The Breach News

Microsoft Concealed 2013 Hack of Its Bug-Tracking Database

In a disturbing revelation for the cybersecurity community, Microsoft faced a significant data breach approximately four and a half years ago, specifically in 2013. Despite the attack involving a highly sophisticated hacking group, the incident remained undisclosed until now. This breach highlights the ongoing struggles corporations face in maintaining data…

Read MoreMicrosoft Concealed 2013 Hack of Its Bug-Tracking Database

Reducing Occupational Therapy Risks in Healthcare: 5 Key Strategies – A Webinar

Governance & Risk Management , Operational Technology (OT) Presented by Claroty 60 mins Healthcare organizations are increasingly grappling with a cybersecurity crisis that poses severe threats to operational resilience, financial stability, and patient safety. This crisis has transitioned from a theoretical concern to a pressing reality, revealing vulnerabilities within the…

Read MoreReducing Occupational Therapy Risks in Healthcare: 5 Key Strategies – A Webinar

Konni Group Employs Russian-Language Malicious Word Documents in Recent Attacks

A recent phishing campaign has surfaced, utilizing a Russian-language Microsoft Word document as a vehicle for deploying malware designed to extract sensitive data from compromised Windows systems. This attack has been linked to a threat actor known as Konni, which exhibits connections to the North Korean cyber espionage group identified…

Read MoreKonni Group Employs Russian-Language Malicious Word Documents in Recent Attacks

Mukashi: A New Variant of Mirai IoT Botnet Targeting Zyxel NAS Devices

In a significant development in cybersecurity, a new variant of the notorious Mirai botnet—dubbed “Mukashi”—is actively exploiting a newly discovered critical vulnerability affecting network-attached storage (NAS) devices. This attack aims to remotely compromise and commandeer vulnerable machines, reflecting an escalation in tactics employed by cybercriminals. Mukashi employs brute-force techniques, systematically…

Read MoreMukashi: A New Variant of Mirai IoT Botnet Targeting Zyxel NAS Devices

Severe Vulnerability (CVSS Score 10) Allows Hackers to Take Control of Oracle Identity Manager

A serious vulnerability has been uncovered in Oracle’s enterprise identity management system, posing risks of severe exploitation by remote, unauthenticated attackers. This flaw, identified as CVE-2017-10151, has been given the highest possible CVSS score of 10, indicating it is both critical and easily exploitable without the need for any user…

Read MoreSevere Vulnerability (CVSS Score 10) Allows Hackers to Take Control of Oracle Identity Manager

Alert: 3 Major Vulnerabilities Put ownCloud Users at Risk of Data Breaches

Recent advisories from the maintainers of ownCloud have revealed three critical vulnerabilities within their open-source file-sharing software that could lead to unauthorized access, data modification, and exposure of sensitive information. These vulnerabilities pose significant risks to users and require immediate attention. The first flaw, identified as CVE-2023-49103, boasts a CVSS…

Read MoreAlert: 3 Major Vulnerabilities Put ownCloud Users at Risk of Data Breaches