Weekly Cybersecurity Stories – 10 February 2025

Read the handpicked cybersecurity stories. These stories include cyber incidents, security vulnerabilities, ransomware incidents, security research reports and more. These stories have been curated from the leading cybersecurity journals and sites.

Cybersecurity stories for 7 February 2025

2024 Saw Increase in Ransomware Attacks but 35% Decrease in Payments

A blockchain analysis suggests an increasing reluctance to pay money to ransomware groups. A new report from Chainalysis revealed a 35% year-over-year decline in ransom payments, which fell from $1.25 billion in 2023 to $813,550,000 in 2024 – the second-lowest annual total in the past 5 years behind the $655.44M paid in 2022. In the first half of 2024, the number of additions to ransomware groups’ data leak sites increased by 2.38% compared to the corresponding period in 2023, and attacks continued to increase in H2 reaching a peak in November 2024. Read the full story.

Hospital Sisters Health System: August 2023 Data Breach Affected 883K Individuals

Hospital Sisters Health System (HSHS) in Springfield, IL, and Prevea Health in Green Bay, WI, were affected by a cyberattack in late August which caused an outage on August 27, 2023, that affected their computer systems, phone lines, and websites. The outage lasted for several days, during which time HSHS and Prevea operated under downtime procedures. The attack took its websites and certain applications offline, including the MyChart and MyPrevea applications. HSHS was also unable to process online payments as its computer system was offline, but care continued to be provided to patients. Read the full story.

DeepSeek iOS App Sending Data Unencrypted to ByteDance Controlled Server 

Critical vulnerabilities have been disclosed in the DeepSeek iOS app, raising concerns over privacy and national security risks. The app, which has been the top iOS download since January 25, 2025, transmits sensitive user data unencrypted to servers controlled by ByteDance, the Chinese company behind TikTok. The NowSecure report highlights several alarming flaws in the DeepSeek iOS app. Read the full story.

Ex-Google Engineer Charged for Stealing AI Secrets to China

A Federal grand jury has indicted Linwei Ding, also known as Leon Ding, on four counts of theft of trade secrets. The charges allege that Ding, a former Google software engineer, illegally transferred proprietary artificial intelligence (AI) data to his personal accounts while covertly affiliating with Chinese companies in the AI sector. The indictment was unsealed today following Ding’s arrest in Newark, California. Read the full story.

Ransomware Extortion Drops to $813.5M in 2024, Down from $1.25B in 2023

Ransomware attacks netted cybercrime groups a total of $813.5 million in 2024, a decline from $1.25 billion in 2023. The total amount extorted during the first half of 2024 stood at $459.8 million, blockchain intelligence firm Chainalysis said, adding payment activity slumped after July 2024 by about 3.94%. “The number of ransomware events increased into H2, but on-chain payments declined, suggesting that more victims were targeted, but fewer paid,” the company said. Read the full story.

Kimsuky hackers use new custom RDP Wrapper for remote access

The North Korean hacking group known as Kimsuky was observed in recent attacks using a custom-built RDP Wrapper and proxy tools to directly access infected machines. This is a sign of shifting tactics for Kimsuky, according to AhnLab SEcurity Intelligence Center (ASEC), who discovered the campaign. ASEC says the North Korean hackers now use a diverse set of customized remote access tools instead of relying solely on noisy backdoors like PebbleDash, which is still used. Read the full story.

Critical RCE bug in Microsoft Outlook now exploited in attacks

CISA warned U.S. federal agencies on Thursday to secure their systems against ongoing attacks targeting a critical Microsoft Outlook remote code execution (RCE) vulnerability. Discovered by Check Point vulnerability researcher Haifei Li and tracked as CVE-2024-21413, the flaw is caused by improper input validation when opening emails with malicious links using vulnerable Outlook versions. The attackers gain remote code execution capabilities because the flaw lets them bypass the Protected View and open malicious Office files in editing mode. Read the full story.

