The Breach News

Hackers Take Advantage of LFI Vulnerability in File-Sharing Platforms

Attack Surface Management, Security Operations Attackers Access Server Files and Compromise Credentials in Gladinet CentreStack and Triofox Anviksha More (AnvikshaMore) • October 10, 2025 Image: Zakharchuk/Shutterstock Recent research reveals that hackers are exploiting a vulnerability that allows unauthorized access to critical files in file-sharing and remote-access applications, including Gladinet CentreStack…

Read MoreHackers Take Advantage of LFI Vulnerability in File-Sharing Platforms

Microsoft Issues Alert on New “Payroll Pirate” Scam Targeting Employee Direct Deposits

Microsoft has issued a warning about a sophisticated scam known as “Payroll Pirate,” which is currently targeting employees by redirecting their paycheck deposits into accounts controlled by fraudsters. This attack begins with the compromise of employee profiles on platforms like Workday or other cloud-based HR services. The scammers initiate the…

Read MoreMicrosoft Issues Alert on New “Payroll Pirate” Scam Targeting Employee Direct Deposits

Crypto Betting Leader Shuffle Acknowledges Significant User Data Breach

Shuffle, a prominent player in the crypto betting sector, has announced a significant data breach that compromised the personal information of a substantial portion of its user base. The source of this breach has been traced back to Fast Track, Shuffle’s customer relationship management (CRM) provider, which itself exhibited security…

Read MoreCrypto Betting Leader Shuffle Acknowledges Significant User Data Breach

Severe RCE Vulnerability in GFI KerioControl Enables Remote Code Execution Through CRLF Injection

Cybercriminals are exploiting a recently identified vulnerability affecting GFI KerioControl firewalls. This flaw, if successfully leveraged, may enable remote code execution (RCE) by malicious actors. The vulnerability, listed as CVE-2024-52875, pertains to a carriage return line feed (CRLF) injection attack, which can facilitate HTTP response splitting. Such an exploit may…

Read MoreSevere RCE Vulnerability in GFI KerioControl Enables Remote Code Execution Through CRLF Injection

PseudoManuscrypt Malware Spreads Like CryptBot, Targeting Korean Users

A sophisticated botnet known as PseudoManuscrypt has been actively targeting Windows systems in South Korea since May 2021, employing tactics similar to those used by the malware CryptBot. This trend has raised significant concerns within the cybersecurity community. A report from the South Korean cybersecurity firm AhnLab Security Emergency Response…

Read MorePseudoManuscrypt Malware Spreads Like CryptBot, Targeting Korean Users

Fortra Acknowledges ‘Unauthorized Access’ Incident Affecting GoAnywhere MFT

Encryption & Key Management, Fraud Management & Cybercrime, Governance & Risk Management Medusa Ransomware Group Linked to Exploitation of Recently Patched Zero-Day Vulnerability Mathew J. Schwartz (euroinfosec) • October 10, 2025 Image: Shutterstock/ISMG Recent cyberattacks have targeted Fortra’s GoAnywhere managed file transfer software, primarily affecting on-premises setups where the management…

Read MoreFortra Acknowledges ‘Unauthorized Access’ Incident Affecting GoAnywhere MFT

Apple Unveils $2 Million Bug Bounty for Critical Exploit Discoveries

Apple has significantly escalated its bug bounty program, now offering a maximum payout of $2 million for software exploits that could facilitate spyware attacks. This announcement was made by Ivan Krstić, Apple’s vice president of security engineering and architecture, during the Hexacon offensive security conference held in Paris. The new…

Read MoreApple Unveils $2 Million Bug Bounty for Critical Exploit Discoveries

Security Flaw in Rogue WordPress Plugin Puts E-Commerce Sites at Risk for Credit Card Theft

Cybersecurity researchers have uncovered a malicious WordPress plugin capable of creating unauthorized administrator accounts and injecting harmful JavaScript code designed to siphon credit card information. This activity is linked to a broader Magecart campaign specifically targeting e-commerce platforms, as reported by Sucuri. According to security analyst Ben Martin, the rogue…

Read MoreSecurity Flaw in Rogue WordPress Plugin Puts E-Commerce Sites at Risk for Credit Card Theft