The Breach News

Attackers Take Advantage of Sitecore Zero-Day Vulnerability

Encryption & Key Management, Security Operations Mandiant Uncovers Significant Vulnerability in Sitecore Products Prajeet Nair (@prajeetspeaks) • September 4, 2025 Image: Shutterstock Cybercriminals have exploited a recently patched zero-day vulnerability within Sitecore, a widely used content management system supporting numerous major enterprises, including HSBC, L’Oréal, Toyota, and United Airlines. Sitecore…

Read MoreAttackers Take Advantage of Sitecore Zero-Day Vulnerability

Hackers Deploy E-Crime Tool Atlantis AIO for Credential Stuffing Across Over 140 Platforms

A recent analysis by Abnormal Security has unveiled the exploitation of a sophisticated e-crime tool known as Atlantis AIO Multi-Checker for conducting credential stuffing attacks. This tool significantly enhances the efficiency of cybercriminals, allowing them to test vast quantities of stolen credentials in quick succession. Credential stuffing attacks occur when…

Read MoreHackers Deploy E-Crime Tool Atlantis AIO for Credential Stuffing Across Over 140 Platforms

The Importance of Integrating Threat Hunting into Every Security Program – Dark Reading

Why Threat Hunting Should Be Integral to Every Security Program In an era marked by increasing cyber threats, the necessity of incorporating threat hunting into security strategies has become increasingly clear. Recent discussions within the cybersecurity community underscore the importance of this proactive approach, which aims to identify and mitigate…

Read MoreThe Importance of Integrating Threat Hunting into Every Security Program – Dark Reading

DslogdRAT Malware Exploits Ivanti ICS Zero-Day CVE-2025-0282 in Cyber Attacks in Japan

Recent reports have highlighted the emergence of a sophisticated malware strain known as DslogdRAT, which exploits a recently patched vulnerability in Ivanti Connect Secure (ICS). This vulnerability, tracked as CVE-2025-0282, was initially leveraged by cybercriminals against organizations in Japan in December 2024. It enabled attackers to install both the malware…

Read MoreDslogdRAT Malware Exploits Ivanti ICS Zero-Day CVE-2025-0282 in Cyber Attacks in Japan

Experts Caution About RambleOn Android Malware Aiming at South Korean Journalists

Recent investigations reveal a sophisticated malware campaign allegedly orchestrated by North Korean state-sponsored actors targeting a journalist in South Korea. The malware, identified as RambleOn by the South Korean non-profit organization Interlab, appears to be part of a broader social engineering strategy aimed at gathering sensitive information. The spyware masquerades…

Read MoreExperts Caution About RambleOn Android Malware Aiming at South Korean Journalists

Microsoft Supports Sola’s $35M Investment in Autonomous AI Security

Series A Accelerates AI Development, Integration Expansion, and Product-Led Growth Strategy Michael Novinson (MichaelNovinson) • September 4, 2025 Sola Security CEO Guy Flechter and COO Ron Peled (Image: Sola Security) Sola Security, under the leadership of former Palo Alto Networks’ application security head, has successfully secured $35 million in Series…

Read MoreMicrosoft Supports Sola’s $35M Investment in Autonomous AI Security

Dutch Data Protection Authority Releases Report on Personal Data Breaches – Lexology

Dutch Data Protection Authority Reports on Personal Data Breaches The Dutch Data Protection Authority (DPA) has recently released a comprehensive report detailing significant breaches of personal data involving various organizations. This assessment highlights vulnerabilities and threats that business entities must address to enhance their cybersecurity frameworks. The report identifies that…

Read MoreDutch Data Protection Authority Releases Report on Personal Data Breaches – Lexology