The Breach News

Senator Urges EHR Vendors to Strengthen Patient Privacy Measures

Data Privacy, Data Security, HIPAA/HITECH Increased Push as HHS Intensifies Oversight of Data Sharing and Record Access Regulations Marianne Kolbasuk McGee (HealthInfoSec) • December 17, 2025 Sen. Ron Wyden is advocating for greater privacy controls for patients regarding their health information. (Image: Getty Images) Senator Ron Wyden of Oregon is…

Read MoreSenator Urges EHR Vendors to Strengthen Patient Privacy Measures

Notice of Cybersecurity and Data Breach

Cybersecurity Breach at the University of Sydney Exposes Personal Data In a significant cybersecurity incident, the University of Sydney has confirmed an unauthorized breach of its online IT code library, which has the potential to impact personal data previously held within the system. Last week, university officials reported discovering suspicious…

Read MoreNotice of Cybersecurity and Data Breach

Malware Exploiting Google MultiLogin to Sustain Access After Password Resets

A recent security report reveals that information-stealing malware is exploiting a previously undocumented Google OAuth endpoint known as MultiLogin. This vulnerability allows cybercriminals to hijack user sessions, granting them continuous access to Google services even after victims have conducted password resets. This revelation has raised significant concerns regarding user privacy…

Read MoreMalware Exploiting Google MultiLogin to Sustain Access After Password Resets

A Google Drive Vulnerability Could Enable Attackers to Coerce You into Installing Malware

A recently uncovered vulnerability in Google Drive presents a significant risk, potentially allowing cybercriminals to distribute malware disguised as legitimate files. This largely unaddressed security oversight enables attackers to leverage Google Drive’s file version management feature, resulting in higher success rates for spear-phishing schemes. The flaw, which Google is reportedly…

Read MoreA Google Drive Vulnerability Could Enable Attackers to Coerce You into Installing Malware

14 Harmful NuGet Packages Discovered Exfiltrating Crypto Wallets and Ad Information

The rapid expansion of digital currencies has seen a corresponding rise in tactics employed by cybercriminals to siphon off assets. Recently, a significant cybersecurity threat emerged on NuGet, a widely utilized platform for software developers seeking building blocks for their applications. This threat was identified by ReversingLabs, a reputable software…

Read More14 Harmful NuGet Packages Discovered Exfiltrating Crypto Wallets and Ad Information

DomainFactory Breached—Hosting Provider Urges All Users to Update Passwords

Data Breach at DomainFactory: A Reminder of Cybersecurity Vigilance A significant data breach affecting DomainFactory, one of Germany’s leading web hosting providers and owned by GoDaddy, has recently come to light. The breach, which first occurred in January, only became public knowledge last week when an unidentified attacker disclosed details…

Read MoreDomainFactory Breached—Hosting Provider Urges All Users to Update Passwords

Chinese Hackers Compromise European Networks for Espionage Activities

Cyberwarfare / Nation-State Attacks, Fraud Management & Cybercrime Ink Dragon Compromises European IIS Networks to Distribute ShadowPad Malware Akshaya Asokan (asokan_akshaya) • December 17, 2025 Image: tostphoto/Shutterstock A Chinese hacking group, identified as Ink Dragon, has compromised European government networks, utilizing them as relay nodes to execute commands and facilitate…

Read MoreChinese Hackers Compromise European Networks for Espionage Activities