Security News

Record breach of French government exposes up to 43 million people's data
2024-03-14 16:06

A French government department - responsible for registering and assisting unemployed people - is the latest victim of a mega data breach that compromised the information of up to 43 million citizens. "The database allegedly extracted illicitly contains the personal identification data of people currently registered, people previously registered over the last 20 years as well as people not registered on the list of job seekers but having a candidate space on francetravail.fr," the statement reads, which was translated electronically from French.

French unemployment agency data breach impacts 43 million people
2024-03-14 13:32

France Travail has informed the country's data protection agency, the National Commission of Informatique and Liberties, which stated that up to 43 million people may be impacted. This data increases the risk of identity theft and phishing for the exposed individuals, so the agency recommends potentially impacted people to be particularly vigilant with emails, phone calls, and SMS they receive.

QEMU Emulator Exploited as Tunneling Tool to Breach Company Network
2024-03-08 07:48

Threat actors have been observed leveraging the QEMU open-source hardware emulator as tunneling software during a cyber attack targeting an unnamed "large company" to connect to their...

American Express credit cards exposed in third-party data breach
2024-03-04 13:38

American Express is warning customers that credit cards were exposed in a third-party data breach after a merchant processor was hacked. This incident was not caused by a data breach at American Express, but rather at a merchant processor in which American Express Card member data was processed.

American Express credit cards exposed in vendor data breach
2024-03-04 13:38

American Express is warning customers that credit cards were exposed in a third-party data breach after one of its service providers was hacked. In a data breach notification filed with the state of Massachusetts, American Express said that the breach occurred at one of its service providers used by their travel services division, American Express Travel Related Services Company.

Golden Corral restaurant chain data breach impacts 183,000 people
2024-02-29 22:14

The Golden Corral American restaurant chain disclosed a data breach after attackers behind an August cyberattack stole the personal information of over 180,000 people. "On or about August 15, 2023, Golden Corral experienced a data security incident that caused a temporary disruption to our corporate operations," Golden Corral said.

20 million Cutout.Pro user records leaked on data breach forum
2024-02-29 15:56

Pro has suffered a data breach exposing the personal information of 20 million members, including email addresses, hashed and salted passwords, IP addresses, and names. On Tuesday, someone using the alias 'KryptonZambie' shared a link on the BreachForums hacking forum to CSV files containing 5.93 GB of data stolen from Cutout.

APT29 revamps its techniques to breach cloud environments
2024-02-27 12:05

Russian threat actors APT29 are changing their techniques and expanding their targets to access cloud environments, members of the Five Eyes intelligence alliance have warned. Microsoft was victim of the same breach and, more recently, the same threat actors hacked into its corporate mailboxes, stealing emails and attached documents.

Insomniac Games alerts employees hit by ransomware data breach
2024-02-23 18:56

Sony subsidiary Insomniac Games is sending data breach notification letters to employees whose personal information was stolen and leaked online following a Rhysida ransomware attack in November. In December, Sony said they were investigating the Rhysida ransomware gang's claims that they breached Insomniac Games and stole over 1.3 million files from its network.

Microsoft expands free logging capabilities after May breach
2024-02-21 22:31

Microsoft has expanded free logging capabilities for all Purview Audit standard customers, including U.S. federal agencies, six months after disclosing that Chinese hackers stole U.S. government emails undetected in an Exchange Online breach between May and June 2023. "Beginning this month, expanded logging will be available to all agencies using Microsoft Purview Audit regardless of license tier," a press release issued today reads.