Legal News, Cyberattack, News
December 17, 2024
1004 views 3 mins 0

SEC Charges Flagstar for Misleading Investors About Cyber Breach

ADMINISTRATIVE PROCEEDINGFile No. 3-22360 December 16, 2024 – The Securities and Exchange Commission today filed settled charges against Flagstar Bancorp, Inc. (now known as “Flagstar Financial, Inc.”), for making materially misleading statements regarding a cybersecurity attack on Flagstar’s network in late 2021 (the “Citrix Breach”). The SEC’s order finds that Flagstar negligently made materially misleading statements […]

Data Breach News, News, Vulnerabilities
December 10, 2024
909 views 14 secs 0

Multiple Cleo file transfer products being exploited by hackers; patch isn’t sufficient

Here we go again: threat actors are taking advantage of vulnerabilities in file transfer products. This time it is Cleo file transfer products. The Record reports: Cybersecurity researchers are warning that vulnerabilities in several file transfer products are being exploited by hackers, even after a patch was released by the developer. The vulnerability — CVE-2024-50623 — was […]

Data Breach News, News, Vulnerabilities
December 10, 2024
883 views 26 secs 0

US sanctions Chinese firm for hacking firewalls in ransomware attacks; $10 million reward for information

The U.S. Treasury Department has sanctioned Chinese cybersecurity company Sichuan Silence and one of its employees for their involvement in a series of Ragnarok ransomware attacks targeting U.S. critical infrastructure companies and many other victims worldwide in April 2020. BleepingComputer reports: According to the Department’s Office of Foreign Assets Control (OFAC), Sichuan Silence is a […]

Commentaries and Analyses, Legal News, News
December 10, 2024
1114 views 35 secs 0

Should regulators do more naming and shaming?

The U.K. Information Commissioner’s Office did an interesting two-year trial and the results suggest that publicly reprimanding public sector entities over breaches and data leaks is an effective strategy — even without any monetary penalties. Infosecurity Magazine reports: The publication of reprimands following data leaks has been cited as an “effective” deterrent for public authorities. […]

Data Breach News, Healthcare, News
December 10, 2024
866 views 2 mins 0

HealthAlliance of Hudson Valley Pays $550,000 to NYS; Failed to Address a Known Cybersecurity Vulnerability

New York State Attorney General Letitia James announced another data security enforcement settlement yesterday. HIPAA Journal writes: A New York healthcare provider that experienced a breach of the personal and protected health information of 242,641 New Yorkers has been ordered to pay a financial penalty of $550,000 and take steps to strengthen its data security […]

News, Consumer Alerts
December 04, 2024
1080 views 48 secs 0

Chinese hack of global telecom providers is ‘ongoing,’ officials urge people to use encrypted apps to communicate

The U.S. may not have totally kicked China-affiliated Salt Typhoon out of U.S. telecommunication systems, a new publication by CISA explains. Politico reports that CISA and the FBI are advising people to use encrypted communications: Jeff Greene, [executive assistant director of cybersecurity at the Cybersecurity and Infrastructure Security Agency], strongly urged Americans to “use your […]