loader image
Nova Scotia Power Hack Exposes Customer Data Theft

Nova Scotia Power confirmed that hackers accessed and stole sensitive customer data in a cybersecurity breach discovered last month. The utility provider, which supplies electricity across the Canadian province, disclosed that the incident involved unauthorized access to its systems by threat actors who exfiltrated confidential customer information. The company did not specify the exact nature […]

Russia Orders Tracking App for All Foreigners in Moscow

Russia has enacted a new law mandating that all foreign nationals in the Moscow region install a location-tracking application on their mobile devices, according to a government announcement. The measure is part of a broader strategy aimed at monitoring the movements of non-citizens within the capital and its surrounding areas. The tracking app will reportedly […]

M&S Says Cyberattack to Cut Profit by £300 Million

Marks & Spencer said a recent cyberattack will reduce its operating profit by an estimated £300 million, citing ongoing disruption expected to last through July. The British retailer disclosed that the financial impact figure is calculated before factoring in potential cost mitigation, insurance coverage or trading-related actions. The company did not specify details about the […]

Samlify Flaw Lets Hackers Bypass SSO as Admin Users

A critical vulnerability has been identified in Samlify, a SAML-based Single Sign-On (SSO) library, that enables attackers to bypass authentication and gain administrative access. The flaw allows malicious actors to inject unsigned assertions into otherwise valid SAML responses, effectively tricking the system into granting elevated privileges without proper verification. The vulnerability stems from improper validation […]

Enzene Biosciences Hit by Cyberattack on U.S. Ops

Enzene Biosciences, a biotechnology subsidiary of Indian pharmaceutical giant Alkem Laboratories, has experienced a cybersecurity breach that disrupted its U.S. operations, according to a report by The Cyber Express. The incident, which involved unauthorized access, reportedly led to a compromise of company funds, although the scope and financial impact have not been disclosed. The attack […]

Arla Foods Hit by Cyberattack, Production Disrupted

Arla Foods has confirmed that it was targeted by a cyberattack that disrupted production operations, causing delays across its supply chain. The dairy giant disclosed the incident to BleepingComputer, stating that the attack affected its ability to produce and distribute goods efficiently. While the company did not provide details about the nature or scope of […]

Crawlomatic Plugin Patched for Critical RCE Flaw

A critical remote code execution vulnerability with a CVSS score of 9.8 has been patched in the Crawlomatic WordPress plugin, according to a notice published by cybersecurity sources. The flaw stemmed from a missing file type validation mechanism, which allowed attackers to upload arbitrary files to affected systems. This oversight enabled unauthorized users to execute […]

vBulletin Flaw Exposes Forums to Remote Code Attacks

A critical vulnerability in vBulletin, one of the most widely used internet forum platforms, has exposed thousands of websites to unauthenticated remote code execution (RCE), cybersecurity researchers have disclosed. The flaw affects vBulletin versions 5.x and 6.x running on PHP 8.1 or later, where changes to PHP’s Reflection API allow attackers to invoke protected methods […]

Fred Hutch to Pay $50 Million in Data Breach Deal

Fred Hutchinson Cancer Center has agreed to pay over $50 million in the aftermath of a 2023 data breach, earmarking the funds for damages, infrastructure upgrades, and fraud monitoring services. The financial commitment follows a cyberattack that compromised sensitive information, prompting the organization to take corrective measures to mitigate fallout and prevent future incidents. According […]

Victoria’s Secret Delays Results After Cyberattack

Victoria’s Secret & Co. has postponed the release of its first-quarter 2025 earnings after experiencing a security incident that disrupted its corporate systems. The fashion retailer is currently engaged in system restoration efforts following the breach, which occurred on May 24, according to a company statement. The decision to delay the earnings report highlights the […]

**Splunk Windows Flaw Lets Users Bypass Admin Controls**

A high-severity vulnerability in Splunk’s Universal Forwarder for Windows is exposing enterprise systems to unauthorized access by non-administrator users. Tracked as CVE-2025-20298 with a CVSS v3.1 score of 8.0, the flaw stems from incorrect permission settings applied during installation or upgrade processes. Affected versions include branches 9.4 (below 9.4.2), 9.3 (below 9.3.4), 9.2 (below 9.2.6), […]

Lee Enterprises Says Hack Exposed Data of 40,000

Lee Enterprises said a ransomware attack led to a data breach affecting approximately 40,000 individuals, following the completion of its internal investigation. The media company confirmed that unauthorized access to its systems resulted in the exposure of sensitive personal information, though it did not specify the exact nature of the compromised data. The breach was […]