Threat actors using private keys and passphrases from LastPass databases stolen in cyberattacks last August and December were reported by ZachXBT and MetaMask developer Taylor Monahan to have been able to exfiltrate $4.4 million worth of cryptocurrency on Oct. 25, BleepingComputer reports.
Quartz reports that almost 87 million U.S. patients had their health data compromised during the first nine months of 2023, 45 million of which had their data breached during the third quarter alone, compared with the 37 million patients who were impacted by data breaches in the entirety of 2022.
Officials at the City of Philadelphia have disclosed that data from an unspecified number of the city's residents may have been compromised as a result of a breach of its email system, The Philadelphia Inquirer reports.
Appsec lessons from the Okta breach, directory traversal (and appsec) lessons from SolarWinds, how CISOs and Boards rank factors around vulns and patching, revisiting cryptocurrency attacks for lessons in business logic and threat modeling, CISA and friends update guidance on Secure Design, and more!
Major U.S. healthcare solutions provider Henry Schein had its manufacturing and distribution divisions disrupted by a cyberattack on Oct. 14, SecurityWeek reports.
This week, in the enterprise security news, AI dominates new funding rounds (I’m shocked. This is my shocked face.), The buyer’s market continues, with lots of small acquisitions, SingTel sells off Trustwave at a significant loss, Yubico goes public (actually, a month ago, sorry we missed it), Yubico can also now ship pre-registered security keys, ...
Today we interview Shane Sims, CEO of Kivu Consulting. We'll be talking about the current state of cybercrime and insights from incidents his consulting firm has recently worked. We'll discuss some of the latest stats and trends related to ransomware, as well as thoughts on future cybercrime trends. Shane will also share some stories from his time ...
Fast Five
Selected by the SC Media Editorial team every Tuesday.
Sign up now for the top five issues cybersecurity pros need to know this week.