The Breach News

Enhancing OT Security Through AI and Machine Learning

Strengthening Operational Technology Security with AI and Machine Learning As cyber threats targeting operational technology (OT) continue to escalate, organizations are grappling with the imperative of bolstering their cybersecurity measures. A recent article highlights that enhancing protection requires not only smarter threat intelligence but also accelerated capabilities for detection and…

Read MoreEnhancing OT Security Through AI and Machine Learning

Security Vulnerabilities in Leading ML Toolkits Allow for Server Takeovers and Privilege Escalation

Recent cybersecurity research has revealed a significant number of security vulnerabilities affecting nearly two dozen open-source machine learning (ML) projects. The findings, reported by software supply chain security firm JFrog, highlight weaknesses present on both the server and client sides of these technologies. The identified server-side vulnerabilities pose a serious…

Read MoreSecurity Vulnerabilities in Leading ML Toolkits Allow for Server Takeovers and Privilege Escalation

CISA Alerts on Ongoing Exploits Targeting Trimble Cityworks Vulnerability

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued an alert regarding a critical vulnerability in Trimble’s Cityworks software for geographic information systems (GIS). This vulnerability, identified as CVE-2025-0994, is currently under active exploitation, posing significant risk to its users. CVE-2025-0994 carries a CVSS v4 score of 8.6, indicating…

Read MoreCISA Alerts on Ongoing Exploits Targeting Trimble Cityworks Vulnerability

HelloXD Ransomware Deploys Backdoor on Targeted Windows and Linux Systems

A new variant of ransomware known as HelloXD is actively targeting both Windows and Linux systems, alongside deploying a backdoor that allows attackers ongoing remote access to compromised machines. This underscores a concerning trend in ransomware threats, where operators are not only encrypting data but also setting up mechanisms for…

Read MoreHelloXD Ransomware Deploys Backdoor on Targeted Windows and Linux Systems

Researchers Caution Against Privilege Escalation Threats in Google’s Vertex AI ML Platform

Recent cybersecurity findings have revealed two significant vulnerabilities within Google’s Vertex AI machine learning platform. These exploits could be leveraged by malicious entities to escalate user privileges and exfiltrate sensitive models directly from the cloud environment. According to an analysis released by researchers from Palo Alto Networks Unit 42, exploiting…

Read MoreResearchers Caution Against Privilege Escalation Threats in Google’s Vertex AI ML Platform