Attacks involved the delivery of malicious emails warning travelers of potential denied entry due to incomplete immigration requirements that include a link redirecting to a fake government portal-spoofing website facilitating login credential and payment data theft, a report from Cofense revealed.
Most of the leaked information consisted of shipping labels and customs declaration forms containing individuals' full names, home addresses, and phone numbers, as well as their order details, according to Cybernews researchers, who noted that Hipshipper had protected the misconfigured storage bucket nearly a month after initial disclosure.
Included in the exposed data were discussions regarding development and technical topics, as well as files uploaded to OmniGPT, such as office projects, market analysis reports, university assignments, police verification assignments, and others that were found to contain credentials and billing details, according to Gloomer.
Massachusetts' Wakefield Public Schools announced that the PowerSchools hack not only exposed 1,384 current and former students' medical information but also special education plans and custody alerts, including restraining orders and legal details, belonging to 708 and 31 current and former pupils, respectively.
While Kraken ransomware was reported to have claimed the theft of Cisco's Windows Active Directory environment credentials, usernames and related domains, accounts' unique relative identifiers, and NTLM hashes through several credential dumping tools, Cisco disclosed that the stolen credentials had already been exposed in a breach nearly three years ago.
Implementation of a backdoor that would enable government access to Apple users' cloud storage data could set a precedent for authoritarian nation-states and threat actors, with Electronic Frontier Foundation's Thorin Klosowski noting the threat of a global emergency stemming from the secret order.
Purportedly included in the exfiltrated information were officers' personal details and photos, gun licenses, email addresses, suspects' and criminals' personal data, sex offender employment permit details, and other classified documents, according to Handala, which also alleged the compromise of Israeli Ministry of National Security servers.
Infiltration of rural hospital's systems led to the theft of individuals' names, birthdates, Social Security numbers, health insurance details, and medical history and treatment data, said Memorial Hospital & Manor in a filing with the Office of the Maine Attorney General.
Fast Five
Selected by the SC Media Editorial team every Tuesday.
Sign up now for the top five issues cybersecurity pros need to know this week.