The Breach News

AI Governance: Accelerating Progress, Not Bureaucracy

Agentic AI, Artificial Intelligence & Machine Learning, Next-Generation Technologies & Secure Development Insights from ServiceNow’s Neeraj Jain on Managing Risk and Ensuring Real-Time Data Access for AI Michael Novinson (MichaelNovinson) • December 15, 2025 Neeraj Jain, Director of Product Management, Hyperscalers and Multi-Cloud, ServiceNow Organizations that incorporate governance into their…

Read MoreAI Governance: Accelerating Progress, Not Bureaucracy

Take Immediate Action: CISA Warns of Ongoing Exploitation of Microsoft SharePoint Vulnerability

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has officially included a critical vulnerability affecting Microsoft SharePoint Server in its Known Exploited Vulnerabilities (KEV) catalog, highlighting evidence of active exploitation within various environments. This vulnerability, identified as CVE-2023-29357, has garnered a significant CVSS score of 9.8, indicating its severity and…

Read MoreTake Immediate Action: CISA Warns of Ongoing Exploitation of Microsoft SharePoint Vulnerability

Hackers Make Off with $5.4 Million from Eterbase Cryptocurrency Exchange

Major Cyber Breach Hits European Cryptocurrency Exchange Eterbase In a significant cybersecurity incident, Eterbase, a cryptocurrency exchange operating out of Bratislava, Slovakia, has reported a breach that has resulted in the theft of cryptocurrencies valued at $5.4 million. This breach, attributed to an unidentified hacker group, highlights ongoing vulnerabilities within…

Read MoreHackers Make Off with $5.4 Million from Eterbase Cryptocurrency Exchange

Chrome Vulnerability Exposed Facebook’s Complete User Data to Hackers

In response to emerging security concerns, Google has underscored the importance of using HTTPS by marking all non-HTTPS websites as ‘Not Secure’ in its Chrome 68 browser update. This shift aims to enhance the security landscape for internet users. Additionally, the upgraded version addresses critical vulnerabilities that may put private…

Read MoreChrome Vulnerability Exposed Facebook’s Complete User Data to Hackers

Youth Sports and NCAA Insurance Claims May Have Been Hacked

Data Breach Notification, Data Security, Healthcare Data Breach At National Accident Health Exposes Medical Information of 181,000 Individuals Marianne Kolbasuk McGee (HealthInfoSec) • December 15, 2025 The NAHGA has issued notifications to 181,000 individuals regarding an April breach that may have compromised their medical claims data. (Image: NAHGA) A breach…

Read MoreYouth Sports and NCAA Insurance Claims May Have Been Hacked

PornHub Targeted by Extortion Following Theft of Premium Member Activity Data

In a significant cybersecurity breach, the adult video platform PornHub has fallen victim to extortion attempts from the ShinyHunters hacking group. This follows the reported theft of search and viewing history concerning PornHub’s Premium members, which stemmed from a recent compromise of analytics provider Mixpanel. Last week, PornHub issued a…

Read MorePornHub Targeted by Extortion Following Theft of Premium Member Activity Data

Nation-State Actors Exploit Ivanti VPN Zero-Days to Deploy Five Families of Malware

Recent reports have detailed a sophisticated cybersecurity incident affecting Ivanti Connect Secure (ICS) VPN appliances, where suspected nation-state actors have exploited two critical zero-day vulnerabilities since early December 2023. The vulnerabilities, identified as CVE-2023-46805 and CVE-2024-21887, have enabled attackers to deploy multiple malware families, allowing them to bypass authentication mechanisms…

Read MoreNation-State Actors Exploit Ivanti VPN Zero-Days to Deploy Five Families of Malware

New Linux Malware Extracts Call Data from VoIP Softswitch Systems

New Linux Malware Targets VoIP Systems to Steal Call Metadata Cybersecurity experts have identified a novel strain of Linux malware named “CDRThief,” specifically engineered to exploit vulnerabilities in voice over IP (VoIP) softswitches. This malware aims to extract sensitive phone call metadata from compromised systems, raising significant concerns for businesses…

Read MoreNew Linux Malware Extracts Call Data from VoIP Softswitch Systems