A cybersecurity incident involving Seiko USA, the American division of Japanese watchmaker Seiko Holdings, surfaced over the weekend after attackers defaced a section of the company’s website and issued a ransom demand, claiming to have stolen sensitive customer data from its e-commerce systems.
KelpDAO, a decentralized finance protocol specializing in liquid restaking on Ethereum, suffered a major cyberattack that resulted in the theft of approximately $290 million in digital assets, with early indicators pointing to involvement by North Korea-linked hackers.
A dataset purportedly containing approximately 400,000 customer records linked to Bol.com, a leading e-commerce marketplace in Belgium and the Netherlands, has surfaced for sale on a cybercrime forum, raising concerns about potential data exposure.
Vercel, a cloud development platform specializing in hosting and deployment infrastructure for modern web applications, has confirmed a security incident involving unauthorized access to certain internal systems after threat actors claimed to have breached the company and offered stolen data for sale.
Inditex, a Spain-based global fashion retailer and the parent company of brands including Zara, Bershka, and Stradivarius, has disclosed a data breach involving unauthorized access to databases managed by a third-party technology provider.
A ransomware attack on Cookeville Regional Medical Center, a 289-bed healthcare provider in Tennessee, has compromised the personal and medical information of approximately 337,000 individuals after hackers exfiltrated roughly 500GB of data from its systems.
SouthState Bank N.A., a regional financial institution operating more than 300 branches across the southeastern United States, has agreed to a $1.5 million class action settlement to resolve claims tied to a February 2024 data breach that exposed sensitive customer information.
Fiverr, an online marketplace connecting freelancers with clients worldwide, has denied allegations that it exposed sensitive user data following claims that documents were publicly accessible through a cloud storage service.
Booking.com, a Netherlands-based online travel and accommodation platform, has disclosed a data breach involving unauthorized access to customer booking information, potentially affecting an unknown number of users worldwide.
The National Railroad Passenger Corporation, known as Amtrak, has been identified by the hacking group ShinyHunters in an alleged cyberattack involving 9.4 million records, with the attackers threatening to release the data publicly if a ransom is not paid.
Data allegedly stolen from Hallmark Cards Inc., a U.S.-based greeting card and social expression products company, is now circulating on cybercrime forums, weeks after a ransomware group threatened to release millions of records linked to the company.
Security researchers at LayerX say they’ve discovered a cross-site request forgery (CSRF) vulnerability in OpenAI’s ChatGPT Atlas browser that lets attackers inject hidden instructions into the assistant’s persistent memory, instructions that can survive sessions and devices and later trigger code execution or data exfiltration.
North Korean state-linked hackers are running a new cyber-espionage campaign against Europe’s defence sector, luring engineers in the drone industry with fake job offers to plant malware and steal sensitive technology.
A newly discovered worm named GlassWorm is spreading through Visual Studio Code extensions, marking one of the most sophisticated supply-chain attacks ever seen against developer ecosystems.
Australian hydraulics and processing company Aussie Fluid Power (AFP) has confirmed it is investigating a cybersecurity breach after the Anubis ransomware group claimed responsibility for an attack on its systems and published stolen data on the dark web.