SouthState Bank N.A., a regional financial institution operating more than 300 branches across the southeastern United States, has agreed to a $1.5 million class action settlement to resolve claims tied to a February 2024 data breach that exposed sensitive customer information.
Fiverr, an online marketplace connecting freelancers with clients worldwide, has denied allegations that it exposed sensitive user data following claims that documents were publicly accessible through a cloud storage service.
Booking.com, a Netherlands-based online travel and accommodation platform, has disclosed a data breach involving unauthorized access to customer booking information, potentially affecting an unknown number of users worldwide.
The National Railroad Passenger Corporation, known as Amtrak, has been identified by the hacking group ShinyHunters in an alleged cyberattack involving 9.4 million records, with the attackers threatening to release the data publicly if a ransom is not paid.
Data allegedly stolen from Hallmark Cards Inc., a U.S.-based greeting card and social expression products company, is now circulating on cybercrime forums, weeks after a ransomware group threatened to release millions of records linked to the company.
McGraw-Hill, a global education company specializing in textbooks and digital learning platforms, has confirmed that unauthorized access to a limited set of its data occurred due to a Salesforce misconfiguration, following claims by the hacking group ShinyHunters.
Hims & Hers Health Inc., a U.S.-based direct-to-consumer telehealth platform, disclosed a cybersecurity breach that exposed limited customer data after attackers gained access to its third-party customer support system using stolen single sign-on credentials.
Rockstar Games, the video game developer behind the Grand Theft Auto franchise, confirmed a data breach involving unauthorized access to internal systems after attackers exploited a third-party cloud analytics integration.
A Swedish human rights organization has filed a lawsuit against Telenor’s former Myanmar subsidiary, alleging the telecom operator shared sensitive user data with the country’s military regime, contributing to the targeting of political dissidents following the 2021 coup.
ChipSoft, a Netherlands-based developer of electronic health record software, has been hit by a ransomware attack that forced the company to take its website and several digital healthcare services offline, affecting hospitals and care providers across the country.
A cyberattack on Signature Healthcare, a regional hospital system in Massachusetts, has disrupted critical information systems and forced facilities to turn away ambulances while operating under emergency procedures, officials said.
Security researchers at LayerX say they’ve discovered a cross-site request forgery (CSRF) vulnerability in OpenAI’s ChatGPT Atlas browser that lets attackers inject hidden instructions into the assistant’s persistent memory, instructions that can survive sessions and devices and later trigger code execution or data exfiltration.
North Korean state-linked hackers are running a new cyber-espionage campaign against Europe’s defence sector, luring engineers in the drone industry with fake job offers to plant malware and steal sensitive technology.
A newly discovered worm named GlassWorm is spreading through Visual Studio Code extensions, marking one of the most sophisticated supply-chain attacks ever seen against developer ecosystems.
Australian hydraulics and processing company Aussie Fluid Power (AFP) has confirmed it is investigating a cybersecurity breach after the Anubis ransomware group claimed responsibility for an attack on its systems and published stolen data on the dark web.