SecurityWeek reports that LastPass had its source code and some proprietary technical data stolen following a cyberattack on its development environment two weeks ago.
Ars Technica reports that at least 15 million of Plex's 30 million subscribers had their usernames, emails, and encrypted passwords, but not payment card details, compromised following a data breach that impacted the streaming media platform's proprietary database.
Nearly 5,000 healthcare data breaches have been reported to the Department of Health and Human Services Office for Civil Rights between 2009 and June 2022, resulting in the exposure of over 342 million health records, HealthITSecurity reports.
This week’s healthcare data breach roundup includes numerous delayed notifications, including a ransomware attack on Practice Resources that led to data theft for 28 of its provider clients.
Ideas on debugging with IDEs, Wiz.io shares technical details behind PostgreSQL attacks in cloud service providers, looking at the attack surface of source code management systems, a Xiaomi flaw that could enable forged payments, defensive appsec design from Signal, what targeted attacks mean for threat models when the targeting goes awry.
Monthly API security breaches occurred in the organizations of 20% of developers and API professionals, even though 51% noted that over half of the development efforts of their organizations have been directed toward APIs, VentureBeat reports.
Fast Five
Selected by the SC Media Editorial team every Tuesday.
Sign up now for the top five issues cybersecurity pros need to know this week.