IT Security Newsletter - 10/14/2025
SimonMed says 1.2 million patients impacted in January data breach
U.S. medical imaging provider SimonMed Imaging is notifying more than 1.2 million individuals of a data breach that exposed their sensitive information. SimonMed Imaging is an outpatient medical imaging and radiology services provider, including MRI and CT scans, X-ray, ultrasound, mammography, PET, nuclear medicine, bone density, and interventional radiology procedures. The radiology company operates about 170 medical centers 11 U.S. states, and has an annual revenue of more than $500 million. READ MORE...
Harvard investigating breach linked to Oracle zero-day exploit
Harvard University is investigating a data breach after the Clop ransomware gang listed the school on its data leak site, saying the alleged breach was likely caused by a recently disclosed zero-day vulnerability in Oracle's E-Business Suite servers. "Harvard is aware of reports that data associated with the University has been obtained as a result of a zero-day vulnerability in the Oracle E-Business Suite system." a Harvard University Information Technology spokesperson told BleepingComputer. READ MORE...
Flax Typhoon can turn your own software against you
For more than a year, hackers from a Chinese state-backed espionage group maintained backdoor access to a popular software mapping tool by turning one of its own features into a webshell, according to new research from ReliaQuest. In a report published Tuesday, researchers said that Flax Typhoon - a group that has been spying on entities in the U.S., Europe and Taiwan since at least 2021 - has had access for more than a year to a private ArcGIS server. READ MORE...
Financial, Other Industries Urged to Prepare for Quantum Computers
Financial firms, government agencies, and other sectors with sensitive data need to worry about the arrival of quantum computers today, even though a cryptographically relevant quantum computer (CRQC) may be decades away, experts warn. In late September, the Financial Services Information Sharing and Analysis Center (FS-ISAC) warned that crypto-procrastination is resulting in financial firms being unprepared for the future threats and data risks posed by quantum computers. READ MORE...
Oracle rushes out another emergency E-Business Suite patch as Clop fallout widens
Oracle is rushing out another emergency patch for its embattled E-Business Suite as the fallout from the Clop-linked attacks continues to spread. The newly disclosed flaw, tracked as CVE-2025-61884 and slapped with a CVSS score of 7.5, affects the Runtime UI component in EBS, and Oracle's advisory warns that the flaw can be exploited remotely without authentication and "may allow access to sensitive resources." READ MORE...
Windows 10 Still on Over 40% of Devices as It Reaches End of Support
Windows 10 has reached end of support (EOS) today, October 14, 2025, but the operating system is still running on hundreds of millions of devices. With Windows 10 reaching EOS, Microsoft will no longer provide free software updates, technical support, or security patches. PCs running Windows 10 will continue to work, but they will become increasingly vulnerable to malware and other cyberattacks as new threats emerge and no patches are released. READ MORE...
Microsoft 'illegally' tracked students via 365 Education, says data watchdog
An Austrian digital privacy group has claimed victory over Microsoft after the country's data protection regulator ruled the software giant "illegally" tracked students via its 365 Education platform and used their data. noyb said the ruling [PDF] by the Austrian Data Protection Authority also confirmed that Microsoft had tried to shift responsibility for access requests to local schools, and the software and cloud giant would have to explain how it used user data. READ MORE...
Pixnapping Attack Steals Data From Google, Samsung Android Phones
A team of researchers at Carnegie Mellon University has identified a new attack method that can allow malicious applications to steal sensitive data from Android devices. Named Pixnapping, the attack has been demonstrated against Google and Samsung phones. Google has released one patch for the Android operating system and is working on an additional fix to protect devices against potential attacks. READ MORE...
Researchers break OpenAI guardrails
The maker of ChatGPT released a toolkit to help protect its AI from attack earlier this month. Almost immediately, someone broke it. On October 6, OpenAI ran an event called DevDay where it unveiled a raft of new tools and services for software programmers who use its products. As part of that, it announced a tool called AgentKit that lets developers create AI agents using its ChatGPT AI technology. READ MORE...
- ...in 1884, George Eastman receives a patent for his paper-strip photographic film.
- ...in 1947, Charles "Chuck" Yeager becomes the first pilot to break the sound barrier, flying the experimental Bell X1 rocket plane.
- ...in 1962, the Cuban Missile Crisis begins, with Soviet-made missiles with nuclear capabilities being spotted by US intelligence in western Cuba.
- ...in 2012, daredevil Felix Baumgartner successfully parachutes from a height of 24 miles, setting multiple world records for both altitude and free-fall velocity.