Category: Uncategorized
-
Delta Dental of California Discloses Data Breach Impacting 6.9 Million People Ionut Arghire
Delta Dental of California says over 6.9 million individuals were impacted by a data breach caused by the MOVEit hack. The post Delta Dental of California Discloses Data Breach Impacting 6.9 Million People appeared first on SecurityWeek. Read More
-
SEC Shares Important Clarifications as New Cyber Incident Disclosure Rules Come Into Effect Eduard Kovacs
The SEC has provided some important clarifications on its new cyber incident disclosure requirements, which come into effect on December 18. The post SEC Shares Important Clarifications as New Cyber Incident Disclosure Rules Come Into Effect appeared first on SecurityWeek. Read More
-

Unmasking the Dark Side of Low-Code/No-Code Applications [email protected] (The Hacker News)
Low-code/no-code (LCNC) and robotic process automation (RPA) have gained immense popularity, but how secure are they? Is your security team paying enough attention in an era of rapid digital transformation, where business users are empowered to create applications swiftly using platforms like Microsoft PowerApps, UiPath, ServiceNow, Mendix, and OutSystems? The simple truth is often swept…
-
3CX Urges Customers to Disable Integration Due to Potential Vulnerability Ionut Arghire
3CX tells customers to temporarily disable SQL Database integration to mitigate a potential vulnerability. The post 3CX Urges Customers to Disable Integration Due to Potential Vulnerability appeared first on SecurityWeek. Read More
-

QakBot Malware Resurfaces with New Tactics, Targeting the Hospitality Industry [email protected] (The Hacker News)
A new wave of phishing messages distributing the QakBot malware has been observed, more than three months after a law enforcement effort saw its infrastructure dismantled by infiltrating its command-and-control (C2) network. Microsoft, which made the discovery, described it as a low-volume campaign that began on December 11, 2023, and targeted the hospitality industry. “TargetsRead More
-

CISA Urges Manufacturers Eliminate Default Passwords to Thwart Cyber Threats [email protected] (The Hacker News)
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) is urging manufacturers to get rid of default passwords on internet-exposed systems altogether, citing severe risks that could be exploited by malicious actors to gain initial access to, and move laterally within, organizations. In an alert published last week, the agency called out Iranian threat actors affiliated withRead More
-
MongoDB Confirms Hack, Says Customer Data Stolen Ryan Naraine
MongoDB CISO Lena Smart said the company was not aware of any exposure to the data that customers store in the MongoDB Atlas product. The post MongoDB Confirms Hack, Says Customer Data Stolen appeared first on SecurityWeek. Read More
-

MongoDB Suffers Security Breach, Exposing Customer Data [email protected] (The Hacker News)
MongoDB on Saturday disclosed it’s actively investigating a security incident that has led to unauthorized access to “certain” corporate systems, resulting in the exposure of customer account metadata and contact information. The American database software company said it first detected anomalous activity on December 13, 2023, and that it immediately activated its incident responseRead More
-

China’s MIIT Introduces Color-Coded Action Plan for Data Security Incidents [email protected] (The Hacker News)
China’s Ministry of Industry and Information Technology (MIIT) on Friday unveiled draft proposals detailing its plans to tackle data security events in the country using a color-coded system. The effort is designed to “improve the comprehensive response capacity for data security incidents, to ensure timely and effective control, mitigation and elimination of hazards and losses causedRead More
-

Microsoft Warns of Storm-0539: The Rising Threat Behind Holiday Gift Card Frauds [email protected] (The Hacker News)
Microsoft is warning of an uptick in malicious activity from an emerging threat cluster it’s tracking as Storm-0539 for orchestrating gift card fraud and theft via highly sophisticated email and SMS phishing attacks against retail entities during the holiday shopping season. The goal of the attacks is to propagate booby-trapped links that direct victims to adversary-in-the-middle (AiTMRead…
