The Breach News

Ransomware Attackers Target Employees for Data Breach Access

In a concerning development for cybersecurity, everyday employees are being targeted by malicious actors, encouraging them to participate in ransomware operations against their own employers. Recent insights from GroupSense, a cybersecurity firm, reveal that malware operators are not only delivering ransomware notices but are also attempting to recruit victims to…

Read MoreRansomware Attackers Target Employees for Data Breach Access

ACLU Cautions That DOGE’s Unrestricted Access Might Breach Federal Law

The American Civil Liberties Union (ACLU) has raised significant concerns regarding the actions of Elon Musk’s Department of Government Efficiency (DOGE), asserting that it has gained unauthorized control over several federal computer systems that manage sensitive data protected by federal law. In a recent communication to federal lawmakers, the ACLU…

Read MoreACLU Cautions That DOGE’s Unrestricted Access Might Breach Federal Law

DeepSeek’s Urgent Alert on AI Security

AI Safeguards Under Fire: DeepSeek’s Security Oversights DeepSeek, a cutting-edge open-source AI model developed by a Chinese tech firm, has come under intense scrutiny following revelations of significant security lapses and a data breach that compromised user information and API keys. During this week’s ISMG Editors’ Panel discussion, Sam Curry,…

Read MoreDeepSeek’s Urgent Alert on AI Security

Edelson Lechtzin LLP Conducts Investigation

Data Privacy Violations Under Investigation at CODAC Behavioral Health EDELSON, Pa. – February 7, 2025 – Edelson Lechtzin LLP, a prominent national class action law firm, has launched an investigation into potential data privacy violations involving CODAC, Inc. operating as CODAC Behavioral Health. The examination follows the organization’s discovery of…

Read MoreEdelson Lechtzin LLP Conducts Investigation

Exploitation of 7-Zip 0-Day Vulnerability During Russia’s Ongoing Invasion of Ukraine

Zero-Day Vulnerability Discovered in 7-Zip Amid Ongoing Conflict in Ukraine In recent developments, security researchers have identified a zero-day vulnerability in the widely used 7-Zip archiving application, which has reportedly been exploited in connection with Russia’s military operations in Ukraine. The vulnerability poses a significant security risk, as it allows…

Read MoreExploitation of 7-Zip 0-Day Vulnerability During Russia’s Ongoing Invasion of Ukraine

Could Accessing CMS Data via DOGE Result in HIPAA Violations?

Data Governance, Data Privacy, Data Security Experts Express Concern Over Musk’s Team and Health Data Access Marianne Kolbasuk McGee (HealthInfoSec) • February 6, 2025 The White House’s DOGE initiative, spearheaded by Elon Musk, has begun accessing federal IT systems to investigate fraud, raising significant privacy concerns (Image: CMS) Privacy experts…

Read MoreCould Accessing CMS Data via DOGE Result in HIPAA Violations?

Impending Deadline for Claims in $21 Million Settlement Over Major Insurance Firms’ Data Breach – PennLive

Deadline Approaches for Claims in $21M Settlement Following Major Insurance Data Breach A significant cybersecurity incident involving major insurance firms has led to a $21 million settlement, with the deadline for filing claims fast approaching. This breach has raised alarm among businesses and individuals alike, highlighting the ongoing vulnerabilities in…

Read MoreImpending Deadline for Claims in $21 Million Settlement Over Major Insurance Firms’ Data Breach – PennLive

DeepSeek iOS App Transmits Data Without Encryption to ByteDance-Controlled Servers

Recent findings by security firm NowSecure have raised significant concerns about the security practices of certain applications. Thomas Reed, the staff product manager for Mac endpoint detection and response at Huntress, highlighted that the practice of disabling App Transport Security (ATS) presents serious risks. In an online interview, Reed emphasized…

Read MoreDeepSeek iOS App Transmits Data Without Encryption to ByteDance-Controlled Servers