Major US Banks Exposed in SitusAMC Vendor Breach
Client data from major US financial institutions, including JPMorgan Chase, Citi, and Morgan Stanley, may have been exposed following a […]
Major US Banks Exposed in SitusAMC Vendor Breach Read More »
Client data from major US financial institutions, including JPMorgan Chase, Citi, and Morgan Stanley, may have been exposed following a […]
Major US Banks Exposed in SitusAMC Vendor Breach Read More »
Spanish flag carrier Iberia has notified customers of a data breach stemming from a compromise at a third-party supplier. The
Iberia Airlines Confirms Customer Data Breach via Third-Party Vendor Read More »
A new report from ENISA, the EU’s cybersecurity agency, highlights that public administration bodies are being increasingly targeted by hacktivists.
ENISA Report: DDoS Attacks Surge Against EU Public Administration Read More »
A new report from BitSight reveals a significant security gap between financial firms and their third-party vendors. While the financial
Financial Sector Vendors Have Weaker Security Than Banks, Creating Risk Read More »
Hyundai AutoEver America, the in-house IT and software company for Hyundai and Kia, has disclosed a data breach. Attackers had
Hyundai AutoEver (IT Firm for Hyundai & Kia) Discloses Data Breach, SSNs Stolen Read More »
A critical (CVSS 9.8) vulnerability, CVE-2025-11953, has been disclosed in the popular “@react-native-community/cli” NPM package, which has ~2 million weekly
Critical (CVSS 9.8) Flaw in React Native NPM Package Exposes Developers to RCE Read More »
Cisco has released patches for two critical vulnerabilities in its Unified Contact Center Express (UCCX) appliance. The most severe, CVE-2025-20354
Critical RCE Flaws in Cisco Contact Center (CVSS 9.8) Allow Root Access Read More »
Cloud software provider Blackbaud has agreed to a $49.5 million settlement with 49 U.S. state attorneys general over its 2020
Blackbaud Pays $49.5 Million Settlement for 2020 Ransomware Breach Read More »
CISA has updated its advisory on the critical WSUS vulnerability (CVE-2025-59287), attributing active, widespread exploitation to the Russian state-sponsored group
CISA Warns: Russian APT “Strontium” Actively Exploiting WSUS Flaw Read More »
A new phishing technique dubbed “GhostLink” has emerged. Attackers compromise a user’s account (e.g., Teams or Zoom) and join a
New “GhostLink” Phishing Tactic Uses Malicious QR Codes in Video Meetings Read More »