The Breach News

World Estimating Strengthens Data Security Measures – Lelezard

World Estimating Strengthens Data Security Measures In an effort to bolster its defenses against increasing cyber threats, World Estimating has announced enhancements to its data security practices. This development comes at a time when numerous organizations face persistent vulnerabilities and the risk of significant data breaches. The company, which operates…

Read MoreWorld Estimating Strengthens Data Security Measures – Lelezard

URGENT: GitLab Update Required – Critical Flaw in Workspace Creation Enables File Overwrite

GitLab has once again addressed a significant security vulnerability in both its Community Edition (CE) and Enterprise Edition (EE). This flaw, designated as CVE-2024-0402, poses a serious risk, allowing authenticated users to write files to arbitrary locations on the server while creating a workspace. The vulnerability, which received a critical…

Read MoreURGENT: GitLab Update Required – Critical Flaw in Workspace Creation Enables File Overwrite

Hackers-for-Hire Group Unveils New ‘PowerPepper’ In-Memory Malware

Cybersecurity Experts Uncover New Windows Backdoor Tied to DeathStalker Group Cybersecurity researchers announced on Thursday the discovery of an in-memory Windows backdoor, named “PowerPepper,” linked to a hacker-for-hire collective. This sophisticated malware is capable of executing malicious code remotely and extracting sensitive information from targets across Asia, Europe, and the…

Read MoreHackers-for-Hire Group Unveils New ‘PowerPepper’ In-Memory Malware

Twitter Reveals Possible State-Sponsored Attack Following Minor Data Breach

Twitter Faces Data Breach Linked to Suspected State-Sponsored Attack Twitter has recently experienced a minor data breach that the company attributes to a possible state-sponsored attack. In a blog post released on Monday, Twitter disclosed that during an investigation into a vulnerability affecting one of its customer support forms, it…

Read MoreTwitter Reveals Possible State-Sponsored Attack Following Minor Data Breach

Hospice Provider and Eye Care Clinic Alert 520,000 About Data Breaches

Recent Data Breaches Target Specialty Medical Providers, Compromising Sensitive Patient Information Marianne Kolbasuk McGee (HealthInfoSec) • December 9, 2025 VITAS Hospice is among the medical specialty providers reporting significant hacking incidents. (Image: VITAS Hospice) In recent developments, two specialty healthcare providers—VITAS Hospice Services based in Florida and Tri Century Eye…

Read MoreHospice Provider and Eye Care Clinic Alert 520,000 About Data Breaches

Nearly 200,000 Affected by Tri-Century Eye Care Data Breach – SC Media

Data Breach at Tri-Century Eye Care Affects Nearly 200,000 Individuals A significant data breach has recently unfolded at Tri-Century Eye Care, impacting approximately 200,000 individuals. The breach, which has raised alarms among cybersecurity experts, involves unauthorized access to sensitive personal information held by the company. This incident highlights the imperative…

Read MoreNearly 200,000 Affected by Tri-Century Eye Care Data Breach – SC Media

New Glibc Vulnerability Provides Attackers with Root Access on Major Linux Distributions

A critical vulnerability affecting the widely used GNU C Library (glibc) has come to light, enabling local malicious actors to gain full root access on Linux systems. This flaw is tracked as CVE-2023-6246, with a CVSS rating of 7.8, indicating a high level of severity. The vulnerability is located in…

Read MoreNew Glibc Vulnerability Provides Attackers with Root Access on Major Linux Distributions

Alert! NASA Notifies Employees of Personal Information Breach

In a significant cybersecurity incident, the National Aeronautics and Space Administration (NASA) has confirmed a breach that potentially exposes personal data of current and former employees. The breach, detected on October 23, involved unauthorized access to one of its servers, raising serious concerns about the integrity of sensitive information held…

Read MoreAlert! NASA Notifies Employees of Personal Information Breach

Checkmarx Acquires Tromzo to Enhance AI Security Automation

Application Security & Online Fraud , Fraud Management & Cybercrime , Next-Generation Technologies & Secure Development Checkmarx Acquires Tromzo, Enhancing AI-Driven Security Solutions Michael Novinson (MichaelNovinson) • December 9, 2025     Sandeep Johri, CEO, Checkmarx (Image: Checkmarx) Checkmarx, a prominent player in the application security arena, has acquired Tromzo,…

Read MoreCheckmarx Acquires Tromzo to Enhance AI Security Automation