The Breach News

Is Your Medical Device Secure? Ensure Proper Contract Language

Endpoint Security, Governance & Risk Management, Healthcare HSCC’s Updated Model Contract Aims for Shared Cyber Risk Among Providers and Device Manufacturers Marianne Kolbasuk McGee (HealthInfoSec) • November 21, 2025 The HSCC’s revised model contract for medical device cybersecurity is designed to aid healthcare entities and manufacturers in negotiating shared risks…

Read MoreIs Your Medical Device Secure? Ensure Proper Contract Language

Harvard Cyberattack: Data Breach Exposes Records of Alumni, Donors, Students, and Faculty—The Full Story, Affected Individuals, and Harvard’s Response

Harvard Cyberattack: Data Breach Exposes Sensitive Records A recent cyberattack at Harvard University has compromised the personal records of alumni, donors, students, and faculty members, following a sophisticated phone-based phishing scheme. The breach has raised extensive concerns regarding the university’s cybersecurity measures, as it is reported to have accessed critical…

Read More

Harvard Cyberattack: Data Breach Exposes Records of Alumni, Donors, Students, and Faculty—The Full Story, Affected Individuals, and Harvard’s Response

Critical New Linux Vulnerability May Expose User Passwords and Enable Clipboard Hijacking

Recent reports have unveiled a significant vulnerability concerning the “wall” command within the util-linux package, which presents risks for users across various Linux distributions. This flaw has the potential to be exploited by a malicious actor to either leak user passwords or manipulate the clipboard. The vulnerability, identified as CVE-2024-28085…

Read MoreCritical New Linux Vulnerability May Expose User Passwords and Enable Clipboard Hijacking

Iranian Hackers Employ Remote Utilities Software for Espionage Activities

Recent cybersecurity investigations have revealed that hackers believed to be affiliated with Iran are intensively targeting academic institutions, government bodies, and tourism organizations throughout the Middle East and its neighboring countries. This campaign appears to be focused on espionage and data theft. Trend Micro has named this operation “Earth Vetala,”…

Read MoreIranian Hackers Employ Remote Utilities Software for Espionage Activities

250 Million Microsoft Customer Support Records Leaked Online

Microsoft Confirms Data Breach Exposing Customer Support Records Microsoft has recently disclosed a significant security breach that may have put nearly 250 million customer support records at risk. This exposure stems from a misconfigured server, which allowed sensitive logs of interactions between Microsoft’s support team and customers to be publicly…

Read More250 Million Microsoft Customer Support Records Leaked Online

SEC Halts SolarWinds Lawsuit Following Significant Legal Challenges

Litigation, Standards, Regulations & Compliance Major Legal Proceedings Conclude as Judge Dismisses SEC’s Cyber Fraud Claims Against SolarWinds Chris Riotta (@chrisriotta) • November 21, 2025 Image: AevanStock/Shutterstock In a significant legal development, the U.S. Securities and Exchange Commission (SEC) has dropped its remaining allegations against SolarWinds and its Chief Information…

Read MoreSEC Halts SolarWinds Lawsuit Following Significant Legal Challenges

Google Reports Over 200 Companies Affected by Data Breach Linked to Gainsight

Gainsight is recognized as a provider of customer support platforms. Summary of Events Google has recently reported a significant supply chain breach that has compromised data stored by Salesforce across more than 200 businesses. The incident was initially revealed by Salesforce on Thursday, noting that “specific customers’ Salesforce data” was…

Read MoreGoogle Reports Over 200 Companies Affected by Data Breach Linked to Gainsight