The Breach News

New BLISTER Malware Leverages Code-Signing Certificates to Bypass Detection

Recent research has unveiled an advanced malware campaign characterized by its use of legitimate code signing certificates to elude cybersecurity measures. This stealthy approach aims to deploy notorious payloads such as Cobalt Strike and BitRAT across compromised systems. The loader, identified as “Blister” by Elastic Security experts, exhibits an alarming…

Read MoreNew BLISTER Malware Leverages Code-Signing Certificates to Bypass Detection

SimonMed Imaging Data Breach Exposes Sensitive Information of Over 1.2 Million Patients – CPO Magazine

Sensitive Patient Information Compromised in SimonMed Imaging Data Breach In a recent cybersecurity incident, SimonMed Imaging has reported a significant data breach affecting the personal information of over 1.2 million individuals. The breach necessitates urgent attention from healthcare providers and business owners alike, as it underscores the vulnerabilities prevalent in…

Read MoreSimonMed Imaging Data Breach Exposes Sensitive Information of Over 1.2 Million Patients – CPO Magazine

Over 300K Prometheus Instances Exposed: Online Leak of Credentials and API Keys

Recent cybersecurity reports indicate a significant vulnerability affecting numerous servers running the Prometheus monitoring and alerting toolkit. Security researchers have identified that thousands of these servers are susceptible to data leakage, denial-of-service (DoS), and remote code execution (RCE) attacks. Experts from Aqua Security, Yakir Kadkoda and Assaf Morag, disclosed that…

Read MoreOver 300K Prometheus Instances Exposed: Online Leak of Credentials and API Keys

Chinese APT Hackers Exploit Log4Shell to Attack Academic Institution

A sophisticated cyber intrusion attributed to a China-based threat group, identified as Aquatic Panda, has been detected leveraging severe vulnerabilities in the Apache Log4j logging system. This attack vector enabled the adversaries to execute various post-exploitation activities, including reconnaissance operations and credential harvesting from their targets. The cybersecurity firm CrowdStrike…

Read MoreChinese APT Hackers Exploit Log4Shell to Attack Academic Institution

One Republican Now Oversees a Significant Portion of US Election Infrastructure

Dominion Voting Systems Acquired by Knowink CEO: Implications for Election Integrity Last week, the acquisition of Dominion Voting Systems by Scott Leiendecker, founder and CEO of Knowink—an electronic poll book manufacturer based in Missouri—has raised questions among election integrity advocates concerning potential impacts on U.S. voter confidence and the electoral…

Read MoreOne Republican Now Oversees a Significant Portion of US Election Infrastructure

HelloKitty Ransomware Group Targets Vulnerabilities in Apache ActiveMQ

Recent warnings from cybersecurity experts indicate that a significant security vulnerability in Apache ActiveMQ, an open-source message broker service, is being actively exploited, potentially allowing remote code execution. This vulnerability, identified as CVE-2023-46604, has drawn attention due to its critical nature. The cybersecurity firm Rapid7 reported that attackers have made…

Read MoreHelloKitty Ransomware Group Targets Vulnerabilities in Apache ActiveMQ

Physician Practices to Pay $50 Million to Resolve Cyberattack Lawsuits

Data Privacy , Data Security , Healthcare 2022 Ransomware Attack, Data Theft Affected 3.4 Million Patients Marianne Kolbasuk McGee (HealthInfoSec) • October 17, 2025     Regal Medical Group is among nine physician practices affiliated with Heritage Provider Network paying nearly $50 million to settle litigation involving a 2022 hacking…

Read MorePhysician Practices to Pay $50 Million to Resolve Cyberattack Lawsuits