Microsoft says attackers use exposed ASP.NET keys to deploy malware

Microsoft warns that attackers are deploying malware in ViewState code injection attacks using static ASP. NET machine keys found online. As Microsoft Threat Intelligence experts recently discovered, some developers use ASP.NET validationKey and decryptionKey keys (designed to protect ViewState from tampering and information disclosure) found on code documentation and repository platforms in their own software. Read the full story.

Lawmakers push for DeepSeek ban from federal devices over China concerns

Two lawmakers have introduced a bill to ban the Chinese artificial intelligence platform DeepSeek from any federal devices. Reps. Josh Gottheimer (D-N.J.) and Darin LaHood (R-IL) unveiled the “No DeepSeek on Government Devices Act” on Thursday to address security concerns about DeepSeek since it emerged as a powerful, low-cost alternative to U.S.-made AI tools like ChatGPT.  “The Chinese Communist Party has made it abundantly clear that it will exploit any tool at its disposal to undermine our national security, spew harmful disinformation, and collect data on Americans,” Gottheimer said. “Now, we have deeply disturbing evidence that they are using DeepSeek to steal the sensitive data of U.S. citizens. This is a five alarm national security fire.” Read the full story.

Cybersecurity stories for 6 February 2025

Over 5 billion accounts breached in 2024, China emerges as top target

The number of compromised accounts in 2024 surged eightfold compared to the previous year, with nearly half of all breaches concentrated in just three countries. Over five billion accounts were breached last year, a “staggering” increase from 730 million in 2023, according to researchers from cybersecurity firm Surfshark. It means that nearly 180 accounts were compromised every second, they said. Read the full story.

DDoS attacks reportedly behind DayZ and Arma network outages

An ongoing distributed denial of service (DDoS) attack targets Bohemia Interactive’s infrastructure, preventing players of DayZ and Arma Reforger from playing the games online. Bohemia Interactive is a Czech video game developer and publisher known for its popular Arma Series tactical shooters and DayZ, a standalone survival game from an Arma 2 mod. Starting last Friday, players of Bohemia’s games started experiencing server connectivity issues that prevented them from playing online. Read the full story.

Spanish police arrest hacker accused of attacks on NATO, US Army

A hacker who claimed responsibility for dozens of cyberattacks on government institutions in Spain and the U.S. was arrested by Spanish National Police.  Spanish officials touted the arrest in a statement on Wednesday, accusing the unnamed hacker of breaching systems used by the U.S. Army, United Nations, the International Civil Aviation Organization, the North Atlantic Treaty Organization and several government bodies in Spain. Read the full story.

IMI reports ‘unauthorized’ cyber activity in latest incident affecting UK engineering firms

The British engineering company IMI has reported a cyber incident to the London Stock Exchange (LSE) — the second U.K.-based engineering giant to do so in the last nine days. In a short notification to the exchange, the company said that as of Thursday, it was responding to an “incident involving unauthorised access to the Company’s systems.” “As soon as IMI became aware of the unauthorised access, the Company engaged external cyber security experts to investigate and contain the incident,” they wrote. Read the full story.

Thailand cuts power supply to Myanmar scam hubs

Thailand cut off power supply on Wednesday to three areas in Myanmar where online scamming hubs are concentrated.  The cuts to fuel, internet and electricity target the scam hubs of Myawaddy, Payathonzu and Tachileik, where criminal syndicates have set up enclaves devoted to fraud. Last week, China’s Assistant Minister of Public Security Liu Zhongyi met with the Thai commissioner of the Cyber Crime Investigation Bureau where he reportedly called on the Thai government to do more to stop scamming activity in Myanmar. Read the full story.

Uganda detains 9 finance ministry officials over central bank hack

Uganda’s police have detained nine finance ministry officials as part of an investigation into accusations of hacking the central bank’s electronic systems that resulted in theft of 62 billion shillings ($16.87 million), the ministry and police said. Those detained include the senior most official of the ministry’s Treasury department, the police and the finance ministry said. Read the full story.

