LATEST POST
Critical Fortinet Vulnerabilities Exploited by the Qilin Ransomware Group
NetSec reports: The Qilin ransomware group has been noticed exploiting two critical vulnerabilities present in FortiOS/FortiProxy equipment. Although the group seems to be focusing on countries with Spanish language, it is likely that attacks exploiting these vulnerabilities will spread to other countries. The Qilin ransomware-as-a-service (RaaS) operation appeared in August 2022, known first as Agenda. Although it is not […]
Texas Enacts Liability Shield From Punitive Damages for Certain Small Businesses That Adopt Cybersecurity Programs
From attorneys at Jackson Lewis: On June 20, 2025, Texas Governor Greg Abbott signed SB 2610 into law, joining a growing number of states that aim to incentivize sound cybersecurity practices through legislative safe harbors. Modeled on laws in states like Ohio and Utah, the new Texas statute provides that certain businesses that “demonstrate[] that at the time […]
Data of more than 740,000 stolen in ransomware attack on Michigan hospital network
The Record reports: Ransomware hackers stole the Social Security numbers and health insurance information for more than 740,000 people during an attack on a prominent Michigan hospital network. McLaren Health Care filed documents on Friday concerning a ransomware attack that took place in August 2024 — the second cyber incident to impact the healthcare giant in 12 months. The […]
AT&T to pay $177 million in data breach settlement affecting 109 million customers
Reuters reports: A U.S. judge granted preliminary approval on Friday to a $177-million settlement that resolves lawsuits against AT&T T.N over breaches in 2024 that exposed personal information belonging to tens of millions of the telecom company’s customers. U.S. District Judge Ada Brown in Dallas said in a ruling that the class-action settlement was fair and reasonable. […]
Oxford City Council Cyberattack: A Comprehensive Overview
Retaining decades worth of unencrypted personal information connected to the internet is a data breach disaster waiting to happen, as this report from DefendOps Diaries illustrates: The recent cyberattack on Oxford City Council has underscored the vulnerabilities inherent in managing vast amounts of historical data. Over the weekend of June 7 and 8, 2025, unauthorized access to […]
Aflac notifies SEC of breach suspected to be work of Scattered Spider
DataBreaches.net reports that Aflac has notified the Securities & Exchange Commission (SEC) of a data security incident. The incident did not involve ransomware, and appears to have the same characteristics as breaches at two other U.S. insurers this month: Erie Insurance and Philadelphi Insurance Companies. The group known as Scattered Spider is suspected of being […]
No, the 16 billion credentials leak is not a new data breach (1)
Bleeping Computer responds to headlines from another site: News broke today of a “mother of all breaches,” sparking wide media coverage filled with warnings and fear-mongering. However, it appears to be a compilation of previously leaked credentials stolen by infostealers, exposed in data breaches, and via credential stuffing attacks. To be clear, this is not a […]
Belk hit with pair of lawsuits over data breach and notification failure
The Charlotte Observer reports: Two lawsuits were filed this week in federal court against Belk for a data breach and then for allegedly concealing the cyberattack. In both cases, the plaintiffs are also seeking certification for class-action suits. Belk failed to protect sensitive personal current and former employee and customer information, according to the lawsuits, […]
