top of page


Enterprise Security Tech
A cybersecurity resource for CxOs
Search


Qilin-Linked Ransomware Attack at ApolloMD Exposes 626,540 Patient Records, Federal Filing Shows
A ransomware attack on ApolloMD has exposed the personal and medical data of more than 626,000 individuals, according to a newly published federal disclosure, underscoring the persistent cybersecurity risks facing healthcare organizations and their third-party partners. The US Department of Health and Human Services breach portal now lists 626,540 individuals as affected by the May 2025 incident, which targeted the Atlanta-based physician and practice management services pr
Feb 12


Everest Ransomware Claims Massive Under Armour Data Leak Affecting 72.7 Million Accounts
The Everest ransomware crew is once again claiming a marquee victim, this time alleging it has siphoned a vast trove of customer data from Under Armour and leaked it onto a cybercrime forum. If verified, the incident would rank among the largest retail data exposures in recent memory and highlight how modern ransomware campaigns can linger long after an initial intrusion. The scale of the alleged breach comes from Have I Been Pwned , which says it ingested data tied to 72.7
Jan 25


StealC Malware Operators Exposed After Flawed Infrastructure Lets Researchers Hack the Hackers
Cybercriminals like to sell the illusion of professionalism. Malware dashboards are slick, subscription plans are clearly tiered, and promises of easy profits are framed with the language of software-as-a-service. But new research from CyberArk Labs shows how thin that polish can be, and how quickly the roles of attacker and victim can blur. The case centers on StealC, an infostealer that has circulated since early 2023 and is sold through a malware-as-a-service model. Buyer
Jan 19


LinkedIn Phishing Scams Hijack Public Comments, Using AI to Impersonate Platform Support
A wave of LinkedIn phishing attacks is exploiting the platform’s own public comment sections, blurring the line between legitimate support messages and outright fraud in a way that security researchers say marks a new phase in social engineering. The campaign surfaced earlier this week when researchers and targeted users began warning that bot-like accounts were replying directly to posts while impersonating LinkedIn itself. The fake comments claim the recipient has violated
Jan 13


University of Hawaii Cancer Center Quietly Managed a Ransomware Breach for Months Before Telling the Public
The University of Hawaii Cancer Center is facing growing scrutiny after quietly navigating a ransomware attack that compromised decades old cancer research data, then waiting months to inform regulators and affected individuals. According to a report filed with the Hawaii state legislature in December, attackers gained unauthorized access to servers supporting cancer research operations in late August. The intruders encrypted systems, disrupted access to research files, and
Jan 13


Cybersecurity in 2025: When Defenders Protected Systems—and Attackers Exploited People
As the cybersecurity industry closes the books on 2025, the year is already solidifying around a familiar but unsettling conclusion: attackers didn’t need radically new malware to cause outsized damage. They needed people, timing, and a growing catalog of quietly catastrophic infrastructure flaws. That’s the throughline emerging from a year-end review by incident response specialists at LevelBlue , which absorbed digital forensics heavyweight Stroz Friedberg earlier this year
Jan 12
bottom of page