TransUnion suffers data breach impacting over 4.4 million people

Picus Blue Report 2025

Update: Story updated with confirmation that this was another Salesforce data theft attack and the types of data stolen. Consumer credit reporting giant TransUnion warns it suffered a data breach exposing the personal information of over 4.4 million people in the United States, with BleepingComputer learning the data wasstolen from it’s Salesforce account. TransUnion is … Ler mais

200 Swedish municipalities impacted by a major cyberattack on IT provider

200 Swedish municipalities impacted by a major cyberattack on IT provider

200 Swedish municipalities impacted by a major cyberattack on IT provider Cyberattack on Miljödata disrupted services in over 200 Swedish municipalities, with concerns over stolen sensitive data. A cyberattack on Miljödata, an IT supplier serving 80% of Swedish municipalities, including Skellefteå,MönsteråsandKalmar, disrupted services in over 200 municipalities and raised concerns of stolen sensitive data. The … Ler mais

Malicious VS Code Extensions Exploit Name Reuse Loophole

Malicious VS Code Extensions Exploit Name Reuse Loophole

A new campaign involving malicious Visual Studio Code (VS Code) extensions has exposed a loophole in the VS Code Marketplace that allows threat actors to reuse names of previously removed packages. The extensions, which carried the name “shiba,”delivered ransomware through a multi-stage attack. How the Attack Works ReversingLabsresearchers found that one of the malicious extensions, … Ler mais

Nevada Confirms Ransomware Attack, State Data Stolen

Nevada Confirms Ransomware Attack, State Data Stolen

A security incident impacting the state of Nevada has been confirmed to be a ransomware attack. Nevada’s chief information officer (CIO) Tim Galluzi provided the update in a press conference on August 27, also revealing that the attackers had exfiltrated data from state networks. “At this stage of our intensive investigation, we cannot yet identify … Ler mais

Servidores FreePBX atingidos por exploração de 0 dias, desativar o acesso à Internet aconselhado

FreePBX Servers Hit by 0-Day Exploit, Disable Internet Access Advised

Os administradores da FreePBX em todo o mundo foram solicitados a desativar imediatamente o acesso público à Internet a seus sistemas depois que uma vulnerabilidade crítica de 0 dias foi descoberta no módulo de gerente de terminais comerciais. A equipe de segurança Sangoma Freepbx confirmado Esse código de exploração controlado pelo atacante pode obter a … Ler mais

TransUnion discloses a data breach impacting over 4.4 million customers

TransUnion discloses a data breach impacting over 4.4 million customers

TransUnion discloses a data breach impacting over 4.4 million customers TransUnion reported a data breach in which threat actors accessed personal information of over 4.4 million customers. TransUnion disclosed a data breach that impacted more than 4,461,511 customers. The company is one of the three major credit reporting agencies in the United States (alongside Experian … Ler mais

Cisco Nexus 3000 e 9000 Vulnerabilidade permite ataques de DOS

Cisco Nexus 3000 & 9000 Vulnerability Enables DoS Attacks

A Cisco emitiu um aviso de consultoria de segurança de alta severidade de uma perigosa vulnerabilidade em seus interruptores da série Nexus 3000 e 9000 que poderiam permitir que os invasores desencadeiam ataques de negação de serviço (DOS) através de pacotes de rede criados. A vulnerabilidade, rastreada ASCVE-2025-20241 e atribuiu uma pontuação CVSS de 7,4, … Ler mais

The UK May Be Dropping Its Backdoor Mandate – Schneier on Security

HomeBlog The UK May Be Dropping Its Backdoor Mandate The US Director of National Intelligence is reporting that the UK government is dropping its backdoor mandate against the Apple iPhone. For now, at least, assuming that Tulsi Gabbard is reporting this accurately. Tags: Apple, backdoors, crypto wars, iPhone, UK Posted on August 28, 2025 at … Ler mais

Chinese Tech Firms Linked to Salt Typhoon Espionage Campaigns

Chinese Tech Firms Linked to Salt Typhoon Espionage Campaigns

The UK, US and partners from across the globe have released a new report on the notorious Chinese APT group Salt Typhoon, claiming it has received help from several commercial tech companies to further its cyber-espionage goals. The report named Sichuan Juxinhe Network Technology, Beijing Huanyu Tianqiong Information Technology and Sichuan Zhixin Ruijie Network Technology … Ler mais

Nova pesquisa explora as táticas de aranha dispersas em cenários do mundo real

New Research Explores Emulating Scattered Spider Tactics in Real-World Scenarios

Especialistas descreveram métodos para imitar as estratégias do grupo de ameaças persistentes (APT), em uma análise recente aprofundada da empresa de segurança cibernética Lares, permitindo que as empresas fortalecem suas defesas por meio de cooperação adversária. Lares é especialista em emulação de ameaças, replicando táticas, técnicas e procedimentos do mundo real observados em atividades cibercriminais. … Ler mais