The Breach News

Class Action Lawsuits Filed Against Allianz Following Data Breach

Recent Allianz Data Breach Exposes Sensitive Information of 1.4 Million Individuals A significant data breach has occurred at Allianz Life, potentially impacting the personal information of approximately 1.4 million individuals. This security incident highlights ongoing vulnerabilities in the handling of sensitive data across organizations, particularly those that utilize customer relationship…

Read MoreClass Action Lawsuits Filed Against Allianz Following Data Breach

Severe Apache Roller Vulnerability (CVSS 10.0) Allows Unauthorized Session Persistence

A severe security flaw has come to light in Apache Roller, the open-source blogging server software built on Java. This vulnerability endangers users by allowing unauthorized access even after changes to their passwords, raising significant security concerns. Designated as CVE-2025-24859, this vulnerability has been rated with a CVSS score of…

Read MoreSevere Apache Roller Vulnerability (CVSS 10.0) Allows Unauthorized Session Persistence

Gootkit Malware Implements New Strategies Targeting Healthcare and Financial Institutions

Recent investigations by Cybereason have revealed that the Gootkit malware, also known as Gootloader, is primarily targeting healthcare and financial entities across the United States, United Kingdom, and Australia. These findings shed light on the evolving threat landscape, emphasizing the need for heightened vigilance in these sectors. In a December…

Read MoreGootkit Malware Implements New Strategies Targeting Healthcare and Financial Institutions

Medical Cannabis Company Faces Lawsuit for Health Data Breach

Data Breach Notification , Data Security , Healthcare Lawsuits Emerge Following Discovery of Unprotected Patient Records Marianne Kolbasuk McGee (HealthInfoSec) • September 5, 2025     Image: Ohio Medical Alliance, operating as Ohio Marijuana Card A security researcher recently uncovered a significant security breach involving an unencrypted database lacking password…

Read MoreMedical Cannabis Company Faces Lawsuit for Health Data Breach

Exploitation of Unpatched Windows Zero-Day Vulnerability by 11 State-Sponsored Threat Actors Since 2017

A recently identified unpatched vulnerability in Microsoft Windows has been exploited by a coalition of eleven state-sponsored hacking groups from nations including China, Iran, North Korea, and Russia. This ongoing cyber threat campaign, dating back to 2017, focuses on data theft, espionage, and financially motivated activities. The zero-day vulnerability, cataloged…

Read MoreExploitation of Unpatched Windows Zero-Day Vulnerability by 11 State-Sponsored Threat Actors Since 2017

Apple Fixes Two Actively Exploited iOS Vulnerabilities Targeted in Sophisticated Attacks

Apple Addresses Critically Exploited iOS Vulnerabilities In a timely response to an escalating cybersecurity threat, Apple announced on Wednesday the release of crucial security updates for its suite of operating systems, including iOS, iPadOS, macOS Sequoia, tvOS, and visionOS. These updates were enacted to mitigate two significant security vulnerabilities that…

Read MoreApple Fixes Two Actively Exploited iOS Vulnerabilities Targeted in Sophisticated Attacks

Researchers Discover Hidden Malicious Code in PyPI Python Packages

Recent investigations have revealed that four rogue packages infiltrated the Python Package Index (PyPI), executing a series of malicious operations including the deployment of malware, the removal of the netstat utility, and the manipulation of the SSH authorized_keys file. The targeted packages—aptx, bingchilling2, httops, and tkint3rs—collectively amassed around 450 downloads…

Read MoreResearchers Discover Hidden Malicious Code in PyPI Python Packages