Security Affairs reports that the Open Web Application Security Project Foundation had data from its earliest members exposed as a result of an old Wiki web server misconfiguration.
Hackread reports that widely known Israeli LGBTQ dating app Atraf had a database containing information from 669,672 users potentially stolen from a 2021 attack by Iranian state-sponsored threat operation Black Shadow exposed by a Russian threat actor.
More than 100,000 individuals were noted by the Cybersecurity and Infrastructure Security Agency to possibly have been affected by a cyberattack against its Chemical Security Assessment Tool involving the exploitation of security vulnerabilities in Ivanti appliances, reports CyberScoop.
U.S. fast fashion retailer Hot Topic had its customers' data compromised following a series of credential stuffing attacks in November, reports BleepingComputer.
New England-based health insurance firm Harvard Pilgrim Health Care disclosed that a ransomware attack last April had compromised data from nearly 2.9 million individuals, which is 12% higher than initially reported, according to The Record, a news site by cybersecurity firm Recorded Future.
Major Turkish car rental service provider Rent Go had data from more than 161,000 customers exposed due to an unsecured Azure Blob Storage instance, reports Cybernews.
The U.S. Department of Justice announced that Idaho and Montana resident Scott Rhodes was fined $9.9 million for conducting thousands of "illegal and malicious" robocalls, or automated phone calls, with disturbing pre-recorded messages across the U.S., BleepingComputer reports.
Fast Five
Selected by the SC Media Editorial team every Tuesday.
Sign up now for the top five issues cybersecurity pros need to know this week.