The Breach News

Medical Cannabis Company Faces Lawsuit for Health Data Breach

Data Breach Notification , Data Security , Healthcare Lawsuits Emerge Following Discovery of Unprotected Patient Records Marianne Kolbasuk McGee (HealthInfoSec) • September 5, 2025     Image: Ohio Medical Alliance, operating as Ohio Marijuana Card A security researcher recently uncovered a significant security breach involving an unencrypted database lacking password…

Read MoreMedical Cannabis Company Faces Lawsuit for Health Data Breach

Exploitation of Unpatched Windows Zero-Day Vulnerability by 11 State-Sponsored Threat Actors Since 2017

A recently identified unpatched vulnerability in Microsoft Windows has been exploited by a coalition of eleven state-sponsored hacking groups from nations including China, Iran, North Korea, and Russia. This ongoing cyber threat campaign, dating back to 2017, focuses on data theft, espionage, and financially motivated activities. The zero-day vulnerability, cataloged…

Read MoreExploitation of Unpatched Windows Zero-Day Vulnerability by 11 State-Sponsored Threat Actors Since 2017

Apple Fixes Two Actively Exploited iOS Vulnerabilities Targeted in Sophisticated Attacks

Apple Addresses Critically Exploited iOS Vulnerabilities In a timely response to an escalating cybersecurity threat, Apple announced on Wednesday the release of crucial security updates for its suite of operating systems, including iOS, iPadOS, macOS Sequoia, tvOS, and visionOS. These updates were enacted to mitigate two significant security vulnerabilities that…

Read MoreApple Fixes Two Actively Exploited iOS Vulnerabilities Targeted in Sophisticated Attacks

Researchers Discover Hidden Malicious Code in PyPI Python Packages

Recent investigations have revealed that four rogue packages infiltrated the Python Package Index (PyPI), executing a series of malicious operations including the deployment of malware, the removal of the netstat utility, and the manipulation of the SSH authorized_keys file. The targeted packages—aptx, bingchilling2, httops, and tkint3rs—collectively amassed around 450 downloads…

Read MoreResearchers Discover Hidden Malicious Code in PyPI Python Packages

ICE Now Equipped with Spyware

The Biden administration has classified certain spyware used for phone hacking as highly controversial, leading to strict limitations on its use by the US government in an executive order issued in March 2024. As the Trump administration takes steps to enhance immigration enforcement, this landscape could shift dramatically, paving the…

Read MoreICE Now Equipped with Spyware

Chess.com Confirms Data Breach Following Exploitation of External System by Hackers

Chess.com, a premier online chess platform, has confirmed a significant data breach that has exposed the personal information of over 4,500 users. The breach occurred due to unauthorized access through an external system connected to the company’s network, underscoring vulnerabilities present in third-party integrations. Based in Orem, Utah, Chess.com revealed…

Read MoreChess.com Confirms Data Breach Following Exploitation of External System by Hackers