Researchers Link DeepSeek’s Blockbuster Chatbot to Chinese Telecom Banned From Doing Business in US

he website of the Chinese artificial intelligence company DeepSeek, whose chatbot became the most downloaded app in the United States, has computer code that could send some user login information to a Chinese state-owned telecommunications company that has been barred from operating in the United States, security researchers say. The web login page of DeepSeek’s chatbot contains heavily obfuscated computer script that when deciphered shows connections to computer infrastructure owned by China Mobile, a state-owned telecommunications company. The code appears to be part of the account creation and user login process for DeepSeek. Read the full story.

Banking Malware Uses Live Numbers to Hijack OTPs, Targeting 50,000 Victims in India

Mobile devices have become a prime target for financial fraud, as the availability of digital payments and interception of OTPs (one-time passwords) for authentication make them vulnerable. Threat actors’ latest targets are Indian bank users, forced to reveal sensitive financial/personal data in a sophisticated mobile malware campaign, uncovered by the Zimperium zLabs research team. According to the company, banking trojans are targeting Indian banks and government institutions, and live phone numbers are used to intercept and redirect SMS messages, putting sensitive data at risk. Read the full story.

Cisco patches two critical Identity Services Engine flaws

Cisco has fixed two critical vulnerabilities in its Identity Services Engine (ISE) that could allow an authenticated remote attacker to execute arbitrary commands as root or access sensitive information, modify configurations, and reload affected devices. The first flaw, CVE-2025-20124, stems from the insecure deserialization of user-supplied Java byte streams in Cisco ISE. The second bug, an authorization bypass vulnerability tracked as CVE-2025-20125, was also disclosed by Radulea. Read the full story.

Italy says Paragon spyware targeted victims in dozens of European countries

Seven Italians and victims in more than a dozen other European countries were targeted with spyware as part of a broad hacking campaign revealed by WhatsApp on Friday, the Italian government said. The country’s Agenzia per la Cybersicurezza Nazionale (ANC), a cybersecurity agency, is investigating the alleged hacking attempts by Paragon Solutions, the Italian government said in a statement Wednesday. Read the full story.

Thousands of McKinney, Texas, residents impacted by October data breach

A large suburb of Dallas informed thousands of residents that a cyberattack in October exposed sensitive information. The city of McKinney, about 35 minutes outside of Dallas, said its government systems were breached on October 31 but security systems only discovered the attack on November 14. After the incident was discovered, the city’s IT team “severed any unauthorized activity” and contacted the FBI, Department of Homeland Security, and Texas Department of Information. “Our investigation determined that certain files may have been exposed without authorization,” the city said in breach notification letters and in a notice on the government website. Read the full story.

CISA orders agencies to patch Linux kernel bug exploited in attacks

​CISA has ordered federal agencies to secure their systems within three weeks against a high-severity Linux kernel flaw actively exploited in attacks. Tracked as CVE-2024-53104, the security bug was first introduced in kernel version 2.6.26 and was patched by Google for Android users on Monday. “There are indications that CVE-2024-53104 may be under limited, targeted exploitation,” the Android February 2025 Android security updates warn. Read the full story.

AMD fixes bug that lets hackers load malicious microcode patches

AMD has released mitigation and firmware updates to address a high-severity vulnerability that can be exploited to load malicious CPU microcode on unpatched devices. The security flaw (CVE-2024-56161) is caused by an improper signature verification weakness in AMD’s CPU ROM microcode patch loader. Attackers with local administrator privileges can exploit this weakness, resulting in the loss of confidentiality and integrity of a confidential guest running under AMD Secure Encrypted Virtualization-Secure Nested Paging (SEV-SNP). Read the full story.

Cybersecurity stories for 5 February 2025

Russian Hackers Exploited 7-Zip Zero-Day Against Ukraine

Russian threat groups have conducted cyberespionage campaigns against government entities in Ukraine exploiting a zero-day vulnerability in the 7-Zip archiver tool, Trend Micro reports. Tracked as CVE-2025-0411 (CVSS score of 7.0), the exploited flaw was discovered in September 2024 and patched two months later, in 7-Zip version 24.09. Trend Micro reveals that CVE-2025-0411 has been exploited in the wild, in a SmokeLoader campaign targeting Ukrainian government entities and other organizations in the country, likely for cyberespionage. Read the full story.

