LATEST POST

FEATURE

SonicWall warns hackers targeting critical vulnerability in SMA 1000 series appliances

Vulnerabilities
1065 views 52 secs

Researchers from Microsoft Threat Intelligence alerted the company to suspected threat activity. Cybersecurity Dive reports: SonicWall issued an alert Friday that a critical remote code execution vulnerability in its SMA appliances is under active exploitation by malicious hackers and urged customers to immediately update any vulnerable firmware. Researchers from Microsoft Threat Intelligence had warned SonicWall about the […]

FEATURE

TalkTalk investigates breach after data for sale on hacking forum

Data Breach News
1083 views 4 secs

Bleeping Computer reports: UK telecommunications company TalkTalk is investigating a third-party supplier data breach after a threat actor began selling alleged customer data on a hacking forum. “As part of our regular security monitoring, given our ongoing focus on protecting customers’ personal data, we were made aware of unexpected access to, and misuse of, one […]

FEATURE

ChatGPT API flaw could allow DDoS, prompt injection attacks

Vulnerabilities
1110 views 56 secs

Another day, another vulnerability. CSO Online reports that a researcher discovered an OpenAI development oversight that could allow attackers to launch DDoS attacks on unsuspecting victims: OpenAI-owned ChatGPT might have a vulnerability that could allow threat actors to launch distributed denial of service (DDoS) attacks on unsuspecting targets.   According to a discovery made by German security researcher […]

FEATURE

WORST Healthcare Breach Ever: 1 in 2 Americans affected by UnitedHealth ransomware attack, new disclosure shows

Data Breach News
1266 views 8 secs

The Minnesota Star Tribune reports: UnitedHealth Group says the impact from the cyberattack last year at its Change Healthcare subsidiary is much wider than previously understood, affecting roughly 190 million patients — up from previous estimates of about 100 million people. The updated tally extends the scope beyond what was previously described by company Chief Executive Andrew […]

FEATURE

Simple STARLINK Bug Let Hackers Control Every Connected Subaru

Vulnerabilities
1095 views 24 secs

Security researchers gained complete control of Subaru vehicles worldwide using only basic customer information like license plates or ZIP codes Motor Illustrated reports: Security researchers discovered a critical vulnerability in Subaru‘s STARLINK connected vehicle service that allowed unauthorized access to vehicles and customer data across the United States, Canada, and Japan, according to a blog post published by […]

FEATURE

Patch now: Cisco fixes critical 9.9-rated, make-me-admin bug in Meeting Management

Vulnerabilities
611 views 4 secs

Another day, another critical patch. The Register reports: Cisco has pushed a patch for a critical, 9.9-rated vulnerability in its Meeting Management tool that could allow a remote, authenticated attacker with low privileges to escalate to administrator on affected devices. Cisco Meeting Management is the management software for the tech giant’s on-premises video meeting platform. […]

FEATURE

PowerSchool data breach a ‘statewide issue,’ more than 300,000 teachers had SS number exposed

Education Sector
1249 views 36 secs

On December 28, PowerSchool discovered that its Student Information System (SIS) program had been compromised. Since then, more and more schools in the U.S. and Canada have been notifying parents and students that student information stored in the system — including a lot of historical data on former students — was involved in the breach. […]

FEATURE

New York State Department of Financial Services Secures $2 Million Cybersecurity Settlement with PayPal, Inc.

Finance
1429 views 2 mins

PayPal’s Cybersecurity Failures Led to the Exposure of Customers’ Social Security Numbers January 23, 2025 New York State Department of Financial Services Superintendent Adrienne A. Harris today announced that PayPal, Inc. (PayPal) will pay a $2 million penalty to New York State for violations of DFS’s Cybersecurity Regulation. An investigation determined PayPal failed to use qualified […]