The Breach News

Mitigating Memcached DDoS Attacks: Activate the Kill Switch and Flush Everything

Security researchers have unveiled a significant breakthrough in combating Distributed Denial of Service (DDoS) attacks that exploit vulnerable Memcached servers. Dubbed a “kill switch,” this mechanism could offer protection for businesses facing overwhelming cyber assaults. Memcached reflection DDoS attacks have surged recently, characterized by a staggering amplification factor that can…

Read MoreMitigating Memcached DDoS Attacks: Activate the Kill Switch and Flush Everything

Alert: Three Widely Used VPN Services Exposing Your IP Address

Recent investigations have identified severe vulnerabilities in three widely-used VPN services that could expose users’ actual IP addresses and other sensitive information. Virtual Private Networks (VPNs) are typically employed to safeguard online activities through data encryption, enhance security, and obscure users’ real IP addresses. Many users opt for VPNs to…

Read MoreAlert: Three Widely Used VPN Services Exposing Your IP Address

EU Politicians Probe Pegasus Spyware, Only to Find It on One of Their Own Devices

The recent findings from Citizen Lab reveal a troubling instance of Pegasus spyware being deployed against Greek Member of the European Parliament (MEP), Alexis Kouloglou. Although the research did not point to any particular government being responsible for the attack, it explicitly noted a lack of evidence regarding the involvement…

Read MoreEU Politicians Probe Pegasus Spyware, Only to Find It on One of Their Own Devices

AMD Recognizes Recently Revealed Vulnerabilities in Its Processors — Fixes on the Way

AMD has officially acknowledged the discovery of 13 critical vulnerabilities and exploitable backdoors affecting its Ryzen and EPYC processors. This disclosure follows a report by Israel-based CTS Labs and comes with a commitment from AMD to release firmware updates for millions of impacted devices within weeks. Research from CTS Labs…

Read MoreAMD Recognizes Recently Revealed Vulnerabilities in Its Processors — Fixes on the Way

Newly Discovered PamStealer: A Unique Threat in the macOS Malware Landscape

Researchers have uncovered a sophisticated piece of macOS malware that utilizes innovative techniques to stealthily infect Macs and steal user credentials. This malware, dubbed PamStealer, is a testament to the evolving landscape of cyber threats targeting businesses and individual users alike. PamStealer employs a two-stage infection process. Initially, it is…

Read MoreNewly Discovered PamStealer: A Unique Threat in the macOS Malware Landscape

Urgent: Remote Execution Vulnerability in Spring Framework Apps — Update Immediately

New Vulnerabilities Discovered in Spring Framework Pose Significant Cybersecurity Risks Recent investigations have unveiled three vulnerabilities within the Spring Development Framework, which is widely used for designing Java-based enterprise applications. Among these, one critical flaw, identified as a remote code execution vulnerability, enables remote attackers to potentially execute arbitrary code…

Read MoreUrgent: Remote Execution Vulnerability in Spring Framework Apps — Update Immediately

Sysdig Unveils JADEPUFFER: The First Documented Agentic Ransomware Operation

A recent cybersecurity incident has illustrated the escalating sophistication of automated attacks. An advanced language model (LLM) agent exploited a vulnerability in Langflow, leading to significant credential harvesting and subsequent destruction of configuration data in a production database. Cybersecurity experts from Sysdig have reported a case where traditional human intervention…

Read MoreSysdig Unveils JADEPUFFER: The First Documented Agentic Ransomware Operation

Authentication Bypass Flaw Discovered in Auth0 Identity Platform

Auth0 Faces Critical Authentication Bypass Vulnerability A significant vulnerability has emerged in Auth0, a leading identity-as-a-service platform known for offering token-based authentication solutions. This flaw could potentially enable malicious actors to gain unauthorized access to applications utilizing Auth0’s services for user authentication. Given Auth0’s extensive reach, with over 2,000 enterprise…

Read MoreAuthentication Bypass Flaw Discovered in Auth0 Identity Platform