Spain arrests suspected hacker of US and Spanish military agencies

The Spanish police have arrested a suspected hacker in Alicante for allegedly conducting 40 cyberattacks targeting critical public and private organizations, including the Guardia Civil, the Ministry of Defense, NATO, the US Army, and various universities. “Using up to three different pseudonyms, the suspect attacked international governmental organizations, accessing databases containing personal information of employees and customers, as well as internal documents that were later sold or freely published on forums,” reads the Spanish police’s announcement. Read the full story.

Treasury says DOGE review has ‘read-only’ access to federal payments system

An assessment of the Treasury Department’s payment system is occurring with “read-only” access by a tech executive hired as an “expert/consultant,” according to a letter sent Tuesday to a senator who had asked about the process. The response, by the department’s Office of Legislative Affairs, comes as lawmakers, cybersecurity experts and privacy advocates have criticized reported activities by Elon Musk’s Department of Government Efficiency (DOGE). The ad-hoc White House agency’s access to the Treasury’s payment system has already drawn a privacy lawsuit by labor union groups. Read the full story.

Ransomware payments drop for first time in years following law enforcement disruptions

Efforts to starve ransomware cybercriminals of their profits appear to finally be having an effect, with the extortion payments that have been funding the criminal ecosystem dropping last year according to a new report by Chainalysis. The surprising and significant drop — down approximately 35% from $1.25 billion to $812.55 million — took place almost entirely in the second half of the year, with the first six months initially indicating 2024 would actually be “the worst year on record,” as the company said at the time. Read the full story.

Hackers Exploiting A Six-Year-Old IIS Vulnerability To Gain Remote Access

The eSentire Threat Response Unit (TRU) revealed that threat actors are actively exploiting a six-year-old IIS vulnerability in Progress Telerik UI for ASP.NET AJAX to gain remote access to systems. This vulnerability, identified as CVE-2019-18935, allows attackers to execute arbitrary code on vulnerable servers, posing a significant risk to organizations that have not updated their systems. Read the full story.

CISA Adds Apache, Microsoft Vulnerabilities to Its Database that Are Actively Exploited in the Wild

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has updated its Known Exploited Vulnerabilities (KEV) Catalog, adding several newly identified vulnerabilities to its authoritative list of security flaws exploited in the wild. The two vulnerabilities are CVE-2024-45195 and CVE-2024-29059. The vulnerabilities need to be remediated by 25 February 2025. Read the full story.

Critical Veeam Backup Vulnerability Let Attackers Execute Arbitrary Code to Gain Root Access

A critical vulnerability, identified as CVE-2025-23114, has been discovered in the Veeam Updater component, a key element of multiple Veeam backup solutions.  This flaw enables attackers to execute arbitrary code on affected servers through a Man-in-the-Middle (MitM) attack, potentially granting root-level permissions. The vulnerability has been assigned a severity score of 9.0, underscoring its significant risk. Read the full story.

Zyxel won’t patch newly exploited flaws in end-of-life routers

Zyxel has issued a security advisory about actively exploited flaws in CPE Series devices, warning that it has no plans to issue fixing patches and urging users to move to actively supported models. VulnCheck discovered the two flaws in July 2024, but last week, GreyNoise reported having seen exploitation attempts in the wild. VulnCheck presented the full details of the two flaws it observed in attacks aimed at gaining initial access to networks. CVE-2025-0890 and CVE-2024-40891 are the two vulnerabilities. Read the full story.

Cyber agencies share security guidance for network edge devices

Five Eyes cybersecurity agencies in the UKAustraliaCanada, New Zealand, and the U.S. have issued guidance urging makers of network edge devices and appliances to improve forensic visibility to help defenders detect attacks and investigate breaches. “Foreign adversaries routinely exploit software vulnerabilities in network edge devices to infiltrate critical infrastructure networks and systems. The damage can be expensive, time-consuming, and reputationally catastrophic for public and private sector organizations,” CISA said. Read the full story.

