The Breach News

Kaiser Permanente Settles Data Breach for $46 Million—Here’s How to Submit Your Claim

Kaiser Permanente to Disburse Payments Following Data Sharing Settlement Kaiser Permanente, a prominent player in the U.S. healthcare landscape, is preparing to issue payments to customers affected by an incident involving the unauthorized sharing of personal data and health information with third-party companies. This move comes in the wake of…

Read MoreKaiser Permanente Settles Data Breach for $46 Million—Here’s How to Submit Your Claim

CISA Adds Severe Adobe ColdFusion Vulnerability to Exploited Vulnerability Catalog

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has recently included a significant security vulnerability affecting Adobe ColdFusion in its Known Exploited Vulnerabilities (KEV) catalog. This action follows evidence indicating active exploitation of the flaw. Cataloged as CVE-2023-26359, with a CVSS score of 9.8, this vulnerability pertains to a deserialization…

Read MoreCISA Adds Severe Adobe ColdFusion Vulnerability to Exploited Vulnerability Catalog

Operator of Malware-Scanning Service Similar to VirusTotal Sentenced to 14 Years in Prison

A notable case in cybercrime has recently concluded with the sentencing of Ruslans Bondars, a Latvian hacker known for creating the counter-antivirus service “Scan4You.” Bondars received a 14-year prison sentence after being convicted in federal court for multiple cyber offenses. His actions have drawn significant attention from law enforcement and…

Read MoreOperator of Malware-Scanning Service Similar to VirusTotal Sentenced to 14 Years in Prison

Reasons for My Skepticism About the Claim That a “Precise” US Cyber Operation Disrupted Venezuela’s Electricity

In recent developments reported by The New York Times, details have emerged regarding a cyberattack that allegedly disrupted power across parts of Venezuela, closely coinciding with the apprehension of President Nicolás Maduro. American officials, who remain unnamed, have indicated that this operation briefly darkened the capital, Caracas, although certain neighborhoods…

Read MoreReasons for My Skepticism About the Claim That a “Precise” US Cyber Operation Disrupted Venezuela’s Electricity

UK Crypto Companies Linked to Iran Sanctions

Blockchain & Cryptocurrency, Cryptocurrency Fraud, Fraud Management & Cybercrime Also: NodeCordRAT Malware, North Korean QR-Phishing Campaign Rashmi Ramesh (rashmiramesh_) • January 15, 2026 Image: Shutterstock This week, Information Security Media Group highlights significant cybersecurity incidents concerning digital assets. Notably, two U.K. cryptocurrency exchanges face allegations of facilitating Iranian sanctions evasion,…

Read MoreUK Crypto Companies Linked to Iran Sanctions

Victoria Department of Education Data Breach Compromises Student Information – SC Media

Victoria Department of Education Data Breach Exposes Student Information A significant data breach has recently transpired, affecting the Victoria Department of Education, which has potentially compromised sensitive student information. This incident raises serious concerns regarding data security within educational institutions, and emphasizes the ongoing risks associated with cyber vulnerabilities in…

Read MoreVictoria Department of Education Data Breach Compromises Student Information – SC Media

Thousands of Unsecured Openfire XMPP Servers Vulnerable to Critical Flaw

Recent cybersecurity reports indicate that thousands of Openfire XMPP servers remain vulnerable to a serious security flaw disclosed earlier this year. A report from VulnCheck highlights that these servers are unpatched and therefore at risk of being exploited by threat actors. The vulnerability, identified as CVE-2023-32315 and rated with a…

Read MoreThousands of Unsecured Openfire XMPP Servers Vulnerable to Critical Flaw

Cybersecurity Researchers Discover First Known UEFI Rootkit in the Wild

ESET cybersecurity researchers have reported the emergence of what they are calling the first UEFI rootkit actively utilized in the field. This advanced malware permits attackers to embed persistent malicious software within targeted devices, enabling it to withstand complete hard-drive formatting, which poses significant implications for affected organizations. The malware,…

Read MoreCybersecurity Researchers Discover First Known UEFI Rootkit in the Wild