Almost 10,000 National Rifle Association of America supporters in Colorado had their contact details exposed on Google after a mailing list was mistakenly posted by the Friends of NRA, a non-profit fundraiser for the NRA, reports Cybernews.
Cybersecurity firm UpGuard has revealed that over 273,000 PDF files containing sensitive financial records were left accessible online through an unsecured Amazon-hosted server, exposing bank transfer details from customers across India, according to TechCrunch.
TechRadar reports that U.S. palliative and in-home care services provider Archer Health has moved to promptly secure a misconfigured database that inadvertently exposed nearly 145,000 health records.
Google and menstrual tracking app Flo Health have denied allegations they have been improperly sharing users' sensitive health data as they agreed to a $56 million combined settlement to resolve the lawsuit, reports The Record, a news site by cybersecurity firm Recorded Future.
The Senate Homeland Security and Government Affairs Committee Democrats urged agencies to revoke the Department of Government Efficiency's access to sensitive information until it complies with privacy laws, as it reported that the department is "bypassing cybersecurity protections" at three federal agencies, according to CyberScoop.
More than 10,000 Texas truckers have had their personal information inadvertently exposed by a misconfigured Amazon S3 bucket linked to the Transportation Department compliance service provider AJT Compliance, Cybernews reports.
Global nursery chain Kido International, which operates in the UK, U.S., and India, had information from almost 8,000 children allegedly stolen by the newly emergent Radiant ransomware group, reports the BBC.Radiant has moved to publish pictures and profiles belonging to 10 students on their leak site in a bid to obtain ransom for their "pentest" effort.
TechCrunch reports that viral call-recording app Neon, which pays users for recorded audio, has been taken down following a security issue that enabled indiscriminate phone number, call recording, and transcript access.
Fast Five
Selected by the SC Media Editorial team every Tuesday.
Sign up now for the top five issues cybersecurity pros need to know this week.