The Breach News

Ledger Users Targeted by Phishing Scam Following Global-e Data Breach that Exposed Order Details

Targeted Phishing Campaign Hits Ledger Users Following Global-e Breach A new phishing campaign is currently targeting users of Ledger, the leading hardware wallet provider, following a significant data breach at Global-e, a third-party e-commerce company associated with Ledger. The attack appears to have exploited sensitive order data that was leaked,…

Read MoreLedger Users Targeted by Phishing Scam Following Global-e Data Breach that Exposed Order Details

Atlassian Confluence Targeted by Actively Exploited Zero-Day Vulnerability – Immediate Patch Required

Atlassian has announced critical updates to address a severe zero-day vulnerability impacting publicly available Confluence Data Center and Server instances. The flaw, identified as CVE-2023-22515, poses a significant security risk as it can be exploited remotely by attackers to create unauthorized administrator accounts, consequently allowing access to Confluence servers. This…

Read MoreAtlassian Confluence Targeted by Actively Exploited Zero-Day Vulnerability – Immediate Patch Required

43 Million Weebly Accounts Compromised; Foursquare Also Affected by Data Breach

In a significant escalation of cybersecurity threats, 2016 has emerged as a watershed year for data breaches, impacting numerous high-profile companies and compromising over a billion user accounts globally. Most recently, Weebly and Foursquare fell prey to these cyber incidents, joining a grim list of organizations affected by massive data…

Read More43 Million Weebly Accounts Compromised; Foursquare Also Affected by Data Breach

FCC Withdraws Key Backing for Biden Administration’s IoT Security Labeling Initiative

Endpoint Security, Governance & Risk Management, Internet of Things Security FCC Lacks Leadership for Cyber Trust Mark Program Following UL Solutions’ Withdrawal Chris Riotta (@chrisriotta) • January 6, 2026 The recent withdrawal of the FCC’s lead administrator for its consumer cybersecurity labeling initiative raises significant questions about the future of…

Read MoreFCC Withdraws Key Backing for Biden Administration’s IoT Security Labeling Initiative

Crypto Hardware Wallet Producer Ledger Affected by Third-Party Data Breach

Ledger, the prominent provider of crypto hardware wallets, has reported a security breach involving its third-party payment processor, Global-e. This incident has led to the exposure of customer names and contact details. Although the exact number of affected customers remains undisclosed, it’s important to clarify that this breach did not…

Read MoreCrypto Hardware Wallet Producer Ledger Affected by Third-Party Data Breach

Apple Releases Security Updates to Address Actively Exploited iOS Zero-Day Vulnerability

On Wednesday, Apple released critical security updates aimed at mitigating a recently identified zero-day vulnerability in both iOS and iPadOS. This flaw, designated as CVE-2023-42824, is reportedly being exploited in the wild, raising alarm for users and businesses alike. The vulnerability exists within the kernel and can be exploited by…

Read MoreApple Releases Security Updates to Address Actively Exploited iOS Zero-Day Vulnerability

Russian Hacker Linked to LinkedIn Breach Also Charged with Hacking Dropbox and Formspring

A recent indictment by U.S. authorities has identified 29-year-old Russian national Yevgeniy Aleksandrovich Nikulin as the perpetrator behind significant data breaches affecting LinkedIn, Dropbox, and the now-defunct social network Formspring. This announcement follows the successful arrest of Nikulin by the FBI, in coordination with Czech law enforcement, on October 5…

Read MoreRussian Hacker Linked to LinkedIn Breach Also Charged with Hacking Dropbox and Formspring