The Breach News

OpenSSH Issues Patch for Newly Discovered Pre-Auth Double Free Vulnerability

The OpenSSH maintainers have announced the release of OpenSSH 9.2, which aims to rectify several security vulnerabilities, notably a memory safety issue identified in the OpenSSH server (sshd). This vulnerability, cataloged as CVE-2023-25136, is classified as a pre-authentication double free vulnerability that was introduced with version 9.1. The maintainers clarified…

Read MoreOpenSSH Issues Patch for Newly Discovered Pre-Auth Double Free Vulnerability

Hackers Leverage New Flash Zero-Day Vulnerability to Spread FinFisher Spyware

Recent reports have unveiled the resurgence of FinSpy, a notorious surveillance malware, which is now targeting high-profile users via a fresh Adobe Flash zero-day exploit embedded within Microsoft Office documents. This significant threat was uncovered by security experts from Kaspersky Labs, who identified a vulnerability in Adobe Flash that is…

Read MoreHackers Leverage New Flash Zero-Day Vulnerability to Spread FinFisher Spyware

20 Million Credit Cards Stolen in South Korea: Data Breach Affects 40% of the Population

Insider Threat Leads to Massive Data Breach in South Korea In a significant breach of financial security, sensitive data from at least 20 million customers was compromised due to the actions of an insider employee in South Korea. The individual, who had worked as a temporary consultant at the Korean…

Read More20 Million Credit Cards Stolen in South Korea: Data Breach Affects 40% of the Population

Live Webinar: Ensuring Audit-Ready Data Disposal in a High-Risk Compliance Landscape

Explore key topics such as Data Backup and Recovery, Data Loss Prevention (DLP), and Data Security. Presented by Blancco 60 Minutes As businesses increasingly modernize their infrastructures to meet demands for AI integration, cloud computing, and sustainability, the management of end-of-life technology has surfaced as a significant risk factor. With…

Read MoreLive Webinar: Ensuring Audit-Ready Data Disposal in a High-Risk Compliance Landscape

Lotus Blossom Hackers Compromise Official Notepad++ Hosting Infrastructure – gbhackers.com

Lotus Blossom Hackers Compromise Notepad++ Hosting Infrastructure In a significant cybersecurity incident, the Lotus Blossom attackers have successfully breached the official hosting infrastructure of Notepad++, a widely used text and source code editor. This breach raises concerns for users and businesses relying on Notepad++ for development and coding tasks, as…

Read MoreLotus Blossom Hackers Compromise Official Notepad++ Hosting Infrastructure – gbhackers.com

Unresolved Security Vulnerabilities Found in Various Document Management Systems

Multiple Vulnerabilities Identified in Document Management Systems Recent findings have highlighted several security vulnerabilities across prominent open-source and freemium Document Management Systems (DMS) offered by four vendors: LogicalDOC, Mayan, ONLYOFFICE, and OpenKM. These unpatched flaws expose organizations to potentially severe cyber threats. Cybersecurity firm Rapid7 has reported eight critical vulnerabilities…

Read MoreUnresolved Security Vulnerabilities Found in Various Document Management Systems

Emerging IoT Botnet Poses a Serious Threat to Internet Stability

A pressing cybersecurity risk has emerged just a year following the notorious Mirai botnet attack, which disrupted numerous Internet services through extensive DDoS attacks. Security researchers are now raising alarms about a new IoT botnet known as “IoT_reaper,” first identified by experts from Qihoo 360. This malware has distinct characteristics,…

Read MoreEmerging IoT Botnet Poses a Serious Threat to Internet Stability