Toronto's Hospital for Sick Children (SickKids) says a cybersecurity incident exposed the personal information of some current and former employees and job applicants, stemming from a flaw in third-party software. Clinical systems and patient records were not affected. (264) [...]

The Hospital for Sick Children (SickKids) has disclosed a cybersecurity incident that exposed the personal information of some current and former employees, as well as job applicants. The Toronto-based pediatric hospital confirmed that the breach originated from a vulnerability in a third-party software application used by SickKids and other organizations.
According to SickKids, its clinical systems and patient records were not affected by the incident, and patient care continued without disruption. However, the hospital's public-facing Careers website was temporarily taken offline following the discovery of the breach. The Careers site has since been restored.
The incident resulted in unauthorized access to data belonging to current and former employees of SickKids, Boomerang (a SickKids-owned pediatric clinic), and the SickKids Foundation, in addition to SickKids job applicants. The hospital has not specified the exact categories of data exposed, the total number of individuals affected, or the date of the intrusion.
SickKids has initiated an investigation into the incident with the assistance of external cybersecurity experts. While the review of the impacted information is ongoing, the hospital is directly notifying individuals confirmed to be affected. Out of an abundance of caution, SickKids has also alerted all potentially impacted individuals and is offering 24 months of complimentary credit monitoring and identity protection services.
The hospital has not publicly identified the third-party vendor, the specific software application, or any associated CVE ID related to the vulnerability. The phrasing of the disclosure suggests a potential wider campaign targeting users of the same product.
This incident marks at least the third publicly known security event impacting SickKids in recent years. In December 2022, the hospital was hit by a ransomware attack attributed to the LockBit gang, which disrupted internal systems and caused delays in lab and imaging results. Although LockBit later issued an apology and provided a free decryptor, SickKids had already spent nearly two weeks restoring its systems independently.
In September 2023, SickKids was also among several Ontario healthcare providers affected by a data breach at a third-party organization that manages perinatal and child health data. That incident, which stemmed from the mass exploitation of the MOVEit Transfer zero-day vulnerability (CVE-2023-34362), exposed information on 3.4 million individuals, including names, home addresses, dates of birth, and health card numbers.

JetBrains is urging Cadence users to revoke and rotate all credentials following a security incident last month in which unidentified threat actors exploited a recently disclosed critical vulnerability in TeamCity to breach its own environment. "Cadence users should immediately revoke or rotate all credentials and secrets that may have been used to run their Cadence executions," JetBrains said.
A weakness has been identified in Tenda CP3 27.5.57.101. This issue affects some unknown processing of the file Net/NetCheckPing.cpp. This manipulation of the argument interface_name/host causes os command injection. The attack can be initiated remotely.
A security flaw has been discovered in Tenda CP3 27.5.57.101. This vulnerability affects the function SystemAsh of the file Apis/system.c of the component Kylin. The manipulation of the argument AlarmVoiceURL results in os command injection. It is possible to launch the attack remotely.

OpenAI has announced a $1 billion commitment to provide subsidized access to its Daybreak AI cybersecurity tools for under-resourced critical infrastructure defenders. The initiative, named Daybreak for Frontline Defenders, will offer AI models, training, and technical support over the next six months, prioritizing water and wastewater utilities, electric grid operators, and local government entities. This move aims to equip organizations with limited budgets and staff against increasingly sophisticated cyber threats.

Attackers are exploiting a new unpatched vulnerability in Magento Open Source and Adobe Commerce that lets them run malicious code on an online store's server without logging in, Dutch e-commerce security company Sansec said in an advisory published on September 5. Sansec, which discovered the flaw and named it StyleSmuggler, said attacks started on September 4. "Sansec is publishing early
In BPF instructions that load/store a value from/to a scratch memory register the register index is an unsigned 32-bit integer and must not exceed 15, but libpcap BPF interpreter does not validate the value. In particular uncommon use cases a crafted filter program can cause the interpreter to try reading and writing the OS process memory in the 16GiB starting at the current stack frame on 64-bit architectures and in the entire address space on 32-bit architectures.