The Breach News

Expedia and Orbitz Travel Sites Compromised: Flights and Hotel Booking Affected

Orbitz Data Breach Exposes Nearly 880,000 Payment Card Numbers Orbitz, a Chicago-based online travel agency and a subsidiary of Expedia, has disclosed a significant data breach affecting its legacy website. Approximately 880,000 payment card numbers have been compromised, potentially exposing customers’ sensitive financial information. Founded as a travel fare aggregator,…

Read MoreExpedia and Orbitz Travel Sites Compromised: Flights and Hotel Booking Affected

Maximizing Business Value through Machine-Led Security Webinar

New Machine-Led Security Approach Aims to Enhance Cyber Defense In the wake of increasing cyber threats, security teams find themselves grappling with an overwhelming amount of data noise, hindering their ability to focus on genuine threats. This operational complexity, combined with the evolving sophistication of adversaries who leverage artificial intelligence,…

Read MoreMaximizing Business Value through Machine-Led Security Webinar

E-Apostille Data Breach Puts Over 1,000 Individuals at Risk of Identity Theft

A fraudulent website posing as Bangladesh’s official e-apostille platform has compromised sensitive data belonging to over 1,100 individuals, raising alarms among cybersecurity experts. This incident is being characterized as one of the most significant failures in digital governance in recent years. Documents that have surfaced online include national identification cards,…

Read MoreE-Apostille Data Breach Puts Over 1,000 Individuals at Risk of Identity Theft

Lazarus Group Leverages Log4j Vulnerabilities for Remote Access Trojan Deployment

The Lazarus Group, a North Korean cybercriminal entity, has launched a significant global campaign leveraging vulnerabilities in Log4j to facilitate the deployment of previously unknown remote access trojans (RATs). This operation, termed “Operation Blacksmith” by Cisco Talos, employs a range of malware families written in DLang, notably including a RAT…

Read MoreLazarus Group Leverages Log4j Vulnerabilities for Remote Access Trojan Deployment

Hackers Impersonate HR Professionals to Target Military and Aerospace Personnel with Fake Job Offers

Targeted Cyber-Espionage Campaign Hits Aerospace and Military Sectors Cybersecurity researchers have unveiled a sophisticated cyber-espionage campaign that specifically targets aerospace and military organizations across Europe and the Middle East. This initiative, termed “Operation In(ter)ception,” reportedly aimed to infiltrate and monitor key personnel within these firms while also attempting to extract…

Read MoreHackers Impersonate HR Professionals to Target Military and Aerospace Personnel with Fake Job Offers

The Platform Myth: Breaking Free from the “Stitched-Together” Security Stack Webinar.

Presented by SentinelOne 60 mins Many identity governance platforms were designed in a time when access was contained within isolated systems and governance consisted mainly of periodic reviews. However, the landscape has significantly evolved; today, access encompasses a range of applications, including ERP, HCM, and various SaaS products. As a…

Read MoreThe Platform Myth: Breaking Free from the “Stitched-Together” Security Stack Webinar.

Consumer Agency Directs SK Telecom to Compensate Users 100,000 Won Each for Data Breach

SEOUL, Dec. 21 (Yonhap) — In a significant development, South Korea’s state-run consumer agency has mandated SK Telecom Co. to compensate each affected user following a major data breach earlier this year. The authority has ordered the telecommunications giant to provide 100,000 won (approximately US$67) to every user impacted by…

Read MoreConsumer Agency Directs SK Telecom to Compensate Users 100,000 Won Each for Data Breach

New Critical RCE Vulnerability Identified in Apache Struts 2 – Update Immediately

Apache Software Foundation has issued a security advisory regarding a critical vulnerability within the Struts 2 open-source web application framework, posing a significant risk for remote code execution (RCE). This vulnerability, designated as CVE-2023-50164, stems from inadequate “file upload logic” that permits unauthorized path traversal. If exploited, attackers can upload…

Read MoreNew Critical RCE Vulnerability Identified in Apache Struts 2 – Update Immediately