LATEST POST
79% of ransomware attacks now originate from compromised identities, Sophos report finds
Manila Standard reports that identity is the dominant initial access vector in ransomware attacks, according to a new report from Sophos: Sophos, a global cybersecurity leader, released its seventh annual State of Ransomware report, a vendor-agnostic survey of IT and cybersecurity leaders across 17 countries identifying the impact of ransomware on businesses and how prepared organizations […]
Healthcare Services Group agrees to $3M settlement after 2024 breach
Paubox reports: In October of 2024, Healthcare Services Group (HCSG), a Bensalem, Pennsylvania-based provider of environmental, dining, and nutritional support for healthcare facilities, became aware of a data breach that impacted 624,496 individuals, including employees and patients. Data that was accessed in the breach included names, Social Security numbers, driver’s license numbers, state identification numbers, financial account information, full […]
KPMG sacks senior partner after finding she hid board documents
Financial Review reports: KPMG has sacked its former chief operating officer Eileen Hoggett from the firm’s partnership in a rare move after finding she had stored printed copies of confidential Lendlease board documents in her locker, shared them with her colleagues to win audit contracts, and repeatedly lied about it. A furious John Sams, the […]
OpenAI’s Attack on Hugging Face Adds to Ongoing AI Agent Security Concerns
Responsible dog owners worry about their pets getting out of the yard and possibly attacking people. Now we all have to worry about AI models breaking out of their sandboxes and attacking tech firms or others. Security Boulevard reports: The cyberattack against Hugging Face launched by rogue AI models from OpenAI is only the latest […]
‘WP2Shell’ Opens Millions of WordPress Sites to Remote Takeover
If you haven’t patched already, get busy. DarkReading reports: Attackers have begun widely exploiting two critical vulnerabilities in WordPress that, when chained, enable unauthenticated remote code execution (RCE) and complete compromise of vulnerable websites. The attacks are being fueled by the ready availability of numerous proof-of-concept exploits for the two bugs, identified as CVE-2026-60137 and CVE-2026-63030. Researchers at […]
Fairlife stops US milk production after ransomware attack
Atlanta News First reports: Fairlife has stopped producing milk in the United States after it was hit by a ransomware attack, Coca-Cola announced Thursday. Fairlife identified “unauthorized access by a third party to a portion of its systems, including its production-related systems, in connection with a ransomware event.” The company notified law enforcement and is […]
SEBI penalizes Central Depository Services for cybersecurity lapses related to 2022 malware attack, imposes Rs 1 crore penalty
MoneyControl reports: Market regulator Securities and Exchange Board of India (SEBI) has imposed a penalty of Rs 1 crore [USD $103,683.10 at today’s rate] on Central Depository Services (India) Ltd (CDSL), holding that a series of cybersecurity failures enabled the malware attack that disrupted the depository’s operations in November 2022 and affected settlement activities across […]
Centers Laboratory Data Breach Affects 540,000 Individuals
SecurityWeek reports: Healthcare diagnostics company Centers Laboratory (Centers Lab NJ LLC) has informed the US government that a data breach discovered nearly one year ago affects more than 540,000 individuals. According to a data breach notice posted on its website, the New Jersey-based provider of testing and laboratory services for healthcare organizations discovered an intrusion in its […]
