The Breach News

Caution: New SideTwist Backdoor and Agent Tesla Variant Discovered in Phishing Campaigns

Iranian Threat Actor APT34 Launches Phishing Campaign Featuring SideTwist Backdoor Recent cybersecurity reports indicate that the Iranian threat group known as APT34 has initiated a new phishing campaign directed at various sectors, leading to the deployment of a backdoor variant named SideTwist. This latest tactic highlights the group’s sophistication in…

Read MoreCaution: New SideTwist Backdoor and Agent Tesla Variant Discovered in Phishing Campaigns

Could Clinicians Face New Cyber Regulations in the Future?

Healthcare Sector Faces New Cybersecurity Expectations Amid Medicare 2025 Rule Proposal In a significant development for the healthcare industry, federal regulators are hinting at the introduction of enhanced cybersecurity requirements tied to Medicare participation. The Centers for Medicare and Medicaid Services (CMS) recently included a brief announcement in its expansive…

Read MoreCould Clinicians Face New Cyber Regulations in the Future?

FTC Imposes $7 Million Fine on Mental Health Startup Cerebral for Significant Privacy Breaches

Cerebral Fined Over Major Privacy Violations in Telehealth Services The U.S. Federal Trade Commission (FTC) has taken decisive action against Cerebral, a mental telehealth company, prohibiting it from utilizing or sharing personal medical data for advertising purposes. The company has also been levied a hefty fine exceeding $7 million in…

Read MoreFTC Imposes $7 Million Fine on Mental Health Startup Cerebral for Significant Privacy Breaches

(Cyber) Risk = Likelihood of Event x Impact Severity

Enhancing Cyber Resilience with CVSS: Understanding the Latest Developments in Vulnerability Scoring In late 2023, the unveiling of the Common Vulnerability Scoring System (CVSS) version 4.0 marked a significant advancement in vulnerability assessment methodologies. This updated framework, replacing its predecessor CVSS v3.0, focuses on improving the evaluation of vulnerabilities for…

Read More(Cyber) Risk = Likelihood of Event x Impact Severity

Emerging HijackLoader Modular Malware Gains Traction in the Cybercrime Landscape

A new malware loader known as HijackLoader is increasingly being adopted by cybercriminals to deploy various payloads, including information-stealing software such as DanaBot, SystemBC, and RedLine Stealer. First identified in July 2023, HijackLoader distinguishes itself with a modular architecture that allows for adaptable code injection and execution. This characteristic is…

Read MoreEmerging HijackLoader Modular Malware Gains Traction in the Cybercrime Landscape

Nokia Launches Investigation into Alleged Source Code Data Breach

Nokia Investigates Cyberattack Linked to Hacking Group IntelBroker Nokia has launched an extensive inquiry into a cyberattack reportedly executed by a hacking group identified as IntelBroker. This group has been disseminating sensitive corporate information across the internet for the last three days, prompting significant concerns both within Nokia and the…

Read MoreNokia Launches Investigation into Alleged Source Code Data Breach