ZDNET reports that Medibank, the largest health insurer in Australia, is poised to face a joint class action from law firms Centennial Lawyers, Bannister Law Class Actions, and Maurice Blackburn Lawyers aimed at seeking compensation for individuals whose data were compromised in a data breach last October.
Organizations using internet-exposed Zoho ManageEngine products with SAML single-sign-on enabled or previously enabled could be subjected to "spray and pray" attacks through CVE-2022-47966 exploitation, SecurityWeek reports.
Cyberattack compromises largest Canadian alcohol retailer's site BleepingComputer reports that Canada's largest beverage alcohol retailer Liquor Control Board of Ontario had its website compromised in a cyberattack that involved malicious code injection for customer and credit card data exfiltration at checkout.
SecurityWeek reports that threat actors have begun attempts to exploit a critical flaw in the widely used free web hosting panel Control Web Panel, previously known as CentOS Web Panel, after a proof-of-concept code was published earlier this month.
Government and critical infrastructure organizations in Ukraine and NATO member nations, including Denmark, Poland, and Norway, have been subjected to distributed denial-of-service attacks by cybercrime operation NoName057(16), which has supported Russia since its invasion of Ukraine, SecurityWeek reports.
Norton LifeLock customers have been informed that their Norton Password Manager accounts were compromised in credential stuffing attacks against other platforms, reports BleepingComputer.
Government organizations and other government-related targets had their networks targeted in attacks exploiting an already patched FortiOS SSL-VPN zero-day flaw, tracked as CVE-2022-42475, reports BleepingComputer.
Fast Five
Selected by the SC Media Editorial team every Tuesday.
Sign up now for the top five issues cybersecurity pros need to know this week.