The Breach News

FBI Chief Kash Patel’s Clothing Store Targeted in ClickFix Infostealer Breach

An online clothing store affiliated with FBI Director Kash Patel was taken offline on Friday following the discovery that it was facilitating the spread of an Infostealer malware to its visitors. The site, known as Based Apparel, had been compromised by hackers who targeted macOS users, tricking them into downloading…

Read MoreFBI Chief Kash Patel’s Clothing Store Targeted in ClickFix Infostealer Breach

Docker CVE-2026-34040: How Attackers Can Bypass Authorization to Gain Host Access

A significant security vulnerability has been uncovered in Docker Engine that may allow attackers to circumvent authorization plugins under certain circumstances. This issue is assigned the identifier CVE-2026-34040, with a critical CVSS score of 8.8. The flaw arises from an incomplete resolution of CVE-2024-41110, which was a severe vulnerability discovered…

Read MoreDocker CVE-2026-34040: How Attackers Can Bypass Authorization to Gain Host Access

Critical Vulnerabilities Identified in VxWorks RTOS, Impacting Over 2 Billion Devices

Security researchers have identified multiple zero-day vulnerabilities, collectively named URGENT/11, within VxWorks, a prevalent real-time operating system (RTOS) embedded in over 2 billion devices across various sectors, including aerospace, medical, and industrial applications. This newly uncovered threat poses significant risk, especially given that six of the eleven vulnerabilities are classified…

Read MoreCritical Vulnerabilities Identified in VxWorks RTOS, Impacting Over 2 Billion Devices

The Rise of AI: Fueling a Competitive Race in Bug Hunting

Rising Challenges in the Bug Bounty Landscape: Trends and Implications Organizations across the tech landscape are grappling with the increasing threat posed by both nation-state and criminal actors, as highlighted by cybersecurity expert Hultquist. While nation-state concerns are indeed significant, it is criminal activity that comprises the majority of incidents…

Read MoreThe Rise of AI: Fueling a Competitive Race in Bug Hunting

OpenAI Cancels macOS App Certificate Following Malicious Axios Supply Chain Attack

OpenAI Discloses Compromise in macOS App Signing Workflow OpenAI has issued a statement regarding a significant security incident that occurred on March 31, revealing that a GitHub Actions workflow tied to the signing of its macOS applications inadvertently downloaded a malicious Axios library. Fortunately, the company has confirmed that this…

Read MoreOpenAI Cancels macOS App Certificate Following Malicious Axios Supply Chain Attack

DHS Alerts: Small Aircraft at Risk of Flight Data Manipulation Attacks

A recent cybersecurity investigation has unveiled a significant vulnerability in small aircraft that allows potential hackers to manipulate the plane’s electronic systems, raising serious safety concerns. The risks associated with this vulnerability include the alarming possibility of hackers tricking a plane’s electronic systems into displaying inaccurate flight data to pilots,…

Read MoreDHS Alerts: Small Aircraft at Risk of Flight Data Manipulation Attacks