role
1 day 20 hours ago
AI Elevates CDO Job From Gatekeeper to Data-Driven Change Agent
The chief data officer is being pushed out of the shadows and into the C-suite spotlight with the rise of AI. While the role emerged as one rooted in compliance and risk management, it has evolved to be a business driver, holding the keys to value creation and human-centered transformation.
The chief data officer is being pushed out of the shadows and into the C-suite spotlight with the rise of AI. While the role emerged as one rooted in compliance and risk management, it has evolved to be a business driver, holding the keys to value creation and human-centered transformation.
Norway Says Salt Typhoon Hackers Hit Vulnerable Systems
1 day 20 hours ago
Security Service Says China-Linked Actor Compromised Vulnerable Network Devices
Norway's security service confirmed it was targeted by the China-linked Salt Typhoon campaign, marking one of Europe’s clearest public acknowledgements that the cyberespionage operation extended beyond U.S. telecom and federal networks into allied infrastructure.
Norway's security service confirmed it was targeted by the China-linked Salt Typhoon campaign, marking one of Europe’s clearest public acknowledgements that the cyberespionage operation extended beyond U.S. telecom and federal networks into allied infrastructure.
Sanctioned Bulletproof Host Tied to DNS Hijacking
1 day 20 hours ago
Shadow Aeza International Directed Traffic to Malicious Adtech
A financially motivated threat actor hacked dozens of domain name system resolvers, connecting them to the infrastructure of a Russian bulletproof hosting service sanctioned by the U.S. Department of Treasury for its criminal links, researchers found.
A financially motivated threat actor hacked dozens of domain name system resolvers, connecting them to the infrastructure of a Russian bulletproof hosting service sanctioned by the U.S. Department of Treasury for its criminal links, researchers found.
NIST Allocates Over $3 Million to Small Businesses Advancing AI, Biotechnology, Semiconductors, Quantum and More
1 day 20 hours ago
NIST is allocating funding to eight small businesses in seven states under the Small Business Innovation Research (SBIR) program.
Sarah Henderson
Unpatched SolarWinds WHD instances under active attack
1 day 20 hours ago
Internet‑exposed and vulnerable SolarWinds Web Help Desk (WHD) instances are under attack by threat actors looking to gain an initial foothold into target organizations’ networks, Microsoft and Huntress researchers have warned. Once inside, the attackers are deploying legitimate remote access and digital forensics and incident response tools, using living-off-the-land techniques, setting up a reverse SSH shell, and stealing sensitive data. Attack details The initial access vector is known: SolarWinds WHD vulnerabilities. What’s unknown is which … More →
The post Unpatched SolarWinds WHD instances under active attack appeared first on Help Net Security.
Zeljka Zorz
NCSC Issues Warning Over “Severe” Cyber-Attacks Targeting Critical National Infrastructure
1 day 21 hours ago
NCSC call firms to ‘act now’ following disruptive malware attacks targeting Polish energy providers
Senegal shuts National ID office after ransomware attack
1 day 21 hours ago
Senegal closed its national ID card office after a ransomware cyberattack disrupted ID, passport, and biometric services. Senegal confirmed a cyberattack on the Directorate of File Automation, the government office that manages national ID cards, passports, and biometric data. After ransomware claims surfaced, authorities temporarily closed the office to contain the incident. The agency warned […]
Pierluigi Paganini
ZAST.AI Raises $6M Pre-A to Scale "Zero False Positive" AI-Powered Code Security
1 day 21 hours ago
January 5, 2026, Seattle, USA — ZAST.AI announced the completion of a $6 million Pre-A funding round. This investment came from the well-known investment firm Hillhouse Capital, bringing ZAST.AI's total funding close to $10 million. This marks a recognition from leading capital markets of a new solution: ending the era of high false positive rates in security tools and making every alert
The Hacker News
基于 RPC RID 枚举的协议级实战剖析
1 day 21 hours ago
某次高规格红队攻防演练,团队已在渗透阶段捕获一批明文密码,但始终无法拿到管理人员的用户名来突破网络边界,内网主机均部署了杀软常规横向手段无异于自投罗网。
Enterprise Wi-Fi: The most trusted attack surface you’re NOT testing (and how to fix that)
1 day 21 hours ago
Enterprise Wi-Fi is a high-risk but under-tested attack surface. Learn how modern wireless attacks work and how HTB CWPE builds real-world Wi-Fi pentesting skills.