exposed
-
Blog
IntelBroker leaks 2.9 TB of exposed Cisco records – and there’s more to come
Hackers have published data claimed to have been stolen from a Cisco developer resource, after an alleged misconfiguration left software artifacts available on the public internet. A well known threat actor has leaked 2.9 TB of data on the dark web, said to be part of a larger 4.5TB dataset, following up on their claims to have found an unprotected…
Read More » -
Blog
Over 25,000 SonicWall VPN Firewalls exposed to critical flaws
Over 25,000 publicly accessible SonicWall SSLVPN devices are vulnerable to critical severity flaws, with 20,000 using a SonicOS/OSX firmware version that the vendor no longer supports. These results come from an analysis conducted by cybersecurity firm Bishop Fox, which was motivated by a series of important vulnerabilities disclosed this year impacting SonicWall devices. Vulnerabilities affecting SonicWall SSL VPN devices were recently…
Read More » -
Blog
CISA warns water facilities to secure HMI systems exposed online
CISA and the Environmental Protection Agency (EPA) warned water facilities today to secure Internet-exposed Human Machine Interfaces (HMIs) from cyberattacks. HMIs are dashboards or user interfaces that help human operators connect to, monitor, and control industrial machines and devices via tablets, portable computers, or built-in displays. “In the absence of cybersecurity controls, threat actors can exploit exposed HMIs at WWS…
Read More » -
Blog
Anna Jaques Hospital ransomware breach exposed data of 300K patients
Anna Jaques Hospital has confirmed on its website that a ransomware attack it suffered almost precisely a year ago, on December 25, 2023, has exposed sensitive health data for over 310,000 patients. Anna Jaques is a not-for-profit community hospital in Massachusetts, recognized for delivering high-quality care and performing over 4,700 surgeries yearly. As a mid-size acute hospital providing 83 beds, 200…
Read More » -
Blog
Over 600,000 Personal Records Exposed by Data Broker
A database linked to SL Data Services, a U.S.-based data broker, has exposed 644,869 sensitive records online. The records included personally identifiable information, property ownership details, vehicle records, court records, and background check documents, and they lacked password protection or encryption. Security researcher Jeremiah Fowler discovered the exposure and reported it to the review and cyber research site WebsitePlanet. He…
Read More » -
Blog
Hackers exploit ProjectSend flaw to backdoor exposed servers
Threat actors are using public exploits for a critical authentication bypass flaw in ProjectSend to upload webshells and gain remote access to servers. The flaw, tracked as CVE-2024-11680, is a critical authentication bug impacting ProjectSend versions before r1720, allowing attackers to send specially crafted HTTP requests to ‘options.php’ to change the application’s configuration. Successful exploitation allows the creation of rogue…
Read More » -
Blog
1.1 Million UK NHS Employee Records Exposed
Over a million NHS employee records — including email addresses, phone numbers, and home addresses — were exposed online due to a misconfiguration of the low-code website builder Microsoft Power Pages. In September, researchers with the software-as-a-service security platform AppOmni identified a large shared business service provider for the NHS that was allowing unauthorised access to sensitive data through insecure…
Read More » -
Blog
D-Link won’t fix critical bug in 60,000 exposed EoL modems
Tens of thousands of exposed D-Link routers that have reached their end-of-life are vulnerable to a critical security issue that allows an unauthenticated remote attacker to change any user’s password and take complete control of the device. The vulnerability was discovered in the D-Link DSL6740C modem by security researcher Chaio-Lin Yu (Steven Meow), who reported it to Taiwan’s computer and response center (TWCERTCC).…
Read More » -
Blog
800,000 users exposed in Landmark Admin data breach
Insurance administrative services company Landmark Admin is warning 800,000 people that their sensitive data has been exposed, following a cyber attack earlier this year. According to the firm’s filing with the Attorney General of Maine, the breach involved an extremely broad range of personal data, including full names and addresses, Social Security numbers, tax identification numbers, drivers’ license numbers, and…
Read More » -
Blog
The National Public Data breach exposed nearly three billion users – now the company has filed for bankruptcy
Data broker National Public Data has filed for bankruptcy, claiming it cannot sustain the mounting financial and reputational damage associated with a major data breach it suffered in December 2023. The background-checking service filed for bankruptcy in Florida under its parent company Jerico Pictures Inc, and explicitly cited the 2023 data breach as a direct contributor to its downfall. NPD…
Read More »