DataBreachToday.com
AI Needs a Firewall and Cloud Needs a Rethink
4 months 2 weeks ago
Tom Leighton of Akamai Wants to End Cloud Bloat and Secure AI From Inside Out
The cloud was meant to be cheaper, but it's not. A bold new vision is emerging: one that slashes costs, decentralizes AI and secures APIs at the edge. From inference to firewalls, a reimagined internet is challenging hyperscaler dominance.
The cloud was meant to be cheaper, but it's not. A bold new vision is emerging: one that slashes costs, decentralizes AI and secures APIs at the edge. From inference to firewalls, a reimagined internet is challenging hyperscaler dominance.
Hackers Target Zero-Day Vulnerability to Exploit CrushFTP
4 months 2 weeks ago
Attackers Modify File-Transfer Server Software to Display Patched Version Number
Managed file-transfer software developer CrushFTP said a zero-day vulnerability in its tool's web interface is being actively exploited to gain admin-level access to servers. The company urged immediate updating, saying all versions of its software released since July 1 are patched.
Managed file-transfer software developer CrushFTP said a zero-day vulnerability in its tool's web interface is being actively exploited to gain admin-level access to servers. The company urged immediate updating, saying all versions of its software released since July 1 are patched.
UK Sanctions 3 Russian Military Cyber Units
4 months 2 weeks ago
Leaders of the Russian Military Intelligence Units of the GRU Also Targeted
The U.K. government on Friday sanctioned three Russian Military Intelligence Service units 29155, 26165 and 74455 in the United Kingdom and Ukraine. The sanctions also targeted 18 Russian officials for their role in GRU cyber operations dating back to 2013.
The U.K. government on Friday sanctioned three Russian Military Intelligence Service units 29155, 26165 and 74455 in the United Kingdom and Ukraine. The sanctions also targeted 18 Russian officials for their role in GRU cyber operations dating back to 2013.
Attackers Exploit Zero-Day Flaws in On-Premises SharePoint
4 months 2 weeks ago
Microsoft Issuing Emergency Patches to Combat Authentication-Bypassing Attacks
Hackers have been exploiting two zero-day vulnerabilities in on-premises installations of Microsoft SharePoint to gain remote access, and steal cryptographic keys and data. As Microsoft rolls out patches against "ToolShell," experts warn administrators to also rotate keys, to help eject attackers.
Hackers have been exploiting two zero-day vulnerabilities in on-premises installations of Microsoft SharePoint to gain remote access, and steal cryptographic keys and data. As Microsoft rolls out patches against "ToolShell," experts warn administrators to also rotate keys, to help eject attackers.
Hackers Exploit FIDO MFA With Novel Phishing Technique
4 months 2 weeks ago
PoisonSeed Threat Actor Uses Cross-Device Login Feature and QR Code to Trick Users
Expel researchers have found a novel adversary-in-the-middle phishing technique used by PoisonSeed, a cybercrime group previously tied to large-scale cryptocurrency thefts, to sidestep one of the most secure forms of multifactor authentication - FIDO2 physical keys.
Expel researchers have found a novel adversary-in-the-middle phishing technique used by PoisonSeed, a cybercrime group previously tied to large-scale cryptocurrency thefts, to sidestep one of the most secure forms of multifactor authentication - FIDO2 physical keys.
Security, AI Oversight Are Flashpoints in Draft Defense Bill
4 months 2 weeks ago
House, Senate Versions of 2026 NDAA Offer Competing Approaches to Cyber
Washington is wagering that future conflicts will unfold as much in cyberspace as on the battlefield, with House and Senate lawmakers unveiling dueling drafts of a nearly $900 billion defense bill that spotlights needs for cybersecurity and artificial intelligence technology.
Washington is wagering that future conflicts will unfold as much in cyberspace as on the battlefield, with House and Senate lawmakers unveiling dueling drafts of a nearly $900 billion defense bill that spotlights needs for cybersecurity and artificial intelligence technology.
Texas Drug, Alcohol Testing Firm Hack Affects Nearly 750,000
4 months 2 weeks ago
Cybercrime Group Bian Lian Claimed Responsibility for Attack Last Year
A Texas-based firm that conducts workplace drug and alcohol testing for private employers and for compliance with state and federal agencies, including the Department of Transportation, disclosed to regulators that a July 2024 hacking incident affected nearly 750,000 people.
A Texas-based firm that conducts workplace drug and alcohol testing for private employers and for compliance with state and federal agencies, including the Department of Transportation, disclosed to regulators that a July 2024 hacking incident affected nearly 750,000 people.
Botnet Abuses GitHub Repositories to Spread Malware
4 months 2 weeks ago
Hackers Using Amadey Bot to Drops Payloads From Fake GitHub Accounts
Threat actors are using public GitHub repositories to host and distribute malware through the Amadey botnet in an ongoing campaign linked to a broader malware-as-a-service operation, Cisco Talos said in a report published Thursday.
