More than 120,000 files and over 1.7 million activity logs leaked by the database revealed Confidant Health patients' psychiatry intake notes, medical histories, disclosures of alcohol and other substance abuse, moods, memory, medications, and overall mental state.
Individuals' full names, birthdates, phone numbers, ID numbers, email addresses, home addresses, vehicle identification numbers, car brands and models, engine numbers, and vehicle colors were leaked by the unsecured Elasticsearch instance.
Such malicious JavaScript code — which is potentially targeted at exfiltrating the credentials of Cisco employees who usually use the site during the checkout process — may have been deployed through the exploitation of the critical XML external entity injection vulnerability in Adobe Commerce dubbed "CosmicSting."
Security pros say while side-channel attacks are difficult to pull off, the sheer volume of YubiKey devices in use makes the potential threat a real concern.
Included in the leaked 27.6 GB archive belonging to VK — which was co-founded by recently arrested Telegram CEO Pavel Durov before being relinquished to Russian state-owned firms in December 2021 — were individuals' names, sex, ID numbers, profile pictures, and location information.
Such a development comes after the emergence of a ransom note from RansomHub said to be related to the incident although Halliburton has not yet been added to the ransomware gang's leak site.
Fast Five
Selected by the SC Media Editorial team every Tuesday.
Sign up now for the top five issues cybersecurity pros need to know this week.