OnTrac Breach Exposes Delivery Data
A March network intrusion at logistics firm OnTrac has triggered data protection warnings for affected customers.
30 results for “breach”
A March network intrusion at logistics firm OnTrac has triggered data protection warnings for affected customers.
A newly uncovered intrusion suggests threat actors are leveraging autonomous AI tools to streamline lateral movement and enumeration.
Recent security incidents involving OpenAI and the Kimi model reveal shifting concerns about internal AI oversight and containment.
The Swiss train manufacturer confirms it rejected a multi-million dollar extortion attempt following a third-party data breach.
A critical vulnerability in Oracle E-Business Suite led to the exposure of personal data at the global cosmetics firm.
A cyberattack on the billing software provider has resulted in the theft of employee, customer, and partner records.
Internal datasets and service credentials were compromised as attackers utilized a malicious dataset to gain unauthorized access.
An autonomous AI agent framework successfully breached internal Hugging Face infrastructure, marking a shift in attacker tactics.
A new index aims to standardize how we monitor material cyber incidents by prioritizing verifiable data over industry-wide estimates.
A third-party platform compromise has led to the unauthorized access of client tax documents at Ernst & Young.
A third-party IT management tool used by Ernst & Young was compromised, leading to the unauthorized exfiltration of tax documents.
Enterprise AI systems face active exploitation of a high-complexity remote code execution flaw following a recent patch release.
A sophisticated threat actor utilized zero-day exploits to gain deep access to SonicWall VPN appliances before official patches existed.
Time is running out for victims of the 2024 Fidelity data breach to claim their share of a $2.5 million settlement fund.
A compromised third-party support platform has led to the exposure of client tax files at professional services giant Ernst & Young.
Abbott is currently evaluating the security impact of two distinct unauthorized access claims within its diagnostic and lab portal divisions.
A Chinese sub-group's infiltration of DigiCert reveals how stolen code-signing certificates are weaponized against the industry.
New research confirms that public sector organizations now face a daily ransomware attack, highlighting a critical infrastructure crisis.
Compromised AsyncAPI and Jscrambler packages expose developers to credential theft via automated malicious injection.
A cyberattack targeting Fairlife has forced an immediate, temporary suspension of production for the Coca-Cola dairy subsidiary.
A coalition of attorneys general has secured an $18 million settlement from 23andMe regarding a 2023 genetic data breach.
A cyberattack on TriWest Healthcare compromised sensitive personal information belonging to approximately 12,000 TRICARE beneficiaries.
Two young men sentenced to prison for a major transport network breach highlight the dangers of high-skill, attention-seeking actors.
Regulators find the airline followed privacy rules despite a massive breach caused by a sophisticated vishing attack.
Two key figures in the Scattered Spider syndicate receive prison sentences for their role in the debilitating 2024 Transport for London breach.
A single master password granted unrestricted access to sensitive client files and employee impersonation at a law firm.
A sophisticated supply chain attack used legitimate GitHub pipelines to push malicious code via the AsyncAPI npm namespace.
New findings reveal that compromised credentials are now the primary catalyst for ransomware breaches, eclipsing software flaws.
Synopsys refutes claims of a massive database breach after a ransomware group alleged the theft of sensitive Bosch data.
NHS Forth Valley faces an investigation after an employee transferred sensitive maternity patient records to a personal email account.