Threat actors are using public GitHub repositories to host and distribute malware through the Amadey botnet in an ongoing campaign linked to a broader malware-as-a-service operation, Cisco Talos said in a report published Thursday.
UK Creative Community, Big Tech Resume AI Copyright Talks
4 months 2 weeks ago
New Working Group Launched After 2 Failed Attempts to Resolve AI Training Impasse
The U.K. government on Wednesday began its latest round of talks between creative owners and the artificial intelligence sector to work out a potential deal on the use of copyrighted content to train AI models. The discussions follow two previous failed attempts.
The U.K. government on Wednesday began its latest round of talks between creative owners and the artificial intelligence sector to work out a potential deal on the use of copyrighted content to train AI models. The discussions follow two previous failed attempts.
Live Webinar | Bot or Not Isn’t Good Enough: Rethinking Bot Protection for the Age of AI Agents
4 months 2 weeks ago
AI, Cloud & Compliance: Mastering Data Security for Financial Services in a Hyper-Regulated Era
4 months 2 weeks ago
Crypto ATM Crackdown: British Cops Bust Suspected Operators
4 months 2 weeks ago
As Crypto ATMs Facilitate Scams and Money Laundering, More Governments Take Aim
Attackers Target Legacy Code in TeleMessage's Signal Clone
4 months 2 weeks ago
Multiple US Government Agencies Have Used the Now-Patched Message Archiving App
Attackers are actively attempting to exploit a vulnerability that exists in older versions of the Signal message app clone TeleMessage TM SGNL, built by Smarsh to keep copies of all communications, including the ability to comply with federal record-keeping requirements.
Attackers are actively attempting to exploit a vulnerability that exists in older versions of the Signal message app clone TeleMessage TM SGNL, built by Smarsh to keep copies of all communications, including the ability to comply with federal record-keeping requirements.
Dermatology, Imaging Hacks Expose 3.3 Million Patients' PHI
4 months 2 weeks ago
Incidents Rank Among the Top Five Health Data Breaches in 2025 - So Far
A Maryland dermatology practice and a Virginia radiology organization have each reported to regulators separate hacking incidents that in total affected the information of more than 3.3 million patients. The incidents rank among the five largest health data breaches reported in 2025 so far.
A Maryland dermatology practice and a Virginia radiology organization have each reported to regulators separate hacking incidents that in total affected the information of more than 3.3 million patients. The incidents rank among the five largest health data breaches reported in 2025 so far.
Coro's New CEO Prioritizes Channel-Driven Global Expansion
4 months 2 weeks ago
Joe Sykora Set to Scale Coro's SMB Cybersecurity Platform Globally Via MSP Partners
As Coro's new CEO, Joe Sykora is steering the SMB cybersecurity platform provider toward rapid international growth with a 100% partner-focused strategy, revamped operations and new tools for MSPs in an effort to dominate the underserved small and midsize business cybersecurity market.
As Coro's new CEO, Joe Sykora is steering the SMB cybersecurity platform provider toward rapid international growth with a 100% partner-focused strategy, revamped operations and new tools for MSPs in an effort to dominate the underserved small and midsize business cybersecurity market.
Golden dMSA Flaw Exposes Firms to Major Credential Theft
4 months 2 weeks ago
Semperis Warns of Flaw in Windows Server 2025 Delegated Managed Service Accounts
A critical cryptographic flaw in Windows Server 2025's delegated Managed Service Accounts, or dMSAs, allows attackers to generate passwords for every managed service account across an Active Directory forest and create a backdoor, Semperis researchers found.
A critical cryptographic flaw in Windows Server 2025's delegated Managed Service Accounts, or dMSAs, allows attackers to generate passwords for every managed service account across an Active Directory forest and create a backdoor, Semperis researchers found.
China-Backed Hackers Intensify Attacks on Taiwan Chipmakers
4 months 2 weeks ago
3 State-Sponsored Groups Spear-Phish Semiconductor Ecosystem
Chinese state-aligned hackers have ramped up espionage efforts against Taiwan's semiconductor ecosystem through spear-phishing campaigns. Three distinct threat actors targeted chipmakers, packaging and testing firms, equipment suppliers and financial analysts.
Chinese state-aligned hackers have ramped up espionage efforts against Taiwan's semiconductor ecosystem through spear-phishing campaigns. Three distinct threat actors targeted chipmakers, packaging and testing firms, equipment suppliers and financial analysts.
Stop the Spread: How to Contain Machine Identity Sprawl
4 months 2 weeks ago
In this 15-minute podcast, identity experts examine key findings from recent industry research on machine identity governance and how you can secure them
Securing the New Identity: AI Agents in the Enterprise
4 months 2 weeks ago
Why do AI agents require new identity governance approaches and the current controls not enough?
Checked
1 hour 4 minutes ago
DataBreachToday.com RSS News Feeds on data breach today news, regulations, blogs and education
DataBreachToday.com feed