The Breach News

FTC Imposes $7 Million Fine on Mental Health Startup Cerebral for Significant Privacy Breaches

Cerebral Fined Over Major Privacy Violations in Telehealth Services The U.S. Federal Trade Commission (FTC) has taken decisive action against Cerebral, a mental telehealth company, prohibiting it from utilizing or sharing personal medical data for advertising purposes. The company has also been levied a hefty fine exceeding $7 million in…

Read MoreFTC Imposes $7 Million Fine on Mental Health Startup Cerebral for Significant Privacy Breaches

(Cyber) Risk = Likelihood of Event x Impact Severity

Enhancing Cyber Resilience with CVSS: Understanding the Latest Developments in Vulnerability Scoring In late 2023, the unveiling of the Common Vulnerability Scoring System (CVSS) version 4.0 marked a significant advancement in vulnerability assessment methodologies. This updated framework, replacing its predecessor CVSS v3.0, focuses on improving the evaluation of vulnerabilities for…

Read More(Cyber) Risk = Likelihood of Event x Impact Severity

Emerging HijackLoader Modular Malware Gains Traction in the Cybercrime Landscape

A new malware loader known as HijackLoader is increasingly being adopted by cybercriminals to deploy various payloads, including information-stealing software such as DanaBot, SystemBC, and RedLine Stealer. First identified in July 2023, HijackLoader distinguishes itself with a modular architecture that allows for adaptable code injection and execution. This characteristic is…

Read MoreEmerging HijackLoader Modular Malware Gains Traction in the Cybercrime Landscape

Nokia Launches Investigation into Alleged Source Code Data Breach

Nokia Investigates Cyberattack Linked to Hacking Group IntelBroker Nokia has launched an extensive inquiry into a cyberattack reportedly executed by a hacking group identified as IntelBroker. This group has been disseminating sensitive corporate information across the internet for the last three days, prompting significant concerns both within Nokia and the…

Read MoreNokia Launches Investigation into Alleged Source Code Data Breach

New Android Trojan ‘SoumniBot’ Outwits Detection with Smart Techniques

A new Android Trojan, named SoumniBot, has been uncovered, specifically targeting users in South Korea by exploiting vulnerabilities in the Android manifest extraction and parsing procedures. This malware is distinctive for its unconventional methods of evasion, particularly through the obfuscation of the Android manifest, as revealed by Kaspersky researcher Dmitry…

Read MoreNew Android Trojan ‘SoumniBot’ Outwits Detection with Smart Techniques

Majority of Cybersecurity Breaches Originate from Third-Party Vendors – Medical Buyer

In a recent address at the HIMSS Healthcare Cybersecurity Forum, cybersecurity experts John Riggi and Richard Staynings emphasized the significant cybersecurity threats that arise from third-party vendors and associated organizations. Riggi, a former FBI special agent and a national advisor for Cybersecurity and Risk at the American Hospital Association, highlighted…

Read MoreMajority of Cybersecurity Breaches Originate from Third-Party Vendors – Medical Buyer

Google Addresses Another Actively Exploited Chrome Zero-Day Vulnerability

Google Addresses Critical Security Flaws in Chrome Browser In a proactive response to ongoing security concerns, Google has deployed patches to rectify nine significant vulnerabilities in its Chrome web browser, one of which is a serious zero-day flaw that has reportedly been exploited in the wild. This vulnerability, designated as…

Read MoreGoogle Addresses Another Actively Exploited Chrome Zero-Day Vulnerability