The Breach News

Report Unveils Average Cost of Data Breaches for Companies: $677 Million

Data Breaches Impose Heavy Financial Costs on Companies, New Report Reveals ExtraHop®, a frontrunner in cloud-native network detection and response (NDR), has unveiled a report illustrating the staggering financial implications of significant data breaches on publicly traded companies. The analysis indicates that organizations typically incur an average loss of approximately…

Read MoreReport Unveils Average Cost of Data Breaches for Companies: $677 Million

China-Based Hackers Exploited ROOTROT Webshell in MITRE Network Breach

The recent cyber incident involving the MITRE Corporation has shed light on the intricacies of the attack, with the earliest signs of compromise identified as far back as December 31, 2023. This breach, which came to public attention in April 2024, specifically targeted MITRE’s Networked Experimentation, Research, and Virtualization Environment…

Read MoreChina-Based Hackers Exploited ROOTROT Webshell in MITRE Network Breach

New XLoader macOS Malware Variant Masquerades as ‘OfficeNote’ Productivity Application

A newly identified variant of Apple macOS malware, known as XLoader, has been discovered in the wild, cleverly disguised as a productivity application named “OfficeNote.” This development raises significant concerns for users in professional environments, as the malware specifically targets sensitive information. The exploit utilizes a password-protected disk image labeled…

Read MoreNew XLoader macOS Malware Variant Masquerades as ‘OfficeNote’ Productivity Application

Global Law Enforcement Operation Targets 22,000 Malicious IP Addresses

International Police Coalition Targets Cybercrime Networks In a significant crackdown on cybercriminal activities, an international coalition of law enforcement agencies has successfully disrupted a variety of online scams, including phishing attempts, credential theft, and ransomware distribution. This operation, known as Synergia II, was spearheaded by Interpol and spanned from early…

Read MoreGlobal Law Enforcement Operation Targets 22,000 Malicious IP Addresses

New Malware “ToxicPanda” Emerges, Aiming to Steal Banking Information from Android Devices

The recent emergence of the malware known as ToxicPanda has raised alarms particularly among Android users. This malicious software, which is primarily aimed at extracting sensitive financial information, notably bank account details, has garnered attention for its deceptive tactics. ToxicPanda masquerades as legitimate applications, making it challenging for users to…

Read MoreNew Malware “ToxicPanda” Emerges, Aiming to Steal Banking Information from Android Devices

Serious Security Vulnerability Discovered in Widely Used LayerSlider WordPress Plugin

A significant security vulnerability has been identified in the LayerSlider plugin for WordPress, posing a serious risk of unauthorized data exposure. This flaw, known as CVE-2024-2879, has been assigned a critical CVSS score of 9.8, indicating its severity. The vulnerability allows unauthenticated attackers to leverage SQL injection techniques to potentially…

Read MoreSerious Security Vulnerability Discovered in Widely Used LayerSlider WordPress Plugin

Hackers Leverage LiteSpeed Cache Vulnerability to Take Full Control of WordPress Sites

A vulnerability classified as high-severity has been discovered in the LiteSpeed Cache plugin for WordPress, which is currently being exploited by cybercriminals to forge unauthorized administrator accounts on affected websites. This alert originated from WPScan, which detailed that the flaw, identified as CVE-2023-40000 with a CVSS score of 8.3, is…

Read MoreHackers Leverage LiteSpeed Cache Vulnerability to Take Full Control of WordPress Sites