The Breach News

E-Commerce Hackers Concealing Credit Card Stealers in Image Metadata

In a troubling evolution of cybercrime tactics, malicious actors are now embedding harmful code within the metadata of image files, notably targeting payment card data entered on compromised websites. This technique, identified as a form of steganography, was recently highlighted by researchers at Malwarebytes, who discovered that cybercriminals have effectively…

Read MoreE-Commerce Hackers Concealing Credit Card Stealers in Image Metadata

Russian Hacker Accused of Breaching LinkedIn and Dropbox Extradited to the U.S.

A significant development in the cybersecurity landscape has emerged with the arraignment of Yevgeniy Aleksandrovich Nikulin, a 30-year-old Russian national accused of orchestrating major data breaches affecting LinkedIn, Dropbox, and Formspring in 2012. The breaches allegedly compromised the personal information of over 100 million users, raising substantial concerns about cybersecurity…

Read MoreRussian Hacker Accused of Breaching LinkedIn and Dropbox Extradited to the U.S.

The Hidden Danger: How Polymorphic Malware is Bypassing Your Email Security—Webinar

Webinar Insights: Combatting Polymorphic Malware Threats to Email Security An alarming trend in cybersecurity has emerged, with approximately $350 million in avoidable losses attributed to polymorphic malware—malicious software that continually alters its code to evade conventional detection methods. As 18% of newly identified malware employs adaptive techniques, organizations are urged…

Read MoreThe Hidden Danger: How Polymorphic Malware is Bypassing Your Email Security—Webinar

New Security Flaws Discovered in pfSense Firewall Software – Update Immediately

Recent findings have uncovered multiple security vulnerabilities within the open-source Netgate pfSense firewall solution. These vulnerabilities could potentially be combined by an attacker, allowing them to execute arbitrary commands on affected devices. The identified issues involve two reflected cross-site scripting (XSS) issues alongside a command injection vulnerability, as reported by…

Read MoreNew Security Flaws Discovered in pfSense Firewall Software – Update Immediately

Enhanced StrongPity Hackers Focus on Syria and Turkey Using Modified Spyware

Recent investigations have revealed targeted watering hole attacks specifically aimed at the Kurdish community in Syria and Turkey. These incursions, attributed to an advanced persistent threat (APT) group known as StrongPity, employ sophisticated strategies to infiltrate and exfiltrate sensitive data from compromised systems, according to a report from Bitdefender shared…

Read MoreEnhanced StrongPity Hackers Focus on Syria and Turkey Using Modified Spyware

Facebook Confirms Breach of Public Data Affecting 2.2 Billion Users

On Wednesday, Facebook disclosed a significant cybersecurity breach impacting its massive user base of 2.2 billion individuals. CEO Mark Zuckerberg announced that cybercriminals exploited the platform’s “Search” functionality, enabling them to access and scrape the public profile information of nearly all users. This troubling revelation highlights Facebook’s ongoing struggle to…

Read MoreFacebook Confirms Breach of Public Data Affecting 2.2 Billion Users

Senate Intel Chair Highlights Risks Associated with Open-Source Security

3rd Party Risk Management, Governance & Risk Management Top Lawmaker Urges Review of Foreign Influence in Open-Source Software Chris Riotta (@chrisriotta) • December 19, 2025 Image: Keith J Finks/Shutterstock The chairman of the Senate Intelligence Committee has called on the White House to address what he identifies as a significant…

Read MoreSenate Intel Chair Highlights Risks Associated with Open-Source Security

French Regulator Imposes €1M Fine on Israeli Marketing Platform for Processor Violations

Israeli Marketing Firm Fined €1 Million for GDPR Violations Following Massive Data Breach In a significant enforcement action, the French data protection authority has levied a €1 million fine against Israeli marketing technology company Optimove for breaching data processor obligations outlined in the General Data Protection Regulation (GDPR). The penalty,…

Read MoreFrench Regulator Imposes €1M Fine on Israeli Marketing Platform for Processor Violations