PrivacySignal
Breach

AU: Updoc patients notified of security breach where personal information may have been stolen

DataBreaches.net · · International · Data Breaches

Updoc, an Australian 24/7 telehealth platform, has notified patients of a security breach involving unauthorised access to a third-party system. Personal information including names, email addresses, and postal addresses may have been stolen.

Why this matters: Telehealth platforms hold a particular kind of sensitive data. People use them when they are sick, anxious, or dealing with something they would not want made public. A breach here is not just an inconvenience. Names and addresses stolen from a health service can be used to target people in ways that go well beyond spam. The third-party system detail matters too. Updoc did not build the door that was left open, but patients trusted Updoc with their information. That trust does not transfer to whoever runs the third-party system. The accountability stays with the platform.

Who should care: Cybersecurity · Privacy officers · Administrators · General readers · Policy

This summary is AI-assisted and may contain errors. It is an original briefing to help you gauge significance quickly — not a reproduction of the source. Always read the linked original before relying on it. See our methodology.

Related stories

Breach
Nextgov/FCW · · US Federal

Hugging Face AI breach is ‘most consequential hack’ since Morris Worm, former NSA cyber chief says

AI may let hackers exploit newly disclosed software flaws so quickly that organizations should weigh whether to immediately patch internet-connected devices, even at the risk of causing outages, Rob Joyce said.

Who should care: Cybersecurity · Privacy officers · Administrators · General readers · AI governance · Policy

#breach#ai#security Read original →
Breach
TechCrunch — Privacy · · International

PSA: Apple’s Private Relay can leak your real IP address

A bug in how Apple implements its Private Relay feature, which in theory masks users’ IP addresses from the sites they visit, can reveal users’ real IP addresses.

Who should care: Cybersecurity · Privacy officers · Administrators

Breach
HIPAA Journal · · US Federal

Data Breach Lawsuits Settled by Omni Healthcare & Western Montana Clinic

Omni Healthcare Financial Holdings and Western Montana Clinic have each agreed to settle class action lawsuits stemming from separate data breaches. The settlements resolve claims brought by individuals whose personal or medical information was exposed.

Who should care: Cybersecurity · Privacy officers · Administrators · Healthcare professionals · Compliance

#breach#healthcare Read original →
Breach
Microsoft Threat Intelligence · · International

ChainDrop supply chain compromise: Anatomy of a self-propagating worm

A self-propagating worm embedded in over 400 malicious npm packages spread through software supply chains by automatically republishing infected updates, stealing credentials along the way. Microsoft's security team has published a detailed breakdown of how the attack worked and how to detect or remediate it.

Who should care: Cybersecurity · Privacy officers · Administrators · Lawyers · Compliance

#breach#regulation Read original →
Breach
BleepingComputer · · International

TP-Link patches Omada ZTP flaws allowing hackers to breach networks

TP-Link has patched 15 vulnerabilities in the zero-touch provisioning (ZTP) mechanism of its Omada network devices that could be chained with previously disclosed flaws to achieve remote code execution (RCE). [...]

Who should care: Cybersecurity · Privacy officers · Administrators

#breach#security Read original →