The Breach News

SimonMed Reports Medusa Ransomware Incident Exposed Data of 1.2 Million Patients

SimonMed Imaging has reported a significant security breach resulting from a ransomware attack earlier this year, compromising sensitive personal data for approximately 1.28 million individuals. This incident ranks among the most substantial healthcare data breaches disclosed in 2025. In a disclosure made to the Maine Attorney General’s Office, the company…

Read MoreSimonMed Reports Medusa Ransomware Incident Exposed Data of 1.2 Million Patients

New “DoubleClickjacking” Exploit Circumvents Clickjacking Safeguards on Leading Websites

Cybersecurity experts have recently unveiled a new campaign characterized by a “widespread timing-based vulnerability class,” which utilizes a double-click sequence to enable clickjacking attacks and unauthorized account access across prominent websites. This technique, termed DoubleClickjacking by researcher Paulos Yibelo, marks a significant evolution in traditional clickjacking methods. Yibelo emphasizes that…

Read MoreNew “DoubleClickjacking” Exploit Circumvents Clickjacking Safeguards on Leading Websites

AI Security Gains Traction as Vendors Ramp Up M&A Investments

Rising Threats in AI Security: Major Acquisitions Signal Industry Response Recent months have witnessed a significant surge in artificial intelligence security acquisitions as leading vendors vie to solidify their foothold in safeguarding AI-driven systems, applications, and workflows. This escalation in activity reflects the industry’s heightened awareness of AI’s vulnerabilities and…

Read MoreAI Security Gains Traction as Vendors Ramp Up M&A Investments

New Hacker Group ‘GambleForce’ Targets APAC Firms with SQL Injection Attacks

Recent cybersecurity reports have surfaced detailing a series of SQL injection attacks attributed to a newly identified hacker group named GambleForce. This group has predominantly targeted organizations across the Asia-Pacific (APAC) region since September 2023, raising significant concerns regarding the vulnerabilities in web application security practices. According to Group-IB, a…

Read MoreNew Hacker Group ‘GambleForce’ Targets APAC Firms with SQL Injection Attacks

Major Security Vulnerabilities Resolved in Microsoft Dynamics 365 and Power Apps Web API

Recent reports have highlighted three critical security vulnerabilities within the Microsoft Dynamics 365 and Power Apps Web API. These exploits, which could lead to unauthorized data exposure, have been addressed as of May 2024, following detection by Stratus Security, a cybersecurity firm based in Melbourne. The vulnerabilities identified reflect significant…

Read MoreMajor Security Vulnerabilities Resolved in Microsoft Dynamics 365 and Power Apps Web API

Ukraine Remains Under Cyber Espionage Attacks from Russian Hackers

Recent cybersecurity investigations have revealed a series of infiltration attempts by a Russian-affiliated hacking group known as Gamaredon, targeting Ukrainian entities as early as July 2021. Broadcom subsidiary Symantec released findings on Monday highlighting the group’s consistent activity in cyberespionage, a pattern they’ve maintained since at least 2013. Ukrainian intelligence…

Read MoreUkraine Remains Under Cyber Espionage Attacks from Russian Hackers