Vendor News, Data Breach News
June 03, 2025
593 views 40 secs 0

Security bug at compliance firm Vanta exposed customer data to other users

TechRadar reports: Security and compliance automation company Vanta has confirmed sharing sensitive customer data with other customers by mistake. In a statement (via TechCrunch), the company said a change it had made in the code resulted in a security breach. In it, some sensitive data from a small subset of customers was shared with other customers. […]

Data Breach News, News, Vendor News
May 29, 2025
1254 views 22 secs 0

LexisNexis breach: Data broker hack exposed trove of sensitive information, including Social Security numbers

Personal information on more than 364,000 people may have been compromised as part of a third-party hack. Fast Company reports: Data analytics firm LexisNexis Risk Solutions said it suffered a data breach that could have affected the names, Social Security numbers, driver’s license numbers, and contact information of more than 364,000 people. The company said […]

Data Breach News, News, Vendor News
May 26, 2025
1280 views 0 secs 0

Indian IT giant Tata Consultancy Services investigating possible link to M&S cyber-attack

Tata Consultancy Services is conducting an internal investigation to determine whether it was the gateway for the cyber-attack on Marks & Spencer. The BBC reports: Tata Consultancy Services (TCS) has provided services to M&S for more than a decade. Earlier this week, M&S said the hackers who had brought huge disruption to the retailer had […]

News, Vendor News
May 22, 2025
1155 views 11 secs 0

Russian Intelligence Hackers Stalk Western Logistics Firms

GovInfoSecurity reports: A slew of Western cybersecurity agencies warned Wednesday that Russian intelligence is targeting logistics and technology companies in a prolonged hacking campaign that includes an emphasis on internet-connected cameras situated along border crossings and military installations. The advisory includes indicators of compromise typical of an attack by Unit 26165 of the Russian Main Intelligence Directorate. […]

Data Breach News, Education Sector, News, Vendor News
May 21, 2025
1149 views 2 mins 0

Massachusetts student pleads guilty to hacking and extorting PowerSchool and an unnamed telecom

The U.S. Attorney’s Office for the District of Massachusetts announced yesterday that  Matthew D. Lane, 19, a student at Assumption University in Worcester, Mass., was charged and has agreed to plead guilty in connection with hacking into the computer networks of two U.S.-based companies and extorting the companies for ransoms. The two companies were not named in the Information […]

Data Breach News, Malware Ransomware, News, Vendor News
May 18, 2025
1466 views 59 secs 0

Broadcom employee data stolen by ransomware crooks following hit on payroll provider

The Register reports: A ransomware attack at a Middle Eastern business partner of payroll company ADP has led to customer data theft at Broadcom, The Register has learned. It’s understood Broadcom’s HR department has begun the process of informing current and former staff who are affected by the September ransomware attack at Business Systems House (BSH).  Broadcom […]

Data Breach News, News, Vendor News
May 16, 2025
1062 views 26 secs 0

RIBridges’ firewall worked, but hundreds of alerts went unnoticed or ignored.

Footnotes in CrowdStrike’s forensics report offer troubling details of Deloitte’s handling of incident logs. Rhode Island Current reports that the attack on RIBridges triggered hundreds of firewall alerts during the five months that attackers were in the network and were transferring gigabytes of data. But the state’s vendor, Deloitte, did not know the system had […]