Tag: Information Security Buzz

CISA Warns of Critical Security Vulnerability in Honeywell Cameras

CISA has warned that a critical security vulnerability (CVE-2026-1670) has been identified in four Honeywell CCTV camera models.  “Successful exploitation of this vulnerability could lead to account takeovers and unauthorized access to camera feeds; an unauthenticated attacker may change the recovery email address, potentially…

Who Can You Trust?

Scammers, confidence men, swindlers. Whatever you call them, for all of human history, people have made a living cheating others out of their hard-earned possessions. While that’s never going to change, their tactics, however, always will. In Q4 2025, email…

Eurail User Records Up for Sale on the Dark Web

Eurail BV has confirmed that some customer data impacted by the previously reported security incident has been offered for sale on the dark web and a sample data set has been posted on Telegram.   The company said it is continuing to investigate the scope…

Dutch Telecoms Company Odido Discloses Breach Affecting Approximately 6.2 Million Customers

Dutch telecoms business Odido has disclosed a cyberattack on its customer contact system that happened on 7 February.   The personal information of approximately 6.2 million customers was disclosed, including names, residential addresses, mobile phone numbers, email addresses, account numbers, and ID information such as passports and driver’s licenses.   In a statement, the company…

Customer data from Volvo Group North America exposed in Conduent breach

Almost 17,000 Volvo employees have had their personal data exposed after attackers breached Conduent, an outsourcing company that manages workforce benefits and back-office services.   In a filing with the Maine Attorney General, Volvo Group North America said it learned in late January that employee data had been exposed through systems run by Conduent.  …

Closing the Cross-Platform Security Gap in Citizen Developer Apps

In many ways, managing security for citizen-developer apps is like flying several planes built by different manufacturers all at once. That’s because each no-code development platform uses separate dashboards, controls, policy engines, etc. Microsoft Power Platform measures altitude in feet,…

The Top Pentesting Platforms of 2026: What You Need to Know

What to Look for in a Pentesting Platform? Pen testing is increasingly becoming the way companies prove compliance with data privacy laws and battle-test their defenses. As the primary way of finding and exploiting vulnerabilities (before attackers do), pen testing…

Substack Discloses Major Data Breach

Media platform Substack has disclosed a data breach that exposed email addresses, phone numbers, and internal metadata of an unknown number of users. Credit card numbers, passwords, and financial information were not accessed.  In an email, Substack CEO Chris Best informed affected…

The Winter Olympics Are Back, and So Are Attackers

The Olympics have traditionally been a major attack vector for cyber disruption, espionage, and financially motivated attacks.   The 2018 Winter Olympic Games in PyeongChang saw the Olympic Destroyer malware used to disrupt Wi-Fi, ticket, and venue systems during the opening…

Attackers allege 1.4TB data breach at Iron Mountain

The Everest ransomware group has claimed responsibility for the breach against the global information management and storage firm Iron Mountain, stating that it stole approximately 1.4 terabytes of the firm’s internal and customer data.   The claims were made through the group’s posts on the…

Notepad++ Update Hijacked in Six-Month, State-Linked Supply-Chain Attack

Attackers have hijacked the update mechanism of Notepad++, one of the world’s most popular open-source text editors, delivering  malware to targeted users over a period of six months.  In an advisory, developer Don Ho discussed how bad actors weaponized his two-decade-old project between June and December last year.  An…

Forescout’s 2025 Threat Roundup: 84% OT Surge Signals Expanding Cyber Chaos

In 2025, attackers didn’t only target traditional areas of vulnerability; they went after those with the least defense and the most rapid change. These include new AI technologies, web applications, and operational technology (OT) for industries such as healthcare, manufacturing, energy, government, and finance.   In fact, attacks against OT protocol rose by…