SecurityWeek reports that U.S. troops stationed in Bahrain have been subjected to a WhatsApp-based influence operation by the Iran-nexus threat operation Handala earlier this week.
A patient, Joseph R. Cox, discovered the vulnerability, which allowed any user with portal access to view other patients' documents, including personal information, medical histories, and photo identification.
The UK government's latest Cyber Security Breaches Survey reveals that 43% of businesses and 28% of charities reported a cyber incident in the past year.
Xorcat claimed to exploit several vulnerabilities, including undocumented API endpoints, a pagination bypass on the CLOB trading system by altering code to request nearly a million data points, and a CORS misconfiguration.
A threat actor claimed on a dark web forum to have obtained and leaked a complete database of AFC players and coaches, including data from Al Nassr FC.
Cybernews reports that European ultra low-cost airline Ryanair had its flight compensation data proliferating across underground cybercrime forums after a threat actor claimed to have breached the airline.
U.S. logistics technology firm Pitney Bowes had data purportedly stolen from its systems exposed by the ShinyHunters extortion group as part of its pay-or-leak attack spree, The Register reports.
Fast Five
Selected by the SC Media Editorial team every Tuesday.
Sign up now for the top five issues cybersecurity pros need to know this week.