Schemata API Flaw Exposed Military Data
A defense technology company exposed user records and military training materials through API endpoints lacking authorization checks, affecting hundreds of user records and sensitive course information.
Attackers exploit identity verification processes, particularly during onboarding and account recovery, to gain unauthorized access to corporate systems.
A defense technology company exposed user records and military training materials through API endpoints lacking authorization checks, affecting hundreds of user records and sensitive course information.
DAEMON Tools devs confirm breach, release malware-free version after supply chain attack trojanized software, impacting thousands of systems worldwide.
Ransomware attacks often succeed even when backups exist, as attackers target and destroy backup systems before launching encryption, making recovery impossible.
Australia has launched a Cyber Incident Review Board to conduct independent reviews of major cyberattacks, focusing on systemic lessons rather than individual culpability.
A new Linux malware, Quasar Linux, targets software developers with rootkit, backdoor, and credential-stealing capabilities, enabling potential supply-chain attacks.
CISA is urging critical infrastructure owners to plan for delivering essential services under emergency conditions, potentially for months, due to threats from state-sponsored hackers.
Germany's federal cabinet has advanced legislation to expand law enforcement use of surveillance technology, including automated biometric image matching against publicly available internet data.
Approximately 5.4 million end-of-life package versions are not being checked by security tools, leaving organizations vulnerable to exploits.
A Latvian ransomware affiliate has been sentenced to over 8 years in prison for conducting attacks on behalf of Conti and Akira, causing $56 million in losses.