CareCloud Data Breach Impacts Over 350,000

CareCloud Data Breach Exposes Sensitive Information for Over 350,000 Individuals A major data breach has struck healthcare information technology company CareCloud, compromising sensitive personal and medical information of at least 350,000 individuals. The incident involved an electronic health record environment within the CareCloud Health division, which was disrupted on March 16, 2026. According to an … Read more

Okta to Acquire Identity Threat Detection Firm Permiso

Okta’s Latest Acquisition Signals Shift in Identity Security Landscape In a move that marks a significant expansion into security operations, identity management giant Okta has signed a definitive agreement to acquire Permiso Security, a cloud-native identity security platform. The deal is expected to close in the third quarter of 2027 and will bring Permiso’s cutting-edge … Read more

Bank of America to Acquire Cybersecurity Firm MDSec

Bank of America’s $500 Million Bet on Cybersecurity Expertise In a significant move to bolster its cybersecurity defenses, Bank of America has announced plans to acquire UK-based information security consultancy MDSec Consulting Limited. The deal, expected to close in the fourth quarter of 2026 pending regulatory approvals, marks a major expansion of the bank’s presence … Read more

CISA Urges Water Sector to Protect OT After Coordinated Attacks on PLCs

A coordinated cyberattack has disrupted automated controls at dozens of water utilities in Minnesota, prompting a fresh warning from the US Cybersecurity and Infrastructure Security Agency (CISA) to protect operational technology (OT) against malicious activity targeting programmable logic controllers (PLCs). The alert comes on the heels of a wave of targeted attacks on OT systems, … Read more

Critical Code Execution Vulnerability Patched in TeamCity

A Critical Vulnerability in TeamCity Exposes Organizations to Remote Code Execution Attacks A devastating security flaw has been discovered in TeamCity On-Premises, a popular continuous integration and delivery (CI/CD) platform used by thousands of organizations worldwide. The vulnerability, tracked as CVE-2026-63077, allows attackers to bypass authentication checks and execute arbitrary operating system commands with the … Read more

CISA Urges Water Sector to Protect OT After Coordinated Attacks on PLCs

The US Cybersecurity and Infrastructure Security Agency (CISA) has issued a stark warning to water and wastewater system operators: protect your operational technology (OT) from malicious activity targeting programmable logic controllers (PLCs). The agency’s alert comes on the heels of a coordinated cyberattack that disrupted automated controls at dozens of water utilities in Minnesota, leaving … Read more

Claude Mythos — Hype vs. Reality: What Security Teams Need to Know

The Hype Surrounding Claude Mythos: A Reality Check for Security Teams A powerful new artificial intelligence (AI) model has taken center stage in the cybersecurity world, sparking both excitement and concern. Anthropic’s Claude Mythos, a large language model (LLM), has been touted as capable of discovering and exploiting critical zero-day vulnerabilities with ease, even in … Read more

AI Harnesses Burst With Potential Exploit Opps

Major AI Vendors Warned of Potential Security Weaknesses in Harnesses A concerning security vulnerability has been discovered in the software frameworks used by major artificial intelligence (AI) vendors, including Anthropic, Google, and OpenAI. Researchers at Novee Security found that these “harnesses” can create attack vectors when components are too trusting of each other, potentially allowing … Read more

Minnesota Water Utility Attacks Expose Sector’s Cyber-Risks

Minnesota Water Utility Attacks Expose Sector’s Cyber-Risks A coordinated cyberattack targeting more than 30 community water systems in Minnesota has sent shockwaves through the critical infrastructure sector, highlighting the growing threat to often poorly protected operational technology (OT). The attacks, attributed by US government officials to an Iran-backed actor, disrupted automated systems in some communities, … Read more