Data Breach News, Vendor News
November 09, 2025
64 views 34 secs 0

Washington Post Falls Victim to Oracle-Linked Data Breach

PC Mag reports: The Washington Post has confirmed it fell victim to a large-scale cybercrime campaign that targeted Oracle’s business applications, joining Harvard University and American Airlines-owned carrier Envoy, which announced similar breaches last month. The news, first reported by Reuters, comes after Google said in October that it believes around 100 companies were affected by the hacking campaign, and that “large amounts […]

Vendor News, Data Breach News
October 27, 2025
95 views 2 mins 0

Marks & Spencer Cuts Ties With Tata Consultancy Services, But It Wasn’t Because of the Data Breach

The Cyber Security Hub Newsletter reports: British retail giant Marks & Spencer (M&S) has officially ended its long-standing partnership with Indian IT services leader Tata Consultancy Services (TCS) after suffering one of the most damaging cyberattacks in its history. The high-profile breach, which occurred earlier this year, is estimated to have cost the company around […]

Data Breach News, Healthcare, News, Vendor News
October 23, 2025
126 views 53 secs 0

Montana Officials Looking Into BCBS Breach Tied to Conduent Breach

Bank Info Security reports: Montana state regulators are investigating a data breach affecting 462,000 Blue Cross Blue Shield of Montana members involving one of the health insurer’s third-party services providers – and they want to know why nearly 10 months have gone by without notifying the breach victims. It took nearly four months for the […]

Legal News, Vendor News
October 22, 2025
102 views 45 secs 0

NY DFS Issues New Cybersecurity Guidance to Address Risks Associated with the Use of Third-Party Service Providers

Given how many breaches are at third-party service providers this year, guidance on dealing with vendors with an eye towards cybersecurity seems timely. October 21, 2025 New York State Department of Financial Services (DFS) Acting Superintendent Kaitlin Asrow today issued new cybersecurity guidance addressing the risks associated with entities becoming increasingly reliant on third-party service […]

Data Breach News, News, Vendor News
October 19, 2025
143 views 35 secs 0

Russian hackers ‘steal HUNDREDS of U.K. Ministry of Defence files and leak them to dark web’ in ‘catastrophic’ attack

The Sun reports: RUSSIAN cybercriminals have stolen hundreds of military documents and posted them on the dark web in a ‘catastrophic’ hack. The security breach compromised eight RAF and Royal Navy bases as well as emails and names of Ministry of Defence staff, as reported in The Mail on Sunday. The breach has been labelled ‘catastrophic’ and the MoD are investigating the […]

Data Breach News, Legal News, Malware Ransomware, Vendor News
October 16, 2025
110 views 32 secs 0

Capita given record £14 million fine over ransomware attack security failings

The Record reports: Capita, the United Kingdom’s largest outsourcing company, was on Wednesday fined £14 million ($18.7 million) over security failings that saw attackers compromise the personal information of 6.6 million people in a ransomware attack in 2023. The voluntary settlement is for less than a third of the £45 million ($60 million) Britain’s data […]

Harvard investigating breach linked to Oracle zero-day exploit

Bleeping Computer reports: Harvard University is investigating a data breach after the Clop ransomware gang listed the school on its data leak site, saying the alleged breach was likely caused by a recently disclosed zero-day vulnerability in Oracle’s E-Business Suite servers. “Harvard is aware of reports that data associated with the University has been obtained […]

News, Legal News, Vendor News
October 10, 2025
106 views 2 mins 0

Policyholder Plot Twist: Cyber Insurer Sues Policyholder’s Cyber Pros

Hunton Andrews Kurth writes: When a cyber incident occurs and the insurer pays out the claim, they often face the frustrating reality that pursuing the actual criminals – the threat actors – for indemnification is virtually impossible. Thus, insurers are now turning to subrogation claims against the very cybersecurity vendors entrusted by policyholders to protect […]

Data Breach News, News, Vendor News
October 09, 2025
97 views 53 secs 0

Hackers claim Discord breach exposed data of 5.5 million users

Bleeping Computer reports: Discord says they will not be paying threat actors who claim to have stolen the data of 5.5 million unique users from the company’s Zendesk support system instance, including government IDs and partial payment information for some people. The company is also pushing back on claims that 2.1 million photos of government IDs […]

Vulnerabilities, News, Vendor News
October 08, 2025
110 views 42 secs 0

Critical Vulnerability Alert: Oracle E-Business Suite

The FBI Cyber Division has posted the following on LinkedIn to emphasize this critical alert and the need to patch and hunt promptly: Oracle just issued a Security Alert for CVE-2025-61882, a remote code execution vulnerability (CVSS 9.8 – Critical) affecting Oracle E-Business Suite versions 12.2.3 through 12.2.14. The vulnerability allows unauthenticated attackers to execute […]