Cybersecurity

Cybersecurity
DentaQuest Breach Affects 23.4 Million, PHI and SSNs Exposed
DentaQuest's breach notification confirms up to 23.4 million Medicaid dental enrollees potentially affected, with SSNs and dental PHI stolen in a network hack.
Cybersecurity
PEAR Ransomware Breach at MCBS Hits 1.26 Million Patients
PEAR ransomware group claimed 3 TB stolen from MCBS, a medical billing firm whose breach exposed 1.26 million patients at seven healthcare organizations.
Application Security
SourTrade Malvertising Assembles Malware in Browser Memory
SourTrade malvertising downloads encrypted fragments and assembles a Windows executable in browser memory, evading file-based detection across 12 countries.
Cybersecurity
ShinyHunters Breach Data Fuels $2,000 Bitcoin Sextortion Wave
Attackers are sending $2,000 Bitcoin sextortion emails that cite specific ShinyHunters-breached companies to make false surveillance threats appear credible.
Cybersecurity
Steam ClickFix Campaign Installs SYSTEM-Level XMRig Miner
Attackers target Steam discussion forums with ClickFix social engineering, tricking players into running PowerShell that installs a SYSTEM-level XMRig miner.
Application Security
GitHub and PyPI Add Time-Based Defenses Against Supply Chain Poisoning
GitHub's new Dependabot 72-hour cooldown and PyPI's 14-day release lock target two supply chain attack vectors that compromised major package ecosystems.
Application Security
Rockwell Patches Four Arena Code Execution Flaws Across Sectors
Rockwell Automation patched four memory corruption CVEs in Arena, its simulation software used by hospitals, supply chain firms, and defense contractors.
Cybersecurity
Scattered Spider TfL Hackers Sentenced to Five and a Half Years
UK authorities sentenced two Scattered Spider members to five-and-a-half years each for the 2024 Transport for London attack, the UK's largest cybercrime case.
Cybersecurity
ClickLock macOS Stealer Uses App-Kill Loop to Coerce Passwords
Group-IB documented ClickLock, a macOS stealer using a 210ms app-kill loop to coerce macOS passwords, hitting more than 100 victims across 33 countries.
Cybersecurity
Elastic Exposes TELEPUZ: C Malware Sold as MaaS via ClickFix Chain
Elastic Security Labs disclosed TELEPUZ, a C-based malware distributed through a ClickFix-to-Vidar chain with VirusTotal volumes indicating a MaaS operation.