The Breach News

10 U.S. States Safeguarding 322 Million Internet Users Against $16 Billion in Cybercrime Losses – DesignRush

10 U.S. States Safeguard 322 Million Internet Users Against $16 Billion in Cybercrime Losses Recent reports highlight significant advancements made by ten U.S. states in their initiative to protect approximately 322 million Internet users from overwhelming cybercrime losses, which have accumulated to an estimated $16 billion. This initiative showcases a…

Read More10 U.S. States Safeguarding 322 Million Internet Users Against $16 Billion in Cybercrime Losses – DesignRush

Critical Update: Microsoft Addresses 57 Security Vulnerabilities, 6 of Which Are Actively Exploited Zero-Days

On Tuesday, Microsoft rolled out security updates addressing a total of 57 vulnerabilities, including six that have been actively exploited in the wild. These updates are particularly crucial for organizations concerned about potential security breaches, as they rectify flaws that could be leveraged by malicious actors. Among the 57 identified…

Read MoreCritical Update: Microsoft Addresses 57 Security Vulnerabilities, 6 of Which Are Actively Exploited Zero-Days

Zero-Day RCE Vulnerability in Sophos Firewall Exploited by Hackers — Patch Now Available

In a significant cybersecurity development, Sophos has issued a critical patch for its firewall product following the discovery of a severe zero-day vulnerability actively being exploited by cyber attackers. This vulnerability has raised serious concerns for users, as it could lead to unauthorized remote code execution. The issue, identified as…

Read MoreZero-Day RCE Vulnerability in Sophos Firewall Exploited by Hackers — Patch Now Available

FileFix Campaign Leverages Facebook Suspension as Hook

Fraud Management & Cybercrime, Social Engineering Malware Dissemination Tied to FileFix Campaign Targeting Facebook Users Pooja Tikekar (@PoojaTikekar) • September 18, 2025 A malicious command is embedded in a deceptive upload window. (Image: Acronis/ISMG) A new social engineering operation, dubbed FileFix, has emerged, employing sophisticated techniques to persuade users into…

Read MoreFileFix Campaign Leverages Facebook Suspension as Hook

This Microsoft Entra ID Vulnerability Posed a Major Threat

Major Security Flaw Discovered in Microsoft Azure’s Identity Management System Over the past decade, a significant transition has occurred in how businesses manage their digital infrastructures, shifting from self-hosted servers to cloud services. This change has allowed many organizations to benefit from the advanced security features offered by key cloud…

Read MoreThis Microsoft Entra ID Vulnerability Posed a Major Threat

JavaScript Cross-Platform Malware Targets Crypto Wallets in Latest Lazarus Group Operation

A new cyber threat attributed to the North Korea-linked Lazarus Group has surfaced, where attackers exploit fake LinkedIn job offers in the cryptocurrency and travel sectors to deliver malicious software. This campaign targets operating systems across the board, including Windows, macOS, and Linux. According to cybersecurity firm Bitdefender, the operation…

Read MoreJavaScript Cross-Platform Malware Targets Crypto Wallets in Latest Lazarus Group Operation

FSC to Implement Fines for Security Breaches Following Lotte Card Hack

Financial Services Commission Vice Chairman Kwon Dae-young speaks during a joint press briefing with the Ministry of Science and ICT at the government complex in Jongno District, central Seoul, on Sept. 19. [YONHAP] The Financial Services Commission (FSC) of South Korea has unveiled plans to implement punitive fines for security…

Read MoreFSC to Implement Fines for Security Breaches Following Lotte Card Hack

Pentesters: Is AI Taking Over Your Job?

AI’s Impact on the Future of Penetration Testing: A New Era of Collaboration and Efficiency For years, discussions around artificial intelligence (AI) positing that it threatens job security, particularly in sectors like cybersecurity, have generated considerable anxiety. A notable report from McKinsey in 2017 warned that by 2030, around 375…

Read MorePentesters: Is AI Taking Over Your Job?

Researchers Uncover Three Hacktivist Groups Advocating for Russian Interests

According to Mandiant, at least three alleged hacktivist groups purportedly aligned with Russian interests are believed to collaborate with state-sponsored cyber operatives. Mandiant, a Google-affiliated cybersecurity firm, has reported with moderate confidence that key figures behind the hacktivist Telegram channels such as ‘XakNet Team,’ ‘Infoccentr,’ and ‘CyberArmyofRussia_Reborn’ are likely coordinating…

Read MoreResearchers Uncover Three Hacktivist Groups Advocating for Russian Interests