Data Breach News, News
March 18, 2025
660 views 25 secs 0

GitHub Action Compromise Risks Data Leaks for 23,000 Repositories

DevOps reports: A popular GitHub Action used in more than 23,000 code repositories has been compromised in a supply chain attack by attackers who introduced a malicious commit aimed at leaking secrets like passwords held in public repositories. In the compromise, which is being tracked as CVE-2025-30066, bad actors modified the code in GitHub Actions tj-actions/changed-files […]

Data Breach News
March 17, 2025
553 views 53 secs 0

Over a thousand of Colorado Veterans’ Personal Information Leaked in Email Mistake

KOAA in Colorado reports: The personal information of over 1,000 veterans in Colorado may be at risk after a data leak. The Veterans Affairs Eastern Colorado Health Care System accidentally sent an email containing personal details about veterans to 75 recipients. The email, which was sent in January, included a spreadsheet with veterans’ full names, the last […]

Data Breach News, Legal News, News
March 15, 2025
615 views 53 secs 0

Judge Calls for Change Healthcare Data Breach Lawsuits in State and Federal Courts To Be Coordinated

About Lawsuits reports that all the state and federal lawsuits against Change Healthcare should be coordinated: The U.S. District Judge appointed to preside over all Change Healthcare data breach lawsuits brought throughout the federal court system has issued an order, outlining a plan to coordinate the pretrial proceedings in the federal multidistrict litigation (MDL) with claims pending […]

Critical Infrastructure, Cyberattack, Data Breach News
March 13, 2025
604 views 55 secs 0

China’s Volt Typhoon Hackers Dwelled in US Electric Grid for 300 Days

SecurityWeek reports that Dragos has published an interesting case study about an attack by the Chinese threat actors known as Volt Typhoon on the electric grid. The target was Littleton Electric Light and Water Departments (LELWD), a small public power utility in Massachusetts that serves Littleton and Boxborough. The utility had been in the process […]

Data Breach News
March 13, 2025
599 views 7 secs 0

Cybersecurity Advisory: Medusa Ransomware

From CISA.gov, a #StopRansomware advisory: Medusa is a ransomware-as-a-service (RaaS) variant first identified in June 2021. As of February 2025, Medusa developers and affiliates have impacted over 300 victims from a variety of critical infrastructure sectors with affected industries including medical, education, legal, insurance, technology, and manufacturing. The Medusa ransomware variant is unrelated to the MedusaLocker variant […]

Data Breach News, News
March 11, 2025
574 views 6 mins 0

Attorney General James Sues National General and Allstate Insurance for Failing to Protect New Yorkers’ Personal Information

The following is a press release issued yesterday by NY Attorney General Letitia James: NEW YORK – New York Attorney General Letitia James today filed a lawsuit against several insurance companies doing business as National General and Allstate Insurance Company (Allstate) for failing to protect New Yorkers’ personal information from cyberattacks. In 2020 and 2021, National General […]

Data Breach News
March 09, 2025
538 views 2 mins 0

Local and state governments continue to be targeted in cyberattacks

State and local governments continue to be targeted by threat actors. Here are three current situations in the news: Mission, Texas. Valley Central reports: The cybersecurity attack on the city of Mission has prompted the Mayor to declare a state of local disaster. Mayor Norie Gonzalez Garza sent a letter to Texas Governor Greg Abbott, […]

Data Breach News
March 09, 2025
158 views 22 secs 0

Lost & Found tracking software site was exposing information on travelers’ lost devices and personal effects

Tech Radar reports on an exposed data set discovered by a researcher: A dataset contai,ning 820,750 records totaling 122GB has been discovered online, most likely belonging to German tracking software firm Lost & Found, which primarily services the aviation industry. As revealed by security researcher, Jeremiah Fowler, this was in an unprotected and publicly exposed dataset […]