The Breach News

Envoy, an American Airlines Subsidiary, Targeted in Oracle Cyberattack

Envoy Air, a fully owned subsidiary of American Airlines, has confirmed it has been targeted in a cyber attack that compromised vulnerabilities within Oracle’s E-Business Suite (EBS). This incident highlights a pressing concern regarding the cybersecurity posture of enterprise software within the aviation industry. The breach came to light through…

Read MoreEnvoy, an American Airlines Subsidiary, Targeted in Oracle Cyberattack

Microsoft Addresses 72 Vulnerabilities, Including a Patch for Actively Exploited CLFS Issue

Microsoft Wraps Up 2024 Patch Tuesday with Critical Security Fixes Microsoft concluded its Patch Tuesday updates for December 2024, addressing a total of 72 security vulnerabilities across its software ecosystem, including a specific flaw reported as actively exploited in the wild. Of these vulnerabilities, 17 have been classified as Critical,…

Read MoreMicrosoft Addresses 72 Vulnerabilities, Including a Patch for Actively Exploited CLFS Issue

Experts Uncover Backdoor Installed in U.S. Federal Agency Network

Backdoor Compromise Targets U.S. Federal Government Entity in APT-Style Attack A federal U.S. commission linked to international rights has suffered a significant security breach, as revealed by researchers who characterized the incident as a “classic APT-type operation.” The attack reportedly infiltrated the commission’s internal network through a backdoor, potentially compromising…

Read MoreExperts Uncover Backdoor Installed in U.S. Federal Agency Network

Hackers Expose Personal Information of ICE, DHS, DOJ, and FBI Officials

markdown In a groundbreaking revelation, researchers from UC San Diego and the University of Maryland have uncovered alarming vulnerabilities in satellite communications this week. Their study highlights that various sensitive data—including T-Mobile calls, text messages, in-flight Wi-Fi browsing sessions, and military communications—are being transmitted without encryption, potentially exposing them to…

Read MoreHackers Expose Personal Information of ICE, DHS, DOJ, and FBI Officials

D-Link Verifies Data Breach: Employee Targeted by Phishing Attack

Data Breach at D-Link Exposes Legacy Information D-Link, a Taiwanese manufacturer specializing in networking equipment, has acknowledged a data breach that resulted in the exposure of information considered to be “low-sensitivity and semi-public.” The company clarified that the compromised data was not sourced from its cloud systems but rather likely…

Read MoreD-Link Verifies Data Breach: Employee Targeted by Phishing Attack

Rising Cross-Border Phishing Attacks Sweep Across Asia

Cyberwarfare / Nation-State Attacks, Fraud Management & Cybercrime Phishing Campaigns Transition from China to Malaysia Targeting Chinese-Speakers Prajeet Nair ( @prajeetspeaks) • October 17, 2025 Image: Shutterstock Recent investigations reveal that a series of coordinated cyberattacks targeting Chinese-speaking individuals across the Asia-Pacific region can be traced back to a single…

Read MoreRising Cross-Border Phishing Attacks Sweep Across Asia

Vietnam’s Struggles with Personal Data Protection in the Digital Era

With Vietnam rapidly advancing its digital transformation, the safeguarding of personal data has emerged as a significant national challenge. The ongoing digital transformation, coupled with economic modernization and the emergence of a digital society, is fundamentally altering Vietnam’s future trajectory. Central to this shift is personal data, a vital asset…

Read MoreVietnam’s Struggles with Personal Data Protection in the Digital Era

Microsoft MFA AuthQuake Vulnerability Allowed Unlimited Brute-Force Attempts Without Notifications

Critical Vulnerability Discovered in Microsoft MFA Implementation Cybersecurity experts have uncovered a significant security flaw in Microsoft’s multi-factor authentication (MFA) system that could allow attackers to easily bypass protection mechanisms and gain unauthorized access to user accounts. This vulnerability was classified as “critical” by researchers from Oasis Security, who highlighted…

Read MoreMicrosoft MFA AuthQuake Vulnerability Allowed Unlimited Brute-Force Attempts Without Notifications

CISA Compliance Guide for 2022

In recent years, the frequency and severity of cyberattacks have escalated dramatically, underscoring a pressing concern for organizations worldwide. A glance at the CISA list of significant cyber incidents reveals the alarming scale of these attacks. A notable instance occurred in May 2021 when a ransomware assault on Colonial Pipeline…

Read MoreCISA Compliance Guide for 2022