One Healthcare Archive Was Breached. 9.5 Million Patients Paid the Price.

A breach at Aesto Health reached 9.5 million people across at least two dozen providers, exposing medical, financial and identity data stored in AWS.
BlackTree articles covering cybersecurity, privacy and digital legislation across North America.

A breach at Aesto Health reached 9.5 million people across at least two dozen providers, exposing medical, financial and identity data stored in AWS.

A breach of Thomson Reuters’ C-Track cloud may have exposed sealed and confidential court records across at least 12 US jurisdictions and Ontario.

ATF says a standalone system breach did not reach its enterprise network or eForms, but the isolated environment contained information about investigation targets.

Alabama has subpoenaed OpenAI over the Hugging Face agent intrusion, testing whether weak AI evaluation controls can also violate consumer-protection law.

Research finds that privacy-protected ad targeting and campaign metrics can compose into an inference channel. The result is a systems limit, not evidence of misuse by one named platform.

Alabama has subpoenaed OpenAI over the Hugging Face agent incident, testing whether an AI containment failure can become a consumer-protection case.

UT San Antonio says an intrusion attempt was stopped before core systems, yet precautionary shutdowns disrupted services and delayed fall classes.

US prosecutors allege Mabna Institute hackers served Iranian state clients while selling stolen research and university access through commercial sites.

Most security teams are trained to look for attackers entering an organisation. Malware arrives. Credentials are stolen. A vulnerability is exploited. A suspicious login appears. The North Korean remote IT worker programme takes a different route. The attacker applies for…

A new White House programme will let vetted U.S. security companies conduct surveillance and disruptive operations against foreign cybercrime groups under federal direction. It is a significant expansion of private-sector offensive capability, but the memorandum’s legal guardrails leave difficult questions about attribution, accountability and escalation.