Cybersecurity

Data breaches fallout reach new heights as the number of exposed records soars

Dive Brief: Cyberattacks and data breaches are exposing personal data at an ever-growing rate, according to an Apple-commissioned study conducted by Stuart Madnick, professor of IT at Massachusetts Institute of Technology, published Thursday. More than 2.6 billion personal records were compromised in 2021 and 2022, and the number of records breached jumped 36% in 2022 […]

Cybersecurity

Progress Software discloses 2 new CVEs in MOVEit

Dive Brief: Progress Software disclosed two new high-severity vulnerabilities in the beleaguered MOVEit file-transfer service last week. A privilege escalation path vulnerability, CVE-2023-6218, and a cross-site scripting vulnerability, CVE-2023-6217, were disclosed and patched Nov. 29.  The additional set of vulnerabilities brings the total number of CVEs in MOVEit to eight since a zero-day vulnerability, CVE-2023-34362, […]

Cybersecurity

CISA performance goals program trims exploited CVEs

Dive Brief: The Cybersecurity and Infrastructure Security Agency said it is making progress toward reducing security risk since the October 2022 release of its cybersecurity performance goals program, the agency said Tuesday.  Since the release of the CPG program, organizations enrolled in the agency’s vulnerability scanning service have reduced their average number of known exploited […]

Cybersecurity

Payments processor Tipalti investigating ransomware attack

Dive Brief: Accounts payable software vendor Tipalti said it’s investigating a ransomware attack that prolific threat group AlphV claimed responsibility for on Saturday.  “Over the past weekend, a ransomware group claimed that they allegedly gained access to confidential information belonging to Tipalti and its customers,” Tipalti said in a Monday post on X, the social […]