InfoSec News Nuggets 05/13/2026

Foxconn confirms cyberattack after ransomware crew claims it stole confidential Apple, Nvidia files Foxconn confirmed a cyberattack affecting some North American factories after the Nitrogen ransomware group claimed it stole 8 TB of data, including more than 11 million files tied to internal project documentation and technical drawings. Foxconn says affected factories are returning to normal production, but the claims still matter because Foxconn supports major hardware supply chains. Even if customer data theft isn’t…
Read More

InfoSec News Nuggets 04/06/2026

CISA gives agencies two weeks to patch video conferencing bug exploited by Chinese hackers CISA has ordered federal agencies to patch CVE-2026-3502 in TrueConf by April 16 after confirming active exploitation. The bug affects the product’s updater validation mechanism and, according to reporting on Check Point’s research, can let an attacker controlling an on-prem TrueConf server push and execute arbitrary files across connected endpoints, making it notable for government and critical infrastructure environments that rely…
Read More

InfoSec News Nuggets 03/31/2026

European Commission confirms cyberattack after hackers claim data breach The European Commission confirmed that attackers breached part of its cloud infrastructure tied to the Europa.eu platform and said it had already contained the incident and implemented mitigation steps. The Commission said its internal systems were not affected, but it’s still investigating what data was taken after hackers claimed they stole large amounts of information from its cloud environment.    Supply chain attack hits widely-used AI…
Read More

InfoSec News Nuggets – 01-26-2026

Sandworm Hackers Linked to Failed DynoWiper Attack on Poland's Power Grid Russian state-sponsored hacking group Sandworm has been attributed to what Polish officials called the "largest cyber attack" targeting Poland's energy infrastructure in years. The attacks occurred on December 29-30, 2025, targeting two combined heat and power plants and a system managing electricity from wind turbines and solar farms. ESET researchers analyzed the novel malware, which they named DynoWiper, and attributed the campaign to Sandworm…
Read More

InfoSec News Nuggets – 01/20/2026

Canada's Investment Regulator Confirms Data Breach Affecting 750,000 Investors The Canadian Investment Regulatory Organization (CIRO) has confirmed that a sophisticated phishing attack it suffered in August 2025 impacted approximately 750,000 Canadian investors. After more than 9,000 hours of forensic investigation, CIRO disclosed that the compromised data includes dates of birth, phone numbers, annual income, social insurance numbers, government-issued ID numbers, investment account numbers, and account statements. CEO Andrew Kriegler said the complexity of the cyberattack…
Read More

InfoSec News Nuggets 01/13/2026

SAP Security Patch Day Delivers 17 Fixes Including Four Critical HotNews Vulnerabilities SAP released its January 2026 Security Patch Day package containing 17 security notes, with four rated as critical HotNews vulnerabilities requiring immediate attention. The most severe issue is CVE-2026-0501, a SQL injection flaw in S/4HANA Financials with a CVSS score of 9.9 that allows authenticated attackers with low privileges to execute arbitrary SQL queries and completely compromise financial data systems. Additional critical vulnerabilities…
Read More

InfoSec News Nuggets 1/16/2025

Microsoft stops using Bing to trick people into thinking they’re on Google Microsoft has quietly killed off its spoofed Google UI that it was using to trick Bing users into thinking they were using Google. Earlier this month you could search for “Google” on Bing and get a page that looked a lot like Google, complete with a special search bar, an image resembling a Google Doodle, and even some small text under the search bar just…
Read More

InfoSec News Nuggets 1/15/2025

UK floats ransomware payout ban for public sector A total ban on ransomware payments across the public sector might actually happen after the UK government opened a consultation on how to combat the trend of criminals locking up whole systems and taxpayers footing the bill. The consultation will consider views on extending the ransom payment ban from central government departments to all public services including hospitals, schools, local authorities, and state-operated transport networks. Announced today,…
Read More

InfoSec News Nuggets 11/15/2024

Chinese national faces 20 years in US prison for laundering pig-butchering proceeds One of the ringleaders of a scheme to launder millions stolen through cryptocurrency investment scams pleaded guilty in a California courtroom on Tuesday. Daren Li, 41, faces up to 20 years in prison for taking part in an operation that laundered more than $73 million stolen from people duped by so-called “pig-butchering” scams. Pig butchering typically involves a scammer forming a relationship with a…
Read More

InfoSec News Nuggets 9/13/2024

Fortinet confirms data breach after hacker claims to steal 440GB of files Cybersecurity giant Fortinet has confirmed it suffered a data breach after a threat actor claimed to steal 440GB of files from the company's Microsoft Sharepoint server. Fortinet is one of the largest cybersecurity companies in the world, selling secure networking products like firewalls, routers, and VPN devices. The company also offers SIEM, network management, and EDR/XDR solutions, as well as consulting services. Early this…
Read More

InfoSec News Nuggets 11/17/2023

Samsung Data Breach: Hackers Steal Data of UK Customers  Samsung has notified its customers in the United Kingdom that a data breach has exposed the personal information of thousands of individuals. The breach impacted customers who made purchases on the company’s UK online store between July 1, 2019, and June 30, 2020. The company discovered the breach on November 13, 2023, and determined that an unauthorized individual exploited a vulnerability in a third-party business application to…
Read More

InfoSec News Nuggets 11/30/2022

Espionage group using USB devices to hack targets in Southeast Asia USB devices are being used to hack targets in Southeast Asia, according to a new report by cybersecurity firm Mandiant. The use of USB devices as an initial access vector is unusual as they require some form of physical access — even if it is provided by an unwitting employee — to the target device. Earlier this year the FBI warned that cybercriminals were…
Read More

InfoSec News Nuggets 10/13/2022

The Real Threat From A.I. Isn’t Superintelligence. It’s Gullibility. The rapid rise of artificial intelligence over the past few decades, from pipe dream to reality, has been staggering. A.I. programs have long been chess and Jeopardy! Champions, but they have also conquered poker, crossword puzzles, Go, and even protein folding. They power the social media, video, and search sites we all use daily, and very recently they have leaped into a realm previously thought unimaginable…
Read More

InfoSec News Nuggets 09/09/2021

Half a million Fortinet VPN passwords leaked online A cybercriminal has released credentials associated with almost half a million Fortinet VPN accounts online. The account information was supposedly scraped from Fortinet devices, by exploiting a security vulnerability that first came to light in April. Although months have elapsed since a patch was released, many of the credentials remain current, the hacker claims. The data was made public by a threat actor known as Orange, who has a…
Read More