UK Biobank Breach Put 500,000 Health Records Up for Sale in China - 5/4/26
Автор: The Rainmaker Report
Загружено: 2026-05-04
Просмотров: 33
Описание:
My first story tracks a brutal trust failure inside one of the world’s most famous health research projects: data tied to all 500,000 UK Biobank volunteers was advertised for sale on Alibaba by sellers linked to research access abuse. The UK government said names and contact details were not included, but the whole selling point of de-identified health data is that it is not supposed to wind up on a Chinese marketplace like discount headphones. UK Biobank paused access, cut off the implicated institutions, and now gets to explain how “strict controls” apparently meant “please don’t repost the crown jewels.”
https://www.infosecurity-magazine.com...
https://www.gov.uk/government/speeche...
https://www.gov.uk/government/news/na...
https://www.bbc.com/news/articles/cpv...
https://www.ukbiobank.ac.uk/news/a-me...
#UKBiobank #databreach #healthdata #privacy #cybersecurity
---
Russia Hijacked Routers to Steal Microsoft Office Tokens - 5/4/26
Our second story covers a deeply obnoxious espionage play: APT28 abused vulnerable small office/home office routers, rewired DNS settings, and quietly shoved victims into adversary-in-the-middle traps to harvest Microsoft Office credentials and OAuth tokens. The campaign reportedly touched more than 18,000 networks and let Russian operators collect passwords, session material, and sensitive traffic without planting malware on the endpoint. Translation: your dusty old router may have been doing counterintelligence work for Moscow while everyone else blamed phishing again.
https://krebsonsecurity.com/2026/04/r...
https://www.ncsc.gov.uk/news/apt28-ex...
https://www.ic3.gov/PSA/2026/PSA260407
https://www.bleepingcomputer.com/news...
#apt28 #microsoft365 #RouterHack #dnshijacking #threatintel
---
Microsoft's Broken 0-Day Patch Left Windows Under Active Attack - 5/4/26
I flagged a painfully familiar Microsoft story: an incomplete patch for CVE-2026-21510, part of an APT28 exploit chain, left behind a new zero-click Windows issue tracked as CVE-2026-32202. Akamai says the original fix stopped the initial RCE path but still allowed forced authentication to an attacker-controlled server, and CISA added the follow-on flaw to KEV due to active exploitation. In other words, Microsoft patched the door, forgot the window, and now everyone gets another emergency update as a hobby.
https://www.theregister.com/2026/04/2...
https://www.akamai.com/blog/security-...
https://www.cisa.gov/news-events/aler...
https://msrc.microsoft.com/update-gui...
https://nvd.nist.gov/vuln/detail/CVE-...
#microsoft #WindowsZeroDay #CVE202632202 #patchtuesday #cybersecurity
Повторяем попытку...
Доступные форматы для скачивания:
Скачать видео
-
Информация по загрузке: