Unlimited Technology Systems Breach Affects 3.8 Million People
Healthcare software provider Unlimited Technology Systems disclosed an October 2025 breach impacting over 3.8 million individuals and sensitive healthcare data.
Tag
30 results in the archive.
Healthcare software provider Unlimited Technology Systems disclosed an October 2025 breach impacting over 3.8 million individuals and sensitive healthcare data.
Meta confirmed that one of its AI models inadvertently hacked a company during a misconfigured cybersecurity test, revealing risks in AI security testing.
The Greatness phishing-as-a-service toolkit now uses device code phishing to exploit OAuth 2.0 Device Authorization Grant, bypassing MFA and hijacking accounts.
Talos analyzed prompt logs from various AI applications used by threat actors to understand their evolving tactics, revealing increased sophistication in leveraging cloud-based AI for malicious activities.
Adform's advertising scripts were compromised in a supply-chain attack that hijacks clipboard cryptocurrency addresses to redirect funds to attackers.
Cisco disclosed a high-severity zero-day vulnerability in its Secure Firewall Management Center involving static credentials, actively exploited to gain unauthorized access.
A coordinated cyberattack targeted operational technology at over 30 Minnesota community water systems in late July, causing outages and communication disruptions.
Iranian state-backed group Nimbus Manticore deploys NightLedger backdoor and custom WebSocket tunnelers in attacks across the Middle East, Africa, and South Asia, enhancing stealth and covert activity.
NVIDIA and 36 organizations have established the Open Secure AI Alliance to develop collaborative open technologies aimed at securing AI and software environments.
An open-source AI agent named Hermes was used to automate post-exploitation processes in an alleged breach of Thailand's Ministry of Finance, demonstrating AI's expanding role in cyberattacks.
A malvertising campaign named SourTrade targets retail traders by using browsers and a legitimate Bun runtime to assemble Windows malware executables, evading traditional detection methods.
The Certighost exploit enables low-privileged Active Directory users to obtain Domain Controller certificates and authenticate as domain controllers, risking critical Kerberos credential compromise.
A malvertising campaign on Bing promotes a fake Claude desktop app from a legitimate domain to deliver SectopRAT malware, posing a threat to affected systems.
The Anubis ransomware group has claimed responsibility for a cyberattack on Coca-Cola's Fairlife brand and threatened to leak stolen data if ransom demands are not met.
Russian intelligence services compromise internet-connected security cameras across Europe and Ukraine to gather military logistics intelligence, as reported by the Netherlands' AIVD and MIVD.
An advanced threat actor exploits the update mechanism of ViPNet private networking software to attack Russian government agencies, illustrating ongoing espionage.
Abbott Laboratories is investigating unauthorized access incidents affecting Exact Sciences legacy systems and its LabCentral portal, with allegations of stolen company data linked to extortion.
North Korean threat actors linked to the Contagious Interview campaign employ steganography within SVG flag images in fake coding challenges to deliver multi-stage OTTERCOOKIE-aligned malware.
ClickLock is a new macOS information-stealing malware that tricks users into revealing their system login password by terminating visible processes.
The OkoBot malware framework deploys more than 20 payloads aimed at stealing cryptocurrency wallet seed phrases, credentials, and sensitive data, posing a notable threat to individuals and enterprises.
CISA issued a warning about three actively exploited vulnerabilities in Internet-exposed on-premises SharePoint Server instances that allow remote compromise.
Zoom has disclosed a critical vulnerability in its Windows desktop client and SDK that enables unauthenticated attackers to hijack user accounts, posing a significant security risk.
Microsoft released its largest Patch Tuesday, addressing 622 security flaws including two actively exploited zero-day vulnerabilities, critical for millions of affected systems.
A threat actor created almost 300 counterfeit GitHub repositories impersonating legitimate software projects to deliver infostealer malware, posing a significant supply chain threat.
Spanish Police arrested four individuals and dismantled a cybercrime network responsible for €140 million in losses through investment fraud and business email compromise attacks.
CISA warns that remote code execution vulnerabilities are actively exploited in Joomla iCagenda and Balbooa Forms extensions through arbitrary file uploads, risking full compromise of affected sites.
Google and Microsoft removed the ModHeader browser extension from their stores due to a dormant hidden browsing-history collector found in the official version, with no evidence of active data transmission.
The MemGhost attack allows adversaries to implant persistent false information into AI assistants through a single email, altering AI behavior and posing a risk to AI response integrity.
The jscrambler npm package version 8.14.0 was compromised to install a Rust-based infostealer via a preinstall hook, impacting Windows, macOS, and Linux environments.
Researchers reveal cyber espionage targeting Pakistani law enforcement by suspected China- and India-aligned groups between 2024 and 2026, compromising police servers with critical data.