The Breach News

Feds Unveil Enhanced HIPAA Security Risk Analysis Tool

Healthcare, Industry Specific, Regulation Experts Recommend Tool Designed for Smaller Organizations Marianne Kolbasuk McGee (HealthInfoSec) • September 10, 2025 Image: Getty Images Federal officials have released an updated version of their HIPAA Security Risk Assessment (SRA) tool, which has historically assisted small and midsized healthcare providers and business associates in…

Read MoreFeds Unveil Enhanced HIPAA Security Risk Analysis Tool

Apple Introduces Essential Updates for 3 Recent Zero-Day Vulnerabilities Affecting Older iOS and macOS Devices

Apple Releases Critical Security Updates for Legacy Devices Apple has taken significant steps to address critical security vulnerabilities by backporting fixes to older models and prior operating system versions. On Monday, the company rolled out updates aimed at mitigating three specific vulnerabilities that have been reported as actively exploited in…

Read MoreApple Introduces Essential Updates for 3 Recent Zero-Day Vulnerabilities Affecting Older iOS and macOS Devices

Cacti Servers Targeted as Most Users Neglect Crucial Security Patch

Unpatched Vulnerabilities in Cacti Servers Present New Threats Recent findings from Censys, an attack surface management platform, highlight a significant cybersecurity concern regarding Cacti servers. A majority of these internet-exposed servers remain unpatched against a critical vulnerability identified as CVE-2022-46169. This flaw has been actively exploited, raising alarms for organizations…

Read MoreCacti Servers Targeted as Most Users Neglect Crucial Security Patch

Pentagon Unveils Long-Anticipated Cybersecurity Regulations for Contractors

Government, Industry Specific Department of Defense Announces New Cybersecurity Maturity Model Certification Rule Chris Riotta (@chrisriotta) • September 10, 2025 Image: Jeremy Christensen/Shutterstock U.S. military contractors are set to face stringent new cybersecurity requirements, following the Department of Defense’s (DoD) official introduction of a mandatory controls framework to be implemented…

Read MorePentagon Unveils Long-Anticipated Cybersecurity Regulations for Contractors

Senator Criticizes Microsoft for Leaving Default Windows Settings Exposed to “Kerberoasting” Vulnerabilities

A leading U.S. senator has requested that the Federal Trade Commission (FTC) launch an inquiry into Microsoft, citing what he has termed “gross cybersecurity negligence.” This call to action stems from concerns regarding the company’s continued reliance on the outdated RC4 encryption method, which is set as the default in…

Read MoreSenator Criticizes Microsoft for Leaving Default Windows Settings Exposed to “Kerberoasting” Vulnerabilities

Dark Caracal Employs Poco RAT to Strike Spanish-Speaking Businesses in Latin America

The cybersecurity landscape is currently grappling with new threats as the group known as Dark Caracal has been linked to a sophisticated campaign deploying the remote access trojan (RAT) named Poco RAT. This recent wave of attacks primarily targets Spanish-speaking audiences in Latin America throughout 2024. The research findings, presented…

Read MoreDark Caracal Employs Poco RAT to Strike Spanish-Speaking Businesses in Latin America