The Breach News

Increasing Malware Attacks Utilizing Dark Utilities’ C2-as-a-Service

A newly emerging service known as Dark Utilities has gained popularity among cybercriminals, with approximately 3,000 users drawn to its capability to provide command-and-control (C2) services aimed at seizing control of compromised systems. This platform has positioned itself as a “C2-as-a-Service” (C2aaS), marketed for tasks including remote access, command execution,…

Read MoreIncreasing Malware Attacks Utilizing Dark Utilities’ C2-as-a-Service

Hackers Concealed Malware Using Complex AI Code

Artificial Intelligence & Machine Learning, Next-Generation Technologies & Secure Development Attackers Conceal Malware Within Vector Image Rashmi Ramesh (rashmiramesh_) • September 24, 2025 Image: Shutterstock Recent findings indicate that hackers have utilized artificial intelligence-generated code to embed malware in a sophisticated phishing campaign, according to insights from Microsoft. This malware…

Read MoreHackers Concealed Malware Using Complex AI Code

Cloudflare Thwarts Record-Breaking 22.2 Tbps DDoS Attack

Cloudflare has announced the successful mitigation of the largest recorded DDoS (distributed denial-of-service) attack to date, which peaked at an astonishing 22.2 terabits per second and included 10.6 billion packets per second. This unprecedented event was identified and countered automatically by Cloudflare’s robust network infrastructure. Despite its severity, the attack…

Read MoreCloudflare Thwarts Record-Breaking 22.2 Tbps DDoS Attack

When Browser Extensions Turn Sour: Key Insights from the Campaign Against Them

A significant security breach has been reported involving a coordinated attack targeting numerous browser extensions, designed to inject malicious code for the purpose of credential theft. Over 25 browser extensions with a combined user base exceeding two million have been compromised. LayerX, a cybersecurity firm specializing in the protection of…

Read MoreWhen Browser Extensions Turn Sour: Key Insights from the Campaign Against Them

Cyber Insurers Provide Strong Guidance, But Take-Up Rates Need Improvement

As cybersecurity threats become increasingly sophisticated, businesses are increasingly turning to insurers for effective strategies on proactive protection and prevention. Recent findings from Traveler’s latest Risk Index reveal that an impressive 86% of business leaders express confidence in the cybersecurity guidance offered by insurance carriers, surpassing their trust in third-party…

Read MoreCyber Insurers Provide Strong Guidance, But Take-Up Rates Need Improvement

CISA Alerts on Craft CMS Vulnerability CVE-2025-23209 Amid Ongoing Attacks

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has escalated attention to a critical vulnerability affecting the Craft content management system (CMS) by incorporating it into its Known Exploited Vulnerabilities (KEV) catalog. This action is prompted by confirmed instances of active exploitation associated with this flaw. Identified as CVE-2025-23209, this…

Read MoreCISA Alerts on Craft CMS Vulnerability CVE-2025-23209 Amid Ongoing Attacks

Vulnerabilities in Emergency Alert System Could Allow Attackers to Send Fake Messages

The U.S. Department of Homeland Security (DHS) has issued an urgent alert regarding significant security flaws found in Emergency Alert System (EAS) encoder and decoder devices. Such vulnerabilities, if not addressed, may allow malicious entities to generate fake emergency alerts across various broadcasting mediums, including television, radio, and cable networks.…

Read MoreVulnerabilities in Emergency Alert System Could Allow Attackers to Send Fake Messages

Feds Link ‘Scattered Spider’ Pair to $115 Million in Ransom Payments – Krebs on Security

In a significant legal development, U.S. prosecutors recently filed criminal charges against Thalha Jubair, a 19-year-old from the U.K., in connection with his alleged involvement as a central figure in Scattered Spider, a notorious cybercrime organization implicated in extortion schemes totaling over $115 million. These accusations, which emerged as Jubair…

Read MoreFeds Link ‘Scattered Spider’ Pair to $115 Million in Ransom Payments – Krebs on Security

Supermicro Server Motherboards Vulnerable to Permanent Malware Infections

Critical Vulnerabilities Found in Supermicro Motherboards Expose Servers to Exploits Recent security findings have revealed significant vulnerabilities in servers powered by motherboards sold by Supermicro. These high-severity flaws enable attackers to remotely install malicious firmware that operates prior to the system’s operating system, resulting in infections that are challenging to…

Read MoreSupermicro Server Motherboards Vulnerable to Permanent Malware Infections