Tag: united states of america

From Log4j to IIS, China’s Hackers Turn Legacy Bugs into Global Espionage Tools
News

From Log4j to IIS, China’s Hackers Turn Legacy Bugs into Global Espionage Tools

A threat actor associated with China has been identified as responsible for a cyber attack on a U.S. non-profit organization, aiming to achieve long-term persistence as part of a wider campaign targeting U.S. entities connected to or involved in policy matters. A report from Broadcom's Symantec and Carbon Black teams indicates that the organization is working to sway U.S. government policy on international matters. In April 2025, the attackers succeeded in accessing the network for several weeks. On April 5, 2025, the first indication of activity was observed as mass scanning attempts were identified against a server using various established exploits, such as CVE-2022-26134 (Atlassian), CVE-2021-44228 (Apache Log4j), CVE-2017-9805 (Apache Struts), and CVE-2017-17562 (GoAhead Web Se...
Welltok data breach exposes data of 8.5 million US patients
News

Welltok data breach exposes data of 8.5 million US patients

The file transfer program that the company uses was compromised in a data theft attack, and as a result, Welltok, a provider of software for healthcare organizations, is alerting customers to the possibility that approximately 8.5 million patients' personal information was compromised. Welltok supports healthcare needs like medication adherence and pandemic response in addition to working with health service providers across the United States to maintain online wellness programs, hold databases containing personal patient data, and generate predictive analytics. The Clop ransomware group compromised thousands of organizations globally earlier this year by taking advantage of a zero-day vulnerability in the MOVEit software read more Welltok data breach exposes data of 8.5 million US ...