The Breach News

Google OAuth Flaw Exposes Millions Through Unsecured Startup Domains

Recent investigations have unveiled a serious vulnerability within Google’s “Sign in with Google” authentication system, which can be exploited through a peculiar loophole in domain ownership. This flaw potentially allows unauthorized users to access sensitive data associated with former employees of defunct companies. Dylan Ayrey, co-founder and CEO of Truffle…

Read MoreGoogle OAuth Flaw Exposes Millions Through Unsecured Startup Domains

Stellantis, Manufacturer of Citroën, FIAT, Jeep, and More, Confirms Data Breach

Stellantis, the multinational automotive corporation behind brands such as Citroën, FIAT, Jeep, Chrysler, and Peugeot, has disclosed a data breach impacting its North American customers. This incident highlights significant vulnerabilities in third-party service provider networks associated with customer service operations. On Sunday, Stellantis reported the detection of unauthorized access to…

Read MoreStellantis, Manufacturer of Citroën, FIAT, Jeep, and More, Confirms Data Breach

Hackers Leverage Vulnerability in Paragon Partition Manager Driver for Ransomware Attacks

Recent investigations have unveiled that cybercriminals have exploited a critical vulnerability in the BioNTdrv.sys driver of Paragon Partition Manager, leveraging it in ransomware attacks to escalate privileges and execute unauthorized code. This significant zero-day vulnerability, classified as CVE-2025-0289, is part of a broader set of five vulnerabilities identified by Microsoft…

Read MoreHackers Leverage Vulnerability in Paragon Partition Manager Driver for Ransomware Attacks

Chinese Hackers Compromise MiMi Chat App to Target Windows, Linux, and macOS Users

Recent investigations by cybersecurity firms SEKOIA and Trend Micro have uncovered a new campaign led by the Chinese threat actor known as Lucky Mouse. This operation involves deploying a compromised version of the MiMi chat application, which serves as a vector for backdoor attacks on systems across multiple platforms. The…

Read MoreChinese Hackers Compromise MiMi Chat App to Target Windows, Linux, and macOS Users

Study Reveals 1.2 Million Medical Devices Vulnerable Online

Recent revelations highlight a critical vulnerability within the healthcare sector, where millions of medical devices are at risk due to inadequate security measures, including default credentials and weak passwords. Soufian El Yadmani, CEO and co-founder of Modat, shared insights from recent research indicating that these security misconfigurations expose sensitive medical…

Read MoreStudy Reveals 1.2 Million Medical Devices Vulnerable Online

Google’s March 2025 Android Security Update Addresses Two Actively Exploited Vulnerabilities

Google has published its March 2025 Android Security Bulletin, addressing a staggering total of 44 vulnerabilities. Among these, two high-severity vulnerabilities have been flagged as actively exploited in real-world settings. This ongoing risk emphasizes the necessity for business owners to maintain vigilance in their cybersecurity posture. The first vulnerability, identified…

Read MoreGoogle’s March 2025 Android Security Update Addresses Two Actively Exploited Vulnerabilities