Curated news, CVE analysis, and threat reports from the world's top cybersecurity sources.
Grindr settles privacy lawsuit tied to disclosure of users’ HIV statuses for $35 million The company will pay the fines in two lump sums, with one payment due by the end of December and the other slated for the end of March, according to a regulatory filing with the Securities and Exchange Commission (SEC) signed on September 4. The settlement concludes a legal fight that dates to April 2024, when UK users sued for the alleged violations of their country’s privacy laws.
In this article Attack chain overview Attribution Mitigation and protection guidance Learn more Microsoft Security Research is tracking active cloud-based intrusions spanning multiple accounts in which unusual sign-ins were followed by threat actor-added authentication methods, high-volume Microsoft Graph activity, SharePoint and OneDrive downloads, and email collection through REST APIs.
Electronic health record company says customer data stolen in breach Electronic health records company Veradigm told regulators on Tuesday evening that hackers infiltrated a vendor’s systems and stole customer information including Social Security numbers. Veradigm provides health record technology and management systems to thousands of hospitals and doctors across the world, reporting $594 million in revenue in 2024.
U.S. cybersecurity and intelligence agencies say that six Chinese AI companies conducted a coordinated campaign to extract billions of tokens from frontier AI models. The agencies accuse these firms of systematically distilling knowledge from models such as Claude and GPT-4 through automated queries and bulk API access, raising concerns about intellectual property theft and national security.
Multiple espionage-motivated threat activity clusters have been found deploying a previously undocumented exploit kit called BlueMoon that chains together multiple vulnerabilities in Microsoft Windows and Google Chrome. The first in-the-wild use of BlueMoon has been attributed to the China-aligned state-sponsored group tracked as APT31 (aka Bronze Vinewood, Judgement Panda, JungleBamboo, PerplexedGoblin, RedBravo, TA412, Tide Castle, and Violet Typhoon) on August 28, 2026.
Multiple Chinese hacking groups seen using identical Chrome zero-day exploit At least four cyber-espionage groups, most linked to Chinese state intelligence, have been using the same previously unknown Google Chrome vulnerability in attacks beginning late August and continuing into this week, cybersecurity firm Proofpoint said Wednesday The groups targeted U.S. defense contractors, NGOs, and Southeast Asian government entities, deploying malware through the exploit.