Threat actor claims to have breached Trump Hotels

A threat actor on BreachForums Tuesday posted what appears to be a sample leak from an alleged data set of 160,000 plus records stolen from the famed Trump Hotels[.]com. The alleged sample was posted on the hacker forum at about 4:00 am Eastern Time by a fairly unknown user, only active on Breached since last August, and who goes by the name FutureSeeker. It appears that the hacker exposed details from the TrumpHotels e-mail notification system, “specifically, the service responsible for reminding and/or verifying reservation details for guests,” said malware repository vx-underground, who posted about the alleged leak on X. Read the full story.

Union groups sue Treasury over giving DOGE access to sensitive data

Union groups that represent 7.2 million people filed a lawsuit Monday against the Treasury Department for handing over information including Social Security numbers, tax return data and bank account details to Elon Musk’s Department of Government Efficiency (DOGE). Plaintiffs in the lawsuit, which include the Alliance for Retired Americans, the American Federation of Government Employees and the Service Employees International Union, allege that Musk and his surrogates are violating a federal law known as the Privacy Act, which bans the government from sharing individuals’ records without consent or unless a statutory exception applies. Read the full story.

Proposal for federal cyber scholarship, with service requirement, returns in House

The chairman of the House Homeland Security Committee will reintroduce legislation on Wednesday to address the country’s digital workforce shortage by creating a new ROTC-like scholarship program for two-year cyber degrees. The bill’s revival will happen the same day the panel holds a hearing on the widening talent shortfall. The measure by Mark Green (R-TN) received unanimous support from the committee last yearRead the full story.

Grubhub says hack on third-party exposed information on campus customers

The delivery service Grubhub said a hacker stole personal data and partial payment card information from customers through a third-party contractor. In a statement published on Monday evening, the company said it recently identified a security incident that “originated with an account belonging to a third-party service provider that provided support services to Grubhub.” The information stolen includes names, email addresses, phone numbers, card types and the last four digits of card numbers. Read the full story.

Researchers warn of risks tied to abandoned cloud storage buckets

Cloud storage tools used by military, government and even cybersecurity organizations around the world have been left abandoned by their users, exposing them to a wide variety of security risks. Cybersecurity researchers at watchTowr published a lengthy report on Tuesday outlining the findings from a study of abandoned Amazon Web Services (AWS) S3 buckets — tools used by a variety of organizations to store code, files, templates and more. Read the full story.

Cybersecurity stories for 4 February 2025

GrubHub data breach impacts customers, drivers, and merchants

​Food delivery company GrubHub disclosed a data breach impacting the personal information of an undisclosed number of customers, merchants, and drivers after attackers breached its systems using a service provider account. “Our investigation found that the intrusion originated with an account belonging to a third-party service provider that provided support services to Grubhub,” the company said on Monday. “We immediately terminated the account’s access and removed the service provider from our systems altogether.” Read the full story.

Australia bans DeepSeek on government devices

Australia joins a growing list of countries imposing bans on DeepSeek, a Chinese chatbot that has taken the world by storm. The Secretary of the Department of Home Affairs issued a mandatory direction for all government entities to “prevent the use or installation of DeepSeek products, applications and web services.” Home Affairs Minister Tony Burke said DeepSeek posed an “unacceptable risk” to government technology and the ban was “to protect Australia’s national security and national interest.” Read the full story.

California man steals $50 million using fake investment sites, gets 7 years

A 59-year-old man from Irvine, California, was sentenced to 87 months in prison for his involvement in an investor fraud ring that stole $50 million between 2012 and October 2020. Allen Giltman and other fraudsters used over 150 fraudulent sites impersonating financial institutions that advertised various investment opportunities (primarily certificates of deposit with higher than average rates of return to lure victims in) and solicited money from investors. Read the full story.

