Data breach at Western Alliance Bank affects 22,000 people | American Banker
Western Alliance Bank experienced a data breach affecting 22,000 individuals.
Daily curated cyber threat intelligence for security professionals.
Sourcewww.americanbanker.com
Curated
Western Alliance Bank experienced a data breach affecting 22,000 individuals.
Sourcewww.darkreading.com
Curated
The Middle East’s rapid digitization, driven by ambitious public and private sector initiatives, poses significant cybersecurity risks. While the region is adopting zero-trust security frameworks, poor cyber hygiene and credential management persist. To mitigate these risks, organizations must prioritize cybersecurity, including zero-trust network access, identity and access management, and data protection, while also investing in digital skills training for employees.
Sourcewww.infosecurity-magazine.com
Curated
California Attorney General Rob Bonta reminded 23andMe customers of their right to delete genetic data under California’s Genetic Information Privacy Act and Consumer Protection Act. This reminder comes after 23andMe filed for Chapter 11 bankruptcy protection and CEO Anne Wojcicki resigned. Despite the company’s financial struggles, including a data breach and workforce layoffs, 23andMe stated that customer data remains protected.
Sourcewww.claimsjournal.com
Curated
Auto insurer Root was fined $975,000 for a data breach affecting 45,000 New Yorkers. The breach, part of a larger industry-wide campaign, exposed personal information including driver’s license numbers and dates of birth. Root must enhance data security, including maintaining a comprehensive information security program and data inventory.
Sourcenews.harvard.edu
Curated
The uncertain future of 23andMe, a popular genetic testing company, raises concerns about the protection of its 14 million customers’ genetic data. While federal health privacy regulations like HIPAA do not cover direct-to-consumer companies like 23andMe, the Genetic Information Nondiscrimination Act prevents discriminatory use of genetic information. To address these concerns, experts propose expanding HIPAA’s scope or implementing broader data privacy protection laws.
Sourcewww.independent.co.uk
Curated
Genetic testing company 23andMe has filed for bankruptcy protection in the US and is seeking a buyer. The company, founded in 2006 and known for its DNA testing kits, is facing financial losses and a data breach investigation. Co-founder and CEO Anne Wojcicki has resigned to pursue the company as an independent bidder.
Sourcewww.globenewswire.com
Curated
Wolf Haldenstein Adler Freeman & Herz LLP is investigating claims on behalf of individuals affected by the Lafayette Federal Credit Union data breach. The breach may have exposed names and Social Security numbers, and affected individuals are encouraged to contact the law firm.
Sourcewww.securityweek.com
Curated
New versions of the Albabat ransomware, also known as White Bat, now target Windows, Linux, and macOS. The ransomware retrieves configuration files from a private GitHub repository and steals data from infected machines, storing it in a remote database.
Sourcethehackernews.com
Curated
A critical security flaw in Next.js, CVE-2025-29927, allows attackers to bypass authorization checks by manipulating the x-middleware-subrequest header. The vulnerability has been patched in versions 12.3.5, 13.5.9, 14.2.25, and 15.2.3.
Sourcewww.tripwire.com
Curated
National security concerns have significantly impacted cross-border data compliance, leading to data localization policies and exemptions for national security purposes. The EU GDPR remains a cornerstone framework, emphasizing user consent and data minimization, while the US lacks a comprehensive federal data protection law. Data sovereignty, while necessary for national security, fragments the digital landscape and can be used for geopolitical influence, necessitating a more nuanced approach involving international frameworks and digital trade agreements.
Sourcewww.tripwire.com
Curated
Scammers use various techniques to manipulate emotions and cloud judgment, exploiting human characteristics and heuristics. These techniques include evoking visceral influence, creating urgency, exploiting fear of missing out, appealing to authority, faking social proof, appealing to reciprocity, leveraging the bandwagon effect, appealing to emotions of guilt or sympathy, normalizing risky behavior, and exploiting trust in experts. Scammers also employ tools like phishing emails, fake social accounts, fake IDs, call spoofing, smishing, internet pop-ups, fake websites, AI technology, deepfake videos, cloned voices, malicious apps, SIM swapping, and QR code scams.
Sourcesecurityaffairs.com
Curated
The Cloak ransomware group claimed responsibility for a February cyberattack on the Virginia Attorney General’s Office, resulting in the theft of 134GB of sensitive data. The group, active since at least 2023, primarily targets small to medium-sized businesses in Europe and Asia, using ARCrypter ransomware to encrypt files.
Sourcewww.helpnetsecurity.com
Curated
Finders Keypers is an open-source tool for analyzing AWS KMS key usage, supporting both customer-managed and AWS-managed keys. It helps identify key usage, assess encryption access control, and evaluate key lifecycle management impact. The tool supports 28 resource types across 21 AWS services and is available for free on GitHub.
Sourcewww.helpnetsecurity.com
Curated
Cloud providers are failing to deliver on security promises, leading 44% of CISOs to change providers. CISOs rely on multiple providers, but many overpromise security, leaving organizations vulnerable. Partnering with channel partners and MSPs can boost security, provide stability, and help mitigate risks associated with cloud migrations.
