Blog
-
Data Broker That Scraped Hundreds of Millions of Records Loses Data to Hack
The data broker, DemandScience, has only just now confirmed it was the source of 122 million records offered for sale on BreachForums earlier in the year. However, DemandScience insists that it has not detected an internal breach and that the data must have been taken from a contractor or partner.
-
Third Party Breach of MOVEit Vulnerability Hits Amazon, Employee Data Remains at Risk
With a total of five million records on offer, and over half of those belonging to Amazon, the third party breach is definitely a matter of concern. However, statements from both Amazon and the hacker indicate that the stolen employee data did not contain highly sensitive information.
-
CISA’s Top Exploited Vulnerabilities List Stresses Importance of Timely Patching
Very few people probably need a reminder at this point, but CISA’s annual list of the most frequently exploited vulnerabilities reinforces the importance of timely patching when zero-days are announced.
-
Hacker Spree of Fake Invoices Stems From Permissive DocuSign APIs
Hackers are using the DocuSign APIs to forge authentic-looking fake invoices for payment backed by the trusted “docusign.net” domain. The term “hacking” is used loosely here as it is something that any paying customer with Envelopes API access could do.
-
Hackers Demonstrates Gathering Stolen Credentials Is as Easy as Scanning for Git Config Files
Recent campaign called “EmeraldWhale” snapped up over 15,000 stolen credentials simply by mass scanning for errant web configurations exposing Git config files to the public.
-
Trump and Vance’s Phone Data Targeted by Chinese Hackers That Broke Into Telcos
Thus far officials are being tight-lipped about the campaign of the Chinese hackers and any phone data they might have accessed, which points to something potentially being stolen. As to what is anyone’s guess.
-
Delta Has a Slim Path to Victory in CrowdStrike Lawsuit Over IT Outage and Flight Disruptions
Delta has been threatening to sue CrowdStrike over the July flight disruptions that caused mass chaos for travelers, and both parties have now filed papers against each other. CrowdStrike pins the extended IT outage primarily on Delta’s “antiquated” systems.
-
Data Breach Information Used to Bilk Canada Revenue Agency for Over $100 Million in Fake Tax Refunds
Canada Revenue Agency (CRA) has admitted that it has been undercounting fake tax refunds it has paid out for at least several years now, and what appeared to be tens of incidents per year has actually been tens of thousands.
-
AI and National Security a Top Focus in the Final Days of the Biden Administration
Some of the national security memo is an exhortation to Congress to authorize funding for projects seen as vital to keeping up with China in these areas. But federal agencies can be expected to immediately pick up the pace in integrating AI and recruiting talent, and both protections and new risk guidelines will be coming…
-
SolarWinds Hack Continues to Cost Companies as SEC Tracks Down Insufficient Cybersecurity Disclosures
“Overly broad language” and concealment of file access in SolarWinds hack cybersecurity disclosures can lead to fines in the millions of dollars, as an SEC investigation has recently demonstrated.










