The Breach News

Researchers Discover Hidden Malicious Code in PyPI Python Packages

Recent investigations have revealed that four rogue packages infiltrated the Python Package Index (PyPI), executing a series of malicious operations including the deployment of malware, the removal of the netstat utility, and the manipulation of the SSH authorized_keys file. The targeted packages—aptx, bingchilling2, httops, and tkint3rs—collectively amassed around 450 downloads…

Read MoreResearchers Discover Hidden Malicious Code in PyPI Python Packages

ICE Now Equipped with Spyware

The Biden administration has classified certain spyware used for phone hacking as highly controversial, leading to strict limitations on its use by the US government in an executive order issued in March 2024. As the Trump administration takes steps to enhance immigration enforcement, this landscape could shift dramatically, paving the…

Read MoreICE Now Equipped with Spyware

Chess.com Confirms Data Breach Following Exploitation of External System by Hackers

Chess.com, a premier online chess platform, has confirmed a significant data breach that has exposed the personal information of over 4,500 users. The breach occurred due to unauthorized access through an external system connected to the company’s network, underscoring vulnerabilities present in third-party integrations. Based in Orem, Utah, Chess.com revealed…

Read MoreChess.com Confirms Data Breach Following Exploitation of External System by Hackers

Severe Erlang/OTP SSH Vulnerability (CVSS 10.0) Enables Unauthenticated Code Execution

A serious security vulnerability has been identified within the SSH implementation of the Erlang/Open Telecom Platform (OTP), which could allow an attacker to execute arbitrary code without requiring prior authentication under specific circumstances. Designated as CVE-2025-32433, this flaw has been assigned a maximum CVSS score of 10.0. Researchers from Ruhr…

Read MoreSevere Erlang/OTP SSH Vulnerability (CVSS 10.0) Enables Unauthenticated Code Execution

New Variant of ESXiArgs Ransomware Surfaces Following CISA’s Release of Decryptor Tool

Recent developments have unfolded in the realm of cybersecurity following the release of a decryptor by the U.S. Cybersecurity and Infrastructure Security Agency (CISA) to assist victims of ESXiArgs ransomware attacks. Cybercriminals have responded with an updated variant that has been observed to encrypt a greater volume of data, complicating…

Read MoreNew Variant of ESXiArgs Ransomware Surfaces Following CISA’s Release of Decryptor Tool

Trump Advocates for AI in Education Amid FTC Investigation into Risks

White House Launches AI Education Initiative Amid FTC Concerns Over Chatbot Risks Chris Riotta (@chrisriotta) • September 5, 2025 Image: VideoFlow/Shutterstock The White House has initiated its Presidential Artificial Intelligence Challenge, aiming to broaden the integration of AI in educational settings as the academic year commences. This move coincides with…

Read MoreTrump Advocates for AI in Education Amid FTC Investigation into Risks