The Breach News

Extortionists Assert Large-Scale Data Theft from Oracle E-Business Suite

Cybercrime, Fraud Management & Cybercrime Ransomware Expert Alerts Executives to Ransom Demands as High as $50 Million Mathew J. Schwartz (euroinfosec) • October 2, 2025 Image: Shutterstock/ISMG Digital extortionists are directly targeting executives at companies utilizing Oracle E-Business Suite, alleging they have compromised sensitive data, according to reports from multiple…

Read MoreExtortionists Assert Large-Scale Data Theft from Oracle E-Business Suite

Cencora Data Security Incident: Are You Eligible for a $5,000 Settlement? – The News Journal

Cencora Data Security Incident: Potential $5K Settlement for Affected Individuals Recently, Cencora, a significant player in the healthcare logistics sector, has been at the center of a notable data security incident. This breach has raised concerns among stakeholders and business owners regarding the integrity of sensitive data and the ongoing…

Read MoreCencora Data Security Incident: Are You Eligible for a $5,000 Settlement? – The News Journal

Lightning AI Studio Flaw Could Have Enabled Remote Code Execution via Concealed URL Parameter

Cybersecurity experts have revealed a serious vulnerability affecting the Lightning AI Studio, a development platform that, if exploited, poses a significant risk of remote code execution. This flaw has been assigned a CVSS score of 9.4, indicating its critical nature and potential for severe repercussions. The vulnerability permits attackers to…

Read MoreLightning AI Studio Flaw Could Have Enabled Remote Code Execution via Concealed URL Parameter

Five Eyes Nations Alert to Russian Cyber Threats Targeting Critical Infrastructure

Recent developments have drawn the attention of cybersecurity experts worldwide, as the Five Eyes nations—comprising Australia, Canada, New Zealand, the United Kingdom, and the United States—issued a comprehensive advisory on rising cyber threats linked to Russian state-sponsored actors and criminal syndicates. This advisory underscores the heightened risk posed to critical…

Read MoreFive Eyes Nations Alert to Russian Cyber Threats Targeting Critical Infrastructure

Nursing Home Penalized $182K for Sharing Patient Photos Online

Data Privacy, Data Security, Fraud Management & Cybercrime ‘Success Stories’ Campaign Improperly Released PHI of 150 Individuals Marianne Kolbasuk McGee (HealthInfoSec) • October 1, 2025 Cadia Healthcare, operating five nursing homes and rehabilitation facilities, has been fined $182,000 for disclosing patient photos and PHI in social media “success stories.” (Image:…

Read MoreNursing Home Penalized $182K for Sharing Patient Photos Online

Millions Affected by Data Breaches at Major Insurance Company and Auto Dealership Software Provider

On Wednesday, two companies revealed alarming updates regarding significant data breaches, indicating that a vast number of individuals had their sensitive information compromised during incidents that transpired over the summer. Allianz Life Insurance Company amended its regulatory filings to confirm that 1.49 million clients had their data accessed on July…

Read MoreMillions Affected by Data Breaches at Major Insurance Company and Auto Dealership Software Provider

Broadcom Addresses VMware Aria Vulnerabilities – Potential Exploits Could Result in Credential Theft

Security Flaws Detected in VMware Aria Operations Broadcom has announced the release of critical security updates addressing five vulnerabilities within VMware Aria Operations and Aria Operations for Logs. Industry experts are raising alarms about the potential for these flaws to be exploited by malicious actors seeking unauthorized access or sensitive…

Read MoreBroadcom Addresses VMware Aria Vulnerabilities – Potential Exploits Could Result in Credential Theft

New Incident Report Uncovers Hive Ransomware’s Targeting Tactics against Organizations

A Hive ransomware incident recently targeted an unspecified organization, leveraging vulnerabilities in Microsoft Exchange Server known as “ProxyShell” to conduct a swift attack that culminated in network encryption within 72 hours of initial compromise. This information was shared by Nadav Ovadia, a security researcher from Varonis, in a detailed post-mortem…

Read MoreNew Incident Report Uncovers Hive Ransomware’s Targeting Tactics against Organizations