The Breach News

Dental Center Chain Reaches $2.7 Million Settlement in Data Breach Lawsuit

Legislation & Litigation , Standards, Regulations & Compliance 2023 Cybersecurity Breach Impacted 1.9 Million Patients and Employees Marianne Kolbasuk McGee (HealthInfoSec) • October 21, 2024 Great Expressions Dental Centers (Image: Shutterstock) In a significant data breach, Great Expressions Dental Centers, a Michigan-based dental organization operating 250 offices across nine states,…

Read MoreDental Center Chain Reaches $2.7 Million Settlement in Data Breach Lawsuit

U.S. Imposes Sanctions on 6 Iranian Officials Over Cyberattacks on Critical Infrastructure

The U.S. Treasury Department’s Office of Foreign Assets Control (OFAC) has imposed sanctions on six individuals affiliated with the Iranian intelligence agency, attributed to cyberattacks targeting critical infrastructure in the United States and globally. This action underscores rising concerns related to cyber threats posed by state-sponsored actors. The individuals sanctioned…

Read MoreU.S. Imposes Sanctions on 6 Iranian Officials Over Cyberattacks on Critical Infrastructure

Internet Archive (Archive.org) Breached Again Within a Month

Internet Archive Faces Repeated Cybersecurity Challenges Amid Major Breaches In October 2024, the Internet Archive, a non-profit organization founded by Brewster Kahle to safeguard the digital history of the internet, encountered significant security setbacks resulting in multiple data breaches. The first incident, occurring on October 9, involved both a data…

Read MoreInternet Archive (Archive.org) Breached Again Within a Month

Insiders Misinterpret Microsoft 365 Copilot’s Responses

Artificial Intelligence & Machine Learning, Next-Generation Technologies & Secure Development Attack Method Exploits RAG-based Technology to Manipulate AI System Outputs Rashmi Ramesh (rashmiramesh_) • October 21, 2024 Malicious insiders could mislead the retrieval-augmented generation backend of well-known AI tools. (Image: Shutterstock) Recent research unveiled a method to manipulate responses from…

Read MoreInsiders Misinterpret Microsoft 365 Copilot’s Responses

Ex-Equifax Employee Accused of Insider Trading Related to Data Breach

In a significant development in the realm of cybersecurity, a former employee of Equifax has been charged with insider trading, a situation that follows the company’s disclosure of a significant data breach last year. The U.S. Securities and Exchange Commission (SEC) along with federal authorities in Atlanta disclosed their charges…

Read MoreEx-Equifax Employee Accused of Insider Trading Related to Data Breach

New Phishing Campaign Uses QR Codes and Microsoft Sway to Steal User Credentials

In a concerning development in cybersecurity, researchers have reported an uptick in QR code phishing campaigns, also known as “quishing.” These attacks utilize Microsoft Sway, a legitimate cloud-based platform, to host counterfeit web pages, underscoring how reputable services can be exploited for malicious activities. Jan Michael Alcantara from Netskope Threat…

Read MoreNew Phishing Campaign Uses QR Codes and Microsoft Sway to Steal User Credentials

Safeguard Your Fleet Against Cyber Threats: 10 Essential Steps

Cyberattacks disrupting various businesses have become increasingly prevalent in today’s digital landscape, notably impacting fleet operations. These cyber threats compromise not just vehicle functionality and cargo but also safety, data integrity, and ultimately, the financial health of the organization. Acknowledging these challenges is the fundamental first step toward enhancing cybersecurity…

Read MoreSafeguard Your Fleet Against Cyber Threats: 10 Essential Steps

Security Vulnerabilities in CocoaPods Risk iOS and macOS Apps to Supply Chain Attacks

A significant security vulnerability has been discovered within the CocoaPods dependency manager, critical for Swift and Objective-C Cocoa projects. This flaw has the potential to facilitate software supply chain attacks, posing serious threats to downstream users. Researchers from E.V.A Information Security reported that these vulnerabilities could allow malicious actors to…

Read MoreSecurity Vulnerabilities in CocoaPods Risk iOS and macOS Apps to Supply Chain Attacks

New Mispadu Banking Trojan Takes Advantage of Windows SmartScreen Vulnerability

The Mispadu banking Trojan has been identified as leveraging a recently patched vulnerability in Windows SmartScreen to target users in Mexico. This malware, which first appeared in 2019, has evolved into a new variant that cybercriminals are utilizing to gain unlawful access to sensitive information. According to a report from…

Read MoreNew Mispadu Banking Trojan Takes Advantage of Windows SmartScreen Vulnerability