The Breach News

Irregular Raises $80M in Series A Funding to Tackle AI Model Exploitation

Artificial Intelligence & Machine Learning, Next-Generation Technologies & Secure Development Startup Develops AI Simulations to Combat Cyber Threats Michael Novinson (@MichaelNovinson) • September 19, 2025 Irregular’s CTO Omer Nevo and CEO Dan Lahav (Image: Irregular) Irregular, an AI security lab, has secured $80 million in funding to create test environments…

Read MoreIrregular Raises $80M in Series A Funding to Tackle AI Model Exploitation

ESET Reports Collaboration Between Two of the Kremlin’s Most Active Hacking Groups

ESET has reported a likely collaboration between two Russian hacking groups, Turla and Gamaredon, suggesting they were working together in recent cyber operations targeting Ukrainian systems. The speculation arises from their shared affiliations with the Federal Security Service (FSB) of Russia, albeit from different centers within the organization. According to…

Read MoreESET Reports Collaboration Between Two of the Kremlin’s Most Active Hacking Groups

AsyncRAT Campaign Deploys Python Payloads and TryCloudflare Tunnels for Stealthy Attacks

Recent investigations have revealed a sophisticated malware campaign deploying a remote access trojan (RAT) called AsyncRAT, utilizing Python payloads and TryCloudflare tunnels for distribution. Forcepoint X-Labs researcher Jyotika Singh indicated that AsyncRAT capitalizes on the async/await programming model, allowing attackers to covertly access and manipulate infected systems, exfiltrate data, and…

Read MoreAsyncRAT Campaign Deploys Python Payloads and TryCloudflare Tunnels for Stealthy Attacks

10 U.S. States Safeguarding 322 Million Internet Users Against $16 Billion in Cybercrime Losses – DesignRush

10 U.S. States Safeguard 322 Million Internet Users Against $16 Billion in Cybercrime Losses Recent reports highlight significant advancements made by ten U.S. states in their initiative to protect approximately 322 million Internet users from overwhelming cybercrime losses, which have accumulated to an estimated $16 billion. This initiative showcases a…

Read More10 U.S. States Safeguarding 322 Million Internet Users Against $16 Billion in Cybercrime Losses – DesignRush

Critical Update: Microsoft Addresses 57 Security Vulnerabilities, 6 of Which Are Actively Exploited Zero-Days

On Tuesday, Microsoft rolled out security updates addressing a total of 57 vulnerabilities, including six that have been actively exploited in the wild. These updates are particularly crucial for organizations concerned about potential security breaches, as they rectify flaws that could be leveraged by malicious actors. Among the 57 identified…

Read MoreCritical Update: Microsoft Addresses 57 Security Vulnerabilities, 6 of Which Are Actively Exploited Zero-Days

Zero-Day RCE Vulnerability in Sophos Firewall Exploited by Hackers — Patch Now Available

In a significant cybersecurity development, Sophos has issued a critical patch for its firewall product following the discovery of a severe zero-day vulnerability actively being exploited by cyber attackers. This vulnerability has raised serious concerns for users, as it could lead to unauthorized remote code execution. The issue, identified as…

Read MoreZero-Day RCE Vulnerability in Sophos Firewall Exploited by Hackers — Patch Now Available

FileFix Campaign Leverages Facebook Suspension as Hook

Fraud Management & Cybercrime, Social Engineering Malware Dissemination Tied to FileFix Campaign Targeting Facebook Users Pooja Tikekar (@PoojaTikekar) • September 18, 2025 A malicious command is embedded in a deceptive upload window. (Image: Acronis/ISMG) A new social engineering operation, dubbed FileFix, has emerged, employing sophisticated techniques to persuade users into…

Read MoreFileFix Campaign Leverages Facebook Suspension as Hook

This Microsoft Entra ID Vulnerability Posed a Major Threat

Major Security Flaw Discovered in Microsoft Azure’s Identity Management System Over the past decade, a significant transition has occurred in how businesses manage their digital infrastructures, shifting from self-hosted servers to cloud services. This change has allowed many organizations to benefit from the advanced security features offered by key cloud…

Read MoreThis Microsoft Entra ID Vulnerability Posed a Major Threat

JavaScript Cross-Platform Malware Targets Crypto Wallets in Latest Lazarus Group Operation

A new cyber threat attributed to the North Korea-linked Lazarus Group has surfaced, where attackers exploit fake LinkedIn job offers in the cryptocurrency and travel sectors to deliver malicious software. This campaign targets operating systems across the board, including Windows, macOS, and Linux. According to cybersecurity firm Bitdefender, the operation…

Read MoreJavaScript Cross-Platform Malware Targets Crypto Wallets in Latest Lazarus Group Operation