Microsoft Patches Critical Azure AI Face Service Vulnerability with CVSS 9.9 Score

Microsoft has released patches to address two Critical-rated security flaws impacting Azure AI Face Service and Microsoft Account that could allow a malicious actor to escalate their privileges under certain conditions. The flaws are CVE-2025-21396 (CVSS score: 7.5) – Microsoft Account Elevation of Privilege Vulnerability and CVE-2025-21415 (CVSS score: 9.9) – Azure AI Face Service Elevation of Privilege Vulnerability. Read the full story.

XE Group Cybercrime Gang Moves from Credit Card Skimming to Zero-Day Exploits

Malware hunters have caught a known Vietnamese cybercrime gang called XE Group shifting tactics beyond credit card-skimming to exploiting at least two zero-day vulnerabilities in a widely deployed enterprise software product. A joint investigation by researchers from Intezer and Solis Security is warning that XE Group targeted VeraCore, a platform used by fulfillment companies, commercial printers, and e-retailers to manage orders and operations. Read the full story.

Hundreds of Thousands Hit by Data Breaches at Healthcare Firms in Colorado, North Carolina

Asheville Eye Associates and Delta County Memorial Hospital District last week disclosed separate data breaches that impacted hundreds of thousands of individuals. On Friday, Asheville Eye Associates said the personal and medical information of a subset of its patients was compromised as a result of a cybersecurity incident. On Friday, non-profit hospital district Delta County Memorial Hospital informed the Maine Attorney General’s Office that hackers had compromised the personal information of 148,363 people in a May 2024 cyberattack. Read the full story.

768 Vulnerabilities Exploited in the Wild in 2024: A 20% Year-Over-Year Surge

According to the latest findings from VulnCheck, 768 Common Vulnerabilities and Exposures (CVEs) were publicly reported as exploited in the wild for the first time this year. VulnCheck’s analysis shows that in 2024, 1% of all published CVEs were reported to have been exploited in the wild. An alarming trend observed in 2024 is the speed at which vulnerabilities are being exploited. VulnCheck reports that 23.6% of Known Exploited Vulnerabilities (KEVs) were actively exploited on or before their public disclosure date. Read the full story.

Casio UK online store hacked to steal customer credit cards

Casio UK’s e-shop at casio.co.uk was hacked to include malicious scripts that stole credit card and customer information between January 14 and 24, 2025. Any customers who made purchases between those dates may have had their personal details and credit card data stolen by hackers. The incident was discovered by JSCrambler, who notified Casio on January 28. The malicious script was removed from the Casio UK site within 24 hours. Read the full story.

Google fixes Android kernel zero-day exploited in attacks

The February 2025 Android security updates patch 48 vulnerabilities, including a zero-day kernel vulnerability that has been exploited in the wild. This high-severity zero-day (tracked as CVE-2024-53104) is a privilege escalation security flaw in the Android Kernel’s USB Video Class driver that allows authenticated local threat actors to elevate privileges in low-complexity attacks. Read the full story.

Mississippi electric utility warns 20,000 residents of data breach

An electric utility, Yazoo Valley Electric Power Association, serving multiple counties in Mississippi was attacked by cybercriminals last summer in an incident that exposed the information of more than 20,000 residents. In breach notification letters filed with regulators last week, the utility confirmed it discovered “suspicious activity” on August 26 and initiated an investigation. “A thorough investigation determined that an unauthorized actor accessed certain files on our network. We then conducted a thorough review of the potentially impacted data to determine the types of information contained therein and to whom the information related,” the organization said. Read the full story.

Australia sanctions ‘Terrorgram’ white supremacist online group

Australia on Monday imposed sanctions on the white supremacist online network Terrorgram, following similar actions by the U.S. and the U.K. Australian Foreign Minister Penny Wong said in a statement that the sanctions are part of ongoing efforts to combat antisemitism and “keep Australians safe.” It is also the first time Australia has sanctioned an entity based entirely online. “There is no place in Australia for antisemitism, hatred, or violence,” Wong said. Read the full story.

