Topic: cybersecurity breach

  • McKesson Confirms Breach After ShinyHunters Claims Patient Data Theft

    McKesson Confirms Breach After ShinyHunters Claims Patient Data Theft

    McKesson confirmed a significant cybersecurity breach in an SEC filing, acknowledging unauthorized access to third-party applications and the potential theft of massive amounts of patient data. The company stated that while it has activated incident response protocols and engaged experts, it has ...

    Read More »
  • Critical First 24 Hours After a Data Breach

    Critical First 24 Hours After a Data Breach

    The first 24 hours after a cybersecurity breach are critical for damage control, requiring a structured, practiced response to contain the incident and preserve evidence. Proactive preparation is essential and includes establishing secure communication channels, identifying key response team memb...

    Read More »
  • ATF Confirms Major Incident Following Qilin Breach Claims

    ATF Confirms Major Incident Following Qilin Breach Claims

    The ATF confirmed a cyberattack by the Qilin ransomware group on a standalone internal system, which was quickly contained without affecting core infrastructure or daily operations. Qilin is a prominent Ransomware-as-a-Service operation that has compromised over 2,200 victims, including major cor...

    Read More »
  • Uber Freight probes alleged data breach claimed by hackers

    Uber Freight probes alleged data breach claimed by hackers

    The Helix hacking group claimed responsibility for a cyberattack on Uber Freight, allegedly stealing corporate data like emails and dispatch documents, though Uber Freight says operations remain unaffected. Helix has targeted multiple transportation and financial firms this year, using social eng...

    Read More »
  • Swiss govt SharePoint hack exposes 200 accounts

    Swiss govt SharePoint hack exposes 200 accounts

    Swiss federal IT agency BIT confirmed hackers breached its Microsoft SharePoint servers by exploiting known vulnerabilities, compromising roughly 200 user accounts after suspicious activity was detected on July 28. The attack likely used either CVE-2026-56164 (a privilege escalation flaw) or CVE-...

    Read More »
  • US government demands Instructure testimony on Canvas breach

    US government demands Instructure testimony on Canvas breach

    The U.S. House Committee on Homeland Security is demanding testimony from Instructure executives after the ShinyHunters extortion group carried out two cyberattacks on the Canvas platform, compromising student data and disrupting school operations during final exams. The first breach exposed 280 ...

    Read More »
  • Itron Reveals Cyber-Attack on Utility Tech Systems

    Itron Reveals Cyber-Attack on Utility Tech Systems

    Itron confirmed a cybersecurity breach in an SEC filing, where an unauthorized third party accessed its internal IT systems, prompting an immediate response with external advisors and law enforcement notification. The company fully remediated the unauthorized activity, found no breach in customer...

    Read More »
  • France’s Tchap messenger breached; officials and hacker clash on severity

    France’s Tchap messenger breached; officials and hacker clash on severity

    France's government-encrypted messaging platform Tchap was compromised, detected by ANSSI on June 7, though officials claim the breach was limited and did not expose sensitive communications. The hacker behind the breach disputes this, claiming a much larger cache of messages and user data was st...

    Read More »
  • US lawmakers press Instructure for answers on Canvas data breaches

    US lawmakers press Instructure for answers on Canvas data breaches

    U.S. House Homeland Security Committee Chair Andrew Garbarino has requested Instructure CEO Steve Daly testify about two data breaches that exposed sensitive student data from the Canvas software, with CISA assisting in the investigation. Instructure faced criticism after the same security vulner...

    Read More »
  • Meteor Tracking Nonprofit Hit by Cyberattack

    Meteor Tracking Nonprofit Hit by Cyberattack

    The International Meteor Organization suffered a severe cyberattack on its aging digital infrastructure, resulting in significant downtime and partial site outages. To maintain essential functions during the transition to new systems, the IMO is prioritizing fireball observations through alternat...

