LATEST POST

FEATURE

Facebook Messenger phishing wave targets 100K business accounts per week

Data Breach News
660 views 45 secs

Hackers use a massive network of fake and compromised Facebook accounts to send out millions of Messenger phishing messages to target Facebook business accounts with password-stealing malware. The attackers trick the targets into downloading a RAR/ZIP archive containing a downloader for an evasive Python-based stealer that grabs cookies and passwords stored in the victim’s browser. […]

FEATURE

Save the Children hit by BianLian extortionist gang

Data Breach News
1184 views 54 secs

BianLian, previously known as a ransomware gang but more recently known for not bothering with encryption but just hacking and exfiltrating data, has reportedly attacked Save the Children, a well-known non-profit. While BianLian did not name the charity (they obfuscate their victims’ names while they are still hoping to get paid), their description of the […]

FEATURE

MGM Resorts Dealing With Significant Cyberattack (Update 3)

Data Breach News
765 views 4 mins

Hotel and casino operator MGM Resorts is dealing with a cyberattack that has somewhat sent it back into the digital dark ages at multiple properties and locations. On September 11, MGM Resorts posted a statement on its Twitter account confirming that it was dealing with what it described as a cybersecurity incident. They did not […]

FEATURE

L.A. Care Healthplan settles HHS OCR charges stemming from multiple violations for $1.3 million and corrective action plan

Healthcare
1401 views 5 mins

Today, the U.S. Department of Health and Human Services’ Office for Civil Rights (OCR) announced a settlement of potential violations of the Health Insurance Portability and Accountability Act (HIPAA) Rules with LA Care, the nation’s largest publicly operated health plan that provides health care benefits and coverage through state, federal, and commercial programs. OCR enforces the HIPAA […]

FEATURE

Dissecting the MOVEit breach: Lessons learned from the ransomware attack

Data Breach News
2332 views 16 secs

The MOVEit data breach, discussed in an earlier post, continues to make headlines. As SDX reports: Orchestrated by ransomware gang CL0P exploiting a zero-day vulnerability, it is now considered one of the largest hacks of 2023 — and potentially in recent history. To date, it is known to have impacted more than 1,150 organizations and nearly 56 million individuals, […]

FEATURE

Rhysida ransomware gang claims responsibility for Singing River Health System attack

Data Breach News
1357 views 59 secs

Rhysida has now added Singing River Health System in Mississippi to their dark web leak site. The health system, which includes Pascagoula Hospital, Ocean Springs Hospital, and Gulfport Hospital as well as 10 clinics discovered the ransomware attack on August 19. In its most recent update of August 31, it stated: “We understand the concerns […]

FEATURE

Your car may be scraping and selling your data, and there isn’t much you can do to stop it

Consumer Alerts
1182 views 42 secs

Car manufacturers are engaging in a “privacy nightmare” by scraping sensitive user data and potentially selling it to unknown actors, according to a new report on the widespread terrible practices in the industry. Mozilla’s Privacy Not Included found 25 major car brands are “terrible at privacy and security” of user data, and their policies allow widespread […]

FEATURE

New SEC Cybersecurity Disclosure Requirements Give Public Companies Only Four Days to Disclose Material Cybersecurity Incidents

Legal News
1094 views 4 secs

This summer, the Securities and Exchange Commission (SEC) adopted rules to enhance and standardize disclosures by public companies regarding cybersecurity risk management, strategy, governance, and incidents.   The rules will impose a number of new requirements, including disclosures regarding: Read more of this article at Workplace Privacy, Data Management & Security Report.