The Breach News

HHS Unveils AI Roadmap During Significant Departmental Revamp

Artificial Intelligence & Machine Learning, Healthcare, Industry Specific Strategic Initiative Aims to Modernize Workflow, Enhance AI Utilization, and Strengthen Cybersecurity Across Agencies Marianne Kolbasuk McGee (HealthInfoSec) • December 4, 2025 The U.S. Department of Health and Human Services has introduced an AI strategy that aims to eliminate departmental silos and…

Read MoreHHS Unveils AI Roadmap During Significant Departmental Revamp

AHPRA Makes Minor Breach of Practitioner Privacy

An error in the Australian Health Practitioner Regulation Authority’s (AHPRA) new online portal resulted in the unintended disclosure of contact information for approximately 3,000 nominated supervisors to their supervisees. AHPRA has confirmed a privacy breach affecting over 3,147 health practitioner employers and supervisors, raising concerns among those in the healthcare…

Read MoreAHPRA Makes Minor Breach of Practitioner Privacy

CISA Alert: Akira Ransomware Targeting Cisco ASA/FTD Vulnerability

On Thursday, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) included a recently patched security vulnerability affecting Cisco’s Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) software in its Known Exploited Vulnerabilities (KEV) catalog. This update comes in response to indications that the flaw is being actively exploited in…

Read MoreCISA Alert: Akira Ransomware Targeting Cisco ASA/FTD Vulnerability

Hackers Behind SolarWinds Attack Also Breached U.S. Justice Department Email Server

The U.S. Department of Justice (DoJ) has confirmed that its internal network was compromised amid the extensive SolarWinds supply chain attack. This acknowledgment positions the DoJ as the latest government entity to confront the ramifications of this alarming breach. According to DoJ spokesperson Marc Raimondi, the Office of the Chief…

Read MoreHackers Behind SolarWinds Attack Also Breached U.S. Justice Department Email Server

‘Signalgate’ Inspector General Report Recommends Only One Change to Prevent Future Debacles

Inspector General Report Raises Concerns Over Sensitive Messaging Practices by Secretary of Defense A recently released Inspector General report highlights serious cybersecurity concerns involving Secretary of Defense Pete Hegseth, indicating potential risks posed to U.S. troops and military operations. The report, shared with Congress earlier this week, reveals that Hegseth…

Read More‘Signalgate’ Inspector General Report Recommends Only One Change to Prevent Future Debacles

New York, Canada, and Ireland Initiate Investigations into Facebook Privacy Violations

Recently, Facebook has faced increasing scrutiny as multiple governmental authorities launch investigations into its handling of user data. The company has already earmarked $5 billion to address potential fines stemming from a Federal Trade Commission (FTC) inquiry regarding privacy violations. This amount appears to be merely the initial sum Facebook…

Read MoreNew York, Canada, and Ireland Initiate Investigations into Facebook Privacy Violations

UK Government Weighs Revision of Computer Misuse Act

Geo Focus: The United Kingdom, Geo-Specific, Legislation Security Minister Dan Jarvis Advocates for Protection of Security Researchers Akshaya Asokan (asokan_akshaya) • December 4, 2025 Minister for Security’s official portrait, July 2024. (Image: UK Home Office/CC BY 2.0) The U.K. government is contemplating revisions to its Computer Misuse Act, originally enacted…

Read MoreUK Government Weighs Revision of Computer Misuse Act

Attackers Leverage ScreenConnect and Microsoft 365 for Security Breaches

Barracuda’s latest cybersecurity report highlights a concerning rise in the unauthorized use of trusted tools, notably ScreenConnect, for remote access, coupled with a notable increase in Microsoft 365 login attempts from unfamiliar locations. The findings suggest that attackers are leveraging popular legitimate software and stolen credentials to infiltrate business networks…

Read MoreAttackers Leverage ScreenConnect and Microsoft 365 for Security Breaches

Russian-Linked Hackers Exploit Roundcube Vulnerabilities to Target Over 80 Organizations

A recent report by Recorded Future has revealed a sophisticated cyber espionage campaign attributed to threat actors with ties to Belarus and Russia. This operation has reportedly taken advantage of cross-site scripting (XSS) vulnerabilities in Roundcube webmail servers, targeting over 80 organizations predominantly based in Georgia, Poland, and Ukraine. The…

Read MoreRussian-Linked Hackers Exploit Roundcube Vulnerabilities to Target Over 80 Organizations