    Read More »
  • Grafana Labs source code stolen, refuses to pay hacker ransom

    Grafana Labs source code stolen, refuses to pay hacker ransom

    Grafana Labs confirmed a security breach where hackers exploited a stolen token to access its GitLab source code repositories, but the company will not pay the ransom demanded to prevent code release. The breach did not compromise customer records or financial data, and Grafana has revoked the co...

    Read More »
  • Trellix Confirms Source Code Breach

    Trellix Confirms Source Code Breach

    Trellix, a major US cybersecurity firm formed from the merger of McAfee Enterprise and FireEye, confirmed on May 4 that threat actors accessed its proprietary source code repository, prompting an investigation with law enforcement and forensic experts. The breach is particularly concerning becaus...

    Read More »
  • AkzoNobel U.S. Site Hit by Cyberattack, Company Confirms

    AkzoNobel U.S. Site Hit by Cyberattack, Company Confirms

    AkzoNobel, a major paints and coatings company, confirmed a contained cybersecurity breach at a U.S. facility, with the impact appearing limited. The Anubis ransomware gang claimed responsibility, alleging theft of 170 GB of sensitive data, including confidential agreements and employee personal ...

    Read More »
  • Report: Chinese hackers exploited VPN flaws to breach Ivanti customers

    Report: Chinese hackers exploited VPN flaws to breach Ivanti customers

    State-linked Chinese hackers exploited a hidden backdoor in Ivanti's Pulse Secure VPN in February 2021, compromising 119 organizations including government agencies and military contractors. The breach is linked to corporate restructuring after Ivanti's 2017 acquisition, where cost-cutting and la...

    Read More »
  • Ivanti Zero-Day Breach Hits European Governments

    Ivanti Zero-Day Breach Hits European Governments

    A coordinated cyber campaign exploited vulnerabilities in Ivanti Endpoint Manager Mobile (EPMM), compromising several European government bodies including the European Commission, Finnish government, and Dutch agencies in late January. The breaches exposed sensitive work-related data like employe...

    Read More »
  • Brightspeed Probes Data Breach Claims

    Brightspeed Probes Data Breach Claims

    Brightspeed, a major US fiber broadband provider, is investigating a potential data breach after the Crimson Collective cybercriminal group claimed responsibility for stealing sensitive customer information. The hackers allege the stolen data includes extensive personal and financial records for ...

    Read More »
  • Hackers Claim Resecurity Breach, Firm Calls It a Honeypot

    Hackers Claim Resecurity Breach, Firm Calls It a Honeypot

    A hacking group claimed to breach cybersecurity firm Resecurity, alleging theft of sensitive data like employee details and client lists as retaliation for social engineering attempts. Resecurity countered that the accessed systems were a deliberate honeypot, using fabricated data to lure and mon...

    Read More »
  • State Hackers Infiltrated Telecom Giant Ribbon for Months

    State Hackers Infiltrated Telecom Giant Ribbon for Months

    Ribbon Communications disclosed that state-sponsored hackers had unauthorized access to its systems for nearly a year, starting in December 2024, and has since removed them with law enforcement involvement. The breach affected a customer base including Fortune 500 companies and government departm...

    Read More »
  • F5 Networks Breached: Hackers Stole Code and Customer Data

    F5 Networks Breached: Hackers Stole Code and Customer Data

    State-sponsored hackers breached F5 Networks' systems, stealing proprietary source code and sensitive customer data, with the company detecting the intrusion on August 9 and implementing containment measures. The attackers accessed F5's BIG-IP development environment and knowledge systems, exposi...

    Read More »
  • Fintech Firm Targeted in $130M Bank Heist Attempt by Hackers

    Fintech Firm Targeted in $130M Bank Heist Attempt by Hackers

    Hackers attempted to steal approximately $130 million from Sinqia S.A., a Brazilian fintech subsidiary, by exploiting stolen credentials to access Brazil's Pix payment network. The breach was detected and contained, with some funds recovered and no customer data compromised, though Sinqia's acces...

    Read More »