The Breach News

Microsoft Uncovers Increased Russian Cyber Attacks Before Mid-Term Elections

Microsoft Discovers New Russian Hacking Attempts Ahead of U.S. Midterm Elections In a recent revelation, Microsoft announced the discovery of new hacking efforts attributed to the Russian hacking group APT28, also known as Strontium or Fancy Bear. These attempts, aimed at conservative think tanks and the U.S. Senate, surfaced amid…

Read MoreMicrosoft Uncovers Increased Russian Cyber Attacks Before Mid-Term Elections

Microsoft Takes Legal Action Against U.S. Government Over Unconstitutional Secret Data Requests

In a significant legal move, Microsoft has initiated a lawsuit against the Department of Justice (DoJ) to contest a gag order that prohibits technology companies from notifying their customers when their cloud-based data is accessed by government authorities. This lawsuit arises from concerns regarding the implications of the Electronic Communications…

Read MoreMicrosoft Takes Legal Action Against U.S. Government Over Unconstitutional Secret Data Requests

OnDemand | Streamlining Secure Access to Comply with HIPAA MFA Standards

OnDemand Automates Secure Access to Comply with HIPAA MFA Requirements In the rapidly evolving landscape of cybersecurity, OnDemand has announced a significant advancement in automating secure access protocols to meet the stringent Multi-Factor Authentication (MFA) requirements set by the Health Insurance Portability and Accountability Act (HIPAA). This initiative comes in…

Read MoreOnDemand | Streamlining Secure Access to Comply with HIPAA MFA Standards

How Secure Are Our Data, Really?

Data Breaches Highlight Ongoing Cybersecurity Challenges for Major Firms Recent incidents involving prominent organizations such as Endesa, Spotify, and the Consorci Sanitari Integral de Catalunya underscore a persistent crisis in data security. Companies often embrace a narrative of resilience: identifying and addressing vulnerabilities while assuring stakeholders that security measures are…

Read MoreHow Secure Are Our Data, Really?

New Python URL Parsing Vulnerability May Allow Command Execution Attacks

A significant security vulnerability has been revealed in the URL parsing function of Python, posing a serious risk where attackers could exploit it to circumvent domain and protocol filtering mechanisms that rely on blocklists. This could lead to unauthorized file readings and arbitrary command executions. The CERT Coordination Center (CERT/CC)…

Read MoreNew Python URL Parsing Vulnerability May Allow Command Execution Attacks

New Apache Struts RCE Vulnerability Allows Hackers to Compromise Web Servers

Critical Vulnerability Discovered in Apache Struts Framework A significant remote code execution vulnerability, designated CVE-2018-11776, has been disclosed in the widely used Apache Struts web application framework, which is crucial for numerous businesses globally. Semmle security researcher Man Yue Mo revealed that this flaw could enable remote attackers to execute…

Read MoreNew Apache Struts RCE Vulnerability Allows Hackers to Compromise Web Servers

Google Requires Chrome Apps to Disclose User Data Collection Practices

Google has taken crucial steps to enhance user privacy by updating its User Data Policy for Chrome extensions. Although these tools can significantly improve user experiences, they also pose risks, such as unauthorized data collection and surveillance. The recent policy change mandates that developers clearly disclose their data collection practices,…

Read MoreGoogle Requires Chrome Apps to Disclose User Data Collection Practices