The Breach News

Oracle Reports No Zero-Day Exploits Connected to Customer Extortion Cases

Data-Theft Attacks Compromise Organizations Amid Absence of July Patch Update Mathew J. Schwartz ( euroinfosec ) • October 3, 2025 Image: Shutterstock/ISMG Oracle has reported that its customers are under attack from data-seeking extortionists. While cybersecurity researchers and the software giant emphasize that no new zero-day vulnerabilities are being exploited,…

Read MoreOracle Reports No Zero-Day Exploits Connected to Customer Extortion Cases

ICE Proposes Establishing a Round-the-Clock Social Media Surveillance Unit

US Immigration Authorities Expand Social Media Surveillance Efforts In a significant expansion of their monitoring capabilities, U.S. immigration authorities are gearing up to enhance their social media surveillance. Plans are underway to recruit nearly 30 contractors to sift through online posts, photos, and messages, transforming this raw data into actionable…

Read MoreICE Proposes Establishing a Round-the-Clock Social Media Surveillance Unit

Cybercriminals Employ Innovative DNS Hijacking Method for Investment Fraud

Recently, a new and sophisticated DNS threat actor, identified as Savvy Seahorse, has emerged, adeptly exploiting various tactics to lure victims into fraudulent investment schemes. The primary modus operandi involves enticing individuals to register on false investment platforms, deposit funds into personal accounts, and then redirect those deposits to banks…

Read MoreCybercriminals Employ Innovative DNS Hijacking Method for Investment Fraud

Renault UK Customers’ Personal Data Compromised in Third-Party Hack

Renault Group UK has reported a data breach affecting the personal information of its customers following a cyber-attack on a third-party data processing partner. This incident underscores the ongoing threat that cyber-attacks pose to major corporations. In an official communication, the company confirmed that the attackers targeted its external data…

Read MoreRenault UK Customers’ Personal Data Compromised in Third-Party Hack

Critical Cacti Vulnerability (CVE-2025-22604) Allows Remote Code Execution

A serious security vulnerability has been identified in the open-source network monitoring and fault management tool, Cacti. This flaw poses a risk of remote code execution for authenticated users on affected installations. The issue has been assigned the identifier CVE-2025-22604 and has garnered a high CVSS score of 9.1 out…

Read MoreCritical Cacti Vulnerability (CVE-2025-22604) Allows Remote Code Execution

Hospital Chain Agrees to Pay $7.6 Million to Resolve Breach Lawsuit

Data Privacy, Data Security, Healthcare Hospital Sisters Health System’s 2023 Cyberattack Impacted Nearly 900,000 Individuals Marianne Kolbasuk McGee (HealthInfoSec) • October 2, 2025 Hospital Sisters Health System has agreed to a $7.6 million settlement and further bolster its data security measures following a significant hacking incident in 2023. (Image: HSHS)…

Read MoreHospital Chain Agrees to Pay $7.6 Million to Resolve Breach Lawsuit

Former Google Engineer Arrested for Allegedly Stealing AI Technology Trade Secrets for China

The U.S. Department of Justice (DoJ) has indicted a 38-year-old Chinese national and a California resident for allegedly stealing proprietary information from Google while covertly working for two tech firms based in China. The indictment highlights a significant cybersecurity breach involving sensitive data theft pertinent to artificial intelligence. Linwei Ding,…

Read MoreFormer Google Engineer Arrested for Allegedly Stealing AI Technology Trade Secrets for China

Essential Tips for Cybersecurity Success

Opinion In recognition of Cyber Security Awareness Month, a GP expert offers essential guidance for general practices to safeguard their systems and data. Experts warn that general practices and healthcare businesses are prime targets for cybercriminals. Have you logged into your device using ‘charlie’ today? Or perhaps you think you’re…

Read MoreEssential Tips for Cybersecurity Success

New SLAP and FLOP Attacks Reveal Vulnerabilities in Apple M-Series Chips to Speculative Execution Exploits

A recent analysis from a team at Georgia Institute of Technology and Ruhr University Bochum has unveiled two significant side-channel attacks specifically targeting Apple silicon chips, notably affecting popular web browsers such as Safari and Google Chrome. The attacks have been aptly codenamed Data Speculation Attacks via Load Address Prediction…

Read MoreNew SLAP and FLOP Attacks Reveal Vulnerabilities in Apple M-Series Chips to Speculative Execution Exploits