LATEST POST

FEATURE

Stealthy Malware in WordPress Sites Enables Remote Code Execution by Hackers

Vulnerabilities
1100 views 19 secs

GBHackers reports that researchers have uncovered malware targeting WordPress websites, leveraging hidden backdoors to enable remote code execution (RCE): One notable case involved attackers embedding malicious scripts within the Must-Use Plugins (mu-plugins) directory, a special WordPress folder that automatically loads plugins on every page load without requiring activation. By placing obfuscated PHP code in this directory, attackers […]

FEATURE

Thousands of Polish lawyers affected by data breach

Data Breach News
1098 views 52 secs

The personal data of thousands of Polish lawyers and trainee lawyers has been leaked online, exposing social security numbers and password hashes, cybersecurity sources have reported. The breach, first reported by CyberDefence24, occurred on February 14 at around 8:00 PM, with some 10,337 names and 9,037 social security—or PESEL numbers—leaked. The Supreme Bar Council (Naczelna […]

FEATURE

Data Breach Prompts Coast Guard to Take Personnel and Pay System Offline

Data Breach News
1130 views 54 secs

Military.com reports: The Coast Guard‘s personnel and pay system was taken offline Friday and will remain down until at least Feb. 19 while officials investigate a data breach that affected more than 1,100 members. Coast Guard officials said Friday that the service’s Direct Access system, which manages pay and personnel matters, including orders, was hacked Friday, exposing sensitive […]

FEATURE

Brightline to pay $7M to resolve Fortra hack lawsuit

Legal News
1234 views 2 mins

2023 was a bad year for commercial file transfer software apps because the Clop ransomware gang kept managing to find zero-day vulnerabilities to exploit. One of their campaigns involved Fortra’s GoAnywhere software. Even though Fortra issued a patch for CVE-2023-0669 within a week of discovery, there were many victims, including Brightline. Now TechTarget reports that […]

FEATURE

New Lazarus Group campaign sees North Korean hackers spreading undetectable malware through GitHub and open source packages

Data Breach News
1096 views 2 secs

The North Korean state-sponsored threat actor known as Lazaraus Group is now running a campaign targeting software and Web3 developers with “undetectable” malware. MSN reports: Cybersecurity researchers at STRIKE from SecurityScorecard said they observed malware being embedded into GitHub repositories and NPM packages, where unsuspecting developers pick them up and integrate into their own projects. The […]

FEATURE

China-linked APT Salt Typhoon has breached more U.S. telecommunications providers via unpatched Cisco IOS XE network devices.

Data Breach News
1165 views 0 secs

Security Affairs reports: China-linked APT group Salt Typhoon is still targeting telecommunications providers worldwide, and according to a new report published by Recorded Future’s Insikt Group, the threat actors has breached more U.S. telecommunications providers by exploiting unpatched Cisco IOS XE network devices. Insikt Group researchers reported that the Chinese hacked have exploited two Cisco flaws, tracked […]

FEATURE

Ninth Circuit upholds $725M Facebook settlement in Cambridge Analytica case, rejects objectors’ appeal

News
1510 views 8 secs

Courthouse News Service has an update on the Cambridge Analytica settlement. The Ninth Circuit Court of Appeals ruled Thursday afternoon that a federal court did not abuse its discretion in 2023 when it approved a $725 million settlement between Facebook, Inc. — now known as Meta — and a settlement class concerning the Cambridge Analytica scandal, an event in which […]

FEATURE

Should India adopt a threshold-based data breach reporting?

Commentaries and Analyses
797 views 2 mins

MediaNama reports: India needs a threshold-based system for data breach reporting, speakers argued at MediaNama’s discussion on the draft Digital Personal Data Protection Rules (DPDP Rules, 2025) on February 7. This came as a comment during the session on the draft rules around data breaches. MediaNama conducted this discussion under the Chatham House Rule. (Chatham […]