14 Jun Insurance giant Globe Life investigating web portal breach American financial services holding company Globe Life says attackers may have accessed consumer and policyholder data after breaching one of its web portals. […]
13 Jun Microsoft delays Windows Recall amid privacy and security concerns Microsoft is delaying the release of its AI-powered Windows Recall feature to test and secure it further before releasing it in a public preview on Copilot+ PCs. […]
13 Jun Truist Bank confirms breach after stolen data shows up on hacking forum Truist Bank, a leading U.S. commercial bank, confirmed this week that its systems were breached in an October 2023 cyberattack after a threat actor posted some of the company’s data for sale on a hacking forum. […]
13 Jun Toronto District School Board hit by a ransomware attack The Toronto District School Board (TDSB) is warning that it suffered a ransomware attack on its software testing environment and is now investigating whether any personal information was exposed. […]
13 Jun Panera warns of employee data breach after March ransomware attack U.S. food chain giant Panera Bread is notifying employees of a data breach after unknown threat actors stole their sensitive personal information in a March ransomware attack. […]
13 Jun Exploit for Veeam Recovery Orchestrator auth bypass available, patch now A proof-of-concept (PoC) exploit for a critical Veeam Recovery Orchestrator authentication bypass vulnerability tracked as CVE-2024-29855 has been released, elevating the risk of being exploited in attacks. […]
13 Jun YouTube tests harder-to-block server-side ad injection in videos YouTube reportedly now injects ads directly into video streams to make it more difficult for ad blockers to block advertisements. […]
12 Jun Phishing emails abuse Windows search protocol to push malicious scripts A new phishing campaign uses HTML attachments that abuse the Windows search protocol (search-ms URI) to push batch files hosted on remote servers that deliver malware. […]
12 Jun CISA warns of criminals impersonating its employees in phone calls Today, the Cybersecurity and Infrastructure Security Agency (CISA) warned that criminals are impersonating its employees in phone calls and attempting to deceive potential victims into transferring money. […]
12 Jun New phishing toolkit uses PWAs to steal login credentials A new phishing kit has been released that allows red teamers and cybercriminals to create progressive web Apps (PWAs) that display convincing corporate login forms to steal credentials. […]