The Breach News

UK Introduces Cybersecurity and Resilience Legislation

Geo Focus: The United Kingdom, Geo-Specific, Standards, Regulations & Compliance Legislation Aims to Strengthen Cybersecurity for the UK’s Economy Akshaya Asokan (asokan_akshaya)® • November 12, 2025 Image: Shutterstock The UK government has unveiled critical cybersecurity legislation aimed at addressing disruptive cyber incidents that threaten essential national infrastructure. Announced Wednesday, the…

Read MoreUK Introduces Cybersecurity and Resilience Legislation

Lawsuit Filed Over Late Notification of Mt. Baker Imaging Data Breach – Bellingham Herald

Delayed Notification of Mt. Baker Imaging Data Breach Leads to Lawsuit In a recent development that underscores the critical challenges in timely cybersecurity communication, Mt. Baker Imaging has become embroiled in a lawsuit following the delayed notification of a significant data breach. The imaging center, based in the United States,…

Read MoreLawsuit Filed Over Late Notification of Mt. Baker Imaging Data Breach – Bellingham Herald

Google Resolves GCP Composer Vulnerability That Risked Remote Code Execution

In a significant security update, Google has patched a critical vulnerability in its Cloud Platform (GCP) Composer service. This flaw, identified by Tenable Research and labeled as CloudImposer, had the potential for attackers to execute remote code on GCP servers. Exploitation routes included a supply chain attack method termed dependency…

Read MoreGoogle Resolves GCP Composer Vulnerability That Risked Remote Code Execution

Covert Rootkit Breaches Networks of Prominent Organizations

A sophisticated threat actor has been exploiting an evasive Windows rootkit to infiltrate high-profile organizations in Asia and Africa, with activity detected since at least 2018. This malware, dubbed ‘Moriya’, operates as a passive backdoor, allowing attackers to monitor incoming traffic on infected systems and selectively respond to packets intended…

Read MoreCovert Rootkit Breaches Networks of Prominent Organizations

DHS Violated Domestic Espionage Rules by Retaining Chicago Police Records for Months

DHS Deletes Compromised Chicago Police Data Amid Oversight Failures On November 21, 2023, field intelligence officers from the Department of Homeland Security (DHS) deleted a significant volume of records from the Chicago Police Department (CPD), but this deletion was far from routine. The data in question, which concerned about 900…

Read MoreDHS Violated Domestic Espionage Rules by Retaining Chicago Police Records for Months

Experts Uncover the Tactics of the ShinyHunters Cybercrime Group

The cybercrime group known as ShinyHunters has made headlines for its ongoing campaign of data breaches and is now reported to be actively exploiting vulnerabilities in companies’ GitHub repositories. This analysis highlights the group’s strategies for conducting broader and more sophisticated cyberattacks. According to a report from Intel 471 shared…

Read MoreExperts Uncover the Tactics of the ShinyHunters Cybercrime Group

HSCC Guidance for Navigating AI Cybersecurity Risks in the Health Sector

Artificial Intelligence & Machine Learning, Healthcare, Industry Specific Guidance Documents Highlight 5 Key Risk Areas and Best Practices for AI in Healthcare Marianne Kolbasuk McGee (HealthInfoSec) • November 12, 2025 The Health Sector Coordinating Council has previewed upcoming materials aimed at helping the healthcare sector address the cyber risks associated…

Read MoreHSCC Guidance for Navigating AI Cybersecurity Risks in the Health Sector

Patch Released for Critical VMware vCenter Vulnerability Enabling Remote Code Execution

Critical Vulnerabilities Discovered in VMware vCenter Server: A Call to Action for Businesses On Tuesday, Broadcom issued urgent updates in response to a significant security vulnerability affecting VMware vCenter Server that could potentially allow remote code execution. This vulnerability, designated CVE-2024-38812 and rated with a CVSS score of 9.8, is…

Read MorePatch Released for Critical VMware vCenter Vulnerability Enabling Remote Code Execution