The Breach News

Clop Linked to Korean Air Vendor Data Breach

Recent Cybersecurity Incidents: A Deep Dive into Breaches and Threats Pooja Tikekar (@PoojaTikekar) • January 1, 1970 Image: Shutterstock/ISMG This week, Information Security Media Group reports significant cybersecurity incidents including a breach tying Clop ransomware to Korean Air vendor data compromise, a sophisticated attack by a China-linked APT leveraging software…

Read MoreClop Linked to Korean Air Vendor Data Breach

Immediate Action Required: VMware Issues Patch for Severe vCenter Server RCE Vulnerability

VMware has issued urgent security updates to rectify a significant vulnerability in its vCenter Server software that poses a risk of remote code execution. This flaw, designated as CVE-2023-34048 and assigned a CVSS score of 9.8, is classified as an out-of-bounds write vulnerability associated with the DCE/RPC protocol. According to…

Read MoreImmediate Action Required: VMware Issues Patch for Severe vCenter Server RCE Vulnerability

Caution: Microsoft Detects Surge in Astaroth Fileless Malware Attacks

New Campaign Unveils Widespread Distribution of Astaroth Fileless Malware In a new report from Microsoft, cybersecurity experts reveal the latest details of an extensive campaign involving the notorious Astaroth fileless malware. Initially targeting users in Europe and Brazil earlier this year, this malware has been operational since at least 2017…

Read MoreCaution: Microsoft Detects Surge in Astaroth Fileless Malware Attacks

Reliance Jio Customers’ Data Reportedly Compromised – Company Rejects Breach Claims

Massive Data Breach Exposes Personal Information of 120 Million Reliance Jio Customers In a troubling incident that highlights vulnerabilities in data security, the personal details of approximately 120 million customers of Reliance Jio have reportedly been compromised. This breach may qualify as one of the most significant incidents of data…

Read MoreReliance Jio Customers’ Data Reportedly Compromised – Company Rejects Breach Claims

Cognizant Hit with US Class-Action Lawsuits Following TriZetto Data Breach

In late November 2024, a significant cybersecurity breach occurred when hackers infiltrated the computer network of Cognizant, a major technology services provider. The attackers gained access to sensitive personal information, which has raised serious concerns about data security practices within the organization. It has come to light that Cognizant did…

Read MoreCognizant Hit with US Class-Action Lawsuits Following TriZetto Data Breach

Nation-State Hackers Target Zero-Day Vulnerability in Roundcube Webmail Software

On October 11, 2023, the threat actor group known as Winter Vivern was detected exploiting a zero-day vulnerability in Roundcube webmail software, allowing them to harvest sensitive email messages from targeted accounts. According to ESET security researcher Matthieu Faou, the group has elevated its offensive by leveraging a newly discovered…

Read MoreNation-State Hackers Target Zero-Day Vulnerability in Roundcube Webmail Software