Luxury fashion brand Dior has alerted customers to a data breach involving its Chinese customer database. The company revealed that an unauthorised external party had gained access to sensitive customer information, though financial data was not affected. The breach came to light after Dior sent an internal memo to affected consumers on 13 May. According to multiple Chinese media outlets, including Global Times, the memo stated that the company discovered the breach on 7 May. The compromised data includes customer names, gender, phone numbers, email addresses, mailing addresses, purchase histories, shopping preferences, and other user-related information collected by Dior. In…
Kirsten Doyle
Zoom Video Communications has disclosed several security vulnerabilities in its Workplace Apps for Windows, macOS, Linux, iOS, and Android platforms. These flaws, which range from medium to high severity, could lead to issues like unauthorized access, denial-of-service (DoS), or remote code execution if exploited. One of the more serious vulnerabilities (CVE-2025-30663) is a time-of-check to time-of-use (TOCTOU) issue caused by a race condition in the app. With a CVSS 4.0 score of 5.9, this flaw could let a local attacker exploit timing gaps to access sensitive data or increase their system privileges. Although it requires access to the affected device…
Marks & Spencer (M&S) has fessed up that personal customer data was stolen in the recent cyber-attack, and that it could include contact details and dates of birth. The company’s chief executive Stuart Machin said: “As we continue to manage the current cyber incident, we have written to customers to let them know that unfortunately some personal information has been taken.” He stressed that there is no reason to believe that the information has been shared and it does not include any useable card or payment details, or account passwords. “There is no need for customers to take any action.” …
The European Union Agency for Cybersecurity (ENISA) has officially launched the European Vulnerability Database (EUVD) to enhance cyber resilience. Developed in accordance with the NIS2 Directive, the platform is now live and will be maintained by ENISA. The EUVD is designed to provide aggregated, reliable, and actionable information about cybersecurity vulnerabilities affecting ICT (Information and Communication Technology) products and services. It includes details such as mitigation measures, exploitation status, and affected versions of ICT products. “The EU Vulnerability Database is a major step towards reinforcing Europe’s security and resilience,” said Henna Virkkunen, European Commission Executive Vice-President for Tech Sovereignty, Security…
A major data breach has exposed the personal information of over three million individuals, including high school student-athletes and college coaches, according to cybersecurity researcher Jeremiah Fowler. The unprotected database, which was discovered by Fowler and reported to vpnMentor, contained more than 3.1 million records and 135 GB of data, including sensitive personally identifiable information (PII) such as names, phone numbers, emails, addresses, and even passport data. The records appear to belong to PrepHero, a Chicago-based recruiting platform operated by EXACT Sports, which helps high school athletes connect with college programs. Among the exposed data were unencrypted .CSV files containing…
Once viewed as a safe digital playground for kids, Roblox is now in the spotlight for all the wrong reasons. A new class action lawsuit is accusing the company of violating children’s privacy by secretly tracking their activity without proper consent. Filed in a California federal court by plaintiffs Michael and Salena Garcia, the suit alleges that Roblox Corporation is in breach of federal privacy laws. The 45-page filing paints a troubling picture. It claims Roblox uses hidden tracking tools that effectively “wiretap” everything a player does on the platform, from keystrokes and mouse movements to private messages and search…
A sophisticated phishing campaign spoofing India’s Ministry of Defence has been uncovered. The operation, which mirrors tactics seen in previous ClickFix-style attacks, appears to be the work of the Pakistan-linked threat group APT36 (Transparent Tribe). It uses cloned government branding and cross-platform malware delivery to target unsuspecting users. Deceptive Infrastructure Mimics Official Government Portal Researchers at hunt.io discovered a fake domain (email.gov.in.drdosurvey[.]info) designed to closely resemble the official Ministry of Defence press release portal. The malicious site mimicked the layout and structure of the real press archive, but with a critical difference: only the link for March 2025 was active,…
The Cybersecurity and Infrastructure Security Agency (CISA), in coordination with the FBI, Environmental Protection Agency (EPA), and Department of Energy (DoE), has issued a joint alert warning that unsophisticated cyber actors are increasingly targeting operational technology (OT) and industrial control systems (ICS) within the United States’ critical infrastructure. “CISA is increasingly aware of unsophisticated cyber actor(s) targeting ICS/SCADA systems within U.S. critical Infrastructure sectors (Oil and Natural Gas), specifically in Energy and Transportation Systems,” the agency says. According to the alert, even basic intrusion techniques are proving dangerous due to widespread poor cyber hygiene and internet-exposed systems. These attacks, while…
One of the largest data breaches in U.S. educational history is worsening, as the attacker behind the December 2024 cyberattack on PowerSchool is now directly extorting affected schools, threatening to leak sensitive student and teacher data unless ransom payments are made. PowerSchool, a widely used student information system (SIS) platform across American K–12 institutions, confirmed that the breach compromised. Data belonging to over 60 million students and 9.5 million educators. Initially believed to have been resolved after PowerSchool paid an undisclosed ransom to the attackers in exchange for a video showing the data’s deletion, the situation has taken a dramatic…
In a novel malware campaign, attackers are leveraging fake AI-powered video and image editing sites to spread a newly identified malware strain: Noodlophile Stealer. This was revealed in recent research by Morphisec. Cybercriminals are like pickpockets; they go where the crowds are. They see users eagerly flocking to platforms that promise to turn selfies into cinematic videos or enhance images with a click and are seizing the day. “Noodlophile Stealer represents a new addition to the malware ecosystem. Previously undocumented in public malware trackers or reports, this stealer combines browser credential theft, wallet exfiltration, and optional remote access deployment,” Shmuel…
