The Breach News

Bots Disrupt Identity: Trust in Crisis

Agentic AI, Artificial Intelligence & Machine Learning, Identity & Access Management Durand: Agentic Models Demand Enhanced Verification and Advanced Access Controls Michael Novinson (MichaelNovinson) • September 12, 2025 Andre Durand, founder and CEO of Ping Identity (Image: Ping Identity) The increasing weaponization of trust by malicious actors is compelling businesses…

Read MoreBots Disrupt Identity: Trust in Crisis

Over 12,000 API Keys and Passwords Discovered in Public Datasets for LLM Training

A recent investigation has uncovered alarming findings regarding a dataset utilized for training large language models (LLMs). This dataset reportedly contains close to 12,000 live secrets, including credentials capable of authenticating access to various services. This discovery raises significant concerns about the risks associated with hard-coded credentials. Organizations face heightened…

Read MoreOver 12,000 API Keys and Passwords Discovered in Public Datasets for LLM Training

NetApp SnapCenter Vulnerability May Allow Remote Admin Access for Users on Plug-In Systems

NetApp SnapCenter has revealed a significant security vulnerability that poses a considerable risk of privilege escalation if exploited. SnapCenter is an enterprise-grade solution employed for the management of data protection across various applications, databases, virtual machines, and file systems. It provides functionalities for backing up, restoring, and cloning data resources,…

Read MoreNetApp SnapCenter Vulnerability May Allow Remote Admin Access for Users on Plug-In Systems

Finnish Vastaamo Hacker Released While Contesting Conviction

Cybercrime, Fraud Management & Cybercrime Vastaamo Hacker Aleksanteri Kivimäki Released While Awaiting Appeal Akshaya Asokan (asokan_akshaya) • September 12, 2025 Aleksanteri Kivimäki in a Finnish courtroom on February 28, 2023 A Helsinki court has ordered the release of one of Finland’s most infamous hackers, Aleksanteri Tomminpoika Kivimäki, pending the outcome…

Read MoreFinnish Vastaamo Hacker Released While Contesting Conviction

Edelson Lechtzin LLP Launches Investigation into Data Breach Claims

Fairmont Federal Credit Union Faces Data Breach Investigation by Edelson Lechtzin LLP FAIRMONT, W.Va., September 12, 2025 — Edelson Lechtzin LLP, a prominent national class-action law firm based in suburban Philadelphia, is currently investigating reported data privacy violations stemming from a breach at Fairmont Federal Credit Union (FFCU). The credit…

Read MoreEdelson Lechtzin LLP Launches Investigation into Data Breach Claims

CISA Issues Warning on Sitecore RCE Vulnerabilities; Active Exploits Target Next.js and DrayTek Devices

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has officially incorporated two significant six-year-old vulnerabilities affecting the Sitecore Content Management System and Experience Platform into its Known Exploited Vulnerabilities (KEV) catalog. This addition follows credible evidence indicating that these flaws are being actively targeted by malicious actors. The first vulnerability,…

Read MoreCISA Issues Warning on Sitecore RCE Vulnerabilities; Active Exploits Target Next.js and DrayTek Devices

Zerobot Botnet Surges as a Rising Threat with Enhanced Exploits and Features

The Zerobot DDoS botnet has undergone significant updates, enhancing its capacity to target a broader range of internet-connected devices and expand its network. Microsoft Threat Intelligence Center (MSTIC) is closely monitoring this evolving threat, referring to it as DEV-1061, which encompasses unidentified, emerging, or developing activity clusters. First reported by…

Read MoreZerobot Botnet Surges as a Rising Threat with Enhanced Exploits and Features