Fernando Del Valle reports: A San Benito school district online auction sold thousands of computers and tablets, some of which contained employees’ and students’ personal data, a computer store owner said Wednesday. South Texas Auction Co.’s records show the district sold more than 2,000 computers and 1,500 tablets during a July 23 online auction,...
The Federal Trade Commission has taken enforcement action for the first time under its Health Breach Notification Rule against the telehealth and prescription drug discount provider GoodRx Holdings Inc., for failing to notify consumers and others of its unauthorized disclosures of consumers’ personal health information to Facebook, Google, and other companies. In a first-of-its-kind...
Matthew Keys reports: An unauthorized person or group gained access to internal systems used by Skyview Networks this week, disrupting the delivery of the CBS World News Roundup and other programming to radio affiliates on Monday. The issue was confirmed in an email sent to Radio Ink by Steve Jones, the president and CEO of Skyview, who...
In 2023, Resolve to Fix Your Organization’s Meta Pixel Problem It’s time to be proactive about user privacy. Find out if you’re sending too much data to Facebook—or if you need to send data at all By: Maria Puertas and Simon Fondrie-Teitler We all use the internet to complete increasingly sensitive tasks: book doctor’s...
Ross Kelly reports: Russian tech company Yandex has issued an apology after racial slurs were discovered in source code leaked in a recent data breach. Several references to racial slurs, including the ‘N-word’, were found in the company’s source code last week. A researcher first revealed the use of offensive terminology in a series...
Sergiu Gatlan reports: GitHub says unknown attackers have stolen encrypted code-signing certificates for its Desktop and Atom applications after gaining access to some of its development and release planning repositories. So far, GitHub has found no evidence that the password-protected certificates (one Apple Developer ID certificate and two Digicert code signing certificates used for...
Bill Toulas reports: Microsoft has disabled multiple fraudulent, verified Microsoft Partner Network accounts for creating malicious OAuth applications that breached organizations’ cloud environments to steal email. In a joint announcement between Microsoft and Proofpoint, Microsoft says the threat actors posed as legitimate companies to enroll and successfully be verified as that company in the...
Matthew Humphries reports: Google is in the process of telling Google Fi customers that their data was stolen as part of the T-Mobile breach earlier this month. On Jan. 5, a hacker breached T-Mobile’s network and stole data from 37 million customer accounts. Google Fi uses T-Mobile’s network for the majority of its connections, and it seems...
Lorenzo Franceschi-Bicchierai reports: A bug in a new centralized system that Meta created for users to manage their logins for Facebook and Instagram could have allowed malicious hackers to switch off an account’s two-factor protections just by knowing their phone number. Gtm Mänôz, a security researcher from Nepal, realized that Meta did not set up a...
UK: Counter-attacking ransomware hackers