June Patch Tuesday digs into 67 bugs
An extremely Windows-heavy month, with a surprise cameo by… Sophos?!
Data leaked on a dark website, allegedly from a Moldovan portal, does not support the hackers’ claims about how they obtained it. It also raises questions about the government’s May 2025 claim that its network had not been compromised. In Part 1, DataBreaches described a data exposure incident involving Moldova’s job applicant portal, cariere.gov[.]md. In……
Cybersecurity researchers have discovered a new campaign that employs malicious JavaScript injections to redirect site visitors on mobile devices to a Chinese adult-content Progressive Web App (PWA) scam. “While the payload itself is nothing new (yet another adult gambling scam), the delivery method stands out,” c/side researcher Himanshu Anand said in a Tuesday analysis. “The…
Cybersecurity researchers have flagged two malicious packages that were uploaded to the Python Package Index (PyPI) repository and came fitted with capabilities to exfiltrate sensitive information from compromised hosts, according to new findings from Fortinet FortiGuard Labs. The packages, named zebo and cometlogger, attracted 118 and 164 downloads each, prior to them being taken down.
Diego Pérez Morales reports: The 2021 cyberattack on T-Mobile exposed sensitive information of 76 million customers, including names, addresses, and Social Security numbers. This breach led to a class-action lawsuit, culminating in a $350 million settlement in 2022. This agreement is notable as the second-largest data breach settlement in U.S. history, only surpassed by Equifax’s $700…
DataBreaches cannot read “Lower Merion School District” without recalling the “Webcamgate” scandal of 2010, when the district was discovered monitoring students remotely in their bedrooms on district-issued MacBooks. At the time, they initially denied any misuse of remote access that was part of a security feature. Now the district is back in local news in…
Neil Henderson reports: Two teenagers have appeared in court facing computer hacking charges in connection with last year’s cyberattack on Transport for London (TfL). Thalha Jubair, 19, from east London, and Owen Flowers, 18, from Walsall in the West Midlands, were charged with conspiring to commit unauthorised acts under the Computer Misuse Act. They appeared……