The Breach News

Senators Reintroduce Legislation to Enhance Cybersecurity in Healthcare

New Bipartisan Bill Aims to Fortify Healthcare Cybersecurity with Enhanced Regulations and Support Marianne Kolbasuk McGee (HealthInfoSec) • December 8, 2025 A bipartisan coalition of U.S. senators has reintroduced a significant cybersecurity bill aimed at enhancing protections in the healthcare sector. (Image: U.S. Congress) A bipartisan group of four U.S.…

Read MoreSenators Reintroduce Legislation to Enhance Cybersecurity in Healthcare

Coupang Hit with U.S. Lawsuit for Punitive Damages Following Data Breach – 조선일보

Coupang Faces U.S. Lawsuit for Punitive Damages Following Data Breach In a significant development within the cybersecurity landscape, Coupang, a prominent South Korean e-commerce platform, is now facing a lawsuit in the United States related to a recent data breach. This legal action seeks punitive damages, reflecting mounting concerns over…

Read MoreCoupang Hit with U.S. Lawsuit for Punitive Damages Following Data Breach – 조선일보

Mastodon Security Flaw Lets Hackers Take Control of Any Decentralized Account

A significant security vulnerability has been identified within the decentralized social network Mastodon, enabling attackers to impersonate any user and seize control of their accounts. The issue stems from inadequate origin validation, as stated in a recent advisory from Mastodon’s maintainers. This vulnerability, cataloged as CVE-2024-23832, carries a severity score…

Read MoreMastodon Security Flaw Lets Hackers Take Control of Any Decentralized Account

Almost 18,000 SolarWinds Clients Installed Compromised Software

SolarWinds, a Texas-based supplier of enterprise monitoring software, has acknowledged a major cybersecurity incident linked to a compromised version of its Orion products. Up to 18,000 customers, including numerous Fortune 500 companies and U.S. military branches, may have implemented this affected software, raising significant alarm across various sectors. This revelation…

Read MoreAlmost 18,000 SolarWinds Clients Installed Compromised Software

France Fines Google $57 Million for Insufficient Transparency and Consent

In a significant enforcement action under the European Union’s General Data Protection Regulation (GDPR), France’s data protection authority, CNIL, has imposed a €50 million (approximately $57 million) fine on Google. This marks the first major penalty levied under the GDPR since its implementation in May 2018. The CNIL cited “lack…

Read MoreFrance Fines Google $57 Million for Insufficient Transparency and Consent

NCSC Alerts: AI Prompt Injection Risks Major Data Breaches in the UK

Growing Concerns Over AI Vulnerabilities in the UK: NCSC Warns of Prompt Injection Risks The National Cyber Security Centre (NCSC) has issued a significant warning regarding a misunderstanding that could expose UK organizations to serious data breaches. As generative AI technologies continue to proliferate, many developers and cybersecurity professionals are…

Read MoreNCSC Alerts: AI Prompt Injection Risks Major Data Breaches in the UK

Widespread Exploitation of Recent SSRF Vulnerability in Ivanti VPN Products

Mass Exploitation of SSRF Vulnerability in Ivanti Products A significant server-side request forgery (SSRF) vulnerability affecting Ivanti Connect Secure and Policy Secure products has been widely exploited. Recent reports indicate that attacks are emanating from over 170 distinct IP addresses, indicating a coordinated effort to establish unauthorized access, including reverse…

Read MoreWidespread Exploitation of Recent SSRF Vulnerability in Ivanti VPN Products

New Findings Indicate SolarWinds’ Codebase Was Compromised to Insert a Backdoor

The ongoing investigation into the SolarWinds breach continues to reveal the intricate tactics employed by the attackers who infiltrated the company’s internal systems and manipulated its software update processes. This meticulous and well-coordinated supply chain attack appears to have been in the making since at least October 2019, when the…

Read MoreNew Findings Indicate SolarWinds’ Codebase Was Compromised to Insert a Backdoor