The Breach News

22-Year-Old Hacker Confesses to Role in 2014 Yahoo Breach, Acknowledges Assistance to Russian Intelligence

Kazakhstan-Born Hacker Enters Guilty Plea in Massive Yahoo Data Breach Karim Baratov, a 22-year-old Canadian citizen originally from Kazakhstan, has pleaded guilty to charges stemming from a significant data breach that compromised all three billion Yahoo accounts in 2014. The U.S. Justice Department previously announced charges against Russian intelligence officers…

Read More22-Year-Old Hacker Confesses to Role in 2014 Yahoo Breach, Acknowledges Assistance to Russian Intelligence

CISA Urges OT Operators to Pause and Consider AI Impacts

Artificial Intelligence & Machine Learning, Critical Infrastructure Security, Next-Generation Technologies & Secure Development International Coalition Warns of Security Risks in Operational Technology’s Transition to AI Shaun Waterman • December 23, 2025 Image: DC Studio/Shutterstock The U.S. Cybersecurity and Infrastructure Security Agency (CISA) and its international partners have issued a cautionary…

Read MoreCISA Urges OT Operators to Pause and Consider AI Impacts

Beyond Penalties: Rethinking Korea’s Response to Coupang’s Data Breach and Accountability Issues

Coupang Data Breach Highlights Cybersecurity Shortcomings and Regulatory Challenges A significant data breach at Coupang, one of South Korea’s largest e-commerce platforms, has raised critical concerns about the company’s approach to cybersecurity and its accountability in safeguarding customer information. This incident is noteworthy not just as a cybersecurity issue but…

Read MoreBeyond Penalties: Rethinking Korea’s Response to Coupang’s Data Breach and Accountability Issues

Hackers Compromise LineageOS, Ghost, and DigiCert Servers Exploiting SaltStack Vulnerability

Shortly after cybersecurity researchers raised warnings about two significant vulnerabilities in the SaltStack configuration framework, an ongoing campaign has already begun exploiting these flaws, targeting organizations such as LineageOS, Ghost, and DigiCert. The vulnerabilities, identified as CVE-2020-11651 and CVE-2020-11652, permit attackers to execute arbitrary code on remote servers operating within…

Read MoreHackers Compromise LineageOS, Ghost, and DigiCert Servers Exploiting SaltStack Vulnerability

Chinese Crypto Scammers on Telegram Are Driving the Growth of the Largest Darknet Markets Yet

The emergence of black markets for illegal goods, including drugs and weapons, began on the dark web over a decade ago, leveraging cryptocurrencies and anonymity tools like Tor. At that time, these innovations facilitated the execution of vast, untraceable online transactions valued in the billions. Fast forward to 2025, and…

Read MoreChinese Crypto Scammers on Telegram Are Driving the Growth of the Largest Darknet Markets Yet

Meet the NSA Employee Who Stored Classified Documents at Home

A former contractor for the U.S. National Security Agency (NSA), Nghia Hoang Pho, has pleaded guilty to unlawfully taking classified documents home, which were subsequently compromised by Russian hackers. This incident has reignited concerns over data security within sensitive government operations. According to a statement from the U.S. Justice Department,…

Read MoreMeet the NSA Employee Who Stored Classified Documents at Home

ServiceNow’s $7.75 Billion Acquisition of Armis Enhances IT and OT Security Coverage

Artificial Intelligence & Machine Learning, Next-Generation Technologies & Secure Development, The Future of AI & Cybersecurity Acquisition Streamlines Security Operations From Asset Discovery to Remediation Jennifer Lawinski • December 23, 2025 Image: Shutterstock ServiceNow, a leader in artificial intelligence software, has made a substantial move in the cybersecurity landscape by…

Read MoreServiceNow’s $7.75 Billion Acquisition of Armis Enhances IT and OT Security Coverage

Microsoft Alerts on APT28, Backed by Kremlin, Exploiting Major Outlook Vulnerability

Microsoft recently announced the detection of nation-state activities tied to the Kremlin, exploiting a critical security vulnerability in the Outlook email service that has since been patched. This issue allowed unauthorized access to user accounts hosted on Microsoft Exchange servers, raising alarming security concerns for organizations relying on this platform.…

Read MoreMicrosoft Alerts on APT28, Backed by Kremlin, Exploiting Major Outlook Vulnerability