The New York Attorney General’s Office and HealthAlliance, a healthcare facility operator, have agreed a $550,000 cyberattack settlement. HealthAlliance was found to have insufficient protections in place, leading to a cyber-attack that compromised 242,641 patients’ data. The company will pay penalties and adopt procedures to improve its cybersecurity practices. It was also revealed that a technical issue was ignored after a vendor suggested action.

400+ SAP NetWeaver Devices Vulnerable to 0-Day Attacks that Exploited in the Wild
Shadow Servers have identified 454 vulnerable SAP NetWeaver systems affected by a critical zero-day flaw, CVE-2025-31324, allowing unauthenticated file uploads and potential system compromise. Discovered