LATEST POST
How sweet it isn’t: Hershey’s notifies 2,214 after phishing attack
ABC reports: The Hershey Company headquartered in Pennsylvania is notifying some customers their data may have been compromised. The data breach happened between September 3 and September 4, and it impacted 2,214 people, according to the company’s filing with the Maine Attorney General. This data included first and last names, health and medical information, credit card numbers […]
Investigation continues after Hendersonville City cybersecurity breach
The Hendersonville Times-News in North Carolina reports: A cyber-threat analyst who has been quoted in national news articles believes even more people could be at risk from the cybersecurity incident reported last week that targeted Hendersonville city employees. On Nov. 29, Hendersonville City Manager John Connet sent out a statement to city employees telling them […]
23andMe confirms hackers stole ancestry data on 6.9 million users
TechCrunch reports: On Friday, genetic testing company 23andMe announced that hackers accessed the personal data of 0.1% of customers, or about 14,000 individuals. The company also said that by accessing those accounts, hackers were also able to access “a significant number of files containing profile information about other users’ ancestry.” But 23andMe would not say how […]
Iran-linked hackers claim to leak troves of documents from Israeli hospital
The Record reports: A hacker group allegedly linked to Iran claimed to have leaked thousands of medical records from an Israeli hospital, including those of Israeli soldiers. In a cyberattack on Ziv Medical Center in the city of Safed, near the border with Syria and Lebanon, the hackers claimed to have accessed 500GB of data dating back […]
Ransomware gang tests new approach to extort victims
Researchers and analysts who track developments in ransomware leak sites are buzzing this morning about a post by the AlphV (“BlackCat”) threat actors. Normally, threat actors try to extort their victims and then, if the victims do not pay or respond, they start leaking information about the attack and any data. This time, AlphV is […]
Cactus ransomware exploiting Qlik Sense flaws to breach networks
If there’s anything the past few years should have taught businesses, it is that if you think you can just wait a month or a few months to patch vulnerabilities when a patch is released, expect to hacked by threat actors who are already searching for businesses that haven’t patched. In this week’s example, Bleeping […]

Update on Cyber Incident Reporting for Critical Infrastructure Act of 2022
Constangy, Brooks, Smith & Prophete, LLP writes: As we near the end of another year, it is time to look ahead to developments in the information security and privacy landscape. One area of particular importance is the development of regulations implementing the Cyber Incident Reporting for Critical Infrastructure Act of 2022. CIRCIA, which was signed into […]