The Breach News

Check Point Alerts on Zero-Day Vulnerabilities Affecting Its VPN Gateway Solutions

Check Point has issued a warning regarding a critical zero-day vulnerability affecting its Network Security gateway products, which has already been exploited by cybercriminals in the wild. The vulnerability, designated as CVE-2024-24919 and carrying a CVSS score of 8.6, affects numerous products including CloudGuard Network, Quantum Maestro, Quantum Scalable Chassis,…

Read MoreCheck Point Alerts on Zero-Day Vulnerabilities Affecting Its VPN Gateway Solutions

Fidelity Experiences Its Second Data Breach This Year

Cybersecurity Alert: Fidelity International Reports Customer Data Breach Fidelity International, a leading multinational financial services firm headquartered in the United States, has issued a warning regarding a potential cyber attack that may have impacted some of its customers. The incident involved an unauthorized breach of Fidelity’s databases by an unidentified…

Read MoreFidelity Experiences Its Second Data Breach This Year

Star Health Data Breach: Options for Affected Policyholders

Star Health and Allied Insurance has recently faced a significant data breach, following a severe hacking incident that compromised the sensitive personal information of approximately 31 million customers. A hacker operating under the pseudonym “xenZen” created a website and utilized Telegram chatbots to expose private data, which included names, phone…

Read MoreStar Health Data Breach: Options for Affected Policyholders

CISA Issues Warning About Hackers Targeting Outdated Cisco Smart Install Functionality

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has reported that threat actors are actively exploiting the outdated Cisco Smart Install feature to compromise sensitive data systems. This legacy technology has become a target due to its vulnerabilities, allowing adversaries to obtain critical system configuration files through various device protocols…

Read MoreCISA Issues Warning About Hackers Targeting Outdated Cisco Smart Install Functionality

Nokia Highlights Cybersecurity Risks in the Telecom Industry

Recent findings published in the Nokia Threat Intelligence Report reveal a troubling increase in vulnerabilities facing the global telecommunications industry, with a particular emphasis on North America. The incorporation of Generative AI (GenAI) and automated strategies by cybercriminals is significantly intensifying these threats, leading to heightened risks for telecom operators.…

Read MoreNokia Highlights Cybersecurity Risks in the Telecom Industry

Unsupported Browser Detected

News Article: Cybersecurity Incident Report: Recent Data Breach Affecting Business Owners In a significant cybersecurity incident recently disclosed, a major corporation has fallen victim to a sophisticated attack, compromising sensitive information and potentially jeopardizing the security of its clients. The incident underscores the growing threats that businesses within the tech…

Read MoreUnsupported Browser Detected

Mysterious Cyber Attack Disrupts Over 600,000 Routers Across the U.S.

Recent reports indicate that over 600,000 small office/home office (SOHO) routers have been disabled following a severe cyber attack attributed to unknown malicious actors, significantly disrupting internet access for users. This incident is particularly noteworthy for its scale and implications on cybersecurity infrastructure. The attack, which has been labeled Pumpkin…

Read MoreMysterious Cyber Attack Disrupts Over 600,000 Routers Across the U.S.

“77,000 Fidelity Customer Records Compromised in August Data Breach” • The Register

Data Breach at Fidelity Investments Affects Over 77,000 Customers Fidelity Investments has reported that a data breach occurring in August has compromised the personal information of approximately 77,099 individuals. While specific details regarding the type of data accessed by the attackers remain undisclosed, the firm has reassured customers that their…

Read More“77,000 Fidelity Customer Records Compromised in August Data Breach” • The Register

Microsoft Uncovers Four OpenVPN Vulnerabilities Paving the Way for Potential RCE and LPE Attacks

OpenVPN Vulnerabilities Disclosed by Microsoft: A Potential Attack Vector Microsoft recently announced the discovery of four medium-severity security vulnerabilities within the open-source OpenVPN software, which could be exploited in conjunction to enable remote code execution (RCE) and local privilege escalation (LPE). The implications of these flaws are significant, as they…

Read MoreMicrosoft Uncovers Four OpenVPN Vulnerabilities Paving the Way for Potential RCE and LPE Attacks