The Breach News

SocGholish Malware Takes Advantage of BOINC Project for Hidden Cyberattacks

Emerging Threat: SocGholish Malware Exploits BOINC for Malicious Activities The cybersecurity landscape has recently encountered a troubling update regarding the behavior of the JavaScript downloader malware known as SocGholish (also referred to as FakeUpdates), further exacerbating existing risks for businesses reliant on digital operations. This malware has evolved to deliver…

Read MoreSocGholish Malware Takes Advantage of BOINC Project for Hidden Cyberattacks

Palo Alto Networks Issues Critical Patches for Exploited PAN-OS Vulnerability

Palo Alto Networks has issued urgent hotfixes in response to a critical security vulnerability affecting its PAN-OS software that is currently being exploited in live environments. This vulnerability, identified as CVE-2024-3400, has received the highest severity rating with a CVSS score of 10.0. It involves a command injection flaw within…

Read MorePalo Alto Networks Issues Critical Patches for Exploited PAN-OS Vulnerability

Millions of Users Turn to Abusive AI ‘Nudify’ Bots on Telegram

In recent discussions on the handling of intimate images online, Kate Ruane, director of the Center for Democracy and Technology’s free expression project, highlighted the growing recognition among major technology platforms regarding the need for policies against nonconsensual distribution of intimate content. Yet, she emphasizes ambiguity in Telegram’s terms of…

Read MoreMillions of Users Turn to Abusive AI ‘Nudify’ Bots on Telegram

ICO Fines Mermaids Transgender Charity for Breach of Data Protection, Exposing Sensitive Personal Information

A data breach incident involving the UK-based transgender charity Mermaids has attracted significant attention after the Information Commissioner’s Office (ICO) issued a £25,000 fine. The breach occurred due to the charity’s internal email group, which was established several years ago with inadequate security settings, leading to the exposure of hundreds…

Read MoreICO Fines Mermaids Transgender Charity for Breach of Data Protection, Exposing Sensitive Personal Information

THN Cybersecurity Highlights: Key Threats and Trends (Sept 30 – Oct 6)

Cybersecurity Weekly Recap: Takedowns, DDoS Attacks, and Emerging Threats The realm of cybersecurity continues to evolve with alarming speed, as evidenced by the latest developments in the threat landscape. One significant topic this week is the prevalence of "pig butchering" scams, alongside impactful government interventions and a staggering array of…

Read MoreTHN Cybersecurity Highlights: Key Threats and Trends (Sept 30 – Oct 6)

Chinese Hackers Attack Taiwan and U.S. NGOs Using MgBot and MACMA Malware

A Beijing-linked state-sponsored hacking group known as Daggerfly has targeted organizations in Taiwan and a U.S. non-governmental organization (NGO) operating in China, deploying an upgraded suite of malware tools in its most recent campaign. This sophisticated operation highlights the group’s engagement in internal espionage activities, as reported today by Symantec’s…

Read MoreChinese Hackers Attack Taiwan and U.S. NGOs Using MgBot and MACMA Malware

Russian APT Unleashes New ‘Kapeka’ Backdoor in Attacks Across Eastern Europe

A newly identified backdoor malware known as Kapeka has been linked to ongoing cyberattacks targeting Eastern European nations, particularly Estonia and Ukraine, since at least mid-2022. This flexible backdoor is believed to be associated with the Russian advanced persistent threat (APT) group Sandworm, a faction also referred to as APT44…

Read MoreRussian APT Unleashes New ‘Kapeka’ Backdoor in Attacks Across Eastern Europe