Sourceinformationsecuritybuzz.com
Curated
A new ransomware campaign, Medusa, is being delivered via a HEARTCRYPT-packed loader. The loader deploys a driver, ABYSSWORKER, signed with a revoked certificate, which disables various EDR solutions. ABYSSWORKER, masquerading as a legitimate CrowdStrike Falcon driver, uses obfuscation techniques and registers callbacks to monitor process creation, image loading, and handle creation, protecting the client process.
Sourceinformationsecuritybuzz.com
Curated
The National Cyber Security Centre (NCSC) has published guidance urging businesses to transition to quantum-resistant encryption methods by 2035. While the commercial availability of quantum computers capable of cracking traditional cryptography is estimated to be five to ten years away, experts emphasize the urgency of preparing for this threat. Implementing post-quantum cryptography (PQC) requires a top-down approach involving a cross-disciplinary team to inventory cryptographic assets and prioritize mitigation strategies.
Published
CBC News has uncovered a sophisticated human smuggling network capable of producing highly convincing fake Canadian passports, raising significant national security concerns.
The forged passports mimic security features and electronic chips of Canadian passports issued between 2013 and 2023, making them nearly indistinguishable from genuine documents. A Montreal man, Garrison Ray, faces multiple human smuggling charges and is believed to be connected to a network with global reach.
The RCMP-led investigation, dubbed “Project Octopus,” uncovered evidence of forged Canadian passports, visas, and documents from European Union countries. The network allegedly involved embassy insiders in Canada, US, France, and Mexico, highlighting the sophisticated nature of the operation.
Kelly Sunberg, a former Canada Border Services Agency officer and current criminology professor, described the forgeries as “incredibly impressive” and unlike anything he had seen in his career. The federal department of immigration stated that security upgrades in new Canadian passports unveiled in 2023 make the document one of the most secure in the world.
This case underscores the ongoing challenges in maintaining border security and the need for constant vigilance and technological advancements in document verification processes.
Sourcewww.malwarebytes.com
Curated
Google Chrome, the most popular web browser, collects data on users’ website visits, searches, clicks, and device information. This data, combined with other Google product data, can create a detailed profile of users. The Lock and Code podcast explores this data collection, its sensitivity, and its implications for user privacy.
Sourcesecurityaffairs.com
Curated
Cisco Talos discovered UAT-5918, an info-stealing threat actor active since 2023, targeting Taiwan’s telecom, healthcare, IT, and critical infrastructure sectors. The group exploits vulnerabilities in unpatched servers, deploying web shells and open-source tools for persistence and credential theft. UAT-5918’s tooling and tactics overlap with multiple Chinese APT groups, suggesting a possible link to China.
Sourcewww.govinfosecurity.com
Curated
Chinese hackers, tracked as UAT-5918, are breaching Taiwan’s critical infrastructure by exploiting unpatched servers. The group, linked to Chinese state-backed groups, uses N-day vulnerabilities to install open-source tools for network surveillance and data theft. UAT-5918’s tactics and tools overlap with those of Volt Typhoon and Flax Typhoon, suggesting a connection to Chinese espionage activities.
Sourcewww.govinfosecurity.com
Curated
A new ransomware group, Babuk2, is attempting to bolster its reputation by claiming to have attacked 26 companies and stolen confidential information. However, many of these organizations were previously targeted by the Cl0p ransomware group, suggesting Babuk2 may be attempting to take credit for Cl0p’s breaches. Cybersecurity experts advise organizations to verify any alleged intrusions and rule out the possibility of recycled data.
Sourcecoinchapter.com
Curated
Zoth protocol, a restaking protocol, experienced a $8.4 million exploit due to a compromised deployer wallet. The hacker quickly converted the stolen funds to DAI and then Ether, avoiding centralized exchanges. The breach was caused by an admin privilege leak, highlighting the risks associated with admin key compromises in decentralized finance platforms.
Sourcedigitalterminal.in
Curated
In a potentially unprecedented digital heist, CloudSEK has uncovered what might be 2025’s largest supply chain attack targeting Oracle Cloud. Detected on March 21 via CloudSEK’s XVigil platform, threat actor “rose87168” is hawking 6 million records—including JKS files, encrypted passwords, and enterprise keys—stolen from Oracle Cloud’s SSO and LDAP systems. The breach, exploiting the login.(region-name).oraclecloud.com endpoint, impacts over 140,000 tenants globally. The sophisticated attacker is not only selling this sensitive data but also extorting affected organizations while seeking help to decrypt credentials. CloudSEK has issued urgent recommendations, including immediate credential rotation, forensic investigations, and enhanced security measures to mitigate what they’ve classified as a “High” severity incident.
Sourcedatabreaches.net
Curated
A security researcher discovered exposed database backups belonging to OrthoMinds clients, potentially affecting over 200,000 patients. OrthoMinds notified clients and individuals potentially affected by the data security breach.
Sourcenyunews.com
Curated
A hacker took over NYU’s website, exposing over 3 million applicants’ data dating back to 1989. The hacker, claiming to expose NYU’s continued use of race-sensitive admissions, displayed average admitted test scores and GPAs for different racial groups. NYU’s IT team responded to the hack, reported it to law enforcement, and is bolstering system security.