Canadian charged in two crypto platform thefts totaling $65 million

A Canadian man has been charged by U.S. federal prosecutors for allegedly hacking into two popular crypto platforms and stealing nearly $65 million. The Justice Department unsealed a five-count indictment on Monday accusing 22-year-old Andean Medjedovic of the two hacks, which targeted KyberSwap and Indexed Finance. The department did not say if Medjedovic is in custody or where he may be located. Read the full story.

Cybersecurity stories for 3 February 2025

Casio and 16 Other Websites Hit by Double-Entry Web Skimming Attack

A recent investigation has revealed a significant web skimming campaign affecting at least 17 websites, including the UK site of electronics giant Casio. Researchers uncovered these infections, likely stemming from vulnerabilities in Magento or similar e-commerce platforms, and are working to notify all affected parties.  Client-side web security provider, Jscrambler, has published exclusive details about a web skimmer infection that impacted electronic brand Casio’s UK website and 16 additional victims, and detected on January 28. Read the full story.

Russian hackers suspected of compromising British PM’s personal email account

Russia is suspected of compromising the personal email account of the British prime minister, Keir Starmer, before he entered office, according to a recently published book. As reported by The Times — which is serializing the book, titled “Get In” — it “reveals that in 2022 Starmer, then the Labour leader in opposition, was told that his email account may have been compromised in a sophisticated ­campaign by Kremlin-linked hackers.” Read the full story.

Sweden releases suspected ship, says cable break ‘clearly’ not sabotage

The Swedish Prosecution Authority (SPA) announced on Monday it was releasing a cargo ship that had been suspected of sabotaging a communications cable in the Baltic Sea, explaining that its investigators were now ruling out an act of sabotage. “The investigation concerning a cable break between Sweden and Latvia in the Baltic Sea has clarified that it is not a case of gross sabotage. Therefore, a decision has been made to lift the seizure of the ship suspected of being involved in the cable break,” the authority stated. Read the full story.

Taiwan bans government departments from using DeepSeek AI

Taiwan on Monday banned government departments from using Chinese startup DeepSeek’s artificial intelligence (AI) service as it was a security risk, toughening language from last week which said it should not be used. During a cabinet meeting, Taiwan Premier Cho Jung-tai said DeepSeek was banned from use in all government agencies “to ensure the country’s information security”, his office said in a statement. Read the full story.

U.S Community Health Center Hacked – 1 Million Patients Data Stolen

Community Health Center, Inc. (CHC), a Connecticut-based federally qualified health center, has disclosed a data breach following a criminal cyberattack on its systems. The breach potentially exposed the sensitive personal and health information of patients and individuals who received COVID-19 tests or vaccines at CHC clinics. In a regulatory filing with the Maine Attorney General’s Office, CHC reported that the data breach impacted 1,060,936 individuals. Read the full story.

Hackers Abusing AWS & Microsoft Azure To Launch Large-Scale Cyber Attacks

Hackers are increasingly leveraging cloud platforms like Amazon Web Services (AWS) and Microsoft Azure to orchestrate large-scale cyber attacks. These platforms, which host critical infrastructure for businesses worldwide, are being exploited through sophisticated methods, including fraudulent account setups, API key theft, and infrastructure laundering. Read the full story.

Mizuno USA says hackers stayed in its network for two months

Mizuno USA, a subsidiary of Mizuno Corporation, one of the world’s largest sporting goods manufacturers, confirmed in data breach notification letters that unknown attackers stole files from its network between August and October 2024. In a Thursday filing with Maine’s attorney general, the company said it detected suspicious activity on its network on November 6, 2024. The investigation found that unknown attackers breached some of its systems and exfiltrated documents containing personal information belonging to an undisclosed number of individuals. Read the full story.

Globe Life data breach may impact an additional 850,000 clients

Insurance giant Globe Life finished the investigation into the data breach it suffered last June and says that the incident may have impacted an additional 850,000 customers. On June 13, 2024, the company discovered during a security review of its networks that it had been compromised by hackers who had gained unauthorized access to one of its web portals. Globe Life was founded in 1900 and is one of the largest providers of life and health insurance plans in the United States. It has a market capitalization of $12 billion and a total revenue that exceeds $5.3 billion. Read the full story.