Critical Zimbra RCE flaw now actively exploited in attacks
CERT Polska, the Polish Computer Emergency Response Team (CERT), warned that attackers have begun exploiting a critical vulnerability in Zimbra Collaboration Suite (ZCS). [...]
CERT Polska, the Polish Computer Emergency Response Team (CERT), warned that attackers have begun exploiting a critical vulnerability in Zimbra Collaboration Suite (ZCS). [...]
A set of 40 Mozilla Firefox extensions has been found to engage in cryptocurrency wallet theft by masquerading as OKX, Rabby Wallet, TronLink, and other Web3 products. According to the Socket Threat Research team, the extensions are part of a broader set of 77 browser add-ons th…
CISA, the Department of Health and Human Services (HHS), and the Federal Bureau of Investigation (FBI) have issued an updated […] The post Medusa Ransomware Group Has Attacked 500+ Critical Infrastructure Orgs appeared first on The HIPAA Journal.
Microsoft is investigating a potential issue with the August 2026 updates that may prevent some games from launching or cause them to crash on affected Windows 11 systems. [...]
See what an investigation actually looks like and learn where organizations fail so you can avoid government fines and drawn out investigations. Based on real experience in over 250 OCR investigations. The post Free Webinar Recording: Inside 250 HIPAA Investigations – What You N…
Ours Privacy Raises $15 Million Series A To Scale HIPAA-Compliant Healthcare Marketing Platform Across 200+ Organizations Pulse 2.0
Cybersecurity researchers have disclosed details of a critical flaw in the Elementor Pro WordPress plugin that, if successfully exploited, could lead to remote code execution. The vulnerability, tracked as CVE-2026-32475, carries a CVSS score of 9.0 out of 10.0. It has been desc…
ChatGPT is experiencing a major outage, and users are unable to sign in, create accounts, or load chats, including previous conversations. [...]
A CISA, o FBI e o Departamento de Saúde e Serviços Humanos dos EUA (HHS) publicaram uma atualização do alerta conjunto sobre o ransomware Medusa, informando que o grupo já comprometeu mais de 500 organizações em todo o mundo até abril de 2026, com forte direcionamento a infraestr…
Agências do governo dos Estados Unidos, incluindo a NSA, o FBI, a CISA e o Departamento de Energia, emitiram um alerta sobre uma ameaça ativa contra PLCs (controladores lógicos programáveis) da série S7 da Siemens, utilizados em sistemas de infraestrutura crítica como abastecimen…
O CPQD marcará presença no Febraban Tech 2026, um dos principais eventos de tecnologia e inovação para o setor financeiro da América Latina, que será realizado entre os dias 24 e 26 de agosto, no Distrito Anhembi, em São Paulo. Promovido pela Federação Brasileira de Bancos (Febra…
A suspected ransomware affiliate is posing as a ransomware recovery service called "Ransom Busters," contacting the victims before the attacks become public and claiming to be able to provide decryption keys and delete stolen data for a fee. [...]
A suspected ransomware affiliate is posing as a ransomware recovery service called "Ransom Busters," contacting the victims before the attacks become public and claiming to be able to provide decryption keys and delete stolen data for a fee. [...]
Japanese cloud and data center service provider Sakura Internet disclosed that hackers accessed its sales management system, where customer contract and membership information is stored. [...]
Heidi Overton, a medical doctor and veteran of the America First think tank, currently serves as deputy director of the White House Domestic Policy Council.
The AI company officially forbids illicit use, while offering guardrail-free social engineering, offensive cybercrime, and OSINT scanning to anyone with a bit of cryptocurrency.
U.S. healthcare IT company CareCloud disclosed that the data breach incident it suffered earlier this year has impacted more than 3.7 million individuals. [...]
Katie Moussouris of Luta Security talks with the Dark Reading News Desk about how enterprises will now need to monitor risks posed by their own agents in the wake of the recent Hugging Face attack.
A Agência de Segurança Cibernética e Infraestrutura dos EUA (CISA) adicionou uma vulnerabilidade crítica de autenticação no Microsoft SharePoint (CVE-2026-55040) ao seu catálogo de vulnerabilidades conhecidas exploradas (KEV) em 18 de agosto, após confirmação de exploração ativa,…
HIPAA Breach Notification Deadline Starts at Discovery, Not Investigation Completion Crowell & Moring LLP