Major human resources, payroll, and benefits management firm Sequoia has confirmed being impacted by a data breach targeted at its cloud storage repository with data from corporate and individual customers of Sequoia One, WIRED reports.
BleepingComputer reports that Indian cybersecurity company CloudSEK has disclosed being impacted by a cyberattack on its Confluence server, which it claims was conducted by another cybersecurity firm.
Chinese advanced persistent threat group BackdoorDiplomacy is believed to have compromised a telecommunications provider in the Middle East in a cyberespionage campaign since last August that involved the exploitation of Microsoft Exchange Server ProxyShell vulnerabilities, according to The Hacker News.
Telecommunications service providers and business process outsourcing companies are being targeted by a new ongoing intrusion campaign by Scattered Spider, which involves mitigation reversal upon breach detection, reports BleepingComputer.
Amnesty International Canada has disclosed having been compromised by Chinese state-sponsored threat actors in October, disrupting the human rights organization for almost three weeks, The Associated Press reports.
This week’s breach roundup includes details on the third-largest healthcare incident reported this year, and is led by an update on the massive cyberattack against CommonSpirit Health.
LastPass reported “unusual activity” within a third-party cloud service that’s shared by LastPass and its GoTo affiliate — an event that was the company’s second reported breach in three months.
Fast Five
Selected by the SC Media Editorial team every Tuesday.
Sign up now for the top five issues cybersecurity pros need to know this week.