France's data protection authority, the CNIL, has imposed a €1.7 million GDPR fine on software company Nexpublica for severe cybersecurity failures that led to a significant data breach, according to The Cyber Express.
The U.S. had 14,486 internet-exposed MongoDB servers exposed to the critical MongoBleed bug, tracked as CVE-2025-14847, making it second only to China, according to Security Affairs.
HackRead reports that ASUS had 1 TB of sensitive data purportedly stolen from its systems exposed in its entirety by the Everest ransomware operation, which claimed to have breached the global hardware and electronics company last month.
Major New Zealand patient information portal ManageMyHealth had information from 108,000 to 126,000 individuals, or 6% to 7% of its userbase, compromised following a New Year's Eve data breach, reports 1News.
Widely known U.S. tech and culture magazine Wired had data from more than 2.3 million website users allegedly exposed on the new Breach Stars hacking forum by the threat actor "Lovely," who has also threatened to publish information from over 40 million users purportedly stolen from Conde Nast, the parent firm of Wired, according to HackRead.
Fast Five
Selected by the SC Media Editorial team every Tuesday.
Sign up now for the top five issues cybersecurity pros need to know this week.