PrivacySignal
Breach

Polymarket customers lose $3 million in supply-chain attack

BleepingComputer · · International · Data Breaches

Polymarket, a prediction market platform, will reimburse roughly $3 million to customers after attackers compromised a third-party vendor and injected malicious code into the platform's frontend, draining user funds. The company says it will cover all losses from the incident.

Why this matters: The attack did not come through Polymarket's own code. It came through a vendor they trusted. That is the supply-chain problem in plain terms: you can do everything right on your end and still get hit through someone else's door. Users had no way to see the risk. The script looked like part of the site because, technically, it was. Reimbursement is good. But the real issue is that platforms need to own the security of everything their users encounter, including the third-party code running quietly in the background.

Who should care: Cybersecurity · Privacy officers · Administrators

This summary is AI-assisted and may contain errors. It is an original briefing to help you gauge significance quickly — not a reproduction of the source. Always read the linked original before relying on it. See our methodology.

Analysis

All analysis →

Weekly Editorial Analysis from Experts and Editors

Related stories

Breach
The Record · · International

Ransomware group hijacks hospital system’s Facebook page amid ongoing cyberattack fallout

A ransomware group attacked a hospital system and then took over its Facebook page as part of the ongoing fallout. The attackers claim to have stolen 6 terabytes of data, including records tied to sexual assault, mental health care, abortions, and sexual harassment incidents.

Who should care: Cybersecurity · Privacy officers · Administrators · Healthcare professionals · Compliance

#breach#healthcare#security Read original →
Breach
HIPAA Journal · · US Federal

Healthcare Orgs Warned About Gunra Ransomware Attacks

CISA, the FBI, and international partners have issued a joint advisory warning healthcare organizations about Gunra, a ransomware-as-a-service operation actively targeting the sector.

Who should care: Cybersecurity · Privacy officers · Administrators · Healthcare professionals · Compliance

#breach#healthcare#security Read original →
Breach
BleepingComputer · · International

Mozilla updates GPG signing key for Firefox releases after exposure

Mozilla has replaced the GPG key used to cryptographically sign Firefox and Thunderbird releases after the key was accidentally exposed in a public GitHub repository. The update is intended to ensure users can continue to verify that software releases are authentic and untampered.

Who should care: Cybersecurity · Privacy officers · Administrators

Breach Critical
BleepingComputer · · International

CISA: Microsoft SharePoint flaw now exploited in ransomware attacks

CISA confirmed today that ransomware gangs have begun abusing a high-severity Microsoft SharePoint remote code execution vulnerability, which has been flagged as actively exploited since early July. [...]

Who should care: Cybersecurity · Privacy officers · Administrators

#breach#security Read original →
Breach
BleepingComputer · · International

US and South Korea warn of Gunra ransomware targeting govt agencies

U.S. federal agencies and South Korea's National Policy Agency warned government and critical infrastructure organizations worldwide to secure their systems against Gunra ransomware attacks. [...]

Who should care: Cybersecurity · Privacy officers · Administrators

#breach#security Read original →