The personal and medical information of nearly 20 million people was compromised in a cyberattack on Oracle Health's legacy Cerner systems early last year, Bloomberg reported, citing a report from the Texas attorney general. The figure is far higher than the counts that surfaced in earlier filings and patient notifications. Oracle has not made a public statement on the number of affected individuals and declined to comment to Bloomberg. READ MORE...
UK fashion retailer ASOS confirmed that a recent data breach was caused by a social engineering attack in which hackers stole an employee's login credentials and used them to access information on third-party platforms used by the company. "We discovered that an unauthorised party gained access to an ASOS employee account by impersonating a trusted contact to obtain log in credentials," reads an ASOS security notification shared with BleepingComputer. READ MORE...
Imagine going to a Google website at its correct URL, only to be redirected to a crim's illegitimate copy. Attackers hijacked top-level domains, allowing them to alter DNS records and mint fraudulent HTTPS certificates for several Google domains, and those belonging to other organizations. Google said it became aware of the series of attacks last week in the .gh (Ghana), .sl (Sierra Leone), and .as (American Samoa) country-code top-level namespaces (ccTLDs). READ MORE...
Autonomous OpenAI agents caused a partial outage of a Wikimedia online service and tried to use others as proxies as part of a series of unauthorized activities it performed across the nonprofit's wiki sites. Inspired by reports of OpenAI agents attempting to break into websites and online services, Wikimedia - a nonprofit foundation that provides technology and Web-hosting services for Wikipedia and other public wikis - did some investigating of its own services. READ MORE...
Yubico and Okta asked 1,890 technology and security professionals across nine countries how they sign in to work accounts. The most common answer was a username and password, at 43%, from a group in which 87% said they were familiar with passkeys. Half of respondents were issued a username and password when they started their current role. The report's authors argue that whatever IT hands out on day one is what people keep using. READ MORE...
Splunk and SonicWall on Wednesday announced patches for multiple critical- and high-severity vulnerabilities in their products, including flaws that could lead to arbitrary code execution. SonicWall rolled out fixes for four vulnerabilities in its SMA1000 appliances, urging users to update to versions 12.5.0-03082 and 12.4.3-03670 as soon as possible. The most severe of the issues is a pre-authenticated SSRF bug that exists due to an unintended alternate access path. READ MORE...
The owner of ransomware remediation company MonsterCloud has been charged with allegedly defrauding ransomware victims by secretly paying their attackers for decryptors while claiming to use proprietary technology to recover encrypted data. Zohar Pinhasi, 50, also known as "Zack Silver" and "Zack Green," was indicted by a federal grand jury in the Eastern District of New York on September 23 and arraigned Wednesday in federal court in Brooklyn. READ MORE...
ESET researchers traced almost two years of changes to MATCHBOIL, a downloader that the Russia-aligned group UAC-0099 uses to plant a second program on Windows machines in Ukraine. Every victim in ESET's telemetry was in Ukraine: transportation companies in July and August 2025, a manufacturer in December 2025, and an energy company in June 2026. The program MATCHBOIL installs is a spying tool, and the access it creates may be useful to other groups. READ MORE...
A suspected Italian attacker armed with a malware-controlling poem has infected more than 3,000 servers since April, breaking into enterprise AI infrastructure to mine cryptocurrency and add compromised systems to its growing botnet. This is the first case of "adversarial poetry" - an AI jailbreak technique that turns harmful prompts into poems to trick LLMs into bypassing safety guardrails - that Lumen's Black Lotus Labs, which has been tracking the PoeLLM malware, has seen in real-world attacks. READ MORE...
If you thought that having companies trawling your social media, browsing history, and TV habits for behavioral clues was bad, sit tight. Meta is just getting started. Its Muse personal AI agent is taking surveillance to the next level. TIME magazine analyzed the software's internal instructions and found that it maintains constantly updated dossiers on users and the people they know. Meta released Muse last month, positioning it as a digital assistant that can handle different parts of your life. READ MORE...
U.S. government agencies are failing to prepare for the transition to post-quantum encryption, creating the risk that their sensitive data will still be vulnerable to decryption by quantum computers whenever those machines are deployed, according to the Government Accountability Office. Experts are divided over when the advent of cryptographically relevant quantum computers (CRQC) will occur, but GAO bluntly declared that "threats from a CRQC could have devastating impacts to federal systems." READ MORE...