The Register reports that almost $3 million worth of non-fungible tokens have been exfiltrated by threat actors that hacked into the Instagram account of the Bored Ape Yacht Club, who then posted a link redirecting to a spoofed website aimed at asset harvesting.
A follow-up notice from Smile Brands about its 2021 ransomware attack and that initially reported 199,683 patients being affected leads this week’s healthcare data breach roundup.
A settlement has been reached in the class action data breach lawsuit against Solara Medical Supplies, over a months-long, undetected email systems hack, requiring a long list of security requirements.
StateScoop reports that nearly 1,700 students in Coventry Public Schools in Connecticut may have had their data compromised as a result of a breach at Illuminate Education early this year.
Microsoft Exchange servers unpatched to ProxyShell security vulnerabilities are being attacked by an affiliate of the Hive ransomware group to facilitate the distribution of the Cobalt Strike beacon and other backdoors, reports BleepingComputer.
ZDNet reports that Microsoft has introduced higher "scenario-based awards" for vulnerabilities disclosed to its Microsoft 365 Bounty Program and Dynamics and Power Platform Bounty Program in an effort to strengthen efforts to mitigate flaws with the most significant customer privacy and security impact.
Fast Five
Selected by the SC Media Editorial team every Tuesday.
Sign up now for the top five issues cybersecurity pros need to know this week.